Privacy law has become the defining compliance challenge of the digital economy — and it doesn’t exempt small businesses.

| ■ BOOK DETAILS |
Data Protection and Privacy: A Guide for Small to Mid-Size International Businesses
Author
John H. Fisher, Compliance Lawyer
Edition
First Edition — 2026
GDPR is not just a European problem. Any U.S. company that sells to EU consumers, employs EU workers, or processes EU personal data is subject to fines of up to 4% of global annual revenue. Add 22+ U.S. state privacy laws, the EU AI Act, COPPA 2026 amendments, BIPA class action exposure, and cross-border transfer requirements — and the compliance landscape is more complex, more consequential, and more legally perilous than at any point in history.
This book was written for the compliance officer, general counsel, or senior executive who faces the same legal obligations as a Fortune 500 company but with a fraction of the resources. Not a simplified summary — privacy law does not reward oversimplification — but a complete operational framework that translates legal complexity into decision trees, compliance checklists, and strategic roadmaps that practitioners can actually use.
Across 12 comprehensive chapters, John H. Fisher delivers publisher-ready legal analysis covering: GDPR compliance operations; U.S. multi-state privacy law; cross-border data transfer mechanisms (DPF, SCCs, TIAs); compliance program governance; sector-specific obligations in healthcare, financial services, employment, and digital marketing; the EU AI Act and algorithmic accountability; incident response and enforcement defense; privacy in M&A transactions; children’s online safety; the ROI of privacy investment; and the strategic roadmap through 2030.
With coverage of the landmark GDPR Enforcement Procedural Regulation (EU) 2025/2518, the COPPA 2026 amendments, the EU AI Act risk tiers through August 2027, the 2025 Consortium of Privacy Regulators enforcement coordination, and the complete BIPA/CIPA/VPPA litigation landscape — this is the most current, comprehensive privacy compliance guide available for U.S. businesses operating internationally.
“The compliance lawyer or Chief Privacy Officer who walks into a board meeting with the Three-Number Framework and a privacy risk register calibrated to the company’s actual exposure will rarely be denied a reasonable program budget.”
— From Chapter 11: The Privacy Program ROI
| ■ WHAT SETS THIS BOOK APART |
| ★ CURRENT | ⚙ PRACTICAL | ◆ AUTHORITATIVE |
| Coverage through July 2026 including: • EU AI Act full implementation • COPPA 2026 amendments • EU Enforcement Procedural Regulation (EU) 2025/2518 • 22+ U.S. state privacy laws • Consortium of Privacy Regulators enforcement coordination • NIST PQC post-quantum standards | Every chapter ends with a Practitioner’s Checklist. Includes: • Decision trees for lawful basis & transfer mechanisms • ROPA templates & DSR timelines • Breach notification protocols • DPIA worksheets • Transfer mechanism comparison charts • Vendor tiering frameworks | Full legal citations throughout: • GDPR articles & recitals • CJEU case law (incl. Schrems I & II) • FTC enforcement actions • CPPA settlements • EDPB guidelines & opinions The depth of a treatise. The usability of a practice guide. |
| ■ CHAPTER-BY-CHAPTER OVERVIEW |
| Chapter | Key Topics Covered |
| Ch. 1 The Global Privacy Landscape | GDPR architecture; U.S. patchwork; UK, Brazil, China, India, Japan regimes; convergence thesis; SMB applicability analysis |
| Ch. 2 GDPR Compliance — A Practical Operational Framework | ROPA; lawful bases decision tree; data subject rights; controller/processor distinctions; DPO requirements; DPIA; privacy notices; 72-hour breach protocol |
| Ch. 3 U.S. Privacy Law — Building a Multi-State Program | FTC/HIPAA/GLBA/COPPA; CCPA/CPRA; VCDPA/CPA/CTDPA; Consortium of Privacy Regulators; GPC signals; data protection assessments |
| Ch. 4 Cross-Border Data Transfers | DPF certification; 2021 SCCs (4 modules); BCRs; 6-step TIA methodology; localization requirements; Schrems I & II |
| Ch. 5 Building a Privacy Compliance Program | Accountability framework; maturity model; governance structure; Privacy by Design; retention schedules; training programs; vendor tiering; metrics/KPIs |
| Ch. 6 Sector-Specific Guidance | HIPAA+GDPR dual-track; GLBA+PSD2; employee data & works councils; cookie compliance; behavioral advertising; CAN-SPAM/CASL |
| Ch. 7 AI, Emerging Technologies, and Privacy | EU AI Act risk tiers; GDPR Article 22 automated decisions; biometric data/BIPA; generative AI governance; Colorado AI Act; neural data regulation |
| Ch. 8 Incident Response, Enforcement Defense & Litigation | 72-hour breach playbook; EDPB 5-step fine methodology; GDPR Enforcement Procedural Regulation (EU) 2025/2518; BIPA/CIPA/VPPA litigation; mass arbitration defense |
| Ch. 9 Privacy in Commercial Transactions | M&A privacy due diligence (6-area framework); Marriott/Starwood lessons; sell-side readiness; privacy reps & warranties; data asset valuation; SaaS DPA requirements |
| Ch. 10 Children’s Privacy & Age Verification | COPPA 2026 amendments; KOSA; California AADC; GDPR Article 8; Member State age thresholds; age verification technology; BIPA for minors |
| Ch. 11 The Privacy Program ROI | Cost-of-breach analysis (IBM/Ponemon 2025); compliance budget model; ISO 27701 certification ROI; board-level three-number framework; privacy as competitive advantage |
| Ch. 12 The Future of Privacy Law | Federal privacy legislation (S.490); quantum computing + NIST PQC standards; global AI governance convergence; five-year strategic roadmap to 2030 |
Legal Disclaimer: This book is intended for educational purposes only and does not constitute legal advice. Readers should consult qualified legal counsel for advice specific to their circumstances. © 2026 John H. Fisher. All rights reserved. Prices, ISBNs, and publisher information subject to change prior to publication. The sell sheet is intended for trade use by authorized distributors, sales representatives, and institutional buyers.
