Organizations facing rapid change in privacy and data security requirements turn to ArentFox Schiff for guidance on compliance, government investigations, litigation, and data breach response across interconnected US and international regulatory regimes.

Overview

Privacy and data security law are expanding at an unprecedented rate across jurisdictions, with new and changing regulatory frameworks and increasing litigation and enforcement activity shaping how organizations collect, use, disclose, and safeguard personal data. Businesses face overlapping and sometimes conflicting obligations under US state laws such as the CCPA and Illinois BIPA, federal statutes such as the FTC Act, COPPA and the VPPA, and international regimes, including the GDPR and member state implementation of the ePrivacy Directive, alongside heightened expectations from regulators, consumers, the plaintiffs’ bar, and business partners. These developments create operational and legal complexity that requires careful navigation across compliance, risk management, and strategic decision-making. Organizations also face new and increasing AI regulatory pressure as they implement AI tools and processes to increase productivity and promote efficiency. Organizations must now navigate complex legal, operational, and reputational considerations when processing personal data and when responding to increasingly-frequent and complex security incidents. ArentFox Schiff advises companies operating in this dynamic environment on privacy, cybersecurity, and information and AI governance.

Our Focus

ArentFox Schiff works with organizations to navigate the rapidly changing privacy and data security landscape, addressing regulatory requirements, enforcement risk, and operational challenges. This includes advising on compliance with state privacy laws such as CCPA, federal frameworks including the FTC Act, COPPA, and the VPPA, and sector-specific laws governing children’s, financial, and health data, as well as international obligations such as the GDPR and ePrivacy Directive.
Working closely with clients, the team supports responses to data security incidents, regulatory inquiries, and privacy and data security litigation exposure, while also helping organizations develop governance structures and practical approaches that align legal requirements with business objectives.

Privacy and data security issues increasingly affect core business operations, from product development and marketing practices to vendor relationships, transactions, and incident response. Organizations must address changing requirements under laws such as the CCPA, GDPR, sector-specific privacy frameworks, and an expanding body of state privacy and AI legislation and regulation, while responding to heightened expectations from regulators, consumers, employees, vendors, and business partners.

Working closely with client teams, ArentFox Schiff helps organizations evaluate legal, regulatory, and operational considerations associated with data use, AI implementation and governance, cybersecurity and incident response, and emerging technologies. Our team advises companies across a broad range of industries, including advertising, technology, financial services, retail, consumer products, healthcare, hospitality, media and entertainment, nonprofits, trade associations, and industry coalitions, helping them navigate evolving requirements while supporting business objectives and risk management efforts.

Focus Areas

In Privacy & Data Security, we support clients with:

What Do We Do?

  • Advise on compliance with US state privacy laws, including CCPA, and other applicable state law frameworks
  • Support compliance with federal and sector-specific privacy requirements, including those affecting children’s, financial, biometric, health, location, and video viewing data
  • Provide guidance on compliance with the EU and UK versions of the GDPR, national implementations of the ePrivacy Directive, and other international data protection obligations
  • Assist with data breach response, notification, and related legal and risk mitigation considerations
  • Represent clients in regulatory investigations and enforcement matters
  • Represent clients in high-stakes privacy litigation, including CIPA, ECPA, TCPA, VPPA, and data breach matters
  • Advise on information and AI governance practices 

Who Do We Help?

  • Advertising companies
  • Consumer products companies
  • Data-driven businesses
  • Health care organizations
  • Hospitality companies
  • Media and entertainment companies
  • Nonprofits and trade associations
  • Retail companies
  • Financial services companies
  • Technology companies

How Can We Help?

Businesses may seek support in connection with evolving regulatory requirements, compliance program development, data incidents, investigations, or litigation exposure. We advise clients on compliance obligations, investigations, breach response and notification requirements, governance initiatives, contractual arrangements involving data, and the privacy implications of emerging technologies, products, and business models.
This support may include addressing evolving state privacy laws, GDPR requirements, sector-specific privacy frameworks involving health, financial, and children’s data, AI governance, regulatory investigations, privacy and data breach litigation, payment security standards, transactional diligence, and other data protection issues arising throughout the business lifecycle.

FAQs

How do we determine which privacy laws apply to our business?

Organizations may be subject to multiple state, federal, and international privacy requirements depending on factors such as the types of personal data they collect, how those data are used, where individuals associated with the personal data are located, and industry- or data-specific obligations.

What should we do if our organization experiences a data breach or cybersecurity incident?

The legal considerations following a security incident often include restoration and recovery, forensic investigation, special ransomware considerations, assessing applicable individual and regulatory notification requirements, preserving relevant evidence, managing communications, coordinating with third-party providers, and addressing regulatory obligations, and preparing for regulatory investigations or post-incident litigation.

When does a data incident trigger breach notification requirements?

Notification obligations depend on the facts and circumstances of the incident, including the type of information involved, the jurisdictions of the affected individuals, and applicable legal requirements.

How can organizations prepare for increasing state privacy law requirements?

Organizations evaluate their personal data processing and consumer rights processes to address evolving requirements under state privacy laws, including the CCPA, and similar laws enacted in other jurisdictions. These rules are changing quickly, so it is important to have a partner who can stay abreast of developments and advice on new of different obligations as they become effective.

What privacy issues should be considered when launching new products, technologies, or data-driven initiatives?

New products and technologies may present privacy, data governance, cybersecurity, consumer protection, and AI governance considerations that can affect design, deployment, contractual arrangements, and regulatory compliance.

What should companies consider when transferring personal data across borders?

Cross-border data transfers require organizations to evaluate applicable US and international data transfer requirements, available contractual safeguards and international frameworks, data processing arrangements, and regulatory expectations.

What happens during an FTC or state privacy investigation?

Regulatory investigations often involve requests for information and documents relating to privacy, data security, advertising practices, privacy and AI governance, and compliance measures. They often begin with consumer complaints, which is one reason why addressing consumer complaints early is a priority at many of our clients’ organizations. Organizations may need to assess legal obligations while responding to regulators’ inquiries. The goal is always to satisfy the regulator that the organization is compliant, or close enough to satisfy the inquiry.

What privacy and data security issues arise in mergers, acquisitions, and other transactions?

Transactions frequently involve reviewing data assets, privacy disclosures, contractual obligations, cybersecurity practices, regulatory risks, and compliance programs as part of diligence and transaction planning.