Well-versed in privacy law, data governance, and cybersecurity
Well-versed in privacy law, data governance, and cybersecurity
Advise companies on technology transactions such as SaaS licensing, domestic and international privacy compliance and regulatory compliance
Counseled hundreds of small to mid-sized businesses in wide ranging industries ranging from EdTech, FinTech, and Real Money Gaming to video games
Skilled in international privacy law and the drafting of data protection addenda, particularly with the application of UK and EU GDPR and the ePrivacy Directive
Entrepreneurial at heart, prior owner of two businesses
Max played tournament chess since childhood reaching the rank of Candidate Master. He hopes to achieve an international title someday when he can again study and his young children stop knocking the pieces off the board!
Max L. Landaw, Senior Counsel at InfoLawGroup, has over a decade of legal experience focused on counseling businesses of all kinds, with a particular focus on technology companies and businesses operating in closely regulated markets. Max keeps abreast of technological developments that carry legal consequences and counsels clients on vendor transactions, privacy compliance, intellectual property protection, and marketing initiatives.
A significant part of Max’s practice involves real money gaming. He advises on the state and federal law governing sweepstakes, casino games, sports wagering, fantasy sports, lottery and lottery courier services, charitable raffles and bingo, skill gaming, and esports, including the licensing requirements attached to each. Max reviews gaming operators and their apps and websites at volume, preparing written risk assessments that clients rely on to decide whether and where an offering can proceed, and he maintains state-by-state analyses of what each category of gaming requires. Much of that analysis turns on the line between skill and chance (a distinction Max understands concretely as a chess Candidate Master), which shapes everything from licensing requirements to where an offering can legally operate.
Max also serves as embedded counsel to in-house legal teams. On an extended secondment with a global technology company, he worked alongside product and engineering teams as new features, tools, and vendors were proposed, identifying the privacy implications and risks of each before development proceeded. That work spanned consumer-facing product privacy, geolocation, messaging services, trust and safety systems, and the use of facial recognition technologies. On a separate privacy coverage engagement, Max handled the full range of day-to-day privacy work: negotiating the privacy terms in commercial contracts, product counseling, responding to domestic and international data subject access requests, managing regulatory investigations, and data breach response.
Max advises on privacy law across more than fifteen jurisdictions spanning six continents, from the United States, Canada, Mexico, Brazil, the United Kingdom, the European Union, Switzerland, India, Israel, South Africa, the Gulf States, and markets across Asia Pacific. He drafts data protection agreements and addenda covering both controller-to-controller and controller-to-processor transfers, builds reusable templates for clients handling the same categories of vendor repeatedly, and advises on responding to data subject requests and inquiries from international supervisory authorities.
Max advises on AI governance and on the legal issues raised by AI. He drafts AI governance and acceptable use policies, including standards for which tools and use cases a business should approve and standard operating procedures for agentic AI. He analyzes clients’ use and development of AI technology, negotiates AI-related provisions in contracts, and counsels on the intellectual property and confidentiality risks raised by AI tools including meeting notetakers. Max has worked with the EU AI Act, and his AI practice frequently intersects with his biometrics work, where he advises on biometric data processing terms in vendor agreements and on biometric and fraud identification systems across multiple jurisdictions.
In helping clients implement privacy by design and default, Max also advises companies with regard to internal technology development and technology acquisitions. He regularly supports new product launches, diving deep into a company’s technology stack so that his advice fits how the product actually functions. Max negotiates SaaS agreements, software licenses, end user license agreements, developer and API agreements, and vendor and supplier agreements, and counsels on risks in licensing transactions and on open source software obligations.
Max is a member of the International Association of Privacy Professionals (“IAPP”) and holds the CIPP/E, CIPP/US, and AIGP (Artificial Intelligence Governance Professional) certifications.
“Max was instrumental to our business from the time we started the company. We were so fortunate to have his guidance through this journey. One of the best attorneys I have worked with in my 20-year career.”
