PRIVACY & DATA SECURITY COUNSELING

In her legal practice, Karachi Achilihu carefully assesses the legal implications of data-driven technology transactions by evaluating the privacy, security, and governance of the data involved in said deals. As privacy counsel, TECH ESQ.® advises clients on:

  • Contractual compliance with applicable global, federal, and state privacy laws and regulations (e.g., GDPR, CCPA, GLBA, HIPAA, COPPA) governing the collection, processing, use, and sharing of personal data during technology transactions

  • Contractual alignment with industry-standard data security frameworks (e.g., SOC2 Type I & II, NIST CSF 2.0, ISO/IEC 27001 & 27701, NIST AI RMF 1.0, DORA, PCI DSS, HITRUST CSF, and HITECH) and additional administrative, physical, technical, and organizational measures designed to ensure data security

  • Data governance throughout the data lifecycle, encompassing privacy assessments, data mapping, data residency, data subject rights, privacy policies, privacy incident procedures, third-party risk management, and other privacy compliance considerations

As an informed privacy professional, TECH ESQ.® helps businesses operationalize privacy and data security considerations in technology transactions — enabling organizational compliance with an evolving set of laws that require trustworthy privacy & data protection practices.