Key word is "may" be completely irrelevant! Of course, if you're providing an Excel of customer data, it will be relevant if the user is in the EU. But still, consent won't be relevant in that context.
User content may include personal data but may also not...so in some senses, better to include totality of use cases in a non-data protection related document.
GDPR and indeed any data protection laws may well be completely irrelevant in the context of Microsoft's services. Even if relevant, consent is unlikely to be a relevant as a processing basis under GDPR in the context of usage of MS services. Performance of contract or legitimate interests much more likely to be relevant...
To an extent, think about vested interests here. Mozilla has little to gain by showcasing how clear a rival's new service agreement is!
The AI services section seems pretty clear in terms of limiting the use cases of user content:
"iv. Use of Your Content. As part of providing the AI services, Microsoft will process and store your inputs to the service as well as output from the service, for purposes of monitoring for and preventing abusive or harmful uses or outputs of the service."
Admittedly, I haven't read other parts to understand the full picture though.
But a unique identifier doesn't necessarily identify a living person, particularly in isolation. It's just that it's frequently associated with a load of additional information that could eventually be used to identify someone (think advertising cookies when associated with a load of browsing data). So you can't escape from scope by saying you're using a unique ID rather than a name.
IP addresses are slightly different because that address can be used to identify the subscriber in certain cases (who in turn may or may not be an individual).
Love the contrast between the title and the text. This isn't even about GDPR, it's about a completely different piece of legislation, the E-Privacy Directive. This is completely agnostic on personal data and so the post is largely flawed.
Even if you're not dealing with any personal data, if you're placing a cookie (or doing anything analogous device fingerprinting etc) you are in scope of the Directive and need consent, irrespective of GDPR.
The new E-Privacy Regulation is looking to implement an exception to consent for analytics but that would have providers like Google Analytics out of scope. Anyway, it's stuck in the mud at present...
I wouldn't trust any article that purports to be about GDPR that uses the term 'PII' a term which itself isn't anywhere to be seen in the regulation!
In reality an IP address is generally not PII, but it may be personal data - the case is Breyer which was decided on pre-GDPR law but still relevant. If you could use reasonable means to identify someone from the IP address then it will be personal data. I don't really agree with the outcome of the case because it implied it was easy to contact an ISP to get them to disclose details of the subscriber information associated with the IP address. In the UK at least it would require cause, and a court order.
No, they're implying that there's been a failure by pro-leavers to acknowledge that many of these roles have been in the recent past been performed by immigrants from Europe.
Now with the UK's departure, employers may struggle to fill vacancies (and indeed it appears they have been - see link below), so the poster was sarcastically suggesting that they can't wait to see pro-leavers performing these tasks because it seems like in many cases UK nationals aren't willing to perform these types of roles.
The nature of the role is irrelevant and the poster wasn't suggesting that pro-leavers should be subject to degradation!
The concept of processing necessary for the performance of a contract is interpreted extremely narrowly by data protection law. Rightly so, because otherwise it would give entities far too much latitude to stuff as many different processing activities as possible within that ground, even though certain processing activities aren't at all necessary to provide the service.
With Grindr, they only need to process data to provide the service by making it available to you and to other users. What they definitely don't need to do in order to provide the core service is to share your data with third parties who can then use it for their own purposes.
Any argument that the processing is necessary because it's an ad-funded service would not be acceptable under data protection law.
On that basis, performance of a contract would not be a relevant ground. You're also looking at e-Privacy Directive considerations in the EU where either a cookie or similar is essential to provide the service, or you need consent. Similar for location data, you will generally need consent.
So you not only have GDPR issues but also e-Privacy Directive issues where your processing grounds are actually incredibly limited anyway.
I would strongly recommend assignment to the company. As you allude to, any investor will want to see core IP in the ownership of the company, and to not have this, even in the presence of a cast-iron license agreement, will be off putting.
Having said that, you could mitigate through an arms length license agreement but it would have to be water-tight and obviously there's a tension between protecting your friend's patent and protecting the company's rights in that patent. The more it protects the company, the less confidence your friend would have (perpetual grant of rights vs time-limited, termination triggers etc).
You could also always start off with a license to give the company confidence, but if you are subsequently looking to fundraise and see investors are being put off, look to assign the patent to the company. The license could even incorporate an option to purchase to give the company further certainty that for the right price it could acquire the rights.
For sure - that was my thinking on the alternative scenario. If that happens then that certainly changes the picture somewhat although my other points remain true around what Grammarly would decide to do with that content I would say!
a) at what point is content uploaded to Grammarly. Is it uploaded automatically as you input (if you have the Chrome extension), or is it uploaded only where a user activates the extension. Clearly if the latter, then no one is going to be using Grammarly to check their code so no issue. Even if the former, it's still debatable whether or not the terms of use would even grant rights. It's still limited to content 'in connection with the use of the services or software' - content uploaded passively without any user action (aside from the initial act of installing the extension) doesn't fall neatly into that bracket.
b) The likelihood of Grammarly taking a decision to incorporate third party code into their service or to improve their service on the basis of the license granted in the terms of use is extremely slim. The reputational hit if it were to come out, and the lack of legal certainty over the status of the third party code would both act as a strong disincentive to do this.
"in connection with the provision of the Software and the Services and to improve the algorithms underlying the Software and the Services."
This on the face of it wouldn't extend to selling your content. Obviously terms of use can change, but a material change like granting Grammarly the right to sell content would usually oblige Grammarly to notify users and at that point users could take a decision to stop using the service.
Also, realistically any proposal to sell data would make use of the service for great swathes of enterprise users a complete non-starter.