If you’re running a tech company, you almost certainly have to implement “reasonable security measures." The best way to show that you've done that is by creating a written information security program (WISP).
When you're thinking through a privacy issue, it's helpful to look at the relevant precedent. But, it's not so easy to find—some of it is in FTC consent decrees, some of it is in class action lawsuits, and some of it is in press stories that, for one reason or another, never turned into litigation.
A non-lawyer tech exec friend asked for a doc to help his team look out for legal issues. This is what I came up with.
A feature update that would be a non-story for almost every tech company can turn into a massive headache for Google. So it goes with the new Chrome auto-sign in feature: > A few weeks ago Google shipped an update to Chr
Facebook is reportedly facing a fine of up to $1.6B [https://www.cnbc.com/2018/10/04/facebook-data-breach-top-eu-regulator-officially-opens-investigation.html] for last month’s hack of ~50M Facebook accounts (~4M belong
Here’s the background in case you missed it: Google+ had a vulnerability which made it possible for third parties to access, via the Google+ API, private Google+ user data between 2015 and March 2018. Google found no evi
AI-assisted writing experiment
If you work at a "regular" tech company and you're warning your clients of fines that are "up to 4% of annual revenue" for GDPR violations, you're misleading them.