AMBART LAW  ·  Privacy & Data Protection for AI & SaaS

Privacy Law for AI and SaaS Companies

Privacy is not a cookie banner or a template policy pasted at the bottom of your site. It is a product question: meaning, what your product collects, processes, and shares—governed by a web of laws, new and decades old, that decide whether you can ship. We counsel the product and draft the agreements that make it defensible.

Book a 20-minute fit call Contact us

What we actually do

Privacy that fits your product, not a template

Most "privacy" work stops at a policy and a cookie banner. We find that this is typically not enough for B2B2C SaaS and AI companies. We start where the risk actually lives—in the product—and we map the laws that apply to what your product does, then build the program and the contracts around it.

01

Privacy Program & Data Mapping

Build or modernize a privacy program that fits your real data flows—data mapping, assessments, and policies that match what your product actually does, not boilerplate.

02

AI Product Counseling

Privacy is a product question. We counsel new features before launch: what data the product collects, processes, and shares—so privacy is designed in, not bolted on after a complaint.

03

Data & Commercial Agreements

Draft and negotiate data processing agreements (DPAs), vendor and data-sharing agreements, and cross-border transfer terms—calibrated to your actual risk.

Why most privacy programs have a blind spot

The privacy laws most likely to get you sued aren't the ones in the headlines.

The new comprehensive state privacy laws get the headlines—California's CCPA/CPRA and the wave that followed. But the laws with real teeth—private rights of action, statutory damages, class actions—are the targeted ones: communications, biometric, and health statutes, some decades old and some brand new, that apply directly to what your product does.

If your product collects, processes, or shares data about people—or just sends them a text—a statute with real teeth probably governs it: the TCPA for messaging, BIPA for biometrics, HIPAA and the new state consumer-health-data laws for health information, a state wiretap law for your session-replay or AI transcription. You are in that conversation whether or not your privacy policy mentions it. Luckily, that is what we are here for.

A few examples of the "legacy" exposure we see most often:

TCPA (1991)

Automated calls and texts carry statutory damages of $500–$1,500 per message and a private right of action—the engine behind enormous class actions. If your growth or product team sends automated SMS, you are in TCPA territory.

CAN-SPAM (2003)

Commercial e-mail must carry accurate headers, identify itself as an ad, honor opt-outs within 10 business days, and include a physical address. Penalties stack per e-mail.

Health data (HIPAA + new state laws)

If you touch health data—even as a vendor "business associate," or as a consumer-health app outside HIPAA—HIPAA, the FTC Health Breach Notification Rule, and state consumer-health-data laws may all apply.

Wiretap & recording-consent

Session-replay trackers and AI note-takers/transcription tools are being sued under decades-old, two-party-consent wiretap statutes (e.g., the Otter.ai and Google transcription cases).

Real privacy counsel means evaluating the laws that apply to your use case—the new state privacy laws (California's CCPA/CPRA and its successors) and the targeted statutes with real teeth: the Telephone Consumer Protection Act (TCPA), the CAN-SPAM Act, the Health Insurance Portability and Accountability Act (HIPAA), the new state consumer-health-data laws, the Gramm-Leach-Bliley Act (GLBA), the Illinois Biometric Information Privacy Act (BIPA), and state wiretap and recording-consent statutes—plus the EU's GDPR and AI Act if you deploy there.

Whom we advise

Built for teams that collect, process, and move data

AI & Tech

Companies building with agents, LLMs, and regulated data that need privacy designed into the product, not patched after launch.

SaaS Providers

Post-product-market-fit teams answering customer security and privacy reviews and signing DPAs at enterprise scale.

Marketing & DTC

Growth and e-commerce teams running e-mail, SMS, and tracking—where TCPA, CAN-SPAM, and wiretap exposure lives.

Health & Fintech

Companies handling health or financial data under HIPAA, the FTC Health Breach Rule, and GLBA.

