High School BeginnerModule B6Lesson 2 of 7

B6.2 Personal Data, Private Data, and Metadata

Learn how to separate everyday personal information from private information, and understand why metadata can reveal context even when the main content looks safe.

Lesson Progress

Personal Data, Private Data, and Metadata

High School BeginnerB6: Digital Identity and Privacy • Lesson 2 of 7

29% complete

Readiness Check

Before You Start

0/3 ready

Professional Hook

Defenders Think About Data Sensitivity

Cybersecurity teams do not protect every piece of information the exact same way. A public project title, a club role, a private message, a password reset code, and a photo timestamp all have different risk levels. The defender mindset is to classify the data before deciding how it should be stored, shared, or protected.

Safety reminder: never share real passwords, recovery codes, personal documents, exact location, home address, private messages, or sensitive school information in a practice activity.

Learning Objective

Explain the difference between personal data, private data, and metadata.

Learning Objective

Identify hidden context in fake screenshots, files, and profile examples.

Learning Objective

Apply data minimization before sharing school, club, or portfolio content.

Why This Matters

Small Details Can Combine Into Bigger Clues

A single detail may not seem serious by itself. But a file name, a timestamp, a school logo, a profile bio, and a background calendar notification can combine into a bigger picture. Safer sharing means checking the main content and the surrounding context before making information public.

Visual Diagram

Data Classification Ladder

Not every piece of information has the same risk. Cyber defenders sort information by sensitivity so they can decide what should be public, limited, private, or removed before sharing.

1

Public or low-risk data

General project topic, school-safe club role, public portfolio title, or broad interest that is intentionally shared.

2

Personal data

Username, profile bio, activity history, school-related account name, or information that can connect content to a person.

3

Private data

Password, exact schedule, address, phone number, private documents, personal messages, account recovery details, or family information.

4

Metadata

Timestamp, file author, edit history, location tag, device name, image details, file path, or sharing status that can reveal context.

Defender rule: before sharing, ask what the information reveals, who needs it, who could misuse it, and whether metadata or background details reveal more than intended.

Core Concept

Data Has Context

Personal data connects information to a person. Private data needs stronger protection because it could create direct safety, account, or identity risk. Metadata may not be the main content, but it can reveal when, where, how, by whom, or with what settings something was created or shared.

Key Vocabulary

Terms for Data Privacy Thinking

Personal data

Information connected to a person, such as a name, username, school role, account activity, interests, or profile details.

Private data

Information that should be protected more carefully, such as passwords, home address, exact location, private messages, personal documents, or sensitive account details.

Metadata

Data about data, such as timestamps, file names, device clues, location tags, author names, sharing settings, or document history.

Sensitive information

Information that could create safety, privacy, identity, reputation, or security risk if exposed to the wrong audience.

Data minimization

The habit of sharing only what is needed for the purpose and removing details that do not need to be public.

Access setting

A permission choice that controls who can view, edit, comment on, download, or share a file or account item.

Technical Breakdown

Metadata Inspector Board

Metadata often sits around the main content. Students do not need to investigate real files here. This fake board shows the kind of context defenders think about before information is shared.

Item type

Photo upload

Visible content

The image itself

Possible hidden context

Possible date, device, location tag, file name, or platform history depending on settings.

Item type

Shared document

Visible content

The document text

Possible hidden context

Author name, edit history, comments, sharing permission, file owner, or previous title.

Item type

Calendar screenshot

Visible content

One event or meeting title

Possible hidden context

Other schedule details, school timing, names, reminders, and private commitments around the event.

Item type

Profile page

Visible content

Bio, projects, and links

Possible hidden context

Cross-account username patterns, public contact methods, tags, linked files, or audience settings.

Fake Dashboard

Safe Sharing Review Panel

This dashboard is fictional. It shows how a student can think about file names, access settings, and private context before sharing.

Fake Data

club-poster-final.pdf

Anyone with link can view

Review before public sharing

scholarship-draft-notes.docx

Private to owner

Keep private

portfolio-project-summary.pdf

Public portfolio folder

Acceptable after teacher review

team-calendar-screenshot.png

Ready to post

Do not post until private schedule details are removed

Fake Dashboard

Fake Data Exposure Review Dashboard

Training dashboard using fictional examples to practice classifying data before sharing.

Public-ready items

3

General project titles and teacher-reviewed summaries.

Needs privacy review

5

Screenshots, file access settings, and document history.

Do not share

4

Recovery codes, private messages, exact schedule, and personal contact details.

Fake SOC Alert

Screenshot Contains Extra Private Context

Source: Fake Privacy Review Training • Time: 10:06 AM

Medium Severity
A fake student wants to post a screenshot of a project dashboard, but the browser tabs, notification banner, and file title reveal private school and schedule details.
Defensive recommendation: Crop or recreate the screenshot with fake data, remove private context, review metadata and file access settings, and ask trusted help before publishing school-related material.

Fake Log Panel

Fake Metadata Review Log

training-log-viewer.log
10:02:11 FILE_CHECK item='portfolio-summary.pdf' author='student display name' review='acceptable after teacher review'
10:03:22 SCREENSHOT_CHECK item='dashboard-image.png' finding='calendar notification visible' risk='medium'
10:04:18 SHARE_CHECK item='club-notes.docx' access='anyone-with-link' review='needed'
10:05:30 IMAGE_CHECK item='team-photo.png' finding='location tag disabled' risk='low'
10:06:44 PRIVATE_DATA_CHECK finding='account recovery code in draft notes' action='do not share'
10:07:19 SAFE_ACTION recommendation='remove private details, narrow file access, use fake data for public examples'

Training note: this is fake data for defensive analysis practice only.

Analyze the Evidence

What Should Be Removed Before Sharing?

A project screenshot shows the main dashboard clearly.
The top browser tab shows a private school document title.
A notification banner shows a meeting time and a student's first name.
The screenshot will be posted on a public portfolio page.

What is the safest sharing decision?

Common Mistakes

Mistakes That Expose More Data Than Intended

Treating metadata as harmless because it is not always obvious on the screen.
Posting screenshots without checking for names, tabs, notifications, locations, or schedule details in the background.
Sharing cloud files with broad access when only a small audience needs to view them.
Confusing personal data with private data and assuming all information needs the same protection level.
Ignoring document history, comments, file titles, and author details before sharing a file publicly.
Trying to fix a serious privacy exposure alone instead of asking trusted adult, teacher, guardian, counselor, or school technology help.

Safe Defensive Lab

Classify a Fake Sharing Situation

Fake Sharing Request

Public Portfolio Update

A student wants to upload a project summary, a dashboard screenshot, a team photo, and draft notes. The goal is to show learning, but the files include a mixture of public-ready, personal, private, and metadata-heavy details.

Defensive Review Steps

  • Classify each item as public, personal, private, or metadata-sensitive.
  • Remove exact schedules, personal contact details, recovery details, and private messages.
  • Check file access settings before sharing links.
  • Use fake data for dashboards, examples, and screenshots.
  • Ask a trusted adult, teacher, or school technology staff member if the exposure seems serious.

Scenario Decision Lab

A Friend Wants You to Post a Club Screenshot

A friend sends you a screenshot from a club planning document and asks you to post it to promote an event. The event title is fine, but the screenshot also shows student names, meeting times, and a private document link.

Defender Habits

Data and Metadata Checklist

Check Your Understanding

B6.2 Mini Quiz: Data and Metadata

Choose your answers first. Explanations appear only after submission.

1. What is metadata?

2. Which example is most likely private data?

3. Why can a screenshot be risky to share?

4. What does data minimization mean?

5. A student accidentally makes a private school document public. What is the safest next step?

Portfolio Prompt

Portfolio Prompt

Write a short data privacy review for a fake student who wants to publish a project page. Identify one piece of public-ready data, one piece of personal data, one piece of private data, and one metadata clue that should be reviewed before publishing.

Use fake examples only and do not include real private details.
Explain what should stay, what should be removed, and what should have restricted access.
Mention when a teacher, guardian, or school technology staff member should review the material.

Key Takeaways

What You Should Remember

1.Personal data connects information to a person, while private data needs stronger protection.
2.Metadata can reveal context such as time, author, location, file history, or sharing settings.
3.Screenshots and shared files can expose hidden details even when the main content looks safe.
4.Data minimization means sharing only what is needed for the audience and purpose.
5.Students should ask trusted help when private information is exposed or when a sharing decision feels unsafe.

Navigation

Continue Module B6