Privacy Lawyers for Eugene, Oregon
Need a privacy lawyer in Eugene, Oregon?
ContractsCounsel matches businesses with Eugene-based privacy lawyers, providing fixed-fee quotes from vetted attorneys with the first proposal typically arriving in just a few hours.
Hire a Lawyer for 60% Less than Traditional Law Firms
Meet some of our Eugene Privacy Lawyers
Jason P.
Jason is a self-starting, go-getting lawyer who takes a pragmatic approach to helping his clients. He co-founded Fortify Law because he was not satisfied with the traditional approach to providing legal services. He firmly believes that legal costs should be predictable, transparent and value-driven. Jason’s entrepreneurial mindset enables him to better understand his clients’ needs. His first taste of entrepreneurship came from an early age when he helped manage his family’s small free range cattle farm. Every morning, before school, he would deliver hay to a herd of 50 hungry cows. In addition, he was responsible for sweeping "the shop" at his parent's 40-employee HVAC business. Before becoming a lawyer, he clerked at the Lewis & Clark Small Business Legal Clinic where he handled a diverse range of legal issues including establishing new businesses, registering trademarks, and drafting contracts. He also spent time working with the in-house team at adidas® where, among other things, he reviewed and negotiated complex agreements and created training materials for employees. He also previously worked with Meriwether Group, a Portland-based business consulting firm focused on accelerating the growth of disruptive consumer brands and facilitating founder exits. These experiences have enabled Jason to not only understand the unique legal hurdles that can threaten a business, but also help position them for growth. Jason's practice focuses on Business and Intellectual Property Law, including: -Reviewing and negotiating contracts -Resolving internal corporate disputes -Creating employment and HR policies -Registering and protecting intellectual property -Forming new businesses and subsidiaries -Facilitating Business mergers, acquisitions, and exit strategies -Conducting international business transactions In his free time, Jason is an adventure junkie and gear-head. He especially enjoys backpacking, kayaking, and snowboarding. He is also a technology enthusiast, craft beer connoisseur, and avid soccer player.
"Very nice! Great on responding back and being available! Recommend 100% !"
Curt B.
Curt Brown has experience advising clients on a variety of franchising, business litigation, transactional, and securities law matters. Mr. Brown's accolades include: - Super Lawyers Rising Star - California Lawyer of the Year by The Daily Journal - Pro Bono Attorney of the Year the USC Public Interest Law Fund Curt started his legal career in the Los Angeles office of the prestigious firm of Irell & Manella LLP, where his practice focused on a wide variety of complex civil litigation matters, including securities litigation, antitrust, trademark, bankruptcy, and class action defense. Mr. Brown also has experience advising mergers and acquisitions and international companies concerning cyber liability and class action defense. He is admitted in California, Florida, D.C., Washington, Illinois, Colorado, and Michigan.
"I was very impressed with the responsiveness and knowledge brought to my situation."
Jim B.
Since 2002, when I first received my law license and began practicing in criminal litigation, I have dedicated myself to providing competent and impassioned legal representation to my clients. Transitioning into business and intellectual property law and serving the Oregon community under the banner of INTELLEQUITY since 2016, I embarked on a mission to offer an unparalleled level of personalized legal guidance that empowers my clients through understanding, support, and legal mastery. As a seasoned attorney, I recognize that behind every case is a person with a distinct set of emotions, aspirations, and challenges. This is why my approach to legal services is not just about cases and statutes; it's about people and their lives. Whether it's navigating the intricacies of business law or safeguarding your intellectual property, I'm here to provide more than just professional counsel—I offer a compassionate, personalized approach to every case. This means keeping you well-informed at every step, empowering you with in-depth understanding, and steering you towards decisions that are legally sound and, more importantly, right for you.
"Great person to work with. He helped gain a better understanding of my own business."
Alexander M.
Broad area practice including Business (domestic & international), IP, Employment, Family Law, Administrative, etc. My focus is a direct, no-BS approach with fast turn around times on completed work.
"Alexander delivered fast, thorough, and practical legal guidance. He identified 22 issues with my MSA, provided a clear MSO/PC structure opinion, and mapped out insurance requirements for both entities — all within 24 hours. Highly recommend for any healthcare startup needing Florida specific legal expertise."
Jessica M.
Jessica Molligan is an attorney with twenty years of experience in family law, bankruptcy, and litigation.
"Jessica was great to work with. We got a quick cliam deed done and it was an easy process to go through with her. Highly reccomend hiring her for any of your needs."
