
Practice Areas

Privacy, data security, and AI governance are no longer side issues. They define enterprise value, insurability, and how a company holds up under forensic scrutiny. For growth-stage and middle-market companies, the risk isn’t just whether a policy exists—it’s whether your contracts and vendor relationships can withstand a breach or a dispute over how data is actually being weaponized.
At Davis, Burch & Abrams, we provide more than a checklist. Our team includes CIPP/US and CIPP/C-certified counsel with deep experience building governance frameworks that reflect operational reality. Whether navigating the Virginia Consumer Data Protection Act (VCDPA) or addressing PIPEDA requirements in Canada, we provide the strategic execution needed to protect your data assets and your reputation.
We advise companies on privacy law, data governance, cybersecurity obligations, and AI-related legal risk where operational, regulatory, and commercial realities intersect. We help clients integrate legal strategy into core operations by focusing on:
We regularly advise on:
We build and refine privacy programs designed to address evolving privacy law requirements across state, federal, and international frameworks, including scalable governance, internal controls, and compliance structures for laws such as the VCDPA, CCPA/CPRA, GDPR, and PIPEDA.
We help companies map how data is collected, stored, shared, retained, and deleted—identifying operational gaps that can create privacy, litigation, or regulatory exposure later.
We advise on data processing terms, vendor diligence, and third-party risk management, including whether vendors have the right safeguards, audit provisions, and data-use limitations in place.
We prepare privacy policies, impact assessments, consent frameworks, and related documentation to support internal workflows and regulatory defensibility.
As privacy lawyers and data breach attorneys, we help clients respond when safeguards fail, including legal analysis, notification obligations, remediation strategy, and post-incident improvements.
We advise on data privacy litigation, cybersecurity litigation, and related claims arising from unauthorized access, misuse of data, or alleged failures in security controls and contractual protections.
We implement AI governance frameworks and acceptable use policies to address “shadow AI,” where employees use public tools in ways that expose proprietary data, customer information, or regulated datasets.
We work with clients on AI-related agreements addressing training data, outputs, ownership, model use, audit rights, and allocation of liability tied to AI-enabled services and tools.
We advise on cross-border transfers, transfer impact assessments, and international privacy obligations for companies operating across multiple jurisdictions.
For companies without an internal privacy lead, we provide ongoing outside legal counsel and practical oversight across privacy, security, and AI governance.
Privacy and cybersecurity frameworks work best when they are built into the business—not layered on after the fact. Our bold, efficient approach shows up here the same way it does elsewhere: focus on the real pressure points, move efficiently, and build structure that can hold up when challenged.
We work closely with clients to understand their systems, data flows, vendors, and decision-making processes, while keeping enough distance to spot gaps before they become disputes, breach exposure, or regulatory problems.
The goal is not policy for its own sake. It is workable, defensible governance that supports growth.

We advise companies across the United States and Canada, while maintaining a strong base in Virginia and the broader Mid-Atlantic. Our work reflects the realities of businesses operating across multiple jurisdictions, systems, and increasingly complex privacy, cybersecurity, and AI expectations.
From founder-led companies scaling quickly to middle-market businesses managing sensitive data and vendor ecosystems, we provide guidance that accounts for both legal obligations and business priorities.




Top Rated Lawyers¹ recognized by Super Lawyers, Virginia Business Legal Elite and Best Lawyers in America.


