Teaching Data Protection and Privacy at Work
Teaching Data Protection and Privacy at Work
Personal data, lawful basis, monitoring and what happens after a breach, taught through workplace situations rather than policy documents. Suitable for grades 9 to 12 business, CTE and computing classes where students handle customer information on placement or in a school enterprise.
See the unit โResources that fit
Units and bundles for this topic
Start with the unit that matches your next teaching block; the bundle is there if you need the whole strand. Tap any cover for the full contents, preview and price.
The teaching problem
Privacy Feels Abstract Until Something Leaks
The subject reads as compliance paperwork, and students switch off inside five minutes. What brings it back is the scope of the term personal data, which is far wider than a name and an address. A staff photo on a shared drive, a delivery driver's location history, a customer's phone number in a group chat, a colleague's sick note: all of it counts, and students who picture only credit card numbers never see the risk in what they do every shift. Consent is the other difficulty. It is the first lawful basis students name and often the weakest one at work, because an employee asked by a manager to agree to monitoring is rarely in a position to refuse. Lessons need situations from inside a workplace, not extracts from a regulation.
A sequence that works
Five Lessons From Data Point to Breach
The unit works through one small company's data: who is in it, why it is held, who may see it, and what happens on the day a spreadsheet leaves the building.
- What counts as personal dataStudents sort thirty items from a fictional company into personal, sensitive and non-personal, then defend the borderline calls such as a work photo and a staff car registration.
- Purpose, minimization and retentionEach data set gets a stated purpose and a deletion date. Students find the fields the company collects out of habit and argue whether an address is needed for a click-and-collect order.
- Lawful basis and real consentSix lawful bases are matched to processing examples. Students test whether consent given to a supervisor is freely given, then rewrite a consent request that fails the test.
- Watching the workforceCameras, keystroke logging, delivery tracking and personal phones used for work are weighed against purpose and proportionality. Students draft a monitoring notice a reasonable employee would accept.
- The breach drillA laptop goes missing an hour before closing. Working to the clock, students decide what to record, who to tell, in what order, and what the affected customers need to hear.
Where it goes wrong
Precision Problems in Privacy Answers
Anonymized and pseudonymized get used as if they mean the same thing. They do not: replacing a name with a customer number leaves data that is still personal, because it can be traced back, and answers claiming a spreadsheet is anonymous after deleting the name column need correcting early. Two habits also need naming. Forwarding a work file to a private email address to finish at home moves data outside the company's controls. A screenshot shared in a group chat is a disclosure, whatever the intention. Assess with a case requiring four statements: what data, for what purpose, on what basis, and for how long. Vague answers to the last two lose the most marks.
What's in the download
Inside the files
Editable Word and PowerPoint plus print-ready PDFs, with answer keys throughout.
- Thirty-item data sorting activity
- Purpose and retention register template
- Lawful basis matching cards
- Monitoring notice drafting task
- Timed breach response scenario
- Teacher notes with jurisdiction comparisons
Good to know
Frequently asked questions
Is this GDPR-only, or does it work in the US?
The lessons teach the principles both systems share: a purpose for holding data, no more than you need, limits on how long, and a duty to tell people when something goes wrong. Where GDPR's lawful bases have no exact US equivalent, teacher notes give a comparison with state privacy laws so you can pitch it accurately. Slides are editable if you would rather lead with one framework.
Do students need computing knowledge?
None beyond ordinary use of email, shared drives and a phone. The unit is about decisions rather than technology, so there is no encryption math and no network configuration. A computing class can extend the breach drill into access controls and logging if you want the technical side, and teacher notes suggest where those extensions fit without disrupting the sequence.
Will this suit students going on work placement?
This unit assumes that starting point. The sorting task, the monitoring lesson and the breach drill all use the kind of information a student on placement actually touches: customer contact details, staff rosters, photographs and delivery records. Running lessons one and five as a pre-placement briefing works well, with the remaining lessons afterward once students have their own examples to bring back.
Before Their First Customer Record
Run the sorting task in one period and students stop thinking privacy means passwords. The rest of the unit builds from there.
Browse the full collection โ



