About
Wall Law exists to make responsible data handling something a company can prove, not just intend.
Privacy law asks a company to explain itself: what it collects, why it is allowed to, who it shares with, how long it keeps it, and what happens when something goes wrong. Artificial intelligence adds a second question about what the system decides and on what basis. Most organisations can answer both in conversation and almost none can evidence it on request. Closing that distance, permanently and in writing, is the whole of the work.
What we hold to
Four commitments that shape every engagement.
They are not decoration. Each one is a rule we apply when a decision is genuinely difficult, which is when values are worth anything at all.
- 01
Plain answers
A question that has a clear answer gets one. Where the law is genuinely unsettled we say so, set out the range of defensible positions, and recommend one rather than leaving the choice on your desk.
- 02
Evidence over intent
Good intentions are not a defence. Every engagement is built to leave behind records, assessments and processes that demonstrate what was decided, when, and on what reasoning.
- 03
Proportion
A twenty-person company and a regulated enterprise do not need the same program. We size the work to your actual exposure and say plainly when something is not worth doing yet.
- 04
Respect for the person behind the record
Every row in a database belongs to someone. Compliance done only to the letter tends to fail the people it was written for, and eventually fails the company too.
Alexandra Wall
Founder and Principal Attorney
CIPP/US, CIPP/E, CIPM, CIPT
Attorney biography
Alexandra Wall
Alexandra Wall founded Wall Law to do privacy work the way clients kept asking for it: legal analysis and practical implementation from the same desk, rather than an opinion handed to a team with no route to act on it. The practice advises companies on data protection, information security and the governance of artificial intelligence, from a first gap assessment through to running a program on a retained basis.
Her work covers the questions companies bring when data becomes complicated. Whether the GDPR reaches a US business and what follows if it does. How the CPRA changes a marketing stack that was built before opt-out signals existed. What a business associate agreement actually obliges a vendor to do. Which machine learning use cases will be treated as consequential decisions, and what has to be documented before one goes live. The answers are delivered as work product a company can use: assessments, drafted notices and contracts, records, review processes and training.
She holds the IAPP designations of Certified Information Privacy Professional for both the United States and Europe (CIPP/US and CIPP/E), Certified Information Privacy Manager (CIPM), and Certified Information Privacy Technologist (CIPT). Taken together, those credentials reflect the shape of the practice: the law of two major privacy regimes, the management of a privacy program as an operating function, and the technical fluency to work with engineering teams on the systems where personal data actually lives.
That technical grounding shapes how engagements run. Reviews start with systems, data flows and contracts rather than with the policy document, because the policy is only a description of a practice and the two drift apart quietly. Recommendations are written to be implemented by the people who own the system, in language they use, with the reasoning left visible so a decision can be defended later.
She is a member of the International Association of Privacy Professionals and follows regulatory developments closely across US state privacy law, European data protection and the emerging body of AI regulation, because clients are usually planning against rules that are still moving.
Affiliations and credentials
Certified where the work actually happens.
The International Association of Privacy Professionals sets the certification standards most widely recognised in this field. The four below cover US law, European law, program management and privacy technology.
International Association of Privacy Professionals
Member of the IAPP, the global professional body for privacy practitioners, and holder of four of its certifications spanning US law, European law, privacy management and privacy technology.
IAPP certification: CIPP/US and CIPP/E
Certified Information Privacy Professional in both the United States and Europe, covering the two bodies of law most often engaged at the same time by a single product.
IAPP certification: CIPM
Certified Information Privacy Manager, the credential covering the design, operation and measurement of a privacy program as an ongoing function.
IAPP certification: CIPT
Certified Information Privacy Technologist, the credential covering privacy in system design, engineering practice and the technologies that carry personal data.
Our approach
What makes this practice different.
Five differences that clients tell us matter, stated plainly enough that you can hold us to them.
- 01
Counsel and implementation from one desk
Most privacy advice ends where the work begins. Here the same practice that identifies the gap drafts the notice, negotiates the processing agreement, builds the assessment method and trains the team that has to run it. Nothing is handed over at the point it becomes difficult.
- 02
Privacy and AI governance run together
Training data, profiling, automated decisions and deletion are simultaneously AI questions and personal data questions. Run separately, the two disciplines produce contradictory answers. Run together, one assessment usually satisfies both.
- 03
Technical fluency, not translation
We read the data model, the vendor list and the tracking stack. Engineering teams get requirements they can implement instead of principles someone else has to interpret for them.
- 04
Deliverables a regulator would accept
The test applied to every piece of work is whether it would stand up if produced under inquiry: dated, reasoned, consistent with what the systems actually do, and complete enough to be relied on.
- 05
Scope and fees agreed in advance
Assessments and defined deliverables are scoped as fixed fee, and ongoing counsel is available on a monthly retainer. You know what an engagement costs before it starts.
Work with counsel who will tell you what is not worth doing.
A first consultation is a conversation about facts, not a pitch. If your position is stronger than you think, we will say so.