
John Martino leads our data privacy practice, representing businesses on compliance with the New Jersey Data Privacy Act and the privacy laws of other states where their customers live. He spent nearly two decades in the enterprise technology industry before concentrating his practice in data privacy.
We draft and update privacy policies, website and mobile application disclosures, cookie and tracking disclosures, and the internal data handling policies that need to line up with what the public-facing documents say. We also review privacy policies a business already has in place against what it actually does with data.
We advise businesses on responding to consumers who ask for a copy of their personal data, ask that it be corrected or deleted, or opt out of how it is used, including requests that arrive through browser-based opt-out signals. That work covers setting up an intake and response process and handling complaints that follow an unanswered request.
We represent businesses on data protection agreements and privacy addenda on both sides, on the privacy and security representations customers ask them to make, and on the security questionnaires and diligence requests that come with a large contract or an investment.
We review and negotiate the data provisions in software, hosting, marketing, analytics, and outsourced services agreements, including how customer data may be used, where it is stored, what happens when the contract ends, and who answers when something goes wrong.
We advise businesses that sell, share, or license personal data on New Jersey's data broker and data collector registration requirements, on whether those requirements reach them at all, and on the data licensing and sharing agreements that shape the answer.
We advise clients on HIPAA compliance questions and on how federal privacy laws covering health, financial, and children's data apply to their business alongside state requirements, including which set of rules governs a particular use of data.
We advise clients selling beyond New Jersey on which other state privacy laws reach them and on building a single set of practices that holds up across all of them rather than a separate approach for each.
When a data breach happens, we advise businesses on notification, on communications with affected individuals and business customers, and on the breach notice provisions in their own vendor and customer agreements. Breach matters that become adversarial or require enforcement defense are handled by attorneys at the firm or referred to counsel who concentrate in that work.
John Martino spent more than a decade working across database and data integration technology, including Oracle, SAP HANA, Vertica, Informatica, and Salesforce Data Cloud. He understands how these systems operate and how information moves between them, which matters in privacy work because the answer usually depends on where a business's data actually lives and where it goes.
If your business collects consumer data and you are not certain where you stand, contact Buchan & Cardamone to discuss your situation with a data privacy attorney.
Contact our office today to discuss your data privacy matter with an attorney.
Schedule a Consultation