The Data and AI School of London is an NCFE approved centre for this qualification (NCFE Account No. 11001657). Enrol below to begin your learning journey.
← All courses
Level 2 · NCFE Self-paced
Enrolling now NCFE Approved Qualification number 603/3639/0

NCFE Level 2 Certificate in Understanding Data Protection and Data Security

Understand GDPR, the Data Protection Act and the Freedom of Information Act, and how to protect data and ICT systems. 110 guided learning hours, assessed by portfolio with no exams.

Duration: 110 guided learning hours, 130 total hours, self-paced online

Level
Level 2
Qualification number
603/3639/0
Awarding organisation
NCFE
Regulated status
On the RQF, regulated by Ofqual
Guided learning hours
110 hours
Total qualification time
130 hours
Delivery
100% online
Study pattern
110 guided learning hours, 130 total hours, self-paced online
NCFE This qualification is awarded by NCFE and regulated by Ofqual
NCFE Account No. 11001657

Course overview

This is a regulated Level 2 qualification (NCFE qualification number 603/3639/0). Its purpose is to allow learners to demonstrate an understanding of data protection and data security, and it will help learners progress to a work role where data protection and data security knowledge is required.

The qualification has five objectives. By the end of the course you will understand current data legislation, understand the steps organisations might take to help protect data, understand how to protect your own data, understand how to protect ICT systems from common threats, and understand the consequences of not protecting data and systems.

You study four mandatory units totalling 110 guided learning hours. Unit 01 covers the General Data Protection Regulation (GDPR), including what personal data is, controllers and processors, the seven key principles of the general data protection regime, the lawful bases for processing, the individual rights, the role of a Data Protection Officer, Data Protection Impact Assessments and what should happen after a personal data breach. It also covers the purpose of the Data Protection Act and the purpose of the Freedom of Information Act, which applies to public authorities.

Unit 02 covers the procedures an organisation might have for recording, storing and disposing of data, ways to protect stored data, symmetric and asymmetric encryption and their advantages and disadvantages, and the security checks an organisation makes before releasing information.

Unit 03 covers common physical and electronic threats to ICT systems and data, vulnerabilities in remote access technologies, denial of service attacks, social engineering including phishing and vishing, how to report breaches and suspicious online behaviour, physical and electronic access controls, malicious software such as viruses, trojans, ransomware and spyware, and how to protect your own personal data and devices.

Unit 04 covers the potential consequences of not protecting data for an organisation, covering legal and regulatory, reputational and financial impact, the consequences of an employee sharing confidential business or customer data, the impact on individuals whose data is accessed or distributed without consent, including identity theft, and the steps an individual can take if they suspect this has happened.

Assessment is by an internally assessed and externally quality assured portfolio of evidence. There are no exams. Evidence could include case studies, questioning, coursework, research documents and presentations. All learners must be assessed in English and all evidence presented for external quality assurance must be in English. A partial certificate can be requested by learners who do not achieve the full qualification but have achieved at least one whole unit.

Learners who achieve this qualification could progress to the Level 2 Certificate in Principles of Business Admin, Level 2 Certificate in Principles of Team Leading, Level 2 Certificate in Principles of Customer Service, Level 2 Certificate in ICT Systems and Principles, Level 2 Certificate in IT User Skills (ITQ), Level 2 Certificate in Digital Skills for Work, Level 3 Certificate in Principles of Business Admin or the Level 3 Certificate in Principles of Customer Service. It is also useful for learners studying in the Business, Administration and Law and the Information and Communication Technology sectors.

Delivery is 100% online with tutor support.

What you will study

The units below, their unit reference numbers and their guided learning hours are taken directly from the NCFE qualification specification.

