5.2.1 Personal data — ethics and law

Personal Data in the Digital Age

Personal data is any information that can identify a living individual — names, addresses, email addresses, phone numbers, health records, browsing history, location data, photos. Digital systems collect vast quantities of personal data, raising serious ethical and legal questions about how it is used, stored and protected.

Key Ethical Issues

Privacy is the right of individuals to control information about themselves. Digital systems routinely collect more data than users are aware of:

  • Smartphones track location, app usage, contacts and browsing behaviour
  • Social media platforms build detailed profiles from posts, likes and interactions
  • Search engines log queries and link them to identifiable users
  • Smart home devices (voice assistants, thermostats) record behaviour inside private homes

Ethical tension: data collection enables useful personalised services but at the cost of privacy. The key question is whether users genuinely understand and accept the trade-off.

Ownership concerns who has rights over personal data once it has been collected. Competing perspectives:

  • User perspective: personal data is an extension of identity — individuals should own it and retain control over how it is used and shared.
  • Company perspective: companies invest in systems and services to collect and process data; they argue the derived insights have commercial value they are entitled to use.
  • Legal perspective: GDPR (in the UK and EU) grants individuals rights over their data — including the right to access it, correct it and request deletion ("right to be forgotten").

The question of data ownership is unresolved in practice — most users sign terms of service that grant companies broad rights over their data without fully understanding the implications.

Consent means individuals must agree to their data being collected and used. Ethically, consent should be:

  • Informed: users understand what data is collected and how it will be used
  • Freely given: not coerced — accepting a cookie banner to access a service is not truly free consent if the alternative is being denied the service
  • Specific: consenting to one use does not imply consent to all uses
  • Withdrawable: users should be able to withdraw consent at any time

In practice, many consent mechanisms are designed to be opaque — long terms of service, pre-ticked boxes and "dark patterns" that nudge users towards accepting data collection.

Misuse of personal data includes any use beyond what was consented to or that causes harm:

  • Selling user data to third parties without explicit consent
  • Using data to discriminate (e.g. insurance companies using social media data to assess risk)
  • Targeted political advertising using detailed personal profiles
  • Data breaches exposing personal information to criminals
  • Using health data to make employment or insurance decisions

Data Protection Law

In the UK, the Data Protection Act 2018 (which incorporates UK GDPR) provides the legal framework. Key principles relevant to GCSE:

PrincipleWhat it means
Lawfulness, fairness and transparencyData must be collected legally, fairly and openly
Purpose limitationData collected for one purpose cannot be used for a different purpose
Data minimisationOnly collect data that is necessary — no more
AccuracyData must be kept accurate and up to date
Storage limitationData must not be kept longer than necessary
SecurityData must be protected against unauthorised access or loss

Individual rights under UK GDPR: right of access (subject access request), right to rectification, right to erasure, right to object to processing.

 Key Takeaways

  • Privacy: individuals have a right to control information about themselves; digital systems routinely undermine this.
  • Ownership: the question of who owns personal data is ethically and legally contested.
  • Consent: must be informed, freely given, specific and withdrawable — in practice, many consent mechanisms fall short.
  • Misuse: using data beyond what was consented to, or in ways that harm individuals.
  • Data Protection Act 2018 / UK GDPR: provides legal rights over personal data including access, correction and deletion.