Blog › ICP guides

Privacy attorney on retainer: GDPR compliance, CCPA advisory, and data privacy counsel on monthly retainer

August 6, 2026 · ~22 min read

A mid-size SaaS company with 280 employees and approximately 1.4 million registered users in the European Union and United Kingdom receives a letter from the Irish Data Protection Commission (DPC) notifying the company that it has received a complaint from a data subject alleging that the company’s behavioral advertising practices — specifically the company’s use of third-party tracking cookies and cross-context behavioral advertising — violate Articles 5, 6, 7, and 13 of the General Data Protection Regulation. The DPC’s letter requests that the company submit a written response within 30 days explaining the legal basis on which the company processes the complainant’s personal data for behavioral advertising purposes and providing a copy of the company’s privacy notice, cookie consent records, and records of processing activities under Article 30 for the advertising processing activity.

The company’s retained privacy attorney, a CIPP/E-certified J.D. specializing in EU data protection law and CCPA compliance, advises that the DPC inquiry requires a multi-track response: a written submission to the DPC within the 30-day window addressing the Article 6 legal basis for behavioral advertising processing, producing Article 30 ROPA records, and submitting consent records demonstrating that the company’s consent management platform (CMP) captured the complainant’s consent; a concurrent review of the company’s Article 13 privacy notice to confirm that it discloses all required information about behavioral advertising processing, including the third-party recipients of personal data, the retention period for advertising profiles, and the data subject’s right to withdraw consent; and a prospective review of the company’s consent mechanism to evaluate whether the CMP’s pre-ticked boxes for behavioral advertising cookies satisfy the Article 4(11) unambiguous indication of agreement requirement or whether the DPC is likely to find that the consent mechanism is noncompliant following the CJEU’s ruling in Planet49 GmbH C-673/17 (2019).

Privacy attorneys and data privacy counsel on monthly retainer — J.D.s specializing in GDPR compliance, CCPA and state privacy law, and data breach response — do a substantial share of their highest-value advisory work between supervisory authority enforcement actions, FTC investigations, and breach notification events. This guide covers GDPR compliance advisory and CCPA and multi-state privacy law advisory: the legal frameworks behind each service area, the applicable regulations and enforcement precedents that govern the advisory, and how to structure a retainer agreement that makes the ongoing privacy advisory work visible between regulatory enforcement milestones.

GDPR compliance advisory

GDPR compliance advisory is the retainer function that manages the controller’s obligations under Regulation (EU) 2016/679 across the full lifecycle of personal data processing: from the initial legal basis analysis for each processing activity through the maintenance of Article 30 records of processing activities, the preparation of Article 35 Data Protection Impact Assessments for high-risk processing, the implementation of Article 46 cross-border transfer mechanisms for transfers to third countries, and the management of Article 83 administrative fine exposure. The retained privacy attorney monitors regulatory enforcement developments from EU supervisory authorities (the EDPB, DPC, ICO, CNIL, BfDI, Garante, and AEPD), advises on the privacy implications of new product features and data processing initiatives, and coordinates the company’s response to supervisory authority inquiries and data subject rights requests.

GDPR Article 6 legal basis analysis and legitimate interests assessment

The GDPR’s Article 6 legal basis requirement mandates that every processing activity involving personal data of EU or UK data subjects be grounded in one of six lawful bases: consent under Article 6(1)(a); performance of a contract to which the data subject is party under Article 6(1)(b); compliance with a legal obligation to which the controller is subject under Article 6(1)(c); protection of vital interests under Article 6(1)(d); performance of a task in the public interest under Article 6(1)(e); or the controller’s legitimate interests, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject under Article 6(1)(f). The legal basis must be identified and documented for each processing activity before the processing begins, and the controller cannot retroactively change the legal basis for processing once notified of a data subject rights request or supervisory authority inquiry.

