- videocam Live Webinar with Live Q&A
- calendar_month October 28, 2026 @ 1:00 PM ET/10:00 AM PT
- signal_cellular_alt Intermediate
- card_travel Cybersecurity and Data Privacy
- schedule 90 minutes
Data Processing Agreements in the Age of AI: Negotiating, Drafting, Compliance Considerations, Risk Mitigation
Welcome to BARBRI, the trusted global leader in legal education. Continue to access the same expert-led Strafford CLE and CPE webinars you know and value. Plus, explore professional skills courses and more.
About the Course
Introduction
This CLE webinar will outline key state, federal, and international frameworks to be considered when negotiating and drafting data protection agreements (DPAs). Core terms and provisions will be examined, including liability limitations, sub-processing restrictions, data security requirements, breach obligations, and more. Time will be spent assessing the impacts of AI on DPAs and ways to integrate AI protections into existing and new DPA agreements.
Description
Businesses—large and small—collect, store, and share data to operate. Examples include customer and sales data, billing information, HR records, and more. Third-party vendors, referred to as service providers, are essential to these business processes.
State privacy and consumer protection laws increasingly require contracts governing the collection, sharing, and processing of personal information. International frameworks, including the GDPR and China's PIPL, also require data protection provisions. As a result, DPAs have become vital components of many commercial agreements and require thoughtful negotiation and drafting.
DPAs define how controllers and processors share and use data, what safeguards apply, and who is responsible when safeguards fail. They may also protect proprietary or confidential business information. As AI becomes embedded in business operations, DPAs should address AI-related privacy and security risks, including IP ownership, discrimination indemnification, data use restrictions, and human oversight, in both existing and new agreements.
A well-drafted DPA should include confidentiality, security measures, breach obligations, subcontractor or sub-processor limits, audit rights, compliance with applicable privacy laws, and more. It should also match the actual business relationship. A vendor that stores data does not share the same risk profile as a vendor using customer information to train or operate an AI-powered tool. DPA negotiation and drafting should take all of this into account to avoid unnecessary friction points and major blind spots.
Listen as our authoritative panel addresses important DPA concepts and core terms to consider when negotiating and drafting data protection agreements. Using real-world experiences and examples, our panel will cover key provisions, how DPA obligations impact business operations of both data controllers and processors, and ways DPAs can address AI-related risks.
Presented By
Mr. Curtis provides AI, privacy, and security guidance to technology-led companies, from start-ups to multinationals. His practice focuses on negotiating data licenses and other commercial contracts, drafting privacy notices, and providing practical product counseling. With experience managing hundreds of strategic transactions each year, Mr. Curtis helps clients streamline compliance efforts and navigate complex regulatory and business challenges. His work spans a range of technology industries, including PropTech, HealthTech, and EdTech among others. He regularly advises clients on privacy policies, terms of service, and data processing agreements, with a particular focus on compliance with the California Consumer Privacy Act (CCPA) and other state privacy laws, state data broker laws, AI regulations, the Children’s Online Privacy Protection Act (COPPA), and cross-border data transfer requirements under the EU and UK General Data Protection Regulation (GDPR). David also counsels clients on AI-powered products, on digital advertising, Internet law, and consumer protection, helping clients anticipate and address evolving legal risks.
Mr. Hobaugh combines his global software, database and network engineering experience with his legal practice to focus on artificial intelligence governance and law, cybersecurity law and privacy law. A certified iapp artificial intelligence governance professional (AIGP) and information privacy professional (FIP/CIPT/CIPP/US/E) plus ISC2 Certified Information System Security Professional (CISSP), he uses his extensive inhouse experience as a data protection officer, incident response counsel, and global privacy program compliance counsel to provide legal and cybersecurity guidance to his clients. Mr. Hobaugh’s work includes GDPR, EU AI ACT, HIPAA, GLBA, FERPA, COPPA, PIPEDA, FTC, and state compliance including data protection agreements, business associate agreements and data protection impact assessments. He specializes in guiding start up companies through the AI, privacy, and security compliance maze. A guest lecturer and author of four books on cybersecurity law, Mr. Hobaugh is sought out counsel for startups, and mergers and acquisitions. Prior to his legal career, Mr. Hobaugh was a software engineer with a focus on international IT consulting and telecom (Europe / Middle East / North West Africa / Brazil), writing his first artificial intelligence program in 1989.
