Blog: Legal Requirements

Page 3

Dual Licensing vs. Open Core: Legal Distinctions Every Business Should Understand

Building a sustainable business around open source software is a balancing act. You want the massive community adoption and collaborative power that comes with an open license, but you also need a clear path to generating revenue. Dual licensing and open core are two popular license models businesses use to square...

The Legal Risks of "Source-Available" Licenses: SSPL, BSL, and Beyond

Source-available licenses allow developers to read and modify a software's source code, but they also impose restrictions on how the software can be used, which disqualify them as true open-source licenses. Companies typically adopt source-available license models to stop cloud providers from reselling their work without contributing back meaningfully. And while...

Contributor License Agreements (CLAs): Friend, Foe, or Necessary Evil?

Contributor License Agreements (CLAs) are a type of licensing agreement that governs how people contribute to open-source software or developments. They can help intellectual property rights between developers and distributors to be clarified, and can ensure that contributed content is clearly licensed. However, they can also leave developers vulnerable to further...

The Rise of Class Actions in Data Protection: What Companies Should Expect

Class action lawsuits are on the rise, and laws such as the European Union's (EU) Directive 2020/1828 make it easier for consumers to bring collective action against companies that breach EU privacy and data protection laws. This article explains what data protection class actions are, the role of Directive 2020/1828, common...

A Privacy Officer's Guide to Building Region-Specific Privacy Policies

If you're a Privacy Officer or compliance lead at a growing business with a global reach, there are a number of drawbacks to a one-size-fits-all Privacy Policy. Customers, regulators, and even app stores expect clear, region-specific disclosures that match the data protection rights of local users. Failing to do so creates...

Identity Verification Standards Under GDPR vs. CCPA/CPRA

If your business collects customer data, you're probably familiar with data subject (customer) requests. They often run along the lines of "I want to see the data you hold on me," or "I want you to delete everything you have on me." These requests are common, and it's your job to...