Teacher Pack

Everything you need for a teaching unit on data protection & the GDPR — worksheets, class test, homework, parent letter and curriculum mapping. Free to use under CC BY 4.0 with attribution to “Webagentur Hochmeir e.U. (webhoch.com)”.

📚 Lower & upper secondary · Years 8–11 ⏱ Double lesson 90 min · Weekly module 3 × 50 min · 5-week project 🍎 Fully printable (Ctrl/Cmd + P)

How do I use this pack?

The teacher pack complements the main page in teacher mode with everything you need to print. It is built so that you can print it once and reuse it for years. The topic is data protection & the GDPR as part of media and digital literacy — recommended for lower and upper secondary (Years 8–11).

Recommended sequence

  1. Preparation: First read through the main page in teacher mode. For each chapter it gives you extended learning goals, timing, discussion guides and quiz answers.
  2. Test the live demo: On the main page, open Chapter 3 “What does this page know about you?” on the projector. The demo reads only locally and sends nothing — an ideal “aha” opener.
  3. Print the material: Print the worksheets that follow (ideally one per student minus one, with one held in reserve). Print the parent letter as a class set.
  4. Assessment: Optional class test at the end of the unit. Grade using the included rubric.

What's included?

A note on the legal position

The content is general awareness and media education — not legal advice. GDPR articles are deliberately simplified; when in doubt, point students to the official texts of the relevant data protection authority. For practical exercises the rule is: students enter no real personal data in live activities.

Printing tips

Worksheets

Each worksheet suits about 15–25 minutes of individual or pair work. The answer key is in a tinted box directly underneath — cut it off before printing the class set, or print double-sided (student side at the front, answer key at the back — do not hand to students).

Worksheet 1: What data does my phone reveal? Name: ______________________ Class: ______________________ Date: ______________________

Worksheet 1 — What data does my phone reveal?

1. Visible data or metadata? (4 points)

Classify each item. Write “V” for visible data (deliberately provided) or “M” for metadata (arises along the way):

  • ☐ Your profile name in an app  → ____
  • ☐ The IP address of your phone  → ____
  • ☐ The time and place a photo was taken  → ____
  • ☐ The text of a message you type  → ____
  • ☐ Which phone model you use  → ____
  • ☐ How long you keep an app open  → ____

2. Trace hunt (3 points)

Name 3 pieces of metadata that arise just from opening a website — without entering anything there:

3. What does a week of location reveal? (3 points)

Someone has only your phone's locations for a whole week — not a single message. What could this person work out about you? Name at least 3 things:

4. Fingerprint without a cookie (2 points)

Explain in 1–2 sentences how a website can recognise you again without storing a cookie:

5. Permission check (2 points)

A flashlight app wants access to your location and your contacts. What do you do — and why?

Total points: ___ / 14

🔑 Answer key for teachers — Worksheet 1

1. Profile name → V · IP address → M · Time/place of a photo → M · Message text → V · Phone model → M · App usage time → M. (Visible data is entered deliberately; metadata arises along the way.)

2. Accept 1 pt each: IP address (rough location), browser/operating system (user-agent), screen size, time zone, language setting, referrer (where you came from), time/dwell duration, device class (phone/tablet/PC).

3. Accepted: home (always at the same place at night), school/workplace (on weekdays), daily rhythm, hobbies/clubs (regular places), circle of friends (who is often at the same place), doctor/authority visits. Core point: metadata often reveals more than the content.

4. Through fingerprinting: the site combines many technical characteristics (browser, screen size, fonts, time zone, language) into a near-unique “fingerprint” — even without a stored cookie.

5. Deny access. Reasoning: a flashlight needs neither location nor contacts; such permissions usually serve to collect and pass on data (data minimisation — grant only what the app genuinely needs to function).

Worksheet 2: Decoding a cookie banner Name: ______________________ Class: ______________________ Date: ______________________

Worksheet 2 — Decoding a cookie banner

🍪 “We value your privacy”
“This website uses cookies and similar technologies to improve your experience, personalise content and measure advertising. By selecting Accept all you consent to processing by us and 47 partners.”
[ Accept all ]    [ Only necessary ]

1. Plain language (3 points)

Translate the marketing language into honest words:

“Improve your experience” often means:

“47 partners” are:

Why is the “Accept all” button more colourful?

