Recent News & Events


Posted on: May 23, 2022

NDAs and other forms of confidentiality agreements are ubiquitous in business for both narrow legal reasons and broader operational reasons. From a legal viewpoint, such contracts are key administrative safeguards for maintaining a party’s proprietary information as “trade secrets” as well as the legal benefits that come with that designation. More generally, confidentiality agreements set expectations for a party’s processing and use of information that the other party considers confidential, whether due to the information’s trade secret status or other legally significant classifications.

Recently, information classification methods have matured in response to the rising prominence of information technology and intangible assets, like data, in the economy. But, that maturation is far from complete, and business leaders continue to struggle with outdated conceptual tools for handling transactions that involve novel and nuanced data issues.

Such data-centric transactions involve new risks associated with rapid technological progress. For example, the widespread use of electronic communications and the digitization of records have made information vulnerable to negligent or malicious transfers to unauthorized third parties, some of which may be anonymous or located in foreign jurisdictions. Likewise, advancements in machine learning have made it possible to gleam new insights from data, potentially increasing the value of and risk profile of such data. Despite developments like these, confidentiality agreements continue to be written in virtually the same form as similar contracts were written before widespread use of the Internet.

While some may dismiss that slow response as just another example of the law’s sluggish adaptation to technological change, attorneys have a duty to their clients to adjust traditional legal tools to fit modern business needs. Failure to do so risks both client dissatisfaction and a breach of the attorney’s ethical duties. In this sense, a basic understanding of data issues and how to respond to them is critical to the attorney’s provision of competent legal services while handling data-centric transactions.

With that requirement in mind, this post identifies some useful approaches attorneys can take to protect their client’s interests in data while drafting and negotiating contracts. Specifically, this post identifies ten approaches to handling data issues that every deal lawyer should have in their arsenal. So, dust off those old contract forms and see if your practice can benefit from any of the following approaches.

Ten approaches to consider when advising clients on data-centric transactions include:

  1. Limiting the Client’s Unnecessary Exposure to High-Risk Data: Consider limiting your client’s unnecessary exposure to high-risk data by explicitly stating the other party’s obligation to not provide your client (or its representatives) with unwanted data sets. That type of provision is meant to help the client to completely avoid legal risks associated with certain kinds of data by protecting the client from receiving that data in the first place. It is commonly used to target unwanted personal data that exposes the client to onerous compliance obligations and security breach liability it is not prepared for.
  2. Clarifying General Data Security Standards with Detailed Protocols: Consider clarifying typical data use and processing standards by explicitly listing minimum data management and security protocols. Such protocols are meant to provide objective steps towards achieving subjective standards typically used in contracts (e.g., “reasonable measures” or “industry best practices”). It is commonly used when the other party lacks internal expertise to keep up with the latest best practices for data management and legal compliance.
  3. Restricting the Other Party’s Authority to Use Data with a Narrow Purpose Limitation: Consider restricting the other party’s authority to use sensitive data in unanticipated and undesirable ways by adding a narrow purpose limitation to applicable permissions and licenses. A purpose limitation is meant to add another layer of protection over traditional use limitations, like constraints on who can process the data and where, when and how they may do so. It is commonly used where the other party is likely to use the client’s data for commercial purposes (e.g., to create a commercial data set for licensing or resale) or other controversial purposes (e.g., building detailed end-user profiles), especially if such purposes are not necessary to achieve the transaction objectives.
  4. Supplementing the Client’s Due Diligence with Robust Warranties and Disclosures: Consider supplementing your client’s due diligence by requiring detailed representations, warranties, and covenants that signal the other party’s appropriate level of sophistication regarding data management and security. This approach is meant to efficiently identify red flags by requiring the other party to push back on the warranty language in negotiations, which in turns triggers a conversation about what sorts of disclaimers the other party must state and what types of promises that party can make. It is often used when negotiating from the other party’s form contract that includes minimum (if any) data processing warranties.
  5. Mitigating Data Security Breach Risks with a Negotiated Response Plan: Consider mitigating the risks associated with data security breaches by outlining each party’s roles, responsibilities and requirements for joint response efforts. The response plan is meant to give the parties a clear course of action if faced with a breach, when the parties will otherwise be dealing with high-stake, time-sensitive decisions and conflicting interests. It is commonly used where the client stands to lose a lot from a fumbled response to the breach, especially from a branding and compliance perspectives.
  6. Allocating Data Security Breach Risks by Adjusting Traditional Contract Mechanisms: Consider allocating the risks associated with data security breaches by adjusting traditional risk allocation mechanisms in contracts. These adjustments are meant to adapt risk allocation mechanisms (e.g., damage exclusions, liability caps, and indemnification) to fit the unique nature of rights in data vis-à-vis “true” forms of intellectual property that contracts typically address (i.e., copyrights, patents, and trademarks). It is commonly used when data risks are a primary concern for the transaction.
  7. Empowering Data Subjects and Other Client Stakeholders to Enforce Beneficiary Rights: Consider empowering data subjects and other relevant third parties by adding terms for their direct benefit. This type of provision is meant to create additional incentives for the other party to comply with its contractual data processing and use obligations. It is commonly used where the client incorporates strong privacy protections into its corporate values and branding, and the client wants its contracts to reflect that stance.
  8. Mapping Out an Exit Route to Safeguard the Client’s Brand: Consider giving the client an exit route in the event the other party is the subject of negative publicity around its handling of data by specifying broad reputation-focused causes for contract termination. That out is meant to mitigate damages to the client’s brand and goodwill if the other party goes viral for all the wrong reasons, like selling sensitive personal data for discriminatory purposes. It is commonly used when the client engages with a company that does not seem to share the client’s commitment to privacy.
  9. Tying Up Loose Ends by Requiring a Certified Data Retention Disclosure: Help your client get closure following the contract’s termination by requiring a full accounting of retained data. This provision is meant to give your client a full record of retained data and the opportunity to contest reasons for the other party’s retention, such as retention for technical or compliance reasons. It is commonly used where the other party refuses to agree to returning or destroying data after termination without qualification.
  10. Easing the Burden of Contract Enforcement with Built-In Evidentiary Presumptions: Supplement traditional dispute resolution provisions by clearly stating each party’s evidentiary burdens regarding claims and defenses based on data processing and use. This type of provision is meant to act as a deterrent by leaving no question as to the other party’s responsibility for proving its compliance with the contract. It is commonly used when the other party is an individual or small company and formal dispute resolution is unlikely to be cost-effective.

The above approaches are just some of the ways to tackle novel and nuanced data issues in contract drafting and negotiations. Keep in mind that most contracts today will have some data issue concerns, whether those have to do with the confidential elements of the parties’ relationship or possible use of regulated personal data. Take care to review those issues with your clients and the determine how changing information technology should inform your approach.

 

This post is not meant to be and is not legal advice. Consult an experienced attorney before applying these approaches to your specific situation.

© 2022 Parker N. Smith.

About the Author...

Parker N. Smith 
CoreServe Legal, LLC
Technology Law Committee Chair