Retail

Group

 

The Hintze Retail Group provides strategic counseling and solutions to retail sector clients.  We advise on the unique privacy, security, and AI challenges and opportunities for e-commerce, brick and mortar, and omnichannel retailers.  We regularly advise both on legal compliance and strategic privacy, security, and AI objectives focused on growing customer trust and engagement.   

The topics and matters we handle include: 

Privacy Programs and Operations. We help retail clients establish, right-size, and optimize privacy programs and operations to address compliance and enable customer trust and engagement.  We advise on risk-focused pragmatic solutions where resources are constrained.   

Data Subject Rights.  We work to establish and optimize data subject rights processes for retailers to efficiently manage customer and prospect requests in line with applicable law and business objectives. 

Privacy Assessments.  We help retail clients to assess new technologies, practices, and processing of personal data through privacy assessments.  We also help retail clients establish, right-size, and optimize repeatable privacy assessment processes to address objectives in line with available resources. 

Marketing.  We help retail clients develop marketing programs in-line with applicable marketing privacy requirements, including for telemarketing, texting, on-device, email, and other direct marketing channels.  We also assist in designing compliance programs to capture and manage opt-in and opt-out consents required for direct marketing efforts, including for refer-a-friend programs and based on TCPA and CAN-SPAM requirements.  

Loyalty Programs.  We help retail clients establish and manage loyalty programs, including in line with state law requirements like in the CCPA that regulate financial incentives and individual data subject rights.   

AdTech and Targeted Advertising.  We help retail clients enable use of adtech capabilities to effectively reach customers and prospects through targeted advertising.  We advise on strategic and practical solutions to facilitate tracking and targeting customers and prospects while addressing privacy laws and objectives as well as industry codes and standards. We also work to establish and mature tracking technology governance strategies for retailer websites and mobile apps to address emerging risks under wiretap laws like CIPA, and obligations under state comprehensive privacy laws. 

Partnerships.  We help retail clients identify and address personal data-related objectives and opportunities in business partnerships, such as in affinity and private label card programs, gift card programs, joint marketing relationships, social media influencers, and brand relationships. 

Vendors and Supply Chain.  We advise on vendor risk management programs, assist with RFPs and vendor evaluations, and review and negotiate contracts with retail client vendors to address privacy, data security, and AI risks and requirements. 

Regulatory Defense.  We assist retail clients in engaging with and responding to regulatory inquiries and investigations about privacy and data practices.  We also assist with managing compliance with regulatory consent decrees and settlement agreements.   

Regulatory and Public Policy.  We help retail clients and retail associations understand and influence legislative and regulatory policy and proposals, including crafting input on developing privacy, data security, and AI laws and regulations.  

Location Data Tracking.  We help retail clients when collecting or using location data of e-commerce or app users, and in store. 

Facial Recognition and Biometric Data.  We help retail clients when collecting or using facial recognition or other biometric data, including with their workforce, customers, and in loss prevention efforts. 

Privacy Notices and Transparency.  We help retail clients set strategies for transparency about privacy practices, including in external communications, trust centers, and privacy notices.  

Data Security and Breaches.  We assist retail clients in responding to data breaches, including by acting as breach coach to help manage the various workstreams and considerations, and as counsel.  We also help retail clients with strategies to minimize the risks involved with data breach, prepare response capabilities and plans, and to set up and right-size privacy incident classification and review protocols. 

Employee Privacy. We help retailers to address employee privacy requirements, including when tracking/monitoring employees, addressing data subject rights, gathering biometric data, or using AI applications.  

Privacy, Security, and AI Policies. We develop privacy, security, and AI policies and resources for retail clients.   


 

Key Contacts

Sam Castic

Partner - Chair