Skip to Main Content

Overview


Businesses rely on data to operate, grow, market, innovate, and compete. That same data now creates significant legal, regulatory, operational, and reputational risk. Baker Donelson helps each client understand and manage those risks through practical privacy and data compliance counsel tailored to their business, industry, technology, and growth strategy.

Our Data Privacy and Compliance team advises clients across the full data lifecycle, from product development and data collection to vendor management, cross-border transfers, regulatory compliance, incident response, and litigation risk. We work with startups, middle-market companies, and large enterprises in highly regulated and data-intensive industries, including health care, financial services, technology, education, manufacturing, and consumer-facing businesses.

We help clients move beyond check-the-box compliance. Our approach is designed to support business objectives while reducing legal exposure, strengthening governance, and building trust with customers, employees, partners, and regulators.

More than one-third of our team is credentialed with the world's largest privacy organization, the International Association of Privacy Professionals (IAPP), as well as other credentialing organizations, including:

  • Artificial Intelligence Governance Professional (AIGP)
  • United States-focused Certified Information Privacy Professional (CIPP/US)
  • Europe-focused Certified Information Privacy Professional (CIPP/E)
  • Canadian-focused Certified Information Privacy Professional (CIPP/C)
  • Privacy management-focused Certified Information Privacy Manager (CIPM)
  • GIAC Law of Data Security & Investigations (GLEG)
  • Privacy Law Specialist (PLS)
  • Payment Card Industry Professional (PCIP)
  • Certified Information Security Manager (CISM)
  • Certified Information Systems Security Professional (CISSP)
  • Qualified Technology Expert (QTE)
  • Certified Information Privacy Technologist (CIPT) 

Core Service Areas

We counsel clients startups to Fortune 100 companies in an array of industries, including  health care, financial services, technology, education, and manufacturing on privacy issues and compliance programs. Our services span the full data lifecycle:

Regulatory Compliance Counseling

We provide skilled regulatory compliance counseling and guidance on the full range of privacy laws in existence today including the California Consumer Privacy Act (CCPA), General Data Protection Regulation (GDPR),state biometric privacy laws, behavioral advertising, the growing number of comprehensive state consumer privacy statutes, and a myriad of other regulatory schemes such as Health Insurance Portability and Accountability Act (HIPAA) and the Gramm-Leach-Bliley Act (GLBA).

Proactive Risk Management and Strategy

We provide companies with strategic advice on how to address and mitigate the growing legal risks that arise when leveraging personal data, including class action litigation readiness, clickwrap agreement design, data retention and destruction programs, internal policies and procedures, and employee training. We also advise on novel liability risks, including those stemming from marketing technology, tracking pixels, age verification, and the increasing threat of mass arbitration.

Product Counseling

We counsel companies as they bring new data-powered products and services to market, including software related to artificial intelligence (AI) and continue providing strategic guidance throughout the duration of the product and data lifecycle. We work closely with business and legal teams in the development and launch of new products and services, and we continue to provide strategic guidance post-launch to facilitate continued, long-term compliance and risk mitigation.

Compliance Program and Policy Development

We partner with companies to develop comprehensive, enterprise-wide compliance programs for all types of technologies and all forms of personal data. Our services include auditing current organizational data practices; developing remediation plans to address and eliminate compliance gaps; drafting and updating privacy policies, website notices, cookie consent mechanisms, data processing agreements, and other external-facing disclosure; and advising on the development and implementation of additional strategic measures to facilitate ongoing legal compliance and manage anticipated risk.

Technology Contract Negotiations and Guidance

We draft and negotiate complex technology agreements that implicate personal data, including data processing agreements, data sharing and licensing agreements, and AI vendor agreements. We also provide guidance and counseling, including benchmarked considerations pertaining to personal data, to companies involved in negotiating technology contracts, as well as advice on existing agreements involving data rights and obligations.

Vendor and Third-Party Risk Management

Vendors and other third-party relationships represent one of the most sizeable risk vectors associated with the use of personal data. We advise companies on a full range of vendor risk management initiatives, including vendor due diligence, contract provisions addressing data rights, and negotiation strategies to limit downstream liability.

Privacy Litigation

We represent and advise companies facing privacy-related litigation, including class actions and regulatory investigations arising from alleged data breaches, violations of privacy laws, including the California Invasion of Privacy Act (CIPA), Video Privacy Protection Act (VPPA), and state wiretapping laws, and misuse of personal data. Our team provides strategic defense and works proactively to minimize litigation risks by guiding clients through pre-litigation assessments, developing tailored response strategies, and supporting settlement negotiations when appropriate. We stay ahead of evolving privacy regulations and enforcement trends to help clients navigate complex legal challenges effectively.

