Privacy and Data Security
InfoLawGroup® has a sophisticated information governance practice that addresses all aspects of privacy, data security and the issues associated with big data and the collection, storage and sharing of information.
InfoLawGroup® has a sophisticated information governance practice that addresses all aspects of privacy, data security and the issues associated with big data and the collection, storage and sharing of information.
Explore Our Focus Areas
Our lawyers work closely with clients on all aspects of privacy compliance, including with regard to federal, state (and sometimes local) regulation. Our advice is practical, and our clients count on us to find solutions to business problems. We draft consumer, employee and b2b privacy notices and disclosures, advise on consent and choice mechanisms, conduct audits, provide "privacy by design" advice for new products and services, and launch compliant marketing campaigns. We understand all aspects of the ad-tech industry, and regularly advise publishers, advertisers, data enhancement services, technology service providers, and others in the ecosystem on compliance. In addition to regularly advising on the FTC Act and related unfair and deceptive trade practice laws, we advise on specific statutes, regulations and industries, including:
Data security is a fundamental aspect of risk management. We provide counsel on the convergence of the legal and technology compliance issues, including:
We work with clients to address compliance with non-U.S. laws and international agreements and standards that apply to their operations, coordinating and working with local counsel as needed.
We advise on overall EU GDPR and ePrivacy and Canadian PIPEDA and CASL compliance for US companies, as well as cross border data transfers, required disclosures, data protection impact assessments, notifications or prior authorizations where required, participation in the US-EU and US-Swiss Privacy Shield programs, data protection addendum and data transfer agreements using EU-approved model contracts, and national authorizations or contractual arrangements outside the EU.
We have deep experience with compliance solutions for ecommerce or mobile apps, cross-border marketing campaigns, and human resources in multinationals operating in virtually every country with comprehensive data protection laws or relevant sectoral legislation. Because of this, we are able to quickly identify potential issues and help companies devise global solutions with practical local adaptations where needed.
Our lawyers are instrumental in helping our clients navigate their preparedness for a data breach and in addressing the compliance in the event of an incident. Our work includes:
Planning and Policies
Notice and Response
Litigation Readiness and Electronic Evidence Management
We assist with privacy and data security policies that govern the internal use, sharing, storage and securing of data. We also assist clients in obtaining third party audits, working with consultants, and obtaining 3rd party seals and certifications. We conduct training sessions to assist our clients in ensuring ongoing compliance with the law and their own policies with regard to data.
We draft and negotiate contracts or specific provisions in contracts to address data security, data collection and data sharing issues.
A purchase or investment in a company raises key privacy and data security issues, which can affect both valuation and potential liabilities. We assist companies, venture capital firms and other investors, along with their M&A attorneys, in conducting key due diligence and integration compliance tasks, including:
Cookies, pixels, and other tracking technologies are subject to increasing scrutiny by regulators and private litigants in the U.S. and abroad, including under state privacy laws, wiretapping statutes, the GDPR, and the ePrivacy Directive. Many companies do not have full visibility into the tracking technologies operating on their websites and apps, including those placed by third parties. We conduct cookie audits that identify the cookies and tracking technologies in use, assess whether current disclosures, consent mechanisms, and preference tools accurately reflect actual data practices, and evaluate compliance with applicable laws. Following an audit, we advise on remediation, including updates to privacy notices, cookie banners, and consent management platforms, and work with clients to establish ongoing review processes as their websites and vendor relationships evolve.
Responding to data subject requests, including access, deletion, and correction requests, across one or more states or jurisdictions can strain internal teams. Our Data Subject Response (DSR) Service is designed to relieve that burden. Our Privacy Manager takes the lead in handling and responding to data subject requests for a monthly flat fee. The service is customized for each client based on the number and types of requests received, the client's current internal processes, and whether the client uses a third-party software system (e.g., OneTrust, TrustArc, or Osano). With our DSR Service, clients can free up their internal teams to focus on other compliance needs.
InfoLawGroup's Privacy Updates & Developments is a subscription bi-monthly newsletter that keeps clients ahead of the legal developments shaping the privacy, AI, and consumer protection landscape. Tailored to each client, it distills the prior two weeks' legislative activity, regulatory enforcement actions, and litigation updates into concise summaries that quickly provide the most important developments you need to know.
What Clients Say
“I appreciate the expertise of InfoLawGroup. They combine expertise and breadth of knowledge with a common sense, practical approach to addressing our complex data privacy issues.”