PRIVACY & SECURITY COUNSELING
In her legal practice, Karachi Achilihu carefully assesses the legal implications of data-driven technology transactions by evaluating the privacy, security, and governance of the data involved in such deals. As privacy & security counsel, TECH ESQ.® advises clients on:
Contractual compliance with global, federal, and state privacy laws and regulations (e.g., GDPR, CCPA, GLBA, HIPAA, and COPPA) governing the collection, processing, use, and sharing of personal data during technology transactions
Contractual alignment with industry-standard data security frameworks (e.g., SOC 2 Type I & II, NIST CSF 2.0, ISO/IEC 27001 & 27701, NIST AI RMF 1.0, DORA, and PCI DSS) and additional administrative, physical, technical, and organizational measures designed to ensure the security of data
Privacy program management throughout the data lifecycle (e.g., privacy assessments, privacy by design, data categorization, data mapping, data residency, data subject rights, privacy policies, privacy incident procedures, third-party risk management, and other data governance considerations)
As an informed privacy professional, TECH ESQ.® helps businesses operationalize privacy and data security considerations in technology transactions — enabling organizational compliance with a myriad of laws requiring trustworthy privacy & data protection practices.