GCSE computer science covers three key UK laws: the Computer Misuse Act 1990 GCSE computer science topic criminalises unauthorised access to computer systems; the Data Protection Act controls how personal data is stored and used; and the Copyright, Designs and Patents Act protects original digital work from being copied without permission.

Why does GCSE computer science include legislation at all?

Both AQA and OCR require students to understand the legal, moral, ethical, cultural and environmental impact of digital technology — not just how systems work technically. This reflects a real professional expectation: anyone writing software, running a network, or handling other people's data is bound by UK law, and ignorance of that law is not a defence.

Three Acts come up most often in exam questions, each protecting a different aspect of digital life: unauthorised access to systems, personal data, and creative or intellectual work.

What does the Computer Misuse Act 1990 cover?

The Computer Misuse Act 1990 was introduced specifically to criminalise hacking, at a time when existing UK law had no clear way to prosecute someone for breaking into a computer system. It defines three main offences:

  1. Unauthorised access to computer material — simply gaining access to a system or data you are not permitted to use, even without doing anything else once inside. This covers guessing or stealing someone's password to look at their files.
  2. Unauthorised access with intent to commit further offences — accessing a system in order to then commit a more serious crime, such as fraud or theft, using the access gained.
  3. Unauthorised modification of computer material — changing, deleting or damaging data or programs without permission, which covers deploying malware, deleting files, or altering records.

A later amendment added a fourth offence covering the making, supplying or obtaining of tools (such as hacking software) intended to be used to commit any of the above. A student who guesses a classmate's school login and reads their private files, without changing anything, has already committed an offence under the first category — no data needs to be stolen or damaged for the Act to apply.

What does the Data Protection Act require?

The Data Protection Act governs how organisations collect, store, use and share personal data — any information that can identify a living individual, such as a name, address, date of birth, or exam results. It works alongside the UK GDPR (General Data Protection Regulation) and sets out core principles that organisations must follow:

  • Personal data must be processed lawfully, fairly and transparently.
  • Data must be collected for a specified, legitimate purpose and not used for anything incompatible with that purpose.
  • Only the minimum data necessary should be collected (data minimisation).
  • Data must be kept accurate and up to date.
  • Data should not be kept longer than necessary.
  • Organisations must keep data secure, protecting it against unauthorised access, loss or damage.

For a GCSE student, the most exam-relevant point is that a school, app, or website holding personal data has a legal duty to protect it — a data breach caused by a weak password policy or an unpatched vulnerability is not just a technical failure, it is a legal one.

The Copyright, Designs and Patents Act 1988 protects original creative and intellectual work — including software code, music, images, video, and written text — from being copied, distributed, or used commercially without the creator's permission. In a computing context, this covers:

  • Copying someone else's source code and presenting it as your own (which is also an academic integrity issue in coursework).
  • Downloading and redistributing copyrighted music, films or software without a licence ("piracy").
  • Using images or code found online in a project without checking the licence terms.

Copyright protection is automatic in the UK — a creator does not need to register or add a copyright symbol for their work to be protected, though doing so helps prove ownership if a dispute arises.

How do the three Acts compare?

The table below summarises what each Act protects, who it typically affects, and an example offence, which is the level of detail GCSE mark schemes usually reward.

Act What it protects Typical offence example
Computer Misuse Act 1990 Computer systems and data from unauthorised access Guessing a password to read someone else's private files
Data Protection Act (with UK GDPR) Personal data about living individuals A company storing customer data insecurely, leading to a breach
Copyright, Designs and Patents Act 1988 Original creative and intellectual work, including code Copying and redistributing someone else's software without permission

Recognising which Act applies to a given scenario is the skill exam questions test most often, so it helps to ask: is this about breaking into a system, about personal data, or about copying someone's original work?

Frequently asked questions

What does the Computer Misuse Act 1990 actually criminalise?

It criminalises unauthorised access to computer systems or data, unauthorised access carried out to commit a further crime, and unauthorised modification of data or programs — including deploying malware. A later amendment also covers making or supplying hacking tools for these purposes.

How is the Data Protection Act relevant to a GCSE computer science student?

It sets legal rules for how any organisation — including a school or an app you might build — must collect, use, store and protect personal data such as names, addresses or grades. GCSE questions typically test whether you can identify a data protection principle being broken in a given scenario, such as data being kept longer than necessary.

Copying someone else's source code, images, music or software and using or distributing it without permission breaks this Act, because copyright protection is automatic in the UK the moment original work is created. This applies whether the work is shared for free or sold commercially.

Do all three Acts apply to the same situation, or just one?

Most exam scenarios are designed to test one Act at a time, so the key skill is identifying whether the situation involves unauthorised system access (Computer Misuse Act), personal data handling (Data Protection Act), or copying original work (Copyright, Designs and Patents Act). In real life, though, a single incident — such as a data breach caused by hacking — can breach more than one Act simultaneously.

Want a subject specialist to walk through legal and ethical scenarios until you can spot the right Act every time? Add the AI Tutors connector at aitutors.me.