• Skip to content
  • Skip to primary sidebar

Davis+Gilbert LLP

From our base in New York, we represent a diverse range of clients across the country and around the world.

  • People
  • Services
  • Emerging Issues

Privacy, Technology + Data Security

bookmarkprintPDFShare>
  • Overview
  • Breach Response and Ransomware
  • Data, Digital Media and Ad Tech
  • Privacy Compliance and Internal Policies
  • Technology Transactions

The increasingly intertwined concerns of privacy and data security continue to cast a long shadow over the business models of companies in nearly every industry. Both concerns carry considerable risk — legal, financial and reputational — but with proper attention to the statutory and contractual requirements that underlie and inform the risk, they can be turned to competitive advantage.

Our attorneys represent data-driven businesses of all kinds, with particular strengths in the areas of digital media, marketing, ad tech and e-commerce. We work with clients from many industries — including retail, media, healthcare, finance and a broad array of technology businesses — to identify and address the compliance risks associated with data flowing in and out of their organizations. Given our deep understanding of these industries, we advise clients regarding best practices, assess their associated contracts, prevent and respond to data breaches, and defend them in litigation and enforcement actions.

Avoiding Privacy Risk

It is now a given that privacy laws in most jurisdictions will undergo perpetual change, and that ad tech and e-commerce, in particular, will be constant targets of new regulation. Our clients look to us to advise them regarding their privacy practices — how they interact with consumers, how they collect and use data, how they build new services, when and how they make disclosures — while keeping a sharp focus on their ongoing regulatory obligations. As they enter into new agreements with vendors and customers, we advise them on the likely effects of these arrangements and how to minimize their risk. In areas where the laws are not fully evolved, we keep them apprised of best practices and any self-regulatory guidelines imposed by their industry.

Monitoring Data Security

As the alarming frequency of data breaches has become an inevitable cost of doing business, our clients count on us to guide their prevention of, and their response to, data security incidents. We help establish their data security protocols, updating policies and controls as needed, in order to maintain both compliance and vigilance. Should a breach occur, we manage the response team, investigate the incident, notify the required authorities and conduct any post-breach remediation.

Forging Technology Contracts

Businesses are constantly entering into contractual arrangements involving a broad array of evolving technologies, including AI, SaaS platforms and ad tech services. Accordingly, we regularly draft contracts for technology-forward companies in virtually every industry sector, including advertising, e-commerce, financial services, manufacturing, hospitality, retail, entertainment, media and real estate. These extend to technology development, licensing, as well as purchases, sales and joint ventures. To each transaction, we bring a deep understanding of both the technology and the underlying business.

Children’s Privacy and Other Special Data Categories

The firm’s long history of leadership in the legal aspects of children’s advertising has been seamlessly adapted to the digital age. We are thoroughly versed in the special concerns afforded children in the collection and uses of personal data, including our broad experience with the Children’s Online Privacy Protection Act (COPPA), as well as with the advertising industry’s self-regulatory body — the Children’s Advertising Review Unit (CARU). We are also deeply knowledgeable in the privacy laws governing other regulated industries. These include the financial services industry, under the Gramm-Leach-Bliley Act (GLBA), and the healthcare industry’s Health Insurance Portability and Accountability Act (HIPAA).

Litigation, Incident Response, Audits

Despite an organization’s best efforts, privacy and data security issues are inevitable. We offer a comprehensive suite of services, taking a cross-disciplinary approach to any matter. Our litigation team handles privacy disputes, such as TCPA claims and liability due to security breaches. Our incident response team can be mobilized quickly in the event of a breach. We also work with clients on preventive and mandated security compliance audits.

Representative Experience

  • Represented an ad tech company in connection with multiple third-party subpoenas and DOJ investigations into the practices of other industry players. Advised on sensitive issues over sharing confidential business strategies and critiquing the practices of other industry participants.

  • Counseled one of the largest media companies in Europe on privacy issues connected with launching a new service in the U.S. Helped the client synchronize requirements under EU and U.S. privacy laws and advised on best practices in the U.S.

  • Advised a social media analytics agency in connection with privacy and data security, including GDPR and CCPA, for both internal and client-facing policies, protocols and data processing form agreements. This ensured the media platform was legally compliant and protected while also remaining customer-friendly.
  • Represented one of the world's largest media buyers in the negotiation of agency-wide agreements with DSPs and other critical media buying platforms and updated templates to address novel content production issues.

  • Advised a large agency regarding a security breach that involved the exposure of thousands of employee W-2 records. Coordinated with law enforcement and the IRS regarding hundreds of unauthorized requests for tax refunds.

  • Advised an international clothing brand on privacy issues connected with launching its e-commerce service for the U.S. market. Helped the client synchronize requirements under EU and U.S. privacy laws and advised on best practices in the U.S.

  • Advised the developer of a popular content creation application on the use of open-source software in mobile app development. Helped the client understand different open-source license terms and usage implications to ensure that their proprietary application retained its value.

Key Contacts

  • Attorney Richard Eisert

    Richard S. Eisert

    Partner/Co-Chair Advertising + Marketing

    Area Of Focus

    • Privacy, Technology + Data Security
    • Advertising + Marketing
    • Intellectual Property + Media
    212 468 4863
    reisert@dglaw.com
  • Attorney Gary Kibel

    Gary Kibel

    Partner

    Area Of Focus

    • Privacy, Technology + Data Security
    • Advertising + Marketing
    212 468 4918
    gkibel@dglaw.com
  • View All
Meet The Team

Primary Sidebar

  • Overview
  • Breach Response and Ransomware
  • Data, Digital Media and Ad Tech
  • Privacy Compliance and Internal Policies
  • Technology Transactions

Insights + Events

  • Podcast The Monopoly Report | Kids Privacy in the Ad Space

    June 4, 2025

  • Event Network Advertising Initiative (NAI) | NAI Summit: Moving Privacy Forward

    May 21, 2025

  • View More

Related Services

  • Advertising + Marketing
  • Public Relations

Get the latest insights from Davis+Gilbert

Subscribe
  • Sitemap
  • Privacy Policy
  • Terms and Conditions
  • Accessibility Statement
  • About Us
  • Location
  • Subscribe
© 2025 Copyright Davis+Gilbert LLP. Attorney Advertising.
  • People
  • Services
  • Emerging Issues
  • Insights + Events
  • Culture + Community
  • Pro Bono + Corporate Social Responsibility
  • Careers
  • About Us
  • Subscribe
  • Location
This site uses cookies to store information on your device. These cookies either support essential functions of the site or are used to develop analytics regarding usage of our site. Click Accept to continue using the site with our recommended settings or click Decline to disable non-essential cookies.AcceptDecline