Privacy and Data Security

Privacy and cybersecurity obligations must work in daily operations and under pressure. We help organizations build compliance programs, prepare for incidents, and respond when data is exposed.

Our focus

Privacy and cybersecurity that work in practice and under pressure.

Privacy and cybersecurity obligations reach across an organization. Policies must work in daily operations, contracts should assign responsibility clearly, and response plans must guide decisions under pressure. We help clients build programs that satisfy legal requirements and protect personal information. Just as important, we prepare their teams to act when an incident occurs.

Our attorneys develop privacy and data security policies, written information security programs, breach response plans, and governance frameworks. We advise on state consumer privacy laws, international requirements, and cross-border data transfers. Our work also addresses industry-specific obligations affecting health care providers, financial institutions, utilities, local governments, and other regulated organizations.

When a cyberattack or other data exposure occurs, we help clients assess their legal obligations and respond quickly. We advise on breach notification requirements and regulatory concerns, helping organizations make decisions that account for financial exposure, business relationships, and reputation.

Privacy and data security issues also arise in transactions, vendor relationships, employment matters, and litigation. We conduct cybersecurity due diligence in mergers and other transactions and negotiate agreements with cloud storage, document management, and other information vendors. When a matter becomes contested, we defend organizations in regulatory enforcement proceedings and class actions involving alleged privacy violations.

We develop privacy and data security policies, written information security programs, breach response plans, and governance frameworks. We also advise on state consumer privacy laws, GDPR requirements, cross-border data transfers, and statutory requests from consumers.

We help organizations respond to cyberattacks and other data exposure events. Our attorneys assess notification requirements, advise on regulatory issues, and help clients manage the legal decisions that follow an incident.

We help organizations prepare through employee training, response planning, tabletop exercises, and breach simulations. Our work clarifies responsibilities and decision-making before an incident places the organization under pressure.

We advise organizations on privacy and data security requirements specific to their industries. Our work includes HIPAA, the Gramm-Leach-Bliley Act, the Fair Credit Reporting Act, utility data-incident reporting requirements, and Payment Card Industry Data Security Standards.

We negotiate agreements with cloud storage, document management, and other information vendors. We also conduct cybersecurity due diligence in mergers and other transactions and help clients allocate privacy and data security responsibilities in commercial agreements.

We defend organizations in Federal Trade Commission and Federal Communications Commission enforcement actions involving consumer privacy. We also represent businesses in class actions and other litigation arising from alleged privacy violations or data exposure.

Learn more.

Key Contacts

Devin Chwastyk

Devin J. Chwastyk

Advises businesses and public entities on privacy, data security, and complex litigation. Counsels on compliance, breach response, and class action defense.

See full profile

How can we help?

Related news and insights

See recent news and insights related to this area, with more context on the developments shaping it.