Skip to topic
    ← Back to course topics

    Consequences of uses of computing — AQA A-Level Computer Science

    Test yourself on Consequences of uses of computing with AQA A-Level practice questions.

    Start free

    7 days Premium · Then free forever · No card, no charge

    Consequences of uses of computing explained

    This subtopic explores the fundamental conflict between the right to individual privacy and the widespread collection of personal data by state and corporate entities, highlighting the legal and ethical frameworks designed to safeguard data.

    Read the full explanation

    It also delves into the practice of censorship, assessing its justifications in contexts such as national security and child protection against the principles of free expression and open access to information.

    Your focus

    1. Evaluate the impact of mass data collection on individual privacy rights.
    2. Analyse the legal protections afforded by data protection laws such as GDPR.
    3. Assess the arguments for and against internet censorship in modern democracies.
    Show all 5 objectives
    1. Explain how technological tools can be used to protect online privacy.
    2. Discuss the ethical responsibilities of organisations collecting personal data.

    Consequences of uses of computing exam tips

    Quick Revision Summary (Key Takeaway)

    The consequences of using computing cover legal, ethical, environmental, and professional issues, including the Data Protection Act 2018, Computer Misuse Act 1990, Copyright Designs and Patents Act 1988, and professional codes of conduct. Students must evaluate the impact of technology on society, including privacy, cybersecurity, and environmental sustainability, and understand the role of stakeholders in decision-making.

    Topic Overview

    The consequences of using computing is a broad topic that examines the impact of technology on individuals, organisations, and society. It covers legal frameworks such as the Data Protection Act 2018, the Computer Misuse Act 1990, and the Copyright, Designs and Patents Act 1988, as well as ethical and professional issues. Students must understand how these laws apply to real-world scenarios, including data breaches, hacking, and intellectual property theft.

    Beyond legal aspects, the topic includes environmental considerations, such as energy consumption and e-waste, and professional responsibilities, like adhering to codes of conduct and ensuring accessibility. It also explores the social implications of technology, including privacy, surveillance, and the digital divide. This topic is crucial for developing a holistic understanding of computing, as it encourages students to think critically about the consequences of technological decisions.

    In the AQA A-Level specification, this topic appears in Paper 1 and Paper 2, often in the form of extended response questions that require evaluation. It links to other areas like networks, databases, and cybersecurity, and it prepares students for the ethical dilemmas they may face in the workplace. Mastery of this topic demonstrates an ability to apply knowledge to complex, real-world issues, which is a key skill for computer scientists.

    Key Concepts
    • →Data Protection Act 2018 (GDPR): principles, rights of data subjects, and responsibilities of data controllers.
    • →Computer Misuse Act 1990: three offences and their penalties.
    • →Copyright, Designs and Patents Act 1988: protection of intellectual property, including software and digital content.
    • →Professional codes of conduct (e.g., BCS) and ethical frameworks.
    • →Environmental impact of computing: energy use, e-waste, and sustainability.
    Marking Points
    • Award credit for accurate reference to at least one piece of relevant legislation (e.g., Data Protection Act 2018, GDPR).
    • Expect discussion of real-world examples, such as social media data misuse or state surveillance programmes.
    • Credit for balanced evaluation: acknowledging both the benefits of data collection (e.g., crime prevention) and the risks to privacy.
    • For censorship, look for nuanced arguments that distinguish between different types (e.g., political vs. protective censorship).
    Examiner Tips
    • 💡Include specific, named case studies to ground your arguments (e.g., Edward Snowden, Cambridge Analytica, China's firewall).
    • 💡Structure your response clearly: start with definitions, then present arguments for and against, and conclude with a reasoned judgment.
    • 💡Use terminology accurately: distinguish between 'privacy', 'anonymity', 'confidentiality', and 'security'.
    • 💡When discussing legislation, mention its specific principles (e.g., GDPR's right to be forgotten).
    • 💡Use specific legislation names and dates, and refer to the ICO (Information Commissioner's Office) as the enforcement body.
    • 💡In evaluation questions, always consider both sides of an argument and reach a justified conclusion. Use phrases like 'on the other hand' and 'overall'.
    • 💡Remember to apply the law to the scenario given, not just state the law. Examiners look for application to gain top marks.
    Common Mistakes
    • Confusing privacy with data security; focusing solely on hacking rather than legal and ethical data handling.
    • Failing to differentiate between government surveillance and corporate data collection, treating them as identical.
    • Presenting a one-sided argument on censorship without considering the complexities of content moderation.
    • Overlooking the global nature of the internet and the jurisdictional challenges in enforcing privacy laws.
    • Misconception: The Data Protection Act only applies to digital data. Correction: It applies to both digital and paper records, as long as they are part of a structured filing system.
    • Misconception: Hacking is only illegal if it causes damage. Correction: Unauthorised access alone is an offence, even if no damage is done.
    • Misconception: Copyright law does not apply to software. Correction: Software is protected as a literary work under the Copyright, Designs and Patents Act 1988.
    Revision Plan
    1. 1Week 1: Focus on legal aspects. Create flashcards for each law, including key terms and penalties. Practice applying them to scenarios.
    2. 2Week 2: Study ethical and professional issues. Read the BCS Code of Conduct and discuss case studies. Then, cover environmental impact and sustainability.
    3. 3Day 10-12: Practice past paper questions, especially 6-mark evaluation questions. Time yourself and review mark schemes.
    4. 4Day 13-14: Revise key concepts and misconceptions. Use active recall to test yourself on definitions and scenarios.
    Exam Question Types
    • 📋Short-answer questions asking to define a term or state a law (e.g., 'State two principles of the Data Protection Act 2018').
    • 📋Scenario-based questions where you must identify legal breaches and explain consequences.
    • 📋Extended evaluation questions (6-9 marks) on ethical or environmental issues, requiring a balanced argument.
    • 📋Multiple-choice questions testing knowledge of specific provisions of the acts.
    Command Word Expectations (AQA)
    Define

