This is an important point, although I can imagine AI could be trained to spot things that don't belong or are unusual provisions in an NDA. This may be what you're getting at, but it's easy in a contract review to focus on reacting to what's there and it's harder to know what's missing. An NDA is a relatively simple, cookie-cutter types of agreement with widely agreed elements. Other agreements not so much. How would AI figure out what's missing?
51-156 minutes is crazy to review an NDA. If an NDA is well drafted, I can do it in about 10 minutes. If it's a bit of a mess, maybe 30 min. If it's worse than that, I can assess that in about 5 minutes and propose using a better form.
I am a transactional lawyer and I definitely would find value in an application that could issue spot an agreement in seconds. That said, just yesterday I spoke on a panel on the topic of how things can go wrong in a contract. We spent the majority of time talking about the dynamics and challenges that exist outside the agreement in the process of trying to memorialize the parties’ intent in a clear, concise, precise and reasonably complete manner. There are often significant challenges in terms of clearly obtaining the intent and relevant issues from the various stakeholders. And there are dynamics like relative negotiating leverage and psychology or other issues that can drive what the deal will look like regardless of pure legal issues. Also, since one never starts with a blank page, there is the contract template one starts with that must be evaluated against all this – what stays, what goes, what must change and how. Navigating these requires intangible skills, instincts, sensitivity to human dynamics, etc. It’s very much a human endeavor. So a key question is to what extent AI could help with all of these external issues. I have to think that’s much farther down the road. But having help assessing purely legal issues within the document would be a great supplement.
A buddy of mine is a wealth manager. His opinion is that this guy obtained significant ears because he predicted and profited off the '08 crisis, but that overall he's a
a bit of a "clown". As linked below, his main fund has a 10% performance of -6.45% and he's basically always bearish.
Here is a great article by one of the top EU privacy attorneys out there explaining the interplay of the ePrivacy Directive (which governs use of cookies) and the GDPR, which often get confused. https://privacylawblog.fieldfisher.com/2018/gdpr-plus-e-priv...
The cookie banners are required by the ePrivacy Directive, not the GDPR or its predecessor, the Data Protection Directive. ePrivacy has been around for years. Directives are EU-wide “directives” to each member state (country) to enact their own version of it. Therefore, both ePrivacy Directive and the old Data Protection Directive resulted in varied laws from country to country making compliance a challenge. Part of the purpose of the GDPR was to create consistency by replacing a directive with an EU-wide regulation. They have the same plan for ePrivacy and already have published an ePrivacy Regulation for review and comment. The ePrivacy Regulation was supposed to be passed at the same time as the GDPR, but they’re behind so people are expecting it in 2019. There is a recognition that the cookie banners have been a failure, and it is expected the ePrivacy Regulation will get rid of them (but there will still be TBD consent requirements around use of cookies).
There is much confusion. Cookies are governed by the ePrivacy Directive, not GDPR. ePrivacy regulates email, phone, text and other communications – not personal data per se. It prohibits setting a third party cookie on a device without first getting consent. It also requires consent for email marketing, which, when collected in the context of a sale to a customer (and some other restrictions) may be opt-out (this is often called a “soft opt-in”). Otherwise, the consent must be opt in. This is getting confused with the GDPR.
Agreed that the fine for a company like Honda appears very reasonable. My only point is that their behavior was more sloppy than malicious or 'terrible' - and sloppy in a way that many, many companies are sloppy. And this size fine for a small company would be very painful - maybe fatal.