How we help

From data map to signed DPA

Privacy Program & Data Mapping

  • Build or modernize a privacy program that fits your real data flows.
  • Data mapping and assessments—so you know what you collect, why, and where it goes.
  • Privacy policies and notices that match the product, not a template.

AI Product Counseling

  • Counsel new features before launch—what data the product touches.
  • Data minimization and consent design built into the roadmap.
  • Translate privacy risk into product decisions your team can ship around.

Marketing & Communications Compliance

  • TCPA-compliant SMS and calling—consent capture, opt-outs, and records.
  • CAN-SPAM-compliant e-mail and honored unsubscribes.
  • Session-replay, pixels, and tracking reviewed for wiretap exposure.

Sensitive Data & Agreements

  • HIPAA, FTC Health Breach Rule, and consumer-health-data compliance.
  • GLBA (financial) and BIPA (biometric) reviews.
  • DPAs, data-sharing, and cross-border transfer agreements.

EU + U.S. coverage

AMBART LAW × Nor Law

Privacy rarely stops at one border. Through a strategic partnership with Nor Law, a Netherlands-based privacy and data-protection firm led by GDPR lawyer Marta Hovanesian, we support companies on both sides of the Atlantic: U.S. companies doing business in the EU, and EU companies expanding into the U.S.—with one coordinated, pragmatic approach to GDPR, U.S. state privacy law, AI, and cybersecurity.

Read about the partnership →

In the press

Quoted on privacy, data, and AI

Reporters covering privacy and data protection regularly call on our founder, Yelena Ambartsumian (AIGP, CIPP/US), for analysis. A selection is below; the full record of our press is collected in one place.

Reader's Digest
January 2026 · Biometric Privacy
On Ring's facial recognition: "The most stringent laws on the collection and processing of biometric data are in Illinois and Texas, as well as in Portland, Oregon—the latter of which bans facial-recognition technology by private entities in places of public accommodation."
Read at Reader's Digest →
Built In
April 2026 · Privacy & Wearables
On smart-glasses face recognition: "Nothing has changed with respect to privacy law that would bless this. Even if only people who opted into 'Name Tag' can be identified, that does not solve the problem of having to collect and process data to determine whether a person has opted in."
Read at Built In →
eWeek
September 2025 · Data Minimization
On always-recording AI glasses: "Virtually every company suffers a data breach, and so the 'convenience' offered by note-taking or meeting-summary devices needs to be weighed against the reality that you are providing a third party with your firm's confidential and proprietary information."
Read at eWeek →
No Jitter
December 2025 · AI Transcription
On vendor risk after the Otter.ai and Google transcription suits: scrutinize the license to your content, how the vendor may "develop" or "improve" using it, and where data is retained and stored.
Read at No Jitter →
Cybernews
August 2025 · Algorithmic Pricing
On personalized pricing: under New York's Personalized Pricing Transparency law, companies using your browsing or shopping history to set prices must disclose, "This price was set by an algorithm using your personal data."
Read at Cybernews →

See the full press record →

Credentials & thought leadership

We write and teach the privacy law we practice

Certifications

Our founder, Yelena Ambartsumian, is an IAPP-certified AIGP (AI Governance Professional) and CIPP/US (privacy), and co-chairs the IAPP's New York KnowledgeNet Chapter.

IAPP

"Even exempt organizations need to be data mapping: Here's why"—why data mapping matters even when a legal regime would otherwise exempt you. Authored by our associate, Maria Cannon.

Read the article →
Investopedia

Consulted on the EU AI Act and what U.S. companies placing AI on the EU market must prepare for—transparency, documentation, and oversight.

Read the article →
Women in AI · Legal Insights

"Is it Too Late to Govern Agentic AI?"—governance, privacy, and safety practices for autonomous, multi-agent AI systems.

Read the article →

Frequently asked questions

Privacy law, answered plainly

Which privacy laws actually apply to my AI or SaaS product?

