Expertise

Privacy & Data Protection

Privacy counsel for US and cross-border technology companies: the CCPA and the twenty state laws now in force, opt-out preference signals and advertising technology, wiretap and video-privacy exposure, data-broker registration, and the automated decision-making rules that become enforceable on January 1, 2027.

Start here

Website exposure scan

We list every advertising vendor, pixel and cookie on your public pages and screen them against US privacy litigation records. A lawyer reviews the findings. No charge, and requesting a scan does not create an attorney-client relationship.

Request a scan

The CCPA and the State-Law Patchwork

Twenty states now have a comprehensive privacy law in force, and their thresholds, definitions and exemptions do not line up. Rather than apply a European program to a company that started in the United States, we establish which of those laws reach your particular data flows, then build one program that satisfies them together.

  • Which state laws apply to you today, and at what revenue and record thresholds
  • Limits on sensitive personal information, purpose limitation and data minimization designed into the product rather than added afterwards
  • Access, deletion, correction and opt-out procedures your support team can run at volume
  • Service-provider and third-party contract terms that keep ordinary vendor use outside the definitions of sale and share
  • The risk assessments the CPPA regulations require, and the cybersecurity audits that phase in from April 2028 by revenue band

SourcesCCPA (Cal. Civ. Code § 1798.100 et seq.)·CPPA rulemaking·IAPP state-law tracker

Opt-Out Preference Signals and Your AdTech Stack

Most US privacy enforcement does not begin with a breach. It begins with the marketing stack. Sale and share are defined broadly enough under the CCPA that ordinary pixels, cookies and audience matching can create opt-out obligations. Businesses have had to detect and honor opt-out preference signals such as Global Privacy Control since the CCPA regulations took effect. From January 1, 2027, AB 566 requires browsers offered to Californians to include the setting, which will raise the volume of signals you receive.

  • Detecting and honoring Global Privacy Control across your properties, and evidencing that you do
  • An audit of tags, pixels and SDKs to establish what sale and share activity is actually taking place
  • Consent Mode and server-side tagging configured so measurement survives an opt-out
  • Data clean rooms and audience matching placed under the correct controller and processor terms
  • Do-not-sell and do-not-share flows that hold up to regulator and plaintiff scrutiny

SourcesAB 566 (Opt Me Out Act)·CCPA·GPC specification

CIPA, VPPA and Session-Replay Claims

Plaintiffs' firms continue to bring wiretap claims under the California Invasion of Privacy Act, video-privacy claims under the VPPA, and session-replay claims against sites that load trackers before consent. Senate Bill 690, which is on the Assembly floor as of August 2026, would remove the private right of action under Penal Code § 638.51 alone. The § 631 claims behind most pixel and session-replay suits would remain. We address the exposure at the consent and code layer, before a demand letter arrives.

  • Technical audits that identify the trackers, session-replay tools and chat widgets creating exposure
  • Consent architecture that loads third-party tags only after a recorded opt-in
  • Closing the evidentiary gaps that plaintiffs' firms rely on to plead a claim
  • Configuration review for any site combining video with advertising identifiers
  • A documented record to rely on if a demand letter still arrives

SourcesCal. Penal Code § 631·§ 638.51·VPPA (18 U.S.C. § 2710)·SB 690 status

Data-Broker Registration and the DELETE Act

If you buy, enrich or monetize data about people you do not collect from directly, you may meet the definition of a data broker. California's Delete Request and Opt-out Platform has been open to consumers since January 2026, and since August 1, 2026 registered brokers must check it at least every 45 days and delete matching records within 45 days. SB 361 doubled the daily fine for failing to register, to $200 per day. The definition reaches further than most companies expect.

