Contact Robert Melton, Esq. or submit a business inquiry online.
GDPR
-
Vendor Data Processing Agreements: What SMBs Need to Know
- May 31, 2026
- Posted by: allan
- Category: Data Privacy & Cybersecurity
No Comments
If your business shares customer data with third-party vendors, privacy laws may require you to have a written data processing agreement in place. This guide explains what a DPA must contain and why getting this right matters for your business.
-
Data Retention Policies: What Businesses Need to Know
- May 26, 2026
- Posted by: allan
- Category: Data Privacy & Cybersecurity
How long should your business keep customer records, employee files, financial data, and other information? The answer varies by law, industry, and type of data — and getting it wrong can be costly in both directions.
-
How to Verify a Consumer or Data Subject Making an Access, Correction, or Deletion Request
- May 10, 2026
- Posted by: rob
- Category: Data Privacy & Cybersecurity
-
Who to Contact in Case of a Data Breach?
- May 3, 2026
- Posted by: rob
- Category: Data Privacy & Cybersecurity
-
Do I Need a Lawyer to Write My Privacy Policy?
- May 2, 2026
- Posted by: rob
- Category: Data Privacy & Cybersecurity
-
CNIL Recommendations on Applying the GDPR to AI System Development
- April 26, 2026
- Posted by: rob
- Categories: AI & Technology Law, Data Privacy & Cybersecurity
-
EDPB Opinion 28/2024: How GDPR Applies to AI Model Training
- April 20, 2026
- Posted by: rob
- Categories: AI & Technology Law, Data Privacy & Cybersecurity
-
Fulfilling the Right to Delete in Agentic AI
- April 9, 2026
- Posted by: rob
- Categories: AI & Technology Law, Data Privacy & Cybersecurity
-
What is the difference between GDPR and CCPA? A CCPA vs GDPR Comparison
- March 12, 2026
- Posted by: rob
- Category: Data Privacy & Cybersecurity
-
Examining Data Protection Audit Rights in Privacy Laws and Contracts
- March 9, 2026
- Posted by: rob
- Category: Data Privacy & Cybersecurity
-
How I negotiate a Data Processing Addendum (DPA) for Vendors
- March 9, 2026
- Posted by: rob
- Category: Data Privacy & Cybersecurity
-
Five Steps to Improve Your Website Privacy Compliance
- May 18, 2025
- Posted by: rob
- Category: Data Privacy & Cybersecurity
-
AI Training Data and Copyright: What the 2024-2025 Cases Settled and What They Left Open
The 2024–2025 AI training data copyright cases produced the first real legal answers on whether training AI models on copyrighted content is fair use — and the results are split. This post walks through the key rulings in Ross, Kadrey, Bartz, and the music cases, what they settled, and what they left open for businesses building or deploying AI.
August 9, 2026 Read more -
Agentic AI Liability in Autonomous Decisions: Who Pays When the AI Gets It Wrong
When an AI agent autonomously places orders, sends communications, or manages accounts, your business is the principal — and bears the legal consequences. This post examines agency law, negligence doctrine, regulatory guidance, and what agentic AI vendor contracts must contain to protect deploying businesses.
August 8, 2026 Read more -
When the Algorithm Is the Defect: AI Recommendation Systems and Design Defect Claims
A new theory of product liability has emerged and is winning in court: the recommendation algorithm itself is the defective product. This post examines the legal landscape, from the social media MDL to the first jury verdict, and what it means for businesses deploying AI-driven recommendation and personalization systems.
August 7, 2026 Read more -
Is Your AI a Defective Product? How Product Liability Law Applies to AI Systems
Courts are allowing product liability claims against AI developers to proceed, bipartisan federal legislation would classify AI systems as defective products, and the EU has already done so by statute. This post explains the three product liability theories — design defect, manufacturing defect, and failure to warn — and what they mean for businesses that build or deploy AI.
August 6, 2026 Read more
