Back to the blog
SaaSPrivacyDataManagement

SaaS privacy: what the LG controversy teaches

September 29, 2026·6 min read·Diego Horvatti

Can you say, right now, what data is leaving your company through the tools you pay for every month? Most business owners can't. And it's not carelessness. It's just that nobody ever asked. This post is about SaaS privacy, and it starts with a TV.

What happened with LG's TVs

An investigation published online accused LG of having something like 216 million "spy TVs" spread around the world. The claim: the devices could record audio and track what people do in front of the screen.

LG pushed back hard. It said the concerns about tracking and snooping are "not true".

I can't say who's right. Neither can you. And that's exactly where the lesson is.

When an accusation like this comes up, the customer gets stuck between two stories. On one side, a scary report. On the other, a big company saying "don't worry". Without real transparency, all that's left is trust. And once trust cracks, a press release won't fix it.

Why this matters for the SaaS you use

A smart TV is, at its core, software running on hardware. It gets updates, sends data to servers and has terms of use nobody reads. Sound familiar?

Your CRM works the same way. So do your support system, your ERP, your scheduling tool and the AI chatbot you added to your website last week. All of them collect data. Often more than you think:

  • Full customer conversations, with names and phone numbers.
  • Pricing and margin spreadsheets.
  • Sales history and browsing behavior.
  • Sometimes, meeting and call recordings.

The difference is that the TV sits in the family living room. The SaaS sits at the heart of your business. If the TV leaks, it's embarrassing. If the CRM leaks, it's a lawsuit.

If you don't know what a tool does with your data, the tool decides.

The problem isn't collecting, it's hiding

Let me be fair to vendors. Collecting data isn't always evil. A lot of it is needed for the product to work. Your support system has to store the conversation, or there's no history. The AI tool has to read the text, or it can't answer anything.

The trouble starts in three situations:

  1. When collection goes beyond what's needed. Why does a calendar app want access to your microphone?
  2. When the use changes without notice. Today the data keeps the product running. Tomorrow it trains an AI model or gets bundled and sold to advertisers.
  3. When nobody can verify it. The company says it doesn't do it, but gives you no way to check.

The LG controversy is the third case at a massive scale. Maybe the TVs do nothing wrong. But if the answer boils down to "trust me", the reputational damage is already done.

My strong opinion: a vendor that can't explain on one page, in plain language, what it does with your data doesn't deserve your credit card. No matter how pretty the dashboard is.

How to check SaaS privacy before you sign

You don't need to become a security expert. You need to ask the right questions. I use a short list with the clients I work with, and it covers 80% of cases.

Where does the data live? Ask for the country and the cloud provider. If the vendor can't answer, that's your answer.

Who inside the company can access it? Can every support employee open your account and read everything? Or are there controls and a log of who accessed what?

Is the data used to train AI? This is the 2026 question. Many tools changed their terms over the past two years to include it. Look for the option to turn it off. If there isn't one, think twice.

Can you export and delete everything? If you cancel tomorrow, do you take your data with you? And does it really disappear from their servers?

Do they comply with the LGPD? Ask for the contact of their data protection officer (the DPO). Serious companies have one, and they answer.

A practical tip: email these questions to the sales team before closing the deal. The speed and quality of the reply say a lot. I've seen a vendor answer in two hours with a ready-made document. And I've seen another one vanish for three weeks and come back with "our legal team is reviewing it". Guess which one I recommended.

What to do with the tools you already use

Signing up carefully is great. But you probably have about ten tools that have been running for years. You can clean house without drama.

Start with a simple inventory. A spreadsheet with four columns: tool name, who uses it, what kind of data goes through it and how much it costs. You'll finish in an afternoon.

Three surprises almost always show up:

  • A tool nobody uses anymore, but it keeps charging you and storing customer data.
  • An app someone on the team installed on their own, connected to the company's Google account with full permissions.
  • An old integration that copies data between systems, and nobody remembers why.

At one retail client, this review turned up a browser extension installed by a former employee. It had read access to every email on the sales team. He had left more than a year earlier. The extension was still there, happily reading everything.

After the inventory, review permissions. Google and Microsoft accounts have a screen showing which apps have access. Remove anything that doesn't make sense. It takes ten minutes and closes doors you didn't even know were open.

Oh, and while you're at it, turn off content recognition on the meeting room TV. Just in case. It doesn't need to know the quarterly results presentation was at 3 p.m.

And if you're the one selling SaaS

If your company sells software, the LG case is a direct warning. Privacy is no longer a footer topic. It's become a selling point. And a reason to lose deals.

B2B customers are asking more and more. Large companies send security questionnaires with 50 or 100 questions before signing. If you don't have the answers ready, the contract stalls.

What really helps:

  • A public page explaining, without legalese, what data you collect and why.
  • An export and delete button that works without opening a ticket.
  • An email notice before any change to the terms, with time for the customer to leave if they disagree.

It looks like red tape. But it's what keeps you out of headlines with the word "spy" in them.

Trust is the product

In the end, every tool you use asks for one thing: access. To your computer, your customers, your conversations. In return, it promises to solve a problem.

That trade only works with transparency on both sides. Without it, you end up like the TV owner reading that it might be listening to the room. Not knowing whether to believe the report or the company.

You can't control everything. But you can know what's running in your business, ask before you sign and cut whatever can't explain itself.

If you want help mapping your tools, replacing the ones you don't trust or building automations you understand from start to finish, let's talk.

LinkedIn summary

Do you know what data is leaving your company through the tools you pay for every month?

LG was accused of having 216 million "spy TVs". It denied it. Nobody can check. And that's where the problem lies.

Your CRM, your support desk and the AI chatbot on your website work the same way. The difference is that if the TV leaks, it's embarrassing. If the CRM leaks, it's a lawsuit.

Collecting data isn't the problem. Hiding it is. A vendor that can't explain on one page, in plain language, what it does with your data doesn't deserve your credit card.

Before you sign, ask where the data lives, who can access it, whether they train AI on it and whether you can delete everything. How long they take to answer already says a lot.

I wrote a practical guide to review the tools you already use. If you want help mapping yours, reach out.

#Privacy #DataProtection #SaaS #InformationSecurity #DigitalTransformation