
OUR SERVICES
AI, Privacy & Security
Privacy, security, and AI governance — advised together, from policy through deployment.
OVERVIEW
What you need
Our attorneys have provided data privacy and security representation since the earliest days of the Internet and the adoption of HIPAA. We bring our depth of knowledge and experience to bear in designing policies and procedures to mitigate corporate risks relating to data and information privacy and security; analyzing and negotiating contractual obligations between companies exchanging PII, PHI, or confidential data; and enabling compliance with E.U. and cross-border data transfer regulations. We constantly monitor evolving regulatory schemes, best-practice standards, and technology models to ensure that our clients remain at the forefront of compliance.
HOW WE DELIVER
We use a series of proprietary tools and processes that we have developed to assist our clients in assessing their privacy and security practices, to determine the regulations that apply to their businesses and types of data they maintain (contractual, E.U., worldwide, PCI DSS, HIPAA), and to develop and implement appropriate policies. We also provide extensive and ongoing training to ensure that our clients maintain compliance and reduce risk of breach.
In the unlikely event a data breach occurs, we assist our clients in assessing the extent of the breach, determining and instituting immediate remedies, providing required notifications, and conducting post-breach remediation.
REPRESENTATIVE MATTERS
AI governance program design and policy
Privacy program design and governance
Security and incident response
AI system and model inventories, including vendor-embedded AI
US state comprehensive privacy laws
Information security policies and workforce training
Deployment review and approval gates
EU and UK GDPR compliance
Vendor security diligence and contractual security terms
AI impact and risk assessments
Standard contractual clauses and transfer assessments
Incident response plans and tabletop exercises
Automated decision-making and profiling analysis
Latin American regimes, including LGPD
Breach analysis and scoping
EU AI Act readiness and risk classification
Data protection impact assessments
Breach notification across every applicable jurisdiction
US state AI statutes and federal government requirements
HIPAA compliance and business associate agreements
Ransomware and extortion counsel, including sanctions screening
NIST AI RMF and ISO/IEC 42001 alignment
State health privacy laws beyond HIPAA
Regulator investigations and state attorney general inquiries
Training data, licensing, and output ownership
Biometric and sensitive data, including BIPA
SEC cyber disclosure and materiality analysis
Vendor and model diligence
Children and teen privacy, including COPPA
PCI DSS compliance
Board and committee reporting
Consumer rights request processes
Cyber insurance coverage review
AI-specific incident and misuse response
Adtech, pixels, and session replay exposure
Post-incident remediation
What we handle

