Information Governance

Overview

We work carefully to understand clients’ information governance profiles and tailor solutions that fit their specific needs, risk tolerances, and regulatory and industry footprints. Clients trust us to help them navigate changing information governance paradigms, reducing risk and cost and positioning them for success.

The risks associated with outdated or faulty strategic information governance are growing as clients face record-keeping compliance penalties, e-discovery costs and sanctions, and expenses and reputational harm associated with frequent data privacy and security incidents. Success depends on the intelligent use and protection of information, but the governance of that information warrants a dramatic and unprecedented change in practice.

To assist clients in managing the maze of potential information governance hazards, our nationwide team includes certified records managers, certified privacy professionals, security professionals and international litigators. We have established relationships with an extensive network of foreign law firms and experts, ensuring the timely delivery of reliable and accurate foreign legal advice when necessary. We also partner with and direct third-party service providers when appropriate.

Our spectrum of services includes:
  • Strategic advice: We provide organizational-level advice, enterprise-wide consistency, compliance with regulatory and legal requirements, and informed prospective guidance for year-on-year success – even when confronting drastic technological and client compositional changes. Advice requires understanding, and our combined interview and investigative approach begins by showing clients where they stand before solutions are provided.
  • Information management – technology and solutions: Our professionals work closely with clients and BakerHostetler’s information technology and transactions teams to develop requests for proposals, select appropriate vendors and solutions, and execute safeguards for the use of those solutions.
  • Information use – policies and schedules: We advise clients on information governance policies and schedules, the creation and modification of those policies, and the maintenance and overhauling of related schedules. Proper policies and schedules provide clear instructions for handling personal and client information, a standard for audit and improvement initiatives, and a foundation for new internal technologies and processes.
More »
  • Prospective corporate activity: We provide due diligence in the context of mergers, acquisitions, asset purchases and divestitures to extract information of value; to assist with legal hold requirements; to help plan IT investment and data migration projects; and to harmonize information governance policies and schedules in a cost-effective way.
  • Corporate audit: We assess information governance practices for information management, security and client contractual obligation gaps.
  • Legacy remediation: We perform legacy remediation projects in the context of clients’ information governance policies and schedules, existing legal hold requirements, internal informational data analytic initiatives, and risk tolerances. We supervise the appropriate disposal of information as well as the proper categorization and intelligent use of information through new technologies and processes.
  • Expert, officer and employee training: We assist clients with the preparation of 30(b)(6), state analogue, and other expert and client-representative witnesses for client information governance practices. Likewise, we train client officers and employees on the proper operation of information governance policies and schedules and their intersection with data privacy, data security and e-discovery issues.
  • Special projects: Multinational clients demand additional knowledge and varied experience. Our multidisciplinary teams combine significant multinational experience to address cross-discipline information governance projects that involve data privacy, data security, e-discovery and information analytics issues.

Select Experience

  • Provided records policy guidance and advice to a multinational organization with offices in 30 countries and an operational footprint in 130 countries; provided additional technological analysis for records associated with communications technologies and bring your own device (BYOD) initiatives.
  • Advised on deal structure considerations involving information governance, cross-border transfer and data disambiguation issues for a multinational organization’s stock-purchase acquisition of a United States company. The acquisition focused on a substantial customer database and related document management and permissions issues.
  • Engaged in comprehensive records policy and schedule drafting, revision and deployment to a technology provider of mobile, telephone and web communication services; revamped then-current processes, working closely with the legal department through a multistage, iterative project.
  • Provided a nonprofit housing authority with revisions and guidance to existing records and information governance practices – including staffing direction and compliance considerations – during business transformation and restructuring processes.
More »

