Skip to main content

Practice area 01

Data Privacy Compliance

Several regulators, several vocabularies, one set of facts about how your company collects, uses and shares personal data. We establish those facts first, then map the obligations that follow from them and close the gaps in the order your risk actually demands.

Frameworks in scope

  • GDPR
  • UK GDPR
  • CCPA / CPRA
  • HIPAA
  • US state privacy laws
  • PIPEDA
Schedule a Consultation
01.1

Where the obligations come from

Most companies are subject to more law than they realise, because privacy statutes follow the data rather than the office. A single product can pull in a European regulator through the GDPR, a California regulator through the CPRA, and a health regulator through HIPAA, all at once. We start by identifying which regimes genuinely apply to you and which do not, so effort goes where it counts.

  • GDPR and UK GDPR: a lawful basis for every use, transparency at the point of collection, honoured data subject rights, documented processing, a lawful route for international transfers, and breach notification measured in hours rather than weeks.
  • CCPA and CPRA: notice at collection, opt-out of sale and sharing, limits on sensitive personal information, prescribed contract terms with every service provider and third party, and risk assessments for higher-risk processing.
  • HIPAA: covered entity and business associate status, executed business associate agreements, the Privacy Rule on use and disclosure, the Security Rule on administrative, physical and technical safeguards, and the Breach Notification Rule.
  • US state privacy laws: a growing body of statutes with common architecture and inconsistent detail, particularly on universal opt-out signals, sensitive data consent, and assessment obligations.
01.2

How Wall Law helps you comply

Advice that stops at a memorandum leaves the work undone. Our engagements are built to end in artefacts you can hand to a regulator, a customer, or an acquirer, and in processes your teams can run without counsel in the room.

  • A gap assessment that reads your systems and contracts, not just your policies, and states plainly where you stand against each applicable law.
  • A remediation roadmap sequenced by exposure and effort, so the board can see what is being fixed this quarter and what is deliberately waiting.
  • Drafted and negotiated documents: privacy notices, consent and preference language, data processing agreements, standard contractual clauses, transfer impact assessments, and business associate agreements.
  • Rights handling that works at volume, with intake, identity verification, response templates, and an audit trail that shows you met the statutory deadline.
  • Vendor and sub-processor diligence, including the contract terms each regime specifically requires rather than a generic addendum.
  • Regulator and customer correspondence, questionnaires and audits, handled with counsel rather than improvised by the account team.
01.3

Evidence, not assurances

When an authority opens a file, it does not ask whether you intended to comply. It asks for records: your processing inventory, your assessments, your notices as they appeared on the day in question, your contracts, and the log of how you answered the individual who complained. We build those records as a by-product of the work, so producing them later is retrieval rather than reconstruction.

What you receive

Work product, dated and defensible.

Every engagement in this area is scoped to end in artefacts you can hand to a regulator, a customer or an acquirer without rewriting them first.

  • Applicability analysis across GDPR, CPRA, HIPAA and state law
  • Written gap assessment with a prioritised remediation roadmap
  • Public privacy notice and internal use policies
  • Records of processing and a maintained data inventory
  • Data processing agreements, SCCs and transfer impact assessments
  • Rights request procedure, templates and response log

How the engagement runs

Four stages, agreed before we start.

  1. 01

    Establish the facts

    Interviews with product, engineering, marketing and procurement, plus a review of systems and contracts, to document what data you hold and why.

  2. 02

    Map the obligations

    Determine which regimes apply, where they overlap, and where a single control can satisfy several of them at once.

  3. 03

    Close the gaps

    Draft, negotiate and implement in priority order, working with the teams who own each system rather than around them.

  4. 04

    Keep it current

    Scheduled reviews tied to product launches, new vendors, new markets, and changes in the law.

Common questions

Asked before most engagements.

We are a US company with no European office. Does the GDPR still apply?

It can. The GDPR reaches companies outside the EU that offer goods or services to people in the EU or monitor their behaviour. The question is answered by how you market, price, and track, not by where you are incorporated. We work through that analysis with you before assuming either answer.

Our privacy policy was written by our previous counsel. Is that enough?

A policy is a description of a practice. If the description and the practice have drifted apart, the policy becomes evidence against you rather than protection for you. We compare what the notice claims with what your systems do, and correct whichever one is wrong.

How do you price this work?

Assessments and defined deliverables are usually scoped as fixed fee, so you know the cost before the work starts. Ongoing counsel is available on a monthly retainer. We agree the basis in writing at the outset.

Find out which laws actually reach you.

A short consultation is usually enough to tell whether you are looking at a focused fix or a broader program.