Digital Assets and Data Management

Overview

“Noted for its strength in litigation and defending regulatory investigations, and sought after for its wide-ranging compliance advice. Maintains a strong reputation for its standout breach response practice.”

– Chambers USA 2020

Data is king – partnerships are gold – and BakerHostetler has been recognized as a powerhouse in this space.

BakerHostetler formed the Digital Assets and Data Management Practice Group (DADM Group) to mirror how our clients do business. Leveraging data and technology is a priority for most entities. We have united key service offerings and technologists to address all the risks associated with an entity’s digital assets. Our clients are collecting data and then utilizing advanced technology to transform their products and services. Doing this creates enterprise risk. Our new practice group works with our clients through the life cycle of data – privacy, security, marketing and advertising, transactions, and emerging technology – within an organization.

We are recognized as a “Powerhouse” by BTI Consulting’s Cybersecurity & Data Privacy 2020 Report and have been named one of BTI’s “Cybersavvy 16,” a nationwide list of the top legal practices in this arena. Our experience and approach enable effective global digital risk management (and are our competitive differentiators). Our attorneys are on-site at client locations hundreds of days a year doing the small and large things necessary to meet our clients’ needs and help them accomplish their goals: conducting training, doing claims audit and substantiation, leading proactive security and risk assessments, working through security and compliance incidents, advising executive leadership teams and boards, preparing witnesses for depositions and regulatory investigations, and providing advice on new initiatives and transactions.

More »

We serve some of the largest names in retail, healthcare, hospitality, education and financial services. We also work on small and midsized matters, and these are often the matters that expose us to new trends and risks. Our technologists analyze key data from our matters to help us identify trends, develop insights and build custom tools to enable digital transformation efforts. The depth and breadth of our group’s experience are unmatched and position us to advise clients on all aspects of managing data and digital assets.

The DADM Group was built from the successes of our highly regarded Data Privacy and Advertising teams, which are ranked by Chambers, Chambers Global and Legal 500. Our lawyers have also been recognized by Law360, Financial Times Innovative Lawyers and American Lawyer for being trailblazers in this space. Indeed, our annual Data Security Incident Response Report is a go-to resource, and the compromise intelligence gained from the work associated with the Report enables us to inform our clients so they can make healthy risk-based decisions affecting various segments of their operations. Additionally, the firm’s recently formed innovative R&D team, IncuBaker, is included in this group to help lawyers and clients navigate the intersection of digital business, emerging technology and law.

The areas of focus for the DADM Group are:

Digital Risk Advisory and Cybersecurity: Managing risk, developing strategies and implementing solutions across all service areas, as well as advising on responses to data security incidents of all kinds.

Advertising, Marketing and Digital Media: Navigating key issues such as data privacy, social media marketing, gaming, sales practices, claim substantiation and much more.

Privacy Governance and Technology Transactions: Operating at the intersection of innovation and information, and managing digital asset strategies with rigorous attention to contracts, policies, training and regulations such as the California Consumer Privacy Act (CCPA) and the EU’s General Data Protection Regulation (GDPR).

Digital Transformation and Data Economy: By focusing on capitalizing on innovations that maximize IP, data, and technology, this team advises on optimal strategies to accelerate business growth, pivot into new service lines, or fundamentally revamp business models.

Healthcare Privacy and Compliance: Ensuring compliance with state and federal regulations and laws, and leveraging emerging technology, managing data and structuring operations so that data can be handled in a way that is compliant with those regulations specific to healthcare.

Privacy and Digital Risk Class Action and Litigation: This team unites a group of attorneys who have deep subject matter experience and have defended more than 100 of these matters. The team has won several appeals and has defeated class certification multiple times.

Emerging Technology: A multifaceted approach to handling data analytics, the emerging use of artificial intelligence, the Internet of Things and blockchain technology, supported by tech-savvy attorneys and technologists and the firm’s new IncuBaker team.

