CONTACT USarrow icon

"*" indicates required fields

Name*

Overview

We help businesses take proactive steps to safeguard sensitive information.

In today’s interconnected, digital world, safeguarding sensitive information and ensuring compliance with data protection regulations are critical for any organization. With evolving threats from cyberattacks and increasingly complex data privacy laws, businesses face unprecedented challenges in maintaining security and legal compliance.

We understand these challenges and offer a comprehensive suite of legal services to protect data, mitigate risk, and ensure full compliance with the latest legal and regulatory standards. Our attorneys combine in-depth legal knowledge with practical, real-world experience to help organizations navigate the intricacies of data security. We work with our clients to identify vulnerabilities, strengthen security protocols, and develop tailored compliance strategies. Whether you are building a cybersecurity program from the ground up, responding to a cyber incident, or establishing an online presence for your business, our dedicated data security and compliance team provides proactive and responsive solutions that protect your business and its reputation.

WHY DATA SECURITY AND REGULATORY COMPLIANCE MATTER

Data security breaches and noncompliance with regulatory requirements can have devastating consequences. From financial losses and operational disruptions to reputational damage and legal fines and penalties for organizations that operate in highly regulated industries, the stakes are even higher.

Dunlap Bennett & Ludwig is committed to ensuring that your business is equipped to managing data and information risks to meet the stringent demands of evolving compliance laws that govern website development and data security.

We advise clients on regulatory compliance laws such as the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), the Health Insurance Portability and Accountability Act (HIPAA), state cybersecurity laws, the Children’s Online Privacy Protection Act (COPPA), and the Americans with Disabilities Act (ADA). We also assist with privacy policies and permission-based marketing programs.

OUR EXPERTISE IN DATA SECURITY AND COMPLIANCE

Our cross-functional data security team combines expertise in legal, compliance, and technology.

We offer the following services :

  • Governing risk: We help businesses create and implement data governance strategies that mitigate risk while enhancing operational efficiency. Our proactive approach ensures that organizations are well-prepared to handle security threats and compliance challenges before they escalate into legal issues.
  • Regulatory advice and guidance: Our attorneys provide continuing guidance and interpretation of laws to help organizations stay ahead of evolving data protection regulations. We ensure that businesses are fully aware of their regulatory obligations and provide actionable solutions to meet compliance standards while minimizing risks.
  • Compliance program development: Building an effective compliance program is essential to long-term data security. Our team assists businesses in developing tailored cybersecurity programs that integrate best practices and regulatory standards, improving data protection from day one.
  • Cyber incident preparedness, reaction, and defense: We collaborate with businesses to create customized incident response plans and provide ongoing training, ensuring teams are fully prepared to act in the event of a data security breach. If a cyber incident does occur, we offer immediate legal assistance, including breach notifications, regulatory compliance guidance, and defense against litigation.
  • Security awareness training and exercises: A comprehensive cybersecurity strategy includes employee training. We provide robust, legally informed training programs that prepare your workforce to identify and address potential threats while maintaining compliance with data protection regulations.
  • Website development compliance: As organizations increasingly rely on digital platforms, website compliance is critical. Our attorneys offer legal counsel on website development to ensure your online presence adheres to global data privacy laws, accessibility requirements, e-commerce regulations, marketing and communication rules, and industry-specific requirements.

WHAT SETS OUR LAW FIRM APART?

  • We take a holistic approach: Unlike other firms, we provide legal counsel and practical, technical insights that address the full spectrum of data security challenges. We understand that effective compliance and security require more than just meeting regulatory standards—they require the seamless integration of law, technology, and business strategy.
  • We focus on proactive strategies: Prevention is at the heart of our approach. We work to anticipate potential security threats and regulatory changes, allowing clients to stay one step ahead of cyber risks and legal obligations. This proactive stance helps businesses avoid costly breaches and noncompliance penalties, keeping their operations running smoothly.
  • We have industry-specific expertise: Our team has deep experience across a wide range of industries, allowing us to offer industry-specific guidance that ensures compliance with data protection laws and industry regulations. We help our clients build security frameworks that are legally compliant and operationally efficient.
  • We provide swift, decisive incident response: Every second counts when a data breach occurs. Our lawyers provide immediate support to ensure compliance with breach notification laws, limit reputational damage, and mount a strong legal defense. We also work alongside cybersecurity teams to investigate breaches, provide strategic advice on remediation, and help clients recover from the incident with minimal disruption.

Our data security team understands the complexities of today’s digital environment and is committed to helping your business thrive within it. Our goal is to give you the peace of mind that comes with knowing your data is secure, your operations are compliant, and your legal risks are minimized.

Frequently Asked Questions

Which privacy laws apply to my company?