2. The technical term (2 points)

What do you call the design tricks meant to push you into clicking “Accept all”?

3. First-party vs. third-party (4 points)

Explain the difference and give one example of each:

First-party cookie:

Third-party cookie:

4. Your decision (2 points)

Which button do you choose on this banner — and which right stands behind it?

5. A legal question (3 points)

A banner has a pre-ticked box “I agree to advertising”. Is this consent valid? Justify your answer:

Total points: ___ / 14

🔑 Answer key — Worksheet 2

1. “Improve your experience” → usually: personalise advertising / track behaviour. “47 partners” → external companies (advertising and analytics networks) who want to read along. Button more colourful → to lure you into accepting; the simpler choice is visually hidden.

2. Dark patterns (manipulative design patterns). Also accepted: “nudging”, “manipulative design”.

3. First-party cookie: set by the visited site itself, usually useful (e.g. remembering your login/shopping cart). Third-party cookie: set by an external company (e.g. an ad network), tracking you across sites (e.g. an advertising tracker that follows you across many websites).

4. “Only necessary”. The right behind it: consent must be freely given; necessary cookies need no consent anyway, and “Reject” must be just as easy as “Accept”.

5. Not valid. GDPR consent must be given actively (Art. 4/7 GDPR); pre-ticked boxes are ineffective (CJEU “Planet49”). Full marks for stating “active consent required” + a reference to the ruling/the GDPR.

Worksheet 3: Matching the GDPR rights Name: ______________________ Class: ______________________ Date: ______________________

Worksheet 3 — Matching the GDPR rights

1. Connect each right to its description (5 points)

Match each right to the correct description (write the letter):

1) Access (Art. 15) → ____A) Take your data with you in a common format
2) Erasure (Art. 17) → ____B) Ask: “What data do you hold about me?”
3) Rectification (Art. 16) → ____C) Object to the use for advertising at any time
4) Objection (Art. 21) → ____D) Have incorrect details corrected
5) Data portability (Art. 20) → ____E) “Right to be forgotten” — have data deleted

2. Identify the legal basis (3 points)

Every processing of data needs a reason (Art. 6 GDPR). Match each one — “consent”, “contract” or “legal obligation”:

  • A shop stores your delivery address to send the parcel →
  • A site wants to set advertising cookies →
  • A company must keep invoices for 7 years →

3. Write a sample request (3 points)

Draft a short, polite access request under Art. 15 GDPR to a made-up company:

4. Where to go if they ignore you? (2 points)

A company does not respond to your request at all. What can you do? Name 2 steps:

Total points: ___ / 13

🔑 Answer key — Worksheet 3

1. 1→B · 2→E · 3→D · 4→C · 5→A.

2. Delivery address → contract (Art. 6(1)(b)). Advertising cookies → consent (Art. 6(1)(a)). Keeping invoices → legal obligation (Art. 6(1)(c)).

3. Accepted: a polite, clear request referring to Art. 15. Example: “Dear Sir or Madam, under Art. 15 GDPR I hereby request access to all personal data you hold about me, together with a copy of it. Kind regards, …”. Full marks: reference to Art. 15 + polite tone + a concrete request for a copy.

4. 1) Remind the company's data protection officer in writing (deadline: 1 month). 2) Lodge a complaint with the competent data protection supervisory authority (in Germany the state data protection authority, in Austria the Data Protection Authority) — free of charge. Bonus: an additional right of action / damages under Art. 82.

Worksheet 4: Data traces & data minimisation Name: ______________________ Class: ______________________ Date: ______________________

Worksheet 4 — Data traces & data minimisation

1. Define the terms (4 points)

Briefly explain what these terms mean:

Data minimisation:

Tracking:

Profiling:

End-to-end encryption:

2. Tracker profile (3 points)

You look at a pair of shoes once — and for days afterwards you see shoe adverts. Explain in 2–3 sentences how this works technically:

3. Order the protective measures (4 points)

Name 4 concrete steps with which you shrink your data trail:

4. Case study: fitness app (3 points)

A free fitness app measures your running routes and sells the movement data to advertising companies. What risks do you see? What would be a better alternative?