Legal basis analysis for each processing activity requires the retained privacy attorney to evaluate which Article 6 lawful basis applies to each category of personal data processing in the controller’s product, operations, and marketing functions. For processing activities relying on consent under Article 6(1)(a), the attorney evaluates whether the consent mechanism satisfies the GDPR’s requirements for freely given, specific, informed, and unambiguous indication of agreement under Article 4(11) and whether the consent request is clearly distinguishable from other matters in plain, intelligible language under Article 7(2). For processing activities relying on legitimate interests under Article 6(1)(f), the attorney conducts a three-part Legitimate Interests Assessment (LIA): (1) the purpose test (whether the controller has a genuine legitimate interest in the processing, not merely a commercial preference); (2) the necessity test (whether the processing is strictly necessary to achieve the legitimate interest, and whether a less intrusive alternative would achieve the same purpose); and (3) the balancing test (whether the data subjects’ interests, rights, and freedoms override the controller’s legitimate interest, taking into account the nature of the personal data, the data subjects’ reasonable expectations based on their relationship with the controller, and the likely impact of the processing on data subjects). The EDPB’s Opinion 06/2014 on legitimate interests provides the framework for the balancing test; supervisory authority enforcement decisions from the DPC (WhatsApp IE: 2021 decision), CNIL (Google LLC: 2019 decision), and the EDPB (Binding Decision 01/2021) guide the attorney’s assessment of likely supervisory authority scrutiny.

Records of Processing Activities (ROPA) under Article 30 require the controller to maintain a written record of all processing activities for which the controller is responsible, covering: the name and contact details of the controller (and DPO where appointed); the purposes of processing; a description of the categories of data subjects and categories of personal data; the categories of recipients to whom personal data have been or will be disclosed; transfers to third countries or international organizations and the Article 46 transfer mechanism; the envisaged time limits for erasure of the different categories of data; and a general description of the technical and organizational security measures under Article 32. The retained privacy attorney builds and maintains the controller’s ROPA as a living document that is updated when new processing activities are initiated, when existing processing activities are modified (new data categories, new recipient categories, new retention periods), and when the controller receives data subject rights requests that reveal gaps in the ROPA documentation. A well-maintained ROPA is the foundation of both supervisory authority audit response and the controller’s ability to respond to Article 15 data subject access requests with a complete and accurate account of all processing of the data subject’s personal data.

Article 35 Data Protection Impact Assessments for high-risk processing

Article 35 GDPR requires controllers to carry out a Data Protection Impact Assessment (DPIA) prior to processing where a type of processing, in particular using new technologies, is likely to result in a high risk to the rights and freedoms of natural persons. Article 35(3) specifies three categories of processing that require a DPIA without exception: systematic and extensive evaluation of personal aspects relating to natural persons based on automated processing (including profiling) on which decisions producing legal or similarly significant effects are based; processing on a large scale of special categories of data or data relating to criminal convictions and offences; and systematic monitoring of a publicly accessible area on a large scale. In addition, each EU supervisory authority publishes a list of processing activities requiring a DPIA under Article 35(4); the EDPB’s harmonized approach provides a list of nine criteria (evaluation or scoring, automated decision-making with legal effects, systematic monitoring, sensitive data, data processed on a large scale, matched or combined datasets, data concerning vulnerable data subjects, innovative use or application of new technological or organizational solutions, and transfer of data outside the EU with insufficient protection) and generally requires a DPIA if two or more criteria apply.

DPIA preparation by the retained privacy attorney involves a structured analysis covering: a systematic description of the envisaged processing operations and the purposes of processing; an assessment of the necessity and proportionality of the processing in relation to the purposes; an assessment of the risks to the rights and freedoms of data subjects (identifying the specific risks and their likelihood and severity); and the measures envisaged to address those risks, including safeguards, security measures, and mechanisms to ensure protection of personal data and compliance with the GDPR (demonstrating that the residual risk after mitigation is acceptable). For processing activities that present a high residual risk after mitigation, Article 36 requires the controller to consult with the supervisory authority prior to processing; the retained attorney advises on whether the DPIA’s residual risk assessment triggers the Article 36 prior consultation obligation and manages the prior consultation process with the relevant supervisory authority if required. The EDPB’s Guidelines 09/2022 on Data Protection Impact Assessments and the supervisory authorities’ published DPIA templates (ICO DPIA template, CNIL PIA tool) guide the DPIA structure.

Article 46 Standard Contractual Clauses and cross-border transfer impact assessments

Transfers of personal data to third countries outside the European Economic Area (EEA) are permitted only where the European Commission has adopted an adequacy decision for the recipient country under Article 45, or where the controller or processor has provided appropriate safeguards under Article 46 and data subjects have enforceable rights and effective legal remedies. The primary Article 46 safeguard for commercial cross-border data transfers is the European Commission’s Standard Contractual Clauses (SCCs), adopted in Commission Implementing Decision (EU) 2021/914 of 4 June 2021, which replaced the prior SCCs with modular clauses covering the four principal transfer configurations: controller-to-controller (Module 1), controller-to-processor (Module 2), processor-to-controller (Module 3), and processor-to-processor (Module 4).

