Blog - Page 10
Legal articles in easy to understand language.
How to Verify the Identity of a Data Subject: Balancing Access Rights and Fraud Prevention
Businesses are increasingly required to walk a fine line between two competing responsibilities: allowing data subjects to exercise their legally-granted privacy rights under laws like the GDPR, and preventing unauthorized access to personal information that could lead to identity theft, fraud, or data breaches. When someone submits a request to do...
What Should Your Purchase Conditions Include? A Legal Checklist for eCommerce Stores
Having clear Purchase Conditions is an essential part of running any successful eCommerce store. This is the case whether you're selling physical products, digital downloads, services, or a combination of things. Purchase Conditions serve as the foundation for the relationship between you and your paying customers. Having well-drafted Purchase Conditions will...
Master Service Agreement vs Terms and Conditions
When businesses provide products or services, whether to individual consumers or other companies, they need to clearly define the rules of engagement. This is where legal agreements come in. Two of the legal agreements most commonly used by businesses include a Master Service Agreement (MSA) and a Terms and Conditions...
Anonymized and Pseudonymized Data: Are They Subject to Data Subject Requests?
Privacy laws like the GDPR and CCPA/CPRA grant data subjects several rights over their personal data, but what happens when that data is anonymized or pseudonymized? Do data subject rights still apply, and if so, to what extent? The legal implications of these two de-identification methods differ fundamentally. Truly anonymized data...
Data Privacy in M&A Transactions: Due Diligence Risks and Red Flags
During mergers and acquisitions (M&A), one company joins or purchases another company. In the process, a lot of information is shared, including the personal information of customers or clients, as well as information on employees. This information-sharing process, called due diligence, raises cyber security and privacy risks for personal data. A number...
How to Deny a Data Subject Request (Legally): Lawful Grounds, Template Language, and Documentation
Under privacy laws like the GDPR and CCPA/CPRA, data subjects can submit formal requests to exercise their user rights over their personal information. But these laws also allow businesses to deny those requests under specific, lawful circumstances. If someone bombards your business with frivolous requests, tries to extort a payout, or...