Privacy and AI Risks in Transactions
An incident response plan has little value when nobody knows how to carry it out during a real breach. Charlyn Ho recommends testing the plan so each person knows who to contact and what action to take.
How Smart Companies Structure Tech Deals
AI is moving faster than your legal foundation can keep up. Rikka helps growing tech companies deploy AI, protect data, and close deals without creating legal risk they didn't see coming.
In this episode of AI-Savvy Lawyer, Rikka founder Charlyn Ho joins host Lisa Mosby to explain how smart companies structure technology deals without creating risks that surface later.
They discuss why privacy compliance is never a one-time achievement and how AI tools add new privacy and cybersecurity risks.
They also cover why third-party vendors are often where the greatest exposure lies, what separates a working incident response plan from one that simply sits in a drawer, and how technical architecture can shape a technology contract.
Finally, they discuss open source licensing and integration clauses, two areas that can create unexpected problems for growing technology companies.
Transcript
Privacy Compliance Is an Ongoing Process
Lisa:
Welcome to AI-Savvy Lawyer with Charlyn Ho, founder of Rikka Law Group.
Charlyn is a technology transactions and data privacy attorney who advises companies on artificial intelligence governance, complex technology agreements, and legal frameworks for deploying emerging technologies responsibly.
I'm Lisa Mosby, and today we're talking about how smart companies structure technology deals without creating risks that show up later.
Thank you so much for joining me, Charlyn.
Charlyn:
Thank you, Lisa. It's my pleasure.
Lisa:
Why is it so difficult to build a meaningful privacy program if a company doesn't know where its data lives or how it moves?
Charlyn:
That's a great question, and it's something we help our clients think through all the time.
Many people think of privacy as a one-time achievement. They say, “I'm GDPR compliant,” referring to Europe's General Data Protection Regulation. Or they say, “I'm HIPAA compliant,” referring to the federal healthcare privacy law in the United States.
But compliance is not a one-time thing.
It's not like reaching a healthy state and then never having to think about it again. You have to keep working at it.
Privacy works the same way.
If you don't know where your data lives, you cannot actually know whether you're compliant.
Many privacy laws require companies to protect data based on its sensitivity.
For example, healthcare data may require protections such as encryption at rest and in transit. You cannot simply leave sensitive information exposed in a Google Doc.
Companies can also face serious problems when sensitive information is stored on devices without proper protection.
Imagine an employee taking a laptop to the airport, forgetting it on a flight, and exposing all the data stored on that device.
That's one of the biggest challenges with privacy compliance. It is not a one-time exercise. It is an ongoing process.
Data is everywhere.
Most employees have access to computers and large amounts of information. That information can also be spread across marketing, IT, accounting, legal, and other departments.
To comply with different privacy laws, an organization needs to understand:
- What data it has
- Where the data is stored
- How the data is organized
- Who has access to it
- Who the company shares it with
- How the data is protected
How AI Changes Privacy and Cybersecurity Risk
Lisa:
How do AI tools complicate both privacy compliance and cybersecurity?
Charlyn:
AI is the word on everyone's lips these days.
AI is truly transformative, but it also creates significant privacy and cybersecurity risks.
Why?
AI tools can generate output based on the information users provide. Depending on the tool and its settings, that information may also be used to improve or train the model.
Imagine that you ask an AI tool to summarize a confidential document.
The AI system processes the information in that document to generate the summary.
What happens to the information you provided depends on the AI tool, the settings you have selected, and the type of account you use.
Tools such as ChatGPT, Claude, and Gemini have privacy and security settings that explain how they handle user data.
Companies need to understand those settings before entering confidential information into an AI system.
For example, imagine an employee has a confidential memo for the CEO.
If the employee uploads that memo to an AI system without understanding the relevant privacy settings, the company could expose information it never intended to share.
That's why AI governance needs to include both privacy and cybersecurity considerations.
Why Third-Party Vendors Create Major Exposure
Lisa:
Why do third-party agreements often become one of the biggest exposure points for companies when it comes to privacy and cybersecurity?
Charlyn:
Third-party agreements are part of a broader issue that I would call vendor management.
Think about how simple data transmission used to be.
If you sent a letter by mail, the process was relatively straightforward. You gave the letter to one party, and that party delivered it to another.
Today, data moves through much more complex networks.
Even during this podcast, I'm using a Lenovo computer, a Chrome browser, and podcast recording software.
Each of those is a different third party that may interact with data.
Then there is the internet provider that transmits the information between different systems.
Companies therefore have a large network of vendors that may touch their data.
Third-party agreements are critical for managing that network.
Regulators are also increasingly aware that privacy and cybersecurity problems may originate with a vendor rather than the company itself.
Target and Home Depot, for example, have both experienced major data breaches involving third-party relationships.
That's why companies need to understand their vendor relationships and the legal protections that apply to them.
A trusted technology transactions lawyer can help companies understand this network of relationships and identify where risk may arise.
What a Strong Incident Response Plan Looks Like
Lisa:
What does a technically sound incident response protocol look like compared with one that only works on paper?
Charlyn:
Having policies and procedures in place is critical.
I'm not diminishing the importance of having a data breach response policy or an incident response policy before an incident occurs.
The first question is: How will you know that there is a breach?
Companies need appropriate monitoring and security tools.
These may include:
- Antivirus software
- Penetration testing
- Vulnerability management
- Security monitoring
- Cybersecurity vendors
The second question is: What happens after a breach is identified?
Companies need to know who receives the initial report and how that information moves through the organization.
