Skip to topic
    ← Back to course topics

    Computing related legislation — OCR A-Level Computer Science

    Test yourself on Computing related legislation with OCR A-Level practice questions.

    Start free

    7 days Premium · Then free forever · No card, no charge

    Computing related legislation explained

    This topic covers the essential legal framework governing the use of computers and digital technology in the UK.

    Read the full explanation

    It requires an understanding of specific legislation, including the Data Protection Act 1998, the Computer Misuse Act 1990, the Copyright Design and Patents Act 1988, and the Regulation of Investigatory Powers Act 2000.

    What to demonstrate

    1. Identification and accurate description of the Data Protection Act 1998
    2. Identification and accurate description of the Computer Misuse Act 1990
    3. Identification and accurate description of the Copyright Design and Patents Act 1988
    Show all 4 objectives
    1. Identification and accurate description of the Regulation of Investigatory Powers Act 2000

    Computing related legislation exam tips

    Topic Overview

    Computing related legislation is a key topic in the OCR A-Level Computer Science specification, covering the laws that govern the use of computers, data, and digital systems. This includes the Data Protection Act 2018 (which implements the GDPR), the Computer Misuse Act 1990, the Copyright, Designs and Patents Act 1988, and the Regulation of Investigatory Powers Act 2000. Understanding these laws is essential for any computing professional, as they dictate how data must be handled, what constitutes illegal access to systems, and how intellectual property is protected in the digital age.

    This topic matters because it bridges the gap between technical computing skills and the legal and ethical responsibilities that come with them. For example, a developer must know that storing personal data without consent or adequate security measures is a breach of the Data Protection Act, and that hacking into a system (even for 'fun') is a criminal offence under the Computer Misuse Act. These laws also have real-world implications for businesses, governments, and individuals, making them a crucial part of a well-rounded computing education.

    In the wider OCR A-Level course, this topic sits within the 'Legal, moral, cultural and ethical issues' section, often linked to discussions about cybersecurity, data privacy, and professional conduct. Students are expected to not only recall the key provisions of each act but also apply them to scenarios, evaluate their effectiveness, and consider how they balance competing interests (e.g., privacy vs. security). This prepares students for both exams and future careers in computing, where legal compliance is non-negotiable.

    Key Concepts
    • →Data Protection Act 2018 (GDPR): Governs the processing of personal data, requiring consent, purpose limitation, data minimisation, and rights for individuals (e.g., right to be forgotten, right to access).
    • →Computer Misuse Act 1990: Makes unauthorised access to computer material (Section 1), unauthorised access with intent to commit further offences (Section 2), and unauthorised acts with intent to impair operation (Section 3) criminal offences.
    • →Copyright, Designs and Patents Act 1988: Protects intellectual property, including software, from unauthorised copying, distribution, or modification. Covers both source code and object code.
    • →Regulation of Investigatory Powers Act 2000 (RIPA): Allows public authorities to intercept communications and access data for national security and crime prevention, but requires warrants and oversight.
    Marking Points
    • Identification and accurate description of the Data Protection Act 1998
    • Identification and accurate description of the Computer Misuse Act 1990
    • Identification and accurate description of the Copyright Design and Patents Act 1988
    • Identification and accurate description of the Regulation of Investigatory Powers Act 2000
    Examiner Tips
    • 💡Ensure you can distinguish between the specific purposes of each piece of legislation.
    • 💡Be prepared to apply these legal concepts to real-world scenarios or case studies provided in the exam.
    • 💡When answering scenario-based questions, always name the specific act and section (e.g., 'This would be an offence under Section 1 of the Computer Misuse Act 1990') and explain why the scenario fits the legal definition. Avoid vague references like 'it's illegal'.
    • 💡For evaluation questions (e.g., 'Discuss the effectiveness of the Data Protection Act'), use a balanced approach: mention strengths (e.g., gives individuals control) and weaknesses (e.g., enforcement challenges, impact on innovation). Use real examples like fines for data breaches to support your points.
    • 💡Memorise key case studies or examples that illustrate each act in action. For instance, the TalkTalk data breach (2015) is a classic example of a Data Protection Act violation, while the conviction of Gary McKinnon for hacking US military systems illustrates the Computer Misuse Act.
    Common Mistakes
    • Misconception: The Data Protection Act only applies to companies storing data online. Correction: It applies to any organisation (including schools, charities, and sole traders) that processes personal data, whether stored digitally or on paper, as long as it is part of a filing system.
    • Misconception: The Computer Misuse Act only covers hacking into systems. Correction: It also covers unauthorised access with intent to commit further crimes (e.g., stealing data) and unauthorised acts that impair the operation of a computer (e.g., launching a DDoS attack).
    • Misconception: Copyright law does not apply to software because it is functional. Correction: Software is explicitly protected as a literary work under the Copyright, Designs and Patents Act, meaning copying code without permission is infringement, even if the code is modified.
    Frequently Asked Questions
    What is the difference between the Data Protection Act 2018 and GDPR?
    The Data Protection Act 2018 is the UK's implementation of the General Data Protection Regulation (GDPR), which was an EU regulation. Since Brexit, the UK has its own version (UK GDPR) which is essentially the same as the EU GDPR but tailored for UK law. The Data Protection Act 2018 supplements the UK GDPR by providing additional details and exemptions. In practice, the principles are identical: both require lawful processing, consent, data minimisation, and give individuals rights like access and erasure.
    Can you be prosecuted for guessing someone's password and logging into their account?
    Yes, under the Computer Misuse Act 1990. Section 1 makes it an offence to cause a computer to perform any function with intent to secure unauthorised access to any program or data. Guessing a password and logging in is unauthorised access, even if no further harm is done. The maximum penalty is up to 12 months in prison and/or a fine. If you then commit a further crime (e.g., stealing data), Section 2 applies with a more severe penalty (up to 5 years).
    Is it legal to download music or movies from torrent sites?
    Generally, no. Downloading copyrighted music or movies without permission from the copyright holder infringes the Copyright, Designs and Patents Act 1988. Torrent sites often distribute content illegally. However, there are exceptions like fair dealing for private study or research, but these are narrow and do not cover typical downloads for personal entertainment. Both uploading and downloading can lead to civil liability (sued for damages) and, in serious cases, criminal prosecution.
    What rights do individuals have under the Data Protection Act 2018?
    Individuals have several key rights: the right to be informed about how their data is used (via privacy notices), the right of access (to see what data is held), the right to rectification (correct inaccurate data), the right to erasure (also known as the 'right to be forgotten'), the right to restrict processing, the right to data portability (move data to another service), and the right to object to processing (e.g., for direct marketing). These rights give individuals control over their personal data.
    How does the Regulation of Investigatory Powers Act (RIPA) affect everyday internet users?
    RIPA allows public authorities like the police and intelligence agencies to intercept communications (e.g., emails, phone calls) and access communications data (e.g., who you called, when) for purposes like national security or preventing crime. For everyday users, this means that your internet service provider may be required to retain certain data and provide it to authorities under a warrant. While this raises privacy concerns, RIPA includes safeguards such as requiring authorisation from a senior official or a judicial commissioner.
    What is the penalty for hacking under the Computer Misuse Act?
    Penalties vary by section. Section 1 (unauthorised access) carries up to 12 months in prison and/or a fine. Section 2 (unauthorised access with intent to commit further offences) carries up to 5 years and/or a fine. Section 3 (unauthorised acts with intent to impair operation of a computer) carries up to 10 years and/or a fine. For example, launching a DDoS attack would fall under Section 3. In serious cases, such as those causing significant damage or affecting critical infrastructure, sentences can be even longer.