Privacy / Data protection / AI governance
Wall Law is privacy counsel for companies that build with data.
Regulators, customers and boards are asking the same question in different words: can you show how you handle personal data, and can you explain what your systems decide? Wall Law answers both. Legal counsel and hands-on program work arrive together, so a GDPR gap assessment ends in a documented program and an AI risk review ends in controls your engineers can actually apply.
IAPP certified across US and European privacy law, privacy management and privacy technology: CIPP/US, CIPP/E, CIPM and CIPT.
Regimes we work in
- GDPR and UK GDPR
- CCPA and CPRA
- HIPAA
- US state privacy laws
- EU AI Act
- NIST AI RMF
Most companies are subject to more than one of these at once, usually without having mapped where the obligations overlap.
Featured in
- Privacy Quarterly
- The Data Ledger
- AI Governance Review
- Counsel Weekly
What we do
Five practice areas, run as one engagement.
Companies rarely have a privacy problem or an AI problem in isolation. Work is scoped across whichever of these the facts require.
- 01
Data Privacy Compliance
GDPR, CCPA and CPRA, HIPAA and the widening set of US state privacy laws, mapped to how your company actually handles personal data.
- Gap assessments against the laws that reach you
- Notices, contracts and records that hold up on inspection
- Data subject and consumer rights that work in practice
Read about this area - 02
AI Governance and Ethics Consulting
Risk assessments, governance frameworks and policy for teams deploying machine learning, so responsible AI becomes a control rather than a statement of intent.
- Model and use-case risk assessments
- Governance frameworks mapped to the EU AI Act and NIST AI RMF
- Policy and review processes engineering teams will actually follow
Read about this area - 03
Data Security and Breach Response
Incident response planning before an event, and counsel-led investigation, notification and regulator handling during one.
- Incident response plans that have been rehearsed
- Counsel-led breach investigation and notification
- Security policy and safeguards review
Read about this area - 04
Privacy Program Development and Management
The standing capability behind compliance: data mapping, assessments, governance and ongoing management, built to run without counsel in the room.
- Program design, build and implementation
- Data mapping and records of processing
- DPIAs and PIAs on a repeatable method
Read about this area - 05
Privacy Training and Awareness
Role-specific training for the people whose daily decisions create privacy risk, delivered in their vocabulary and measured on what changes afterwards.
- Curricula written for engineering, marketing, sales and support
- Live sessions using your own systems as the examples
- Records of completion that stand up as evidence
Read about this area
Download our free guide
The AI Governance Readiness Checklist
Twelve questions to answer before your next model goes live
A working checklist for teams deploying machine learning: the classification questions regulators are converging on, the documentation a review should produce, the training data issues that surface late, and the human oversight that has to be real to count.
- How to classify a use case by consequence rather than by technology
- The training data questions that become expensive after launch
- What human oversight has to include before it counts as oversight
- The record a review should leave behind, and who should sign it
Written for teams shipping AI, not for a compliance shelf
Alexandra Wall
Founder and Principal Attorney
CIPP/US, CIPP/E, CIPM, CIPT
The practice
Counsel who reads the data model, not only the policy.
Alexandra Wall advises companies on privacy, data protection and AI governance, combining legal counsel with the program work that makes it hold. Engagements are built to leave you with work product you can rely on: assessments, contracts, records and teams who know what to do next.
- 01Privacy, data protection and AI governance run as one practice, so a single assessment answers both sets of obligations.
- 02IAPP-certified across US and European privacy law, privacy management and privacy technology (CIPP/US, CIPP/E, CIPM, CIPT).
- 03Engagements end in usable work product: assessments, contracts, records and trained teams, not a memorandum.
Tell us what you are trying to ship.
Most engagements start with a short consultation about a specific problem: a product launching into Europe, a model going into a decision workflow, a customer questionnaire nobody can answer. Bring the problem and we will tell you what it actually requires.