Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

So now they have admitted what they have done, is someone in the UK going to prosecute them, I wonder?

It seems they may have broken the data protection act in more than one way.

* First, they collected personal data about UK citizens without their permission (as a 3rd party cannot give that permission),

* Secondly, personal information was kept for longer than is necessary (it should have been deleted after it was used)

* Thirdly, they allowed personal data to leave the EU.

Note that personal data includes name and address, telephone number or Email address.

http://en.wikipedia.org/wiki/Data_Protection_Act_1998



This may be a calculated risk. Hopefully they did more due diligence, but a quick search shows a Dec 2011 case [1] where an estate business was prosecuted for collecting info, but was fined a small amount (< £1,000). The extenuating circumstances were that they had already complied with the law by the time the case was heard by the court. [1]: http://www.ico.gov.uk/news/latest_news/2011/estate-agent-pro...


But they are still not complying. They are allowing people to opt-in on behalf of their friends which strictly speaking is against the rules.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: