Privacy Governance and Technology Transactions

Overview

Strong, proactive privacy governance and technology strategy is vital to every business today. Our national team counsels clients on how to reduce or eliminate risk through rigorous review of policies that may pose privacy and security risks, as well advises on strategic acquisitions of technology.

We work with the key personnel who have responsibility for privacy and security and for technology infrastructure, including chief information and privacy officers, marketing team leaders, compliance officers, finance leaders and in-house legal teams. Our incident response experience and regulatory knowledge mean we are uniquely qualified to examine both internal and privacy governance policies. Our deep understanding of technology positions us to advise clients regarding the best practices for technology transactions, including negotiating agreements regarding cloud services and technology infrastructure as well as data ownership and other key issues that arise when companies do business together.

Regulatory Defense

We advise clients on how to develop and maintain consumer privacy programs. In addition, we help clients assess privacy impacts and employ privacy by design to balance commercial and consumer interests and to craft transparent, accurate and customer-friendly notices regarding data practices.

Our deep experience and relationships with state attorneys general and other regulatory officials allow us to deal efficiently with investigatory inquiries, often resulting in positive dispositions, including the conclusion of investigations without any charges being brought.

Our experience encompasses:
  • California Consumer Privacy Act (CCPA) and other state privacy laws.
  • General Data Protection Regulation (GDPR).
  • Attorney General privacy investigations related to data collection and use.
  • Data localization and retention laws.
  • The Children’s Online Privacy Protection Act (COPPA).
  • Gramm Leach Bliley Act (GLBA).
  • Telephone Consumer Protection Act (TCPA) and Controlling the Assault of Non-Solicited Pornography and Marketing Act compliance.
  • Federal Trade Commission matters.
  • The Fair Credit Reporting Act. (FCRA).
More »
Technology Contracts
  • Our team has a well-grounded understanding of transactions involving the use, licensing, acquisition and commercialization of data and technology. We review, negotiate and draft agreements and agreement provisions regarding:
  • Cloud computing.
  • Data ownership and data protection.
  • The PCI Data Security Standard and protected health information.
  • Service level agreements.
  • Software.
  • Hardware.
  • Mobile data and commerce.
  • E-commerce.
  • Back offices and infrastructure.
  • Outsourcing.

We handle agreements involving all forms of cloud service (SaaS, IaaS, PaaS), video game development, mobile apps, music distribution, geolocation, payment processing, fraud prevention, data analytics and digital advertising.

In addition, as companies everywhere undergo digital transformation, our team offers guidance on where opportunities and vulnerabilities lie and assists in designing plans to manage, protect and leverage your digital assets, including Big Data, predictive analysis, machine learning, robotics, the Internet of Things (IoT), and voice, text and vision recognition.

GDPR and CCPA

We provide comprehensive advice regarding the EU’s General Data Protection Regulation (GDPR) and the new California Consumer Privacy Act (CCPA), including:

  • Compliance readiness assessments.
  • Compliance program development and implementation.
  • Inventory data and mapping data flows.
  • Privacy and data security assessments to prepare for the impact of the private right of action arising from security incidents.
  • Risk management.
  • Tracking legislative and regulatory developments.
  • Vendor contract drafting and review.
  • Identifying, engaging and managing IT consultants and solutions.

Select Experience

Privacy Governance
  • Counseled hundreds of companies on developing, implementing and maintaining privacy programs and complying with applicable data protections laws, including the CCPA.
  • Representing the interests of multiple clients in the digital advertising sector while working with the Internet Advertising Bureau to help develop a policy framework, multiparty agreement and technical signal program that will allow publishers and advertisers to integrate their CCPA “do not sell” requests with internet-based advertising technologies.
Technology Transactions
  • Representing an insurance company in its multimillion-dollar multiparty cloud and software services agreements.
  • Supporting a large healthcare system as lead technology and intellectual property counsel; advising the organization in more than $50 million worth of technology acquisitions.
More »

Professionals

Name Title Office Email
Associate Atlanta
Associate New York
Partner Atlanta
Associate Costa Mesa
Partner New York
Partner Atlanta
Partner Cleveland
Partner Atlanta
Partner Atlanta
Associate San Francisco
Associate New York
Partner New York
Partner New York
Partner New York
Associate Atlanta
Partner Atlanta
Partner Seattle
Partner New York
Associate Seattle
Partner New York
Partner Philadelphia
Associate Los Angeles
Associate Atlanta
Partner Philadelphia
Partner San Francisco
Partner New York
Partner Washington, D.C.
Associate New York
Partner Cincinnati
Associate Los Angeles
Partner Atlanta

