top of page
Search


Can you disclaim your liabilities for someone else's software?
A client came to us recently with a design that's more common than most hardware businesses admit to: a physical product, software embedded in it that a third party built, and a growing worry that if the software fails, the claim lands on whoever's name is on the box, rather than the supplier who wrote the code. Their proposed fix was a disclaimer in the software licence: something along the lines of "we are not the developer of this software and accept no liability arising f
fox303
4 days ago4 min read


The FCA's Consumer Duty Consultation: When "Could Affect" Meets "Should Be Proportionate"
The FCA has published its consultation on the scope and proportionality of the Consumer Duty. Why this consultation exists When the Consumer Duty came into force in 2023, it was framed simply enough: firms must act to deliver good outcomes for retail customers, tested against four specific outcomes — product and service design, fair value, consumer understanding, and consumer support. But the scope of "affecting outcomes for retail customers" turned out to be extraordinarily
fox303
6 days ago5 min read


Why we don't do "joint IP" — and what to do instead
A question came up recently with a SaaS client that's worth setting out properly, because the same pattern shows up from time to time in tech and payments deals. The client licenses their core product to business customers. For one particular customer, the platform had been adapted: some workflow tweaks, a different data model for that customer's sector, and a co-branded front end. Reasonable enough commercially. The trouble started when the customer's lawyers proposed that t
fox303
Jun 204 min read


The data security gap hiding in your billing system
Most businesses that collect payments have heard of PCI-DSS. Fewer have thought carefully about what it doesn't cover — and why that gap matters. The ICO's recent £963,900 fine against South Staffordshire Water is a useful prompt. The penalty notice records that the personal data exfiltrated and published on the dark web included bank account numbers and sort codes for hundreds of thousands of customers. It also records, almost in passing, that payment card data was held outs
Katherine Kennedy
Jun 183 min read
bottom of page