Services
Five practice areas for companies whose data has become complicated.
Each area below is a full engagement in its own right, and most clients need more than one. They are run from a single desk so that one set of facts produces one consistent answer rather than three overlapping opinions.
- 01
Data Privacy Compliance
GDPR, CCPA and CPRA, HIPAA and the widening set of US state privacy laws, mapped to how your company actually handles personal data.
- Gap assessments against the laws that reach you
- Notices, contracts and records that hold up on inspection
- Data subject and consumer rights that work in practice
- 02
AI Governance and Ethics Consulting
Risk assessments, governance frameworks and policy for teams deploying machine learning, so responsible AI becomes a control rather than a statement of intent.
- Model and use-case risk assessments
- Governance frameworks mapped to the EU AI Act and NIST AI RMF
- Policy and review processes engineering teams will actually follow
- 03
Data Security and Breach Response
Incident response planning before an event, and counsel-led investigation, notification and regulator handling during one.
- Incident response plans that have been rehearsed
- Counsel-led breach investigation and notification
- Security policy and safeguards review
- 04
Privacy Program Development and Management
The standing capability behind compliance: data mapping, assessments, governance and ongoing management, built to run without counsel in the room.
- Program design, build and implementation
- Data mapping and records of processing
- DPIAs and PIAs on a repeatable method
- 05
Privacy Training and Awareness
Role-specific training for the people whose daily decisions create privacy risk, delivered in their vocabulary and measured on what changes afterwards.
- Curricula written for engineering, marketing, sales and support
- Live sessions using your own systems as the examples
- Records of completion that stand up as evidence
How we work
Three ways an engagement is usually structured.
Most relationships begin with an assessment, move into a build, and settle into retained counsel. You are not required to take all three, and we will say so when a later stage is not yet worth the cost.
- 01
Assessment
A defined piece of analysis with a written result: applicability, gap assessment, AI risk review or safeguards review. Fixed fee, agreed before the work starts.
- 02
Build
Implementation of what the assessment found: policies, notices, contracts, assessments, response plans and the training that goes with them.
- 03
Retained counsel
Ongoing availability for questions, reviews, escalations and customer diligence, with the program kept current between projects.
Not sure which of these you need?
That is a normal starting point. Describe the situation and we will tell you which practice area it falls into, or whether it needs more than one.