Ms. Krasnow advises companies on privacy, data security, technology matters, and cyber governance, including data breaches/incidents/other events (ransomware, account takeover, business email compromise, phishing, and vulnerabilities), preparing written information security programs (organizational and employee), devising incident response plans, and facilitating and participating in tabletop exercises. She counsels boards of directors and officers on privacy, data security, and technology risk oversight and developments, and reviews cyber liability insurance policies. Ms. Krasnow advises companies on regulatory inquiries and complying with state, federal, and international privacy and data security, advertising and marketing, governance and compliance, and regulated industry laws. She prepares website and mobile application privacy policies and terms (including regarding the GDPR, CPRA and other state privacy laws, geolocation, big data, and artificial intelligence/chatbots), and technology policies. Ms. Krasnow works with companies on negotiating (and renegotiating in the wake of data breaches/incidents/other events) and documenting technology and commercial transactions, including master services agreements, non-disclosure agreements, data security addenda, business associate agreements, data license agreements, GDPR and other data processing agreements, and CPRA and other state privacy law agreements.
-
This 90-minute webinar is eligible in most states for 1.5 CLE credits.
-
Live Online
On Demand
Date + Time
- event
Wednesday, October 28, 2026
- schedule
1:00 PM ET/10:00 AM PT
I. Examining state privacy and consumer protection laws and DPA requirements
II. California's Consumer Privacy Law Act: Understanding the CPCPA/CPRA framework and incorporating it into DPAs
III. Key international frameworks: EU's GDPR Article 28, Canada's PIPEDA, China's PIPL, and more
IV. AI and state legislative efforts
V. Key DPA provisions and considerations
A. Scope of data processing and ancillary obligations
B. Confidentiality
C. Data location/transfers
D. Data deletion/return after termination
E. Security requirements and data breach obligations
F. Subcontractor limitations
G. Defining applicable laws and regulations
VI. Audit rights, audit provisions and implementation: Drafting considerations, audit readiness, documentation
VII. AI technology and how to account for AI-related risk in DPAs
VIII. Liability limits and indemnification considerations
The panel will discuss these and other key issues:
- What risks arise when vendors process or use business data?
- What laws and frameworks shape DPA negotiations and provisions?
- Which key provisions should be included in DPAs?
- What factors should be considered when negotiating DPAs?
- How can controllers and processors limit risk and liability through indemnification provisions?
- When and how can existing DPAs be updated to reflect AI-related risks?
- What are best practices to draft audit provisions and improve outcomes?
Unlimited access to premium CLE courses:
- Annual access
- Available live and on-demand
- Best for attorneys and legal professionals
Unlimited access to premium CPE courses.:
- Annual access
- Available live and on-demand
- Best for CPAs and tax professionals
Unlimited access to premium CLE, CPE, Professional Skills and Practice-Ready courses.:
- Annual access
- Available live and on-demand
- Best for legal, accounting, and tax professionals
Unlimited access to Professional Skills and Practice-Ready courses:
- Annual access
- Available on-demand
- Best for new attorneys
Related Courses
Data Processing Agreements in the Age of AI: Negotiating, Drafting, Compliance Considerations, Risk Mitigation
Wednesday, October 28, 2026
1:00 PM ET/10:00 AM PT
Data Inventories: A Critical Component for Privacy, Cybersecurity, and AI Governance
Wednesday, September 30, 2026
1:00 PM ET/10:00 AM PT
EU Data Laws: How European Laws Affect U.S. Domestic Business Data Governance
Wednesday, September 23, 2026
1:00 PM ET/10 AM PT
Recommended Resources
Explore the Advantages of Consistent Legal Language
- Learning & Development
- Business & Professional Skills
- Talent Development
The Power of Project Management: Using the 80/20 Rule in E-Discovery
- Legal Technology
- E-Discovery