A-Level Computer Science: Computing and the Law

This material trains the legal content of A level Computer Science: recognising which law applies to a situation involving computers and data, and explaining why. It is for Year 12 and Year 13 students who know the names of the Acts and need practice in applying them to cases, which is how the topic is usually examined.

The quiz has twelve questions, ten of them built on short invented scenarios. Three apply the Computer Misuse Act 1990: reading someone's files with an overheard password, logging in to a payroll system in order to divert a salary, and knocking a website offline with a flood of requests, which shows that an offence can be committed without logging in at all. Four apply data protection law, the UK GDPR together with the Data Protection Act 2018: a school that passes parents' emergency numbers to an advertiser, a phone company that will not correct an address, a customer asking for her own data, and what a company must do after its customer database is stolen. Two apply the Copyright, Designs and Patents Act 1988, contrasting copying a game's code with writing a new game on the same idea. Two cover the Regulation of Investigatory Powers Act 2000: the power to require a decryption key and the purpose of the Act. The last asks why legislators find computing hard to regulate.

Every explanation states the rule and ties it to the facts in the scenario, and explains why the other laws do not fit. Where the law has moved on, the material says so: the Data Protection Act 1998, still named in some specifications, was replaced in 2018, and much of RIPA's interception regime now sits in the Investigatory Powers Act 2016.

The flashcards cover the Computer Misuse Act offences, UK data protection law, its seven principles and the rights of individuals, subject access requests, the Information Commissioner's Office, controllers and processors, copyright in software, what copyright does not protect, software licences, RIPA and the Investigatory Powers Act 2016.

The written work has eight longer tasks to answer on paper: applying the Computer Misuse Act to a case with a keylogger and deleted files, four data protection principles for a gym's member records, individuals' rights and breach reporting, three copyright situations, the purpose of RIPA with arguments for and against, a database copied onto a USB stick, why computing is hard to legislate for, and a school's plan to monitor web searches. Each task has a model answer and the points a marker would look for.

There is also a short oral practice with an examiner, who builds each question on an invented scenario, never asks for section numbers and gives brief feedback at the end.

The content is based on the legislation named in OCR H446 section 1.5.1 and the legal issues and challenges facing legislators in AQA 7517 section 4.8. It is practice for the exam and is not legal advice.

  • Identify offences under the Computer Misuse Act 1990 in a given scenario
  • Apply the data protection principles of the UK GDPR and the Data Protection Act 2018
  • Describe individuals' data rights and an organisation's duties after a data breach
  • Explain how the Copyright, Designs and Patents Act 1988 protects software and what it does not protect
  • Describe the purpose of the Regulation of Investigatory Powers Act 2000 and the debate around it
  • Explain why computing is difficult to legislate for

Practice material written by Zestly, based on the computing-related legislation in the A level Computer Science specifications (OCR H446 section 1.5.1: Data Protection Act, Computer Misuse Act 1990, Copyright Designs and Patents Act 1988, Regulation of Investigatory Powers Act 2000; AQA 7517 section 4.8). Data protection content reflects the UK GDPR and the Data Protection Act 2018, which replaced the 1998 Act. Not legal advice.

Sample question

A student watches a teacher type a password, later logs in to the teacher's account with it and reads the class's marks, but changes nothing. Which law has the student most clearly broken?

See the answer

The Computer Misuse Act 1990, by gaining unauthorised access to computer material

Knowingly accessing a computer system or data without permission is the basic offence of unauthorised access under the Computer Misuse Act 1990. It is committed even if nothing is altered. The marks are not a creative work being copied, and reading them from a logged-in account is not interception of a communication in transmission.

← Computer Science

↑ A-Level