Ed note: I wrote this in 2018 and published it to an earlier version of this blog. The content is still relevant, so I'm reposting it here. tl;dr Every Product Counsel has her own perspective about what constitutes a con
Ed note: I wrote this in 2018 and published it to an earlier version of this blog. The content is still relevant, so I'm reposting it here. tl;dr People have drastically different sensitivities about privacy. Some believ
When you're thinking through a privacy issue, it's helpful to look at the relevant precedent. But, it's not so easy to find—some of it is in FTC consent decrees, some of it is in class action lawsuits, and some of it is in press stories that, for one reason or another, never turned into litigation.
It sucks to botch privacy issues. It feels professionally bad (like, how did I not see that coming!?) and people—Twitter, the press, users, and, in extreme cases, regulators and plaintiffs’ attorneys—won’t let you forget it.
A non-lawyer tech exec friend asked for a doc to help his team look out for legal issues. This is what I came up with.
Perhaps the GDPR isn’t really about protecting privacy. I mean, from an Internet user's perspective, not much has changed since its inception. Companies still collect and use personal data in all sorts of ways. Internet users (EU-based and otherwise) still get retargeted with Adidas ads . . .
Because the GDPR only applies to “personal data”, knowing whether information qualifies as such is critical. The GDPR doesn’t make this easy. The crux of the problem is this: whether data qualifies as personal information depends entirely on who’s asking—that is . . .
Disclaimer: Reading legal articles on the Internet and naively applying it to your situation would be silly. What follows isn't legal advice, it's general legal information. If you aren't an attorney, consult one. tl;dr
A feature update that would be a non-story for almost every tech company can turn into a massive headache for Google. So it goes with the new Chrome auto-sign in feature: > A few weeks ago Google shipped an update to Chr
The Sears consent decree dispels the notion, still common among some clients and some attorneys, that a privacy policy disclosure is a cure-all.
Sears released a consumer research app that paid consumers $10 to join an “online community” of Sears Holding
Here’s the background in case you missed it: Google+ had a vulnerability which made it possible for third parties to access, via the Google+ API, private Google+ user data between 2015 and March 2018. Google found no evi
Part of your job as product counsel is to monitor changing perceptions of privacy practices. When those perceptions have changed, you should re-do your legal analysis to ensure it’s still valid.
AI-assisted writing experiment
If you work at a "regular" tech company and you're warning your clients of fines that are "up to 4% of annual revenue" for GDPR violations, you're misleading them.