Ariel Herzog Law

Security, Privacy & AI

Security, privacy, and artificial intelligence obligations are created by contract and by regulation. This practice advises on those obligations and conducts privileged assessments of whether a company meets them.


Overview

A company makes commitments about security and data in its customer contracts, its data processing agreements, its privacy policy, its insurance applications, and its regulatory filings. Those commitments are enforceable, and they are what a company is measured against.

Much of the work is comparing what a company has promised against what it actually does, and correcting whichever of the two is wrong, on a written plan with dates. Other matters are narrower: negotiating a single agreement, answering one customer’s security review, or assessing a specific feature before it launches.

These questions may arise in a number of places. A customer sends a security questionnaire or redlines a data processing agreement. A buyer or an investor raises them in diligence. A cyber insurer asks them on an application. A board asks directly.

An owner may also commission a review without any of those prompts. That engagement is a review of the company’s systems, policies, and contracts, concluding in a written assessment signed by the firm: what was examined, what was found, where the exposure lies, and what should be done in what order.

A written assessment serves multiple purposes. It documents that the company took reasonable steps, which is the standard most regulators and most contracts apply. It allows an insurance application to be answered accurately. It gives a board or an investor something more than a self-assessment. And it identifies problems before a customer or a regulator does.

A skyscraper against a clear sky

Why the work goes through a law firm

A security assessment performed by a consultant is generally discoverable. If the company is later sued or investigated, the opposing party can obtain the report, and any identified weakness that was not remediated becomes evidence against the company.

The same assessment conducted through a law firm may be protected by the attorney-client privilege and the work-product doctrine, because its purpose is to enable a lawyer to advise the client on its legal obligations and its exposure.

Where technical verification is required — how customer data moves through a system, whether a control described in a contract exists, how a system is configured — the security engineer is retained by the firm rather than by the company, on a scope the firm defines, and reports to the firm in support of its legal advice. That is the arrangement the privilege doctrine contemplates for a consultant assisting counsel, and it must be established at the outset of the engagement rather than reconstructed later.

Two limits apply, and both should be stated directly.

Privilege is neither automatic nor absolute. It depends on how the engagement is structured, the purpose of the review, and how the resulting documents are distributed. Courts have declined to protect security assessments where equivalent work was already being performed for ordinary business purposes, or where the report was circulated broadly within the company.

Privilege protects legal advice, not facts. A system’s configuration is discoverable whether or not counsel documented it. What privilege can protect is the legal analysis, the assessment of exposure, and internal deliberation about remediation.

Network cabling in a data centre

Legal exposure from a data breach

Notification. All fifty states require notice to affected residents, most within a fixed period, and many require notice to the state attorney general. New York’s SHIELD Act separately requires reasonable administrative, technical, and physical safeguards, independent of whether a breach occurs.

State enforcement. State attorneys general enforce their states’ breach notification and data security statutes. A notification filed with a state attorney general can itself prompt an inquiry into whether the company’s safeguards met the standard the statute requires, and those offices have authority to seek penalties and injunctive relief.

Federal Trade Commission. Section 5 of the FTC Act prohibits unfair or deceptive acts or practices, and the Commission has applied it to data security in two ways. A company that describes its security in a privacy policy, a customer agreement, or marketing materials in terms that do not match what it actually does may be found to have made a deceptive representation, whether or not a breach ever occurs. Separately, security failures that cause substantial consumer injury which consumers cannot reasonably avoid may be treated as an unfair practice, even where the company promised nothing specific.

Sector and disclosure obligations. Public companies have SEC disclosure obligations for material cybersecurity incidents. Protected health information brings obligations to HHS. Covered financial services companies in New York are subject to the Department of Financial Services cybersecurity regulation, including its annual certification requirement.

Private litigation. Consumer class actions commonly follow breaches involving personal information, and business customers bring contract claims.

Contractual liability. Enterprise agreements, data processing agreements, and security addenda contain specific obligations: named controls, notification periods, audit rights, indemnities, and in some cases liability for data incidents carved out of the general limitation of liability. Liability is measured against what was agreed, not against what was implemented.

Insurance. Cyber policies are underwritten on the representations made in the application, which operate as warranties. A material misstatement about controls can support a denial of coverage.

Director and officer exposure. Oversight of information security is increasingly treated as a board responsibility, and failures of oversight are pleaded as breaches of fiduciary duty.

Cooling fans in a data centre

Law firms

Law firms hold client confidential information and are subject to the professional conduct rules in handling it. In New York, Rule 1.6(c) requires reasonable efforts to prevent unauthorized access to or disclosure of information relating to the representation, and the duty of competence under Rule 1.1 extends to the technology a lawyer uses. ABA formal opinions address securing client communications, a lawyer’s obligations following a data breach, and the use of generative artificial intelligence in practice.

Clients now ask firms which tools they use, how client confidential information is handled within those tools, and whether that use is disclosed. Answering requires a written information security and AI policy grounded in the conduct rules, and a vendor review standard the firm applies consistently.

A modern glass-walled office

The work

  • Privileged security reviews and written assessments signed by the firm
  • Reviews of systems, policies, and customer commitments
  • Remediation plans ordered by legal exposure
  • Data processing agreements and security addenda
  • Customer security questionnaires and enterprise security reviews
  • Subprocessor lists and vendor contract review
  • Cyber insurance applications and the warranties in them
  • Security, privacy, and AI due diligence on acquisitions
  • Representations, disclosure schedules, and indemnities for data and AI risk
  • Readiness work for owners preparing to sell a business
  • Pre-launch review of features that move customer data
  • Breach notification analysis under state law
  • AI and data provisions in customer and vendor agreements
  • Information security and AI policies for law firms under the conduct rules
  • Board and investor AI and data risk assessments

Fees

Scope and fees are agreed in writing before work begins. Where a matter can sensibly be handled for a fixed fee, it is.