What you can now do — and the answers worth keeping at your desk.
If it points to a person — a name, an email, an IP — it's personal data, and it's protected.
Before I share someone's personal data, what should I check?
Make sure the person asking is who they say they are, and that they're actually entitled to it. Verify identity before anything leaves your hands.
— Sprig: "A confident voice on the phone said he was Bonnie's husband and rattled off a CPR number. That's not proof. I nearly read out her medical note."
What do I do when something goes wrong with personal data?
Treat it as a likely breach and report it fast to your manager and DPO/IT. Reporting is the system working — burying it is the real mistake.
— Bonebeard: "I fired a roster off to the wrong cadet and said nothing. The trouble wasn't the slip — it was the silence."
If someone asks me to delete their data, do I have to?
Sometimes — erasure is situational, not absolute. Where a ground applies (e.g. consent withdrawn, no other basis), act without undue delay; otherwise explain why you must keep it.
— Dewey: "I'd kept every cadet scroll since 1991 'just in case'. Most of it should have been let go long ago."
Can I put personal data into an outside tool — a free app, an AI, something hosted abroad?
Check first. Use sanctioned systems only, and never let personal data leave for an unvetted or overseas tool on your own say-so. Where a tool makes decisions about people, keep a human in the loop.
— Pixel: "My oracle auto-rejected cadets, and I was uploading the whole register to a free overseas app. Convenient isn't the same as allowed."
Is it still a breach if I don't think anyone saw the data?
Yes. If personal data was exposed, the possibility of access is enough — report it and let the risk be assessed. "No sign anyone looked" feeds that assessment; it doesn't decide whether a breach happened.
— Quill: "I posted a cohort photo with CPR numbers on a clipboard in shot. I deleted it in seconds — and still reported it."
What actually counts as personal data?
Anything that points to a living person — a name, an email, a phone number, an IP address, an ID number. If it can be linked back to someone, it's personal data and it's protected.
— Polly: "Squawk! 'Where's the harm in a name?' A name is personal data. Start there."
What are the different categories of data, and which need extra care?
Regular (everyday) data; special-category (sensitive) data; and, in Denmark, confidential data. All three are personal data and all are protected — the last two need extra care.
— Polly: "Squawk! Three boxes. Most things are regular. Some are sensitive. A few sit in between."
Why is some data "sensitive", and what does that change?
Special categories — health, race or ethnicity, religion or beliefs, trade-union membership, sex life or orientation, political opinions, genetics, biometrics — can be used to harm or discriminate. Don't collect them unless truly necessary, and guard them harder.
— Polly: "Squawk! Health is a special category. Handle it like it could hurt someone — because mishandled, it can."
How do I know if I'm collecting too much?
Ask "do I need this for the actual purpose?" Collect the minimum — need-to-have, not nice-to-have. "Might be handy later" is not a reason.
— Stan: "My fair form asked for birth dates and home harbours for a one-day event. I didn't need a scrap of it."
When I rely on consent, what makes it valid?
It must be freely given, specific, informed, and as easy to withdraw as to give. No pre-ticked boxes, no bundling, and consent for one purpose doesn't cover another.
— Stan: "I treated one tick-box as a forever-licence to market. It wasn't — consent is tied to the purpose it was given for."
Does GDPR even apply to us?
Yes, if you handle the personal data of people in the EU — wherever your organisation is based. Where you're located doesn't get you out of it.
— The Inspector: "I don't care where your ship is flagged. If you hold these people's data, you answer for it."
Can I take personal data out of the office?
Only on sanctioned, encrypted devices — and only when you need to. The device is the risk: encryption is what turns a lost laptop into a non-event, but only if it was done beforehand.
— Sprig: "I left the work laptop in the car with the cadet register on it. Unencrypted. That one became a fine."
Do the rules apply to data I handle in my private life?
No — purely personal or household use is outside GDPR. But respecting people's data is still the decent thing to do.
— Polly: "Squawk! Your friends' numbers in your own phone? Not GDPR's business. Being careful with them is still kind."