B6.2 Personal Data, Private Data, and Metadata
Learn how to separate everyday personal information from private information, and understand why metadata can reveal context even when the main content looks safe.
Lesson Progress
Personal Data, Private Data, and Metadata
High School Beginner • B6: Digital Identity and Privacy • Lesson 2 of 7
Readiness Check
Before You Start
0/3 ready
Professional Hook
Defenders Think About Data Sensitivity
Cybersecurity teams do not protect every piece of information the exact same way. A public project title, a club role, a private message, a password reset code, and a photo timestamp all have different risk levels. The defender mindset is to classify the data before deciding how it should be stored, shared, or protected.
Learning Objective
Explain the difference between personal data, private data, and metadata.
Learning Objective
Identify hidden context in fake screenshots, files, and profile examples.
Learning Objective
Apply data minimization before sharing school, club, or portfolio content.
Why This Matters
Small Details Can Combine Into Bigger Clues
A single detail may not seem serious by itself. But a file name, a timestamp, a school logo, a profile bio, and a background calendar notification can combine into a bigger picture. Safer sharing means checking the main content and the surrounding context before making information public.
Visual Diagram
Data Classification Ladder
Not every piece of information has the same risk. Cyber defenders sort information by sensitivity so they can decide what should be public, limited, private, or removed before sharing.
Public or low-risk data
General project topic, school-safe club role, public portfolio title, or broad interest that is intentionally shared.
Personal data
Username, profile bio, activity history, school-related account name, or information that can connect content to a person.
Private data
Password, exact schedule, address, phone number, private documents, personal messages, account recovery details, or family information.
Metadata
Timestamp, file author, edit history, location tag, device name, image details, file path, or sharing status that can reveal context.
Core Concept
Data Has Context
Personal data connects information to a person. Private data needs stronger protection because it could create direct safety, account, or identity risk. Metadata may not be the main content, but it can reveal when, where, how, by whom, or with what settings something was created or shared.
Key Vocabulary
Terms for Data Privacy Thinking
Personal data
Information connected to a person, such as a name, username, school role, account activity, interests, or profile details.
Private data
Information that should be protected more carefully, such as passwords, home address, exact location, private messages, personal documents, or sensitive account details.
Metadata
Data about data, such as timestamps, file names, device clues, location tags, author names, sharing settings, or document history.
Sensitive information
Information that could create safety, privacy, identity, reputation, or security risk if exposed to the wrong audience.
Data minimization
The habit of sharing only what is needed for the purpose and removing details that do not need to be public.
Access setting
A permission choice that controls who can view, edit, comment on, download, or share a file or account item.
Technical Breakdown
Metadata Inspector Board
Metadata often sits around the main content. Students do not need to investigate real files here. This fake board shows the kind of context defenders think about before information is shared.
Item type
Photo upload
Visible content
The image itself
Possible hidden context
Possible date, device, location tag, file name, or platform history depending on settings.
Item type
Shared document
Visible content
The document text
Possible hidden context
Author name, edit history, comments, sharing permission, file owner, or previous title.
Item type
Calendar screenshot
Visible content
One event or meeting title
Possible hidden context
Other schedule details, school timing, names, reminders, and private commitments around the event.
Item type
Profile page
Visible content
Bio, projects, and links
Possible hidden context
Cross-account username patterns, public contact methods, tags, linked files, or audience settings.
Fake Dashboard
Safe Sharing Review Panel
This dashboard is fictional. It shows how a student can think about file names, access settings, and private context before sharing.
club-poster-final.pdf
Anyone with link can view
Review before public sharing
scholarship-draft-notes.docx
Private to owner
Keep private
portfolio-project-summary.pdf
Public portfolio folder
Acceptable after teacher review
team-calendar-screenshot.png
Ready to post
Do not post until private schedule details are removed
Fake Dashboard
Fake Data Exposure Review Dashboard
Training dashboard using fictional examples to practice classifying data before sharing.
Public-ready items
3
General project titles and teacher-reviewed summaries.
Needs privacy review
5
Screenshots, file access settings, and document history.
Do not share
4
Recovery codes, private messages, exact schedule, and personal contact details.
Fake SOC Alert
Screenshot Contains Extra Private Context
Source: Fake Privacy Review Training • Time: 10:06 AM
Fake Log Panel
Fake Metadata Review Log
10:02:11 FILE_CHECK item='portfolio-summary.pdf' author='student display name' review='acceptable after teacher review' 10:03:22 SCREENSHOT_CHECK item='dashboard-image.png' finding='calendar notification visible' risk='medium' 10:04:18 SHARE_CHECK item='club-notes.docx' access='anyone-with-link' review='needed' 10:05:30 IMAGE_CHECK item='team-photo.png' finding='location tag disabled' risk='low' 10:06:44 PRIVATE_DATA_CHECK finding='account recovery code in draft notes' action='do not share' 10:07:19 SAFE_ACTION recommendation='remove private details, narrow file access, use fake data for public examples'
Training note: this is fake data for defensive analysis practice only.
Analyze the Evidence
What Should Be Removed Before Sharing?
What is the safest sharing decision?
Common Mistakes
Mistakes That Expose More Data Than Intended
Safe Defensive Lab
Classify a Fake Sharing Situation
Fake Sharing Request
Public Portfolio Update
A student wants to upload a project summary, a dashboard screenshot, a team photo, and draft notes. The goal is to show learning, but the files include a mixture of public-ready, personal, private, and metadata-heavy details.
Defensive Review Steps
- Classify each item as public, personal, private, or metadata-sensitive.
- Remove exact schedules, personal contact details, recovery details, and private messages.
- Check file access settings before sharing links.
- Use fake data for dashboards, examples, and screenshots.
- Ask a trusted adult, teacher, or school technology staff member if the exposure seems serious.
Scenario Decision Lab
A Friend Wants You to Post a Club Screenshot
A friend sends you a screenshot from a club planning document and asks you to post it to promote an event. The event title is fine, but the screenshot also shows student names, meeting times, and a private document link.
Defender Habits
Data and Metadata Checklist
Check Your Understanding
B6.2 Mini Quiz: Data and Metadata
Choose your answers first. Explanations appear only after submission.
1. What is metadata?
2. Which example is most likely private data?
3. Why can a screenshot be risky to share?
4. What does data minimization mean?
5. A student accidentally makes a private school document public. What is the safest next step?
Portfolio Prompt
Portfolio Prompt
Write a short data privacy review for a fake student who wants to publish a project page. Identify one piece of public-ready data, one piece of personal data, one piece of private data, and one metadata clue that should be reviewed before publishing.
Key Takeaways
What You Should Remember
Navigation