So, as the first tech hire/partner, what can we do to protect our users?
- Expire non-critical data after 30 - 90 days, e.g. activity data, not account data.
- When feasible, have the client encrypt the really private user data, only store encrypted blobs on the server (Protonmail does this).
- Send out a positively worded, subtle email notice to warn the more savvy users of a pending acquisition, as soon as that news is no longer private. Let them disseminate the real sitrep on social media and in the news. We did build a community, after all.
- Propose a data architecture update for great efficiency, in which redundant and superfluous data is cleaned and aggregated, before the big handover.
Are there any other suggestions? I am particularly curious if the laws of any one user's country could be used to complicate or thwart a bulk handover of private user data to a new owner. Europeans, I'm looking at you for advice.