Overview
Our experienced attorneys assist businesses in understanding and complying with the European Union’s General Data Protection Regulation (GDPR) requirements, minimizing the risk of substantial penalties and reputational damage.
We help clients assess their data processing activities, implement privacy by design, and update policies and procedures to meet GDPR standards. Our team provides strategic advice on data subject rights management, cross-border data transfers, and data protection officer (DPO) appointments, ensuring compliance with all aspects of the regulation.
Since the adoption of GDPR in 2018, our attorneys have been ensuring clients develop policies and procedures that comply with GDPR regulations, reviewing privacy policies, data security and use agreements, marketing consent processes, cookie consent applications, and data use reporting guidelines. Our expertise includes preparing GDPR-compliant policies and procedures, negotiating GDPR contract language, and handling incident response and reporting. Our firm can help your business maintain compliance in the EU, foster trust with its customers, and succeed in an increasingly regulated global marketplace.
Full Spectrum Services
- Developing a tailored GDPR compliance plan;
- Implementing subject rights, including rights to information, access, correction, to be forgotten, and data portability;
- Identifying the legal basis for processing or using protected information;
- Negotiating data processing agreements and other contracts;
- Advising clients on building compliance programs that comply with both EU and US laws and regulations
- Support for privacy by design and default implementation in products and services
- Guidance on cross-border data transfers and the use of appropriate safeguards, such as Standard Contractual Clauses;
- Assistance with data protection officer (DPO) appointment and ongoing support;
- Monitoring and analysis of GDPR developments, including European Data Protection Board (EDPB) guidance and EU court decisions’
- Guidance on the interplay between GDPR and other privacy regulations, such as the California Consumer Privacy Act (CCPA) and Brazil’s General Data Protection Law (LGPD);
- Assistance with data breach response and notification under GDPR requirements.