PMP lesson · Business Environment · Compliance and law · lesson 2 of 2 · about 7 minutes
Legal issues: IP, licences, confidentiality and data privacy
All approachesFree preview
Goal: After this lesson you can recognise intellectual property, licensing, confidentiality and privacy issues, and respond with contain → consult → report → correct.
1The situation
Four legal surprises
On the MES project, a developer wants to use an open-source library whose licence would force the customer's software to become open source, but the contract gives the customer exclusive rights. Another developer copied real employee data into a shared test system. A team member posted photos of the customer's prototype online, against the NDA. And developers have been pasting the customer's code into a public AI chatbot.
None of them meant harm. All four create real legal exposure for both companies.
2The PM is not a lawyer, but must recognise the risk
The PM's job is to recognise legal issues early, contain them, and involve the right specialists. Engineering opinions (“the patent is weak”) are not legal advice.
Use only with a lawful basis; minimise and protect.
Exam pattern: contain the exposure, consult the specialist function, report as required, then use a compliant alternative. Never hide it, never “just use it until the end of the project”.
Open-source licence conflicts with customer's exclusive rights · one licence shared by many
Legal/IP review before use · correct the violation, obtain licences
Confidentiality
Team member posts photos of customer's machine
Remove, assess with legal/contracts, inform customer as required
Data privacy
Real employee data copied into a test system
Remove, report per data-protection procedure, use anonymised data
Data residency / AI tools
Customer data to a foreign cloud or public AI tool
Check contract and policy first; choose compliant options
Export control
Controller shipped to a controlled destination
Hold; consult export compliance; obtain licence
Each has the same pattern: stop, ask, report, correct.
4How it looks on the exam
Exam-style question 1. A developer copied a snapshot of the customer's production database, containing employee names and badge records, into a test environment accessible to the whole team and two external contractors. It has been there for three weeks. What should the project manager do FIRST?
A. Restrict access to internal staff and continue testing
B. Remove the personal data, report the situation according to data-protection procedures, and arrange compliant test data
C. Ask the customer for retrospective permission
D. Delete the data at the end of testing
Show the answer and the decode
Answer: B.
In simple English
Personal data used without authorisation.
What is the question really asking?
The first action.
Key words / trigger
“employee names and badge records”
PMP logic
Contain, report, use compliant alternatives.
Why the wrong answer looks attractive
Restricting access reduces exposure but leaves the breach unreported.
5Remember this
Your memory card
Recognise IP, licence, confidentiality, privacy and export issues early
Contain → consult → report → correct
Legal questions go to legal specialists, not engineering opinion
Never hide a breach or keep using something non-compliant