This is an important point, although I can imagine AI could be trained to spot things that don't belong or are unusual provisions in an NDA. This may be what you're getting at, but it's easy in a contract review to focus on reacting to what's there and it's harder to know what's missing. An NDA is a relatively simple, cookie-cutter types of agreement with widely agreed elements. Other agreements not so much. How would AI figure out what's missing?
51-156 minutes is crazy to review an NDA. If an NDA is well drafted, I can do it in about 10 minutes. If it's a bit of a mess, maybe 30 min. If it's worse than that, I can assess that in about 5 minutes and propose using a better form.
I am a transactional lawyer and I definitely would find value in an application that could issue spot an agreement in seconds. That said, just yesterday I spoke on a panel on the topic of how things can go wrong in a contract. We spent the majority of time talking about the dynamics and challenges that exist outside the agreement in the process of trying to memorialize the parties’ intent in a clear, concise, precise and reasonably complete manner. There are often significant challenges in terms of clearly obtaining the intent and relevant issues from the various stakeholders. And there are dynamics like relative negotiating leverage and psychology or other issues that can drive what the deal will look like regardless of pure legal issues. Also, since one never starts with a blank page, there is the contract template one starts with that must be evaluated against all this – what stays, what goes, what must change and how. Navigating these requires intangible skills, instincts, sensitivity to human dynamics, etc. It’s very much a human endeavor. So a key question is to what extent AI could help with all of these external issues. I have to think that’s much farther down the road. But having help assessing purely legal issues within the document would be a great supplement.
A buddy of mine is a wealth manager. His opinion is that this guy obtained significant ears because he predicted and profited off the '08 crisis, but that overall he's a
a bit of a "clown". As linked below, his main fund has a 10% performance of -6.45% and he's basically always bearish.
Here is a great article by one of the top EU privacy attorneys out there explaining the interplay of the ePrivacy Directive (which governs use of cookies) and the GDPR, which often get confused. https://privacylawblog.fieldfisher.com/2018/gdpr-plus-e-priv...
The cookie banners are required by the ePrivacy Directive, not the GDPR or its predecessor, the Data Protection Directive. ePrivacy has been around for years. Directives are EU-wide “directives” to each member state (country) to enact their own version of it. Therefore, both ePrivacy Directive and the old Data Protection Directive resulted in varied laws from country to country making compliance a challenge. Part of the purpose of the GDPR was to create consistency by replacing a directive with an EU-wide regulation. They have the same plan for ePrivacy and already have published an ePrivacy Regulation for review and comment. The ePrivacy Regulation was supposed to be passed at the same time as the GDPR, but they’re behind so people are expecting it in 2019. There is a recognition that the cookie banners have been a failure, and it is expected the ePrivacy Regulation will get rid of them (but there will still be TBD consent requirements around use of cookies).
There is much confusion. Cookies are governed by the ePrivacy Directive, not GDPR. ePrivacy regulates email, phone, text and other communications – not personal data per se. It prohibits setting a third party cookie on a device without first getting consent. It also requires consent for email marketing, which, when collected in the context of a sale to a customer (and some other restrictions) may be opt-out (this is often called a “soft opt-in”). Otherwise, the consent must be opt in. This is getting confused with the GDPR.
Agreed that the fine for a company like Honda appears very reasonable. My only point is that their behavior was more sloppy than malicious or 'terrible' - and sloppy in a way that many, many companies are sloppy. And this size fine for a small company would be very painful - maybe fatal.
Both in how companies are complying and in the public discourse, I’m seeing a jumbling of ‘consent’ and ‘notice’ that doesn’t align with my understanding of the intent and reading of the law. Under the transparency principle (Art. 5) and disclosure obligations (Arts 13 and 14), there are a variety of things that must be disclosed to a data subject at time of collection. See https://gdpr-info.eu/ for easy access to the law’s text. That’s what privacy polices (increasingly called privacy notices) are generally used for. Many companies are trying to either make you click something to prove they’ve notified you or add language to the notices saying “by using this site, you consent to this privacy policy”, which is a form of ‘consent’ they are deciding to collect themselves. Separately, a controller is supposed to have a legal basis for processing personal data (Art. 6). Consent of the data subject is only one of six legal bases. Legitimate interests of the controller is the other common basis for a business and is expected to be relied up on increasingly since the GDPR makes collecting valid consent harder and it has the downside that it must be tracked and can be withdrawn (which also must be tracked). Consent as a basis is not allowed to be buried in a privacy policy. It must be called out separately with a separate consent for each purpose the data will be used for on an opt-in basis. The policies and these consents all are supposed to be presented in as simple and plain English as possible and it’s encouraged to use layered notices/policies to convey quick summaries with an ability to drill down. To add to the complexity, email marketing is governed by the ePrivacy Directive (responsible for the cookie banners) and requires consent. Each country has its own enactment of ePrivacy so compliance is very complex. Also, under the GDPR, a data subject has an absolute right to object to direct marketing regardless of the basis being relied upon. Much of this flurry of email privacy policy updates and/or consents to marketing are conflating ePrivacy and the GDPR. What I see right now is a bit of a mess as companies try to figure out what compliance looks like and balance full disclosure (transparency) with simple, easy, plain English disclosure.
