Blog - Page 68

Legal articles in easy to understand language.

Transfer Impact Assessment (TIA)

The EU General Data Protection Regulation (GDPR) imposes strict rules on transferring personal data out of the European Economic Area (EEA). Before you make an international data transfer by sharing personal data with another organization outside the EEA, you must ensure that the organization can protect the data to EU-equivalent standards. A...

GDPR: Don't Use Pre-Ticked Boxes for Cookies

When the General Data Protection Regulation (GDPR) passed in 2016, websites started putting up cookie banners in preparation for its 2018 enforcement date. But many of these cookie banners didn't actually comply with the new consent thresholds imposed by the GDPR. Nearly five years have passed, and most cookie consent solutions...

Why Your Privacy Policy Needs to Mirror Your Privacy Practices

Laws such as the General Data Protection Regulation (GDPR) in Europe and the California Consumer Privacy Act (CCPA/CPRA) in the U.S. require your business to have a Privacy Policy. A Privacy Policy explains how you deal with the personal data of customers. The Federal Trade Commission (FTC) issued a warning to...

Google's "Data Disclosure" Policy

In January 2021, Google will be providing additional information to Chrome users when they browse extensions and other products in the Chrome Web Store. This information will include a detailed description of how each extension collects, uses, and shares user data. Google is also cracking down on how Chrome products collect...

Is a Terms and Conditions Agreement Legally Required?

While not legally required, a Terms and Conditions agreement (T&C) is highly recommended to have on your business website for a number of important reasons. Not only will having this agreement help your users understand the rules for using your website/service, but the T&C will also work to limit your...

Swedish Protective Security Act

The Swedish Protective Security Act (PSA) received an overhaul recently. Among other changes, the PSA now has a broader scope, which includes non-Swedish companies. The PSA applies to both public and private organizations engaged in "security-sensitive activities" that are important to Sweden's national security and infrastructure. It covers a broad range...