Experience

  • Provided records policy guidance and advice to a multinational organization with offices in 30 countries and an operational footprint in 130 countries; provided additional technological analysis for records associated with communications technologies and bring your own device (BYOD) initiatives.
  • Advised on deal structure considerations involving information governance, cross-border transfer and data disambiguation issues for a multinational organization’s stock-purchase acquisition of a United States company. The acquisition focused on a substantial customer database and related document management and permissions issues.
  • Engaged in comprehensive records policy and schedule drafting, revision and deployment to a technology provider of mobile, telephone and web communication services; revamped then-current processes, working closely with the legal department through a multistage, iterative project.
  • Provided a nonprofit housing authority with revisions and guidance to existing records and information governance practices – including staffing direction and compliance considerations – during business transformation and restructuring processes.
  • Provided an information governance policy and supporting strategy in conjunction with a legal hold process and documentation for a multinational consumables retailer and provider of data analytic services. Reviewed and provided guidance on specific record retention schedule issues.
  • Consulted on cross-border transfer, data hosting and storage, and information governance advice for a multinational technology organization considering human resources data hosting and consolidation efforts for Latin American operations.
  • Advised on information governance and related privacy considerations and representations for a proposed energy company venture and a domestic online consumer lending program.
  • Provided a multistate restaurant holding organization with a record retention policy and schedule guidance on human resources, payroll, OSHA, financial, legal, tax, risk management and project development issues.
  • Provided information governance advice in conjunction with an information security review and recommendations for a nonprofit healthcare services organization.
  • Provided information governance, record retention policy and schedule, and related policy documentation for an energy company’s operations, structured data and device data flows, and employee BYOD considerations.
  • Constructed bottom-up information governance and legal hold regimens, integrating policies and a records retention schedule and social media considerations into a multinational, varied operation business conglomerate seeking to mitigate risk, increase business intelligence and smooth cross-company business operations.
  • Advised a healthcare organization considering application of business associate agreement requirements to existing information governance practices, regulatory retention periods and associated legal hold considerations.

Recognition

  • Chambers USA: Nationwide Privacy & Data Security (2013 to 2018)
    • Chambers USA Privacy and Data Security - Healthcare Spotlight Table (2018)
  • Recognized as one of the top law firms for client service, BakerHostetler was named to the 2020 BTI Client Service 30 for the sixth consecutive year.

News

Publications

Key Contacts

Blog

In The Blogs

Previous Next
Data Counsel
What to Expect on Privacy with a New Democratic Majority at the FTC
By Daniel Kaufman
June 20, 2022
It has been just over one year since Lina Khan was confirmed by the Senate and designated Federal Trade Commission (FTC) chair by the president. At the outset of her tenure, she had a Democratic majority, which ended in October 2021 when...
Read More ->
Data Counsel
DSIR Deeper Dive into the Data: Ransomware Front and Center
By Joseph L. Bruemmer, Elise R. Elam
June 16, 2022
There is no question that ransomware is here to stay. Thirty-seven percent of the matters we handled last year involved ransomware, compared to 27 percent of matters in 2020. In 2019, there were approximately 15 active ransomware threat...
Read More ->
Data Counsel
If it's broke, just fix it…: Curing Alleged CCPA Violations
By Casie D. Collignon, Colby M. Everett, Robyn M. Feldstein
June 14, 2022
Courts across the United States continue to grapple with California’s landmark consumer privacy law, the California Consumer Privacy Act (CCPA). While the contours of this law are being litigated on multiple fronts, one important, but not...
Read More ->
Data Counsel
CPPA Begins CPRA Rulemaking
By Jennifer L. Mitchell, Jeewon K. Serrato, Justin T. Yedor
June 2, 2022
On May 26, 2022, the California Privacy Protection Agency (CPPA or the Agency) held a public board meeting to provide updates on the Agency’s rulemaking process. The next day, the CPPA released draft regulations for the California Privacy...
Read More ->
Data Counsel
North Carolina is the First State to Prohibit Public Entities from Paying Ransoms: What Does This Mean for North Carolina Public Schools and Universities?
By Elise R. Elam, Benjamin D. Wanger
May 19, 2022
On April 5th, North Carolina became the first state to prohibit state agencies and local governments from paying ransoms after becoming victims of a ransomware attack. Indeed, in addition to prohibiting said entities from paying ransoms...
Read More ->