Skip to main content

Data & technology law

Data Privacy

Almost every business processes personal data. Whether you operate an online platform, develop software, employ staff, use artificial intelligence, install surveillance systems or expand internationally, data protection obligations arise throughout your business operations. Mostar advises businesses on data privacy, data protection and information governance across Armenia, the United Arab Emirates, the United States, Russia and Kazakhstan, helping organisations reduce regulatory risk while enabling responsible business growth.

Privacy compliance across jurisdictions. One team, one fee.

Speak with a lawyer

02 / Capabilities

What this covers

01

Privacy policy and notices

We draft privacy policies, cookie notices, and data processing agreements compliant with the applicable law.

02

Data localisation compliance

We advise on where data must be stored and processed, particularly for Russian and Kazakhstani requirements.

03

Cross-border data transfers

We structure data transfer mechanisms for operations that move personal data across borders.

04

Data breach response

We advise on notification obligations and regulatory response in the event of a breach.

Operating models

Privacy work for data-driven business

The compliance model has to reflect the product, its users and where the data moves.
  1. SaaS & platformsProduct data, enterprise customers and processor obligations.01
  2. E-commerce & consumer appsMarketing, cookies, customer information and retention.02
  3. HR & distributed teamsEmployee data, recruitment and remote-work tools.03
  4. Regulated sectorsFinancial, health and other sensitive data environments.04

Compliance workstreams

Privacy compliance in practice

We map actual data flows before drafting the documents that govern them.
01

Data mapping

What is collected, why, where it is stored and who receives it.

02

Privacy notices

Policies, cookie notices and consent architecture.

03

Vendor & DPA terms

Processor agreements and allocation of responsibility.

04

Cross-border transfers

Transfer mechanisms and localisation requirements.

05

Incident readiness

Internal process and regulator-facing response to a breach.

05 / Client situations

When clients come to us

01

Client situation 01

Your product is live and you have no privacy policy. An enterprise client is asking for a data processing agreement.

  • UAE
  • USA
02

Client situation 02

You store user data in the cloud and your Russian users trigger data localisation requirements.

  • Russia
03

Client situation 03

You are entering a new market and the local data protection law is different from what you comply with today.

  • Armenia
  • UAE
04

Client situation 04

You are preparing for an investor due diligence and your data handling practices have never been formally reviewed.

  • UAE
  • Armenia

06 / Jurisdictions

Where we operate

07 / The Mostar approach

Cross-border privacy without empty paperwork

We focus on the product and operating model, then make compliance usable for the team.
01

Product-aware review

Advice considers how the service actually collects and uses information.

02

Multi-jurisdiction scope

We coordinate local rules and cross-border data-transfer requirements.

03

Operational documents

Policies and agreements people can implement, not templates left on a drive.

How the compliance work proceeds

Common questions

Questions about data privacy

You may also need

Company FormationContracts & Commercial LawEmployment LawLicensingIntellectual Property

Speak with a legal advisor

Telegram

@mostar_legal

WhatsApp

+374 41 321 532