Transfer Impact Assessments (TIAs) are required following the CJEU’s judgment in Data Protection Commissioner v. Facebook Ireland Limited and Maximillian Schrems (Schrems II) C-311/18 (2020), which invalidated the EU-US Privacy Shield and confirmed that SCCs alone are insufficient if the law and practices of the third country of destination do not ensure adequate protection for the personal data transferred. The retained privacy attorney conducting a TIA evaluates: the legal framework of the third country of destination governing surveillance, access, and disclosure obligations applicable to the data importer; the practical application of that legal framework (enforcement track record, intelligence agency surveillance programs, access requests received by technology companies); the specific categories of personal data being transferred and whether those categories attract surveillance interest (financial data, health data, communications content, location data); and whether supplementary technical or contractual measures (end-to-end encryption with key management by the data exporter, pseudonymization, contractual commitments by the data importer to notify the data exporter of government access requests) effectively neutralize the identified risks. The EDPB’s Recommendations 01/2020 on Supplementary Measures and the EC’s adequacy decision for the EU-US Data Privacy Framework under Commission Implementing Decision (EU) 2023/1795 guide the TIA analysis for transfers to the United States.

Data Processing Agreements (DPAs) under Article 28 are required for every engagement with a processor — a natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller under Article 4(8). Article 28(3) specifies eight mandatory elements that must appear in every controller-processor DPA: processing only on the controller’s documented instructions; confidentiality obligations; implementation of Article 32 security measures; sub-processing restrictions; assistance to the controller in responding to data subject rights requests; assistance to the controller in meeting Article 32-36 obligations (security, DPIA, breach notification, prior consultation); deletion or return of data at termination; and cooperation with supervisory authority audits. The retained privacy attorney reviews vendor DPAs to ensure Article 28(3) compliance, negotiates Article 28 provisions favorable to the controller’s compliance obligations (broader audit rights, stronger sub-processor notification timelines, more specific security measure specifications), and identifies processors whose sub-processing arrangements involve transfers to third countries that require supplementary TIA analysis.

CCPA, CPRA, and multi-state privacy law compliance advisory

CCPA and multi-state privacy law compliance advisory is the retainer function that manages the controller’s obligations under the California Consumer Privacy Act (Cal. Civ. Code §§1798.100-1798.199 as amended by the California Privacy Rights Act), the regulations adopted by the California Privacy Protection Agency (CPPA), and the growing body of state comprehensive privacy laws enacted in Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Texas (TDPSA), Florida (FDBR), and other states. Unlike the GDPR’s broadly applicable framework, U.S. state privacy laws apply based on threshold criteria tied to the number of consumers whose data is processed and, in some states, the percentage of annual revenue derived from the sale of personal information.

CCPA/CPRA consumer rights implementation and Global Privacy Control compliance

The CCPA as amended by CPRA grants California consumers six primary rights: (1) the right to know what personal information is collected, used, shared, or sold under Cal. Civ. Code §1798.110-1798.115; (2) the right to delete personal information collected from the consumer under §1798.105, subject to specified exceptions including completion of transactions, security incident detection, legal compliance, and internal uses reasonably aligned with consumer expectations; (3) the right to opt out of the sale or sharing of personal information under §1798.120 and the CPRA’s extension to “sharing” (defined to include cross-context behavioral advertising regardless of monetary consideration); (4) the right to limit the use and disclosure of sensitive personal information under §1798.121 (covering Social Security numbers, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, contents of mail/email/text messages, genetic data, biometric information, health information, and sex life or sexual orientation); (5) the right to correct inaccurate personal information under §1798.106; and (6) the right to data portability (receiving a copy of personal information in a portable, technically feasible format) under §1798.110.

Global Privacy Control (GPC) compliance requires that the business treat a consumer’s GPC signal as an opt-out of sale or sharing under CPPA Regulations Section 7025(c), effective for all sales or sharing of the consumer’s personal information once the GPC signal is detected. The retained privacy attorney advising on GPC compliance reviews the company’s website and mobile application to confirm that the GPC signal is being detected and honored, that the opt-out is applied retroactively to the consumer’s prior personal information as well as prospectively, and that the opt-out is applied across all processing systems that involve the sale or sharing of personal information (advertising platforms, data broker relationships, analytics vendors). The CPPA has initiated enforcement actions against companies that fail to honor GPC signals; the CPPA’s enforcement guidance confirms that detecting and honoring the GPC signal is not optional for businesses subject to the CCPA.

