Privacy & Data Protection

What’s the Deal With Data Broker Law?

Six states now make you register as a data broker if you sell or license personal data about people who never dealt with you, and the definition is a lot wider than the reputation. California has already fined S&P Global $62,600 over an administrative error. Here is how to tell if it reaches you.

Read More »

Data Retention Policy: 3 Takeaways for SaaS Vendors

Data Retention Policy: 3 Takeaways for SaaS Vendors Short answer: a good data retention policy makes three promises and backs each one with proof. You say how long you keep customer data and delete it automatically, you stop anyone from casually reading it, and you give the customer a way

Read More »

The Vendor Security Alliance: Why SaaS Companies Should Care

Short answer: security due diligence is the primary bottleneck in enterprise SaaS deals today. The Vendor Security Alliance standardizes the security questionnaire buyers send vendors, letting you prove your security posture once in a trusted format rather than answering a custom questionnaire for every enterprise deal. As a SaaS attorney,

Read More »

Kevin Mitnick’s New Book

If you run a software or SaaS company, the biggest hole in your security is probably not your code. It is your people. That is the lesson of Kevin Mitnick’s book Ghost in the Wires, and it is why I think every software founder should read it. If you have

Read More »

FTC’s Negative Option Rule

Short answer: the FTC’s Negative Option Rule is the federal standard for how you sell subscriptions, free-to-paid trials, and auto-renewals, and the core idea is simple: you cannot treat a customer’s silence as a “yes.” The headline “Click-to-Cancel” version of that rule was struck down by a federal appeals court

Read More »

3 Privacy Tips for a Software or SaaS Company

Short answer: the Supreme Court’s decision in City of Ontario v. Quon gives software and SaaS companies three durable employee-privacy lessons. First, write a clear technology usage policy. Second, make sure any search of employee data has a legitimate reason. Third, keep managers from rewriting the policy on the fly.

Read More »

Contract or Policy?

Short answer: use a contract when you need a commitment neither side can change unilaterally (caps, indemnities, service levels); use a policy when you need the freedom to change the rules as your business evolves (security practices, support hours, acceptable use). The test is whether you need to be bound

Read More »

Free Initial Consultation

Get started with a free initial consultation. Fill out the form below to connect with our experts today!