Photo of Zachary Heck

Zach’s practice focuses on privacy and data security. Specifically, Zach assists clients in the areas of privacy compliance, data governance, and guidance in the aftermath of an information security incident, including data breach. Zach has experience advising clients with respect to FTC investigations, federal privacy regulations (such as HIPAA, FCRA, TCPA, and GLBA), state laws governing personally identifiable information (e.g., CCPA/CPRA), foreign privacy regulations (e.g., PIPEDA and GDPR), artificial intelligence, and government contracting security requirements (e.g., NIST 800-171 and CMMC 2.0).

Martin Edwards, vice president of Taft’s Public Affairs Strategies Group in Taft’s Washington, D.C. office, contributed to this post.

On July 23, 2025, the White House published “America’s AI Action Plan,” which sets a public policy framework targeting the United States’ technological leadership in artificial intelligence. The AI Action Plan, coupled with three

Martin Edwards, vice president of Taft’s Public Affairs Strategies Group in Taft’s Washington, D.C. office, contributed to this post.

Early on July 1, the U.S. Senate voted to halt an effort to impose a 10-year moratorium on state regulation of artificial intelligence. The vote, 99-1, removed the AI provision from President Trump’s “Big, Beautiful Bill”