Service provider and contractor agreement requirements under the CCPA require that personal information shared with a service provider (an entity that processes personal data on behalf of the business under a contract that prohibits retaining, using, or disclosing the personal information for any purpose other than performing the services specified in the contract) or a contractor (an entity to whom the business makes available personal information for a business purpose under a written contract that prohibits the contractor from selling or sharing the personal information, retaining, using, or disclosing the personal information for any purpose other than the business purpose specified in the contract, and prohibits the contractor from combining the personal information with other personal data collected independently) be governed by a qualifying written contract. The retained privacy attorney reviews the business’s vendor agreements to identify vendors that receive personal information without a qualifying CCPA service provider or contractor contract, negotiates contract provisions that satisfy the CCPA requirements, and advises on the reclassification of vendors that do not agree to qualifying restrictions (which may mean that personal information shared with such vendors must be disclosed as a “sale” or “sharing” in the privacy policy and must be subject to the opt-out right).

Multi-state privacy law threshold analysis and compliance

The Virginia Consumer Data Protection Act (VCDPA, Va. Code §§59.1-575 to 59.1-585), Colorado Privacy Act (CPA, C.R.S. §§6-1-1301 to 6-1-1313), Connecticut Data Privacy Act (CTDPA, Conn. Gen. Stat. §§42-515 to 42-525), Texas Data Privacy and Security Act (TDPSA, Tex. Bus. & Com. Code §§541.001-541.203), and Florida Digital Bill of Rights (FDBR, Fla. Stat. §§501.701-501.721) each impose controller obligations similar to the CCPA — data protection assessments, consumer rights (access, deletion, correction, portability, opt-out of targeted advertising and sale), controller-processor agreements, universal opt-out mechanism recognition — but with distinct threshold criteria, definition differences (notably the VCDPA, CPA, CTDPA, TDPSA, and FDBR use “targeted advertising” rather than “sharing” for cross-context behavioral advertising opt-out), and enforcement mechanisms (primarily attorney general enforcement with no private right of action, except for CCPA’s limited private right of action for data breaches under §1798.150).

Threshold analysis for each state privacy law requires the retained privacy attorney to evaluate whether the company’s data processing volume and revenue satisfy the law’s applicability threshold: the VCDPA applies to controllers that process personal data of at least 100,000 Virginia consumers annually, or 25,000 Virginia consumers annually if the controller derives over 50% of gross revenue from the sale of personal data; the Colorado CPA applies to controllers that process personal data of at least 100,000 Colorado consumers annually, or 25,000 Colorado consumers annually if the controller derives revenue from the sale of personal data; the CTDPA applies to controllers that process personal data of at least 100,000 Connecticut consumers annually, or 25,000 Connecticut consumers annually if the controller derives over 25% of gross revenue from the sale of personal data; the TDPSA applies to persons doing business in Texas that process personal data of Texas residents and meet the CCPA-like threshold criteria; and the FDBR applies to controllers with annual global revenue exceeding $1 billion that derive at least 50% of global revenue from the sale of online advertising or operate a consumer smart speaker and associated service, or have an app store or digital game distribution platform with at least 250,000 consumer devices. The retained attorney builds a multi-state applicability matrix for the company that tracks which state laws currently apply based on consumer data processing volumes by state, projects when additional state laws will become applicable as the company’s user base grows, and prioritizes compliance investments accordingly.

Data protection assessments required by the VCDPA (§59.1-582), CPA (C.R.S. §6-1-1309), CTDPA (§42-521), and TDPSA (§541.105) for processing activities that present a heightened risk of harm to consumers (targeted advertising, sale of personal data, profiling with legal or similarly significant effects, processing of sensitive data) are analogous to GDPR DPIAs. The retained attorney conducting a multi-state data protection assessment adapts the DPIA structure to satisfy both the GDPR Article 35 requirements and the applicable state law assessment requirements in a single document, reducing duplicative assessment effort while ensuring that the controller’s assessment documentation satisfies the requirements of each applicable jurisdiction.

Incident response advisory and multi-state breach notification compliance

Data breach incident response advisory is the privacy retainer function that activates when the controller discovers a security incident that may constitute a notifiable breach under applicable law. The retained privacy attorney manages the legal analysis and notification obligations across the multiple overlapping legal frameworks that may apply to a single data breach affecting U.S. and EU residents.