More than you would expect, and the oldest ones often carry the most risk. Depending on what your product does, you may be subject to the new state privacy laws (California's CCPA/CPRA and the wave of similar state laws), and a set of older, established statutes—several of them decades old—that carry private rights of action and statutory damages: the TCPA (messaging), CAN-SPAM (e-mail), HIPAA (health data), GLBA (financial data), BIPA (biometrics in Illinois and others), and state wiretap and recording-consent laws. If you sell into the EU, add the GDPR and the EU AI Act. We map which of these apply to your specific use case—rather than handing you a generic policy.

Does the TCPA apply to my texts and calls?

Very likely, if any of them are automated. The Telephone Consumer Protection Act restricts autodialed and prerecorded calls and texts and generally requires prior express consent. It carries a private right of action and statutory damages of $500 to $1,500 per message—which is why it drives some of the largest class actions in the country. And in February 2024, the FCC confirmed that calls using AI-generated or cloned voices count as "artificial" voices under the TCPA—so AI voice bots and agents need that same prior express consent. If your growth or product team sends marketing SMS, runs an AI calling agent, or uses automated dialing, you are in TCPA territory, and consent capture and recordkeeping matter.

What does CAN-SPAM require for our marketing e-mail?

The CAN-SPAM Act governs commercial e-mail. In short: accurate "from" and subject lines, clear identification that the message is an advertisement, a working opt-out that you honor within 10 business days, and a valid physical postal address. There is no private right of action—the FTC and state attorneys general enforce it—but penalties can be assessed per e-mail, so volume adds up quickly.

We handle health data but aren't a hospital—does HIPAA apply?

Maybe directly, maybe not—but you are rarely off the hook, and the bigger surprise is usually the state consumer-health-data laws. HIPAA applies only to "covered entities" (providers, health plans, clearinghouses) and their "business associates." Many apps, wearables, and SaaS tools that touch health data fall outside HIPAA entirely—yet are squarely reached by a newer wave of state consumer-health-data laws: Washington's My Health My Data Act (which defines "consumer health data" broadly, requires consent to collect and share it, and carries a private right of action), Nevada's SB 370, and Connecticut's consumer-health-data amendments, among others. On top of that, the FTC Health Breach Notification Rule and Section 1557 of the ACA can apply. The upshot: a company with zero HIPAA obligations can still carry serious health-privacy exposure. We help you figure out which regime you are actually in before you build—read our analysis of the state consumer-health-data wave.

What are the new state "consumer health data" laws, and do they apply to us?

A fast-growing category that reaches far beyond HIPAA. Washington's My Health My Data Act (MHMDA) defines "consumer health data" broadly—data that identifies a person's past, present, or future physical or mental health—requires consent to collect it and separate authorization to share it, and carries a private right of action, which makes it especially dangerous. Nevada's SB 370 takes a similar approach (enforced by the attorney general), and Connecticut amended its privacy law to treat consumer health data as sensitive data requiring opt-in consent. The catch: "health data" is defined so broadly that ordinary apps, wearables, advertising pixels, and websites—well outside HIPAA—can be swept in. If your product or marketing touches anything health-adjacent, we map which of these apply and build the consent and data flows to match. Read our deep dive on the shifting state consumer-health-data landscape →

Is our session-replay or AI transcription a wiretap problem?

It can be. In two-party (all-party) consent states, recording or intercepting a communication without everyone's consent can violate decades-old wiretap statutes. Plaintiffs have used these laws against session-replay trackers and AI note-takers and transcription tools (see the Otter.ai and Google transcription cases). If your product or your team records calls, meetings, or on-site behavior, consent design is not optional.

What is a DPA, and when do we need one?

