6.4 - Computer Legislation
Introduction to computer legislation
Computer legislation refers to laws designed to regulate the use of technology, protect data, and prevent misuse in the digital world. These laws help ensure that personal information is handled responsibly, creative works are safeguarded, and computer systems are secure from unauthorised interference.
The Data Protection Act 2018
The Data Protection Act 2018 is a law that governs how personal data is collected, stored, and used by organisations. Personal data includes any information that can identify an individual, such as names, addresses, or online identifiers. The act aims to protect people's privacy while allowing organisations to use data responsibly.
Key requirements for organisations
Before an organisation can collect personal data, it must follow specific rules to comply with the law.
Requirements for data collection:
- Registration - Organisations must register with the government, detailing what personal data they plan to collect and how they intend to use it.
- Accountability - Organisations are responsible for following the act's rules. Failure to comply can result in large fines.
Rights of data subjects
Data subjects are individuals whose personal data is stored on computer systems. The act provides them with important rights to control their information.
Rights provided by the act:
- The right to view the personal data an organisation holds about them.
- The right to request amendments if the data is inaccurate.
- The right to ask for data to be deleted under certain circumstances.
However, there are exceptions to these rights, such as when releasing data could impact national security or influence a court case.
The seven principles of data protection
The act is built around seven core principles that guide how personal data should be handled.
The seven principles:
- Fair, lawful, and transparent use - Data must be collected and used in a way that is honest, legal, and clear to the data subject.
- Specified purpose - Data can only be used for the reasons it was originally collected.
- Adequate and relevant - Only necessary data should be collected; it must be sufficient for the purpose without being excessive.
- Accurate and up to date - Data should be correct and updated regularly to avoid errors.
- Limited retention - Data must not be kept longer than needed for its purpose.
- Safe and secure - Appropriate measures must protect data from loss or unauthorised access.
- Accountability - Organisations must demonstrate compliance with all the data protection principles.
The Copyright, Designs and Patents Act 1988
The Copyright, Designs and Patents Act 1988 protects intellectual property, which is anything created by a person or organisation, such as ideas, inventions, or creative works. This law prevents others from using these creations without permission, encouraging innovation in fields like computing.
What the act protects
The act covers two main areas to safeguard different types of intellectual property.
Types of intellectual property protection:
- Copyright - This applies to written or recorded content, including books, music, films, software, and video games. It makes it illegal to share copyrighted files without permission, use unlicensed software, or plagiarise (copy) someone else's work. Copyright holders can grant permission, often for a fee.
- Patents - These protect new inventions, focusing on ideas and concepts rather than the content itself. For example, a patent might cover innovative hardware like a new type of processor. In computing, patents are commonly used for physical devices.
Challenges with the internet and file sharing
The growth of the internet has complicated copyright enforcement, as digital content can be easily copied and distributed.
Common methods of illegal file sharing:
- Peer-to-peer networks - These use protocols like BitTorrent to share files directly between devices.
- Cloud-based file-hosting websites - Users upload copyrighted material, which others can download. Website owners may face prosecution for hosting such content, though responsibility can be unclear if users are the ones uploading it.
Enforcement is particularly difficult when content is stored on servers in countries with lenient copyright laws, making global cooperation essential. Many illegal sharing sites have been shut down through legal action, highlighting the act's role in protecting creators' rights.
The Computer Misuse Act 1990
The Computer Misuse Act 1990 addresses cyber crimes by making it illegal to access or alter computer systems without permission. It was created to combat hacking and related threats, defining specific offences that can lead to fines or imprisonment.
The three main offences
The act outlines three key criminal activities to protect networks and data.
Offences under the Computer Misuse Act:
- Unauthorised access - Gaining entry to a private network or device without permission, such as through hacking. Even simple access can result in penalties.
- Unauthorised access with intent to commit a crime - Accessing a system to carry out further illegal acts, like stealing data or damaging the network.
- Unauthorised modification - Changing, deleting, or altering computer files without permission. This also includes creating, supplying, or obtaining malware (malicious software designed to harm systems).