Select Experience

  • The Advertising, Privacy Governance and Technology Transactions, Digital Risk and Cybersecurity teams provide seamless overall counseling to global consumer products and retailers, helping the companies navigate the supporting of advertising claims, evolving loyalty and subscription programs, and CCPA compliance. The coordination of such work has never been more important as companies grapple with how lawfully to collect, protect and use valuable consumer data.
  • We served as incident response and post-disclosure counsel for Marriott Hotels regarding the Starwood Hotels guest record security incident disclosed in 2018. We also are defending Marriott in multidistrict litigation against claims brought by individuals, banks and cities.
  • All seven of our teams have supported a multinational grocer, including advised on CCPA compliance, conducting an advertising and digital media boot camp, providing counsel regarding e-commerce and cybersecurity and handling legal issues related to the response, notification and litigation arising from a payment card security incident.
  • We advised a large specialized research and treatment center on healthcare compliance, including the use of de-identified protected health information for research purposes.
More »

Professionals

Name Title Office Email
Associate New York
Partner Atlanta
Associate Denver
Staff Attorney Columbus
Associate Atlanta
Counsel Cleveland
Associate Costa Mesa
Associate New York
Partner New York
Partner Atlanta
Associate Dallas
Associate Cleveland
Counsel Cincinnati
Partner Cleveland
Associate San Francisco
Associate Cleveland
Partner Orlando
Associate New York
Partner Cleveland
Associate Dallas
Partner Los Angeles
Counsel New York
Partner Denver
Partner Atlanta
Counsel Houston
Chief Information Officer
Chief Information Officer Cleveland
Counsel Atlanta
Associate Denver
Partner Atlanta
Associate Chicago
Associate Cincinnati
Counsel Atlanta
Associate New York
Associate Columbus
Counsel Washington, D.C.
Associate Cincinnati
Associate New York
Associate New York
Partner New York
Associate Chicago
Associate Washington, D.C.
Partner New York
Partner Atlanta
Partner Los Angeles
Associate Atlanta
Partner Cleveland
Partner New York
Associate Philadelphia
Associate Denver
Partner New York
Partner Washington, D.C.
Associate Houston
Associate Atlanta
Partner Chicago
Partner Cincinnati
Partner Columbus
Partner Cincinnati
Associate Chicago
Staff Attorney Columbus
Partner Cincinnati
Associate Atlanta
Partner Cleveland
Partner Atlanta
Associate Chicago
Associate Chicago
Partner Seattle
Partner Denver
Partner Washington, D.C.
Associate Seattle
Partner Cleveland
Partner New York
Partner Los Angeles
Associate New York
Partner Atlanta
Associate Seattle
Counsel Columbus
Associate Chicago
Director of Practice Services
Director of Practice Services Cincinnati
Associate Washington, D.C.
Associate Cleveland
Associate Los Angeles
Partner Columbus
Associate Costa Mesa
Partner New York
Associate Washington, D.C.
Partner Cleveland
Partner San Francisco
Partner Seattle
Partner Seattle
Partner Washington, D.C.
Partner Cleveland
Counsel Chicago
Partner Philadelphia
Associate Denver
Partner Philadelphia
Associate Chicago
Associate Seattle
Partner Cincinnati
Partner Cleveland
Associate New York
Associate Atlanta
Partner Philadelphia
Partner Washington, D.C.
Associate Houston
Partner San Francisco
Partner Houston
Partner Washington, D.C.
Partner New York
Partner Philadelphia
Partner Cleveland
Partner Orlando
Partner Washington, D.C.
Partner Cleveland
Associate Denver
Associate New York
Associate Seattle
Partner Cincinnati
Associate Denver
Partner Chicago
Counsel Philadelphia
Partner Cleveland
Counsel Chicago
Associate Los Angeles
Counsel Philadelphia
Partner Cleveland
Associate Atlanta
Associate Atlanta
Partner Atlanta
Partner Houston
Partner Atlanta
Associate Washington, D.C.

Experience

  • The Advertising, Privacy Governance and Technology Transactions, Digital Risk and Cybersecurity teams provide seamless overall counseling to global consumer products and retailers, helping the companies navigate the supporting of advertising claims, evolving loyalty and subscription programs, and CCPA compliance. The coordination of such work has never been more important as companies grapple with how lawfully to collect, protect and use valuable consumer data.
  • We served as incident response and post-disclosure counsel for Marriott Hotels regarding the Starwood Hotels guest record security incident disclosed in 2018. We also are defending Marriott in multidistrict litigation against claims brought by individuals, banks and cities.
  • All seven of our teams have supported a multinational grocer, including advised on CCPA compliance, conducting an advertising and digital media boot camp, providing counsel regarding e-commerce and cybersecurity and handling legal issues related to the response, notification and litigation arising from a payment card security incident.
  • We advised a large specialized research and treatment center on healthcare compliance, including the use of de-identified protected health information for research purposes.
  • Multiple DADM Group teams combined to provide services to a multi-brand restaurant company with thousands of locations. Our work included data security incident response; incident response training and tabletop exercises; extensive technology contract negotiations to support integration of new brands into the multi-brand concept; guidance regarding implementation of secure payment technology and mobile payment applications; and acquisition-related due diligence and security assessments.
  • We represent an alliance of multinational corporations in connection with a partnership with IBM Watson Health and other analytics providers. This partnership harnesses the power of IBM’s artificial intelligence capabilities and other provider services through the collection and analysis of health data to improve health outcomes for employees and to reduce healthcare costs for member companies.
  • Our Digital Risk Class Action and Litigation team defeated certification of a putative class action brought against a large regional discount retailer on behalf of banks that issued payment cards affected by the retailer’s 2015 data breach. The plaintiffs attempted to certify a class of about 2,500 banks, arguing that the retailer was negligent in its failure to maintain adequate cybersecurity, leading to damages including actual fraud losses, card reissuance costs and lost revenue from the potential compromise of more than 1 million payment cards. Through significant fact discovery, the team developed a solid factual record to oppose class certification.
  • We advised an international fast food chain regarding the use of a new blockchain tool to tokenize and distribute sensitive data, including an analysis of the technology against laws providing safe harbors for encryption in the event of a security incident.