June 28, 2023
Shanon G.
Have experience in contract, family law, municipality work, criminal defense, litigation, some wills and estates as well. Been practicing law for over 22 years.
December 4, 2023
McCoy S.
P. McCoy Smith is the Founding Attorney at Lex Pan Law LLC, a full-service technology and intellectual property law firm based in Portland, Oregon, U.S.A and Opsequio LLC, an open source compliance consultancy. Prior to his current position, he spent 20 years in the legal department of a Fortune 50 multinational technology company as a business unit intellectual property specialist; among his duties was setting up the free & open source legal function and policies for that company. He preceded his in-house experience with 8 years in private practice in a large New York City-based boutique intellectual property law firm, working simultaneously as a U.S. patent litigator and U.S. patent prosecutor. He was also a patent examiner at the U.S. Patent & Trademark Office prior to attending law school. He is licensed to practice law in Oregon, California & New York and to prosecute patent applications in the U.S. Patent & Trademark Office; he is also a registered Trademark and Patent Agent with the Canadian Intellectual Property Office. He has degrees from Colorado State University (Bachelor of Science, Mechanical Engineering, with honors), Johns Hopkins University (Masters of Liberal Arts) and the University of Virginia (Juris Doctor). While in private practice, and continuing into his in-house career, he taught portions of the U.S. patent bar exam for a long-standing and well-known patent bar exam preparation course, and from 2014-2020 was on the editorial board of the Journal of Open Law, Technology & Society (JOLTS), and starting in 2023 will be on the editorial board of the American Intellectual Property Law Quarterly Journal (AIPLAQJ). He is the author or co-author of chapters on open source and copyright and patents in “Open Source Law, Policy & Practice” (2022, Oxford University Press). He lectures frequently around the world on free and open source issues as well as other intellectual property topics.
August 23, 2025
Alexander C.
I am a solo practitioner that runs my own legal practice. I am currently licensed in 16 states and I'm working to expand that reach.
Neil R.
Neil Rust is a transactional attorney with almost four decades of experience ranging across a broad range of fields, including M&A, finance, structured finance, VC and general corporate. Before moving to Oregon, Mr. Rust was a partner at the Los Angeles office of an international law for 26 years and the Century City office of a national law firm for 5 years. During his big firm tenure, Neil Rust gathered experience across multiple industries and enjoys counselling clients as much as drafting and negotiating.
Grace C.
May 12, 2026
Grace C.
I’m Grace E. Carlson, an intellectual property & transactional attorney, founder of aTMospheric IP, LLC, with over 6 years of combined law firm and in-house experience. I help businesses, startups, creators, and entrepreneurs draft, review, and negotiate commercial contracts while protecting their brands and innovations. My expertise includes SaaS agreements, MSAs, NDAs, licensing contracts, vendor and partnership agreements, as well as comprehensive trademark strategy, copyright matters, AI-related IP issues, and technology transactions. I’ve supported global companies including Robinhood, Iron Mountain, and Microsoft, and provided flexible in-house counsel through Axiom Law across fintech, SaaS, consumer goods, and data center industries. Known for translating complex legal issues into clear, practical solutions, I focus on delivering contracts that reduce risk, support go-to-market strategies, and scale with your business. Whether you need a custom SaaS agreement, trademark-integrated contracts, or AI compliance review, I provide responsive, business-minded counsel. Bar Admissions: Washington (2020) & Oregon (2021) J.D., Seattle University School of Law Let’s get your contracts and IP protections done right — efficiently and effectively.
Find the best lawyer for your project
Browse Lawyers NowMeet some of our other Privacy Lawyers
Gene R.
I help founders and business owners set up core contracts, deal documents, and ownership terms so they can form companies, close business sales, bring in partners, and launch products without expensive surprises later. I focus on LLC and corporation formations and operating/shareholder agreements, business sales, founder and partner arrangements (including buyouts and separations), commercial contracts (NDAs, MSAs, privacy policies), and IP/SaaS ownership and licensing tied to those deals. Clients describe me as “the antidote to Big Law inefficiency,” “a legal sniper,” and say I’ve “potentially saved hundreds of thousands” by catching gaps other lawyers missed. I do all my own work, explain options in plain English, and give clear scope and hour ranges before I start. Harvard Law (cum laude), MIT, former Wilson Sonsini attorney, and GC/VP Legal for media and tech companies and venture‑backed startups, with a 5.0 rating and repeat clients on this platform.
Nick G.
