Attorney Advertising
New York, NY [Phone number] consultant@kmcjustice.com

Business & Corporate

Technology & Data Privacy

Contracts, compliance and risk management for technology businesses and data-driven organizations.

Overview

What this involves

Technology moves faster than the law, and personal data now crosses borders with every click. Businesses need contracts that protect their products and data, and privacy practices that satisfy regulators in the United States and abroad.

We advise technology companies and data-driven businesses on software and SaaS agreements, privacy compliance under laws such as New York's SHIELD Act, the CCPA and the GDPR, and the response to data incidents.

How We Help

How we can help

  • SaaS, software licensing and technology agreements
  • Privacy policies, terms of use and consent practices
  • Compliance with US state privacy laws and the GDPR
  • Data processing and cross-border data transfer agreements
  • Data breach response planning and notification
  • Technology aspects of transactions and investments

Our Process

How the process works

A clear, structured approach, so you always know where your matter stands and what comes next.

  1. Assessment

    We review your business, your exposure and your existing policies and controls.

  2. Risk mapping

    We identify the rules that apply and where the real risks lie.

  3. Program design

    We design practical policies, procedures and contract terms that fit your operations.

  4. Implementation and training

    We help roll the program out and train the people who need to apply it.

  5. Monitoring and response

    We advise on reviews, reporting and any inquiries from regulators.

Who It's For

Who we help

Software and SaaS companies

E-commerce and digital businesses

Companies handling customer or employee data

Businesses serving customers in Europe

Organizations responding to a data incident

FAQs

Frequently asked questions

Does the GDPR apply to a US business?

It can, for example where a business offers goods or services to people in the EU or monitors their behavior. We help you assess whether it applies.

What should we do after a data breach?

Act quickly: contain the incident, preserve evidence and get legal advice on notification obligations, which can have short deadlines.

Do we need a privacy policy?

If you collect personal information, you almost certainly need one, and it must accurately describe what you actually do.

This page provides general information, not legal advice. Every situation is different; please contact us to discuss yours.

Request a Consultation

Discuss your technology and data privacy matter with us.

Tell us briefly about your situation. We will review your inquiry and contact you to discuss how we can help.