Every work product
runs on a playbook.
Counsel-authored SOPs for the work we do most: executed on the platform, versioned, and always exam-ready. The judgment is a lawyer's; the procedure is what makes it repeatable and defensible. Every playbook below is live today.
Privacy Impact Assessment
Clear a new product, feature or data use before it ships. GDPR Art. 35 · CPRA.
Data Processing Agreement
Review, counter and execute processor terms with flow-downs that hold.
Data Subject Access Request
Intake to response on a clock, with identity checks and exemption logic.
HIPAA Business Associate Agreement
Review and redline BAAs; auto-detects whether the client is business associate or covered entity and applies the matching positions. 45 CFR 164.504(e).
Use-Case Triage
Does this need a PIA, a mandatory DPIA, or can it proceed? Answered in a day, not a month, with the rationale recorded.
Regulatory Gap Analysis
A new reg drops: diff it against current policy and practice, output a gap list and a dated remediation plan.
Policy Monitor
Keep the privacy policy current with practice: a weekly sweep of PIAs, DPA reviews and triage results to catch drift before a regulator does.
Incident & Breach Response
Detection to multi-jurisdiction notice, privilege-first from the opening hour. GDPR Arts. 33–34 · HIPAA · US state breach statutes.
Vendor / AI Risk Assessment
Score vendors and models before they touch your data, and again at every renewal.
Records of Processing
Article 30 records as a living register, maintained continuously rather than rebuilt every audit season. GDPR Art. 30.