Security, privacy and the data lifecycle
≈ 45 minSecurity, privacy and the data lifecycle
Data has a lifecycle: it is collected, stored, used, shared, retained and eventually deleted. A secure system considers each stage. A study app may need topic progress to recommend revision, but it does not need a learner’s contacts or precise location. The purpose should be clear before collection, and access should be limited to people and services that genuinely need it.
Security controls include strong authentication, role-based access, encryption in transit and at rest, audit logs, backups and incident response. Privacy controls include minimisation, clear notice, retention limits and correction or deletion processes. Encryption does not make unnecessary collection justified, and a privacy policy does not repair weak access controls.
Worked reasoning. An educator dashboard shows class-scoped completion and misconceptions, not every private learner activity. A learner joins a class explicitly. The platform stores only progress needed for support, encrypts it, logs access and deletes or exports it through a defined process. A compromised password should not grant a teacher access to unrelated classes.
Exam lens. For a scenario, name the asset, the threat, the control and the remaining limitation. Do not stop at “use a password.”
Which statement is the most defensible principle for Security, privacy and the data lifecycle?
Enter the key term for Security, privacy and the data lifecycle. What principle says collect only personal information that is needed for a defined purpose?
A revision feature wants microphone access to recommend flashcards. What should be the default decision without a clear learning need?
Name the concise safeguard or principle that completes this lesson’s scenario: A revision feature wants microphone access to recommend flashcards. What should be the default decision without a clear learning need?

