Skip to content
IGCSE·Tuition
ICT · Lessons

Identify a data-protection risk in a fictional case

A case study gives you a paragraph of details, and the hard part is knowing which detail is the risk.

On this page
  1. How do you find the risk in a case?
  2. Worked example
  3. The mistake to watch for
  4. Check yourself
  5. Where this leads next

A data-protection risk is a way that personal data could be seen, changed, shared or lost by someone who should not have that power. Case-study questions ask you to find the risk in a described situation and name a sensible control.

This skill belongs to safety, security and effects and also supports your written answers on user accounts and records.

How do you find the risk in a case?

Work through four questions in order. Each one narrows the answer.

  1. What data is there? List it, and mark which items identify a person.
  2. Where is it kept? A shared computer, a USB stick, an email, a paper file.
  3. Who can reach it? Staff, visitors, anyone on the network.
  4. What could go wrong? Seen by the wrong person, copied, altered, lost or kept too long.

The control then answers the risk directly: a password for unwanted viewing, encryption for a lost device, a lock for a paper file, deletion for data kept too long.

Worked example

Invented case: Kampung Hijau Library (fictional) keeps a spreadsheet with member names, home addresses and the books borrowed. The file sits on a USB stick that the librarian carries in a bag between the library and home.

Step 1, data: names and home addresses identify people. The borrowing history shows personal interests.

Step 2, location: a portable USB stick with no protection.

Step 3, access: whoever finds or takes the stick can open the file.

Step 4, risk: the stick could be lost or stolen, so strangers could read members’ addresses and reading habits.

Control: encrypt the file so it cannot be understood without a key, and keep the master copy on the library computer with a password. State the reason: encryption protects the data even when the device is lost.

The mistake to watch for

A common slip is writing a risk that has nothing to do with the data in the case.

Mistaken answer: “The library could get a virus.”

This names a general danger but never connects to members’ addresses or the USB stick.

The fix is to tie the risk to the data and the weak point: “The USB stick could be lost, so members’ addresses could be read by a stranger.” Always include who or what is affected.

Check yourself

1. A clinic (fictional) emails appointment lists with patient names to every member of staff, including cleaners. Name the risk and one control.

Show answer

Risk: people who do not need the patient details can see them, which breaks the idea of using data only for its purpose. Control: give each role access only to the information it needs, for example a list without names for the cleaners.

2. A school keeps exam results for former pupils from ten years ago “just in case”. Which data-protection idea does this go against?

Show answer

Keeping personal data longer than needed. The control is a retention rule that deletes records after a set period.

3. Why is encrypting a file better than renaming it to hide it?

Show answer

A renamed file can still be opened by anyone who finds it. Encryption scrambles the contents so they cannot be read without the key.

Where this leads next

Once you can state a risk and control cleanly, move to backup and recovery and then test yourself on the practice set. The practical task and evidence checker is useful when a brief asks you to protect a file you have produced.

If your written answers are close but keep missing the exact wording, online one-to-one ICT tuition lets a teacher mark up your phrasing with you.

Questions people ask

What counts as personal data in an ICT question?

Any information that identifies a living person, such as a name with an address, a phone number, a photo or a student record. A single first name alone may not identify anyone. Read the case and ask whether the details together point to one real person.

Is data protection the same as data security?

They overlap but differ. Protection is about handling personal data fairly and only for the right purpose. Security is about the technical and physical measures that stop unauthorised access or loss. A good answer often uses both ideas.

Do I need to quote a particular law?

Not unless the question asks. Describe the principle in plain words, such as keeping data accurate, using it only for the stated purpose and not keeping it longer than needed. Check the Cambridge ICT 0417 syllabus page for what your exam year expects.

Updated:

Your next step

If you can see that something is wrong in a case but struggle to phrase the risk precisely, a one-to-one teacher can work through your own wording and tighten it.

Paid one-hour trial at your assigned teacher’s confirmed rate, starting from RM80. Other fees, schedules and ongoing arrangements are confirmed directly with your teacher after the trial class.

Tuition is arranged with a parent or guardian. Send them this page on WhatsApp and they can enquire for you.

Parent or guardian? Enquire here

9,000+ students helped through our service