Sophisticated Compliance Lawyer for Companies Navigating AI, Privacy, and Global Regulatory Risk
Free Consultation
20 Years Legal Experience | 1000+ Contracts Negotiated | 100+ Clients Represented
Philadelphia, PA and US-wide
Some of the Laws I work with:
GDPR
The 2018 privacy regulation of the European Economic Are and the United Kingdom set the standard for the world’s toughest data protection law.
COPPA
This US federal privacy law regulates certain collection of personal data of children under 13 years of age online.
CCPA
The first comprehensive US state privacy law was adopted by California and later amended by voters in the CPRA. A dozen state laws followed.
FERPA
Vendors to schools often have questions about this US privacy law regulating the data of colleges and other schools.
HIPAA
The leading US privacy law regulating protected health information of doctors, hospitals, health plans and their business associates.
GLBA
This federal privacy law in the US regulates non-public personal information at financial institutions.
BIPA
The Illinois Biometric Information Privacy Act requires written consent for collection and use of biometric identifiers of Illinois residents.
TCPA
Established the National Do Not Call Registry and limits robocalls and telemarketing to consumers.
Insights - Latest News & Thoughts
Some of the Industries I serve:
Technology
Counsel to SaaS platforms, software developers, and hardware companies on a variety of compliance and privacy issues.
Startups
Representing tech and other companies from idea to exit with data protection and compliance.
Health Care & Life Sciences
I work with industry software vendors, VC-backed medical providers and others with their regulatory and privacy compliance.
eCommerce
Advising online sellers with privacy and security.
Financial Services
I work with fintech companies and bank software providers on privacy and security such as the Gramm Leach Bliley Act.
Advertising & Marketing
Working with companies engaged in advertising and marketing with privacy compliance
AI / ML
Counsel to companies implementing AI such as LLMs with best practices, contracting and regulatory compliance.
Cryptocurrency
Bitcoin, crypto and smart contracts pose interesting compliance and privacy challenges.
+1 267 978 4292
rob@robmelton.com
Audubon, PA, US
Mon–Friday: 9:00 AM–5:00 PM
Sat-Sun: By Appointment
Experience
Robert Melton has represented businesses and their legal teams in complex regulatory and compliance matters for nearly two decades. His practice is built on a foundation of transactional depth — he has negotiated and drafted more contracts, data protection agreements, and compliance documents than most lawyers see in a career — combined with substantive regulatory expertise that spans AI governance, privacy law, healthcare compliance, anti-corruption, employment, intellectual property, and global trade. When clients bring him a problem, they get a lawyer who has almost certainly encountered a version of it before.
Contract Drafting and Policy Development
Rob drafts and negotiates the full range of technology and data protection agreements that businesses need: SaaS contracts, software licensing agreements, data licensing and sharing arrangements, enterprise security addendums, and AI-specific contractual provisions for companies deploying machine learning and generative AI. He also drafts the internal frameworks that sit behind those agreements — information security policies, incident response plans, business continuity and disaster recovery programs, HIPAA policies and procedures, and privacy and security training materials. He approaches every document as a working business instrument, not a legal formality. The goal is a contract that does what the client needs it to do and holds up under pressure.
A Track Record of Excellence
Since the GDPR took effect in May 2018, Rob has accumulated a body of transactional experience in data protection and privacy law that is unusual in its depth. He has reviewed and negotiated hundreds of data processing addendums, hundreds of business associate agreements, hundreds of enterprise security addendums, hundreds of standard contractual clauses, and hundreds of technology vendor agreements on data protection matters. He has negotiated thousands of indemnification clauses and liability caps in data protection contexts — enough to know precisely where the real risk concentrates and where the boilerplate is noise. He has handled dozens of student data protection agreements for EdTech companies, dozens of AI and generative AI agreements, dozens of data licenses, and dozens of NDAs. Volume matters in legal practice: patterns emerge at scale, and a lawyer who has seen hundreds of the same type of agreement stops being surprised by the hard issues and starts being efficient at resolving them.
Data Protection and Incident Response
Rob has guided dozens of companies through security incidents — from the first hours of discovery through the legal investigation, regulatory notification analysis, and remediation process. He has advised companies on hundreds of GDPR and CCPA compliance questions across industries and company sizes. He has led the legal workstream for companies navigating international data transfer challenges following Schrems II, including the assessment and implementation of standard contractual clauses and transfer impact assessments. He understands that data protection advice is most valuable when it is practical and actionable under the constraints that real businesses actually operate within.
Mergers & Acquisitions
Rob regularly serves as data protection and regulatory diligence counsel in M&A transactions. He has represented buyers on data protection and compliance in dozens of private equity rollups and B2B startup acquisitions, and in more than a dozen transactions involving reps and warranties insurance, where the rigor of the diligence directly affects the scope and reliability of coverage. He has advised more than a dozen healthcare companies on HIPAA and data protection in the M&A process. He has represented sellers across the advertising, ecommerce, financial services, healthcare, and technology industries. M&A diligence is not a checklist — it is a risk assessment that has to be calibrated to deal structure, purchase price, and the operational realities of integration. Rob approaches it that way.
Regulatory Compliance and Government Investigations
Beyond transactional work, Rob has advised clients across a wide range of regulatory compliance matters and government proceedings. He has assisted companies with export compliance under the EAR and ITAR, EEOC investigations involving employment discrimination claims, False Claims Act matters, Foreign Corrupt Practices Act compliance and internal investigations, and inquiries from the SEC and CFTC. He has managed subpoena responses for corporate clients and guided companies through voluntary self-disclosure processes with federal enforcement agencies. This regulatory breadth reflects the nature of his practice: the businesses he advises operate in complex, multi-front regulatory environments, and they need a lawyer who can follow the problem wherever it leads.
Contract Drafting and Negotiation
Get assistance and advice from experienced contracting counsel.
From $550/hour
- Data Processing Addendums
- Business Associate Agreements
- Security Addendums
Ready your startup for enterprise software sales.
Leverage my policy templates for fast and efficient drafting.
From $550 / hour
- Written Information Security Policy
- Security Incident Response Policy
- Business Continuity and Disaster Recovery Plan
- More
Conduct a Gap Analysis to improve your Compliance
Review your policies, procedures and practices for compliance with the law and best practices.
Get an Hourly or Flat Free Proposal
Incident Response and More!
Get assistance in a data breach or start planning your response by bolstering your incident response policy, conducting a tabletop exercise and lining up your vendors.
Get an Hourly or Flat Free Proposal










