Privacy Lawyers for Des Moines, Iowa
Need a privacy lawyer in Des Moines, Iowa?
ContractsCounsel matches businesses with Des Moines-based privacy lawyers, providing fixed-fee quotes from vetted attorneys with the first proposal typically arriving in just a few hours.
Hire a Lawyer for 60% Less than Traditional Law Firms
Meet some of our Des Moines Privacy Lawyers
Melissa L.
Seasoned negotiator, mediator, and attorney providing premier legal advice, services, and representation with backgrounds in the following but not limited to law areas: business/commercial (restaurant & manufacturing), contracts, education, employment, family and matrimonial, healthcare, real estate, and probate & wills/trusts
"This attorney has been extremely professional, accurate, available, and extremely fast. In a word, very efficient. Within 3 days she gave me the final product, a high quality one. I should also add that her courtesy throughout the process was the cherry on top of the cake. I could not recommend her enough!"
Brad B.
Business attorney with over 15 years of experience serving companies big and small with contracting including business, real estate and employment.
March 9, 2025
Christopher R.
Over the course of the past 30 years, in both General Counsel roles (3 times) and in private practice, I have built a successful national real estate transaction, construction, and environmental law practice
August 23, 2025
Alexander C.
I am a solo practitioner that runs my own legal practice. I am currently licensed in 16 states and I'm working to expand that reach.
Find the best lawyer for your project
Browse Lawyers NowMeet some of our other Privacy Lawyers
Michael J.
Combining extensive experience in litigation and as general counsel for a real estate and private equity company, I provide ongoing guidance and support to clients on a variety of transactional matters, including business formation, partnership agreements, corporate agreements, commercial and residential leasing, and employment issues.
"Michael did an excellent job. I will hire him again. Thank you!"
Anand A.
Anand is an entrepreneur and attorney with a wide-ranging background. In his legal capacity, Anand has represented parties in (i) commercial finance, (ii) corporate, and (iii) real estate matters throughout the country, including New Jersey, Pennsylvania, Delaware, Arizona, and Georgia. He is well-versed in business formation and management, reviewing and negotiating contracts, advising clients on financing strategy, and various other arenas in which individuals and businesses commonly find themselves. As an entrepreneur, Anand is involved in the hospitality industry and commercial real estate. His approach to the legal practice is to treat clients fairly and provide the highest quality representation possible. Anand received his law degree from Rutgers University School of Law in 2013 and his Bachelor of Business Administration from Pace University, Lubin School of Business in 2007.
"Anand was a pleasure to work with! He was very thorough and professional."
Howard B.
Berkson is a dedicated, practical, and detail-oriented attorney licensed to practice in every state court of Oklahoma and the United States Northern and Eastern District Courts. He graduated from the University of Tulsa College of Law with Honors. While there, he received awards for highest grade in trial practice, legal research, and civil procedure. He was also the Executive Notes and Comments Editor for the Energy Law Journal, the official journal of the Energy Bar Association in Washington, D.C. The Energy Law Journal is one of the few peer-reviewed journals in the legal profession. Prior to becoming an attorney, Howard Berkson held executive positions involving a wide range of business and human resources management functions. He has in-depth knowledge of both business and HR practices. During his business career, Berkson negotiated, wrote, red-lined, and disputed contracts. He has answered charges, handled inspections, and supervised audits involving numerous agencies including the Department of Labor, the Equal Employment Opportunity Commission, the National Labor Relations Board, the Occupational Safety and Health Administration, and various state agencies. Berkson honed his analytical and writing skills while earning his Bachelor of Arts degree in Philosophy from the University of Washington. He went on to obtain a Master of Arts in Labor and Industrial Relations from the University of Illinois. Berkson’s work can be found in such publications as The Energy Law Journal, Human Resource Management Review and Personnel Psychology. He is a member of Phi Alpha Delta law fraternity and of Phi Kappa Phi honor society.
"Very easy and effective to work with. Howard knows what he is doing."
Gill D.
Erik has been a practicing attorney in Florida for over a decade. He specializes in employment and real estate contracts. He has represented clients big and small and can assist with any contract issue.