A data processing agreement (DPA) is the contract that governs how a vendor processes personal data on your behalf—purpose limits, security, sub-processors, deletion, and audit rights. It is required under the GDPR (Article 28) and under many U.S. state privacy laws when you share personal data with a service provider or processor. In practice, your enterprise customers will also demand one before they sign. We draft and negotiate these—including DPAs for AI vendors, agents, and agentic workflows, where the data flows and sub-processors are harder to pin down—so they protect your data without stalling the deal.

Do we need to worry about biometric privacy (BIPA)?

If you collect faceprints, voiceprints, fingerprints, or similar identifiers, yes. The Illinois Biometric Information Privacy Act (BIPA) requires notice, consent, and a written retention/destruction policy—and, critically, it carries a private right of action with statutory damages, which has produced very large settlements. Texas and Washington have biometric laws too, and other states are following. Voice AI, face recognition, and even some authentication features can trigger these.

Does the GDPR or EU AI Act apply to a U.S. company?

It can. The GDPR reaches companies that offer goods or services to, or monitor, people in the EU—regardless of where the company sits. The EU AI Act similarly reaches providers and deployers placing AI systems on the EU market. If you sell into or track users in the EU, we assess which obligations attach and on what timeline—and through our strategic partnership with Nor Law in the Netherlands, we coordinate EU and U.S. compliance under one roof.

How is this different from your AI governance or Fractional GC work?

The work overlaps; the framing differs. This practice focuses on privacy and data protection across your product and marketing. Our AI governance practice covers the broader AI risk and contracting picture, and our Fractional GC program embeds all of it on a predictable monthly plan. If you are not sure which fits, the fit call will tell you.

How do we start working with you?

Book a 20-minute fit call or e-mail info@ambartlaw.com. We will learn about your product, your data flows, and your risk, and then recommend a plan to move forward—or tell you if we are not the right fit.

Reach out

Let's map your privacy exposure

In a 20-minute fit call, we'll assess what your product collects and shares, identify the laws that actually apply, and recommend a plan.

