Ed note: I wrote this in 2019 and published it to my earlier blog. It's still relevant, so I'm reposting it here. From a WSJ article [https://www.wsj.com/articles/new-parents-complain-amazon-ads-are-deceptive-1543417201]
Ed note: I wrote this in 2018 and published it to an earlier version of this blog. The content is still relevant, so I'm reposting it here. tl;dr People have drastically different sensitivities about privacy. Some believ
If you’re running a tech company, you almost certainly have to implement “reasonable security measures." The best way to show that you've done that is by creating a written information security program (WISP).
When you're thinking through a privacy issue, it's helpful to look at the relevant precedent. But, it's not so easy to find—some of it is in FTC consent decrees, some of it is in class action lawsuits, and some of it is in press stories that, for one reason or another, never turned into litigation.
It sucks to botch privacy issues. It feels professionally bad (like, how did I not see that coming!?) and people—Twitter, the press, users, and, in extreme cases, regulators and plaintiffs’ attorneys—won’t let you forget it.
A non-lawyer tech exec friend asked for a doc to help his team look out for legal issues. This is what I came up with.
The Sears consent decree dispels the notion, still common among some clients and some attorneys, that a privacy policy disclosure is a cure-all.
Sears released a consumer research app that paid consumers $10 to join an “online community” of Sears Holding
Here’s the background in case you missed it: Google+ had a vulnerability which made it possible for third parties to access, via the Google+ API, private Google+ user data between 2015 and March 2018. Google found no evi
AI-assisted writing experiment
If you work at a "regular" tech company and you're warning your clients of fines that are "up to 4% of annual revenue" for GDPR violations, you're misleading them.