GDPR breach notification analysis under Article 33 requires the controller to notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, no later than 72 hours after becoming aware of it, where the breach is likely to result in a risk to the rights and freedoms of natural persons. Article 34 requires the controller to communicate the breach to the affected data subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms. The retained privacy attorney advising on GDPR breach notification assesses: whether the security incident constitutes a “personal data breach” within the Article 4(12) definition (a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed); whether the breach is likely to result in a risk (Article 33 notification trigger) or a high risk (Article 34 communication trigger) to the rights and freedoms of natural persons, applying the WP29/EDPB Guidelines 01/2021 on Examples Regarding Personal Data Breach Notification risk assessment factors (type of breach, nature of personal data, number of data subjects affected, ease of identification, special circumstances of the data subjects, and special characteristics of the controller); the 72-hour Article 33 notification timeline and whether a preliminary notification with supplemental information is appropriate given the incomplete breach investigation; and whether Article 3 of the GDPR makes the breach subject to multiple supervisory authorities’ jurisdiction (lead supervisory authority for cross-border processing versus local supervisory authorities with connections to affected data subjects).

Multi-state breach notification compliance in the United States requires the retained privacy attorney to evaluate all applicable state breach notification statutes — which now exist in all 50 states, the District of Columbia, Guam, Puerto Rico, and the U.S. Virgin Islands — to determine: which states’ laws apply based on the residency of affected individuals; what categories of personal information trigger notification obligations under each state’s statute (most states use Social Security numbers, driver’s license numbers, financial account numbers, and certain health information as triggers; California, New York, and Texas statutes are broader than most); what form of notification (written, electronic, or substitute notice) is required and permissible under each state’s statute; what the notification content requirements are (some states require specific language, specific breach description elements, or specific credit monitoring offers); what the notification timeline requirements are (California requires “expedient” notification; New York’s SHIELD Act requires “expedient” notification without unreasonable delay; Florida requires 30 days; Ohio requires 45 days); and whether any state’s attorney general requires advance notification before individual notices are sent. The retained privacy attorney also evaluates federal notification obligations (HHS breach notification under HIPAA 45 CFR Part 164 Subpart D for healthcare entities; FTC notification under the FTC Health Breach Notification Rule 16 CFR Part 318 for vendors of personal health records; federal financial regulator notification for banking organizations under the FDIC, OCC, and Federal Reserve interagency computer-security incident notification rule).

Tracking privacy attorney retainer hours with a shared dashboard

Privacy attorneys and data privacy counsel on monthly retainer perform the advisory work between supervisory authority enforcement actions, FTC investigations, and breach notification events that determines the controller’s legal basis for each processing activity, maintains Article 30 ROPA documentation, ensures DPIAs are completed for high-risk processing, and positions the controller for supervisory authority audit response. That advisory work (GDPR legal basis analysis, ROPA maintenance, Article 28 DPA reviews, TIA preparation, CCPA consumer rights implementation, multi-state threshold analysis, incident response planning) generates no visible supervisory authority correspondence or enforcement output for the client’s privacy team or GC until a specific regulatory enforcement event or data breach is triggered.

A retainer dashboard that gives the client’s privacy team and general counsel real-time visibility into the privacy attorney’s time allocation — which compliance matters consumed the month’s hours, which ROPA updates were completed, which vendor DPAs were reviewed and negotiated, which DPIA was prepared for the new product feature — transforms the retainer from an opaque monthly fee into a documented privacy compliance record. The work log accompanying each entry (privacy matter, applicable GDPR Article or CCPA section, legal analysis outcome, hours spent) provides the client’s privacy team with a running account of the advisory activity that explains the retainer fee in terms of specific regulatory compliance outcomes and enforcement risk mitigation.

HourTab provides a public, no-login retainer dashboard URL that the privacy attorney sends to the client once and the client’s privacy team or general counsel bookmarks. The dashboard shows the current retainer burn-down (hours used vs. hours remaining in the cycle), a chronological work log of entries from the privacy attorney, and the reset date for the next billing cycle — eliminating the monthly “how many hours do I have left?” inquiry and giving the privacy team a self-serve view of the compliance advisory utilization between the attorney’s monthly billing statements.

Frequently asked questions

What does a privacy attorney on retainer typically do?

