Practice Privacy & compliance
Practice area 06
Privacy & compliance
GDPR, CCPA/CPRA, HIPAA where it applies, and the EU AI Act read like source, not scripture. Compliance you can ship against.
- Privacy policy
- GDPR / CCPA
- HIPAA scoping
- EU AI Act
Problems we solve
- Your privacy policy was written by a template two years ago and does not describe your model.
- You are being asked to sign a BAA and you are not sure whether HIPAA even applies.
- You want an EU AI Act posture before a customer asks for one.
What you get
- Product-specific privacy policy that describes what your model actually does.
- GDPR and CCPA/CPRA gap analysis with a prioritized fix list.
- HIPAA scoping decision: whether you are a covered entity, business associate, or neither.
- EU AI Act risk classification, obligations map, and deployment posture.
- Data subject request workflow you can operate without legal in the loop.
What we will not do
- We do not conjure HIPAA obligations where none exist to sell more work.
- We do not treat compliance as a checklist detached from the product.
How this fits with other practice areas
Most engagements combine two or three practice areas. This one commonly pairs with Open source & IP and Disputes & response. When you send an intake, we tell you which combination fits and price the scope in writing before you sign anything.