Rob Melton Law advises US businesses across a broad range of regulatory and compliance domains. This page provides an overview of the firm’s core practice areas. Each section describes what the practice covers, the legal frameworks involved, and links to the substantive guides and articles available throughout this site. Whether you are a startup navigating privacy law for the first time, an enterprise managing global regulatory risk across multiple jurisdictions, or an in-house legal team seeking specialist counsel in a specific area, these resources are designed to help you understand where the law stands and how Rob can help.
Privacy & Data Protection
Privacy law is no longer a single statute — it is a layered, multi-jurisdictional compliance framework that touches every part of how a business collects, processes, and shares personal data. Rob advises US businesses on the full spectrum of privacy law obligations, from the EU’s General Data Protection Regulation and the UK GDPR to the California Consumer Privacy Act and the growing roster of US state privacy laws now in force in Virginia, Colorado, Connecticut, Texas, Washington, and more than a dozen other states. He negotiates and drafts data processing addendums, standard contractual clauses, and data transfer impact assessments. He conducts privacy program gap assessments, advises on lawful basis and consent requirements, helps companies respond to data subject rights requests, and advises service providers and processors on their obligations as vendors under the CCPA and GDPR.
Key resources: How to Negotiate a Data Processing Addendum · Introduction to the CCPA for Service Providers · CCPA Data Subject Rights for Service Providers · CCPA Contract Guide for Service Providers · GDPR vs. CCPA: A Comparison · Data Protection Audit Rights · Data Mapping for Privacy Compliance · Five Steps to Website Privacy Compliance
Artificial Intelligence & Emerging Technology
Artificial intelligence is generating legal obligations faster than most businesses can track. Rob advises companies developing, deploying, or integrating AI systems on their obligations under the EU AI Act — the world’s first comprehensive binding AI regulation, which applies to many US businesses with EU operations or sales — as well as US state AI laws in California, Colorado, and Utah, emerging federal guidance from the FTC and NIST, and the specific legal challenges of agentic AI systems that take autonomous action without continuous human oversight. He advises on AI governance frameworks, AI-specific contractual provisions, consumer disclosure requirements, and the intersection of AI with data protection law — including the implications of using personal data to train or operate AI models.
Key resources: What US Businesses Need to Know About the EU AI Act · AI Governance and Compliance Safeguards for Businesses Deploying Agentic AI · Five Challenges of Agentic AI for Compliance Teams · OWASP Top 10 for Agentic AI · Securing AI Agents · Fulfilling the Right to Delete in Agentic AI · How GDPR Applies to AI Model Training
Cybersecurity & Incident Response
When a security incident occurs, the legal clock starts immediately. Rob advises businesses on building the incident response infrastructure they need before a breach happens — including incident response plans, tabletop exercise programs, cyber insurance procurement and review, and external vendor relationships with forensics firms, breach coaches, and notification vendors. He also guides companies through the legal dimensions of live incidents: attorney-client privilege preservation, regulatory notification obligations under state breach notification laws and sector-specific rules, vendor management, and post-incident regulatory response. He advises on cybersecurity governance at the board level, including the SEC’s cybersecurity disclosure rules for public companies.
Key resources: Developing an Effective Security Incident Response Plan · Planning an Incident Response Tabletop Exercise · Reviewing Cyber Insurance During Renewal · Preparing for Incident Response With External Vendors · Security Incident Notification Laws
Healthcare & Life Sciences Compliance
Healthcare is one of the most heavily regulated sectors in the US economy, and the intersection of healthcare with technology and AI is generating new compliance challenges at a rapid pace. Rob advises covered entities and business associates on HIPAA Privacy Rule and Security Rule compliance, including the minimum necessary standard, breach notification obligations, risk assessments, and the negotiation and drafting of business associate agreements. He advises healthcare companies on AI and machine learning in clinical and administrative settings, on mobile health applications, and on the regulatory framework for handling substance use disorder records under 42 CFR Part 2. He also advises EdTech companies on FERPA and COPPA obligations, and healthcare companies involved in M&A on data protection due diligence.
Key resources: HIPAA Minimum Necessary Rule · Do You Need a BAA With Every Vendor? · BAA Negotiation Guide
FCPA & Anti-Corruption Compliance
The Foreign Corrupt Practices Act imposes criminal and civil liability on US companies and individuals — and on foreign companies with US connections — for bribery of foreign government officials and for accounting control failures that allow corruption to occur. FCPA enforcement has remained aggressive across administrations and carries penalties that can reach hundreds of millions of dollars. Rob advises companies on the full spectrum of FCPA compliance: who is covered and what is prohibited, designing compliance programs and third-party due diligence systems, identifying and responding to red flags, conducting FCPA internal investigations, and navigating the voluntary self-disclosure process with the DOJ and SEC. He also advises on the DOJ’s new Department-wide Corporate Enforcement and Voluntary Self-Disclosure Policy.
Key resources: The DOJ’s New Corporate Enforcement and Voluntary Self-Disclosure Policy
Sanctions & Export Controls
US sanctions and export control regimes are among the most complex and rapidly evolving areas of regulatory law, and the penalties for non-compliance — including criminal prosecution, civil fines, and debarment — are severe. Rob advises businesses on OFAC sanctions compliance, including screening obligations and the management of SDN List and comprehensive country embargo exposure. On export controls, he advises on EAR compliance administered by BIS — including export classification, license determinations, end-user screening, and deemed export obligations for foreign national employees — and on ITAR compliance for companies handling defense articles and services on the US Munitions List. He advises on supply chain due diligence under the Uyghur Forced Labor Prevention Act and on voluntary self-disclosure when violations are discovered.
