What your data requires, and what it is worth.
A company’s data is two things at once: an obligation and an asset. The practice addresses both, what you are required to do with the data you collect, and whether the data you already hold can become something of value.
Most privacy questions now turn on what your analytics, advertising, and AI vendors actually do with the data you send them. Answering that takes reading the technical reality, not only the policy, which is where the real exposure and the real opportunity both tend to sit.
What the work covers.
What you collect and disclose
Mapping what the business actually collects against what its notices and policies say, so the two match. Privacy policies, disclosures, and consent that describe reality rather than a template borrowed from another company.
Vendors, analytics, and AI
What your analytics, advertising, and AI vendors do with the data you send them, the contract terms that keep it in bounds, and the exposure created when a vendor retains, enriches, trains on, or resells data you were responsible for.
Obligations across states and sectors
Privacy obligations vary by state and by the kind of data involved. Building a posture that holds up across the states you operate in and the data you hold, rather than a single policy that fits none of them well.
Data as an asset
Whether the data you already hold can be developed into a licensable or revenue-generating product, and the rights, consents, and agreements required to do that lawfully.
Incidents and inquiries
Responding to a data incident, a regulator’s inquiry, or a dispute with a vendor or customer over how data was used or shared.
The advantage is seeing what the vendor sees.
My background is in technology and in the analytics and AI work that most privacy questions now turn on. I can look at what a vendor actually does with your data, not only at what its contract says it does.
That distinction is where the exposure lives. A tool that quietly retains, enriches, or trains on the data you send it creates an obligation your privacy policy may not describe, and no amount of policy language fixes a data flow no one has traced.
The same view finds value. The data a company collects as a byproduct is often an asset in its own right, and seeing that, together with what it would take to use it lawfully, is the other half of this work.
Diagnosis before recommendation
What looks like a policy problem is often a data-flow problem, and a policy cannot describe what no one has mapped. The work starts with what actually happens to the data, then turns to what to say about it.
Built for the obligation to come
A privacy posture is eventually read by a regulator, a customer’s counsel, or an acquirer’s diligence. It is documented from the start to hold up under that reading rather than to look complete.
Scope and fees
Scope, responsibilities, and fee structure are established in writing before work begins. Depending on the matter, engagements proceed on an hourly, fixed-fee, or phased basis.
Direct access to counsel
Correspondence, analysis, and strategic decisions come from me directly.
What people ask first.
What does my business’s privacy policy actually need to say?
It needs to describe what your business actually does with data, which means it cannot honestly be written before that is known. At a minimum it should reflect what you collect, why, who you share it with, and the choices you offer, and it has to match reality, because the gap between a policy and the actual data practice is what creates exposure. A policy copied from another company is a common source of that gap rather than a fix for it.
What are my analytics and AI vendors allowed to do with the data I send them?
Generally only what their contract permits, which is often broader than businesses assume. Many analytics, advertising, and AI tools reserve the right to retain, aggregate, enrich, or train on the data they receive. The controlling document is the data-processing or terms-of-service agreement, and the practical step is to read what it actually allows, then narrow it where the permitted use exceeds what you can stand behind to your own customers.
Does my business have to comply with other states’ privacy laws?
Possibly, and it does not depend only on where you are located. A number of states have privacy laws that can reach a business based on the residents whose data it handles and on thresholds that vary by state, so a company can owe obligations in states where it has no office. Because applicability turns on specific facts about your data and operations, it is worth assessing directly rather than assuming a single state’s rules are the whole picture.
Can my company make money from the data it already collects?
Sometimes, and doing so lawfully depends on how the data was gathered and what was promised at the time. The questions are whether your rights and the consents you obtained permit the intended use, whether any of the data is personal or otherwise regulated, and what your contracts allow. When those align, data collected as a byproduct can become a licensable asset. The analysis belongs before the data is built into a product, not after.
Your data is already an obligation. The work is to make it an asset as well.