Overview
Privacy and data security law are expanding at an unprecedented rate across jurisdictions, with new and changing regulatory frameworks and increasing litigation and enforcement activity shaping how organizations collect, use, disclose, and safeguard personal data. Businesses face overlapping and sometimes conflicting obligations under US state laws such as the CCPA and Illinois BIPA, federal statutes such as the FTC Act, COPPA and the VPPA, and international regimes, including the GDPR and member state implementation of the ePrivacy Directive, alongside heightened expectations from regulators, consumers, the plaintiffs’ bar, and business partners. These developments create operational and legal complexity that requires careful navigation across compliance, risk management, and strategic decision-making. Organizations also face new and increasing AI regulatory pressure as they implement AI tools and processes to increase productivity and promote efficiency. Organizations must now navigate complex legal, operational, and reputational considerations when processing personal data and when responding to increasingly-frequent and complex security incidents. ArentFox Schiff advises companies operating in this dynamic environment on privacy, cybersecurity, and information and AI governance.
Our Focus
ArentFox Schiff works with organizations to navigate the rapidly changing privacy and data security landscape, addressing regulatory requirements, enforcement risk, and operational challenges. This includes advising on compliance with state privacy laws such as CCPA, federal frameworks including the FTC Act, COPPA, and the VPPA, and sector-specific laws governing children’s, financial, and health data, as well as international obligations such as the GDPR and ePrivacy Directive.
Working closely with clients, the team supports responses to data security incidents, regulatory inquiries, and privacy and data security litigation exposure, while also helping organizations develop governance structures and practical approaches that align legal requirements with business objectives.
Privacy and data security issues increasingly affect core business operations, from product development and marketing practices to vendor relationships, transactions, and incident response. Organizations must address changing requirements under laws such as the CCPA, GDPR, sector-specific privacy frameworks, and an expanding body of state privacy and AI legislation and regulation, while responding to heightened expectations from regulators, consumers, employees, vendors, and business partners.
Working closely with client teams, ArentFox Schiff helps organizations evaluate legal, regulatory, and operational considerations associated with data use, AI implementation and governance, cybersecurity and incident response, and emerging technologies. Our team advises companies across a broad range of industries, including advertising, technology, financial services, retail, consumer products, healthcare, hospitality, media and entertainment, nonprofits, trade associations, and industry coalitions, helping them navigate evolving requirements while supporting business objectives and risk management efforts.