    Provide a precise, concise definition. No extra explanation needed. For example, 'Define the term data controller.' Answer: 'The person or organisation that determines the purposes and means of processing personal data.'

    Explain

    Give reasons or causes. For example, 'Explain why the Computer Misuse Act 1990 was introduced.' Answer: 'To address the rise in computer-related crime, such as hacking and viruses, which were not covered by existing laws.'

    Evaluate

    Consider both strengths and weaknesses, and make a judgement. For example, 'Evaluate the impact of the Data Protection Act on businesses.' Answer: 'The DPA protects individuals' privacy but imposes compliance costs on businesses. It can be seen as a burden, but it also builds trust. Overall, the benefits outweigh the costs.'

    How Students Lose Marks (Examiner Pitfalls)
    Pitfall: Students often confuse the Data Protection Act 2018 with GDPR, or fail to mention the eight principles. They also forget to apply the law to a specific scenario, instead giving generic definitions.
    ❌ Weak Answer (Loses Marks):The Data Protection Act protects people's data. It says data must be kept safe and not shared without permission.
    Example improved answer:The Data Protection Act 2018 (DPA) implements GDPR in the UK. It requires data controllers to process personal data fairly and lawfully, for specified purposes, and to ensure data is adequate, relevant, and not excessive. Data subjects have rights, including access, rectification, and erasure. In this scenario, the company must obtain explicit consent before collecting customer data and must implement appropriate technical measures to prevent unauthorised access.
    Examiner Tip: Always link the law to the scenario: identify the data, the controller, the subject, and the specific principle or right being breached. Use correct terminology like 'data controller' and 'data subject'.
    Pitfall: In questions about the Computer Misuse Act 1990, students often forget the three offences or fail to distinguish between unauthorised access and unauthorised modification. They also miss the intent requirement.
    ❌ Weak Answer (Loses Marks):Hacking is illegal under the Computer Misuse Act. It is wrong to access someone's computer without permission.
    Example improved answer:The Computer Misuse Act 1990 has three offences: (1) unauthorised access to computer material, (2) unauthorised access with intent to commit or facilitate further offences, and (3) unauthorised modification of computer material. For example, if a person guesses a password to view files, they commit offence 1. If they then delete files, they commit offence 3. The act also covers denial-of-service attacks, as they impair the operation of a computer.
    Examiner Tip: Learn the three offences and be able to apply them to scenarios. Mention the need for 'intent' and 'unauthorised' actions. Use case examples like the ICO fines for data breaches.
    Step-by-Step Worked Solutions

    Question: A company stores customer data on a cloud server. A hacker gains access by exploiting a weak password and modifies the data. Identify the offences under the Computer Misuse Act 1990 and explain the potential legal consequences for the hacker.