Book a 20-minute fit call Contact us

. .btn{display:inline-block;font-family:var(--ambart-font-display);text-transform:uppercase;letter-spacing:.06em;font-size:.95rem;padding:15px 30px;border-radius:4px;margin:22px 10px 0 0;transition:transform .12s ease;} .ambart-hub .btn:hover{transform:translateY(-2px);text-decoration:none;} .ambart-hub .btn-primary{background:var(--ambart-purple);color:#fff;} .ambart-hub .btn-ghost{border:1.5px solid var(--ambart-purple);color:var(--ambart-purple);} .ambart-hub .section-dark .btn-ghost{color:#fff;border-color:#fff;} .ambart-hub .triad{display:grid;grid-template-columns:repeat(3,1fr);gap:26px;margin-top:36px;} .ambart-hub .card{background:#fff;border:1px solid var(--ambart-tint);border-radius:8px;padding:30px 26px;} .ambart-hub .card .num{font-family:var(--ambart-font-display);color:var(--ambart-purple);font-size:1.6rem;} .ambart-hub .card h3{margin-top:8px;} .ambart-hub .feature-quote{border-left:4px solid var(--ambart-purple);padding-left:24px;margin:8px 0 0;font-size:1.15rem;} .ambart-hub .svc-grid{display:grid;grid-template-columns:repeat(2,1fr);gap:18px 40px;margin-top:28px;} .ambart-hub .svc h3{color:var(--ambart-dark);} .ambart-hub .check{list-style:none;padding:0;margin:0;} .ambart-hub .check li{padding-left:30px;position:relative;margin-bottom:12px;} .ambart-hub .check li::before{content:"\2713";position:absolute;left:0;color:var(--ambart-purple);font-weight:700;} .ambart-hub .media-grid{display:grid;grid-template-columns:repeat(3,1fr);gap:22px;margin-top:32px;} .ambart-hub .media{background:#fff;border:1px solid var(--ambart-tint);border-radius:8px;padding:24px;display:flex;flex-direction:column;} .ambart-hub .media .outlet{font-family:var(--ambart-font-display);text-transform:uppercase;letter-spacing:.04em;color:var(--ambart-dark);font-size:1.05rem;} .ambart-hub .media .meta{font-size:.82rem;color:#6b6486;margin:2px 0 12px;text-transform:uppercase;letter-spacing:.06em;} .ambart-hub .media blockquote{margin:0 0 16px;font-size:.98rem;color:var(--ambart-ink);} .ambart-hub .media a{margin-top:auto;font-weight:600;font-size:.9rem;} .ambart-hub .pubs{display:grid;grid-template-columns:repeat(2,1fr);gap:18px;margin-top:28px;} .ambart-hub .pub{background:var(--ambart-paper);border:1px solid var(--ambart-tint);border-radius:8px;padding:22px 24px;} .ambart-hub .pub .src{color:var(--ambart-purple);font-weight:600;font-size:.85rem;text-transform:uppercase;letter-spacing:.05em;} .ambart-hub .faq details{border-bottom:1px solid var(--ambart-tint);padding:20px 0;} .ambart-hub .faq summary{font-family:var(--ambart-font-display);text-transform:uppercase;letter-spacing:.02em;color:var(--ambart-dark);font-size:1.12rem;cursor:pointer;list-style:none;display:flex;justify-content:space-between;gap:16px;} .ambart-hub .faq summary::-webkit-details-marker{display:none;} .ambart-hub .faq summary::after{content:"+";color:var(--ambart-purple);font-family:var(--ambart-font-body);font-weight:700;} .ambart-hub .faq details[open] summary::after{content:"\2013";} .ambart-hub .faq .ans{padding-top:14px;} .ambart-hub .cta-box{text-align:center;} @media(max-width:880px){ .ambart-hub .triad,.ambart-hub .media-grid{grid-template-columns:1fr;} .ambart-hub .svc-grid,.ambart-hub .pubs{grid-template-columns:1fr;} .ambart-hub section{padding:54px 0;} }

AMBART LAW  ·  Privacy & Data Protection for AI & SaaS

Privacy Law for AI and SaaS Companies

Privacy is not a cookie banner or a template policy pasted at the bottom of your site. It is a product question: meaning, what your product collects, processes, and shares—governed by a web of laws, new and decades old, that decide whether you can ship. We counsel the product and draft the agreements that make it defensible.

Book a 20-minute fit call Contact us

What we actually do

Privacy that fits your product, not a template

Most "privacy" work stops at a policy and a cookie banner. We find that this is typically not enough for B2B2C SaaS and AI companies. We start where the risk actually lives—in the product—and we map the laws that apply to what your product does, then build the program and the contracts around it.

01

Privacy Program & Data Mapping

Build or modernize a privacy program that fits your real data flows—data mapping, assessments, and policies that match what your product actually does, not boilerplate.

02

AI Product Counseling

Privacy is a product question. We counsel new features before launch: what data the product collects, processes, and shares—so privacy is designed in, not bolted on after a complaint.

03

Data & Commercial Agreements

Draft and negotiate data processing agreements (DPAs), vendor and data-sharing agreements, and cross-border transfer terms—calibrated to your actual risk.

Why most privacy programs have a blind spot

The privacy laws most likely to get you sued aren't the ones in the headlines.

The new comprehensive state privacy laws get the headlines—California's CCPA/CPRA and the wave that followed. But the laws with real teeth—private rights of action, statutory damages, class actions—are the targeted ones: communications, biometric, and health statutes, some decades old and some brand new, that apply directly to what your product does.

If your product collects, processes, or shares data about people—or just sends them a text—a statute with real teeth probably governs it: the TCPA for messaging, BIPA for biometrics, HIPAA and the new state consumer-health-data laws for health information, a state wiretap law for your session-replay or AI transcription. You are in that conversation whether or not your privacy policy mentions it. Luckily, that is what we are here for.

