Skip to main content

All Questions

1 vote
0 answers

Is it GDPR compliant to require registration to access a privacy policy?

There is currently an issue with Windows operating systems, reputed to be related to Falcon Sensor from CrowdStrike. From the description of their tool, the question of GDPR compliance can be asked ...
User65535's user avatar
  • 7,730
6 votes
1 answer

Is deciding to use google fonts the sort of decision that makes an entity a controller rather than a processor?

In ensuring GDPR compliance determining which entities are data controllers and which data processors is a critical step. The UK government says: The UK GDPR defines a controller as: the natural or ...
User65535's user avatar
  • 7,730
0 votes
0 answers

Does the transfer occurring under Article 45, 46 or 49 affect the Right of Access under Article 15.2?

Transfer of personal data from the UK to the US can, at least in theory, occur under Articles 45, 46 and 49. These all have different requirements. Article 15 of the GDPR the Right of access includes ...
User65535's user avatar
  • 7,730
0 votes
0 answers

What does being "informed of the appropriate safeguards pursuant to Article 46" mean?

Article 15 of the GDPR the Right of access includes section 2: Where personal data are transferred to a third country or to an international organisation, the data subject shall have the right to be ...
User65535's user avatar
  • 7,730
1 vote
0 answers

How specific does the information need to be relating to personal information transfer between data controllers?

When personal information is transferred between data controllers the GDPR imposses certain requirements. Among these are information that must be provided to the data subject. As I understand it ...
User65535's user avatar
  • 7,730
1 vote
1 answer

Can computer performance metrics be personal data?

ScorecardResearch is a major data collection organisation that serves code onto some major UK web sites. Their privacy policy mentions a lot of tracking, including "hardware or device ...
User65535's user avatar
  • 7,730
8 votes
2 answers

Is it legal to discriminate on marital status for car insurance/pensions etc.?

In 2012 the European Court of Justice (ECJ) ruled that gender is no longer allowed to be a factor when premiums are calculated for "everything from pensions to car and life insurance". I ...
User65535's user avatar
  • 7,730
0 votes
3 answers

Do the various anti-end to end encryption laws have provisions concerning third party clients?

There has been multiple attempts to criminalise end to end encryption (E2E). Currently in the news is the EU Chat Control 2.0 (though it seems it has now been withdrawn), the UK passed the Online ...
User65535's user avatar
  • 7,730
3 votes
0 answers

Does there exist an example of meaningful information about an automated individual decision-making algorithm?

The GDPR Article 14 includes provisions for the data subject to have meaningful information about an automated individual decision-making algorithm that which produces legal effects concerning him or ...
User65535's user avatar
  • 7,730
0 votes
0 answers

Does the GDPR right to deletion in Art. 17 effectively include some "disproportionate effort" exception?

Some provisions of the GDPR have explicit exceptions about "disproportionate effort". Particularly relevant is the one in Article 19: The controller shall communicate any rectification or ...
User65535's user avatar
  • 7,730
1 vote
1 answer

What exactly is a decision wrt. GDPR Automated individual decision-making?

The GDPR Article 22 provides rights relating to automated individual decision-making, including profiling. It starts: The data subject shall have the right not to be subject to a decision based ...
User65535's user avatar
  • 7,730
5 votes
2 answers

How do Wi-Fi Positioning Systems interact with the GDPR?

There is a paper (described in the news) that details how to use Apple's Wi-Fi Positioning System (WPS) facilitates mass surveillance, even of those not using Apple devices. The system is described ...
User65535's user avatar
  • 7,730
0 votes
2 answers

Double Jeopardy when received a police caution?

I was curious about the application of Double Jeopardy around the world, and in particular the European Union, in the following scenario. Someone commits a crime in England, the police arrest them. ...
user5623335's user avatar
  • 1,202
0 votes
0 answers

MLAT De Minimis period?

The UK Government website covers Mutual Legal Assistance Treaty (MLAT) requests that it receives from outside of the UK. I was hoping someone could clarify the De Minimis part. Question 1: Focusing on ...
user5623335's user avatar
  • 1,202
4 votes
1 answer

What happens when data that was not personal information become personal information?

Supposed there is some data that is not associated with an individual. This data is processed by a company and distributed on the web. At a later date this data becomes associated with an individual ...
User65535's user avatar
  • 7,730
0 votes
0 answers

Is a third party which solicits and accepts personal data from a customer on another’s behalf a processor or a controller?

Alice contracts with ACME insurance which sends her to their identity verification solution provider’s app/website (BCME KYC SOLUTIONS Inc). BCME’s portal asks Alice for photos of herself and other ...
TylerDurden's user avatar
1 vote
1 answer

Can either side of a GDPR SAR require the other to agree to ToS during the identification process?