5. Discussion: “I have nothing to hide” (2 points)

Many people say: “I don't care about data protection, I have nothing to hide.” Write a good counter-argument:

Total points: ___ / 16

🔑 Answer key — Worksheet 4

1. Data minimisation: collect/store only as little data as necessary. Tracking: following behaviour across websites/apps, usually for advertising. Profiling: automatically evaluating data to predict preferences/behaviour. End-to-end encryption: only sender and recipient can decrypt — not even the provider in between.

2. When you look at the shoes, an ad network sets a (third-party) cookie or builds a fingerprint. On other sites the same network recognises you again and serves matching adverts — often via a real-time auction (real-time bidding). Bonus: mention of a tracking pixel / a profile.

3. Accept 1 pt each: choose “Only necessary” on cookie banners; install a tracker blocker; turn on browser tracking protection; block third-party cookies; restrict app permissions; turn off the advertising ID on the phone; fill in mandatory fields only; pseudonyms/disposable addresses; delete old accounts; messenger with E2E encryption.

4. Risks: a movement profile reveals home/work/habits; passing data to third parties is often irreversible; in a data breach it becomes public; re-identification despite being “anonymous”. Alternative: an app without tracking / local storage / a paid app that does not sell data / reduce location accuracy. Full marks: 2 risks + 1 sensible alternative.

5. Accepted: any coherent argument. Examples: privacy ≠ secrecy (drawing the curtains at home is normal too); data can be taken out of context or misused in leaks; a power imbalance — whoever knows everything about you can influence you (advertising, prices, manipulation); it is also about other people's data (friends, family). Data protection means control, not hiding.

Class test — final assessment

Duration: 45 min · Points: 30 · Grade: per rubric below

The test does not fit into a 90-minute double lesson — recommended as its own lesson at the end of the weekly module (3 × 50 min) or as the close of the 5-week project.

Understanding data protection — final test Name: ______________________ Class: ______________________ Date: ______________________ Points: ___ / 30

Part A: Multiple choice 1 pt each · 6 pts

1. What describes data protection best?

  • A program that protects the computer from viruses
  • The right to decide for yourself who uses which data about you
  • Keeping everything secret and doing nothing online any more
  • An obligation to always use a password

2. Which of these is an example of metadata?

  • The subject visible in a photo
  • The text of a message you write
  • The time and place a photo was taken
  • Your self-chosen profile name

3. How can a website recognise you again WITHOUT setting a cookie?

  • Not at all — without a cookie it is impossible
  • It simply asks you for your name
  • Through fingerprinting (combining many device characteristics)
  • Through your phone number

4. What is a third-party cookie?

  • A cookie of the site you are on that remembers your login
  • A cookie of an external company that tracks you across sites
  • A necessary cookie for the shopping cart
  • A biscuit you can eat

5. How long does a company usually have to answer an access request (Art. 15)?

  • Within 24 hours
  • Within one month
  • Within one year
  • Not at all — it is voluntary

6. What does “data minimisation” mean?

  • Compressing data as small as possible to save space
  • Collecting and storing only as little data as necessary
  • Deleting all data regularly
  • Spreading data across several servers

Part B: Short answer 2 pts each · 8 pts

7. Explain in 1–2 sentences the difference between visible data and metadata:

8. Name three rights the GDPR gives you:

9. What is a “dark pattern” in a cookie banner? Give an example:

10. Why does deleting cookies offer little protection against fingerprinting?

Part C: Application 10 pts

11. Write a short, polite access request under Art. 15 GDPR to a made-up company (4 pts):

12. A free app wants access to contacts, location, microphone and photos when installing. Which permissions would you allow, which not? Justify your decision (3 pts):

13. Using an example, explain the difference between encryption “in transit” (HTTPS) and “at rest” (stored) (3 pts):

Part D: Reflection 6 pts

14. Discuss in 5–8 sentences: “I don't care about data protection — I have nothing to hide.” Argue FOR and AGAINST this statement, then take a position of your own.