A few examples of the "legacy" exposure we see most often:

TCPA (1991)

Automated calls and texts carry statutory damages of $500–$1,500 per message and a private right of action—the engine behind enormous class actions. If your growth or product team sends automated SMS, you are in TCPA territory.

CAN-SPAM (2003)

Commercial e-mail must carry accurate headers, identify itself as an ad, honor opt-outs within 10 business days, and include a physical address. Penalties stack per e-mail.

Health data (HIPAA + new state laws)

If you touch health data—even as a vendor "business associate," or as a consumer-health app outside HIPAA—HIPAA, the FTC Health Breach Notification Rule, and state consumer-health-data laws may all apply.

Wiretap & recording-consent

Session-replay trackers and AI note-takers/transcription tools are being sued under decades-old, two-party-consent wiretap statutes (e.g., the Otter.ai and Google transcription cases).

Real privacy counsel means evaluating the laws that apply to your use case—the new state privacy laws (California's CCPA/CPRA and its successors) and the targeted statutes with real teeth: the Telephone Consumer Protection Act (TCPA), the CAN-SPAM Act, the Health Insurance Portability and Accountability Act (HIPAA), the new state consumer-health-data laws, the Gramm-Leach-Bliley Act (GLBA), the Illinois Biometric Information Privacy Act (BIPA), and state wiretap and recording-consent statutes—plus the EU's GDPR and AI Act if you deploy there.

Whom we advise

Built for teams that collect, process, and move data

AI & Tech

Companies building with agents, LLMs, and regulated data that need privacy designed into the product, not patched after launch.

SaaS Providers

Post-product-market-fit teams answering customer security and privacy reviews and signing DPAs at enterprise scale.

Marketing & DTC

Growth and e-commerce teams running e-mail, SMS, and tracking—where TCPA, CAN-SPAM, and wiretap exposure lives.

Health & Fintech

Companies handling health or financial data under HIPAA, the FTC Health Breach Rule, and GLBA.

How we help

From data map to signed DPA

Privacy Program & Data Mapping

  • Build or modernize a privacy program that fits your real data flows.
  • Data mapping and assessments—so you know what you collect, why, and where it goes.
  • Privacy policies and notices that match the product, not a template.

AI Product Counseling

  • Counsel new features before launch—what data the product touches.
  • Data minimization and consent design built into the roadmap.
  • Translate privacy risk into product decisions your team can ship around.

Marketing & Communications Compliance

  • TCPA-compliant SMS and calling—consent capture, opt-outs, and records.
  • CAN-SPAM-compliant e-mail and honored unsubscribes.
  • Session-replay, pixels, and tracking reviewed for wiretap exposure.

Sensitive Data & Agreements

  • HIPAA, FTC Health Breach Rule, and consumer-health-data compliance.
  • GLBA (financial) and BIPA (biometric) reviews.
  • DPAs, data-sharing, and cross-border transfer agreements.

EU + U.S. coverage

AMBART LAW × Nor Law

Privacy rarely stops at one border. Through a strategic partnership with Nor Law, a Netherlands-based privacy and data-protection firm led by GDPR lawyer Marta Hovanesian, we support companies on both sides of the Atlantic: U.S. companies doing business in the EU, and EU companies expanding into the U.S.—with one coordinated, pragmatic approach to GDPR, U.S. state privacy law, AI, and cybersecurity.

Read about the partnership →

In the press

Quoted on privacy, data, and AI

Reporters covering privacy and data protection regularly call on our founder, Yelena Ambartsumian (AIGP, CIPP/US), for analysis. A selection is below; the full record of our press is collected in one place.

