Blog - Page 7
Legal articles in easy to understand language.
The Legal Risks of "Source-Available" Licenses: SSPL, BSL, and Beyond
Source-available licenses allow developers to read and modify a software's source code, but they also impose restrictions on how the software can be used, which disqualify them as true open-source licenses. Companies typically adopt source-available license models to stop cloud providers from reselling their work without contributing back meaningfully. And while...
How to Handle California Consumer Data Requests (CCPA Rights Management)
To handle data requests in accordance with the California Consumer Privacy Act (CCPA), your business needs clear internal procedures, verified request channels, and documented proof that it has complied with the 45-day response deadline. The CCPA gives California residents five enforceable consumer rights, and your business must be able to receive,...
Contributor License Agreements (CLAs): Friend, Foe, or Necessary Evil?
Contributor License Agreements (CLAs) are a type of licensing agreement that governs how people contribute to open-source software or developments. They can help intellectual property rights between developers and distributors to be clarified, and can ensure that contributed content is clearly licensed. However, they can also leave developers vulnerable to further...
The Rise of Class Actions in Data Protection: What Companies Should Expect
Class action lawsuits are on the rise, and laws such as the European Union's (EU) Directive 2020/1828 make it easier for consumers to bring collective action against companies that breach EU privacy and data protection laws. This article explains what data protection class actions are, the role of Directive 2020/1828, common...
What to Do When You Receive a DSR via Third Party (Like Privacy Tools or Brokers)
Responding to a data subject request (DSR) has become a routine obligation under privacy laws like the GDPR and the CCPA/CPRA. But when those requests come through third parties or privacy tools, it often raises questions about how to handle verification correctly. While most privacy laws allow third parties to act...
A Privacy Officer's Guide to Building Region-Specific Privacy Policies
If you're a Privacy Officer or compliance lead at a growing business with a global reach, there are a number of drawbacks to a one-size-fits-all Privacy Policy. Customers, regulators, and even app stores expect clear, region-specific disclosures that match the data protection rights of local users. Failing to do so creates...