MVPing your Legal Terms and Policies
Knowing what customer-facing documentation you’ll need at various stages of your startup’s evolution can both help you prepare for growth and be choosy about when to invest in costly legal documentation.
Internet, product, and privacy law
Topic archive
8 essays on gdpr.
Knowing what customer-facing documentation you’ll need at various stages of your startup’s evolution can both help you prepare for growth and be choosy about when to invest in costly legal documentation.
If you’re running a tech company, you almost certainly have to implement “reasonable security measures." The best way to show that you've done that is by creating a written information security program (WISP).
A non-lawyer tech exec friend asked for a doc to help his team look out for legal issues. This is what I came up with.
Perhaps the GDPR isn’t really about protecting privacy. I mean, from an Internet user's perspective, not much has changed since its inception. Companies still collect and use personal data in all sorts of ways. Internet users (EU-based and otherwise) still get retargeted with Adidas ads . . .
Because the GDPR only applies to “personal data”, knowing whether information qualifies as such is critical. The GDPR doesn’t make this easy. The crux of the problem is this: whether data qualifies as personal information depends entirely on who’s asking—that is . . .
If your job is to implement the GDPR, let me start by saying . . . I'm sorry. I don't know if you pissed off someone powerful, or if you just made poor career choices, but here you are.
Facebook is reportedly facing a fine of up to $1.6B [https://www.cnbc.com/2018/10/04/facebook-data-breach-top-eu-regulator-officially-opens-investigation.html] for last month’s hack of ~50M Facebook accounts (~4M belong
AI-assisted writing experiment
If you work at a "regular" tech company and you're warning your clients of fines that are "up to 4% of annual revenue" for GDPR violations, you're misleading them.