Developing, implementing, and maintaining privacy policies and data security practices that protect sensitive business and customer information from unauthorized use and disclosure is imperative for organizations of all sizes and across all industries. Whether it’s personally identifiable customer information, patient information, trade secrets, intellectual property, or other confidential information, the data must be managed in compliance with rapidly evolving laws and regulations and consistent with best practices. In today’s complex legal and regulatory landscape, businesses need an experienced, reliable, and responsive legal team.

        Verrill’s team of Privacy and Data Security attorneys have extensive experience across various industries, practice areas, and jurisdictions. Our attorneys stay updated with the latest state, federal, and international privacy laws and regulations for collecting personal/sensitive data. We offer counsel on data privacy and cybersecurity concerns, data security breaches, mergers and acquisitions, joint ventures, consumer protection, marketing programs, compliance and regulatory issues, information management, and information sharing. We help clients understand and implement necessary safeguards and comply with applicable notification and other legal requirements.

        We have experience with a wide range of state, federal, and international laws and industry best practices, including:

        • Healthcare: HIPAA, HITECH
        • Education: FERPA
        • Finance: GLBA, FACTA, FCRA
        • Marketing and Communications: TCPA, TSR, FTC, and CAN-SPAM
        • International: EU GDPR, UK GDPR, PIPEDA
        • Technology: COPPA, CFAA, Stored Communications Act
        • State Data Privacy and Information Security laws

        Verrill takes a collaborative and proactive approach to helping its clients comply with regulations. We carefully analyze and pinpoint areas that require immediate attention and improvement and work with our clients to implement effective measures to address and rectify them. If any challenges arise, Verrill is always ready to support clients in conducting a timely, thorough, and effective response.

        The following are the services we provide related to data governance and privacy:

        • Providing counsel on compliance with evolving data privacy laws and regulations, helping clients navigate complex legal requirements and adapt their practices accordingly.
        • Establishing and maintaining privacy and data security programs tailored to the client’s specific needs, ensuring ongoing adherence to best practices and regulatory requirements.
        • Conducting comprehensive risk assessments to evaluate data governance practices, including conducting privacy impact assessments to identify potential risks to data privacy.
        • Formulating and implementing administrative safeguards, encompassing the creation of robust policies, procedures, and contractual agreements to ensure compliance with privacy regulations and standards.
        • Delivering targeted awareness training sessions to educate employees and stakeholders on the importance of data privacy and security measures.
        • Advocating for clients in both defensive and prosecutorial capacities regarding privacy and data security claims, ensuring their interests are protected.
        • Responding promptly and effectively to regulatory inquiries and criminal investigations related to data privacy, ensuring compliance with legal obligations.
        • Overseeing incident readiness and response procedures, including counseling with respect to data breach reporting and notifications under state and federal law, including drafting and coordinating individual and agency notifications.
        • Drafting data use and sharing agreements, customized policies and procedures, training materials, and business associate agreements.
        • Developing robust business continuity and disaster recovery plans to mitigate the impact of data breaches or other unforeseen events on the client’s operations.
        • Negotiating cyber insurance coverage tailored to the client’s specific risk profile and pursuing claims in the event of data breaches or cyber incidents.
        • Resolving transactional disputes related to data governance and privacy matters through negotiation or other legal means, protecting the client’s interests.
        People
        
