High School BeginnerModule B6Lesson 7 of 7

B6.7 Privacy Review Lab

Apply the full Module B6 privacy workflow by reviewing fake account settings, digital footprint clues, permissions, audiences, and shared files before writing a clear defensive recommendation.

Lesson Progress

Privacy Review Lab

High School BeginnerB6: Digital Identity and Privacy • Lesson 7 of 7

100% complete

Readiness Check

Before You Start

0/3 ready

Professional Hook

Privacy Reviews Turn Information Into Action

Defenders do more than notice a risky setting. They collect evidence, compare it with the approved purpose, prioritize the greatest risk, choose a mitigation, and document the reason. This lab combines the main skills from Module B6 into one safe fictional case.

Safety reminder: do not review real classmates, private accounts, or suspicious services. Use fake examples only and involve trusted adults or school staff when a real privacy situation feels serious or unsafe.

Learning Objective

Review a complete set of fake privacy evidence using a repeatable workflow.

Learning Objective

Prioritize issues based on sensitivity, audience, purpose, and possible impact.

Learning Objective

Write a clear defensive recommendation that reduces exposure without using real private data.

Why This Matters

One Small Setting Can Affect the Entire Privacy Picture

A private account can still have public posts. A safe profile can still have broad app permissions. A strong project can still reveal private contact details. A complete review connects these separate clues so the safest action addresses the whole situation instead of only one visible symptom.

Visual Diagram

The Privacy Review Workflow

A good privacy review follows a repeatable process. Students identify what is exposed, evaluate the risk, reduce unnecessary access, and document the decision using fake evidence only.

1

Discover

List the account settings, public details, permissions, tags, shared files, and audiences that need review.

2

Evaluate

Compare each item with its purpose, sensitivity, audience, and possible future impact.

3

Reduce

Remove unnecessary data, narrow audiences, turn off unneeded permissions, and correct unsafe defaults.

4

Document

Record the evidence, decision, safer action, and reason without using real private information.

Defender rule: prioritize the settings or details that create the greatest exposure, then choose the safest action that still supports the approved purpose.

Core Concept

Evidence, Purpose, Risk, and Action Must Connect

A strong privacy conclusion explains four things: what the evidence shows, why the information or access is unnecessary, what risk it creates, and what safer action should be taken. Good reasoning is specific, calm, defensive, and supported by the fake evidence.

Key Vocabulary

Terms for Privacy Review Thinking

Privacy review

A structured check of accounts, audiences, permissions, public content, shared files, and data exposure.

Exposure

The amount of information visible or available to people, systems, or audiences that may not need it.

Privacy risk

The chance that information could be misunderstood, copied, shared too widely, misused, or connected to other details.

Mitigation

A safer action that reduces risk, such as limiting an audience, removing a permission, or deleting unnecessary information.

Evidence

The fake settings, logs, alerts, profile details, or sharing records used to support a defensive conclusion.

Review cycle

A repeated schedule for checking privacy settings, old content, permissions, and shared access.

Technical Breakdown

Privacy Risk Priority Board

Not every issue has the same impact. A strong review prioritizes exposure involving private data, routines, locations, broad access, and future consequences.

High priority

Review question

Does the issue reveal private contact information, exact routines, locations, IDs, or unsafe access?

Defensive action

Reduce exposure immediately and involve trusted help when the situation is serious.

Medium priority

Review question

Could the setting, permission, tag, or old link expose more information than the task requires?

Defensive action

Narrow the audience, remove unnecessary access, and review similar settings.

Low priority

Review question

Is the issue mainly about appearance, organization, or a preference with little privacy impact?

Defensive action

Document it, but handle higher-risk exposure first.

Positive item

Review question

Does the content safely show useful skills, accomplishments, or school-approved work?

Defensive action

Keep it accurate, remove private details, and use it as a positive professional artifact.

Fake Dashboard

Privacy Case Review Panel

This fictional case combines settings, permissions, profile details, tags, and shared files into one defensive review.

Fake Data

Public profile biography

Includes school, exact practice schedule, and personal phone number

Remove routine and private contact details. Keep only information that supports the profile’s clear purpose.

Default post audience

Set to Public

Change to an approved audience so future posts do not automatically reach more people than intended.

Photo permission

A study app can access the full photo library

Limit access to selected photos or deny the permission if the feature does not need it.

Old shared folder

Anyone with the link can still open completed project files

Restrict access and remove unnecessary viewers after confirming school retention requirements.