🔑 Answer key for teachers — Class test

Part A: 1b · 2c · 3c · 4b · 5b · 6b

Part B:

7. Visible data is entered deliberately (name, email, photo); metadata arises along the way (IP, location, time, device) and often reveals more.

8. Three of: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection (Art. 21), complaint to the supervisory authority.

9. A manipulative design that pushes you towards a particular (privacy-unfriendly) choice. Example: “Accept all” large and colourful, “Only necessary” small/grey/hidden.

10. Because fingerprinting does not rely on stored cookies but on device characteristics (browser, screen, fonts, time zone). These stay the same even if you delete all cookies.

Part C:

11. Full marks: polite salutation + reference to Art. 15 + a clear request for access and a copy + a sign-off. Example: “Dear Sir or Madam, under Art. 15 GDPR I request access to all data stored about me, together with a copy. Kind regards, …”. Partial marks for each component present.

12. Ideal answer: grant permissions only if the app genuinely needs them for its purpose (data minimisation). Example: a photo-editing app needs photos (yes), but hardly contacts/microphone (no); location at most “while using”. Assessment: the reasoning based on purpose limitation counts, not the exact selection.

13. “In transit” protects the transmission on the way (HTTPS/TLS — the padlock in the browser) so no one can read along. “At rest” protects stored data on servers/disks (e.g. AES). Example: the message is sent encrypted (in transit) AND stored encrypted on the server (at rest). Full marks: both states correct + one example.

Part D:

14. Full marks: a nuanced discussion with pro and con arguments and a reasoned position of one's own. Possible arguments — pro “don't care”: I do nothing forbidden, convenience. Con: privacy is not secrecy (the curtains/letters analogy); data can be taken out of context or misused in leaks; a power imbalance and manipulation (advertising, prices); it is also about other people's data. The depth of the argument is graded, not the position.

Grading rubric

PointsGrade (DE/AT)Grade (CH)Assessment
27 – 301 / Very good5.5 – 6.0Complete understanding, independent reflection, precise terminology.
23 – 262 / Good4.5 – 5.0Confident knowledge, minor gaps, reflection present.
18 – 223 / Satisfactory3.5 – 4.0Basics understood, reflection superficial.
14 – 174 / Sufficient3.0 – 3.4Key terms present, many gaps in application.
0 – 135 / Insufficient< 3.0Basic terms not understood — extra support recommended.

Grades follow the DE/AT 1–5 and CH 1–6 systems; map the point bands to your own grading scale as needed.

Weighting recommendation

Homework collection — 3 difficulty tiers

3 tasks per topic: Easy Medium Challenging. Answer hints are in expandable details directly underneath (collapsible on screen, always open when printed).

Topic 1 — What data does my phone reveal?

Task HW 1.1 Easy

List 5 apps on your phone. Check in the settings which permissions each one has (location, camera, contacts, microphone). Note which ones look unnecessary to you.

🔑 Answer hint

Accepted: a documented list with permissions. Expected insight: at least one app has more rights than it needs for its purpose (e.g. a game with microphone access).

Task HW 1.2 Medium

On the main page, open the live demo “What does this page know about you?”. Note 5 characteristics the page knew about your device, and for each one write what it reveals.

🔑 Answer hint

Accepted: 5 characteristics with an explanation (browser/system → what you browse with; language → country; screen → fingerprint building block; time zone → rough location; device class → phone/PC). Bonus: the insight that nothing was sent.

Task HW 1.3 Challenging

Research what a “movement profile” is. Write a short analysis (½ A4 page): what can be worked out about a person from just one week of location data — and why is that problematic?

🔑 Answer hint

Full marks: concrete examples (home, workplace/school, daily rhythm, hobbies, social contacts) + reflection on the risks of misuse (stalking, profiling, re-identification despite “anonymous” data).

Topic 2 — Cookies & tracking

Task HW 2.1 Easy

Next time you browse, watch out for 3 cookie banners. For each, note: was there a “Reject” or “Only necessary” button? Was it just as visible as “Accept”?