  • A direct answer on whether you meet the data-broker definition in California, Texas, Oregon or Vermont
  • Registration, disclosures and the expanded reporting SB 361 added
  • A pipeline that processes DROP deletion requests on the 45-day cycle and records the outcome
  • Structuring data purchases and enrichment so you do not acquire broker status by accident

SourcesDELETE Act (as effective Jan 2026)·SB 361·CPPA data-broker registry·DROP

Automated Decision-Making: The January 2027 Deadline

The CCPA regulations on automated decision-making technology were approved in September 2025 and took effect on January 1, 2026. A business that uses ADMT to make a significant decision about a California resident must comply by January 1, 2027, which is when enforcement is expected to begin. Risk assessments are required for processing carried out from January 1, 2026, with the first submission to the CPPA due by April 1, 2028. Colorado has repealed its 2024 AI Act and replaced it with SB 26-189, which also applies from January 1, 2027. This is where privacy work and AI governance meet, so we build one program rather than several.

  • Pre-use notices, opt-out rights and access rights for ADMT under the CCPA regulations
  • Risk assessments for the processing the regulations designate, in the form the CPPA will ask to see
  • Review of significant decisions in hiring, lending, housing, insurance and education, where the rules bite hardest
  • One control set mapped across California, Colorado and the EU AI Act rather than three separate ones
  • Disclosure and safety obligations for consumer-facing AI, including the companion-chatbot rules in SB 243, which carry a private right of action

SourcesCCPA ADMT regulations (final text)·CPPA rulemaking·Colorado SB 26-189·SB 243·EU AI Act

Processing Agreements and Vendor Terms

A data processing agreement has to describe how your service actually runs, including multi-tenant architecture, streaming and models in the loop, rather than restate a template drafted for a different decade. We draft and negotiate the terms your enterprise buyers will sign and a regulator will not need to question.

  • Sub-processor and vendor terms mapped to your real data flows rather than a boilerplate annex
  • Model-training clauses that either protect customer data or deliberately permit its use, on the record
  • Cross-border transfer terms, Standard Contractual Clauses and transfer impact assessments
  • Multi-tenant isolation and security addenda that enterprise procurement will accept

SourcesGDPR·EU Standard Contractual Clauses

GDPR and International Expansion

When you begin operating in the EU or the UK, we run the standard program: records of processing, data protection impact assessments, DPO cover, standard contractual clauses, transfer impact assessments and the EU-representative decision. Our team is IAPP certified (CIPP/E, CIPP/US, CIPT, FIP), and the program is sized for a company that started in the United States.

  • Fractional or named DPO cover with credentials supervisory authorities recognize
  • Records of processing, DPIAs and the documentation you will be asked to produce
  • Standard Contractual Clauses, transfer impact assessments and EU or UK representative decisions

SourcesGDPR·EDPB·UK ICO

Dates We Are Working To

The obligations below are settled law or final regulations. We use this sequence to plan client work, and we will tell you plainly which of them apply to you and which do not.

  • August 1, 2026: registered data brokers must check DROP at least every 45 days and action the deletion requests they find
  • January 1, 2027: ADMT compliance date under the CCPA regulations, and the point at which enforcement is expected
  • January 1, 2027: Colorado SB 26-189 applies, replacing the 2024 AI Act
  • January 1, 2027: browsers offered to Californians must include an opt-out preference signal setting under AB 566
  • April 1, 2028: first risk-assessment submissions due to the CPPA, and the first cybersecurity audits for businesses above $100 million in revenue
  • December 2, 2027: EU AI Act obligations for Annex III high-risk systems, as deferred by the Digital Omnibus

SourcesCPPA regulations·AB 566·Colorado SB 26-189·Digital Omnibus on AI (Reg. (EU) 2026/1744)

Key Questions We Help You Answer

  • ?Are we selling or sharing personal information simply by running advertising and analytics?
  • ?Are we detecting and honoring Global Privacy Control today, and can we show it?
  • ?Do our tracking pixels create CIPA or VPPA exposure?
  • ?Do we meet the data-broker definition in California, and should we be registered?
  • ?What has to be in place before January 1, 2027 if we use automated decision-making?
  • ?Which state laws apply to us, and what is the smallest program that satisfies them?
Your plan

Privacy Counsel

$1,800/quarter

An outsourced privacy function: CCPA alignment, adtech and pixel risk, records of processing and impact assessments. DPO Central and vendor.watch are included. Tiers from startup to large scale.

See plans & tiers

Get Started

Discovery Call

30 min • Video call

Pacific Time (PT) • San Francisco