You’re Not Ready For CPRA If Your Vendors Aren’t
Sep 01, 2022
by Rich Vestuto, Wayne Matus

Rich Vestuto is a managing director in Kroll's Data Insights and Forensics practice, based in the New York office. He leads the firm’s information governance, records and contract management capabilities, leveraging his over 20 years of experience in contract lifecycle management (CLM), and information governance supporting complex litigation supporting complex litigation, M&A and regulatory engagements.
Prior to joining Kroll, Rich was a managing director at Deloitte where he focused on CLM and information governance, providing services to many of the world’s top banks, media companies, technology firms and others. He has been instrumental in many large and complex repapering projects and other CLM-based engagements. In addition to consulting on records and information challenges, including data privacy, records separation, contract management and cross-border issues, Rich has consulted in more than 200 litigations and investigations in the U.S., UK, Europe and Asia Pacific.
As a licensed attorney, Rich brings legal training along with technology experience to his consulting practice. He spent three years on the board of directors of ARMA International, the world's leading information management membership organization. He is a member of the Sedona Conference brainstorming groups on Data Privacy and Cross Border Litigation, and a member of the New York State Bar Association, American Bar Association (ABA), ABA Advisory Panel, Section of Litigation of the ABA, ABA Cyberspace Law Committee, International Legal Technology Association (ILTA) and the Digital Forensics Association.
Rich’s representative engagements include information governance and data privacy compliance guidance for an international airline; a divestiture-based records separation for an industrial products conglomerate; a GDPR/CCPA remediation project for a security software provider; and a complex response to a regulatory document request for a foreign exchange investigation by the U.S. Securities and Exchange Commission and Department of Justice.
At Kroll, Rich advises large enterprises undergoing digital transformations and complex regulatory challenges, providing information governance, litigation support and CLM support. Organizations that are driven by privacy or regulatory requirements to undergo information governance or CLM often find that this comes with compliance and cyber security implications. Rich works closely with the Compliance and Cyber Risk practices to provide clients with a tailored, holistic approach when these problems arise.
Rich has authored numerous articles on artificial intelligence (AI), data analytics, technology enablement and has been cited in publications, including The Wall Street Journal, Forbes, Corporate Counsel and Bloomberg Law, regarding various privacy and other regulations such as GDPR, CCPA, recovery and resolution, and those issued by NY Department of Financial Services, such as NYCRR 500. He has conducted more than 150 accredited CLE presentations and lectured around the world on the use of legal technology, AI, litigation support, CLM, information governance, third-party risk, how legal departments can utilize data analytics, data retention and compliance, privacy, FCPA matters, cross-border litigation, Dodd-Frank whistleblower rules and other electronically stored information related issues.
Rich received a BFA in communications and media from the New York Institute of Technology and a JD from Touro College Jacob D. Fuchsberg Law Center.
We are the leading advisors to organizations, providing expertise and solutions to address complex risks and challenges involving technology and data. We advise clients with services to address risks in disputes, investigations and regulatory compliance.
Governance to Harmonize Multiple Information Disciplines, Merging Security and Productivity