Counsels on the state and federal law governing real money gaming (RMG), from sweepstakes and casino games to sports wagering, fantasy sports, lottery and courier services, charitable gaming, skill gaming, and esports, including licensing requirements and per-operator risk assessments
Counsels on corporate formation, intellectual property protection and licensing, data privacy, and other commercial, regulatory compliance, and operational matters
Drafts and negotiates service agreements, end user license agreements, privacy policies, intellectual property licensing documentation, vendor and supplier agreements, liability waivers, independent contractor agreements, and other technology transactions agreements
Advises on privacy compliance in more than fifteen jurisdictions, including the United States, Canada (PIPEDA), Mexico, Brazil (LGPD), the United Kingdom (UK GDPR & PECR), the European Union (GDPR & ePD), Switzerland (FADP), India (DPDPA), Israel (PPL), South Africa (POPIA), Saudi Arabia (SA PDPL), the United Arab Emirates (UAE PDPL), Australia (Privacy Act/APPs), New Zealand (Privacy Act), Singapore(PDPA), Taiwan (PDPA), China (PIPL, CSL, DSL), South Korea (PIPA), and Japan (APPI)
Serves as embedded privacy counsel on secondments and privacy coverage engagements with in-house legal teams
Drafts AI and acceptable use policies, including standards for tool and use case approval and standard operating procedures for agentic AI
Advises on biometric privacy, including biometric processing terms in vendor agreements and biometric identification systems across multiple jurisdictions
Advises on legal, regulatory, and product management surrounding product development, coding practices, data privacy, and open-source technology
Counsels on privacy issues related to websites, data collection and use. Well-versed in privacy law, data governance and cybersecurity. Drafts privacy policies and DPAs which consider GDPR, CCPA, CPRA and other privacy laws
Drafts data protection addenda which considers domestic privacy laws (e.g. CCPA/CPRA, CPA, VCDPA, UCPA, CTDPA) and international privacy laws (e.g. UK/EU GDPR) including additional documentation for international transfers to the United States
Regularly drafts SaaS licensing agreements
Advises on responding to privacy-related data subject requests and investigations from international data supervisory authorities.
“Supreme Court Clears the Way: Texas's App Store Accountability Act Is Now Enforceable,” The American Legal Blogger, July 2026
“Europe Just Activated a New Tool for Cross-Border Data Transfers,” The American Legal Blogger, June 2026
“Wisconsin Legalizes Online Sports Wagering; Follows Florida’s Lead (with Its Own Twist),” Lexology, April 2026
“Is It All Just Gambling? Prediction Markets, Sports Betting, and U.S. Real Money Gaming,” Lexology, April 2026
“Foundational Legal Questions About Online Real Money Gaming,” Lexology, July 2025
“Keeping the Skill in Skill Gaming – Removing Chance from Esports,” The American Legal Blogger, July 2025
“New Jersey Banning Sweepstakes Casinos?,” The American Legal Blogger, June 2025
“Real Money Gaming and Opinion Letters,” Lexology, May 2025
“Texas Settles Privacy Related Lawsuits Against Google For $1.375 Billion,” The American Legal Blogger, May 2025
“Antitrust & Other Legal Risks in the Age of Algorithmic Pricing,” Lexology, February 2025
“Missouri Narrowly Legalizes Sports Wagering,” Lexology, December 2024
“Florida Paves A New Path For Sports Wagering Legalization In Other States,” The American Legal Blogger, August 2024
“Europe Issues Guidance on the Interplay Between Data Protection and Generative AI,” The American Legal Blogger, June 2024
“The Future of Behavioral Advertising In Europe and the United States,” Lexology, November 2023
“Excusez-moi, Make Way for Quebec’s Privacy Law,” Lexology, September 2023
“6 Things You Need to Know About India’s Digital Personal Protection Bill of 2023,” Lexology, August 2023
“EU-US Date Privacy Framework in Force: EU Commission Grants Adequacy Determination to the US,” Lexology, July 2023
“The Texas Data Privacy and Security Act: What Small Businesses Need to Know,” Lexology, June 2023
“Where EU to US Transfers Stand After the Irish DPC’s Meta Decision”, Lexology, June 2023
“Third Time’s a Charm? The New EU-US Data Privacy Framework and the US’s Pursuit of an EU Adequacy Decision under GDPR,” Lexology, October 2022
“European Union Passes Digital Services and Markets Acts to Increase Pressure for Transparency,” Lexology, May 2022
“United Kingdom Unveils New Processes for International Data Transfers,” Lexology, February 2022
Treasurer of Data Privacy Section, Austin Bar Association
Privacy & Data Security
Technology
Intellectual Property
Advertising & Marketing
Association of National Advertisers (ANA)
International Association of Privacy Professionals (IAPP), CIPP/E, CIPP/US and certified Artificial Intelligence Governance Professional (AIGP)
California, 2011
Texas, 2019
Illinois, 2020
UC Hastings College of the Law, J.D. 2011
UC Berkeley, B.A., Political Science, 2008