    1. 1.Step 1: Identify the actions: unauthorised access (guessing password) and unauthorised modification (changing data).
    2. 2.Step 2: Match to offences: Offence 1 (unauthorised access) and Offence 3 (unauthorised modification).
    3. 3.Step 3: State consequences: up to 2 years imprisonment for offence 1, up to 10 years for offence 3, and unlimited fines.
    4. 4.Step 4: Conclude: The hacker is liable under both offences, and the company may also face penalties under the Data Protection Act for failing to protect data.
    Final Answer: The hacker commits offences under sections 1 and 3 of the Computer Misuse Act 1990. They could face up to 10 years in prison and fines. The company may also be fined by the ICO for inadequate security.

    Question: Evaluate the environmental impact of cloud computing, considering both positive and negative consequences. (6 marks)

    1. 1.Step 1: Define cloud computing and its reliance on data centres.
    2. 2.Step 2: Negative impacts: high energy consumption, carbon emissions, e-waste from hardware, cooling requirements.
    3. 3.Step 3: Positive impacts: shared resources reduce overall hardware, virtualisation improves efficiency, renewable energy use in some data centres, and reduced need for personal devices.
    4. 4.Step 4: Balance: argue that while cloud computing has significant environmental costs, it can be more efficient than local servers if managed sustainably.
    5. 5.Step 5: Conclude with a reasoned judgement, e.g., 'Overall, the environmental impact is mixed, but with green initiatives, cloud computing can be more sustainable.'
    Final Answer: Cloud computing has negative impacts like high energy use and e-waste, but positive impacts like resource sharing and efficiency. The net effect depends on data centre practices, but with renewable energy, it can be more sustainable than traditional computing.
    Active Recall Memory Test
    What are the three offences under the Computer Misuse Act 1990?
    Key Fact: 1. Unauthorised access to computer material. 2. Unauthorised access with intent to commit or facilitate further offences. 3. Unauthorised modification of computer material.
    Name four principles of the Data Protection Act 2018.
    Key Fact: Lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; accountability.
    What is the role of the Information Commissioner's Office (ICO)?
    Key Fact: The ICO is the UK's independent authority set up to uphold information rights, including enforcing the Data Protection Act and GDPR, and imposing fines for breaches.
    How does cloud computing affect the environment positively?
    Key Fact: It can reduce energy consumption through shared resources and virtualisation, and data centres may use renewable energy, leading to lower carbon emissions compared to local servers.
    Frequently Asked Questions
    What is the difference between the Data Protection Act 2018 and GDPR?
    The Data Protection Act 2018 is the UK law that implements the General Data Protection Regulation (GDPR) into UK law. GDPR is an EU regulation that sets out data protection rules, and the DPA 2018 supplements it with additional provisions. After Brexit, the UK has its own version, but it is largely similar to GDPR. In exams, you can treat them as equivalent, but it's good to mention both.
    Can I use open-source software without any restrictions?
    No, open-source software is still protected by copyright. The open-source license (e.g., MIT, GPL) grants you permission to use, modify, and distribute the software, but you must comply with the license terms, such as including attribution or making your code open-source if you use GPL. Violating the license is a breach of copyright.
    What are the penalties for breaking the Computer Misuse Act?
    The penalties vary: unauthorised access (offence 1) can lead to up to 2 years in prison and a fine; unauthorised access with intent (offence 2) can lead to up to 5 years; unauthorised modification (offence 3) can lead to up to 10 years. In practice, sentences depend on the severity and impact.
    How can companies reduce their environmental impact from computing?
    Companies can use energy-efficient hardware, virtualise servers to reduce physical machines, use renewable energy sources for data centres, implement cooling optimisations, and adopt a policy of recycling e-waste. They can also encourage remote working to reduce office energy consumption.
    What is the BCS Code of Conduct?
    The BCS (British Computer Society) Code of Conduct is a set of professional standards for IT professionals. It includes duties to the public, employers, and the profession, such as acting with integrity, ensuring competence, and avoiding conflicts of interest. It is not law but is enforced by the BCS and can lead to expulsion from the society.
    Why is it important to study the consequences of computing?
    Understanding consequences helps you make ethical decisions in your career, ensures you comply with laws, and allows you to evaluate the impact of technology on society. It also helps you design systems that are secure, private, and sustainable, which is increasingly important to users and regulators.