I shall use a real situation that happened to me, but this is just to demonstrate my point. I am definitely not going to do anything about it. This is a purely theoretical question, I am not ...
User65535's user avatar
  • 7,730
0 votes
1 answer

Is "gossip surveillance" processing personal data under the GDPR?

The Guardian has an article on "gossip surveillance" where strangers report on social media private conversations they are not party to in the hope of exposing duplicity from the speakers in ...
User65535's user avatar
  • 7,730
2 votes
2 answers

Is it legal/appropriate to email a GDPR SAR to the executive team if that is the only email address the company provides?

This is prompted by this question but I am fairly sure I do not have the correct answer so I am making this one. My personal answer to "How do I get my data from company X under GDPR" is to ...
User65535's user avatar
  • 7,730
1 vote
2 answers

What are an employed/contracted software developer's responsibilities under the GDPR?

This is prompted by this question but that is rather complicated by the technical details. Suppose the following hypothetical: Alice is a software developer for Bob Inc. perhaps as a normal employee, ...
User65535's user avatar
  • 7,730
3 votes
1 answer

Can one person's genetic information be another persons personal information?

In the UK GDPR ‘personal data’ is defined as: ‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one ...
User65535's user avatar
  • 7,730
8 votes
1 answer

Does GDPR apply when PII is already publicly available?

Pretend there is a website, it might be free to access, or be a paid per search service, where the users get access to summarised information on the people that they search for. All of the information ...
user5623335's user avatar
  • 1,202
4 votes
1 answer

What does "Household Exception" to the GDPR mean?

GDPR Section 2 Recital 18 (?) reads: Not Applicable to Personal or Household Activities This Regulation does not apply to the processing of personal data by a natural person in the course of a purely ...
User65535's user avatar
  • 7,730
0 votes
1 answer

To what extent was the Equality Act 2010 shaped by or did it “implement” legal provisions of the EU?

The DPA 2018 was passed pursuant to the EU GDPR to achieve uniformity across the EU in relation to matters of personal data. The unfair contract term regulations too were passed to implement EU ...
TylerDurden's user avatar
0 votes
1 answer

Do anti discrimination laws bind overseas service providers when the victims of their discrimination are in the jurisdiction of the law?

Bob lives in Birmingham or perhaps Madrid. He joins an online club operated by an overseas entity based in Peru, or perhaps Chicago. They incidentally find out that he is black and promptly cancel his ...
TylerDurden's user avatar
12 votes
3 answers

Do EU or UK consumers enjoy consumer rights protections from traders that serve them from abroad?

Bob lives in Manchester, or alternatively in Lyon. He purchases a product or service from a vendor in the USA, or perhaps Timbuktu. Do European or British consumer rights legislations bind the ...
TylerDurden's user avatar
1 vote
1 answer

Do any other consumer rights laws have extraterritorial applicability to international organisations that cater to British or European customers?

The GDPR purports to bind any organisation, wheresoever it may be based, that serves individuals based in the EU, or (as the case may be) the UK. The GDPR governs the obligations of organisations and ...
TylerDurden's user avatar
3 votes
2 answers

What is the U.K. GDPR?

I understand that the DPA implemented the GDPR in British law as an act of Parliament. Then there was Brexit, and the U.K. GDPR was introduced to stand in for the no longer binding EU GDPR, with only ...
TylerDurden's user avatar
5 votes
1 answer

Under what conditions are 3rd party works automatically subject to the OGL 1.0a?

Are 3rd party creations that are "compatible with" D&D automatically subject to the OGL (OGL 1.0a for the purposes of all references in this question), or can they be published without ...
illustro's user avatar
  • 151
2 votes
1 answer

Do contracts require pages or clauses numbered?

A question asked by another member about missing pages in a lease brings to my mind the question of whether there is a legal requirement for contract pages to be numbered so that it is e.g. obvious ...
StephenG - Help Ukraine's user avatar
-1 votes
2 answers

Can someone be prosecuted posthumously?

Can someone be prosecuted posthumously in the British or EU courts for alleged sexual offences committed many centuries ago?
user366312's user avatar
1 vote
1 answer

Is selling program / liking bot legal?

Would it be legal to sell a program / bot that log into a website account and like others posts? Is it legal on the assumption that user is responsible for use of that program (getting ban is his ...
Patryk Chowratowicz 'Zszywacz''s user avatar
1 vote
1 answer

What exactly triggers the GDPR Article 14?

Article 14 of the GDPR concerns the requirement for a data controller to inform the data subject when they obtain personal data has been obtained from an entity that is not the data subject: Art. 14 ...
User65535's user avatar
  • 7,730
10 votes
4 answers

Is there a way to determine if an email address is personal information?

