• videocam Live Webinar with Live Q&A
  • calendar_month October 28, 2026 @ 1:00 PM ET/10:00 AM PT
  • signal_cellular_alt Intermediate
  • card_travel Cybersecurity and Data Privacy
  • schedule 90 minutes

Data Processing Agreements in the Age of AI: Negotiating, Drafting, Compliance Considerations, Risk Mitigation

About the Course

Introduction

This CLE webinar will outline key state, federal, and international frameworks to be considered when negotiating and drafting data protection agreements (DPAs). Core terms and provisions will be examined, including liability limitations, sub-processing restrictions, data security requirements, breach obligations, and more. Time will be spent assessing the impacts of AI on DPAs and ways to integrate AI protections into existing and new DPA agreements.

Description

Businesses—large and small—collect, store, and share data to operate. Examples include customer and sales data, billing information, HR records, and more. Third-party vendors, referred to as service providers, are essential to these business processes.

State privacy and consumer protection laws increasingly require contracts governing the collection, sharing, and processing of personal information. International frameworks, including the GDPR and China's PIPL, also require data protection provisions. As a result, DPAs have become vital components of many commercial agreements and require thoughtful negotiation and drafting.

DPAs define how controllers and processors share and use data, what safeguards apply, and who is responsible when safeguards fail. They may also protect proprietary or confidential business information. As AI becomes embedded in business operations, DPAs should address AI-related privacy and security risks, including IP ownership, discrimination indemnification, data use restrictions, and human oversight, in both existing and new agreements.

A well-drafted DPA should include confidentiality, security measures, breach obligations, subcontractor or sub-processor limits, audit rights, compliance with applicable privacy laws, and more. It should also match the actual business relationship. A vendor that stores data does not share the same risk profile as a vendor using customer information to train or operate an AI-powered tool. DPA negotiation and drafting should take all of this into account to avoid unnecessary friction points and major blind spots.

Listen as our authoritative panel addresses important DPA concepts and core terms to consider when negotiating and drafting data protection agreements. Using real-world experiences and examples, our panel will cover key provisions, how DPA obligations impact business operations of both data controllers and processors, and ways DPAs can address AI-related risks.

Presented By

David Curtis
Of Counsel
Orrick, Herrington & Sutcliffe LLP

Mr. Curtis provides AI, privacy, and security guidance to technology-led companies, from start-ups to multinationals. His practice focuses on negotiating data licenses and other commercial contracts, drafting privacy notices, and providing practical product counseling. With experience managing hundreds of strategic transactions each year, Mr. Curtis helps clients streamline compliance efforts and navigate complex regulatory and business challenges. His work spans a range of technology industries, including PropTech, HealthTech, and EdTech among others. He regularly advises clients on privacy policies, terms of service, and data processing agreements, with a particular focus on compliance with the California Consumer Privacy Act (CCPA) and other state privacy laws, state data broker laws, AI regulations, the Children’s Online Privacy Protection Act (COPPA), and cross-border data transfer requirements under the EU and UK General Data Protection Regulation (GDPR). David also counsels clients on AI-powered products, on digital advertising, Internet law, and consumer protection, helping clients anticipate and address evolving legal risks.

Jack L. Hobaugh Jr.
Shareholder
Brownstein Hyatt Farber Schreck LLP

Mr. Hobaugh combines his global software, database and network engineering experience with his legal practice to focus on artificial intelligence governance and law, cybersecurity law and privacy law. A certified iapp artificial intelligence governance professional (AIGP) and information privacy professional (FIP/CIPT/CIPP/US/E) plus ISC2 Certified Information System Security Professional (CISSP), he uses his extensive inhouse experience as a data protection officer, incident response counsel, and global privacy program compliance counsel to provide legal and cybersecurity guidance to his clients. Mr. Hobaugh’s work includes GDPR, EU AI ACT, HIPAA, GLBA, FERPA, COPPA, PIPEDA, FTC, and state compliance including data protection agreements, business associate agreements and data protection impact assessments. He specializes in guiding start up companies through the AI, privacy, and security compliance maze. A guest lecturer and author of four books on cybersecurity law, Mr. Hobaugh is sought out counsel for startups, and mergers and acquisitions. Prior to his legal career, Mr. Hobaugh was a software engineer with a focus on international IT consulting and telecom (Europe / Middle East / North West Africa / Brazil), writing his first artificial intelligence program in 1989. 

Melissa Krasnow
Partner
VLP Law Group, LLP

Ms. Krasnow advises companies on privacy, data security, technology matters, and cyber governance, including data breaches/incidents/other events (ransomware, account takeover, business email compromise, phishing, and vulnerabilities), preparing written information security programs (organizational and employee), devising incident response plans, and facilitating and participating in tabletop exercises. She counsels boards of directors and officers on privacy, data security, and technology risk oversight and developments, and reviews cyber liability insurance policies. Ms. Krasnow advises companies on regulatory inquiries and complying with state, federal, and international privacy and data security, advertising and marketing, governance and compliance, and regulated industry laws. She prepares website and mobile application privacy policies and terms (including regarding the GDPR, CPRA and other state privacy laws, geolocation, big data, and artificial intelligence/chatbots), and technology policies. Ms. Krasnow works with companies on negotiating (and renegotiating in the wake of data breaches/incidents/other events) and documenting technology and commercial transactions, including master services agreements, non-disclosure agreements, data security addenda, business associate agreements, data license agreements, GDPR and other data processing agreements, and CPRA and other state privacy law agreements.


Credit Information
  • This 90-minute webinar is eligible in most states for 1.5 CLE credits.


  • Live Online


    On Demand

Date + Time

  • event

    Wednesday, October 28, 2026

  • schedule

    1:00 PM ET/10:00 AM PT

I. Examining state privacy and consumer protection laws and DPA requirements

II. California's Consumer Privacy Law Act: Understanding the CPCPA/CPRA framework and incorporating it into DPAs

III. Key international frameworks: EU's GDPR Article 28, Canada's PIPEDA, China's PIPL, and more

IV. AI and state legislative efforts

V. Key DPA provisions and considerations

A. Scope of data processing and ancillary obligations

B. Confidentiality

C. Data location/transfers

D. Data deletion/return after termination

E. Security requirements and data breach obligations

F. Subcontractor limitations

G. Defining applicable laws and regulations

VI. Audit rights, audit provisions and implementation: Drafting considerations, audit readiness, documentation

VII. AI technology and how to account for AI-related risk in DPAs

VIII. Liability limits and indemnification considerations

The panel will discuss these and other key issues:

  • What risks arise when vendors process or use business data?
  • What laws and frameworks shape DPA negotiations and provisions?
  • Which key provisions should be included in DPAs?
  • What factors should be considered when negotiating DPAs?
  • How can controllers and processors limit risk and liability through indemnification provisions?
  • When and how can existing DPAs be updated to reflect AI-related risks?
  • What are best practices to draft audit provisions and improve outcomes?