The Buccaneer Academy Field Manual

What you can now do — and the answers worth keeping at your desk.

What you can now do

If it points to a person — a name, an email, an IP — it's personal data, and it's protected.

  1. Someone asks to see / fix / delete / move their data → it's a rights request. Route it, don't stall.
  2. Someone wants data on the phone / by email → verify who they are first.
  3. Data is wrong → actually correct it (a stapled note isn't a fix); pause its use till sorted.
  4. Someone withdraws consent / asks to be deleted → act without undue delay; don't keep "just in case".
  5. You're collecting → say who you are, why, how long, and their rights (to see, fix, or delete their data) — at that moment.
  6. Collected for one thing → don't quietly reuse it for another. A sign-up list isn't a marketing list.
  7. Before collecting → "do I actually need this?" Take the minimum. Sensitive data: don't collect unless truly necessary, and guard it harder.
  8. Wrong recipient / lost device / exposure → it's a breach. Report it fast to manager + DPO/IT. Write down who your manager and DPO/IT contact are now — you'll need them before you need them.
  9. Everyday handling → lock your screen, encrypt portable devices, share on need-to-know, send securely.
  10. AI deciding about people, or data about to leave for an outside/free/overseas tool → stop. Keep a human in the loop; check before data leaves.

Questions worth keeping

Before I share someone's personal data, what should I check?

Make sure the person asking is who they say they are, and that they're actually entitled to it. Verify identity before anything leaves your hands.

— Sprig: "A confident voice on the phone said he was Bonnie's husband and rattled off a CPR number. That's not proof. I nearly read out her medical note."

What do I do when something goes wrong with personal data?

Treat it as a likely breach and report it fast to your manager and DPO/IT. Reporting is the system working — burying it is the real mistake.

— Bonebeard: "I fired a roster off to the wrong cadet and said nothing. The trouble wasn't the slip — it was the silence."

If someone asks me to delete their data, do I have to?

Sometimes — erasure is situational, not absolute. Where a ground applies (e.g. consent withdrawn, no other basis), act without undue delay; otherwise explain why you must keep it.

— Dewey: "I'd kept every cadet scroll since 1991 'just in case'. Most of it should have been let go long ago."

Can I put personal data into an outside tool — a free app, an AI, something hosted abroad?

Check first. Use sanctioned systems only, and never let personal data leave for an unvetted or overseas tool on your own say-so. Where a tool makes decisions about people, keep a human in the loop.

— Pixel: "My oracle auto-rejected cadets, and I was uploading the whole register to a free overseas app. Convenient isn't the same as allowed."

Is it still a breach if I don't think anyone saw the data?

Yes. If personal data was exposed, the possibility of access is enough — report it and let the risk be assessed. "No sign anyone looked" feeds that assessment; it doesn't decide whether a breach happened.

— Quill: "I posted a cohort photo with CPR numbers on a clipboard in shot. I deleted it in seconds — and still reported it."

What actually counts as personal data?

Anything that points to a living person — a name, an email, a phone number, an IP address, an ID number. If it can be linked back to someone, it's personal data and it's protected.

— Polly: "Squawk! 'Where's the harm in a name?' A name is personal data. Start there."

What are the different categories of data, and which need extra care?

Regular (everyday) data; special-category (sensitive) data; and, in Denmark, confidential data. All three are personal data and all are protected — the last two need extra care.

— Polly: "Squawk! Three boxes. Most things are regular. Some are sensitive. A few sit in between."

Why is some data "sensitive", and what does that change?

Special categories — health, race or ethnicity, religion or beliefs, trade-union membership, sex life or orientation, political opinions, genetics, biometrics — can be used to harm or discriminate. Don't collect them unless truly necessary, and guard them harder.

— Polly: "Squawk! Health is a special category. Handle it like it could hurt someone — because mishandled, it can."

How do I know if I'm collecting too much?

Ask "do I need this for the actual purpose?" Collect the minimum — need-to-have, not nice-to-have. "Might be handy later" is not a reason.

— Stan: "My fair form asked for birth dates and home harbours for a one-day event. I didn't need a scrap of it."

When I rely on consent, what makes it valid?

It must be freely given, specific, informed, and as easy to withdraw as to give. No pre-ticked boxes, no bundling, and consent for one purpose doesn't cover another.

— Stan: "I treated one tick-box as a forever-licence to market. It wasn't — consent is tied to the purpose it was given for."

Does GDPR even apply to us?

Yes, if you handle the personal data of people in the EU — wherever your organisation is based. Where you're located doesn't get you out of it.

— The Inspector: "I don't care where your ship is flagged. If you hold these people's data, you answer for it."

Can I take personal data out of the office?

Only on sanctioned, encrypted devices — and only when you need to. The device is the risk: encryption is what turns a lost laptop into a non-event, but only if it was done beforehand.

— Sprig: "I left the work laptop in the car with the cadet register on it. Unencrypted. That one became a fine."

Do the rules apply to data I handle in my private life?

No — purely personal or household use is outside GDPR. But respecting people's data is still the decent thing to do.

— Polly: "Squawk! Your friends' numbers in your own phone? Not GDPR's business. Being careful with them is still kind."