🔑 Answer hint

Accepted: a documented observation. Expected: often “Accept” is designed to stand out more (a dark pattern). Bonus: names the pattern correctly.

Task HW 2.2 Medium

Explain to a family member (e.g. a grandparent) in your own words what tracking cookies are and why “Only necessary” is often the better choice. Then write in 4–6 sentences how the conversation went.

🔑 Answer hint

Accepted: a documented conversation without jargon. Full marks: an understandable analogy (e.g. “a minder who follows you from shop to shop and notes what you look at”).

Task HW 2.3 Challenging

Research the term “real-time bidding”. Write a short explanation (½ A4 page) of how your page visit turns into advertising in milliseconds — and how many companies see your data along the way.

🔑 Answer hint

Full marks: a correct description of the real-time auction (bid request → bids → highest bidder gets the ad slot) + the insight that profile signals go to dozens/hundreds of companies (the bidstream). This explains why so many “partners” appear in the banner.

Topic 3 — Fingerprinting & recognition

Task HW 3.1 Easy

Explain in 3 sentences what fingerprinting is and why it works even without cookies.

🔑 Answer hint

Accepted: many device characteristics (browser, screen, fonts, time zone, language) are combined into a near-unique “fingerprint”; nothing is stored; deleting cookies barely helps.

Task HW 3.2 Medium

Compare two browsers of your choice (e.g. a standard browser and a privacy-friendly one). Research which anti-tracking features each one offers and contrast them in a small table.

🔑 Answer hint

Accepted: a table with features such as tracking protection, third-party cookie blocking, anti-fingerprinting, “Do Not Track”. Bonus: your own assessment of which protects better and why.

Task HW 3.3 Challenging

Discussion essay (1 A4 page): “Should fingerprinting require consent, just like a cookie?” Argue for and against, then take a position of your own.

🔑 Answer hint

Accepted: a balanced argument. Pro: the same recognition as cookies, so the same protection is needed. Con: technically hard to separate from necessary functions. A reasoned position of one's own. Bonus: a reference to the ePrivacy rules/the GDPR.

Topic 4 — Your rights (GDPR)

Task HW 4.1 Easy

Write the 6 most important GDPR rights on a sheet (large enough to display) and explain each in one short sentence.

🔑 Answer hint

Access · rectification · erasure · restriction · data portability · objection. Full marks: one understandable sentence each; poster-ready.

Task HW 4.2 Medium

Pick the privacy policy of an app or website you use. Find out: which data is collected? Who is it passed on to? Summarise it in 5–8 sentences.

🔑 Answer hint

Accepted: a documented analysis with concrete findings (e.g. “collects location and usage data”, “passes it on to advertising partner X”). Bonus: the insight into how hard such texts often are to understand.

Task HW 4.3 Challenging

Research a real GDPR fine case (e.g. against a large tech company). Write a mini report (max. 400 words): what happened, which right was violated, how high was the fine?

🔑 Answer hint

Accepted: a documented, genuinely existing case with a source. Full marks: a clearly named violation + the breached principle (e.g. missing legal basis, lack of transparency) + the size of the fine + your own assessment.

Topic 5 — Staying in control & data minimisation

Task HW 5.1 Easy

This week, put 3 of the protection tips you learned into practice (e.g. reject a banner, revoke a permission, turn off the advertising ID). Note down what you did.

🔑 Answer hint

Accepted: 3 documented measures actually carried out. Bonus: a short reflection on what was easy/hard.

Task HW 5.2 Medium

Design a poster (1 A4 page or digital) titled “5 rules for my data”. Target audience: your classmates.

🔑 Answer hint

Accepted: clearly structured, suited to the audience (no jargon), visually appealing. Full marks: 5 practical, unambiguous rules.

Task HW 5.3 Challenging

Write a short guide (1 A4 page), “Data protection for beginners”, for someone who has never thought about it — for instance a younger sibling or a grandparent. Avoid jargon or explain it.

🔑 Answer hint

Full marks: understandable, with no unexplained jargon, with concrete everyday steps and an encouraging, non-alarming stance (“control, not hiding”). Bonus: examples tailored to the audience.