Key resources: Voluntary Self-Disclosure Under the Export Administration Regulations
Whistleblower Programs
The US operates a network of government whistleblower programs that offer financial rewards to individuals who report corporate misconduct to agencies including the SEC, CFTC, DOJ, IRS, and FinCEN. Rob advises companies on how these programs work, on designing internal reporting systems that surface concerns before they reach regulators, and on responding appropriately when external whistleblower complaints are filed. He also advises individuals considering a whistleblower report on their rights, the reporting process, and the anti-retaliation protections that apply to them under federal and state law.
Employment Law
Employment law compliance is a persistent challenge for US businesses, particularly those with multi-state workforces, remote employees, or rapid headcount growth. Rob advises employers across the full employment life cycle: compliant hiring practices, offer letters and employment agreements, background check compliance under the FCRA, worker classification, wage and hour law, noncompete and non-solicitation agreements, reasonable accommodation obligations, WARN Act compliance for reductions in force, severance agreements, and the legal requirements governing terminations. He advises on internal investigations involving employee misconduct and retaliation, and on the distinct compliance obligations that arise when companies hire internationally through employer-of-record or PEO arrangements.
Intellectual Property
Intellectual property is among the most valuable assets that technology companies, startups, and creative businesses hold — and among the assets most frequently lost through inadequate legal protection. Rob advises businesses on copyright ownership and registration, trademark clearance, application, and registration through the USPTO, patent strategy and infringement avoidance, and trade secret protection under the Defend Trade Secrets Act. He advises on IP ownership in employment and contractor relationships, the work-made-for-hire doctrine, invention assignment agreements, and the handling of trademark and copyright infringement — whether the company is the rights holder seeking enforcement or the accused infringer assessing exposure.
Attorney-Client Privilege & Internal Investigations
Attorney-client privilege is the foundation of confidential legal advice, and preserving it in complex corporate environments requires careful attention to who participates in communications, in what capacity, and for what purpose. Rob advises in-house legal teams, compliance officers, and business managers on how to protect privilege in internal investigations, in communications involving non-lawyer professionals, and in multi-jurisdictional matters where the scope of privilege varies by jurisdiction. He advises on the attorney work product doctrine, inadvertent waiver risks, and how to structure document retention and communication practices to preserve privilege under regulatory and litigation pressure. He also designs and conducts internal investigations into potential legal violations, regulatory misconduct, and employee complaints.
Corporate Governance & Directors and Officers (D&O)
Directors and officers of US corporations face a complex web of fiduciary obligations, regulatory duties, and personal liability exposure that has grown significantly more demanding in recent years. Rob advises boards, executives, and general counsel on the core fiduciary duties of directors, the business judgment rule, the Caremark standard for board oversight of compliance risk, director independence and committee requirements, D&O insurance program structure and claims, indemnification agreements, and the governance dimensions of cybersecurity, AI, and ESG risk. He also advises private companies and their founders and investors on governance structures, shareholder agreements, and governance-related dispute resolution.
Key resources: Corporate Governance & D&O Overview
ESG & Climate Disclosure
ESG disclosure has shifted from voluntary best practice to binding legal obligation. Rob advises US public and private companies on California’s mandatory climate disclosure laws — SB 253 (which requires annual GHG emissions reporting for companies with over $1 billion in revenue doing business in California, with the first Scope 1 and Scope 2 deadline on August 10, 2026) and SB 261 (currently enjoined pending Ninth Circuit appeal) — as well as the EU Corporate Sustainability Reporting Directive and its implications for US multinationals with EU operations. He advises on GHG emissions reporting under the GHG Protocol, greenwashing liability under FTC and SEC standards, ESG in M&A due diligence, and board-level governance obligations for climate risk.
Import/Export & Trade Compliance
Global trade compliance reaches far beyond manufacturers and defense contractors. Any business that exports technology, software, or services internationally; employs foreign nationals working with controlled technology; imports goods through complex supply chains; or operates in jurisdictions subject to US tariff measures faces meaningful trade compliance obligations. Rob advises on ITAR registration and licensing, EAR classification and license determinations, deemed export compliance for foreign national employees, supply chain due diligence under the Uyghur Forced Labor Prevention Act, US customs compliance, Section 301 and Section 232 tariff strategy, and the design and implementation of export compliance programs.
Mergers & Acquisitions
Rob regularly serves as data protection and regulatory diligence counsel in M&A transactions. He has represented buyers on data protection and compliance in dozens of private equity rollups and B2B startup acquisitions, and in more than a dozen transactions involving reps and warranties insurance — where the quality of the legal diligence directly affects the scope of coverage. He has advised more than a dozen healthcare companies on HIPAA and data protection matters in the M&A process, and has represented sellers across the advertising, ecommerce, financial services, healthcare, and technology industries. He understands that M&A diligence is a risk assessment calibrated to deal structure, purchase price, and the practical realities of integration, not a checklist exercise.
Work With Rob
If your business is navigating a compliance challenge in any of these areas — whether it is an immediate deadline, a government inquiry, a transaction with regulatory dimensions, or the need to build a compliance program from the ground up — Rob is available to discuss your situation. The first consultation is free. Contact Rob at rob@robmelton.com or use the contact form to schedule a call.
