Melinda L. McLellan

Partner

New York
T +1.212.589.4679
F +1.212.589.4201

Overview

Melinda McLellan works with clients to navigate complex privacy, cybersecurity and data management issues in a rapidly evolving regulatory environment. She counsels companies of all sizes across multiple industry sectors, helping them identify, evaluate and manage the myriad compliance obligations associated with corporate privacy and information security practices. Melinda regularly advises on the creation, development and implementation of global privacy and security policies, standards, procedures and guidelines, as well as company codes of conduct and employee privacy training programs. Attentive to her clients' business needs, Melinda's proactive approach favors pragmatic, forward-thinking compliance strategies that emphasize prevention and mitigation of privacy and data security risks.

Select Experience

  • Counsels clients on regulatory compliance strategies and best practices for private-sector use of cloud computing solutions, biometric authentication, facial recognition technology, geolocation tracking systems, mobile applications, behavioral marketing tools, social media platforms, data analytics services and other emerging technologies. 
  • Advises on compliance with international data transfer restrictions and data localization requirements, including through the implementation of cross-border transfer mechanisms such as the EU-U.S. Privacy Shield framework, standard contractual clauses, intercompany agreements and binding corporate rules.
  • Manages complex technology transactions on both the vendor side and the customer side, drafting and negotiating multiparty contracts and outsourcing agreements from the RFP through follow-up compliance assessments. 
More »

Experience

  • Counsels clients on regulatory compliance strategies and best practices for private-sector use of cloud computing solutions, biometric authentication, facial recognition technology, geolocation tracking systems, mobile applications, behavioral marketing tools, social media platforms, data analytics services and other emerging technologies. 
  • Advises on compliance with international data transfer restrictions and data localization requirements, including through the implementation of cross-border transfer mechanisms such as the EU-U.S. Privacy Shield framework, standard contractual clauses, intercompany agreements and binding corporate rules.
  • Manages complex technology transactions on both the vendor side and the customer side, drafting and negotiating multiparty contracts and outsourcing agreements from the RFP through follow-up compliance assessments. 
  • Works with cross-disciplinary teams to devise and implement clear, concise, non-obtrusive and legally compliant disclosures regarding data management practices as well as opt-in and opt-out mechanisms for the collection, use and sharing of sensitive information.
  • Manages all aspects of information security breach response, including evaluating legal and regulatory notification obligations, developing written communications for affected populations and internal stakeholders, refining media messaging strategies, coordinating forensic investigations, working with law enforcement authorities, and interfacing directly with state and federal regulators.
  • Prepares cyber risk exposure analyses, disclosure statements and supporting materials for publicly traded companies and entities preparing for IPOs and other corporate transactions.
  • Advises clients on legal risks and best practices associated with background checks, employee monitoring and Bring Your Own Device programs, including by developing internal policies and protocols and implementing mobile device management systems. 
  • Drafts and negotiates privacy and data security provisions for commercial contracts, including service provider agreements; assists clients with remediation of privacy and data security deficiencies and lacunae in legacy vendor contracts.
  • Conducts thorough assessments of third-party vendor candidates to evaluate data protection posture and compliance readiness prior to engagement, then assists with oversight and enforcement of privacy and security representations over the course of the service agreement. 
  • Devises privacy and information security awareness programs and training modules for personnel, typically deploying a multitiered, risk-based approach to account for varying degrees of employee access to, and responsibility for, sensitive data.
  • Conducts in-house security training and tabletop exercises to build awareness and help companies prepare to effectively and efficiently manage data security threats and incidents.
  • Counsels clients on information governance practices and the development of records retention, maintenance and destruction policies and procedures.
  • Implements insider threat analysis tools for organizations, particularly in the financial sector, to detect and prevent security incidents and facilitate integrated enterprisewide security solutions.
  • Provides data protection counseling to a variety of technology companies and outsource vendors that offer big data analytics and complex fraud detection and prevention services.
  • Works directly with in-house counsel, internal stakeholders and third-party technologists to develop complex privacy and information security policies, procedures, protocols, guidelines and notices.

Recognitions and Memberships

Recognitions

  • New York Metro Super Lawyers "Rising Star" (2012 to 2017)
    • New York Super Lawyers "Top Women Attorneys" (2012 to 2016)
  • New York State Bar Association: Empire State Counsel (2007 to 2013)
  • The Legal 500 United States (2017)
    • Next Generation Lawyer in Media, Technology and Telecoms: Data protection and privacy

Memberships

  • International Association of Privacy Professionals
    • Certified Information Privacy Professional – United States (CIPP/US)
    • Certified Information Privacy Professional – Europe (CIPP/E)
  • Women in eDiscovery, New York City Chapter
  • The Sedona Conference: Working Group 11, Data Security and Privacy Liability 

News

News

Press Releases

Blog Posts

Pro Bono

  • New York City Bar Justice Center, Legal Clinic for the Homeless
  • Lawyers' Committee for Civil Rights Under Law, Election Protection Program
  • Successfully represented a West African victim of gender-based violence seeking asylum in the United States before the Department of Homeland Security

Admissions

  • New York

Education

  • J.D., Harvard Law School, 2005; Executive Editor, Harvard International Law Journal
  • B.A., Political Science and French Studies, Rice University, 2000

Languages

  • French
  • Italian

Blog

In The Blogs

Previous Next
Data Privacy Monitor
Canadian Breach Notification Requirements Take Effect November 1
By Julie A. Hein, Melinda L. McLellan
April 25, 2018
On April 18, 2018, the Canadian government published long-awaited Breach of Security Safeguards Regulations specifying the requirements for notifying the Office of the Privacy Commissioner and affected individuals of data breaches that...
Read More ->
Data Privacy Monitor
Court Limits 2015 Text Marketing Rules, Gives New FCC an Opportunity to Provide Clarity
By Alan L. Friel, Melinda L. McLellan
March 19, 2018
On March 16, the D.C. Circuit issued a long-awaited decision in a challenge to the Federal Communications Commission’s July 10, 2015 Declaratory Ruling and Order regarding the Telephone Consumer Protection Act (the July 2015 Order). We...
Read More ->
Data Privacy Monitor
Clock Ticking, European Commission Launches GDPR Implementation Guidance Website
By Melinda L. McLellan
January 26, 2018
With only four months remaining until the EU General Data Protection Regulation takes effect on May 25, 2018, the European Commission has launched a new website offering guidance on requirements and implementation targeted at an array of...
Read More ->
Data Privacy Monitor
From the Mouths of Babes: FTC Issues COPPA Enforcement Policy Regarding Voice Recordings
By Alan L. Friel, Melinda L. McLellan
November 7, 2017
On October 23, the Federal Trade Commission (FTC) released new guidance on how the Children’s Online Privacy Protection Act (COPPA) Rule may apply to audio recordings of children’s voices collected by websites and online services...
Read More ->
Data Privacy Monitor
Privacy Shield Update: Ahead of First Joint Review, Europeans Remain Skeptical as FTC Announces Enforcement Actions
By Emily R. Fedeles, Melinda L. McLellan
September 12, 2017
On September 8, 2017, the Federal Trade Commission (FTC) announced enforcement actions against three companies alleged to have falsely claimed participation in the EU-U.S. Privacy Shield Framework. The move follows several months of...
Read More ->