Recognition

  • Selected as a 2020 “Pacesetter” in Cybersecurity Services by ALM Intelligence Pacesetter Research
  • BTI Cybersecurity Powerhouse (2020)
  • BTI CyberSavvy Law Firm (2020)
  • Chambers Global
    • Privacy & Data Security (USA) (2014 to 2020)
    • Privacy & Data Security: Healthcare Spotlight Table – Nationwide (2018 to 2020)
  • Chambers Fintech
    • Legal – USA (2018 to 2020)
  • Chambers USA
    • Advertising: Transactional & Regulatory – Nationwide (2018 to 2020)
    • Privacy & Data Security – Nationwide (2013 to 2020)
    • Privacy & Data Security: Healthcare Spotlight Table – Nationwide (2018 to 2020)
  • Chambers USA Award: “Privacy & Data Security Team of the Year” finalist (2015, 2017)
  • The Legal 500 United States
    • Media, Technology and Telecoms: Advertising and Marketing: Transactional and Regulatory (2018 to 2020)
    • Media, Technology and Telecoms: Cyber Law (2016 to 2020)
    • Media, Technology and Telecoms: Data Privacy and Data Protection (2016 to 2020)
  • Law360: Privacy "Practice Group of the Year" (2013 to 2015, 2018)
  • Selected for Vault's Guide to Legal Practice Areas (2017 to 2020)

News

News

Press Releases

Publications

Alerts

Articles

Blog Posts

Key Contacts

Blog

In The Blogs

Previous Next
Data Counsel
European Authorities Release Back-to-Back Drafts Addressing Cross-Border Data Transfers
By Melinda L. McLellan, Nichole L. Sterling
November 19, 2020
Last week, both the European Data Protection Board (EDPB) and the European Commission released highly anticipated draft documents offering guidance to organizations that engage in cross-border data transfers involving EU personal data. The...
Read More ->
AD-ttorneys Law Blog
California Ballot Referendum on CCPA Will Have Significant Effects on AdTech
By Kyle R. Fath, Alan L. Friel
November 18, 2020
On Election Day, California voters approved a ballot measure, Proposition 24, known as the California Privacy Rights Act of 2020 (CPRA). Referred to by some as CCPA 2.0, the CPRA amends certain provisions of the paradigm shifting 2018...
Read More ->
AD-ttorneys Law Blog
Will FTC Penalties Under Section 5(m)(1)(B) Rise Again?
By Amy Ralph Mudge, Randal M. Shaheen
November 5, 2020
As we wait to see how the Supreme Court will rule on the FTC’s redress authority and whether the FTC will potentially be controlled by Republicans or Democrats for at least the next four years, it is worth noting that Commissioner Chopra...
Read More ->
Data Counsel
California Voters Approve Reworking of Landmark Consumer Privacy Law – What CCPA 2.0 Will Mean for Businesses and Consumers
By Kyle R. Fath, Alan L. Friel
November 4, 2020
The nation awoke the morning after Election Day 2020 with much still unresolved. However, what seemed clear was that California voters almost certainly approved a ballot measure, Proposition 24, known as the California Privacy Rights Act...
Read More ->
Data Counsel
CISA Updates Advisory on Large-Scale Impending and Credible Ransomware Threat to Healthcare to Include Additional IOCs
By Sara M. Goldstein, Aleksandra Vold
October 30, 2020
On Oct. 28, a joint cybersecurity advisory was published by the Cybersecurity and Infrastructure Security Agency (CISA), the FBI and the Department of Health & Human Services. The advisory warned of an imminent cybercrime threat to U.S...
Read More ->