Advisori.
PRACTICE AREAS

Deep in privacy and AI — and only privacy and AI.

A specialist bench, not a generalist one.

01
HIPAA & BAAs
Business associate agreements drafted, negotiated, and actually tracked.
45 CFR 164.504(e)
02
Data Processing Agreements
Processor terms that survive counterparty redlines.
GDPR ART. 28
03
PIAs & DPIAs
Impact assessments written to be read by a regulator, not filed.
GDPR ART. 35
04
AI Governance
Advice on model intake, risk classification, and governance documentation.
EU AI ACT · NIST AI RMF
05
US State Privacy Laws
One obligation register across California, Colorado, and the rest.
CAL. CIV. CODE §1798.100
06
Cross-Border Data Transfers
SCC remediation programs and transfer risk assessments, run at enterprise scale — hundreds of vendor agreements repapered.
EU · UK · SWISS SCCs
07
Incident Response & Breach Notification
Breach counsel from first report through multi-state notification analysis, investigation, and regulator response.
45 CFR 164.400 · STATE BREACH LAWS
08
Privacy Program Design & Operations
Privacy offices built from the ground up: notices, consent, DSAR playbooks, ROPAs, risk dashboards, and training.
GDPR ART. 30 · ART. 37–39

Industries

Sectors where regulated data is the business, and where our attorneys have done the work.
Pharmaceuticals

Clinical trial and research data, consent frameworks, cross-border transfers, and the privacy questions that follow the pipeline from study to market.

CLINICAL DATA · CONSENT · TRANSFERS
Medical Device Manufacturers

Connected devices and the patient data they generate: telemetry, software-driven products, AI-enabled functions, and vendor ecosystems.

CONNECTED DEVICES · PATIENT DATA · AI
Hospitality

Guest data at global scale — loyalty programs, reservations, payments, and marketing across jurisdictions. The sector where this practice began.

GUEST DATA · LOYALTY · GLOBAL OPERATIONS

What is on your desk?

Request counsel