| > No, you may not in this case :) That is why people keep emphasising the way in which the data was published. This is Sweden, not the US. Here is the relevant paragraph: "För dataintrång döms den som olovligen bereder sig tillgång till en uppgift som är avsedd för automatisk behandling eller olovligen ändrar, utplånar, blockerar eller i register för in sådan uppgift" The requisites are: "olovligen", "bereder sig tillgång till", and "uppgift som är avsedd för automatisk behandling". Christian's app full fills the requisites. API means "Application Programming Interface" and if you think the city created or intended to create such a thing you don't know what an API is. > If you cannot reasonably be said to have circumvented any technical measures to secure the data (cryptographic keys, some sort of login, IP range blocks, etc) it is not a breach. You have no idea what you are talking about. There are several precedents that show that circumventing technical measures is not required for data breach to have occurred. |