Practice Privacy & compliance
Practice area 06

Privacy & compliance

GDPR, CCPA/CPRA, HIPAA where it applies, and the EU AI Act read like source, not scripture. Compliance you can ship against.

  • Privacy policy
  • GDPR / CCPA
  • HIPAA scoping
  • EU AI Act

Problems we solve

  • Your privacy policy was written by a template two years ago and does not describe your model.
  • You are being asked to sign a BAA and you are not sure whether HIPAA even applies.
  • You want an EU AI Act posture before a customer asks for one.

What you get

  • Product-specific privacy policy that describes what your model actually does.
  • GDPR and CCPA/CPRA gap analysis with a prioritized fix list.
  • HIPAA scoping decision: whether you are a covered entity, business associate, or neither.
  • EU AI Act risk classification, obligations map, and deployment posture.
  • Data subject request workflow you can operate without legal in the loop.

What we will not do

  • We do not conjure HIPAA obligations where none exist to sell more work.
  • We do not treat compliance as a checklist detached from the product.

How this fits with other practice areas

Most engagements combine two or three practice areas. This one commonly pairs with Open source & IP and Disputes & response. When you send an intake, we tell you which combination fits and price the scope in writing before you sign anything.