Technology & Data › Privacy & Data

Data Privacy & Compliance Lawyer

Handle data like it's someone else's — because it is.

Privacy policies, terms of service, data processing agreements, and compliance guidance for tech companies in CT, NY, and MA.

What We Handle

Privacy Policies & ToS

The public-facing documents: what data is collected, why, who it goes to, and how long it is kept — written to match what the product actually does.

Data Processing Agreements

The contract between a company and its vendors or customers covering who controls the data, who processes it, and what each side must do when something goes wrong.

Regulatory Compliance

Connecticut's Data Privacy Act, other state privacy laws, and the GDPR where a company has EU users. Which ones apply depends on where the users are, not where the company is.

Incident Preparedness

Breach-notification obligations, the timelines attached to them, and a written plan that exists before it is needed rather than after.

Why it matters

A policy that doesn't match your practices is worse than none — it's a written admission.

Regulators and plaintiffs read the policy first and compare it to the product second. A policy copied from another company describes that company's data practices, which makes every gap between the two a documented misstatement.

Working together

How the work runs

The work starts with what the product actually does — what gets collected, where it is stored, which vendors touch it, and who the users are. That determines which laws apply, and it is usually a shorter list than founders expect.

From there Turley Law drafts the policy, the terms, and the data processing agreement to match, and flags the practices that need to change before the paperwork can honestly describe them. Where a company is answering a customer's security questionnaire, the same review produces the answers.

Questions?

Good to know

Do we need a privacy policy?

If you collect any personal data — emails, account info, analytics — yes. Most state and international privacy laws require one, and it needs to actually match what you do with the data.

Does the GDPR apply to a Connecticut company?

It can. The GDPR follows the users, not the company — if a company offers goods or services to people in the EU or monitors their behavior, it applies regardless of where the company sits. Having a few EU visitors on a website is not the same as targeting EU customers, and the difference matters.

What is a data processing agreement, and who needs one?

A data processing agreement (DPA) is the contract that governs personal data moving between two companies — it names who decides how the data is used, who handles it, and what each side owes the other on security and breach notice. Any company that either sends personal data to vendors or receives it from customers will be asked for one.

We had a breach. What happens now?

The obligations turn on what data was involved and where the affected people live, and several states set deadlines measured in days. The first call should happen before notice goes out, because what gets said in that notice is itself evidence.

Get ahead of it.