Originally posted by billybiro
					
						
						
							
							
							
							
								
								
								
								
									View Post
								
							
						
					
				
				
			
		Are you considering the clients privacy, data and security policies which you also have to sign as part of the 'demands of the contract' or are you just talking about the contract for work and nothing else?
If you get all the paperwork from a client including contract and other policies that apply to all, have read, understood and can comply with it and none of that mentioned restrictions about working abroad then yes, you are right, you don't have to tell them.
Problem is you've skipped over the problem bits in one simplistic comment 'meet the demands of the contract'. If you'd put 'demands of the contract and the other clients policies then it's none of the clients concern then you would be absolutely correct... and to be honest that's what people have been saying already. If the client allows their data to go offshore then fill your boots and there is no need to tell them.
If the client has clauses about not accessing data from outside the UK then you are dead in the water. To work abroad if they have these policies in you will have to lie to them, make a false statement and then hide the truth from them by technology breaching mulitple clauses along the way which is very bad and I am assuming you aren't suggesting they do this.
Unfortuantely you did go on to say
			
			
				You're aware that I could be based in (say) Spain, connect to a Virtual Machine located in the UK and from there, access data that is also located in the UK and which might have to remain resident in the UK?
All else being equal (i.e. assuming I actually have legitimate access to the data, am using it for legitimate business reasons and don't transfer it off the UK-based VM etc.) then no laws/regulations around data-residency or access have been broken.
	All else being equal (i.e. assuming I actually have legitimate access to the data, am using it for legitimate business reasons and don't transfer it off the UK-based VM etc.) then no laws/regulations around data-residency or access have been broken.
I don't know much about Security but I'm finding it hard to believe that this setup will even work in this day and age.


 
				 
				 
				 
				
Comment