Experience

Privacy Governance
  • Counseled hundreds of companies on developing, implementing and maintaining privacy programs and complying with applicable data protections laws, including the CCPA.
  • Representing the interests of multiple clients in the digital advertising sector while working with the Internet Advertising Bureau to help develop a policy framework, multiparty agreement and technical signal program that will allow publishers and advertisers to integrate their CCPA “do not sell” requests with internet-based advertising technologies.
  • Advising numerous clients regarding compliance with international data transfer restrictions and data localization requirements. Additionally, we developed and implemented GDPR compliance programs for U.S. and international organizations, including applicability analysis, data mapping, data transfer mechanisms, consent mechanisms, “right to be forgotten,” data security assessments, breach response programs, the selection of Data Protection Officers and employee training.
  • Served as lead privacy counsel to a cutting-edge healthcare funding provider; provided a 50-state analysis of the privacy landscape for the company.
Technology Transactions
  • Representing an insurance company in its multimillion-dollar multiparty cloud and software services agreements.
  • Supporting a large healthcare system as lead technology and intellectual property counsel; advising the organization in more than $50 million worth of technology acquisitions.
  • Acting as lead counsel to a minerals and material solutions provider, evaluating and mitigating the risks of third-party installation of IoT tracking technologies for assets management.
  • As privacy counsel to a global public relations and earned media software company, led the organization through multiple acquisitions of portfolio companies and conducted privacy diligence for a number of transactions.
  • Advised a healthcare customer-relationship management company on commercial transactions and the development of a privacy and data strategy, navigating HIPAA compliance and regulations.

Recognition

  • BTI Cybersecurity Powerhouse (2020)
  • BTI CyberSavvy Law Firm (2020)
  • Chambers Global
    • Privacy & Data Security (USA) (2014 to 2021)
    • Privacy & Data Security: Healthcare Spotlight Table – Nationwide (2018 to 2021)
  • Chambers Fintech
    • Legal – USA (2018 to 2020)
  • Chambers USA
    • Advertising: Transactional & Regulatory – Nationwide (2018 to 2020)
    • Privacy & Data Security – Nationwide (2013 to 2020)
    • Privacy & Data Security: Healthcare Spotlight Table – Nationwide (2018 to 2020)
  • Chambers USA Award: “Privacy & Data Security Team of the Year” finalist (2015, 2017)
  • The Legal 500 United States
    • Media, Technology and Telecoms: Advertising and Marketing: Transactional and Regulatory (2018 to 2020)
    • Media, Technology and Telecoms: Cyber Law (2016 to 2020)
    • Media, Technology and Telecoms: Data Privacy and Data Protection (2016 to 2020)
  • Law360: Privacy "Practice Group of the Year" (2013 to 2015, 2018)

News

News

Press Releases

Blog Posts

Blog

In The Blogs

Previous Next
Data Counsel
Private Right of Action May Again Poison Washington Privacy Act
By Andreas T. Kaltsounis
March 30, 2021
On March 26, with less than a month left in the Washington Legislature’s 2021 session, the House Civil Rights and Judiciary Committee (CRJC) passed the Washington privacy act (2SSB 5062), with amendments, on a straight party-line vote of...
Read More ->
Data Counsel
International Data Protection Update – First Quarter 2021
By Andreas T. Kaltsounis, Melinda L. McLellan, Nichole L. Sterling
March 29, 2021
This quarterly update highlights some of the international data protection issues that have caught our attention, and the attention of our clients, in the past three months. Europe, the Middle East and Africa Cookies and Tracking...
Read More ->
Data Counsel
Virginia Becomes the Second State with a Comprehensive Privacy Law
By Patrick R. Waldrop
March 2, 2021
Governor Ralph Northam has signed the Consumer Data Protection Act (CDPA), making Virginia the second state with a comprehensive privacy law. The CDPA is inspired by both the California Consumer Privacy Act (CCPA) and General Data...
Read More ->
Data Counsel
New EDPB Draft Guidance Provides Practical Scenarios for Data Breach Notification Analysis Under the GDPR
By Michael E. Fitzgerald, Benjamin D. Wanger
February 19, 2021
In certain cases, the General Data Protection Regulation (GDPR) requires entities that experience a personal data breach to provide notice of the incident to relevant national supervisory authorities and the individuals whose personal data...
Read More ->
Data Counsel
Virginia Poised to Enact the Consumer Data Protection Act, the Nation's Second Comprehensive Consumer Privacy Law
By Patrick R. Waldrop
February 17, 2021
Having passed both houses of the Virginia General Assembly, the proposed Consumer Data Protection Act (CDPA) may become the second comprehensive consumer privacy bill to be enacted in the United States. However, to reach the governor’s...
Read More ->