 Keefe B. Clemons
        (617) 357 3717
        
 Patrick D. Duplessis
        (203) 222 3116
        
 Michael K. Fee
        (617) 292 2866
        
 Andrew Ferrer
        (617) 357 3733
        
 Robert L. Hover
        (617) 292 2871
        
 Rebecca Lessard
        (207) 253 4424
        
 Adam Nyhan

        Adam Nyhan

        Partner
        (207) 253 4416
        
 Abby Plummer

        Abby Plummer

        Associate
        (207) 253 4486
        
 Derek Rocha
        (857) 383 2644
        
 Jeffrey D. Russell
        (207) 253 4626
        
 William H. Stiles
        (207) 253 4966
        
 John W. Van Lonkhuyzen
        (207) 253 4624
        Events
        When: June 5, 2026 at 8:00am - 4:30pm This Month
        Location: University of Maine School of Law
        People: Keefe B. Clemons
        When: April 8, 2026 at 1:00pm - 2:00pm
        Location: Webinar
        People: Keefe B. Clemons
        When: October 20-23, 2025
        Location: Portland, Maine
        People: Keefe B. Clemons
        When: June 6, 2025 at 8:45am – 4:45pm (EDT)
        Location: University of Maine School of Law
        People: Keefe B. Clemons

        Firm Highlights

        Media Mentions

        Verrill Recognized by WMTW for Partnership Supporting Hunger Relief in Maine

        Verrill was recently featured in coverage by WMTW News 8 for its role in a collaborative effort to combat food insecurity across southern...
        Press Releases

        33 Verrill Attorneys, Across Four Offices, Recognized in the 2026 Chambers USA Guide

        BOSTON, Massachusetts, PORTLAND, Maine, WESTPORT, Connecticut, and WASHINGTON, D.C. – Verrill has been recognized as a Leading Firm in 14...
        Blog

        Will the Knicks Beat the Spurs? (Are Prediction Market Event Contracts Gambling?)

        For those of you who like to keep score, currently 18 states are engaged in litigation over prediction markets, such as Kalshi and Polymarket,...
        Alerts and Newsletters

        DOJ Announces Faster Review and Enhanced Enforcement for Benefits-Fraud FCA Matters

        On May 27, 2026, the U.S. Department of Justice (DOJ) Civil Division issued a new memorandum, “Accelerating Review and Enhancing Enforcement in...
        Alerts and Newsletters

        DOJ Announces Minnesota Health Care Fraud Takedown; Signals Intensified Medicaid Enforcement Nationwide

        On May 21, the Department of Justice (“DOJ”) announced a first-of-its kind Minnesota Health Care Fraud Takedown charging 15 defendants, including...
        Media Mentions

        Lauren Galvin Quoted in Massachusetts Lawyers Weekly on Arbitration and Anti-SLAPP Protections

        Verrill Partner Lauren Galvin was recently featured in a Massachusetts Lawyers Weekly article highlighting a notable Superior Court decision...
        Blog

        Section 530A Accounts: What Employers Should Consider Before Offering Contributions to “Trump” Accounts

        Section 530A accounts, commonly referred to as Trump accounts, have attracted attention since the enactment of the One Big Beautiful Bill Act in...
        Blog

        Navigating PBM Reform: Regulatory Changes, Market Shifts, and Practical Guidance for ERISA Fiduciaries

        Pharmacy Benefit Manager (“PBM”) arrangements have long relied on rebates with limited transparency into true drug costs. Recent regulatory and...
        Blog

        DOL’s Proposed Regulation on Selecting Alternative Investments: Broad Implications for 401(k) and 403(b) Plan Fiduciaries

        On March 30, 2026, the Department of Labor issued a proposed regulation purporting to implement an executive order to expand access to “alternative...
        Press Releases

        Verrill Welcomes Private Clients & Fiduciary Services Attorney Gracie Castle

        BOSTON, Massachusetts – Verrill is pleased to welcome Gracie Castle to the firm’s Private Clients & Fiduciary Services Group as an Associate,...
        Published Works

        Francesco De Vito Authors Article in the Journal of the American College of Mortgage Attorneys

        Verrill Partner Frank De Vito authored an article featured in the Spring 2026 issue of The Abstract, the journal of the American College of Mortgage...
        Alerts and Newsletters

        Recent FinCEN Advisory Highlights Rising Health Care Fraud Risk for Financial Institutions

        As the federal government intensifies its “whole of government” approach to combat fraud, waste, and abuse, particularly in Federal Health Care...