"Gill was incredibly responsive and professional throughout the entire process. He provided clear, practical legal guidance and handled a difficult, uncooperative counterparty with great patience. Highly recommend his services."
Christopher M.
I am a corporate attorney with several years of experience with contracts, corporate and business, government projects, and employment law.
"Chris helped us put together a quick SaaS contract. HE is very nice and professional."
July 8, 2022
AHAJI A.
Ahaji Amos, PLLC is a Houston-based intellectual property and civil litigation firm servicing clients throughout the U.S.
April 18, 2024
Gayle G.
Fractional General Counsel and Board Advisor with over 26 years of experience advising companies and their management in the US, EMEA and APAC. I use my legal and finance background to understand the client's business and bring the most practical, efficient legal solutions to grow the business while reducing risk. Focus includes: Compliance | Governance (including AI) | Tech Transactions | Licenses | SaaS | Cross Border | Equity Investments | JVs | International Expansion | Fractional GC https://www.linkedin.com/in/ggorvettesq
September 4, 2022
Deborah W.
Williamson Health Law is an established and trusted law firm focused on representing hospitals, health plans, physician groups, physicians, physical therapy businesses, psychologists and other health care providers, professionals, and businesses in all aspects of health law. including the Stark law, the Anti-Kickback Statute (“AKS”), the Health Insurance Portability and Accountability Act (“HIPAA”), regulatory compliance, Medicare and Blue Cross audits and overpayment appeals, payer departicipation and disaffiliation appeals, payer and provider disputes, reimbursement and billing, compliance plans, health care industry contracts and professional licensure. We represent clients throughout Michigan and the U.S. with certain federal matters such as federal regulatory analysis and Medicare audits.
Privacy Legal Questions and Answers
Privacy
Website Terms of Service and Privacy Policy
Texas
Can a company change its Terms of Service and Privacy Policy without notifying its users?
I recently discovered that a popular online platform I use has made significant changes to its Terms of Service and Privacy Policy, which I was not notified about. These changes seem to give the company more access to my personal data and reduce my rights as a user. I'm concerned about the implications of these changes and whether the company is allowed to make such modifications without informing its users in advance.
Jennifer B.
Online platforms can modify their terms of service and privacy policies without advance notice if: (1) Their terms explicitly allow such changes, and (2) Users continue using the platform after changes are made. However, modifications may still be challenged if they are unconscionable or violate privacy laws, particularly if they significantly impact user rights or data protection. While platforms may have the right to make unannounced changes, the enforceability depends on the specific modifications and their compliance with applicable regulations.
Privacy
Data Processing Agreement
Texas
Is a Data Processing Agreement necessary for my business?
I recently started a small online business where I collect and process personal data from customers, such as their names, addresses, and payment information. I've heard about the importance of protecting customer data and ensuring compliance with data protection laws. I want to make sure I am taking the necessary steps to safeguard this information and maintain legal compliance. I've come across the term 'Data Processing Agreement' but I'm not sure if it is something I need for my business. Can you please advise me on whether a Data Processing Agreement is necessary and what it entails?
Jennifer B.
As an online business collecting customer data in Texas, you're right to be concerned about data protection compliance. Data privacy regulations depend on where your customers are and your volume of business. A Data Processing Agreement is a contract between a data controller (you, as the business owner) and a data processor (any third party that processes personal data on your behalf). It establishes the rights and obligations of each party regarding the processing of personal data. It helps ensure compliance with applicable data protection laws. It also discloses to your customers which companies are processing their data. Whether you need a DPA depends on several factors: Third-party services: If you use services like payment processors, cloud storage providers, email marketing platforms, or website hosting that access your customers' personal data, you likely need DPAs with these service providers. Applicable laws: While Texas doesn't have a comprehensive data privacy law like California's CCPA, it does have the new Texas Data Security and Privacy Act, which likely impacts you if your company earns 25%+ of its revenue from selling consumer data or hits other revenue thresholds. Laws in other states and in the EU also might apply. Industry standards: DPAs have become standard practice for demonstrating data protection compliance, regardless of strict legal requirements. Benefits of Implementing a DPA: Even if not strictly required by law in Texas, DPAs offer significant benefits: (1) clarify responsibilities between your business and service providers; (2) reduce legal liability through contractual protections; (3) increase customer trust by demonstrating a commitment to data protection; (4) preparation for evolving data protection laws; and (5) a potential competitive advantage over businesses without such protections. As data privacy regulations evolve, implementing DPAs now positions your business ahead of compliance requirements while building customer trust through demonstrated commitment to data protection. I use one in my practice. You should speak with an attorney who can provide a detailed DPA analysis based on your industry and customers.