Both in how companies are complying and in the public discourse, I’m seeing a jumbling of ‘consent’ and ‘notice’ that doesn’t align with my understanding of the intent and reading of the law. Under the transparency principle (Art. 5) and disclosure obligations (Arts 13 and 14), there are a variety of things that must be disclosed to a data subject at time of collection. See https://gdpr-info.eu/ for easy access to the law’s text. That’s what privacy polices (increasingly called privacy notices) are generally used for. Many companies are trying to either make you click something to prove they’ve notified you or add language to the notices saying “by using this site, you consent to this privacy policy”, which is a form of ‘consent’ they are deciding to collect themselves. Separately, a controller is supposed to have a legal basis for processing personal data (Art. 6). Consent of the data subject is only one of six legal bases. Legitimate interests of the controller is the other common basis for a business and is expected to be relied up on increasingly since the GDPR makes collecting valid consent harder and it has the downside that it must be tracked and can be withdrawn (which also must be tracked). Consent as a basis is not allowed to be buried in a privacy policy. It must be called out separately with a separate consent for each purpose the data will be used for on an opt-in basis. The policies and these consents all are supposed to be presented in as simple and plain English as possible and it’s encouraged to use layered notices/policies to convey quick summaries with an ability to drill down. To add to the complexity, email marketing is governed by the ePrivacy Directive (responsible for the cookie banners) and requires consent. Each country has its own enactment of ePrivacy so compliance is very complex. Also, under the GDPR, a data subject has an absolute right to object to direct marketing regardless of the basis being relied upon. Much of this flurry of email privacy policy updates and/or consents to marketing are conflating ePrivacy and the GDPR. What I see right now is a bit of a mess as companies try to figure out what compliance looks like and balance full disclosure (transparency) with simple, easy, plain English disclosure.
I'm an attorney leading (from a legal standpoint) a SaaS provider's GDPR compliance effort. There most definitely is an administrative burden (setting aside whether you think that burden is merited). The SaaS provider is acting as a processor for its business customers (so fewer obligations than if it were controller) and there are many admin requirements. The GDPR is an accountability framework and one must be prepared to demonstrate not just compliance but often how one got to the compliance decisions they landed on. One must maintain processing records, implement DPA's and a variety of other things. The GDPR is not a privacy law, it's a data protection and personal rights law, which is much broader.
A UK privacy attorney I know considered 20k records (individuals) to be large scale. I haven't seen much helpful guidance. The WP29 guidance I've read only gives examples at the very extremes of large and small so not too helpful. Practical guidelines will evolve over time.
You are correct as to a DPO, but if he is, say in the US, and subject to GDPR, he must have an EU Representative, who by all indications would be liable for his violations. That's a significant burden if not a practical impossibility for most in his position. Also, if he's transferring personal data from the EU to the US directly from individuals, his only practical way of making that transfer compliant is likely to be privacy shield certified which is not cost free (although he could maybe rely on consent as a derogation, but relying on that has risk). I can think of many things like this that have, if not a hard cost, then a definite cost in time and resources to comply including keeping up with compliance. Could easily be not worth the effort for a single individual.
I'm an attorney who's spent the last year or so working on GDPR compliance for a US SaaS provider some of whose clients have EU employees. My understanding is that it's true that EU enforcement is more in the spirit of "how can we get you compliant?" before doling out fines (vs. the US where it can be more "let's make an example of this company by hitting them with a big fine" and scaring others into compliance). I also agree that the authorities aren't going to be handing out 7 figure fines like candy, both because it's not their historical approach and because they don't have the resources to fight too many of those battles. I want to say I read that the Irish authority's annual budget is around $9M. Theirs is higher than most and Ireland is where most of the US tech giants are established due to tax laws. That said, I think to say that GDPR compliance is simple because it's text is fairly readable or that EU data protection law is simply a matter of transparently respecting people's personal data and not being a bad actor as to privacy is an overstatement. For example, the ePrivacy Directive, most known for prompting all those cookie consent banners, can be incredibly complex to comply with. Each member state has implemented that Directive in different ways. Look at this example https://ico.org.uk/media/action-weve-taken/mpns/2013732/mpn-... where Honda sent out emails to its 350k database simply trying to confirm continued interest in being on their list and got a 13k euro fine for their troubles. I don't know all the facts, but from the document, it doesn't appear that Honda got the fine because they were recalcitrant or being terrible actors. And if the fine is proportionate to the offense (not to the size of the violator), then 13k euro might be levied against a small company for whom it is a significant penalty (not to mention costs, legal fees, etc. in dealing with it).
