Data Privacy & AI2026-08-07T13:14:13-07:00

Data terms are no longer an exhibit that gets signed without reading. For companies that handle customer or consumer data, the data processing addendum is now negotiated as hard as the underlying commercial agreement, and AI terms are close behind.

John negotiates data processing addenda, security addenda, and cross-border transfer terms as a regular part of his commercial practice, including against the paper of some of the largest retailers and consumer brands in the country. He advises clients on how U.S. state privacy laws and industry privacy frameworks apply to their products, data practices, and vendor relationships, always in the practical context of getting a deal signed.

John’s data privacy and AI experience includes:

  • Authored the form data processing addendum for a creator commerce platform valued at over $1 billion, now used across its brand and retailer relationships.
  • Negotiated data processing addenda opposite the paper of national retailers, global beauty and luxury brands, a national wholesale distributor, a health wearable company, and a leading database software company.
  • GDPR and Swiss data protection compliant addenda for a SaaS provider serving European enterprise customers.
  • Security addenda and audit provisions, including SOC 2 and ISO reporting structures negotiated in lieu of on-site audit rights.
  • Analysis of the interaction between an industry multi-state privacy framework and individual brand data processing addenda for a commerce platform.
  • AI addenda and AI provisions in SaaS agreements: training data restrictions, model output ownership, customer data usage rights, and allocation of responsibility between vendor and customer.

Go to Top