An original GRE "Analyze an Issue" practice prompt on data privacy regulation — write a timed response, then compare it against three model answers.

তথ্য গোপনীয়তা নিয়ন্ত্রণ নিয়ে একটি মৌলিক GRE "Analyze an Issue" অনুশীলন প্রম্পট — সময়বদ্ধ উত্তর লিখুন, তারপর তুলনা করুন।

30min
Timeসময়
1
Taskটাস্ক
0–6
Score Rangeস্কোর সীমা

How to use it: Start the timer, plan for ~5 minutes, then write your essay in the box below. When you're done, open the checklist and the model responses to self-assess.

ব্যবহারের নিয়ম: টাইমার শুরু করুন, পরিকল্পনা করুন, তারপর রচনা লিখুন।

Issue Prompt

"Governments should impose strict regulations on the collection and use of personal data by technology companies."

Write a response in which you discuss the extent to which you agree or disagree with the statement above and explain your reasoning. In developing your position, consider ways the statement might or might not hold true, and explain how these considerations shape your position.

30:00
Aim for 400–600 words.0 words

Self-Assessment Checklist

লেখা শেষে নিজেই যাচাই করুন — প্রতিটি সঠিক হলে টিক দিন।

0 / 8 checked

Model Responses

Compare your essay against these three model responses, written at different score levels on the official 0-6 rubric.

আপনার রচনাকে বিভিন্ন স্কোর স্তরের এই তিনটি মডেল উত্তরের সাথে তুলনা করুন।

Model Response Score 6

Strict regulation of personal data is justified in principle, but the word "strict" needs qualification: regulation should be proportionate and clearly scoped, not maximal, or it risks trading one harm (privacy loss) for another (stifled competition and innovation).

The case for regulation is well documented. The 2018 Cambridge Analytica scandal showed how personal data harvested without meaningful consent could be used to influence elections at scale, and numerous data breaches since then have exposed millions of users' financial and health information with little recourse for the individuals affected. In the absence of legal obligation, most companies have shown limited incentive to prioritize user privacy over data monetization, since the costs of a breach are often externalized onto users rather than borne by the company itself. The European Union's General Data Protection Regulation (GDPR), which requires explicit consent, data minimization, and the right to erasure, has become an influential model precisely because it responds to this incentive gap.

Yet an important counterargument deserves attention: regulation imposes compliance costs that fall disproportionately on small companies and startups, which lack the legal and engineering resources of large firms to implement complex consent architectures. Ironically, blunt, one-size-fits-all regulation can entrench the market power of the very large technology companies it aims to constrain, since only they can easily absorb the compliance burden. This is a genuine cost, and it means that "strict" regulation, if poorly designed, could reduce competition rather than protect consumers.

The resolution lies in how regulation is designed rather than whether it exists. Tiered rules that scale obligations to a company's size and the sensitivity of the data it handles — as GDPR partially attempts, and as several newer regulatory proposals do more explicitly — can protect users without disproportionately burdening smaller players. Regulation focused on high-risk categories, such as biometric or health data, rather than blanket restriction on all data of every kind, better targets the genuine harms.

In conclusion, governments should regulate the collection and use of personal data, since the incentive structure of the industry does not reliably protect users on its own — but the regulation should be carefully calibrated rather than maximalist, so as not to entrench the largest players or stifle the smaller innovators who might otherwise challenge them.

Why this scores a 6: Directly engages with the specific word "strict" in the prompt rather than answering a generic version of the question; cites a real, verifiable event (Cambridge Analytica) and a real regulatory framework (GDPR) with accurate detail; the counterargument about compliance costs and market concentration is substantial, specific, and genuinely shapes the final, qualified position; sophisticated transitions and varied sentence length throughout. প্রম্পটের নির্দিষ্ট শব্দ নিয়ে যুক্তি, বাস্তব উদাহরণ এবং শক্তিশালী বিপরীত যুক্তির কারণে এটি ৬ স্কোর পায়।
Model Response Score 4–5

I agree that governments should regulate how technology companies collect and use personal data, because without regulation, companies may misuse people's information.

One reason is that technology companies collect huge amounts of data about users, often without users fully understanding what is being collected or how it will be used. This can lead to privacy violations, such as data being sold to third parties or used in ways users did not expect.

Another reason is that data breaches have become common, and when companies are not required to follow strict security standards, users' personal information, like financial details, can be exposed to hackers. Regulation can require companies to take stronger security measures.

However, some people argue that too much regulation could slow down innovation and make it harder for smaller tech companies to compete, since following complex rules can be expensive. This is a fair point, but I still think protecting users' privacy is more important.

In conclusion, I believe governments should regulate personal data collection because the risks of privacy violations and data breaches are too significant to ignore, even though regulation does have some downsides for businesses.

Why this scores a 4–5: Clear position with logical, correctly sequenced reasons and a real counterargument (compliance cost for small companies) — but no specific named example (no particular breach, company, or law is cited), and the counterargument is acknowledged rather than substantively engaged ("this is a fair point, but I still think..."). Adequately developed but generic compared to a top-scoring response. যুক্তি স্পষ্ট কিন্তু কোনো নির্দিষ্ট উদাহরণ নেই, তাই এটি ৪-৫ স্কোরের পর্যায়ে থাকে।
Model Response Score 3

I agree that governments should make strict rules about personal data because companies collect too much information about people these days.

Technology companies know a lot about us, like what we buy and where we go, and this is not good because it is private information that should not be shared without permission. If there are no rules companies will keep collecting more and more data.

Some people think regulation is bad for business but I think privacy is more important than business so the government should still make strict rules anyway.

In conclusion strict rules on personal data are necessary because privacy is important and companies should not be allowed to collect data however they want without any rules.

Why this scores a 3: A position is stated and repeated across all four paragraphs without meaningfully developing new supporting points; there is no specific example (no named company, law, or event); the counterargument in paragraph 3 is mentioned only to be brushed aside in the same sentence, without any real analysis. Organization is thin and several sentences are simple restatements of the thesis. এই উত্তর ৩ স্কোর পায় কারণ একই যুক্তির পুনরাবৃত্তি এবং নির্দিষ্ট উদাহরণের অভাব।