Where your numbers and your data need a lawyer, not just a form.
Meridian Tax & Privacy Counsel represents individuals and businesses before the IRS and state tax authorities, and advises companies on data privacy compliance, breach response, and cross-border data transfers.
$180M+
In disputed tax liability resolved
40+
State privacy compliance programs built
300+
Breach incidents managed under privilege
2
Practices, one integrated team
Tax Law
IRS Audit Defense
Representation from the first notice through the final determination.
- Response to IRS notices (CP2000, audit letters)
- Document preparation and examiner meetings
- Individual, business, and payroll tax audits
Tax Controversy & Appeals
Disputing an IRS or state tax determination through administrative appeal or Tax Court.
- IRS Office of Appeals representation
- U.S. Tax Court petitions
- Collection Due Process hearings
Collections & Offers in Compromise
Resolving back taxes through installment agreements, offers in compromise, or currently-not-collectible status.
- Offer in compromise applications
- Installment agreement negotiation
- Currently-not-collectible determinations
Business & Individual Tax Planning
Structuring transactions and entities before problems start, not after.
- Entity formation and structuring
- Unfiled and delinquent return preparation
- Transaction and succession tax planning
Privacy Law
State Privacy Law Compliance
Building a compliance program for CCPA/CPRA and the growing list of state privacy statutes.
- Privacy policy and notice drafting
- Data mapping and inventory
- Consumer rights request (DSAR) workflows
GDPR & Cross-Border Data Transfers
Compliance for organizations handling data on individuals in the EU/UK.
- Standard Contractual Clauses and transfer impact assessments
- Lawful basis and consent framework review
- EU representative and DPO coordination
Data Breach Response
Coordinated legal response in the hours and days after an incident.
- Incident response coordination under privilege
- Multi-state breach notification analysis
- Regulator and attorney general communications
Vendor & Data Processing Agreements
Reviewing and negotiating the contracts that govern how data actually moves.
- Data Processing Agreement (DPA) drafting and review
- Vendor privacy and security risk assessments
- SaaS and cloud services contract review
How an engagement moves, step by step.
- 01
Confidential intake
We review your notice, contract, or incident under privilege before anything else happens.
- 02
Risk assessment
You get a plain-language read on exposure, deadlines, and realistic options — not a sales pitch.
- 03
Representation or program build
We handle the IRS or regulator directly, or build the compliance program, contracts, and documentation you need.
- 04
Resolution & recordkeeping
Every matter closes with a clear written record — of the settlement, the program, or the response — so you're covered if it's ever revisited.
Identifying details redacted. The outcomes are real.
Shared with client permission. Past results do not guarantee a similar outcome in any future matter.
“I'd gotten a CP2000 notice and panicked. They handled every letter after that and the whole thing resolved for a fraction of what I feared.”
“Our CCPA program was a patchwork before they rebuilt it. Now we actually know where our data is and who can see it.”
“During our breach, they were the calmest people in the room. We had a notification plan within a day.”
Questions clients ask before their first call.
Do I need a tax attorney or a CPA?+
A CPA generally prepares returns and provides tax advice; a tax attorney is needed when you're in a dispute with the IRS or a state agency, when communications need to be protected by attorney-client privilege, or when a matter could result in litigation. Many clients use both — we regularly coordinate directly with a client's existing CPA.
What's the difference between CCPA and GDPR compliance?+
CCPA/CPRA is a California statute (with similar laws now in many other states) built around consumer rights like access, deletion, and opt-out of sale/sharing. GDPR is EU/UK law built around a 'lawful basis' requirement for any processing of personal data, with stricter consent and cross-border transfer rules. Organizations that serve both U.S. and EU users typically need a compliance program that satisfies both frameworks at once.
How fast do I need to respond to a data breach?+
It depends on the states and regulations involved — some U.S. state laws require notification within 30 days of discovery, while others allow 'without unreasonable delay.' GDPR generally requires notifying the relevant supervisory authority within 72 hours of becoming aware of a breach. Because timelines are jurisdiction-specific and can overlap, breach response should start the same day an incident is discovered.
Can you help if I haven't filed tax returns in several years?+
Yes — this is one of the more common matters we handle. There's typically a path to get current that limits exposure to penalties and criminal referral, but the right sequence of filings and disclosures matters, so this isn't something to navigate by simply filing the missing returns on your own.
Is a consultation confidential?+
Yes. An initial consultation is confidential, and we do not contact the IRS, a regulator, or any other party without your authorization. Confidentiality of a specific matter, and the attorney-client relationship itself, begins once a written engagement agreement is signed.
Tax and privacy deadlines rarely wait.
A confidential consultation costs nothing and takes about fifteen minutes. Find out where you stand before a deadline decides it for you.
Schedule a Confidential Consultation