Privacy & Data Security

Against a multitude of business challenges, executives and general counsel continue to cite privacy and data security at the top of their list of risk threats and day-to-day concerns. A shifting regulatory landscape has organizations not only struggling to adequately protect sensitive data but also to understand confusing rules about how consumers’ personal data should be collected, shared, and maintained. Additionally, businesses must ensure consumers are informed of their rights through enhanced privacy notices that meet regulatory approval.

How can we help? Let's talk.

How Can We Help? Let's Talk

Our full range of privacy and data security services includes the following:

Compliance Programs

We help mitigate privacy and data security risks through the design and implementation of practical, cost-effective compliance programs. Among other things, this includes drafting policies and procedures, training executive management and other employees, and establishing robust quality assurance protocols.

Compliance Audits

We regularly conduct on-site and/or virtual compliance audits of our clients’ operations. These audits are typically the best way to assess the organization’s risk exposure and verify that a compliance program is working as designed. Oftentimes, these audits bring to light new business practices that have not been fully vetted from a compliance perspective. By discovering these issues proactively, we’ve successfully helped our clients remediate noncompliant practices before they catch the attention of regulators or plaintiffs’ attorneys.

Defense of Class Action & Individual Lawsuits

We have defended numerous companies against class action and individual lawsuits involving the FDCPA, FCRA, TCPA, and other privacy laws, achieving optimal outcomes for our clients. In many instances, we have obtained voluntary dismissal of the case or settlement on an individual, rather than class-wide, basis.

Data Breach Response

In the hours and days after a data breach has been discovered, businesses need clear and fast counsel regarding their breach response obligations. We advise clients on breach response requirements and best practices, and work with their public relations team and senior leadership to navigate the complex issues that arise in the aftermath of a data breach.

Third-Party Due Diligence & Contract Review

In addition to auditing internal compliance programs, we also help clients reduce external risks by establishing robust due diligence programs for their vendors, dealers, marketing partners, and merger and acquisition targets. Such programs might include pre-contract due diligence measures, contractual requirements/prohibitions, ongoing due diligence protocols, and remediation measures.

State & Federal Investigations

We help clients respond to regulatory inquiries and investigations brought by the FTC, FCC, CFPB, and state attorneys general. We have achieved significant success in resolving investigations without negative findings against our clients or with consent agreements containing little or no monetary penalty.

Regulatory Advocacy

We advocate for clients’ privacy-related interests before the FTC and FCC. This includes filing petitions or comments on behalf of our clients and meeting with regulatory staff and leadership regarding such issues.

Related Attorneys

Related Webinars

Related Insights

October 31, 2025
Maryland’s MODPA: A New Standard for Data Privacy—and Data Minimization

On October 1, 2025, the Maryland Online Data Privacy Act (MODPA) became effective, joining the growing list of states with comprehensive consumer data privacy laws. With enforcement beginning April 1,

October 23, 2025
California’s Privacy Law Is “A Total Mess”: What the ERC Case Reveals About CIPA’s Outdated Language

In a sharply worded opinion, U.S. District Judge Vince Chhabria recently granted summary judgment in favor of the Eating Recovery Center (ERC) in a privacy lawsuit that has reignited debate