Parent-letter template

You can adapt this template to your school and class. Replace the [placeholders in gold] with your own details and print the template for your class.

[Your school]
[Address]
[Date]

To the parents of class [Year X]

Subject: Teaching unit “Understanding data protection”

Dear parents,

over the coming [weeks / double lesson] your child's class will be looking at the topic of data protection & privacy. Our children leave data traces every day — while browsing, in apps and on social networks. We want to empower them to protect their data competently and self-determinedly — with no scaremongering at all, but with the guiding idea: data protection means control, not hiding.

What your child will learn:

  • What data you leave behind online — visible data and invisible metadata
  • What a website already knows about you just from being opened (with a live demo that sends nothing)
  • How cookies, tracking and fingerprinting work
  • How to see through cookie banners and “dark patterns”
  • What rights the GDPR gives you (access, erasure, objection …)
  • How to shrink your own data trail in everyday life (data minimisation)

Material and source: We use the freely available learning platform datenschutz-verstehen.webhoch.com, provided by the Austrian agency Webagentur Hochmeir e.U. under a free licence (CC BY 4.0). The content is age-appropriate for [Years 8–11].

How you can support at home:

  • Talk with your child about the cookie banners and app permissions you come across yourselves.
  • Help your child to deliberately choose “Only necessary” on cookie banners.
  • Go through the privacy settings on the family phone together (advertising ID, app tracking, permissions).
  • A reminder: provide personal data (name, address, passwords) sparingly and only where it is genuinely needed.

Important notes:

  • During the lesson, students enter no real personal data in online activities. The live demo used sends no data — it only reads locally what the browser reveals anyway.
  • The content is general media education, not legal advice.
  • If you have questions or concerns: [Your email address]

We are glad that your child is gaining this important future skill — and we appreciate your support along the way.

Kind regards,
[Your name]
[Role / class teacher]

Curriculum mapping

This unit covers core learning areas of media and digital literacy. In general, it maps to lower- and upper-secondary media-, digital- and civics-literacy curricula (≈ Years 8–11, ages 13–17). The mapping below is adaptable to the German, Austrian and Swiss education standards.

Curriculum references (general media & digital literacy; DE/AT “Digitale Grundbildung / Informatik”, CH Lehrplan 21 “Medien und Informatik”)

Subject / areaCompetence / standardWorksheet
Digital literacy / computingRecognise data traces; explain tracking and fingerprinting; secure device and browser settings1, 2, 4
Media literacySee through manipulative design patterns (dark patterns); read privacy policies critically2, 4
Civics / lawFundamental rights in the digital space; the GDPR and data-subject rights; supervisory authorities3
Ethics / religionPrivacy, self-determination and responsibility in a data-driven society4
Language / EnglishArgue and discuss; write formal texts (an access request)3, 4

Competence matrix (Bloom's taxonomy)

LevelNameExample from this unit
K1KnowledgeName terms (metadata, cookie, tracking, GDPR, fingerprinting …)
K2ComprehensionTell visible data from metadata; explain first- vs. third-party
K3ApplicationDraft an access request; check app permissions
K4AnalysisDecode a cookie banner; interpret the live demo; the fitness-app case study
K5EvaluationDevelop a position on “I have nothing to hide”
K6CreationDesign a “5 rules for my data” poster or a beginner's guide (homework 5.2/5.3)

Time allocation

VariantBreakdownRecommended for
Double lesson (90 min)All 6 chapters of the main page in excerpts, live demo, one worksheetProject day, cover lesson, taster course
Weekly module (3 × 50 min)Day 1: data traces + live demo (WS 1); Day 2: cookies + rights (WS 2, 3); Day 3: control (WS 4) + class testStandard lessons across one week
5-week project (5 × 90 min)One topic per week (data traces · cookies/tracking · fingerprinting · GDPR rights · data minimisation) with own researchIn-depth study, project work, gifted-and-talented support
Project week (5 × 4h)Days 1–4: deep dive into the topics with own research · Day 5: presentations + testThemed week, media-literacy week

Where do I connect this?