Unit Title Unit reference Hours
01 Understand current data protection legislation (mandatory)
3 learning outcomes
  1. Understand the General Data Protection Regulation
    • 1.1 Define what is meant by personal data
    • 1.2 Describe the purpose of the General Data Protection Regulation (GDPR)
    • 1.3 Define the following in relation to GDPR: • a controller • a processor.
    • 1.4 Describe the following key principles of the general data protection regime: • lawfulness, fairness and transparency • purpose limitation • data minimisation • accuracy • storage limitation • integrity and confidentiality • accountability.
    • 1.5 Explain what is meant by a lawful basis for processing personal data
    • 1.6 Describe the following lawful bases: • consent • contract • legal obligation • vital interests • public task • legitimate interests
    • 1.7 Describe the following individual rights: • right to be informed • right of access • right of rectification • right to erasure • right to restrict processing • right to data portability • right to object • rights related to automated decision making including profiling.
    • 1.8 Describe the role of a Data Protection Officer (DPO)
    • 1.9 Outline what a Data Protection Impact Assessment (DPIA) is
    • 1.10 Outline what should happen in the event of a personal data breach
  2. Understand the purpose of the Data Protection Act
    • 2.1 Explain the purpose of the Data Protection Act
    • 2.2 Describe the following elements of the Data Protection Act: • general data processing • law enforcement processing • intelligence services processing • regulation and enforcement.
    • 2.3 Explain how the Data Protection Act differs from the GDPR
  3. Understand the purpose of the Freedom of Information Act
    • 3.1 Explain the purpose of the Freedom of Information Act
K/617/2469 35
02 Understand organisational procedures concerning data (mandatory)
2 learning outcomes
  1. Understand organisational procedures concerning data
    • 1.1 Outline procedures an organisation might have for the: • recording of data • storage of data • disposal of data.
  2. Understand procedures to maintain data confidentiality and security
    • 2.1 Describe ways to protect stored data
    • 2.2 Outline the two basic techniques for encrypting information
    • 2.3 Describe the advantages and disadvantages of each encryption technique
    • 2.4 Explain the security checks an organisation might make before releasing information
    • 2.5 Explain the actions an organisation might take where: • a customer is unable to satisfy the required security checks • they suspect an attempt at fraud.
D/617/2470 25
03 Understand threats to ICT systems and data (mandatory)
3 learning outcomes
  1. Know the common types of threat to ICT systems and data
    • 1.1 Explain common types of physical threat to ICT systems and data
    • 1.2 Explain common types of electronic threat to ICT systems and data
    • 1.3 List the security vulnerabilities associated with remote access technologies
    • 1.4 Explain what a denial of service (DoS) attack is
    • 1.5 Define what social engineering is
    • 1.6 Define the following social engineering techniques: • phishing • vishing.
    • 1.7 Explain ways to report breaches of security or suspicious online behaviour internally
  2. Know how to protect ICT systems
    • 2.1 Identify methods of providing physical access control and security for ICT systems and data
    • 2.2 Identify methods of providing electronic access control and security for ICT systems and data
    • 2.3 Describe types of malicious software
    • 2.4 Outline the impact of malicious software
    • 2.5 Describe ways to prevent malicious software
  3. Understand how to protect their own personal data and devices
    • 3.1 Outline potential types of threat to their own personal data
    • 3.2 Describe ways to protect their own personal information and data
    • 3.3 Outline the range of software and tools available to help protect personal data and devices
    • 3.4 Explain how to differentiate between trustworthy and untrustworthy sources of information online
H/617/2471 30
04 Understand the consequences of not protecting data (mandatory)
2 learning outcomes
  1. Understand the potential consequences of not protecting data
    • 1.1 Explain the potential consequences not protecting data could have on an organisation, including the following areas: • legal/regulatory impact • reputational impact • financial impact.
    • 1.2 Describe the potential consequences of an employee sharing confidential business or customer data
  2. Understand the impact of data breaches on individuals
    • 2.1 Explain the potential impact on individuals if their data is accessed or distributed without consent
    • 2.2 Describe steps an individual can take if they suspect their data has been accessed or distributed without consent
K/617/2472 20
Total guided learning hours 110

Entry requirements

  • There are no specific recommended prior learning requirements for this qualification.
  • This qualification is suitable for learners aged pre-16 and above.
  • Learners may find it helpful if they have already achieved a Level 1 qualification in the business, administration and law sector.
  • There is no requirement to undertake any work experience or placement. Learners who are in work can provide evidence from real-life situations.
  • All learners must be assessed in English, and all assessment evidence presented for external quality assurance must be in English.
  • Registration is at the discretion of the centre, in accordance with equality legislation.
Take it with you

The course guide

Everything on this page as one document you can keep, print, or send to whoever is deciding with you.

  • All 4 units, with the hours behind each one
  • How you are assessed, and who checks the marking
  • How paying works, and what is due when
  • Entry requirements and where the qualification leads
Download the guide (PDF)

Generated from this qualification's record, so the units and hours in it are the ones on this page. The fee is here on the page rather than in the guide, so a saved copy cannot quote you an old one.

