Privacy in SaaS: what the LG TV case teaches
Imagine opening the news and reading that your product spies on your customers. It doesn't matter if it's true. From that moment on, you're working to prove otherwise. That's what happened to LG. The case is a lesson in SaaS privacy for any company that stores customer data, including yours.
What happened to LG
An investigation published online claimed that around 216 million LG TVs could track what people watch and even record audio. The number is huge, and the headline spread fast.
LG pushed back hard. It said the tracking and snooping claims were "not true". It denied recording conversations and defended its practices.
I don't know who's right on the technical details. You probably don't either. And that's exactly the point.
Most LG TV owners will be left with a vague memory: "I heard that TV listens to us." The official denial almost never travels as far as the accusation.
When you have to defend yourself, trust has already walked out the door.
Why this matters if you don't make TVs
Maybe you're thinking: "Diego, I run a clinic, a store, a consultancy. I don't sell televisions."
But you probably use, or sell, some software that collects data. A scheduling system. A CRM. A WhatsApp chatbot. A customer app. All of these work as SaaS. They run in the cloud and store information about real people.
And a smart TV is, at its core, a SaaS with a big screen. It connects to the internet, sends data to a server, and receives ads and recommendations. Content recognition technology, which identifies what's playing on screen, has existed for years across many brands. It's not a trade secret. The problem is that almost nobody knows it exists until someone writes a news story.
The same goes for your business. A few examples I see all the time:
- The chatbot records every conversation, but the customer thinks they're talking to a robot that forgets everything.
- The website form sends data to three different marketing tools.
- Screen recordings from support calls are kept indefinitely, and nobody knows where.
None of this is illegal on its own. But if it becomes news without a prior explanation, it looks like spying.
Privacy in SaaS is about expectations, not just the law
Brazil's data protection law, the LGPD, says what you can and can't do with personal data. Complying with the law is the bare minimum. But a reputation crisis rarely starts with breaking the law. It starts with a surprise.
Customers feel betrayed when they discover something they didn't expect. Even if it was written on page 14 of the terms of service.
Think about your own phone. You accepted the terms for every app you have. Did you read any of them? Exactly. Your customers didn't read yours either.
Here's my strong opinion: long terms of service don't protect your reputation. They protect your lawyer. Your reputation is protected by a short explanation, in the right place, at the right time.
This is the difference:
- "By continuing, you agree to the Privacy Policy" (a link to 9,000 words).
- "We keep this conversation for 90 days to improve our service. You can ask us to delete it at any time."
The second one is two short sentences. And it saves you a huge headache.
How to keep your business from becoming the next case
You don't need a legal department to get the basics right. You need an afternoon and some honesty. This is the step by step I use with clients:
1. Make a simple data map. A spreadsheet with four columns: what data you collect, where it's stored, who can access it and for how long. On a recent project, this map revealed that a client was sending patients' national ID numbers to an email marketing tool. Nobody had decided that. It was an integration set up in a rush years ago.
2. Cut what you don't use. Data stored for no reason is risk with no return. If you ask for a birth date and never even send a birthday message, stop asking. Less data means less to leak and less to explain.
3. Explain where the customer is. The explanation should show up at the moment of collection, not hidden in the footer. In the chatbot, one line at the start of the conversation. In the form, one sentence below the button. In the app, a notice the first time it asks for microphone or location access.
4. Make "no" easy. If a customer wants their data deleted, how many clicks does it take? If the answer is "they send an email and we look into it", that's fine to start. But someone needs to answer that email in days, not months.
5. Have the answer ready before the question. Write down today, in plain language, what your system does and what it doesn't do. If someone accuses you one day, you don't improvise. You point to a text that's been public for months. That's worth far more than a statement written in a hurry.
"But my competitors collect way more and nobody cares"
This is the objection I hear most. And there's some truth to it. Plenty of companies collect everything and never face any consequences.
Until they do.
LG is one of the largest manufacturers in the world. It has a legal team, a press office and decades in the market. Even so, it spent a week answering headlines. Now picture a small company with 300 customers, half of whom know each other on Instagram. One viral post from an angry customer does proportionally much more damage.
And there's the other side: transparency sells. When you clearly say what you do with data, customers feel they're dealing with serious people. In niches like healthcare, law and education, that becomes a real differentiator. I've seen deals close because the client asked "where is my patients' data stored?" and the answer came in one sentence, without hesitation.
AI makes this even more sensitive
If your business already uses, or plans to use, artificial intelligence, the privacy question gets more urgent.
Voice assistants, automatic meeting transcription and chatbots that "learn" from history are great tools. I build many of them. But they all work by processing people's conversations. And "is this thing listening to me?" is exactly the question that ruined LG's week.
A few rules I follow on every AI project:
- Sensitive data doesn't go to a third-party model without a clear agreement that it won't be used for training.
- Recordings have a defined expiration date, and the system deletes them automatically.
- The end customer knows they're talking to an AI. Always.
It may seem like overkill. But it's much cheaper than spending a week explaining to the press that your TV, I mean, your chatbot, isn't listening to anyone.
The practical takeaway
The LG case will keep people talking, and we may never know for sure who was right. For you, the lesson is much simpler: customers need to know what your system does before someone else tells them.
Map your data. Cut the excess. Explain it in one sentence. Make leaving easy. It fits in an afternoon and protects years of reputation.
If you want to review what your website, chatbot or system is collecting, or you're thinking about adding AI to your customer service without creating this kind of risk, let's talk about your case.
LinkedIn summary
If your customer finds out something from the news, you've already lost. Even if you're right. LG spent the week denying that 216 million TVs spy on their users. The denial never travels as far as the accusation. And this isn't just a TV maker's problem. Your chatbot, your CRM and your forms also store data about real people. A reputation crisis rarely starts with breaking a privacy law. It starts with a surprise. Long terms of service protect your lawyer. One clear sentence at the moment of collection protects your reputation. Map your data, cut the excess, explain it in one line and make opting out easy. It fits in an afternoon. If you want to review what your system is collecting, reach out and we'll look at your case. #Privacy #DataProtection #SaaS #ArtificialIntelligence #Trust