Problem and Solution Technology Task 2

Personal data is collected by companies on a scale most people do not understand.

A full IELTS Writing Task 2 answer to this question at Band 6.0, 7.0, 8.5, with a paragraph plan, the vocabulary that fits this topic, and the reasons each answer scores what it does.

The question

You should spend about 40 minutes on this task.

Personal data is collected by companies on a scale most people do not understand.

What problems result from this? What measures could be taken to protect people?

Give reasons for your answer and include any relevant examples from your own knowledge or experience.

Write at least 250 words.

How to read this question

The prompt itself contains the key: people do not understand the scale. That means consent is the mechanism that has failed, and solutions built on better consent — clearer notices, more checkboxes — are addressing the symptom. The strongest answers argue that the burden must move from the individual to the collector, which is a specific and defensible position rather than general unease about privacy.

Paragraph plan

Introduction — Paraphrase, then signpost: the problems are meaningless consent and inference from harmless-looking data; the solutions must shift responsibility away from the user.

Body 1 — Problems — nobody can read or evaluate what they agree to, and combined datasets reveal what was never disclosed.

Body 2 — Solutions — restrict collection by default, ban use beyond the stated purpose, and enforce with penalties large enough to alter behaviour.

Conclusion — Consent cannot carry this weight; the answer is to limit what may be collected, not to explain it better.

Model answers

Band 6.0 model answer

254 words

Every day companies collect enormous amounts of information about us: which websites we visit, where we go with our telephone, what we buy and even how long we look at a photograph. Most people do not understand how much information is collected, and this creates several problems.

The first problem is that people cannot give real permission. Before using an application, we must accept a document of fifty pages written in difficult legal language. Nobody reads it, everybody clicks 'accept', so this permission does not mean anything. In reality the user does not know what he agreed to.

The second problem is security. When one company keeps the personal information of millions of people in one place, this becomes a target for criminals. If there is an attack, our passwords, addresses and bank details appear on the internet, and criminals use them to steal money or to open accounts in our name.

One solution is stronger laws. Governments should say clearly which information a company can collect and forbid the collection of everything else. The fine must be very big, because if the fine is small, a big company simply pays it and continues.

Another solution is education. Schools should teach young people how to check the settings of their telephone, how to refuse cookies and why they should not share personal details with unknown websites.

In conclusion, mass collection of data destroys real consent and creates a danger of theft, but strict laws with serious fines and better education can protect ordinary users.

Why this is Band 6.0

  • Both parts are answered and the solutions relate to the problems.
  • Ideas are general — 'companies should protect data better' is not developed.
  • Cohesion is clear and mechanical.
  • Vocabulary is adequate with repetition of data, companies and people.

Band 7.0 model answer

305 words

Companies now gather personal information continuously and at a scale few users could estimate. The resulting problems are not primarily about secrecy, and the remedies that would work are correspondingly different from those usually proposed.

The central problem is that consent has become meaningless. Permission is obtained through documents that are long, legally drafted and presented at the moment a person wants to use a service, so effectively nobody reads them and refusal usually means losing access altogether. What is called agreement is therefore a formality, and building a system of rights on it protects no one.

The second problem is inference. Individually harmless records — locations visited, purchase timings, how long a page was viewed — become highly revealing when combined, allowing conclusions about health, financial difficulty, political views or relationships that the person never disclosed. Because these are derived rather than supplied, they fall outside what most people imagine themselves to have shared, and they are frequently more sensitive than anything they would have volunteered.

The most effective solution is to limit collection at source rather than to improve disclosure. If companies may gather only what a service genuinely requires, and may not retain or reuse it for unrelated purposes, the question of whether users understood the terms becomes far less critical.

This requires enforcement proportionate to revenue. Fines calculated as a percentage of global turnover change corporate behaviour; fixed penalties are absorbed as an operating cost. Individual education has a place, but expecting users to manage this through settings misplaces the responsibility onto the party with the least information and the least power.

In conclusion, the problems are consent that cannot function and inference from data that appears trivial. The remedy is to restrict what may be collected and to enforce it seriously, rather than to ask people to read more carefully.

Why this is Band 7.0

  • The essay identifies why consent has failed rather than simply noting that policies are long.
  • The inference problem — that combined data reveals what was never given — is a substantive point most answers miss.
  • Less common lexis used accurately: consent, aggregate, infer, enforcement.
  • A good range of complex structures with only minor slips.

