Skip to main content

All Questions

13 votes
1 answer
119k views

UK: Is it legal to secretly audio record a meeting or a phone call? Is it possible to use such recording in court?

In the United Kingdom: Is it legal to secretly audio record a meeting (in an office) or a phone call while being a participant? Is it possible to use such recording as an evidence in court or ...
unknown's user avatar
  • 139
1 vote
1 answer
112 views

How far up the chain of internet provision does my GDPR responsibility go?

Say I host a web page on my computer, and you visit that site from somewhere in Europe. The web server on my computer will know your IP address, and I can choose to "forget" it as soon as ...
Dave's user avatar
  • 827
60 votes
4 answers
20k views

Does GDPR include UK customers, or not anymore?

Now that Brexit happened, does GDPR include UK customers, or not anymore?
Nuno's user avatar
  • 1,033
38 votes
3 answers
6k views

Legality of penalising Russian Oligarchs

What is the legal basis for penalising individual Russian Oligarchs? Having ill-gotten wealth and dubious friends is hardly unique to Russia, and whilst I can understand with the desire of the Western ...
ConanTheGerbil's user avatar
10 votes
4 answers
5k views

Is there a way to determine if an email address is personal information?

The GDPR defines personal data as: Personal data is information that relates to an identified or identifiable individual. My understanding is that this means that [email protected] is ...
User65535's user avatar
  • 7,730
7 votes
1 answer
3k views

Is it illegal to sell malware?

Is it illegal to produce and sell malware? If no, is there any data I need to collect on the customers? Is it illegal to produce and sell Crypters(programs that hide other programs from antivirus)? ...
hjbvmkbjnmb's user avatar
2 votes
1 answer
185 views

Does the GDPR cover reference to court proceedings?

On this site many good answers are referenced by real court cases, usually in the form Surname vs. Surname [date] <link to further details>. There also exist documents (example is US so as not ...
User65535's user avatar
  • 7,730
2 votes
2 answers
176 views

Is it legal/appropriate to email a GDPR SAR to the executive team if that is the only email address the company provides?

This is prompted by this question but I am fairly sure I do not have the correct answer so I am making this one. My personal answer to "How do I get my data from company X under GDPR" is to ...
User65535's user avatar
  • 7,730
1 vote
2 answers
199 views

What are an employed/contracted software developer's responsibilities under the GDPR?

This is prompted by this question but that is rather complicated by the technical details. Suppose the following hypothetical: Alice is a software developer for Bob Inc. perhaps as a normal employee, ...
User65535's user avatar
  • 7,730
1 vote
2 answers
134 views

Are all statutory instruments in the UK subordinate to an Act of Parliament?

Are all statutory instruments in the United Kingdom subordinate to an Act passed by Parliament? If so, is the intention that the thrust of law is democratically accountable, but for expediency the ...
52d6c6af's user avatar
  • 533
1 vote
1 answer
286 views

What exactly triggers the GDPR Article 14?

Article 14 of the GDPR concerns the requirement for a data controller to inform the data subject when they obtain personal data has been obtained from an entity that is not the data subject: Art. 14 ...
User65535's user avatar
  • 7,730
1 vote
1 answer
35 views

Responsabilities on data breaches UK Data Protection Act

Following a question from THIS StackExchange about Data Protection Act application in the UK, there is an aspect about "proactivity" and "responsabilities" that I do not fully ...
Javier Gonzalez Moncayo's user avatar
0 votes
0 answers
19 views

Does the transfer occurring under Article 45, 46 or 49 affect the Right of Access under Article 15.2?

Transfer of personal data from the UK to the US can, at least in theory, occur under Articles 45, 46 and 49. These all have different requirements. Article 15 of the GDPR the Right of access includes ...
User65535's user avatar
  • 7,730
0 votes
0 answers
22 views

What does being "informed of the appropriate safeguards pursuant to Article 46" mean?

Article 15 of the GDPR the Right of access includes section 2: Where personal data are transferred to a third country or to an international organisation, the data subject shall have the right to be ...
User65535's user avatar
  • 7,730
0 votes
1 answer
59 views

Does the UK have a (enforcable) law linked with the Data Protection Act to control document's metadata?

Reading the information on the ICO's website, I came across a few items mentioning how to handle metadata on my organization's workflow like THIS or THIS. I noticed they use expressions like "...
Javier Gonzalez Moncayo's user avatar