Featured Videos


Digital Tracking Under Pressure: Compliance, Litigation, and the Path Forward August 28, 2025
Human Resources' Evolving Role with Technology Changes Including AI, Privacy, and Cybersecurity – A Survival Guide June 18, 2025
2025 Cybersecurity & Data Privacy Outlook: Trends, Threats, and Tactics January 28, 2025

Results may vary depending on your particular facts and legal circumstances.

  • Privacy Compliance and Counseling

  • Assisted a nationwide e-commerce beverage company with comprehensive privacy compliance initiatives, including drafting and modernizing privacy policies, advising on data collection and use practices, and aligning operations with evolving U.S. state privacy laws.

  • Advised a nonprofit organization on global privacy compliance, including the structuring of cross-border data transfer mechanisms and the application of international privacy frameworks to the organization's multijurisdictional operations.

  • Advised a credit union on various cybersecurity and data privacy initiatives including updates to the organization's incident response plan, enhancement of privacy and security procedures, and facilitation of tabletop exercises to test response procedures and improve coordination among business, legal, compliance, and technology stakeholders.

  • Advised a financial services lending institution on the development and implementation of updated privacy policies and procedures designed to achieve compliance with applicable state privacy laws, with particular focus on the permissible use of consumer data in connection with digital marketing activities.

  • Drafted and negotiated a comprehensive data access agreement for a financial services institution, enabling secure and compliant information sharing with third parties.

  • a comprehensive enterprise service agreement, data processing agreement, and platform terms of service for a school digital media management provider.

  • Counseled an academic medical center in the creation of a website cookies consent program and privacy policy.

  • Privacy Litigation

  • Defended the world's largest food distributor in a multidistrict class action litigation stemming from a significant data breach. Served as lead counsel in consolidating lawsuits nationwide, securing multiple dismissals, and engaging in early motion practice that set the stage for a favorable settlement.

  • Successfully defended a health care provider in a class action complaint alleging violations of patient privacy rights. Obtained dismissal of the entire complaint.

  • Lead counsel for a national financial services company in defending more than 20 class action lawsuits following a data breach impacting more than 500,000 individuals nationwide. Defense includes coordination of multidistrict litigation and the representation of numerous defendants, including several hospital systems.

  • Currently representing a health care system in a putative CIPA wiretapping class action involving Microsoft Clarity session replay software.

  • Successfully defended a popular online ceiling fan manufacturer in two successive lawsuits involving website tracking technologies and TCPA claims. Our team negotiated early, favorable resolutions while also strengthening the company's compliance posture and reducing the risk of future claims.

  • Successfully defended an American fast-casual restaurant chain in litigation alleging website violations of the Americans with Disabilities Act (ADA). Our team conducted a privileged investigation, assessed accessibility compliance, and crafted a strategy focused on early resolution, which resulted in a favorable outcome for the client.

  • Defended an automotive original equipment manufacturer (OEM) against a $7.5+ billion class action filed in Florida challenging session replay software that allegedly tracks users' activities on websites. Shortly after we obtained an early-stage stay of discovery, the plaintiff voluntarily dismissed the case with no settlement.

  • Currently defending an automotive OEM against a class action brought under the California Invasion of Privacy Act (CIPA) in state court.

  • Defended a regional health care entity in a pending class action filed in Tennessee state court alleging violation of Tennessee's State Wiretapping Act.

  • Successfully defended a national online retail client against multiple Video Privacy Protection Act (VPPA) class actions filed in New York and Florida; the cases were dismissed at the motion-to-dismiss phase before a class could be certified.

  • Achieved dismissal for an insurance company from a Telephone Consumer Protection Act (TCPA) class action lawsuit in which it had been wrongly targeted.

  • Defended a plastic surgery medical practice against a class action lawsuit alleging violation of Florida state privacy law.

  • Facilitated a nuisance-value, individual settlement for an innovative building and siding solutions company in a putative CIPA trap-and-trace class action through informal negotiations with opposing counsel.

  • Facilitated a nuisance-value, individual pre-suit settlement for a health care provider in a threatened CIPA pen register/trap-and-trace class action through negotiations with opposing counsel.

  • Facilitated a nuisance-value, individual pre-suit settlement for a global specialty chemical company in a threatened CIPA pen register/trap-and-trace class action through negotiations with opposing counsel.

  • Obtained a dispositive, voluntary dismissal of a global biometric identity verification technology provider in a putative BIPA class action involving a cryptocurrency exchange customer's use of a biometric identity verification solution through informal discussions with opposing counsel.

Email Disclaimer

NOTICE: The mailing of this email is not intended to create, and receipt of it does not constitute an attorney-client relationship. Anything that you send to anyone at our Firm will not be confidential or privileged unless we have agreed to represent you. If you send this email, you confirm that you have read and understand this notice.
Cancel Accept