I'm an attorney leading (from a legal standpoint) a SaaS provider's GDPR compliance effort. There most definitely is an administrative burden (setting aside whether you think that burden is merited). The SaaS provider is acting as a processor for its business customers (so fewer obligations than if it were controller) and there are many admin requirements. The GDPR is an accountability framework and one must be prepared to demonstrate not just compliance but often how one got to the compliance decisions they landed on. One must maintain processing records, implement DPA's and a variety of other things. The GDPR is not a privacy law, it's a data protection and personal rights law, which is much broader.
A UK privacy attorney I know considered 20k records (individuals) to be large scale. I haven't seen much helpful guidance. The WP29 guidance I've read only gives examples at the very extremes of large and small so not too helpful. Practical guidelines will evolve over time.
You are correct as to a DPO, but if he is, say in the US, and subject to GDPR, he must have an EU Representative, who by all indications would be liable for his violations. That's a significant burden if not a practical impossibility for most in his position. Also, if he's transferring personal data from the EU to the US directly from individuals, his only practical way of making that transfer compliant is likely to be privacy shield certified which is not cost free (although he could maybe rely on consent as a derogation, but relying on that has risk). I can think of many things like this that have, if not a hard cost, then a definite cost in time and resources to comply including keeping up with compliance. Could easily be not worth the effort for a single individual.
I'm an attorney who's spent the last year or so working on GDPR compliance for a US SaaS provider some of whose clients have EU employees. My understanding is that it's true that EU enforcement is more in the spirit of "how can we get you compliant?" before doling out fines (vs. the US where it can be more "let's make an example of this company by hitting them with a big fine" and scaring others into compliance). I also agree that the authorities aren't going to be handing out 7 figure fines like candy, both because it's not their historical approach and because they don't have the resources to fight too many of those battles. I want to say I read that the Irish authority's annual budget is around $9M. Theirs is higher than most and Ireland is where most of the US tech giants are established due to tax laws. That said, I think to say that GDPR compliance is simple because it's text is fairly readable or that EU data protection law is simply a matter of transparently respecting people's personal data and not being a bad actor as to privacy is an overstatement. For example, the ePrivacy Directive, most known for prompting all those cookie consent banners, can be incredibly complex to comply with. Each member state has implemented that Directive in different ways. Look at this example https://ico.org.uk/media/action-weve-taken/mpns/2013732/mpn-... where Honda sent out emails to its 350k database simply trying to confirm continued interest in being on their list and got a 13k euro fine for their troubles. I don't know all the facts, but from the document, it doesn't appear that Honda got the fine because they were recalcitrant or being terrible actors. And if the fine is proportionate to the offense (not to the size of the violator), then 13k euro might be levied against a small company for whom it is a significant penalty (not to mention costs, legal fees, etc. in dealing with it).
Agreed. GDPR replaces the current Directive and the various member state laws implementing it. GDPR's requirements are (making up a number) 80% or 90% already required by current laws. It's just that the fines were small. GDPR allows fines of up to 4% of annual revenue for the corporate group. So that's why it's getting so much attention. Large multinationals can't afford to ignore such a fine. The reality is probably that the enforcement authorities would only be able to hand out so many mult-million dollar fines (and fight the ensuing battle) at a time. We'll see what enforcement really looks like over time and that'll indicate how serious this is all taken.
If you'd like an explanation of what this is about, check out the IAPP's Privacy Advisor Podcast - March 29 episode interviewing Matthias Matthieson, who heads the IAB. Basically, they realize that tracking things like user consent in the programmatic online advertising space with all the uses and participants accessing and pooling the data will be pretty much impossible unless an agreed protocol is used for doing so within the advertising ecosystem. For a perspective that says GDPR and programmatic advertising as it currently exists using personal data are not compatible, see Johnny Ryan's two earlier interviews on the same podcast.
