← All Practices

Information Security

If you collect data in any part of your business — financial, health, human resources, online behavioral data, private user communications and images — you face increasing financial and regulatory pressures to protect it. Threats come from all directions – disgruntled employees, lost laptops, organized crime syndicates, underground hacker groups, and foreign governments. The cost of a security breach is significant. You could lose intellectual property or trade secrets, sensitive consumer data, or customers’ trust and confidence. Running afoul of regulators and privacy watchdog groups is just as perilous to your bottom line.

We develop consumer-facing and internal privacy and security policies and incident response plans that can bring your company into compliance with applicable laws and help you keep pace with developing industry standards. Specifically, we help our clients with:

  • Compliance with the EU General Data Protection Regulation (GDPR), Data Privacy Framework (DPF), HIPAA, COPPA, Gramm-Leach Bliley, FCRA, FTC Rulings and Consent Decrees, and compliance with other federal, state, and international privacy laws.
  • Development of privacy policies that articulate corporate practices in a way that satisfies legal requirements and meets industry best practice guidance for plain language and transparency.
  • Development of written information security programs and incident response plans.
  • Internal mechanisms to facilitate the transfer of data to affiliates, foreign data storage locations, service providers, partners, and advertisers.
  • Internal reviews and checklists for determining compliance with regulatory requirements.
  • Contract provisions regarding data protection requirements.
  • Compliance plans for sensitive data, including data related to children, health, or other sensitive areas.
  • Employee training.

We can also help:

  • Advise on security breach investigations, user requirements, and defend resulting regulatory inquiries and civil litigation.
  • Conduct information security assessments.
  • Develop and implement policies and procedures to minimize vulnerabilities, including incident response plans, data breach notification procedures, record retention, and related policies.
  • Advise on the security requirements of HIPAA, COPPA, GLB, FCRA, state and local security breach notification laws, and other U.S. state, federal, and international security requirements.
  • Perform information security due diligence for corporate acquisitions or equity investments.

Billing That Works the Way You Do

We aren’t a typical law firm and we don’t bill like one either. We customize our billing practices to fit each client’s needs—building flexibility, transparency, and trust into every engagement. Whether through flat fees, monthly retainers, or competitive hourly rates, we focus on delivering clear value and predictable results, so you can plan confidently and stay focused on what matters most.

  • <h5>MONTHLY RETAINERS</h5>
    1

    MONTHLY RETAINERS

    We handle all of the legal work in a given area or subject matter for a monthly retainer, which we can adjust upward or downward as the work ebbs and flows.

  • <h5>FLAT/PROJECT FEES</h5>
    2

    FLAT/PROJECT FEES

    Under this model, we take the risk that we have underestimated the time that needs to be spent. If it takes longer, you still don’t pay more. If we are very efficient, we get the benefit of our efficiency.

  • <h5>COMPETITIVE HOURLY RATES</h5>
    3

    COMPETITIVE HOURLY RATES

    Because we work collectively to solve your problems, a majority of our attorneys are available for the same hourly rate, except our Fellows and Junior Attorneys who bill at lower rates and are perfect for tasks you don’t want to pay a legal veteran to do.

What clients are saying...

“I always feel like I get a calibrated response from ZwillGen on how to deal with particular types of issues. I think they are a friendly bunch of lawyers and do top notch work in terms of client service.”

Chambers Respondent

“ZwillGen provides a rapid response, dependability, quality service, and knowledge in the subject matter.”

Chambers Respondent

“ZwillGen specializes in all things privacy and data security. We use them for all of our privacy litigation and I find their advice to be extremely practical, business-friendly, and easy to implement.”

Chambers Respondent