Strategic Business Leader · Big data and data analytics
Big Data Risks, Ethics and Data Protection for ACCA SBL
Updated 11 October 2026 · Fact-checked
Big data brings risks in privacy, security, data quality, bias and regulatory compliance, and it raises ethical questions about fairness, consent and transparency. In SBL, you identify the specific risks in the scenario, explain their consequences for the organisation and stakeholders, then recommend practical controls and governance responses.
Understand Risks, Ethics and Data Protection
Big data means very large, fast and varied data sets that organisations analyse to find patterns. The value is better decisions. The danger is that more data, held for longer and used in new ways, creates more ways to harm people and the business.
Start with the main risk groups. Privacy is about who is allowed to collect and use personal data, and for what purpose. Security is about protecting data from theft, loss or unauthorised access. They are not the same. You can have strong security and still breach privacy, for example by using customer data for a purpose they never agreed to.
Data quality and bias hit the reliability of decisions. If data is incomplete, out of date or wrongly recorded, the analysis is wrong. If the data reflects past unfair patterns, or the algorithm is built on a skewed sample, results can discriminate against groups, for instance in credit scoring or recruitment. Also watch for correlation being mistaken for cause, and for over-reliance on a model nobody can explain.
Regulatory compliance means following data protection law, such as the EU and UK GDPR or local equivalents. Common principles include lawful and fair use, a clear purpose, collecting only what is needed, accuracy, limited storage, security and accountability. Individuals usually have rights, such as access to their data and correction or deletion in some cases. Breaches can bring fines, legal claims and loss of trust. Cross-border data transfers add complexity for global businesses.
Ethical issues go beyond the law. Is it fair to profile customers? Is the organisation open about how it uses data? Is consent real or buried in small print? Is data sold on? ACCA expects you to link these issues to ethical principles, stakeholder interests and the public interest, and to the professional accountant's duty to raise concerns.
Key rules to remember
- Privacy vs security
- Privacy = rightful use of personal data; Security = protection of data from unauthorised access
- Use this distinction when a question asks for the difference. Security is needed for privacy, but is not enough on its own.
- Typical data protection principles (GDPR-style)
- Lawful, fair and transparent; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; accountability
- Use them as a checklist against the scenario. Say 'GDPR-style' unless the scenario names a specific law.
- Risk response framework
- Identify risk → assess likelihood and impact → respond (treat, transfer, avoid, accept)
- Links data risks to the TARA approach for recommendations.
- Ethics check
- Is it legal? Is it fair? Is it transparent? Would stakeholders accept it if they knew?
- A quick test for ethical issues that the law may not cover.
How to solve Risks, Ethics and Data Protection questions
Use this method for any SBL task on big data risks, ethics or data protection. Keep every point tied to the scenario.
- 1Read the requirement and note the verb: identify, discuss, evaluate or recommend. This sets the depth and the structure.
- 2Pick out scenario facts: what data is held, whose data, how it is used, where it is stored, and who has access.
- 3Sort issues into groups: privacy, security, data quality, bias, compliance and ethics. Choose those the facts support.
- 4For each issue, explain the consequence for the organisation and for stakeholders such as customers, regulators and employees.
- 5Apply a principle or rule: a data protection principle, an ethical principle or the accountant's duty, as the case needs.
- 6Recommend specific actions: governance policy, consent controls, access controls, data audits, bias testing, training and board oversight.
- 7Give a reasoned conclusion that weighs the benefits of analytics against the risks, and state your priority.
- 8Check you have used professional skills: a clear structure, commercial judgement and a balanced view.
Quickest way: Issue, impact, action
When to use it: Use when time is short, or for a part worth few marks.
- Jot the headings: Privacy, Security, Quality, Bias, Compliance, Ethics.
- Tick the two or three that the scenario evidence supports most.
- Write one short paragraph for each: issue, scenario fact, impact, action.
- Finish with one line on who is accountable, such as the board or a data protection officer.
Common mistakes in Risks, Ethics and Data Protection
Treating privacy and security as the same thing.
Both involve protecting data, so students blur them.
Fix: State the difference in one line: privacy is about rightful use, security is about protection. Then give a scenario example of each.
Writing a generic list of risks with no link to the scenario.
Students recall a learned list and write it out.
Fix: Quote the facts given, such as the type of data or the customers, and explain the impact on this organisation.
Quoting GDPR as the law everywhere.
It is the best-known data law, so students assume it applies.
Fix: Say 'GDPR-style' or name the regime only if the scenario does. Mention that rules differ by country and apply to cross-border transfers.
Saying a practice is ethical because it is legal.
Compliance is easier to judge than fairness.
Fix: Test both law and ethics. Ask about fairness, transparency and consent, and the interests of stakeholders.
Giving risks but no recommendations.
Students run out of time or forget the verb 'recommend'.