Reader's Digest
January 2026 · Biometric Privacy
On Ring's facial recognition: "The most stringent laws on the collection and processing of biometric data are in Illinois and Texas, as well as in Portland, Oregon—the latter of which bans facial-recognition technology by private entities in places of public accommodation."
Read at Reader's Digest →
Built In
April 2026 · Privacy & Wearables
On smart-glasses face recognition: "Nothing has changed with respect to privacy law that would bless this. Even if only people who opted into 'Name Tag' can be identified, that does not solve the problem of having to collect and process data to determine whether a person has opted in."
Read at Built In →
eWeek
September 2025 · Data Minimization
On always-recording AI glasses: "Virtually every company suffers a data breach, and so the 'convenience' offered by note-taking or meeting-summary devices needs to be weighed against the reality that you are providing a third party with your firm's confidential and proprietary information."
Read at eWeek →
No Jitter
December 2025 · AI Transcription
On vendor risk after the Otter.ai and Google transcription suits: scrutinize the license to your content, how the vendor may "develop" or "improve" using it, and where data is retained and stored.
Read at No Jitter →
Cybernews
August 2025 · Algorithmic Pricing
On personalized pricing: under New York's Personalized Pricing Transparency law, companies using your browsing or shopping history to set prices must disclose, "This price was set by an algorithm using your personal data."
Read at Cybernews →

See the full press record →

Credentials & thought leadership

We write and teach the privacy law we practice

Certifications

Our founder, Yelena Ambartsumian, is an IAPP-certified AIGP (AI Governance Professional) and CIPP/US (privacy), and co-chairs the IAPP's New York KnowledgeNet Chapter.

IAPP

"Even exempt organizations need to be data mapping: Here's why"—why data mapping matters even when a legal regime would otherwise exempt you. Authored by our associate, Maria Cannon.

Read the article →
Investopedia

Consulted on the EU AI Act and what U.S. companies placing AI on the EU market must prepare for—transparency, documentation, and oversight.

Read the article →
Women in AI · Legal Insights

"Is it Too Late to Govern Agentic AI?"—governance, privacy, and safety practices for autonomous, multi-agent AI systems.

Read the article →

Frequently asked questions

Privacy law, answered plainly

Which privacy laws actually apply to my AI or SaaS product?

More than you would expect, and the oldest ones often carry the most risk. Depending on what your product does, you may be subject to the new state privacy laws (California's CCPA/CPRA and the wave of similar state laws), and a set of older, established statutes—several of them decades old—that carry private rights of action and statutory damages: the TCPA (messaging), CAN-SPAM (e-mail), HIPAA (health data), GLBA (financial data), BIPA (biometrics in Illinois and others), and state wiretap and recording-consent laws. If you sell into the EU, add the GDPR and the EU AI Act. We map which of these apply to your specific use case—rather than handing you a generic policy.

Does the TCPA apply to my texts and calls?

Very likely, if any of them are automated. The Telephone Consumer Protection Act restricts autodialed and prerecorded calls and texts and generally requires prior express consent. It carries a private right of action and statutory damages of $500 to $1,500 per message—which is why it drives some of the largest class actions in the country. And in February 2024, the FCC confirmed that calls using AI-generated or cloned voices count as "artificial" voices under the TCPA—so AI voice bots and agents need that same prior express consent. If your growth or product team sends marketing SMS, runs an AI calling agent, or uses automated dialing, you are in TCPA territory, and consent capture and recordkeeping matter.

What does CAN-SPAM require for our marketing e-mail?

The CAN-SPAM Act governs commercial e-mail. In short: accurate "from" and subject lines, clear identification that the message is an advertisement, a working opt-out that you honor within 10 business days, and a valid physical postal address. There is no private right of action—the FTC and state attorneys general enforce it—but penalties can be assessed per e-mail, so volume adds up quickly.

We handle health data but aren't a hospital—does HIPAA apply?

