Karissa L. Smith is an Associate in Mullen Coughlin’s Advisory Compliance practice. She advises organizations across all industry sectors with data privacy, data security, and emerging technology risk management compliance across U.S. federal, state, and local regulatory regimes. Drawing on significant experience helping organizations address critical regulatory and operational issues, Karissa counsels organizations through data governance challenges, regulatory investigations, data privacy and security incidents, and other matters with immediate business, legal, and reputational implications. This experience provides a practical understanding of the issues most likely to attract regulatory scrutiny or consumer concern, allowing her to help clients proactively manage risk and strengthen compliance programs.
She works closely with organizational stakeholders – including management teams, legal teams, and IT teams – to advise on legal and regulatory frameworks and develop core compliance infrastructure, including data processing agreements, privacy policies, consumer rights requests processes, and data privacy and security Incident Response Plans (IRPs).
Her experience spans U.S. and federal comprehensive consumer privacy laws, including:
- The California Consumer Privacy Act (CCPA)/California Privacy Rights Act (CPRA);
- The Gramm-Leach-Bliley Act (GLBA);
- The Health Insurance Portability and Accountability Act (HIPAA);
- FTC enforcement and consumer protection principles under Section 5 of the FTC Act;
- state health data privacy laws;
- state biometric privacy laws; and
- emerging artificial intelligence (AI) and automated decision-making regulations.
She frequently advises her clients on the intersection of these overlapping regimes, helping organizations navigate complex compliance obligations while supporting business objectives.
Karissa works with organizations ranging from closely held and family-owned businesses, to national and international companies operating in highly regulated and consumer-facing industries. Whether helping a company respond to a significant regulatory challenge or proactively strengthen its data privacy and security posture, she focuses on delivering practical and business-oriented solutions tailored to each client’s operational realities and risk profile.
Outside of her practice, Karissa volunteers as a Mentor Attorney with Legal Outreach and is an ESL instructor. She is also conversational in Spanish.