My name is Nick Gleason, and I’m an attorney licensed in California and a veteran of the United States Navy. While in law school, during my clerkship with Mob Entertainment, I worked under the General Counsel, drafting cease and desist letters, demand letters, and assignment and licensing agreements. I also worked with outside counsel on copyright infringement matters, helping to protect the interests of the company. Now in my professional practice, I continue to help clients like you protect your interests by offering affordable legal representation for all your contract and copyright needs. I can draft contracts, review proposed agreements for vulnerabilities, and negotiate terms on your behalf, as well as prepare effective cease and desist letters and demand letters tailored to your situation, including in copyright and DMCA-related matters. I will always be fair and transparent with my fees. I’d love to hear from you.
Privacy Legal Questions and Answers
Privacy
Software Agreement
North Carolina
Software agreement and GDPR compliance?
I am the founder of a software company that is looking to enter into a software agreement with a new client. We are in the process of finalizing the agreement but I am concerned that it may not be compliant with the General Data Protection Regulation (GDPR). I want to make sure that the agreement is compliant with GDPR so that our company is not at risk of any legal action or penalties.
Nicholas M.
You are smart to consider GDPR, but also should consider US Privacy Policies in connection with the agreement. There are several states the already have GDPR level of privacy policies and over 20 states with bills introduced as well. A well formed policy will consider the data collected, where it is stored and how it is transferred, who has access to the data, the purpose of the data for use in the app, the ability to sell or reuse the data for additional purposes, and when the data should be deleted. This process should be contemplated and consistent within employee manuals, data access procedures, and implemented in master services agreements across all vendors, subcontractors, and suppliers. One final note is that you need to practice what you write, because a published privacy policy that is not followed may be considered a deceptive trade practice by the FTC resulting in fines on top of the costs of a breach.
Privacy
Data Processing Agreement
Texas
What are the key provisions that should be included in a Data Processing Agreement?
I am a business owner and I recently entered into a partnership with another company to provide data processing services. As part of this partnership, we need to draft a Data Processing Agreement to outline the responsibilities and obligations of both parties in relation to data protection and processing. I want to ensure that the agreement covers all the necessary provisions to protect both our companies and the personal data we handle, so I am seeking guidance on the key provisions that should be included in such an agreement.
Ricardo A.
A Data Processing Agreement (DPA) is a legally binding document that governs the relationship between the data controller and data processor in compliance with data protection laws such as the General Data Protection Regulation (GDPR). Here are the key provisions that should be included: 1. Scope and Purpose • Clearly define the purpose of the data processing and the nature of the data being processed. • Specify the categories of data subjects (customers, employees). • Outline the types of personal data involved. 2. Roles and Responsibilities • Define the roles of the parties (controller vs. processor). • State that the processor will act only on the documented instructions of the controller. 3. Compliance with Laws • A commitment to comply with applicable data protection laws and regulations, such as the GDPR or CCPA. 4. Confidentiality • Ensure that the processor’s personnel are subject to confidentiality obligations. • Prohibit unauthorized access or sharing of data. 5. Security Measures • Require the processor to implement appropriate technical and organizational measures to protect personal data (encryption, access controls). • Include procedures for detecting and responding to data breaches. 6. Sub-processors • Outline conditions for engaging sub-processors ( prior authorization or notification). • Ensure sub-processors comply with the same data protection obligations. 7. Data Subject Rights • Require the processor to assist the controller in responding to data subject requests (access, correction, deletion). 8. Data Transfers • Specify the conditions for transferring personal data outside the European Economic Area (EEA) or other restricted jurisdictions. • Include safeguards such as Standard Contractual Clauses (SCCs) or Binding Corporate Rules (BCRs). 9. Data Breach Notification • Oblige the processor to notify the controller promptly in the event of a personal data breach. • Provide details on how incidents will be managed. 10. Audit Rights • Grant the controller or its appointed auditor the right to inspect and audit the processor’s compliance. 11. Retention and Deletion of Data • Specify the duration of processing. • Require the processor to delete or return personal data after the end of the contract or processing period. 12. Liability and Indemnification • Allocate liability for breaches or non-compliance. • Include indemnification provisions if appropriate. 13. Termination and Consequences • Address the conditions for terminating the DPA. • Define the post-termination obligations (data return or deletion). 14. Jurisdiction and Governing Law • Specify the governing law and jurisdiction for resolving disputes. 15. Annexes or Schedules • Include detailed annexes to provide additional information, such as: • A list of sub-processors. • A description of technical and organizational measures. • A record of processing activities. Legal Review Always consult a legal expert to ensure that the DPA aligns with the applicable laws and the specific needs of the parties involved.
