Privacy & Data Protection
How regimes like the NDPA, the GDPR and the UK GDPR actually bind a business, and what cross-border transfers genuinely require.
- Adequacy, SCCs and transfer assessments
- NDPA · GDPR · UK GDPR, read side by side
Focus Areas
Four regions of practice I read closely and write about. Not services, but areas of focus, where cross-border regulation is hardest to navigate and most worth explaining.
How regimes like the NDPA, the GDPR and the UK GDPR actually bind a business, and what cross-border transfers genuinely require.
Reading new rules like the EU AI Act for what truly applies, and governing AI without overcorrecting.
Licensing and structuring across markets, where the same product wears a different regulatory identity in each.
Sequencing an entry so the legal workstreams meet at the seams, instead of failing between them.
These themes run through the Insights. The site is a knowledge platform, not a law firm, so there are no engagements to book here, only thinking to read.