MVPing your Legal Terms and Policies
Knowing what customer-facing documentation you’ll need at various stages of your startup’s evolution can both help you prepare for growth and be choosy about when to invest in costly legal documentation.
Internet, product, and privacy law
PCounsel@
Page 2 of 3
Knowing what customer-facing documentation you’ll need at various stages of your startup’s evolution can both help you prepare for growth and be choosy about when to invest in costly legal documentation.
If you’re running a tech company, you almost certainly have to implement “reasonable security measures." The best way to show that you've done that is by creating a written information security program (WISP).
When you're thinking through a privacy issue, it's helpful to look at the relevant precedent. But, it's not so easy to find—some of it is in FTC consent decrees, some of it is in class action lawsuits, and some of it is in press stories that, for one reason or another, never turned into litigation.
It sucks to botch privacy issues. It feels professionally bad (like, how did I not see that coming!?) and people—Twitter, the press, users, and, in extreme cases, regulators and plaintiffs’ attorneys—won’t let you forget it.
A Legal team is unlike almost any of your others: Instead of building or improving something, it’s goal is to address low-probability, high-impact issues . . . .
At the absolute minimum, your counsel should be able to concisely tell you what rules apply to your situation and, using these rules, tell you whether the situation you’ve described falls within it.
A non-lawyer tech exec friend asked for a doc to help his team look out for legal issues. This is what I came up with.
Perhaps the GDPR isn’t really about protecting privacy. I mean, from an Internet user's perspective, not much has changed since its inception. Companies still collect and use personal data in all sorts of ways. Internet users (EU-based and otherwise) still get retargeted with Adidas ads . . .
tl;dr Reviewing advertising and marketing materials is often straightforward buuuuttttt it can be easy to overlook legal issues. One solution: A checklist. This post provides a checklist that you can give to your marketing team or use yourself.
Because the GDPR only applies to “personal data”, knowing whether information qualifies as such is critical. The GDPR doesn’t make this easy. The crux of the problem is this: whether data qualifies as personal information depends entirely on who’s asking—that is . . .