How you are assessed

Your work is assessed by our qualified assessors, internally quality assured, and externally quality assured by NCFE. Assessment is against the criteria published in the qualification specification, and your assessor tells you what is needed before you start each unit.

For what happens after you submit: who marks it, who checks the marking, how long feedback takes and what to do if you disagree with a decision, see how assessment works.

If you need an adjustment to how you are assessed, for a disability or any other reason, ask us before you begin. We arrange adjustments under our Reasonable Adjustments policy, and you can request one online.

How we assess and quality assure is set out in DAIS-POL-016 Assessment and Internal Quality Assurance.

How you study, and what you need

You study online through our virtual learning environment, which is where the teaching material, your assessment submissions, your feedback and your progress all live. You work at your own pace, with tutor support throughout. Everyone completes a short online induction before starting an assessed unit.

What you need to take part
Device Laptop or desktop computer
Operating system Windows 10 or macOS 10.15 or later
Browser Google Chrome or Mozilla Firefox, latest version
Internet speed 10 Mbps download and 5 Mbps upload
Webcam Required for live sessions and identity verification
Microphone Required for live sessions

These are the minimum requirements published in DAIS-POL-024 Online Learning and Digital Delivery.

Support, and how quickly we reply

These are the response times we commit to in policy, not an aspiration.

What How Response
General questions Message your tutor in the VLE Within 2 working days
Assessment feedback Returned in the VLE or e-portfolio Within 10 working days of submission
Technical problems Technical support email Within 1 working day
Urgent welfare concerns Email to the Designated Safeguarding Lead Within 1 working day

Published in DAIS-POL-024 and DAIS-POL-009 Learner Support.

Registration and your certificate

We register you with NCFE before you begin any assessed unit, and we collect your Unique Learner Number as part of that. When your assessment decisions are finalised and quality assured, we claim your certificate through the NCFE portal and you are notified digitally. The certificate comes from NCFE, not from us.

Set out in DAIS-POL-008 Learner Registration and Certification.

Progression

Progression: prepares you for our Level 3 Certificate in Data, and for roles carrying data protection and information governance duties. This qualification does not carry UCAS Tariff points.

Other names for this qualification

The regulated title is NCFE Level 2 Certificate in Understanding Data Protection and Data Security, qualification number 603/3639/0. People also look for it as:

  • Level 2 Data Protection and Data Security
  • Data Protection and Data Security Level 2
  • NCFE Level 2 Data Protection and Data Security
  • 603/3639/0
  • NCFE 603/3639/0
  • Data Protection and Data Security course online
  • Data Protection and Data Security qualification UK
  • Data Protection and Data Security distance learning

If you arrived searching one of those, you are in the right place: they all describe this one qualification.

Common questions

Who awards NCFE Level 2 Certificate in Understanding Data Protection and Data Security, and how do I get my certificate?

NCFE Level 2 Certificate in Understanding Data Protection and Data Security is awarded by NCFE, an Ofqual-approved awarding organisation, and sits on the Regulated Qualifications Framework (RQF). The qualification number is 603/3639/0. The Data and AI School of London is an NCFE approved centre (Account No. 11001657). We register you with NCFE before you start any assessed unit and collect your Unique Learner Number. Once your work is assessed and quality assured we claim your certificate through the NCFE portal, and it is issued by NCFE rather than by us.

How long does NCFE Level 2 Certificate in Understanding Data Protection and Data Security take?

This qualification carries 110 guided learning hours and a total qualification time of 130 hours. It is studied online at your own pace, so how long it takes in calendar time depends on how much you can commit each week.

What do I need before I can start?

There are no specific recommended prior learning requirements for this qualification. We assess every applicant individually and will tell you if a different level would suit you better.

Can I study this entirely online?

Yes. Teaching, materials and assessment are all delivered through our Moodle-based virtual learning environment, so you can study from anywhere in the UK. You need a laptop or desktop computer, a current version of Chrome or Firefox, and a broadband connection of at least 10 Mbps down and 5 Mbps up. Tutor support is available throughout, and we answer questions within 2 working days and return assessment feedback within 10 working days of submission.

Can I enrol now, and when do I pay?

The fee is £395. Enrolment is open, so you can apply online today. Nothing is paid at application: payment is taken only after you accept an offer.

Not sure this is the right qualification?

Ask before you apply. We will say honestly if a different level would suit you better.

Worth reading first

More from the blog

Other qualifications

See all qualifications