Band 8.5 model answer

435 words

The prompt identifies the difficulty precisely: collection happens on a scale people do not understand. That matters because the entire legal architecture of privacy rests on the assumption that they do. Once consent is recognised as the thing that has broken, the choice between remedies becomes much clearer — and most of what is currently proposed can be set aside.

The first problem is that notice-and-consent cannot work under these conditions. Agreements are long, drafted by lawyers, presented at the moment of use, and offered on a take-it-or-leave-it basis by services that have no substitute. Reading them all would consume weeks a year, refusing usually means exclusion, and comprehension is not realistically possible even for the diligent. What is recorded as agreement is therefore a ritual. Any system that treats it as a genuine authorisation is not protecting people; it is documenting that they can be presumed to have accepted whatever follows.

The second problem is that the most sensitive information is never disclosed at all. It is inferred. Location traces, purchase timing, browsing patterns and interaction speeds are individually trivial, but aggregation converts them into confident conclusions about pregnancy, illness, financial distress, sexuality or political alignment. These derived findings are frequently more revealing than anything the person would have volunteered, and consent could not have covered them, because neither party knew at the time what the data would eventually yield.

What follows is that the burden has to move. Data minimisation — permitting collection only of what a service actually requires to function — removes the problem at source, since information never gathered cannot be leaked, sold or inferred from. Purpose limitation completes it: data collected for one reason may not be repurposed for another, which directly addresses the inference problem by making the secondary use itself unlawful rather than merely undisclosed.

Enforcement decides whether any of this is real. A fixed fine is a licence fee for a company earning billions, and will be treated as one; a penalty set as a share of global turnover changes the calculation in the boardroom rather than in the compliance department. This is the point most proposals miss — the objective is not to punish breaches after the fact but to make over-collection commercially irrational in advance.

Education has a modest role, but it should not be the centrepiece. Placing responsibility on individuals to manage privacy settings asks the party with the least information, the least expertise and no bargaining power to solve a problem created by the party with all three. The problems here are structural, and structural problems are not fixed by better-informed clicking.

Why this is Band 8.5

  • Argues that the consent model itself is the failure rather than its implementation, which is a precise diagnosis and dictates the solutions.
  • Develops inference as the harm that consent could never have covered, since the data was derived rather than given.
  • Justifies turnover-based penalties by explaining the incentive they change, rather than simply demanding tougher laws.
  • Lexis is precise and idiomatic: notice and consent, data minimisation, purpose limitation, inference, aggregation, externality.
  • Wide and flexible structural range including a cleft, inversion and controlled parenthesis; errors are rare and minor.

Model answers written and reviewed by The English All-in-One IELTS team. They are teaching models showing what each band looks like, not real candidate scripts.

This is a problem and solution question. The answers above show you what each band looks like when it is finished. What they cannot show you is how to get there from a blank page in forty minutes.

That is what our Writing Study Library is for: the structure we teach for this exact question type, the paragraph pattern that goes with it, and the sentence openers for each stage — so the essay is planned before you start writing rather than assembled as you go.

See the structure for this question type →

Vocabulary for this topic

Word or phraseMeaningUsed in a sentence
notice and consentthe model where users are told terms and agree to themNotice and consent has broken down at this scale.
data minimisationcollecting only what is genuinely neededData minimisation removes the problem at source.
purpose limitationa rule that data may only be used for the stated reasonPurpose limitation makes secondary use unlawful.
inferencea conclusion drawn from data rather than stated in itInference reveals what a person never disclosed.
aggregationcombining separate records into a fuller pictureAggregation turns trivial records into sensitive findings.
proportionate (penalty)scaled to the size of the offenderOnly proportionate penalties change corporate behaviour.

Write your own answer

Draft your response below, then get it marked against all four IELTS criteria. Your draft stays in this browser — nothing is published.

Common questions

How do I use the wording of the prompt to build an argument?

Take its claim seriously and follow the consequence. Here, "people do not understand the scale" means consent cannot function — which immediately rules out solutions based on better explanation. Reading the prompt closely is frequently where the best essays find their thesis.

Is it acceptable to dismiss education as a solution?

Yes, if you give a reason and do not dismiss it entirely. Saying it has a modest role but misplaces responsibility onto the weakest party is evaluation. Simply ignoring an obvious remedy looks like an oversight.

Do I need technical knowledge of how data is collected?

No. Everyday examples — locations, purchases, how long you look at something — carry the argument completely. What matters is the reasoning about consent and inference, not familiarity with the technology.