Purnima Lallan Sharma Foundation · Est. 2021
PLS FoundationPLS FOUNDATIONEducate. Empower. Care.

Digital skills

Personal data and digital footprints

A digital footprint includes what you post, what a service records and what others can infer by combining details. Learn to choose an audience, reduce unnecessary collection and review sharing without assuming you can erase every existing copy.

By PLS Foundation · · 5 min read, plus practice

By the end of this lesson: Identify direct and inferred personal information, explain cookies and private browsing, redesign an over-collecting form and review a file or photo before sharing.

Read this topic on its own, or follow Create, communicate and think digitally

The core idea

Privacy is control over appropriate information flows, not simply hiding everything. Ask what data is needed, who receives it, what they can do with it and how long it remains useful. Share the minimum needed for the task and revisit permissions as circumstances change.

1. Information can identify people in combination

Personal information is not limited to an identity number. A name, contact address, photograph, location pattern or account activity can reveal something about a person. Some information is supplied deliberately, such as a profile description. Other information is recorded during use, such as login times or device details. Further information can be inferred by combining records. For example, a public timetable, repeated location posts and a school uniform in a photo may reveal a routine even when no home address is written. This does not mean every detail must be secret. It means judging a combination and its audience, rather than examining each detail in isolation. Ask whether a stranger could learn something unnecessary from the full set. Privacy choices should support participation in learning and public life without requiring avoidable exposure.

Sources: W3C: Privacy Principles ↗

2. Audience is a practical design choice

A message to one teacher, a class group and a public page have different audiences. Choose the smallest audience that can fulfil the purpose. A restricted group can still contain people who take screenshots or forward messages, so its boundary is useful but not absolute. Deleting your original post may reduce future exposure without removing every copy already received. A cloud sharing link can also outlive the project that required it. Review whether access is named, restricted to an organisation or open to anyone with the link, and whether the permission allows viewing, commenting or editing. The right setting depends on the task. Publicly sharing a finished learning resource may be intentional; putting a participant contact list beside it is a separate decision with different consequences.

Sources: Google Drive: Share files and choose permissions ↗ · W3C: Privacy Principles ↗

3. Cookies and private browsing have limited jobs

A cookie is a small piece of information a website can ask a browser to store and send with later relevant requests. Cookies can support useful functions such as remembering a session or preferences; some also support tracking. Therefore, “cookie” is not another word for a virus, and deleting cookies is not a complete privacy plan. Private browsing mainly changes what the browser retains locally after the private session ends. In Firefox, downloads and bookmarks remain unless removed, and private browsing does not make you anonymous to websites or your network provider. Signing into an account still identifies you to that service. A network operator may observe connection information even when HTTPS protects page contents in transit. Match a tool to the risk it addresses instead of treating one mode as universal invisibility.

Sources: MDN: Using HTTP cookies ↗ · Mozilla: Common myths about private browsing ↗

4. Worked scenario: a reading-club registration form

A student team designs a fictional reading-club form asking for name, preferred session, phone number, date of birth, full home address and identity-document scan. The activity only needs to allocate a session and communicate changes. The team removes the document scan and home address, considers whether a preferred name is enough, and chooses an appropriate minimal contact route. If an age-related requirement genuinely matters, they ask only the information needed to establish that requirement rather than collecting a full biography. They explain who will receive the data, its purpose and when the list will be reviewed or deleted. Attendance statistics can often be reported as totals without publishing names and phone numbers. This is data minimisation: first justify the need, then collect, instead of collecting everything because a form makes it easy.

Follow information through its life

  1. CollectWhat is needed for this task?
  2. UseWho needs to see or edit it?
  3. ShareCan a smaller audience or an anonymous total serve the purpose?
  4. ReviewDoes this access or copy still need to exist?
A privacy review asks about purpose, audience and time together. Deleting an original does not necessarily remove copies already received.

Sources: W3C: Privacy Principles ↗

5. Worked scenario: a helpful screenshot reveals too much

Dev wants help with a spreadsheet error and prepares a screenshot for a public discussion group. The formula is visible, but so are a classmate's phone number, a private browser tab and an account notification. Instead of posting the original, he creates a small example with invented names and numbers that reproduces the error. This usually explains the problem more clearly while exposing less. If a photo of an activity includes other people, discuss the intended audience and ask permission where appropriate before sharing; agreeing to attend does not automatically mean agreeing to public promotion. Check the background, visible badges, location clues and file information as well as the main subject. The goal is not cosmetic blurring alone: make sure the final shared file no longer contains the details you intended to remove.

Sources: W3C: Privacy Principles ↗ · Google Drive: Share files and choose permissions ↗

6. Review access through the life of the task

Review privacy at collection, use, sharing and closure. For an app permission, ask what feature needs it and whether a narrower option exists. A one-time location request for directions differs from continuous location access unrelated to the task. Review connected apps and shared folders periodically, remove unnecessary access and close accounts you no longer need through the provider's process. First preserve anything you need and understand what closure removes; account deletion is not a promise that every recipient's copy disappears. When using a shared computer, sign out, close the session and remove personal downloads appropriately. If information has been exposed, limit further sharing, change access where possible and ask the relevant service for help. Avoid publicly reposting sensitive evidence to demonstrate the exposure, because that can multiply the original problem.

Sources: W3C: Privacy Principles ↗ · Mozilla: Common myths about private browsing ↗ · Google Drive: Share files and choose permissions ↗

PUT IT INTO PRACTICE

Reduce the footprint of a fictional activity

  1. Copy the fictional reading-club fields onto paper. Next to each, write the exact activity purpose it serves. Mark fields with no clear purpose for removal.
  2. Design a smaller form and a plain-language explanation of who uses the answers. Decide which organisers need access and whether they need to edit.
  3. Plan an attendance summary for a public page. Replace individual contact details with suitable totals, and set a review point for the original list.
  4. Solution reasoning: a session choice helps scheduling, while an identity scan usually does not help this fictional activity. Restricted access and a deletion review reduce exposure. Totals can answer the reporting question without publishing everyone’s identity.

Check your understanding

Can ordinary details become identifying when combined?

Yes. A uniform, repeated location and timetable can reveal a routine even when no single field states a home address.

Does deleting your post erase every copy?

No. Recipients may already have copies or screenshots. Deletion can reduce continued access without reversing every previous disclosure.

Are all cookies harmful?

No. Some maintain useful session state or preferences. Judge their purpose and controls rather than treating the name as proof of harm.

Does private browsing make a signed-in user anonymous?

No. Signing in identifies the account to the service. Private mode mainly limits certain local browser records and does not erase downloaded files.

Why remove an identity scan from the reading-club form?

The fictional task needs session allocation and contact, not detailed identity proof. Collecting unnecessary sensitive material adds exposure without serving that purpose.

Why reproduce a problem with invented data?

It preserves the mechanism needed for help while removing unrelated personal details. A small example can also make the error easier to understand.

Keep exploring

How computers and files work

A phone and a school computer both process instructions, keep information and exchange files. Understand these jobs so you can organise assignments, prepare for weak connectivity and recover from ordinary mistakes.

Learn more →

Internet, web and search: finding evidence

A result can look convincing and still answer the wrong question. Learn how pages load, how to read an address, and how to turn a broad search into a checked answer.

Learn more →

Passwords, passkeys and account safety

Protecting an account involves more than choosing a complicated word. Understand sign-in, second factors, device access and recovery so a lost phone or leaked password does not become a chain of losses.

Learn more →