Agreed. GDPR replaces the current Directive and the various member state laws implementing it. GDPR's requirements are (making up a number) 80% or 90% already required by current laws. It's just that the fines were small. GDPR allows fines of up to 4% of annual revenue for the corporate group. So that's why it's getting so much attention. Large multinationals can't afford to ignore such a fine. The reality is probably that the enforcement authorities would only be able to hand out so many mult-million dollar fines (and fight the ensuing battle) at a time. We'll see what enforcement really looks like over time and that'll indicate how serious this is all taken.
If you'd like an explanation of what this is about, check out the IAPP's Privacy Advisor Podcast - March 29 episode interviewing Matthias Matthieson, who heads the IAB. Basically, they realize that tracking things like user consent in the programmatic online advertising space with all the uses and participants accessing and pooling the data will be pretty much impossible unless an agreed protocol is used for doing so within the advertising ecosystem. For a perspective that says GDPR and programmatic advertising as it currently exists using personal data are not compatible, see Johnny Ryan's two earlier interviews on the same podcast.
I started making sourdough out of law school back in the late 90's when I got Nancy Silverton's book on the topic (La Brea Bakery Founder). I baked bread back then, but found it too exacting and inconsistent. I began again years later after starting a family and almost every weekend we make the amazing sourdough pancakes and waffles in Silverton's book. We maintain a starter that's 60% water and 40% flour by weight. It stays in the fridge during the week. We pull it out Friday morning, feed it midday and night and it's ready to go in the morning a repeat for Sunday. Then it gets a small feeding and goes back in the fridge. It can stay there for up to a few weeks. The pancakes are excellent and light I believe because the yeast digests much of the flour. You don't have that heavy feeling after eating them. The waffles are the best I've had anywhere. I have a one-page spreadsheet that has the feeding recipe and schedule for various batch sizes and the recipes for the waffles and pancakes if anyone is interested. We also make kefir soda from water kefir grains, which is really good. Naturally carbonated soda that's not too sweet and is probiotic.
On internships, there are different contexts. One can clerk at a law firm during law school and be paid for it and a starting attorney at a firm is often arguably paid more than they are worth making them akin to an intern (the firm is investing in cultivating future attorneys for their firm). These are the opportunities I am suggesting are shrinking dramatically, but still exist. The intern context I’m speaking about is in the context of small firms such as my 6 partner transactional firm. California sets out a set of requirements for a unpaid internships to be legal. Essentially, it must be an educational experience where the intern is not really engaged in productive work for the benefit of the business. Our firm is not in the position to create an educational experience for an intern without tangible benefit to the firm. At the same time, the services they might provide to our firm are not important enough to us to merit paying them even the minimum wage (plus deal with other employer hassles and risk). Transactional work (e.g. negotiating a SaaS agreement) is particularly challenging in this regard because it doesn’t require much low-level work as compared to litigation or M&A work. All of that said, I’d be happy to mentor a new attorney in negotiating and drafting commercial agreements in exchange for them say, organizing my forms library. I believe that this would be a mutually beneficial arrangement and I don’t think there is much likelihood of abuse. New attorneys are capable of evaluating the benefits of this arrangement and leaving if it doesn’t work out. Entertainment is a peculiar example where there is unusual desperation to get into the industry and unusual concentration of power in individuals in the industry (and many egos and *holes). I’ve heard of production companies where the interns not only didn’t get paid, but had to pay the company e.g. $30k. I’m sure there are industries where these unpaid internship restrictions provide some important protections and I’ve no illusions about businesses’ capacity to take advantage of people, but in my context, I think it’s preventing what would be a useful arrangement to help address a critical need.
Thanks. Agreed that it's a problem. I was active in leadership in the local bar association and often ran into attorneys straight out of the local law schools (e.g. <6 mos.) who had opened their own practice due to a lack of other options and need to repay their student loans. The old system of training is broken.