Tech & Counsel

Learn/Product Advisory and Cross-Functional Work

Module 4 Exercise: QuickSave and the Open API

About 30 minutes

Tech & Counsel provides education only. Nothing on this site is legal advice, and nothing here creates a solicitor–client relationship.

Study exercise. Invented company. Not a memorandum you send.

Scenario

You are internal product counsel at NaijaWealth, a Lagos investment app. Next month the team wants “QuickSave.” An external SDK will read a user’s bank SMS, infer spending, and pull money into an investment wallet.

On the configuration screen, permission to read those messages is pre-ticked. The product manager plans to keep the raw texts forever, unencrypted, to train an internal model.

During your review, security tells you that an older API was breached 24 hours ago. Names and email addresses of 10,000 users are exposed.

Write

About 750 words to the CTO and the product manager together:

  1. Name the dark pattern and say how the consent screen has to change.
  2. Refuse the permanent unencrypted SMS store. Propose a smaller design, using the retention and minimisation ideas from Module 2.
  3. Set out the next 48 hours of the breach: who is told, what the incident log must contain, and what you still need to confirm in the current notification rule before a letter goes to a regulator.

Create a free account to mark this lesson complete.