Privacy
Website Terms of Service and Privacy Policy
Texas
Can a company change its Terms of Service and Privacy Policy without notifying its users?
I recently discovered that a popular online platform I use has made significant changes to its Terms of Service and Privacy Policy, which I was not notified about. These changes seem to give the company more access to my personal data and reduce my rights as a user. I'm concerned about the implications of these changes and whether the company is allowed to make such modifications without informing its users in advance.
Jennifer B.
Online platforms can modify their terms of service and privacy policies without advance notice if: (1) Their terms explicitly allow such changes, and (2) Users continue using the platform after changes are made. However, modifications may still be challenged if they are unconscionable or violate privacy laws, particularly if they significantly impact user rights or data protection. While platforms may have the right to make unannounced changes, the enforceability depends on the specific modifications and their compliance with applicable regulations.
Privacy
Data Processing Agreement
Texas
Is a Data Processing Agreement necessary for my business?
I recently started a small online business where I collect and process personal data from customers, such as their names, addresses, and payment information. I've heard about the importance of protecting customer data and ensuring compliance with data protection laws. I want to make sure I am taking the necessary steps to safeguard this information and maintain legal compliance. I've come across the term 'Data Processing Agreement' but I'm not sure if it is something I need for my business. Can you please advise me on whether a Data Processing Agreement is necessary and what it entails?
Jennifer B.
As an online business collecting customer data in Texas, you're right to be concerned about data protection compliance. Data privacy regulations depend on where your customers are and your volume of business. A Data Processing Agreement is a contract between a data controller (you, as the business owner) and a data processor (any third party that processes personal data on your behalf). It establishes the rights and obligations of each party regarding the processing of personal data. It helps ensure compliance with applicable data protection laws. It also discloses to your customers which companies are processing their data. Whether you need a DPA depends on several factors: Third-party services: If you use services like payment processors, cloud storage providers, email marketing platforms, or website hosting that access your customers' personal data, you likely need DPAs with these service providers. Applicable laws: While Texas doesn't have a comprehensive data privacy law like California's CCPA, it does have the new Texas Data Security and Privacy Act, which likely impacts you if your company earns 25%+ of its revenue from selling consumer data or hits other revenue thresholds. Laws in other states and in the EU also might apply. Industry standards: DPAs have become standard practice for demonstrating data protection compliance, regardless of strict legal requirements. Benefits of Implementing a DPA: Even if not strictly required by law in Texas, DPAs offer significant benefits: (1) clarify responsibilities between your business and service providers; (2) reduce legal liability through contractual protections; (3) increase customer trust by demonstrating a commitment to data protection; (4) preparation for evolving data protection laws; and (5) a potential competitive advantage over businesses without such protections. As data privacy regulations evolve, implementing DPAs now positions your business ahead of compliance requirements while building customer trust through demonstrated commitment to data protection. I use one in my practice. You should speak with an attorney who can provide a detailed DPA analysis based on your industry and customers.
Privacy
GDPR Compliance
Texas
Is my website required to comply with GDPR regulations?
I recently launched a small e-commerce website that sells products to customers in the European Union. While I am based in the United States, I have noticed that a significant portion of my customers are from EU countries. I have heard about the General Data Protection Regulation (GDPR) and its requirements for businesses handling personal data of EU citizens, but I'm not sure if my website needs to comply with these regulations. Can you clarify if my website falls under the scope of GDPR and what steps I need to take to ensure compliance?
Randy M.
