Digital Literacy · Grade 7 · Chapter 1
Privacy & Personal Data
What apps collect about us, how data travels, and why digital privacy matters.
Chapter Goals
What We Will Master Today
- Identify PII: Distinguish Personally Identifiable Information from general data.
- Analyze App Permissions: Evaluate which permissions are necessary vs risky.
- Trace Digital Footprints: Map how data travels from your device to data brokers.
- Protect Privacy: Apply defensive habits, encryption checks, and settings.
Here's a problem
The App That Knew Too Much
A free puzzle game asks for access to your contacts, precise GPS location, and camera — just to play level 1! Why does a puzzle game want all of that?
Discuss before revealing: What could an app developer do with your exact location or full contact list?
Core Concept 1
What is Personal Data (PII)?
Personally Identifiable Information (PII) is any data that can directly identify you or be linked together to figure out who you are.
If a stranger combines your school name, favorite soccer team, and first name, can they locate you? That is indirect PII!
Data Breakdown
Direct PII vs Indirect PII
Direct PII
Identifies You Immediately
- Full Legal Name
- Home Address & Phone Number
- National ID / Passport Number
- Fingerprint / Face ID data
Indirect PII
Identifies You When Combined
- ZIP / Postal Code + Birth Date
- Device IP Address
- Browser Type & Device Model
- Daily commute routes
Smartboard Voting
Is This PII? Vote with Your Hands!
Item 1
Your home Wi-Fi network name
Item 2
The color of Python's official logo
Item 3
Your gaming username + birth year
Teacher Note: Ask students why Item 1 and Item 3 are indirect PII, while Item 2 is public general knowledge!
Core Concept 2
Your Digital Footprint
Every click, search, tap, and download leaves a digital breadcrumb trail on servers around the world.
Active Footprint
Data you intentionally submit: Social posts, comments, filled forms, uploaded photos.
Passive Footprint
Data collected automatically: IP address, location tracking, time spent viewing an ad.
Visual Flow
How App Data Travels Behind the Scenes
1
You open a free game on your phone
2
App reads GPS & Contacts
4
Data Brokers build your profile
Notice: The app developer isn't just making a game — they are monetizing your habits!
Monetization
Why Is Personal Data So Valuable?
- Targeted Advertising: Showing you shoes you searched for 10 minutes ago.
- Data Brokers: Companies that buy, aggregate, and sell profile data to marketers.
- Algorithm Training: Feeding your interactions to train AI recommendation systems.
- Monetizing "Free" Services: "If you aren't paying for the product, you ARE the product."
Permissions Audit
Necessary vs Suspicious Permissions
✓ Necessary Permission
Navigation App requesting GPS Location while the app is active.
Directly required to function!
✗ Suspicious Permission
Calculator App requesting Contacts & Microphone access.
Has zero connection to math operations!
Scenario Analysis
Audit This App: "FitTrack Pro"
FitTrack Pro counts your steps and logs workouts. Here is what it requests upon installation:
1. Motion & Fitness Data [Makes Sense]
2. Camera Access [Maybe for profile photo?]
3. Read SMS Messages & Contacts [RED FLAG!]
Question: Which option should you select in settings? ("Allow Always", "Allow While Using", or "Deny")
Core Concept 3
Cookies & Web Trackers
Cookies are tiny text files stored in your browser by websites you visit.
1st Party Cookies
Remember your login state, dark mode preference, or items inside a shopping cart.
3rd Party Cookies
Placed by advertising networks to follow your browsing activity across different websites.
Spot the Mistake
What's Wrong With This Photo Post?
Caption: "Finally got my new student ID badge! Can't wait for soccer practice at 4 PM! ⚽️"
Image shows: A student holding their ID card with full name, student ID number, barcode, and school name clearly visible.
- ID Barcode can be scanned and cloned!
- Full name + exact location + routine time leaked to public.
Tech Deep Dive
HTTP vs HTTPS: Protecting Data in Transit
When you send password or chat data over Wi-Fi, encryption scrambled it so eavesdroppers can't read it.
# Unencrypted (HTTP) - Plain text visible on Wi-Fi
"user=alex&pass=secret123"
# Encrypted (HTTPS - SSL/TLS) - Scrambled ciphertext
"7f8a9b2c!$k90#m1a88zqq2..."
Always check for the padlock icon 🔒 and https:// in your browser address bar!
Think-Pair-Share
Smart Speakers & Listening Microphones
Smart speakers (Alexa, Siri, Google Assistant) are constantly listening for their wake word ("Hey Siri", "Alexa").
Discussion Question: Are smart speakers a privacy risk inside a classroom or home office? What happens to voice recordings stored in the cloud?
Myth Buster
Misconception: Incognito Mode = 100% Invisible
What Incognito DOES
Deletes local history, cookies, and form data from your own device when you close the window.
What Incognito DOES NOT Do
Does NOT hide your activity from your Wi-Fi manager, ISP, school network, or visited websites!
Quick Check · Quiz 1
Which of the following is an example of Personally Identifiable Information (PII)?
AThe operating system of your computer
BYour home street address and phone number
CThe screen resolution of your tablet
DThe price of a video game online
Click to reveal answer
Quick Check · Quiz 2
What is the primary purpose of 3rd-party tracking cookies?
ATo speed up your device processor
BTo save your game progress locally
CTo track browsing history across websites for targeted ads
DTo clean virus files automatically
Click to reveal answer
Quick Check · Quiz 3
Why is a Flashlight app requesting your contacts list a privacy red flag?
AContacts make the flashlight beam brighter
BThe app function has zero operational need for contact data
CIt uses contacts to calculate battery level
DFlashlights require contacts to turn on LED
Click to reveal answer
Quick Check · Quiz 4
Which web protocol encrypts communication between browser and website?
Click to reveal answer
Guided Practice
3-Step Personal Device Privacy Audit
1
Open Settings → Privacy → Location Services
2
Change "Always" to "While Using" for non-map apps
3
Turn off "Allow Apps to Request to Track"
Class Task: Take 2 minutes to inspect these 3 settings on your smartphone or tablet!
Real-World Application
Public Wi-Fi Safety Rule
You are at a cafe connected to "Free_Cafe_WiFi". You want to log into your bank or school portal.
- Rule 1: Never enter passwords on HTTP websites over public Wi-Fi.
- Rule 2: Use a VPN (Virtual Private Network) to encrypt all traffic.
- Rule 3: Disable "Auto-Connect to Open Wi-Fi Networks".
Summary & Takeaways
What We Learned in Chapter 1
- PII must be guarded carefully to protect identity and digital security.
- App permissions should match the actual functional purpose of the app.
- Data brokers monetize passive digital footprints via 3rd-party cookies.
- HTTPS encrypts data in transit — look for the padlock icon!
Exit Ticket
2-Minute Reflection Challenge
Write down or share with your shoulder partner:
1. One permission you will check on your phone today.
2. Why "Incognito mode" does NOT make you invisible to school Wi-Fi managers.
Next Chapter: Logic Gates → Python Thinking!