Privacy
Software Agreement
North Carolina
Software agreement and GDPR compliance?
I am the founder of a software company that is looking to enter into a software agreement with a new client. We are in the process of finalizing the agreement but I am concerned that it may not be compliant with the General Data Protection Regulation (GDPR). I want to make sure that the agreement is compliant with GDPR so that our company is not at risk of any legal action or penalties.
Nicholas M.
You are smart to consider GDPR, but also should consider US Privacy Policies in connection with the agreement. There are several states the already have GDPR level of privacy policies and over 20 states with bills introduced as well. A well formed policy will consider the data collected, where it is stored and how it is transferred, who has access to the data, the purpose of the data for use in the app, the ability to sell or reuse the data for additional purposes, and when the data should be deleted. This process should be contemplated and consistent within employee manuals, data access procedures, and implemented in master services agreements across all vendors, subcontractors, and suppliers. One final note is that you need to practice what you write, because a published privacy policy that is not followed may be considered a deceptive trade practice by the FTC resulting in fines on top of the costs of a breach.
Privacy
GDPR Compliance
Texas
Is my website required to comply with GDPR regulations?
I recently launched a small e-commerce website that sells products to customers in the European Union. While I am based in the United States, I have noticed that a significant portion of my customers are from EU countries. I have heard about the General Data Protection Regulation (GDPR) and its requirements for businesses handling personal data of EU citizens, but I'm not sure if my website needs to comply with these regulations. Can you clarify if my website falls under the scope of GDPR and what steps I need to take to ensure compliance?
Randy M.
Yes. If you sell to people in the European Union, the GDPR applies to you. It doesn’t matter where your business is based. Under Article 3, the law extends beyond Europe to cover any company that offers products or services to EU residents or tracks their behavior online. So if you accept orders from the EU, you're legally required to follow GDPR rules. The GDPR lays out key principles in Article 5. In simple terms: • You must have a lawful basis before collecting personal data (lawfulness). • Data must be collected and used fairly and transparently (fairness and transparency). • Only gather the minimum data necessary and for clear, legitimate purposes (purpose limitation and data minimisation). • Keep personal data accurate and update or correct it when needed (accuracy). • Don’t keep data longer than required for the stated purpose (storage limitation). • Protect data with appropriate technical and organizational safeguards (integrity and confidentiality). • Be able to show regulators that you comply with all of these rules (accountability). You also need to be able to prove you're doing all this if a regulator asks. When Are You Allowed to Use Customer Data? For things like shipping an order or taking payment, you’re covered by what's called the “contract” basis under Article 6(1)(b). You need info like names, addresses, and payment details to complete a sale. That’s allowed. For email marketing, things are stricter. Consent is usually required. That means a clear opt-in, like an unchecked box the customer has to actively click. Some EU countries allow limited “soft opt-in” for existing customers, but the rules vary by country. If you’re unsure, it’s safest to get clear consent before emailing EU customers with promotions. What Rights Do Customers Have Over Their Data? Articles 15–21 give EU customers a lot of control. They can: • Ask what data you have on them • Correct wrong info • Ask you to delete their data (in certain cases) • Tell you to stop using it • Opt out of marketing • Ask you to send their data to another company You need systems in place to respond to these requests quickly and efficiently. What About Cookies? The EU’s top court (in the Planet49 case) made it clear: you can’t assume consent for tracking cookies. That means: • No pre-checked boxes • No vague “we use cookies” banners • You must let users actively choose which types of cookies to allow • You need to record and prove that consent was given Your cookie banner should be easy to use and offer equal choices for accepting or rejecting cookies. How