Sophisticated Compliance Lawyer for Companies Navigating AI, Privacy, and Global Regulatory Risk

Free Consultation

20 Years Legal Experience | 1000+ Contracts Negotiated | 100+ Clients Represented
Philadelphia, PA and US-wide

Some of the Laws I work with:

GDPR

The 2018 privacy regulation of the European Economic Are and the United Kingdom set the standard for the world’s toughest data protection law.

COPPA

This US federal privacy law regulates certain collection of personal data of children under 13 years of age online.

CCPA

The first comprehensive US state privacy law was adopted by California and later amended by voters in the CPRA. A dozen state laws followed.

FERPA

Vendors to schools often have questions about this US privacy law regulating the data of colleges and other schools.

HIPAA

The leading US privacy law regulating protected health information of doctors, hospitals, health plans and their business associates.

GLBA

This federal privacy law in the US regulates non-public personal information at financial institutions.

BIPA

The Illinois Biometric Information Privacy Act requires written consent for collection and use of biometric identifiers of Illinois residents.

TCPA

Established the National Do Not Call Registry and limits robocalls and telemarketing to consumers.

Insights - Latest News & Thoughts

Buy-Sell Agreements: Protecting Your Business When Co-Owner Situations Change

A buy-sell agreement is the legal mechanism that governs what happens to an owner’s interest in a business when they die, become disabled, divorce, retire, or want to exit. Without one, co-owner transitions can become chaotic, expensive, and destructive to the business. This guide explains how buy-sell agreements work and what they must address.

Arbitration Clauses in Commercial Contracts: Benefits, Risks, and Drafting Considerations

Arbitration clauses are among the most consequential provisions in any commercial contract — they determine whether disputes are resolved in court or before a private arbitrator. This guide explains how arbitration works, when it benefits businesses, how to draft effective clauses, and where arbitration can go wrong.

Consumer Protection and the FTC Act: What Every Business Must Know

The FTC Act prohibits unfair or deceptive acts and practices in commerce — and it applies to virtually every US business. This guide explains what the FTC considers deceptive, how the unfairness standard works, what specific practices draw FTC enforcement, and how to keep your business’s marketing and sales practices on the right side of the law.

Music Licensing for Businesses: What You Need to Know

Playing music in your business — whether in a retail store, restaurant, gym, or on your website — requires a license. This guide explains how music copyright works, why streaming services don’t cover business use, what performing rights organizations require, and how to get the licenses your business actually needs.

Equity Compensation: Stock Options and Restricted Stock for Private Companies

Equity compensation is a powerful tool for attracting and retaining talent at private companies. This guide explains the key forms of equity — ISOs, NSOs, restricted stock, and RSUs — how they are taxed, and what companies and employees need to know before granting or receiving equity.

Employee Benefits Law: Required and Optional Benefits for US Employers

US employers face a layered set of legally required benefits obligations and must navigate complex rules when offering optional benefits. This guide explains which benefits are required by law, which trigger the ACA’s employer mandate, and what legal requirements apply to voluntary benefits programs.

Some of the Industries I serve:

Technology

Counsel to SaaS platforms, software developers, and hardware companies on a variety of compliance and privacy issues.

Startups

Representing tech and other companies from idea to exit with data protection and compliance.

Health Care & Life Sciences

I work with industry software vendors, VC-backed medical providers and others with their regulatory and privacy compliance.

eCommerce

Advising online sellers with privacy and security.

Financial Services

I work with fintech companies and bank software providers on privacy and security such as the Gramm Leach Bliley Act.

Advertising & Marketing

Working with companies engaged in advertising and marketing with privacy compliance

AI / ML

Counsel to companies implementing AI such as LLMs with best practices, contracting and regulatory compliance.

Cryptocurrency

Bitcoin, crypto and smart contracts pose interesting compliance and privacy challenges.

Why choose Rob Melton Law

Experienced

15+ year legal professional with extensive business and startup experience.

Entrepreneurial

I am a business person and investor so I understand what my clients want in a lawyer.

Detail Oriented

As a former options trader I understand that the details matter.

Flexible

I have seen throughout my career that there is more than one way to achieve the necessary result.

