top of page

Qualification:
Cambridge Advanced Nationals in Computing (AAQ)

Certificate:
Computing: Application Development (H029 / H129)

Unit:
F161: Developing Application Software

Watch on YouTube:
Computer Misuse Act
Data Protection Act
UK General Data Protection Regulation
Freedom of Information Act
Privacy and Electronic Communications Regulations
Independent bodies
UK Information Commissioner's Office

6.1 - Legal Considerations

You need to know the latest version and main purpose of each act/regulation, as well as actions taken to comply with the act and the impacts of not complying with it.

 

You must also understand how Privacy and Electronic Communications Regulations (PECR) relate to the Data Protection Act and UK General Data Protection Regulation (UK GDPR), and the role of the Information Commissioner's Office (ICO) in the UK.

What You Need to Know

noun-knowledge-8136749e.png

Developers must ensure application software complies with relevant legislation and regulations to protect users, their data and computer systems and to avoid legal and financial consequences.

Computer Misuse Act (CMA)

The Computer Misuse Act (CMA) protects computer systems and data from unauthorised access and misuse. It makes activities such as unauthorised access, hacking and deliberately impairing computer systems criminal offences.

 

Developers must only access systems and data they have permission to use, ensure any security testing is authorised, and must not develop or use software to deliberately gain unauthorised access or damage systems. If individuals do not comply with the CMA, they could face criminal prosecution, fines or imprisonment, while an organisation could also experience financial costs and reputational damage.

 

Example: A developer must have permission before attempting to access restricted parts of a client's system, even if they claim they were only testing its security.

Data Protection Act (DPA)

The purpose of the Data Protection Act (DPA) is to control how organisations collect, process, store and protect personal data. It helps ensure people's (known as data subjects) information is handled fairly, lawfully and securely.

 

Developers should ensure applications only collect necessary personal data, explain how it will be used, only use it for its intended purpose, keep it secure and remove it when it is no longer required. Non-compliance can result in complaints, data breaches, regulatory action, legal disputes, financial penalties, operational disruption and reputational damage.

​

Example: A revision application should not collect a student's home address if that information is unnecessary for providing the service.

UK General Data Protection Regulation (UK GDPR)

UK General Data Protection Regulation (UK GDPR) provides rules and principles governing the lawful processing and protection of personal data. It gives individuals rights over how organisations use their information. It operates alongside the DPA 2018 in the UK.

​

Developers should ensure there is a lawful reason for processing personal data, collect only necessary information, clearly explain its use, keep it accurate and secure, avoid retaining it unnecessarily and allow users to exercise their data rights where applicable. If they do not comply, organisations can face investigations, enforcement action, significant fines, compensation claims and reputational damage, particularly following serious data breaches.

 

Example: A bank application collecting account information should clearly tell users what personal data is collected and why it is needed.

Freedom of Information Act (FOIA)

The Freedom of Information Act (FOIA) gives people the right to request recorded information held by public authorities, such as government departments, councils, state schools and the NHS, subject to exemptions.

​

To comply, when developing software for a public authority, developers should consider how information can be stored, organised, searched and retrieved so the organisation can respond appropriately to information requests. Non-compliance may cause a public authority to face complaints, investigations, enforcement action and reputational damage if it fails to meet its legal responsibilities.

​​

Example: A system developed for a council should allow relevant recorded information to be located when the council receives a valid FOI request.

Privacy and Electronic Communications Regulations (PECR)

Privacy and Electronic Communications Regulations (PECR) protect people's privacy when using electronic communications, including rules covering electronic marketing, cookies and similar technologies and the security of communications services.

 

To comply, developers may need to ensure applications obtain appropriate consent for non-essential cookies or similar technologies, provide relevant information to users and follow the rules when enabling electronic marketing such as emails or text messages. If they don't comply, organisations could face regulatory action, financial penalties, complaints and reputational damage.

 

Example: A website should not simply place certain advertising or analytics cookies on a user's device without providing the required information and obtaining consent where required.

Independent Bodies

Independent bodies are organisations that operate separately from the organisations they oversee and can provide guidance, monitor legal compliance and take action when rules or standards are not followed.

​

When developing application software, independent bodies may:

  • Provide guidance and codes of practice that developers can follow.

  • Monitor and investigate whether organisations are meeting their legal responsibilities.

  • Handle complaints from users or members of the public.

  • Take or recommend enforcement action when organisations fail to comply.

  • Help developers understand how legislation should be applied to applications and user data.

Information Commissioner's Office (ICO)

The Information Commissioner's Office (ICO) is the UK's independent regulator for information rights and data protection, overseeing areas including the DPA, UK GDPR, FOIA and PECR.

​

When developing application software, the ICO is relevant because it:

  • Provides guidance on how personal information should be collected, processed, stored and protected.

  • Helps organisations understand how to comply with data protection and privacy legislation.

  • Can investigate complaints and data breaches.

  • Can take enforcement action when organisations fail to meet their legal obligations.

  • Promotes good practice in areas such as privacy, electronic marketing, cookies and protecting users' information.

 

Example: If developers create an application that collects users' names, email addresses and dates of birth, they can use ICO guidance to help ensure the application handles this personal data appropriately and complies with data protection requirements.

logoheadwhite.png

Questo's Questions

6.1 - Legal Considerations:

​​​​​

1. State the main purposes of the CMA, DPA, UK GDPR, FOIA and PECR[2 each]

​​​​​

2. For each act or regulation, explain the actions developers should take to ensure application software complies with its requirements. â€‹[2 each]

​​​

3. Explain the possible impacts on an organisation if its application software does not comply with relevant legislation or regulations​[2 each]

​​​​

4. Explain the role of independent bodies and the Information Commissioner's Office (ICO) when developing and operating application software. â€‹[4]

​

5. A revision app collects users' personal data, uses cookies and sends marketing emails. Identify the relevant legislation and explain how the developers should comply with it. â€‹[4]

Following a 2018 cyberattack, personal data belonging to more than 400,000 British Airways customers was compromised. In 2020, the Information Commissioner's Office (ICO) fined British Airways £20 million for failing to adequately protect its customers' data, the largest data protection fine the ICO has issued.

Did You Know?

noun-plane-8377485.png

© CSNewbs 2026

The written, video and visual content of CSNewbs is protected by copyright. © 2026
bottom of page