Data Privacy

Green fingerprint with digital pixel effect on a black background.

Why Privacy Risk Assessments Are No Longer Optional for GCs

Burke’s article in Today’s General Counsel May 8, 2026

Burke Data & Privacy (BDP) advises organizations on the design, implementation, and maturation of privacy, cybersecurity, and information governance programs, including data protection agreements, technical and organizational measures, technology vendor agreements, and compliant privacy notices and consent mechanisms. This work increasingly encompasses AI-related governance, including monitoring and safeguard technologies, associated policies, and governing agreements—an area in which BDP has gained particular insight through its work with an AI governance platform client.

Patrick Burke began advising on data protection matters in Europe in 2006, working under the EU Data Protection Directive well before the emergence of U.S. privacy law. As European counsel to a cybersecurity software company, he developed corporate compliance frameworks under the Directive that later evolved into GDPR compliance programs. He subsequently taught data privacy at Cardozo Law School and led consumer data protection initiatives at the New York State Department of Financial Services.

Privacy Program Design and Regulatory Compliance

BDP designs and implements privacy compliance programs tailored to applicable legal and industry-sector requirements, including U.S. federal law (GLBA, HIPAA/HITECH, SEC cybersecurity disclosure rules), U.S. state privacy and breach notification statutes, the EU and UK GDPR, Canada's PIPEDA and provincial legislation, and relevant NIST and SOC frameworks. This work spans data mapping through policy drafting, with particular depth in adtech, pharmaceutical, financial services, and other regulated industries processing personal information on a global scale.

Contractual Risk Allocation

Recognizing that data protection obligations are ultimately defined through contract, BDP advises on the negotiation and drafting of data processing agreements, standard contractual clauses, business associate agreements, and vendor and client data-sharing arrangements—balancing data protection obligations against operational and commercial requirements.

Sensitive Data, Privacy-by-Design, and Risk Assessment

BDP assists clients in addressing heightened obligations applicable to health, biometric, financial, and children's data, as well as geolocation and employee monitoring information, and in embedding privacy-by-design principles into products and business processes. This includes conducting data protection impact assessments, privacy impact