Privacy policy and notices
We draft privacy policies, cookie notices, and data processing agreements compliant with the applicable law.
Data & technology law
Almost every business processes personal data. Whether you operate an online platform, develop software, employ staff, use artificial intelligence, install surveillance systems or expand internationally, data protection obligations arise throughout your business operations. Mostar advises businesses on data privacy, data protection and information governance across Armenia, the United Arab Emirates, the United States, Russia and Kazakhstan, helping organisations reduce regulatory risk while enabling responsible business growth.
Privacy compliance across jurisdictions. One team, one fee.
Speak with a lawyer02 / Capabilities
We draft privacy policies, cookie notices, and data processing agreements compliant with the applicable law.
We advise on where data must be stored and processed, particularly for Russian and Kazakhstani requirements.
We structure data transfer mechanisms for operations that move personal data across borders.
We advise on notification obligations and regulatory response in the event of a breach.
Operating models
Compliance workstreams
What is collected, why, where it is stored and who receives it.
Policies, cookie notices and consent architecture.
Processor agreements and allocation of responsibility.
Transfer mechanisms and localisation requirements.
Internal process and regulator-facing response to a breach.
05 / Client situations
Your product is live and you have no privacy policy. An enterprise client is asking for a data processing agreement.
You store user data in the cloud and your Russian users trigger data localisation requirements.
You are entering a new market and the local data protection law is different from what you comply with today.
You are preparing for an investor due diligence and your data handling practices have never been formally reviewed.
06 / Jurisdictions
Comply with EU-aligned data protection law
Data privacy →UAEAEMeet DIFC Data Protection Law requirements
Data privacy →USAUSNavigate CCPA, CPRA, and state privacy laws
Data privacy →RussiaRUComply with Federal Law 152-FZ
Data privacy →KazakhstanKZKazakhstani law and AIFC
Data privacy →OffshoreOFInternational structures and compliance
Data privacy →07 / The Mostar approach
Advice considers how the service actually collects and uses information.
We coordinate local rules and cross-border data-transfer requirements.
Policies and agreements people can implement, not templates left on a drive.
Process
Four steps. One responsible lawyer. No handoffs.
Common questions
Common questions