Maybe directly, maybe not—but you are rarely off the hook, and the bigger surprise is usually the state consumer-health-data laws. HIPAA applies only to "covered entities" (providers, health plans, clearinghouses) and their "business associates." Many apps, wearables, and SaaS tools that touch health data fall outside HIPAA entirely—yet are squarely reached by a newer wave of state consumer-health-data laws: Washington's My Health My Data Act (which defines "consumer health data" broadly, requires consent to collect and share it, and carries a private right of action), Nevada's SB 370, and Connecticut's consumer-health-data amendments, among others. On top of that, the FTC Health Breach Notification Rule and Section 1557 of the ACA can apply. The upshot: a company with zero HIPAA obligations can still carry serious health-privacy exposure. We help you figure out which regime you are actually in before you build—read our analysis of the state consumer-health-data wave.

What are the new state "consumer health data" laws, and do they apply to us?

A fast-growing category that reaches far beyond HIPAA. Washington's My Health My Data Act (MHMDA) defines "consumer health data" broadly—data that identifies a person's past, present, or future physical or mental health—requires consent to collect it and separate authorization to share it, and carries a private right of action, which makes it especially dangerous. Nevada's SB 370 takes a similar approach (enforced by the attorney general), and Connecticut amended its privacy law to treat consumer health data as sensitive data requiring opt-in consent. The catch: "health data" is defined so broadly that ordinary apps, wearables, advertising pixels, and websites—well outside HIPAA—can be swept in. If your product or marketing touches anything health-adjacent, we map which of these apply and build the consent and data flows to match. Read our deep dive on the shifting state consumer-health-data landscape →

Is our session-replay or AI transcription a wiretap problem?

It can be. In two-party (all-party) consent states, recording or intercepting a communication without everyone's consent can violate decades-old wiretap statutes. Plaintiffs have used these laws against session-replay trackers and AI note-takers and transcription tools (see the Otter.ai and Google transcription cases). If your product or your team records calls, meetings, or on-site behavior, consent design is not optional.

What is a DPA, and when do we need one?

A data processing agreement (DPA) is the contract that governs how a vendor processes personal data on your behalf—purpose limits, security, sub-processors, deletion, and audit rights. It is required under the GDPR (Article 28) and under many U.S. state privacy laws when you share personal data with a service provider or processor. In practice, your enterprise customers will also demand one before they sign. We draft and negotiate these—including DPAs for AI vendors, agents, and agentic workflows, where the data flows and sub-processors are harder to pin down—so they protect your data without stalling the deal.

Do we need to worry about biometric privacy (BIPA)?

If you collect faceprints, voiceprints, fingerprints, or similar identifiers, yes. The Illinois Biometric Information Privacy Act (BIPA) requires notice, consent, and a written retention/destruction policy—and, critically, it carries a private right of action with statutory damages, which has produced very large settlements. Texas and Washington have biometric laws too, and other states are following. Voice AI, face recognition, and even some authentication features can trigger these.

Does the GDPR or EU AI Act apply to a U.S. company?

It can. The GDPR reaches companies that offer goods or services to, or monitor, people in the EU—regardless of where the company sits. The EU AI Act similarly reaches providers and deployers placing AI systems on the EU market. If you sell into or track users in the EU, we assess which obligations attach and on what timeline—and through our strategic partnership with Nor Law in the Netherlands, we coordinate EU and U.S. compliance under one roof.

How is this different from your AI governance or Fractional GC work?

The work overlaps; the framing differs. This practice focuses on privacy and data protection across your product and marketing. Our AI governance practice covers the broader AI risk and contracting picture, and our Fractional GC program embeds all of it on a predictable monthly plan. If you are not sure which fits, the fit call will tell you.

How do we start working with you?

Book a 20-minute fit call or e-mail info@ambartlaw.com. We will learn about your product, your data flows, and your risk, and then recommend a plan to move forward—or tell you if we are not the right fit.

Reach out

Let's map your privacy exposure

In a 20-minute fit call, we'll assess what your product collects and shares, identify the laws that actually apply, and recommend a plan.

Book a 20-minute fit call Contact us