+1 267 978 4292

rob@robmelton.com

Audubon, PA, US

Mon–Friday: 9:00 AM–5:00 PM
Sat-Sun: By Appointment

Experience

Robert Melton has represented businesses and their legal teams in complex regulatory and compliance matters for nearly two decades. His practice is built on a foundation of transactional depth — he has negotiated and drafted more contracts, data protection agreements, and compliance documents than most lawyers see in a career — combined with substantive regulatory expertise that spans AI governance, privacy law, healthcare compliance, anti-corruption, employment, intellectual property, and global trade. When clients bring him a problem, they get a lawyer who has almost certainly encountered a version of it before.

Contract Drafting and Policy Development

Rob drafts and negotiates the full range of technology and data protection agreements that businesses need: SaaS contracts, software licensing agreements, data licensing and sharing arrangements, enterprise security addendums, and AI-specific contractual provisions for companies deploying machine learning and generative AI. He also drafts the internal frameworks that sit behind those agreements — information security policies, incident response plans, business continuity and disaster recovery programs, HIPAA policies and procedures, and privacy and security training materials. He approaches every document as a working business instrument, not a legal formality. The goal is a contract that does what the client needs it to do and holds up under pressure.

A Track Record of Excellence

Since the GDPR took effect in May 2018, Rob has accumulated a body of transactional experience in data protection and privacy law that is unusual in its depth. He has reviewed and negotiated hundreds of data processing addendums, hundreds of business associate agreements, hundreds of enterprise security addendums, hundreds of standard contractual clauses, and hundreds of technology vendor agreements on data protection matters. He has negotiated thousands of indemnification clauses and liability caps in data protection contexts — enough to know precisely where the real risk concentrates and where the boilerplate is noise. He has handled dozens of student data protection agreements for EdTech companies, dozens of AI and generative AI agreements, dozens of data licenses, and dozens of NDAs. Volume matters in legal practice: patterns emerge at scale, and a lawyer who has seen hundreds of the same type of agreement stops being surprised by the hard issues and starts being efficient at resolving them.

Data Protection and Incident Response

Rob has guided dozens of companies through security incidents — from the first hours of discovery through the legal investigation, regulatory notification analysis, and remediation process. He has advised companies on hundreds of GDPR and CCPA compliance questions across industries and company sizes. He has led the legal workstream for companies navigating international data transfer challenges following Schrems II, including the assessment and implementation of standard contractual clauses and transfer impact assessments. He understands that data protection advice is most valuable when it is practical and actionable under the constraints that real businesses actually operate within.

Mergers & Acquisitions

Rob regularly serves as data protection and regulatory diligence counsel in M&A transactions. He has represented buyers on data protection and compliance in dozens of private equity rollups and B2B startup acquisitions, and in more than a dozen transactions involving reps and warranties insurance, where the rigor of the diligence directly affects the scope and reliability of coverage. He has advised more than a dozen healthcare companies on HIPAA and data protection in the M&A process. He has represented sellers across the advertising, ecommerce, financial services, healthcare, and technology industries. M&A diligence is not a checklist — it is a risk assessment that has to be calibrated to deal structure, purchase price, and the operational realities of integration. Rob approaches it that way.

Regulatory Compliance and Government Investigations

Beyond transactional work, Rob has advised clients across a wide range of regulatory compliance matters and government proceedings. He has assisted companies with export compliance under the EAR and ITAR, EEOC investigations involving employment discrimination claims, False Claims Act matters, Foreign Corrupt Practices Act compliance and internal investigations, and inquiries from the SEC and CFTC. He has managed subpoena responses for corporate clients and guided companies through voluntary self-disclosure processes with federal enforcement agencies. This regulatory breadth reflects the nature of his practice: the businesses he advises operate in complex, multi-front regulatory environments, and they need a lawyer who can follow the problem wherever it leads.

My Services

Contract Drafting and Negotiation

Get assistance and advice from experienced contracting counsel.

From $550/hour

  • Data Processing Addendums
  • Business Associate Agreements
  • Security Addendums

Ready your startup for enterprise software sales.

Leverage my policy templates for fast and efficient drafting.

From $550 / hour

  • Written Information Security Policy
  • Security Incident Response Policy
  • Business Continuity and Disaster Recovery Plan
  • More

Conduct a Gap Analysis to improve your Compliance

Review your policies, procedures and practices for compliance with the law and best practices.

Get an Hourly or Flat Free Proposal

Incident Response and More!

Get assistance in a data breach or start planning your response by bolstering your incident response policy, conducting a tabletop exercise and lining up your vendors.

Get an Hourly or Flat Free Proposal