Fix: For each main risk, add a specific control or governance action and who should own it.
Ignoring bias and data quality, and focusing only on hacking.
Cyber attacks feel like the obvious risk.
Fix: Always consider whether the data is accurate and representative, and whether the model could treat groups unfairly.
Worked examples
Example 1
RetailCo uses loyalty card data and online browsing history to predict what customers will buy and to target offers. It plans to sell anonymised customer profiles to third-party advertisers. Customers were told only that their data would be used 'to improve service'. Discuss the privacy and ethical issues for RetailCo.
Show the solution
- Issue 1, purpose: customers were told data would improve service. Selling profiles to advertisers is a different purpose. This conflicts with purpose limitation and fair, transparent use.
- Issue 2, consent and transparency: a vague notice is unlikely to be real, informed consent. Customers may feel misled if they later discover the sale.
- Issue 3, anonymisation: profiles described as anonymised may still identify people when combined with other data. RetailCo should test whether re-identification is possible.
- Impact: regulatory action and fines, legal claims, lost trust and reputation damage, and possible customer defection, which hits revenue.
- Ethical view: even if the sale is legal, ask whether customers would accept it if they knew. Fairness and honesty to customers point towards telling them clearly.
- Recommendations: update the privacy notice, obtain clear opt-in consent for new uses, test anonymisation, appoint a data protection officer, and have the board approve any data-sharing policy.
Answer: The sale of profiles risks breaching purpose limitation and transparency, and it is ethically doubtful because customers did not clearly agree. RetailCo should obtain explicit consent, verify that anonymisation is robust, and set board-level governance over data sharing before proceeding.
Example 2
BankCo has built an algorithm using ten years of past lending decisions to approve loans automatically. A review finds that applicants from certain postcodes are refused far more often, though their repayment records are similar. Explain the risks and recommend actions.
Show the solution
- Identify the risk: bias. The model learns from past decisions, which may reflect earlier unfair practices. Postcode can act as a proxy for protected characteristics.
- Impact on customers: unfair refusal, financial exclusion and harm to individuals.
- Impact on BankCo: possible discrimination claims, regulatory scrutiny, reputation damage, and lost profitable lending because good customers are refused.
- Data quality link: the training data may be unrepresentative or contain errors, so the model may be inaccurate as well as unfair.
- Governance gap: decisions are automated, so customers may be unable to get an explanation or ask for review. Some data laws give rights relating to automated decisions.
- Recommendations: test the model for bias before and after use, remove or limit proxy variables, retrain on better data, keep human review of refusals, document how decisions are made, and report results to the risk committee.
Answer: The postcode pattern points to algorithmic bias from historical data. BankCo should test and correct the model, add human review and explanation for refused applicants, and have the board or risk committee oversee fairness, because the legal, reputational and ethical risks are significant.
Exam tips
- Always tie each risk to a fact in the scenario. Generic lists earn few marks.
- Show the difference between legal compliance and ethical behaviour. Examiners reward the extra step.
- Include recommendations with owners, such as the board, a data protection officer or internal audit.
- Use professional skills marks: structure the answer with clear headings, keep a balanced view of benefits and risks, and write in the format asked, such as a report or briefing note.
- If you are asked as a professional accountant, mention the duty to act with integrity and in the public interest, and to raise concerns through the proper channels.
Practice questions from Big data and data analytics
- Kessan Airlines wants its engine-monitoring system to flag abnormal vibration within milliseconds so that engineers can act before a fault d…
- Zenith Retail's board reviews a dashboard showing that online sales in the northern region fell 12% last quarter compared with the previous …
- Halden Logistics wants its analytics system to automatically recommend, each morning, the delivery routes and vehicle allocations that minim…
- Norvik Telecom wants to reduce customer churn. Its analysts use five years of customer records, including usage, complaints and contract len…
- Kestrel Retail, a national grocery chain, has produced a dashboard showing that sales of barbecue products fell 18% in the last quarter comp…
Risks, Ethics and Data Protection in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Risks, Ethics and Data Protection: frequently asked questions
What is the difference between data privacy and data security?
Data privacy is about the rightful collection and use of personal data, including consent and purpose. Data security is about protecting data from theft, loss or unauthorised access. A firm can be secure but still breach privacy by misusing data.
Do I need to know GDPR in detail for SBL?
No. You need the main principles and their business implications, such as lawful use, purpose limits, minimisation, accuracy, security and accountability. Apply them to the scenario rather than quoting article numbers.
How do I answer an ethics of data analytics question?
Identify the ethical issues the scenario shows, such as consent, fairness and transparency. Explain who is affected and how. Then recommend actions and give a reasoned conclusion that weighs benefits against risks.
What is algorithmic bias?
It is when an analytical model produces unfair results for certain groups. Causes include skewed or historical data and poor design choices. Controls include testing, better data, human review and clear accountability.