For example, if a lower-level employee discovers a potential incident, who do they report it to?
If the CEO learns about the incident, who should they contact?
A strong incident response plan should answer these questions before a crisis happens.
Companies should also have a cybersecurity or forensic vendor ready to respond.
When an incident occurs, you want someone who can act immediately.
If the breach is ongoing, you do not want data to continue leaving the organization while you're trying to find a vendor.
The written plan is only the beginning.
If a company cannot execute the plan, that's where things break down.
This is why tabletop exercises are so useful.
A tabletop exercise allows a company to simulate a breach and walk through the response process.
The goal is to practice before a real incident occurs.
You do not want employees opening an incident response policy for the first time during a crisis.
Why Technical Architecture Matters to Technology Contracts
Lisa:
Why can technical architecture decisions made before lawyers are involved create problems in technology transactions later?
Charlyn:
I would say that technical architecture creates opportunities as well as problems.
The technical foundation of a technology product is critical to understanding how legal risk can be managed.
For example, many organizations are now procuring AI systems through major cloud and large language model providers.
Some tools use proprietary large language models. Others are applications built on top of foundational models.
Understanding how those systems fit together is extremely important.
Consider an AI-powered billing system.
Instead of manually recording time entries, an AI tool might monitor activity on a computer and predict which tasks should be associated with a particular time entry.
Now imagine that the billing software is built on top of OpenAI.
There may be two different third parties involved.
First, there is the billing software provider.
Second, there is the foundational AI model provider.
That raises important questions.
What information can each provider access?
Where does that information go?
What restrictions apply to its use?
What can each provider do with the data?
The answers depend on the technical architecture.
As a lawyer, you need to understand that architecture to properly manage legal and contractual risk.
How Data Flows Shape Technology Agreements
Lisa:
How do data flows determine which provisions companies need in their technology agreements?
Charlyn:
Data flows are critical to structuring the agreement.
Privacy laws often create different obligations based on the role an entity plays in relation to the data.
The California Consumer Privacy Act, for example, distinguishes between roles such as a business and a service provider.
The business is the entity collecting the information and maintaining the relationship with the consumer.
For example, Rikka Law Group may collect information from one of its clients. Rikka controls how that information is stored, shared, and protected.
Now imagine that Rikka uses Google or Gmail as an email provider.
Google may act as a service provider in that relationship. It processes information to provide the services rather than using that information for its own unrelated purposes.
That distinction matters.
Data has significant value, but it also creates significant risk when it is exposed.
Understanding how data moves helps privacy lawyers determine which laws apply and what contractual protections are needed.
Consider another example.
A company may store data in the United States even though the data belongs to an individual in the European Union.
Depending on the circumstances, additional legal mechanisms may be required before that data can be transferred to the United States.
Without understanding the data flows, a lawyer cannot properly determine which legal requirements apply.
Open Source Licensing Risks
Lisa:
What kinds of risks can arise from open source licensing that companies don't always anticipate when building their technology stack?
Charlyn:
Open source licensing is extremely powerful.
At a basic level, open source software allows developers to use and build on code that is made available to the public.
That lets developers benefit from work created by people around the world.
But open source software is not necessarily free of obligations or risk.
Different open source licenses impose different requirements.
Some licenses are generally referred to as copyleft or viral licenses.
These licenses can require developers to make certain source code available under the same or similar licensing terms when they incorporate the open source code into their software.
That's why the term “viral” is sometimes used.
The license requirements can extend to other parts of the software that incorporate the open source code.
This matters for companies building commercial products.
If a company spends significant resources developing software that it plans to sell, it does not want to accidentally include open source code that creates licensing obligations that limit commercialization.
Even a small piece of open source code can create significant issues if the applicable license is not properly understood.
Why Integration Clauses Matter
Lisa:
Why can integration clauses become so important in technology contracts, particularly when it comes to what isn't written into the agreement?
Charlyn:
When people begin discussing a business deal, lawyers are often not involved yet.
It may start with one CEO speaking with another CEO and saying, “I love what you're doing. Let's partner.”
The conversation may happen over the phone, by text message, through Zoom, or on Microsoft Teams.
Those conversations can create misunderstandings.
Imagine one CEO later says, “You told me you would do X, Y, and Z, but you didn't.”
If those promises are not included in the final agreement, that can create a serious dispute.
This is where an integration clause becomes important.
An integration clause generally states that the written agreement supersedes prior oral or written communications about the subject matter of the deal.
In other words, the final contract becomes the definitive record of what the parties agreed to.
That means conversations at a coffee shop, text messages, emails, or other discussions may not control unless they are included in the written agreement.
This is especially important when significant amounts of money are involved.
Companies should be clear about exactly what they have agreed to.
That's why it is important to work with someone who understands both commercial contracts and technology.
A well-drafted agreement can help reduce misunderstandings and make the parties' obligations clear.
Closing
Lisa:
Charlyn, I want to thank you for your insights today.
This is a complicated issue that almost every company needs to understand, and it is still very new to many of us.
Thank you for the work you're doing to help companies navigate these challenges.
Charlyn:
Absolutely. Thank you so much, Lisa, for having me.
Lisa:
That's it for today's episode of AI-Savvy Lawyer.
If you'd like to learn more about Charlyn Ho and the work her team does at Rikka Law Group, visit rikkagroup.com.
If you enjoyed this conversation, we invite you to subscribe to the show and share this episode with someone who may find it useful.
We'll see you next time.What does a technically sound incident response protocol look like compared

















