Rimon

Elimu Kajunju

Partner

Data Privacy and Cybersecurity, Technology, Artificial Intelligence, Life Sciences
Atlanta

EDUCATION

Mitchell Hamline School of Law

J.D.

Saint Mary's University of Minnesota

B.S., Business

Certifications

• AIGP (Artificial Intelligence Governance Professional) • CISSP (Certified Information System Security Professional) • CISSP-ISSAP (Certified Information System Security Professional – Information System Security Architecture Professional) • CIPP/US (Certified Information Privacy Professional/US) • CIPP/E (Certified Information Privacy Professional/Europe) • CIPP/C (Certified Information Privacy Professional/Canada) • CIPP/G (Certified Information Privacy Professional/Government) • CIPT (Certified Information Privacy Technologist) • CIPM (Certified Information Privacy Manager)

PREVIOUS EXPERIENCE

  • Honeywell (General Counsel – Cybersecurity & Product Compliance)
  • Google (Head of Health Information Privacy)
  • DaVita (Vice President, Chief Privacy Officer, Associate General Counsel – Privacy, Cybersecurity & AI)
  • McKesson (Vice President, Global Privacy)
  • UnitedHealthcare (Chief Privacy Officer, Sr. Compliance Director & Sr. Associate General Counsel)
  • Boston Scientific (Chief Privacy Officer & Compliance Counsel)

    ADMISSIONS

  • State of Minnesota
  • State of Georgia

    Languages

  • English
  • French (Conversational)

Mr. Kajunju is one of the premier privacy and cybersecurity lawyers in the world. He has over 25 years of experience handling privacy, cybersecurity and technology matters. As a former security engineer, business owner and corporate executive, he has a strong appreciation of the complexity of the intersection of technology, business objectives and the law. He has been relied upon to navigate complexity by some of the world’s largest and most innovative companies, including Google, Honeywell and McKesson.

Mr. Kajunju’s practice spans the following key areas:

  • Privacy:
    • Agreements (BAAs, DPAs, SCCs, etc.) drafting and negotiation
    • Application and implication of artificial intelligence, Internet of Things, facial recognition, biometrics, data mining and other emerging technologies and innovation
    • Compliance with regulatory requirements and standards, including BIPA, CAN-SPAM, COPPA, ePrivacy Directive, EU and UK GDPR, FCRA, FERPA, GLBA, HIPAA Privacy & Breach Notification, TCPA, etc.
    • Cookie notices, policies and practices
    • Data acquisition, data rights and data use strategies
    • Due diligence for Mergers and Acquisitions and post M&A integration
    • Governance, risk and compliance
    • Incident/breach preparedness, investigation, response, communication and remediation
    • Legislative monitoring, assessment and analysis
    • Program review and assessment
    • Training and awareness programs
    • Privacy-by-design program design, documentation and implementation
    • Product privacy reviews
    • Regulatory filings, response and communication
    • State privacy laws (California, Colorado, Connecticut, Utah, Virginia, etc.)
    • Workplace privacy
  • Security:
    • Agreements (DPAs, Security Addendum, etc.) drafting and negotiation
    • Application and implication of artificial intelligence, Internet of Things, facial recognition, biometrics, data mining and other emerging technologies and innovation
    • Compliance with regulatory requirements and standards, including CMMC 2.0, CRA, DORA, FASCSA, HIPAA Security, NIS 2 Directive, PCI DSS, RED, etc.
    • Cyber insurance evaluation and negotiation
    • Due diligence for Mergers and Acquisitions and post M&A integration
    • External statements and messaging relating to the organization’s security posture and compliance
    • Governance, risk and compliance
    • Incident/breach preparedness, investigation, response, communication and remediation
    • Legislative monitoring, assessment and analysis
    • Materiality assessments for incident notification
    • Physical security, surveillance, monitoring, personnel security and other matters related to the security of facilities, equipment and people
    • Privileged investigations, assessments and penetration tests
    • Program review and assessment
    • Regulatory filings, response and communication
    • Training and awareness programs
    • Security-by-design program design, documentation and implementation
    • Security exception, concessions, deviations and compensating controls review
    • State security laws
    • Vulnerability management program components, including bug bounty programs, vulnerability notifications, security advisories, fix prioritization, etc.
  • Technology:
    • AI governance program design and implementation
    • Compliance with regulatory requirements and standards, including EU AI Act, EU Data Act, etc.
    • Cross-border transfer issues
    • Data localization strategies and compliance
    • Legislative monitoring, assessment and analysis
    • Product compliance for digital products
    • Records management programs

Selected Experience

  • Hundreds of privacy and security incidents responded to (including investigation, mitigation, communication and remediation)
  • Built privacy programs for several Fortune 100 companies
  • Built security compliance programs for large healthcare and hospitality organizations
  • Led privacy and security due diligence for several dozens of mergers, acquisitions, divestitures and spinoffs
  • Negotiated over a thousand business associate agreements, data protection agreements, security addendums, data use agreements and other documents containing privacy and/or security terms
  • Expanded US privacy and security programs globally for multiple Fortune 500 companies
  • Built program for use of health data for AI models at Google

Memberships

  • IAPP (International Associate of Privacy Professionals)
  • ISC2 (International Information System Security Certification Consortium)

EDUCATION

Mitchell Hamline School of Law

J.D.

Saint Mary's University of Minnesota

B.S., Business

Certifications

• AIGP (Artificial Intelligence Governance Professional) • CISSP (Certified Information System Security Professional) • CISSP-ISSAP (Certified Information System Security Professional – Information System Security Architecture Professional) • CIPP/US (Certified Information Privacy Professional/US) • CIPP/E (Certified Information Privacy Professional/Europe) • CIPP/C (Certified Information Privacy Professional/Canada) • CIPP/G (Certified Information Privacy Professional/Government) • CIPT (Certified Information Privacy Technologist) • CIPM (Certified Information Privacy Manager)

PREVIOUS EXPERIENCE

  • Honeywell (General Counsel – Cybersecurity & Product Compliance)
  • Google (Head of Health Information Privacy)
  • DaVita (Vice President, Chief Privacy Officer, Associate General Counsel – Privacy, Cybersecurity & AI)
  • McKesson (Vice President, Global Privacy)
  • UnitedHealthcare (Chief Privacy Officer, Sr. Compliance Director & Sr. Associate General Counsel)
  • Boston Scientific (Chief Privacy Officer & Compliance Counsel)

    ADMISSIONS

  • State of Minnesota
  • State of Georgia

    Languages

  • English
  • French (Conversational)

News, Events, & Insights

View More →
Rimon Law
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.