From the not too long ago launched American Privacy Rights Act—which proposes new federal client privateness requirements—to quite a few state-level payments, to current and impending synthetic intelligence laws, the info privateness panorama is evolving at lightning pace.
Compliance considerations at the moment are entrance and heart for organizations of all sizes—overseas and in america. Whereas it’s unlikely that laws will move on the federal degree, states have clearly demonstrated a willingness to move and implement complete privateness legal guidelines.
California led as the primary state when it passed the California Consumer Privacy Act (signed into regulation in 2018 and went into impact in 2020). And it was then joined by Virginia, Colorado, Utah and Connecticut, all of which have been carried out in 2023 with new client privateness legal guidelines. By the date of this text, at least 19 states have handed complete privateness laws (with implementation dates in 2025 and 2026).
Make no mistake: Sustaining privateness compliance is a fancy transferring goal, and the checks and balances that your organization wanted 10 years in the past don’t even scratch the floor of what you want at the moment. As a common counsel, you should be capable of assemble a robust, adaptable authorized group that may assist your organization keep compliant with present requirements and anticipate and reply to the various adjustments coming down the pike.

Key issues for GCs
When making ready for the brand new frontier of privateness and information safety, take into account how your division and group will deal with the next important points.
  1. Possession of privateness issues. Who’s accountable for privateness considerations inside your group—is it the authorized division solely? If you happen to do have a privateness group, how does your group accomplice with authorized to make sure that all bases are coated? As information privateness considerations grow to be more and more paramount to your operations and threat administration efforts, you might need to take into account the advantages of getting a separate, devoted group for these points. This laser-focused help may help your organization preserve updated with regulatory adjustments and reply with the mandatory insurance policies and procedures, thereby lowering the danger of violations and hefty fines. What’s extra, a freestanding privateness group is usually a bridge between varied departments, guaranteeing that privateness is taken into account throughout all enterprise capabilities.
  2. Drafting of privateness notices. Given current and rising laws, the drafting of privateness notices and privacy-related contract provisions has taken on new urgency for companies that deal with client information. Poorly drafted notices can expose your enterprise not solely to authorized dangers but in addition to fines and reputational harm. Whereas most attorneys have a level of ability in drafting these notices, take into account whether or not you will have the fitting particular person dealing with this process. A seasoned privateness lawyer understands the authorized nuances of your organization’s information monitoring, assortment, processing, storage and sharing practices. They’ll additionally assist steadiness authorized compliance and person accessibility by ensuring that every one privateness notices are clear, clear and simply comprehensible for shoppers.
  3. Implications of AI expertise. AI isn’t just the buzzword of the second; it’s probably one of many greatest technological revolutions in human historical past. Generative AI and different sorts of machine studying are being carried out in several applied sciences, by almost all corporations and distributors of all types, at a fast tempo. That implies that even when your organization isn’t in a regulated trade, you’ll nonetheless have to fret about being regulated by any AI legal guidelines on the horizon.
The European Union took step one within the march towards AI regulation, with the EU Artificial Intelligence Act taking impact throughout all 27 member states Aug. 1. Whereas some provisions are already energetic, by 2026, most of this regulation’s provisions will go into power.
Not eager to fall behind, Congress has proposed federal laws, and the White Home and businesses, such because the Federal Commerce Fee, the Securities and Change Fee and the Equal Employment Alternative Fee have offered guidance on the topic.
Many states are being proactive, with Colorado and Illinois passing AI laws in 2024 that take impact in 2026. Moreover, on the finish of its 2024 legislative session, California passed numerous AI bills.
The plethora of AI laws could have vital world implications for corporations that develop, deploy or function AI programs—no matter the place they’re on the earth. Corporations worldwide must put money into AI governance; adapt their applied sciences to satisfy these regulatory requirements; and be certain that their AI programs are lawful, moral and reliable (or else face penalties and enterprise restrictions within the EU or different markets).
Even when your organization is utilizing AI not directly (e.g., via a third-party vendor) and never actively growing AI instruments, it’ll face unprecedented new calls for on this space. You may be obligated to explicitly define how you’re utilizing AI, implement an AI threat administration coverage, and carry out AI threat assessments.
These issues won’t be unique to the authorized/privateness group. As an alternative, it requires a multidisciplinary AI group that brings collectively key enterprise stakeholders, authorized, IT, information science, threat, data safety, advertising and different capabilities. As a GC, you will have to have the ability to perceive authorized’s position within the AI ecosystem and what you’re finally obligated to do to satisfy compliance requirements.
Think about versatile expertise who could make a direct impression
In case you are questioning whether or not your group has the bandwidth or experience to handle new and rising privateness calls for and you aren’t but prepared so as to add head depend, one possibility to contemplate is utilizing interim, or short-term, counsel. These attorneys may help lighten your load, whether or not it’s for a particular undertaking or a versatile vary of time, bringing in specialised authorized experience as you get your arms round new privateness laws. A privateness lawyer may help you rapidly assess privateness dangers, implement corrective measures, and prepare your inside groups.
Along with a wealth of privateness and/or AI experience, interim counsel can typically hit the bottom working with out a lot help. They provide rapid help and strategic steering for the long run—all with out the long-term dedication of a everlasting rent. That stated, you probably have an interim privateness lawyer that makes a stable addition to your group, you possibly can typically convert them to a everlasting worker down the highway.
Keep knowledgeable, agile and proactive
Getting ready your authorized group for the evolving privateness panorama isn’t just a matter of compliance—it’s a strategic necessity if you wish to keep forward of the curve. By educating your self on the adjustments to return, defining roles and obligations, and getting artistic with the way you construct your group, you can be poised to mitigate threat and emphasize your position as a trusted adviser to the enterprise.
Maureen Dry-Wasson is vice chairman, group common counsel and world privateness officer with the Allegis Group and Main, Lindsey & Africa. She has been an in-house lawyer for greater than 25 years and is a fellow of knowledge privateness with certifications from the Worldwide Affiliation of Privateness Professionals for AI governance privateness administration.
Iris Zuckerman is a managing director of consumer improvement with Main, Lindsey & Africa’s interim authorized expertise group in Chicago, working with regulation companies and authorized departments to determine high-quality authorized expertise to tackle short-term, project-based engagements.
Thoughts Your Enterprise is a collection of columns written by attorneys, authorized professionals and others inside the authorized trade. The aim of those columns is to supply sensible steering for attorneys on run their practices, present details about the most recent tendencies in authorized expertise and the way it may help attorneys work extra effectively, and techniques for constructing a thriving enterprise.
Inquisitive about contributing a column? Ship a question to [email protected].
This column displays the opinions of the creator and never essentially the views of the ABA Journal—or the American Bar Affiliation.