On the question of what info you have to give the PPU. I was told that any usernames must be disclosed, as notification rules include disclosing "any other name you are known by". It doesn't matter whether the SHPO mentions usernames or not.
Also my SHPO includes a catch all clause which says I must not refuse to disclose any details of my "internet activity". So vaguely worded, it can mean anything the PPU wants it to. By writing it as a negative requirement - 'must not refuse' - they can get around the current restrictions on not requiring positive actions. This is very common in SHPOs. Must not refuse to allow the PPU to inspect your devices, for example, is a positive action, disguised as a negative.
|