I started making sourdough out of law school back in the late 90's when I got Nancy Silverton's book on the topic (La Brea Bakery Founder). I baked bread back then, but found it too exacting and inconsistent. I began again years later after starting a family and almost every weekend we make the amazing sourdough pancakes and waffles in Silverton's book. We maintain a starter that's 60% water and 40% flour by weight. It stays in the fridge during the week. We pull it out Friday morning, feed it midday and night and it's ready to go in the morning a repeat for Sunday. Then it gets a small feeding and goes back in the fridge. It can stay there for up to a few weeks. The pancakes are excellent and light I believe because the yeast digests much of the flour. You don't have that heavy feeling after eating them. The waffles are the best I've had anywhere. I have a one-page spreadsheet that has the feeding recipe and schedule for various batch sizes and the recipes for the waffles and pancakes if anyone is interested. We also make kefir soda from water kefir grains, which is really good. Naturally carbonated soda that's not too sweet and is probiotic.
On internships, there are different contexts. One can clerk at a law firm during law school and be paid for it and a starting attorney at a firm is often arguably paid more than they are worth making them akin to an intern (the firm is investing in cultivating future attorneys for their firm). These are the opportunities I am suggesting are shrinking dramatically, but still exist. The intern context I’m speaking about is in the context of small firms such as my 6 partner transactional firm. California sets out a set of requirements for a unpaid internships to be legal. Essentially, it must be an educational experience where the intern is not really engaged in productive work for the benefit of the business. Our firm is not in the position to create an educational experience for an intern without tangible benefit to the firm. At the same time, the services they might provide to our firm are not important enough to us to merit paying them even the minimum wage (plus deal with other employer hassles and risk). Transactional work (e.g. negotiating a SaaS agreement) is particularly challenging in this regard because it doesn’t require much low-level work as compared to litigation or M&A work. All of that said, I’d be happy to mentor a new attorney in negotiating and drafting commercial agreements in exchange for them say, organizing my forms library. I believe that this would be a mutually beneficial arrangement and I don’t think there is much likelihood of abuse. New attorneys are capable of evaluating the benefits of this arrangement and leaving if it doesn’t work out. Entertainment is a peculiar example where there is unusual desperation to get into the industry and unusual concentration of power in individuals in the industry (and many egos and *holes). I’ve heard of production companies where the interns not only didn’t get paid, but had to pay the company e.g. $30k. I’m sure there are industries where these unpaid internship restrictions provide some important protections and I’ve no illusions about businesses’ capacity to take advantage of people, but in my context, I think it’s preventing what would be a useful arrangement to help address a critical need.
Thanks. Agreed that it's a problem. I was active in leadership in the local bar association and often ran into attorneys straight out of the local law schools (e.g. <6 mos.) who had opened their own practice due to a lack of other options and need to repay their student loans. The old system of training is broken.
I come from a family with several California lawyers (I am a lawyer as well) and see this transition from apprenticeship to law school in my family. My great, great uncle was a lawyer and a judge in a small town in the Bay Area. He never went to law school. His nephew, my grandfather, went to law school, but only needed a 2 year college degree to attend law school. He became the judge in the town after his uncle retired. Both were successful and well regarded professionally.
Reading this article, it’s easy to conflate bar passage success with being an effective lawyer. Law school is probably better training for passing the bar than it is for practicing law. Thus, it wouldn’t surprise me that apprentices have lower passage rates than law school grads. Apprentices are training to practice – not to take tests. It is well understood among lawyers that law school may give you some discipline, some research skills, and some understanding about how to think about fundamental aspects of “the Law”, but that it doesn’t by itself result in being able to practice law. That happens over the course of about the first 5 years of practicing law. Becoming a lawyer or a doctor both take about 8-9 years, but with law, you do most of it out in practice. So in this sense, all lawyers are apprentices. Another thing that illustrates this point is the fact that a lawyer’s effectiveness has much less to do with the quality of their law school than is generally thought. I know many excellent attorneys who attended local law schools here in San Diego that do not rank well. What they did in their first 5 years (and other factors) mattered more than law school.
I see the arc of the profession as one that used to be more tuned toward apprenticeship in the context of a much slower overall pace of business and life toward one where it is increasingly hard to access that critical one-the-job training. Historically, clients would essentially subsidize the training of new associate attorneys, but, particularly since the belt tightening post-2008, clients increasingly refuse to do so and many law grads are left to figure it out themselves. Some have rules that no attorneys with e.g. less than 3 years’ experience are allowed to work on their matters. Another challenge are the strict laws in California on unpaid internships. I would be happy to provide training to a new lawyer in exchange for some unpaid help and know many new attorneys who would jump at the chance, but that is not allowed in California.
