As a strategic thought partner to businesses, non-profits and other organizations, Andrew Epstein provides risk-based options and operationalizes solutions to clients’ privacy and cybersecurity compliance obligations that are designed to optimize clients' abilities to leverage a key asset: data. Andrew's wide breadth of experience includes counseling clients on cutting-edge privacy/cybersecurity practices; negotiating privacy/cybersecurity provisions in technology-transaction agreements; providing proactive/reactive security incident guidance; leading privacy/cybersecurity efforts in M&A/VC/PE/IPO transactions; as well as responding to foreign, federal and state regulatory investigations into clients’ privacy/cybersecurity practices.
Andrew advises a broad range of F500 to emerging company clients across industries including SaaS, FinTech, InsurTech, EdTech, life sciences, healthcare and others. He holistically advises clients on the development and implementation of data-driven products and services to comply with regulatory frameworks such as the EU/UK GDPR, CCPA, VCDPA, CPA, CMIA, GLBA, FCRA, TCPA, HIPAA, COPPA and CAN-SPAM as well as their contractual and industry obligations. Clients turn to Andrew for guidance navigating issues ranging from business model to granular product design questions. Further, Andrew’s employment law experience allows him to creatively solve unique issues posed by employee privacy concerns.
Andrew brings practical/operational in-house and private practice experience to the changing foreign, national and local privacy/cybersecurity landscape since he was, respectively, the privacy and cybersecurity senior corporate counsel at an InsurTech startup and an associate with a global AmLaw100 firm’s privacy and cybersecurity practice.
Privacy and Cybersecurity Strategic Counseling
- Developed and implemented strategies, programs, policies and procedures to comply with domestic (federal and state) and foreign data protection laws/regulations such as the California Consumer Privacy Act (CCPA), Virginia Consumer Data Protection Act (VCDPA), Colorado Privacy Act (CPA), EU General Data Protection Regulation (EU GDPR), UK General Data Protection Regulation (UK GDPR), Gramm-Leach-Bliley Act (GLBA), Fair Credit Reporting Act (FCRA), Health Insurance Portability and Accountability Act (HIPAA), Children’s Online Privacy Protection Act (COPPA) and others.
Incident Response
- Directed organizations’ legal response to, and forensic investigations of, data security incidents (including ransomware, supply-chain and social-engineering attacks).
Transactional
- Led privacy/cybersecurity diligence in M&A/VC/PE/IPO transactions; drafted and negotiated representations and disclosures.
- Negotiated privacy, cybersecurity and commercial terms in vendor agreements; and conducted vendor diligence.