Tagged team photo

Shows uniforms, a location sign, and several students

Review consent, audience, location clues, and tagging controls before keeping or sharing it.

Fake Dashboard

Fake Privacy Case Dashboard

Training dashboard combining fictional profile, permission, audience, tag, and shared-file evidence.

Evidence items

10

Profile details, permissions, audiences, tags, logs, and shared files.

High priority

3

Exact routine, private contact details, and broad file access need attention.

Positive items

2

School-approved project and club work can remain after privacy review.

Fake SOC Alert

Multiple Privacy Exposures Detected

Source: Fake Privacy Review Lab • Time: 2:18 PM

High Severity
A fictional student profile exposes a personal phone number and exact practice schedule. New posts default to Public, and a completed project folder remains open to anyone with the link.
Defensive recommendation: Remove private contact and routine details, change the default audience, restrict the old folder, and review related posts and permissions.

Fake Log Panel

Fake Privacy Review Evidence Log

training-log-viewer.log
14:09:02 PROFILE_FIELD field='personal_phone' visibility='public' priority='high'
14:09:51 PROFILE_FIELD field='practice_schedule' visibility='public' priority='high'
14:11:04 POST_DEFAULT audience='public' review='narrow to approved audience'
14:12:26 APP_PERMISSION permission='full_photo_library' feature='study_timer' review='not justified'
14:14:17 SHARED_FOLDER access='anyone_with_link' task_status='complete' priority='high'
14:16:08 POSITIVE_ARTIFACT type='school_project' privacy='reviewed' status='keep'
14:18:42 SAFE_ACTION recommendation='remove private details, reduce audiences, limit permissions, document changes'

Training note: this is fake data for defensive analysis practice only.

Analyze the Evidence

Which Action Should Happen First?

A fictional public profile includes a personal phone number and exact weekly practice schedule.
The default audience for new posts is Public.
A completed project folder allows anyone with the link to open it.
A school-approved project page contains no private information.

What is the strongest first priority?

Common Mistakes

Mistakes That Weaken a Privacy Review

Changing one privacy setting and assuming every other account, post, message, tag, file, and permission is protected.
Making decisions without comparing the setting to the real purpose.
Treating every public detail as equally risky instead of prioritizing by sensitivity and impact.
Deleting school-related information without checking teacher or school requirements.
Writing reports that include real passwords, private messages, addresses, phone numbers, or student records.
Handling serious harassment, impersonation, threats, or privacy exposure alone instead of involving trusted adults or school staff.

Safe Defensive Lab

Complete the Fictional Privacy Case

Fake Case File

StudentHub Account Review

A fictional student uses a private account with public post defaults, a detailed profile biography, open location sharing, an old group folder, broad photo permissions, several tags, and a strong school project portfolio.

Lab Instructions

  1. List each evidence item and its current audience or access.
  2. Classify the item as high, medium, low, or positive.
  3. Explain the purpose and why the current exposure is or is not necessary.
  4. Recommend one specific defensive action for each risky item.
  5. Write a final three-sentence privacy summary.

Scenario Decision Lab

A Serious Privacy Issue Appears During the Review

While reviewing the fictional case, the student receives repeated unwanted messages that mention the student’s school routine and exact practice location.

Defender Habits

Privacy Review Lab Checklist

Check Your Understanding

B6.7 Mini Quiz: Privacy Review Lab

Choose your answers first. Explanations appear only after submission.

1. What should happen first in a privacy review?

2. Which issue should usually receive the highest priority?

3. What is the best example of mitigation?

4. Why should privacy-review decisions be documented?

5. What should a student do when a privacy issue involves serious harassment or threats?

Portfolio Prompt

Portfolio Prompt

Write a one-page fake privacy review report for the fictional StudentHub case. Include an evidence summary, risk priorities, recommended mitigations, positive items to keep, and a short review schedule.

Use fake names, fake settings, and fake evidence only.
Explain why each recommendation matches the evidence and purpose.
End with a monthly or quarterly privacy-review cycle.

Key Takeaways

What You Should Remember

1.A complete privacy review connects settings, audiences, permissions, digital footprints, and shared access.
2.High-priority risks often involve private contact details, exact routines, locations, broad audiences, or open files.
3.Strong recommendations explain the evidence, purpose, risk, action, and reason.
4.Positive school-safe work can remain after unnecessary private details are removed.
5.Serious privacy issues require platform safety tools and trusted help, not retaliation or private investigation.

Navigation

Complete Module B6