to Keep Customer Data Secure You’re expected to take technical and organizational steps to protect people’s personal data. That includes things like: • Using SSL/TLS encryption • Restricting access to databases • Having solid contracts with vendors who handle customer data If there’s a data breach, Article 33 says you must tell the relevant EU authority within 72 hours if the breach could put someone’s rights at risk. If it’s a serious risk to individuals, Article 34 says you also need to inform the affected customers. What If You Use Outside Vendors? If you work with third parties such as payment processors, email services, or cloud providers, you’re responsible for what they do with customer data. The GDPR requires you to sign Data Processing Agreements (DPAs) with them. These agreements must cover: • How they protect the data • Their legal obligations • How they’ll help you stay compliant You can’t skip this part. It’s not optional. Do You Need an EU Representative? If you regularly sell to EU customers, the answer is yes. Article 27 requires most non-EU businesses to appoint an official representative inside the EU. This rep acts as your point of contact for EU regulators and customers. You only get an exemption if: • You rarely process EU data • It’s low-risk • It doesn’t involve sensitive data But if you're actively targeting or shipping to EU customers, that exemption likely won’t apply. What Happens If You Don’t Comply? Regulators can fine you up to €20 million or 4% of your global annual revenue, whichever is higher. That said, small businesses aren’t usually hit with huge fines right away. Most EU regulators aim to help companies comply, especially if you’re clearly making an effort. But ignoring GDPR isn’t a good strategy. Being able to show you’ve taken real steps toward compliance is your best protection. Attorneys on Contracts Counsel are ready to help with GDPR compliance, including privacy policies, vendor contracts, and other legal obligations tailored to your business needs.
Privacy
Terms and Conditions
California
SaaS Agreement for beta use for anyone
We are a technology SaaS startup in the process of launching our product. We need an agreement that covers our beta period of a few months. We are allowing anyone to use it in this period to market the product. The usage is free of cost. Besides the standard SaaS terms, we want terms to cover for any issues with data loss/protection and anything that can possibly go wrong as we are still in beta and have a few things to fix before we go live in production. Please let me know how much this will cost and when we can have it available. We are a Southern California based company in infancy.
Gregory B.
This is a pretty standard document. The biggest concern is just making sure that the document reflects the reality of how customer data will be used. Usually a Privacy Policy is referenced in the terms, and is likely one of the most important documents for a CA startup.
Quick, user friendly and one of the better ways I've come across to get ahold of lawyers willing to take new clients.
View Trustpilot ReviewHow It Works
Post Your Project
Get Free Bids to Compare
Hire Your Lawyer
Privacy lawyers by top cities
- Austin Privacy Lawyers
- Boston Privacy Lawyers
- Chicago Privacy Lawyers
- Dallas Privacy Lawyers
- Denver Privacy Lawyers
- Houston Privacy Lawyers
- Los Angeles Privacy Lawyers
- New York Privacy Lawyers
- Phoenix Privacy Lawyers
- San Diego Privacy Lawyers
- Tampa Privacy Lawyers
Privacy lawyers by nearby cities
Contracts Counsel was incredibly helpful and easy to use. I submitted a project for a lawyer's help within a day I had received over 6 proposals from qualified lawyers. I submitted a bid that works best for my business and we went forward with the project.
View Trustpilot Review
I never knew how difficult it was to obtain representation or a lawyer, and ContractsCounsel was EXACTLY the type of service I was hoping for when I was in a pinch. Working with their service was efficient, effective and made me feel in control. Thank you so much and should I ever need attorney services down the road, I'll certainly be a repeat customer.
View Trustpilot Review
I got 5 bids within 24h of posting my project. I choose the person who provided the most detailed and relevant intro letter, highlighting their experience relevant to my project. I am very satisfied with the outcome and quality of the two agreements that were produced, they actually far exceed my expectations.
View Trustpilot ReviewHow It Works
Post Your Project
Get Free Bids to Compare
Hire Your Lawyer