In graduate school, I took a class on evolutionary biology. One of the principles put forth was that women (think cave women) evolved to focus on seeking a mate that provided time and resources because women are more focused on the long-term reproduction strategy of investing in their offspring and want a mate to help maximize their success (i.e. that offspring surviving to reproduce). Both men and women were shown to engage in both short and long term reproduction strategies of sorts. Men sleeping around (short term) and supporting a child (long term). Women supporting a child with a mate's help (long term) and sneaking out on mate to have sex with genetically superior mate (short term). One of the supporting studies showed that in a list of things that would most anger a man or women relative to their mate, men rated sexual infidelity as number one (this is in part because men have paternal uncertainty and their worst outcome is investing in the long term strategy of raising another male's child). Women listed sexual infidelity as somewhere in the top few, but number one was their mate spending time/money/resources on another woman. For example, imagining their guy taking another woman out to dinner, spending time and thought on her, buying her a gift, etc. upset them more than the thought of him simply have sex with a women he wasn't otherwise invested in. Within this theory, an expensive diamond communicates that the male is making a large investment and communicates to other women that the woman with the diamond is worthy of that large investment. In real life, women of course range from "don't care or think that way" or "achieve that validation through non-material means" to "totally obsessed with sucking material goods and services from a man and showing that off to other people (mostly women). It was an interesting course and study.
I know someone whose husband wrote a business leadership book (a crowded category). The book hit the New York Times best seller list for a couple weeks. However, my impression was that he simply paid a publicist (or agent or whatever) who was able to make that happen in some narrow subcategory of the list for 2 weeks. The sole purposes was that on their next printing, they could add the "New York Times Bestseller" badge to the cover. It sounded like a game.
The only thing I'd predict is that Avis will screw up Zipcar in some way. They'll raise prices or make the service worse or both. The major car rental companies for years have been owned by major car manufacturers and, in part, serve as backdoor dealerships. Ever wonder how the Ford Taurus was the top selling car in America? I wonder if and how Zipcar will be modified to support that model.
I think part of it is that groupon got started at a time of peak desperation for retailers. They were desperate to try anything. They may still be desperate, but wiser.
I think its a fundamental flaw of the public company ecosystem. Management is driven to have a very short-term, myopic view of shareholder value (i.e. stock price quarter to quarter). This was made much worse by the rise in profile of analysts in the late 90's tech boom with increased focus on short term earnings guidance. Perhaps eventually Zuckerberg will be replaced by a more market-savvy CEO. Also being public will force a giant set of obligations and priorities that has nothing to do with their offerings (shareholder proxies, disclosure, class action derivative suits, SOX compliance, investor relations) and will suck huge resources.
Being public will make FB a poorer company and service.
As a side note, I love how reporters of newly public companies quote risk factors from a 10-k and present them as some significant revelation of a skeleton in the closet. Risk factors are required disclosure and attorneys stuff them with horrible sounding proclamations that often are really just stating the obvious when you really read them. They are cheap insurance for the public company - not sure anyone declines to buy a stock based on risk factors but the company can say "I told you" in the event of certain shareholder suits.
I would qualify this. Note the recent implosion of the law firm Dewey Leboeuf. It grew very large through mergers and by luring lateral hires with multi-million dollar guarantees which it ultimately couldn't support. Many firms have become too bloated and have failed. More failures are expected. But you're right, the personal liability and ethical and other constraints on lawyers does induce risk aversion among law firms relative to bankers. However, the big catch is that the downside of lawyers and accountants being too conservative is not as acute as for investment banks where being too conservative has a very real and deep impact on markets, credit, liquidity, etc. So we (society, politicians, etc.) have tinkered with their regulations to try to improve markets, economy, etc. such as the repeal of Glass Steagall, etc. and we suffer the consequences.
I agree that change for change sake is frustrating, but I jumped from Office 2003 to 2010 and a year later I still hate it. It's not just a matter of it being different. It's demonstrably worse. Things that took 1 click now take 3 or more. I also went from XP to Windows 7 and I can't stand it either. Why do I need libraries and all the confusion that comes from a library location and a 'real' location?
It seems like there are easy improvements to search by ratings they could make. If I am browsing for a new book, I'd like to be able to search by number of reviews alone. Anything with more than 500 or so reviews is probably worth taking a look at. I also would like to filter out items with less than 'x' reviews or search by a ratio of number of reviews to the number of stars. This might hurt products trying to get off the ground, but I'd really like it as a user.
> In most cases large retailers force their vendors to cover the costs of returned merchandise that they can't resell (due to opened packaging etc).
Yes, and this can increase costs to the consumer. Cost is cost. It has to be born by someone in the chain and it's pushed on to the consumer if possible (granted in the competitive retail space it's harder to make consumers absorb costs).