
Generating Email Addresses from Public Data is Illegal
Using Companies House data to generate speculative email addresses is illegal under GDPR and PECR. I explain why personal email misuse violates privacy laws.
Articles
The General Data Protection Regulation (GDPR) is a legal framework introduced by the European Union in 2018. It changed the expectations around privacy and personal data on the web. The writing here is concerned with the engineering behind those expectations, and with why responsible data handling cannot be reduced to a cookie banner or a last‑minute compliance task.

Using Companies House data to generate speculative email addresses is illegal under GDPR and PECR. I explain why personal email misuse violates privacy laws.