top of page
logo-reverse.png
GET IN TOUCH
services-band-background.png

OUR SERVICES

AI, Privacy & Security

Privacy, security, and AI governance — advised together, from policy through deployment.

OVERVIEW

What you need

Our attorneys have provided data privacy and security representation since the earliest days of the Internet and the adoption of HIPAA. We bring our depth of knowledge and experience to bear in designing policies and procedures to mitigate corporate risks relating to data and information privacy and security; analyzing and negotiating contractual obligations between companies exchanging PII, PHI, or confidential data; and enabling compliance with E.U. and cross-border data transfer regulations. We constantly monitor evolving regulatory schemes, best-practice standards, and technology models to ensure that our clients remain at the forefront of compliance.

HOW WE DELIVER

We use a series of proprietary tools and processes that we have developed to assist our clients in assessing their privacy and security practices, to determine the regulations that apply to their businesses and types of data they maintain (contractual, E.U., worldwide, PCI DSS, HIPAA), and to develop and implement appropriate policies. We also provide extensive and ongoing training to ensure that our clients maintain compliance and reduce risk of breach.

In the unlikely event a data breach occurs, we assist our clients in assessing the extent of the breach, determining and instituting immediate remedies, providing required notifications, and conducting post-breach remediation.

REPRESENTATIVE MATTERS

AI governance program design and policy

Privacy program design and governance

Security and incident response

AI system and model inventories, including vendor-embedded AI

US state comprehensive privacy laws

Information security policies and workforce training

Deployment review and approval gates

EU and UK GDPR compliance

Vendor security diligence and contractual security terms

AI impact and risk assessments

Standard contractual clauses and transfer assessments

Incident response plans and tabletop exercises

Automated decision-making and profiling analysis

Latin American regimes, including LGPD

Breach analysis and scoping

EU AI Act readiness and risk classification

Data protection impact assessments

Breach notification across every applicable jurisdiction

US state AI statutes and federal government requirements

HIPAA compliance and business associate agreements

Ransomware and extortion counsel, including sanctions screening

NIST AI RMF and ISO/IEC 42001 alignment

State health privacy laws beyond HIPAA

Regulator investigations and state attorney general inquiries

Training data, licensing, and output ownership

Biometric and sensitive data, including BIPA

SEC cyber disclosure and materiality analysis

Vendor and model diligence

Children and teen privacy, including COPPA

PCI DSS compliance

Board and committee reporting

Consumer rights request processes

Cyber insurance coverage review

AI-specific incident and misuse response

Adtech, pixels, and session replay exposure

Post-incident remediation

What we handle

AI Governance Advisory

Product Counsel

Technology Consulting

Breach Response

Cross-Border Transfer

Compliance Programs

bottom of page