The GDPR defines personal data as: Personal data is information that relates to an identified or identifiable individual. My understanding is that this means that [email protected] is ...
User65535's user avatar
  • 7,730
1 vote
1 answer

Is satelite data personal data?

It is in the news that artificial intelligence (AI) has been applied to aerial photography to identify homeowners who have made unauthorised additions of swimming pools to their properties in France. ...
User65535's user avatar
  • 7,730
1 vote
1 answer

Responsabilities on data breaches UK Data Protection Act

Following a question from THIS StackExchange about Data Protection Act application in the UK, there is an aspect about "proactivity" and "responsabilities" that I do not fully ...
Javier Gonzalez Moncayo's user avatar
0 votes
1 answer

Does the UK have a (enforcable) law linked with the Data Protection Act to control document's metadata?

Reading the information on the ICO's website, I came across a few items mentioning how to handle metadata on my organization's workflow like THIS or THIS. I noticed they use expressions like "...
Javier Gonzalez Moncayo's user avatar
5 votes
0 answers

Pension rights post Brexit

In the EU, if you worked in another member state for a period of time, that period will add to the minimum amount of time you need to work to be able to claim pension from another member state (with ...
sygi's user avatar
  • 123
1 vote
2 answers

If I sell an item to someone in another country, whose laws apply?

If I sell a large item (example car/caravan/boat) from the UK in a private deal to a person in a country in the EU, which countries laws (apply in the event of a dispute)?
ConanTheGerbil's user avatar
0 votes
2 answers

If you recieve others PII as part of the response to a GDPR SAR do you become a data controller?

Say Alice makes a GDPR Subject Access Request of a data controller, and in response receives some of Bob's Personally Identifiable Information, does the Alice then become a data controller with ...
User65535's user avatar
  • 7,730
1 vote
2 answers

Is it legal in Spain/Europe to retain an employee until a replacement is found?

When an employee sends his resignation letter, is it legal to retain that employee indefinitely until a replacement is found? Is it legal to claim damages if he leaves? This is for Spanish law and ...
Esteb's user avatar
  • 111
0 votes
1 answer

Is it possible to receive VAT refunds for products bought within last 6 months before leaving UK from stores not specifically enrolled in scheme?

Edit: as pointed out by xngtng, this is no longer in operation and was scrapped a couple of years ago. Suppose one buys something from a shop that doesn't specifically partake in the vat refund scheme....
JosephCorrectEnglishPronouns's user avatar
1 vote
2 answers

Limits of automated decision making WRT workplace surveys

As part of the GDPR, if personal data is used for automated decision making a number of rules apply, particularly regarding consent and access to data. A number of companies offer workplace surveys, ...
User65535's user avatar
  • 7,730
10 votes
2 answers

Can I store the names of arbitrary business associates in my CRM system?

I'm running an agency and I would like to store the names of employees of my client's companies to help me build client relationships. For example, "Gina works on reception." Is this allowed ...
Jordan Regan's user avatar
-3 votes
1 answer

Does a company’s T&C or their house rules supersede law and is asking private health status (including the request to wear a mask) an offence?

In January 2022 I used an airline to fly from UK to Spain. As soon as I boarded, I made myself comfortable and ready to sleep as I had no opportunity to do so the night before. I took my mask off as I ...
Dan's user avatar
  • 119
1 vote
1 answer

Does the GDPR apply to reference managers?

Reference managers are software products that record the details of scientific papers that one interacts with. All academics and many others use them as a crucial tool of their work. Common examples ...
User65535's user avatar
  • 7,730
2 votes
1 answer

Does the GDPR cover reference to court proceedings?

On this site many good answers are referenced by real court cases, usually in the form Surname vs. Surname [date] <link to further details>. There also exist documents (example is US so as not ...
User65535's user avatar
  • 7,730
38 votes
3 answers

Legality of penalising Russian Oligarchs

What is the legal basis for penalising individual Russian Oligarchs? Having ill-gotten wealth and dubious friends is hardly unique to Russia, and whilst I can understand with the desire of the Western ...
ConanTheGerbil's user avatar
1 vote
1 answer

What references are available for the GDPR legitimate interests balancing test?

A basis for the processing of personally identifiable data (PII) is legitimate interest. According to the UK ICO data controllers who rely on this basis should conduct a legitimate interests ...
Dave's user avatar
  • 827
0 votes
1 answer

Create a company to manage my personal domain name

I own a domain name that has the format, that is used primarily for personalised email addresses for my family. At the moment, I am the legal owner of the domain name and the ...
CuriousUser1234's user avatar

15 30 50 per page