Compliance & Regulatory Library

Global Surveillance Compliance Library

A transparent, centralized reference mapping how our hardware-modified solutions align — and do not align — with global surveillance regulations. We publish this because clarity about legal constraints is itself a form of responsible practice.

Transparency Statement

Compliance is the buyer's, not the seller's, burden

Surveillance tools do not authorize surveillance. Legal authority comes from statute, consent, court order, or a recognized investigatory power — never from the availability of a device. This library exists to make that boundary explicit. We describe how our hardware-modified solutions relate to major regulatory frameworks, where they may lawfully be used, and where they may not. Where alignment is conditional, the condition is stated plainly.

This page is a transparency statement and not legal advice. Every buyer must engage qualified counsel to confirm authorization in the specific jurisdictions where monitoring will occur.

Regulatory Framework Matrix

Where the product aligns, is conditional, or is prohibited

The matrix below states our position on alignment with major regulatory frameworks. Alignment does not imply permission; it means a lawful pathway exists. Conditional means a lawful basis must be established by the buyer. Prohibited means we will not supply the device for that use under any terms.

GDPR — General Data Protection Regulation

European Union

Conditional

Processing of personal data captured by the device constitutes controller activity. Lawful monitoring requires a valid Article 6 basis — most commonly legitimate interests under Article 6(1)(f) balanced against data-subject rights, or a specific legal obligation. We do not sell for processing lacking a lawful basis.

Note: Buyers must conduct a Data Protection Impact Assessment (DPIA) for high-risk monitoring and honor data-subject rights (access, erasure, restriction).

CCPA / CPRA

United States (California)

Conditional

Personal information collected through monitoring is subject to CCPA/CPRA where the buyer is a qualifying business. Employee-investigation and law-enforcement exemptions may apply, but transparency, minimization, and deletion obligations remain relevant to professional deployments.

Note: Buyers should map captured data against their privacy notice and honor consumer/employee rights as applicable.

ECPA / Title III — Wiretap Act

United States (Federal)

Conditional

Interception of electronic communications generally requires one-party or all-party consent depending on state law, or a court order. Title III criminalizes interception without authorization. We sell only where the buyer has documented legal authority — consent, court order, or a recognized statutory exception.

Note: Buyers are responsible for confirming consent requirements in each jurisdiction where interception occurs.

RIPA / Investigatory Powers Act

United Kingdom

Conditional

Covert interception by private parties is unlawful without lawful authority. Authorized use by private entities is limited to specific contexts (e.g., consent-based monitoring of owned devices, or lawful investigatory powers). We do not supply devices for interception lacking lawful authority under UK law.

Note: UK buyers must confirm a lawful basis; self-authorizing interception is not supported.

National Intercept Laws (per-member-state)

European Union

Conditional

Each EU member state maintains its own lawful-interception statute regulating private-party monitoring. Authorization thresholds, consent rules, and evidentiary admissibility vary. We defer to the buyer's qualified legal counsel to confirm per-jurisdiction compliance.

Note: Cross-border monitoring may implicate multiple national regimes simultaneously.

Human Rights & Necessity Frameworks

Global

Aligned

Where monitoring is conducted under lawful authority, it must remain necessary and proportionate. Our vetting process refuses procurement where the stated purpose appears unnecessary, disproportionate, or inconsistent with internationally recognized human-rights norms.

Note: Necessity and proportionality are assessed at procurement and reconfirmed during the engagement.

Stalking / Unlawful Surveillance Statutes

All Jurisdictions

Not Permitted

We will not supply any device for stalking, domestic abuse, harassment, or surveillance of a person who has not consented where consent is legally required. Every request is reviewed, and procurement is refused where the stated use is unlawful or intended to cause harm.

Note: This is a hard boundary. No commercial terms override it.

Compliance Commitments

What we require and what we refuse

These commitments govern every engagement. They are not advisory; they are conditions of procurement and continued supply.

Vetted Procurement

Every request is reviewed before procurement. Buyers must confirm authorized status — corporate, investigative, or compliance professional — and legal authority to monitor the target device.

Documented Lawful Basis

Buyers must identify the lawful basis for monitoring in their jurisdiction before activation. We do not provision operator credentials without a stated, reviewed authorization rationale.

Data Minimization by Design

The hardware intelligence layer captures only what the operator directs it to capture. There is no passive bulk collection; capabilities are operator-invoked and audit-logged per command.

Audit-Logged Operations

Every command issued to the implant and every data object retrieved is recorded in an append-only, tamper-evident log within the secure enclave — supporting internal review and evidentiary defensibility.

Refusal of Unlawful Use

We refuse procurement for stalking, unlawful interception, surveillance without required consent, or any purpose inconsistent with lawful authority. This refusal is non-negotiable.

No Legal Advice — Buyer's Counsel

This library is a transparency statement, not legal advice. Compliance with applicable law is the buyer's responsibility. Buyers must engage qualified counsel to confirm authorization in each jurisdiction.

Due Diligence Process

How lawful use is established

Before a device is prepared or operator credentials are provisioned, the following review is completed. Failure at any step halts the engagement.

01

Authorization Review

The buyer's authorized status and legal authority to monitor the target device are confirmed before procurement. Requests that cannot establish lawful authority are refused.

02

Jurisdiction Mapping

The buyer identifies the jurisdictions where monitoring will occur and confirms the lawful basis (consent, court order, statutory exception) applicable in each.

03

Proportionality Assessment

The stated monitoring purpose is assessed for necessity and proportionality. Deployment scope is limited to what the lawful purpose requires.

04

Acceptance of Policies

Procurement is conditional on acceptance of our Legal Notice, Legal Use Policy, and Acceptable Use Policy. Violation of these terms voids the engagement.

Legal Notice

Authorized Use Only — Lawful Monitoring Required

SpyPhone hardware-modified devices are sold exclusively to vetted corporate, investigative, and compliance professionals for lawful monitoring of devices the purchaser is legally authorized to monitor. Use requires legal authority under the applicable jurisdiction. We do not sell for stalking, unlawful interception, or surveillance without consent where required by law. Every request is reviewed before procurement, and all sales are conditional on acceptance of our Legal Notice.