A privacy attorney on monthly retainer provides ongoing advisory across GDPR compliance (Article 6 legal basis analysis and Legitimate Interests Assessments, Article 30 Records of Processing Activities maintenance, Article 35 DPIA preparation for high-risk processing, Article 28 controller-processor DPA review, Article 46 SCC selection and Transfer Impact Assessments for cross-border transfers, DPO appointment advisory, and supervisory authority inquiry and enforcement response) and CCPA/CPRA and multi-state privacy law compliance (consumer rights implementation including opt-out of sale or sharing and sensitive PI use limitation, GPC compliance, service provider and contractor agreement review, multi-state threshold analysis and data protection assessments, and multi-state breach notification compliance). The retained attorney also advises on privacy-by-design product development review, incident response planning, and FTC regulatory compliance.

What privacy advisory work is most commonly underlogged?

The most systematically underlogged categories are: GDPR legal basis analysis and LIA preparation (evaluating Article 6 legal basis for each processing activity and conducting three-part balancing tests for legitimate interests claims — takes 10 to 30 hours per processing inventory review and produces no visible regulatory output until a supervisory authority inquiry); Article 30 ROPA maintenance (documenting all processing activities, recipients, transfer mechanisms, and retention periods — takes 15 to 40 hours per initial ROPA build and 5 to 10 hours per quarterly update); Article 35 DPIA preparation for new product features (identifying DPIA triggers, conducting necessity and proportionality analysis, and documenting risk mitigation — takes 15 to 40 hours per DPIA); Article 28 DPA review for vendors (reviewing eight mandatory DPA elements, negotiating audit rights, evaluating sub-processing arrangements — takes 5 to 15 hours per vendor DPA); and CCPA service provider and contractor agreement review (identifying vendors receiving personal information without qualifying contracts and negotiating qualifying restrictions — takes 5 to 15 hours per vendor agreement cycle).

What should a privacy attorney retainer agreement include?

Privacy attorney retainer agreements should specify: services covered (GDPR compliance advisory, CCPA/CPRA compliance advisory, multi-state privacy law compliance, incident response advisory, privacy-by-design product advisory, or a defined combination); applicable legal frameworks (GDPR Regulation (EU) 2016/679; UK GDPR; CCPA/CPRA California Civil Code §§1798.100-1798.199; CPPA Regulations; Virginia VCDPA; Colorado CPA; Connecticut CTDPA; Texas TDPSA; Florida FDBR; state breach notification statutes; FTC Act Section 5); deliverables format (GDPR ROPA documentation, DPIAs, Article 28 DPA templates, SCC TIAs, CCPA privacy notice reviews, consumer rights response procedures, breach notification drafts, and incident response playbooks); and the work log format giving the client's privacy team and GC visibility into privacy advisory activity between regulatory enforcement events and breach notifications. Monthly retainer amounts typically range from $3,000 to $15,000 per month, increasing to $20,000 to $60,000 or more during active supervisory authority investigations or major data breach incidents.

What are typical retainer rates for privacy attorneys?

Privacy associates and counsel with 3 to 7 years of experience typically bill at $300 to $500 per hour. Senior privacy partners with 8 or more years of experience in supervisory authority enforcement defense, FTC investigations, or complex cross-border transfer structuring typically bill at $450 to $800 per hour. Privacy attorneys with CIPP/E, CIPP/US, or CIPM certifications from IAPP, and attorneys with former supervisory authority or FTC experience, command rates at the top of these ranges. Monthly retainer amounts for ongoing privacy compliance advisory typically range from $3,000 to $12,000 per month for mid-size technology companies with EU or California user bases; companies undergoing active supervisory authority investigation or FTC enforcement typically incur $15,000 to $60,000 or more per month during the active enforcement phase.

How should privacy attorney retainer hours be logged?

Privacy attorney retainer work log entries should capture: the privacy matter (GDPR legal basis analysis, ROPA maintenance, DPIA, SCC TIA, Article 28 DPA review, CCPA consumer rights response, state privacy law threshold analysis, breach notification, incident response), the specific privacy task, the applicable GDPR Article or CCPA section analyzed, and the finding or recommended privacy strategy. A useful format is: [Privacy Matter] + [Specific privacy task] + [GDPR Article or CCPA section analyzed] + [Finding or recommended strategy]. Entries that identify the specific Article 6 legal basis analyzed, the LIA balancing test outcome, the DPIA trigger determination, and the TIA risk assessment conclusion transform the privacy compliance retainer from a general legal advisory agreement into a documented compliance record between supervisory authority enforcement actions and breach notification events.


HourTab gives privacy attorneys and data privacy counsel a public retainer dashboard URL their clients can bookmark — no client login, no portal, just a URL that shows hours used, hours remaining, and the work log behind the retainer. Learn more at hourtab.com.