Yes. If you sell to people in the European Union, the GDPR applies to you. It doesn’t matter where your business is based. Under Article 3, the law extends beyond Europe to cover any company that offers products or services to EU residents or tracks their behavior online. So if you accept orders from the EU, you're legally required to follow GDPR rules. The GDPR lays out key principles in Article 5. In simple terms: • You must have a lawful basis before collecting personal data (lawfulness). • Data must be collected and used fairly and transparently (fairness and transparency). • Only gather the minimum data necessary and for clear, legitimate purposes (purpose limitation and data minimisation). • Keep personal data accurate and update or correct it when needed (accuracy). • Don’t keep data longer than required for the stated purpose (storage limitation). • Protect data with appropriate technical and organizational safeguards (integrity and confidentiality). • Be able to show regulators that you comply with all of these rules (accountability). You also need to be able to prove you're doing all this if a regulator asks. When Are You Allowed to Use Customer Data? For things like shipping an order or taking payment, you’re covered by what's called the “contract” basis under Article 6(1)(b). You need info like names, addresses, and payment details to complete a sale. That’s allowed. For email marketing, things are stricter. Consent is usually required. That means a clear opt-in, like an unchecked box the customer has to actively click. Some EU countries allow limited “soft opt-in” for existing customers, but the rules vary by country. If you’re unsure, it’s safest to get clear consent before emailing EU customers with promotions. What Rights Do Customers Have Over Their Data? Articles 15–21 give EU customers a lot of control. They can: • Ask what data you have on them • Correct wrong info • Ask you to delete their data (in certain cases) • Tell you to stop using it • Opt out of marketing • Ask you to send their data to another company You need systems in place to respond to these requests quickly and efficiently. What About Cookies? The EU’s top court (in the Planet49 case) made it clear: you can’t assume consent for tracking cookies. That means: • No pre-checked boxes • No vague “we use cookies” banners • You must let users actively choose which types of cookies to allow • You need to record and prove that consent was given Your cookie banner should be easy to use and offer equal choices for accepting or rejecting cookies. How to Keep Customer Data Secure You’re expected to take technical and organizational steps to protect people’s personal data. That includes things like: • Using SSL/TLS encryption • Restricting access to databases • Having solid contracts with vendors who handle customer data If there’s a data breach, Article 33 says you must tell the relevant EU authority within 72 hours if the breach could put someone’s rights at risk. If it’s a serious risk to individuals, Article 34 says you also need to inform the affected customers. What If You Use Outside Vendors? If you work with third parties such as payment processors, email services, or cloud providers, you’re responsible for what they do with customer data. The GDPR requires you to sign Data Processing Agreements (DPAs) with them. These agreements must cover: • How they protect the data • Their legal obligations • How they’ll help you stay compliant You can’t skip this part. It’s not optional. Do You Need an EU Representative? If you regularly sell to EU customers, the answer is yes. Article 27 requires most non-EU businesses to appoint an official representative inside the EU. This rep acts as your point of contact for EU regulators and customers. You only get an exemption if: • You rarely process EU data • It’s low-risk • It doesn’t involve sensitive data But if you're actively targeting or shipping to EU customers, that exemption likely won’t apply. What Happens If You Don’t Comply? Regulators can fine you up to €20 million or 4% of your global annual revenue, whichever is higher. That said, small businesses aren’t usually hit with huge fines right away. Most EU regulators aim to help companies comply, especially if you’re clearly making an effort. But ignoring GDPR isn’t a good strategy. Being able to show you’ve taken real steps toward compliance is your best protection. Attorneys on Contracts Counsel are ready to help with GDPR compliance, including privacy policies, vendor contracts, and other legal obligations tailored to your business needs.
Quick, user friendly and one of the better ways I've come across to get ahold of lawyers willing to take new clients.
View Trustpilot ReviewHow It Works
Post Your Project
Get Free Bids to Compare
Hire Your Lawyer
Privacy lawyers by top cities
- Austin Privacy Lawyers
- Boston Privacy Lawyers
- Chicago Privacy Lawyers
- Dallas Privacy Lawyers
- Denver Privacy Lawyers
- Houston Privacy Lawyers
- Los Angeles Privacy Lawyers
- New York Privacy Lawyers
- Phoenix Privacy Lawyers
- San Diego Privacy Lawyers
- Tampa Privacy Lawyers
Privacy lawyers by nearby cities
- Bend Privacy Lawyers
- Gresham Privacy Lawyers
- Hillsboro Privacy Lawyers
- Portland Privacy Lawyers
- Salem Privacy Lawyers
Contracts Counsel was incredibly helpful and easy to use. I submitted a project for a lawyer's help within a day I had received over 6 proposals from qualified lawyers. I submitted a bid that works best for my business and we went forward with the project.
View Trustpilot Review
I never knew how difficult it was to obtain representation or a lawyer, and ContractsCounsel was EXACTLY the type of service I was hoping for when I was in a pinch. Working with their service was efficient, effective and made me feel in control. Thank you so much and should I ever need attorney services down the road, I'll certainly be a repeat customer.
View Trustpilot Review
I got 5 bids within 24h of posting my project. I choose the person who provided the most detailed and relevant intro letter, highlighting their experience relevant to my project. I am very satisfied with the outcome and quality of the two agreements that were produced, they actually far exceed my expectations.
View Trustpilot ReviewHow It Works
Post Your Project
Get Free Bids to Compare
Hire Your Lawyer