Each company that collects, processes, shares, stores, or disposes of personal data must ensure that these data are protected with the appropriate security measures. The Federal Trade Commission and State Attorneys General have interpreted the Federal and State Unfair and Deceptive Practices Acts to require the use of appropriate security policies and procedures. Numerous laws, regulations, and industry standards contain specific detailed provisions that define the required security safeguards.
Adopting reasonable security measures makes sense. Failure to do so exposes a company to fines or penalties from the regulators, class action suits for negligence by injured parties, and much more. If personal data are lost, exposed or compromised, the incident is likely to become known by the public, and in many cases, widely reported on blogs and tweets.
We have worked on data protection matters since the early 1990s, and have a unique in-depth, experience and expertise with these issues. We have assisted hundreds of businesses of all sizes, in all markets, with respect to data security issues. We keep abreast of the most recent data security legal developments in the United States and abroad.
The depth and breadth of our knowledge of the data security bills, laws, regulations, government enforcement actions, jurisprudence, standards and industry guidelines provide the framework within which we advise businesses, shape internal policies, procedures and processes, and draft contracts that follow the applicable mandates, or train the company’s workforce and leadership on the relevant data protection issues and recent developments.
Our compliance services aim at providing our clients with the ability to understand the requirements of the complex and ever changing requirements that apply to their business. As security counsel to businesses, we have worked on a variety of data security matters.
Counseling on Applicable Laws and Standards
Depending on the market in which our client evolves, different laws apply to their business. We are very familiar with these laws and can quickly respond to their request, usually without any research time. For example, we regularly counsel our clients, on the data security laws and regulations that govern the handling of:
Development of Policies and Procedures
We work in tandem with our clients’ CTO, CIO, CSO, and CISO to develop or improve data security policies and procedures that comply with the applicable data security laws. We may, for example:
Data Security Issues in Commercial Contracts
Commercial contracts in which the parties share or exchange personal data involve significant data security issues that result from each party’s obligation to comply with the myriad applicable data security legal requirements that govern the collection, processing, sharing or disposal of personal data.
As data security counsel, we guide our clients through the maze of the legal requirements and restrictions that may affect the proposed transaction. For example, we:
Security Breach Disclosure
We assist companies in the development of documentation as necessary to prepare for the eventuality of a breach of security of their systems.
If a breach of security occurs, we work with the client on responding promptly to the incident in a manner that is consistent with the applicable laws.
Awareness and Training
We enhance our clients’ training program, by providing to their personnel targeted, relevant, up-to-date training on applicable data security laws and regulations. This training is required under many laws and regulations, Federal Trade Commission and State Attorneys General rulings. It is also necessary for the workforce to keep up with the ever-changing legal landscape.
We have conducted training with respect to many aspects of data security, such as:
| Mail: |
555 Bryant Street, #603 Palo Alto, CA 94301 USA |
| Email: | Contact form here. |
| Telephone: | +1 (650) 328-1800 |