The answer depends on where you operate, what information you collect, and how you use it. For example, the GDPR may apply if your company offers goods or services to people in the EU or monitors their behavior there. The CCPA covers for-profit companies that do business in California and meet certain revenue or data-processing thresholds. HIPAA covers protected health information handled by healthcare providers, health plans, and their business associates. COPPA applies to online services that collect personal information from children under 13. Legal counsel should map the data you collect, determine which federal, state, and international laws apply, and help you build a compliance program around their requirements.

We just discovered a data breach. What should we do first?

Act quickly, but don’t make assumptions about what happened or who needs to receive notice. Contact your information technology or security team and legal counsel as soon as possible. Then activate your incident response plan, contain the threat, and preserve relevant records and evidence. Legal counsel can determine which laws apply, coordinate the forensic investigation, notify your cyber insurer, and manage communications with regulators, customers, employees, and others. Time is of the essence because reporting periods begin as soon as you learn of an incident. For example, the GDPR requires that a company notify a regulator within 72 hours of becoming aware of a qualifying breach.

What is a privacy impact assessment? Do we need one?

A privacy impact assessment (PIA) identifies privacy risks by examining how a project, product, system, or vendor collects, uses, stores, protects, and shares personal information. Some laws require a privacy or data protection assessment for higher-risk activities, such as processing sensitive information or using personal data to make important decisions about people. Even when the law doesn’t require an assessment, conducting one before launch can uncover problems when you still have time to address the affected project, product, or vendor relationship.

We just built a new website. Do we need a legal review?

It’s a good idea. A legal review will identify problems involving privacy notices, cookies and tracking tools, accessibility, online sales, marketing communications, intellectual property, and the collection of personal information. The requirements that apply to your site depend on its function, the information it collects, and its users. A business that serves customers in several states or countries may need to address different privacy and cookie rules. A business open to the public should also consider whether its website gives people with disabilities equal access to its goods and services. When possible, have an attorney review your site before launch, while you can still change its design and data practices.

How do we build a compliance program that will hold up?

Start by identifying what data you hold, why you collect it, where you store it, who can access it, how long you keep it, and which vendors receive it. Then work with legal counsel to align your policies, contracts, security controls, and training with the applicable laws and risks. Written policies help only if your company puts them into practice, so assign responsibility for carrying out the program and keep records of important decisions.

Does employee training reduce legal risk?

Training reduces risk by giving employees practical, job-related guidance. Employees need to know how to recognize phishing attempts, protect sensitive information, use company systems safely, and report a possible incident. Some laws, contracts, and security frameworks also require or expect regular training. A generic annual presentation won’t prepare employees for every threat. For example, our data security and compliance team delivers security awareness training and tabletop exercises that let employees and leadership teams practice responding to realistic scenarios before an incident occurs.

How should we prepare for a data breach before one happens?

Create an incident response plan that sets forth decision-makers, important contacts, and a process for investigating, mitigating, and reporting an incident. Review contracts so you know which customers, business partners, and vendors may require notice. Also decide how you will preserve evidence and continue critical operations. A tabletop exercise can reveal gaps in your plan before an incident puts it to the test.

Are we responsible for how our vendors handle personal data?

Your company may remain legally or contractually responsible for personal information after sharing it with a vendor. A strong contract helps, but it doesn’t replace careful selection and oversight. Before giving a vendor access, find out what data it needs, how it will use and protect your data, whether it will involve subcontractors, and where it will store your information. Your contract should address security requirements, permitted uses, breach notification, audit rights, legal compliance, and the return or deletion of your data at the end of the relationship. You should also monitor important vendors after signing.

What does privacy compliance require beyond posting a privacy policy?

A privacy policy should accurately explain what your company does with personal information, but posting one is only the beginning. Your practices must align with your policy. You may need a process for responding when people ask to access, correct, delete, or stop certain uses of their information. Privacy compliance may also require consent procedures, limits on data collection and retention, security safeguards, vendor agreements, employee training, and records showing how your company handles requests and makes privacy decisions.

OUR TEAM

Team

Craig Besnoy

Of Counsel

Robert J. Eatinger, Jr.

Of Counsel

Daniel W. Sutherland

Of Counsel

Su Young (Jane) Cho

Associate

Alex Rowan

Associate

Brandon Rickwood

Senior Associate

Contact Us

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Name*
Please do not include any confidential or sensitive information in this form.
Submitting this form does not create an attorney-client relationship.

Intern Program

As part of our effort to recruit, develop and retail the best and brightest attorneys, Dunlap Bennett & Ludwig offers a summer intern program for promising law school students who are looking to work as part of an innovative and incredibly successful team. With a global team of lawyers, selected candidates are able to work on high level projects in a collaborative space.

Paralegals and Legal Support Staff

At Dunlap Bennett & Ludwig, our team of paralegals and staff work together collaboratively along side our attorneys toward a common goal. We have created a positive work environment where our paralegals and legal assistants work to successfully reach firm-wide goals and support each other to combine individual strengths to enhance team performance. They regularly assist our attorneys with organizing and maintaining files, conducting legal research, and preparing documents.