Business and Technology · Regulation and financial crime
Cybercrime and Data Protection for ACCA BT
Updated 11 October 2026 · Fact-checked
Cybercrime is crime carried out using computers or networks, such as hacking, phishing and malware. Data protection law sets rules for how organisations collect, use and store personal data. To answer BT questions, identify the threat or principle in the scenario, then match it to the correct control or compliance duty.
Understand Cybercrime and Data Protection
Cybercrime is any criminal act that uses computers, networks or the internet as a tool or a target. Criminals want money, data or disruption. Common types are hacking (gaining unauthorised access to a system), phishing (fake emails or messages that trick people into giving passwords or payment details), malware (harmful software such as viruses, worms, trojans and spyware) and ransomware (malware that locks data until a payment is made).
Other threats include denial of service attacks, which flood a website so genuine users cannot reach it, and identity theft, where stolen personal details are used to commit fraud. Threats can come from outside the organisation or from insiders, such as staff who misuse access.
Personal data is information that identifies a living person, such as a name, address, email or bank details. Data protection laws control how organisations handle it. The best-known example is the EU General Data Protection Regulation (GDPR). Many other countries have similar laws. ACCA tests the general principles, not the detail of one country's law.
The usual principles are that personal data must be processed lawfully, fairly and transparently; collected for specified and legitimate purposes; adequate, relevant and limited to what is needed; accurate and kept up to date; kept no longer than necessary; and processed securely. The organisation must also be able to show it complies (accountability).
Individuals (data subjects) have rights, such as to see their data, to have errors corrected and, in some cases, to have data erased. Organisations protect data through technical controls (passwords, encryption, firewalls, anti-malware, backups), and organisational controls (training, policies, access limits, incident response plans). Breaches may need to be reported to the regulator and can lead to heavy fines and loss of reputation.
Key formulas to remember
- Data protection principles (GDPR-style)
- Lawful, fair and transparent | Purpose limitation | Data minimisation | Accuracy | Storage limitation | Integrity and confidentiality | Accountability
- Learn these as a checklist. Match each scenario to the principle it breaks.
- Information security aims (CIA)
- Confidentiality + Integrity + Availability
- Confidentiality: only authorised people see data. Integrity: data is accurate and unaltered. Availability: data is accessible when needed.
- Main cyber threats
- Hacking | Phishing | Malware | Ransomware | Denial of service | Identity theft
- Know a one-line definition of each.
- Control types for data
- Preventive | Detective | Corrective
- Firewall and passwords prevent. Intrusion monitoring detects. Backups and recovery plans correct.
How to solve Cybercrime and Data Protection questions
Use this method for any question on cybercrime or data protection.
- 1Read the scenario and underline what actually happened, for example a fake email, locked files or data kept for years.
- 2Decide whether it is a threat question (cybercrime type) or a compliance question (data protection principle or right).
- 3For a threat, match the key feature to the definition: tricking people is phishing, unauthorised access is hacking, harmful software is malware, locked files with a demand is ransomware.
- 4For compliance, name the principle that is breached, such as storage limitation for data kept too long.
- 5Pick the control that fits the problem and its type: preventive, detective or corrective.
- 6Check the question wording: how many options to select, or whether it asks for the best, first or most likely.
- 7Eliminate options that are true in general but do not answer the question asked.
Quickest way: Keyword matching
When to use it: Use for objective test questions where you have about a minute per mark.
- Spot the trigger word: fake email or link means phishing; locked files means ransomware; flooded website means denial of service; unauthorised access means hacking.
- For data rules, spot the trigger: too much data means minimisation; old data means storage limitation; wrong data means accuracy; no consent or notice means lawful, fair and transparent.
- For controls, ask whether it stops, spots or fixes the problem.
- Pick the option that matches the trigger and remove the rest.
Common mistakes in Cybercrime and Data Protection
Confusing phishing with hacking.
Both lead to unauthorised access, so they look alike.
Fix: Phishing tricks a person into giving details. Hacking breaks into a system technically. Phishing is often the first step to hacking.
Calling every harmful program a virus.
Virus is the everyday word for malware.
Fix: Use malware as the general term. Virus, worm, trojan, spyware and ransomware are types of it.
Thinking data protection covers all company data.
The title sounds broad.
Fix: Data protection law applies to personal data about living individuals. Commercial secrets are protected by other controls.
Treating security as only a technical issue.
Students focus on firewalls and passwords.
Fix: Include people and process controls: training, policies, access rights and incident plans. Staff error is a major cause of breaches.
Mixing up the types of control.
Backups and monitoring both seem like protection.
Fix: Preventive stops the event, detective finds it, corrective restores things afterwards. Backups are corrective.
Assuming consent is the only lawful basis for processing.
Consent is the most talked-about idea.
Fix: Processing can also be lawful for reasons such as a contract or a legal obligation. Say that consent is one basis among several.
Worked examples
Example 1
Staff at a company receive an email that appears to be from the bank, asking them to click a link and enter their online banking password. Which cybercrime is this? A Hacking B Phishing C Denial of service D Ransomware
Show the solution
- The key feature is a fake message that tricks the reader into giving details.
- Hacking is direct unauthorised access to a system, not a trick message.
- Denial of service floods a site with traffic, and ransomware locks files for payment. Neither is described.
- The description matches phishing.
Answer: B Phishing
Example 2
A retailer keeps customers' names, addresses and purchase histories on file for 15 years after their last purchase, with no business reason. Which data protection principle is most clearly breached, and what should the retailer do?
Show the solution
- Identify the facts: personal data is kept long after it is needed.
- Match to the principle: personal data should be kept no longer than necessary for its purpose. This is storage limitation.
- Recommend action: set a retention policy with fixed periods for each data type.
- Add controls: securely delete or anonymise data past its retention date, and review this regularly.
- Mention accountability: keep records to show the policy is followed.
Answer: The retailer breaches the storage limitation principle. It should set a retention policy and securely delete or anonymise data it no longer needs.
Exam tips
- Learn one-line definitions of hacking, phishing, malware, ransomware and denial of service. Objective tests reward quick matching.
- For data protection, memorise the principles as a list and practise assigning a scenario to one principle.
- In multiple response questions, select exactly the stated number of options. Pick the clearly correct ones first.
- Distinguish personal data from other business information. Many wrong options use this trap.
- Answer with the control type in mind. If a question asks for a preventive control, remove detective and corrective options.
Practice questions from Regulation and financial crime
- An accountant, Priya, files an internal suspicion report about a client's unusual transactions. Later, she tells the client that the report …
- A bank's customer service employee, who has no business reason to do so, looks up the account details of a celebrity customer out of curiosi…
- Which of the following best describes the purpose of a whistleblowing policy within a company?
- The MLRO of a firm receives an internal report from a junior member of staff about a client's unusual transactions. After review, the MLRO c…
- Which of the following is an example of fraudulent financial reporting, as distinct from misappropriation of assets?
Cybercrime and Data Protection in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Cybercrime and Data Protection: frequently asked questions
What are the data protection principles in GDPR?
They are lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. For ACCA BT, learn them as a general checklist and apply them to scenarios.
Do I need to know GDPR in detail for ACCA BT?
No. You need the main principles and ideas of data protection, not article numbers. Questions focus on applying principles and controls to short scenarios.
What is the difference between phishing and malware?
Phishing is a trick that persuades someone to reveal information or click a link. Malware is harmful software. A phishing email may deliver malware, but the two are different things.
How can an organisation protect its data?
It combines technical controls, such as passwords, encryption, firewalls, anti-malware and backups, with organisational controls, such as staff training, access limits, clear policies and an incident response plan.