Year 2 · 45 minutes · Privacy
Can harmless-looking clues fit together to identify someone?
One broad clue can match many fictional people. Several precise clues together may match only one. Our mosaic counts how many supplied synthetic records fit an age range and map area. A larger matching group can reduce this kind of identification risk, but it is not a guarantee of privacy: another clue could narrow the group again.
Print the supplied fictional grid of 24 records. Explain clearly that no record describes a class member. Set the survey purpose: count people in a broad region and age band, not find one person.
Group fictional cards by a visible feature. Useful earlier investigations: f-signal Use pairs: one child chooses or points while the other traces or checks. Swap after one case. An adult records the child’s words; drawing and movement are equally valid evidence.
Australian Curriculum Version 9 · Digital Technologies: AC9TDI2P07, AC9TDI2K02. Selected aspects only. This activity contributes evidence; it does not cover the full descriptor or achievement standard. A programming descriptor is not claimed for merely moving controls. ACARA AI curriculum connection · V9 Technologies These are planning connections, not ACARA endorsement or exhaustive descriptor alignment.
Read a broad fictional age clue and mark all matches on paper.
Ask: “Does this clue name one person?”
Listen for: “No, lots of records fit.”
Add a location clue and predict whether the matching crowd grows or shrinks.
Ask: “Can adding another clue create more matches?”
Listen for: “It should keep or remove matches.”
Narrow only the age range, then reset and narrow only the map region. Record remaining candidates and retained regional usefulness.
Ask: “Which records disappeared, and why?”
Listen for: “They no longer fit the smaller window.”
Apply both precise fields and reveal a unique synthetic match.
Ask: “Were the clues still harmless when combined?”
Listen for: “Together they pointed to one record.”
Coarsen fields until several records match while the broad-region count remains possible. Write a purpose statement.
Ask: “What detail does our question actually need?”
Listen for: “An age band and region, not an exact age and address.”
Explain why a count of several matches is not a promise of anonymity.
Ask: “Could a new clue narrow it again?”
Listen for: “Yes, like another known detail.”
Harmless facts cannot identify someone.
Predict the candidate count direction when adding a precise location to a broad age clue.
Age band and location each match multiple fictional records, but their intersection can match one.
Choose coarse age and region fields for a regional survey and record both usefulness and remaining matches.
Ask learners to describe an intersection using the highlighted records. Do not accept a fixed candidate count as a universal privacy guarantee.
Use eight fictional tokens and two circles to show overlap physically before exploring numbers.
Add a third invented clue on paper and explain why a previous privacy judgement needs revision.
A minimal survey design with candidate counts and a statement of residual risk.
Never enter real class demographics, addresses or birthdays. This demonstration is not a method for identifying real people.
Generate large synthetic populations and compare uniqueness rates under different age/location coarsening policies, keeping the underlying population fixed.
| Criterion | Beginning | Secure | Extending |
|---|---|---|---|
| Combining clues | Considers each field alone | Explains that combining narrows matches | Predicts and verifies an intersection |
| Minimisation | Deletes data without considering purpose | Coarsens fields while preserving purpose | Explains residual identification risk |
Australian Curriculum Version 9 · Digital Technologies
References: AC9TDI2P07, AC9TDI2K02. Read the current source (checked 2026-09-07).
Evidence to assess: A minimal survey design with candidate counts and a statement of residual risk.
Selected aspects only. This activity contributes evidence; it does not cover the full descriptor or achievement standard. A programming descriptor is not claimed for merely moving controls. Moderate the supplied illustrative responses against your school unit and current achievement standard.
These are planning estimates to test with your class. A short session develops one supported claim; it does not compress the whole senior project.
| Stage | 45 minute focus | 60 minute investigation |
|---|---|---|
| Readiness and prediction | 0–5 | 0–5 |
| Trace the supplied example | 5–13 | 5–15 |
| Author and run cases | 13–25 | 15–35 |
| Counterexample and redesign | 25–35 | 35–45 |
| Explain and discuss | 35–42 | 45–55 |
| Export and handover | 42–45 | 55–60 |
For a longer project, use three 50-minute sessions. Session 1 (0–50): readiness, model, hypothesis and initial cases. Export a project and record the next test. Session 2 (50–100): reopen, check settings, author counterexamples and revise the design. Export the changed project and identify unresolved evidence. Session 3 (100–150): independent peer test, final artefact, individual explanation and moderation. If using two 60-minute sessions, stop at minute 60 after saving the first comparison; use 60–120 for redesign, independent test and defence.
Entry check: Group fictional cards by a visible feature. Ask the learner to demonstrate it before choosing the level of support.
Preparation: allow about 10 minutes to run the starter, print the cards and check a project can be reopened. This estimate has not yet been measured in a classroom pilot.
For young learners, show one picture or case at a time. Accept pointing, movement, a drawing or adult transcription. Read the question aloud; explain the numeric model privately to the adult. Do not assess keyboard speed or independent reading.
For one device, use a projector: one pair predicts, one operates, and the class records on paper. Swap roles after the first comparison. For individual access, support keyboard controls and a written table equivalent to each visual. Learners may explain orally or with an annotated diagram. Never require personal data, a recorded voice, or a photograph.
Mixed readiness: if the entry check is difficult, use the linked prerequisite and the first two case cards; retain the same central question. If secure, ask the learner to design an unseen test and state which explanation it could disprove.
Intersect the two sets of matching cards. Compare each clue alone with their combination.
Starting parameters: Activity clue = music, Travel clue = bus
1 fictional cards fit both clues.
| person | activity matches | travel matches | both match |
|---|---|---|---|
| Bo | True | True | True |
| Pip | True | False | False |
| Wattle | False | True | False |
| Kiki | False | False | False |
| Reef | True | False | False |
| Fern | False | False | False |
These are authored examples, not work collected from children. Assess reasoning using the lesson rubric, not whether the first prediction was correct.
Beginning: “It worked because the result looks right.” This identifies no exact case, control or measurement. Ask the learner to point to one row and say what happened.
Developing: “In the first case I recorded person: Bo; activity matches: True; travel matches: True; both match: True.” This cites evidence, but does not yet explain how the result follows from the rule. Ask the learner to trace the relevant step.
Secure: “For the first supplied case, person: Bo; activity matches: True; travel matches: True; both match: True. I can trace it using this mechanism: Intersect the two sets of matching cards. Compare each clue alone with their combination. My result supports a claim about these supplied cases. It does not establish that the same result holds outside them.” Look for an accurate trace, the actual settings and a bounded claim; accept equivalent oral or visual evidence.
Extending: The learner constructs and reruns a new case, reports whether the first explanation survives, and defends a revised design. Use this concrete challenge: Invent six fictional character cards. Find two harmless-looking clues that together identify one card. Require the original and changed evidence and this boundary: These are fictional cards; do not enter information about classmates.
Moderation: first assess independently against each lesson criterion. Compare the exact trace or artefact that led to your judgement. Resolve differences using evidence, not polished language. Keep each learner's individual explanation even when the artefact was produced in a group.