Privacy & Cybersecurity
While news headlines demonstrate the daily risks associated with handling data, smart companies know the mastery of privacy and cybersecurity can be a market differentiator. From day-to-day protective measures to navigating the increasing complexity of the global regulatory landscape, companies have the opportunity to protect their assets and their brands by properly collecting, processing, and transmitting data.
HOW WE HELP
Seyfarth’s Privacy & Cybersecurity team advises clients on cutting-edge topics—from automotive telematics, to the Internet of Things, big data, and usage-based insurance—as well as the latest US and international regulations. In particular, General Data Protection Regulation (GDPR)—the most significant change in data privacy regulation in the past 20 years—continues to have far-reaching impact, and our attorneys have been at the forefront of this issue, preparing clients for compliance and assisting with ongoing concerns.
Our attorneys provide a thoughtful, holistic approach to addressing clients’ privacy- and cybersecurity-related needs. Seyfarth’s team understands that data privacy and cybersecurity is a complex and multidimensional business issue that demands an integrated, cross-departmental approach to compliance, incident management, litigation, and vendor and technology transactions services.
Leading companies across diverse industries—including financial institutions, hotel franchisees, transportation companies, real estate management firms, software-as-a-service providers, health care and life sciences companies, consumer electronics manufacturers, grocery stores, and online retailers—have enlisted our Privacy & Cybersecurity team for guidance on these mission-critical areas of business.
OUR SERVICES
Compliance. Our attorneys prevent issues by creating comprehensive internal practices and policies aimed at regulatory compliance. With experience developing policies and procedures for clients doing business in every corner of the world, the team counsels employers and consumer-focused companies on domestic and international data compliance programs.
Incident Management. The unauthorized disclosure or use of information requires a quick yet thoughtful response. Seyfarth’s rapid-response team stands at the ready to investigate such incidents and assess clients' responsibilities under applicable domestic and international laws and contracts. In the event of a breach related to personal information, our attorneys advise on communicating with law enforcement, regulators, consumer reporting agencies, and the public. Our Privacy & Cybersecurity team also develops appropriate remedial measures to guard against a similar breach down the road.
Litigation. Cybersecurity breaches often lead to litigation. Our Privacy & Cybersecurity attorneys defend clients in actions brought by civil plaintiffs and regulators—including local data protection authorities, the Federal Trade Commission, and state attorney generals—as well as litigate issues arising from computer and e-mail hacking. Beyond cybersecurity breaches, our experienced team litigates other types of privacy issues, such as obtaining information regarding anonymous/pseudonymous parties from Internet service providers and in building cases involving defamation, misappropriation, disparagement, and spoofing on websites.
Vendor & Technology Transactions. Our team advises the world’s largest companies—as well as innovative startups and emerging growth companies—on the data privacy and cybersecurity issues inherent in technology transactions and related contracts, from complex multinational sourcing and joint venture arrangements to mergers and acquisitions.
THE SEYFARTH EXPERIENCE
Our attorneys provide both the technological proficiency and legal knowledge needed to evaluate a company’s data privacy and cybersecurity practices. With backgrounds in data security and encryption, our team helps clients proactively prevent data breaches and implement effective remediation strategies if a breach occurs. Seyfarth’s tech-savvy attorneys have the skills to handle the forensic analysis essential to the breach management process and can tap into valuable vendor relationships for additional support when needed.
Our team frequently collaborates with Seyfarth’s world-class professionals in health care, electronic discovery, corporate transactions, and labor and employment to deliver seamless, comprehensive data privacy and cybersecurity solutions with a highly integrated, cross-functional approach.
To see our team in action, watch this video produced in collaboration with the American Health Law Association on the topic of Health Law Disruption: Cybersecurity and Emerging Data Risks.
Examples of our recent work include:
- Advised a commercial manufacturer that had experienced several cyberattacks. We managed the overall approach to incident response including containment, remediation, indicators of compromise, legal obligations, management-level briefings, and public relations related issues. We also led an overall cyber maturity assessment for the organization and provide ongoing cyber advice to the client.
- Advised an employee screening company that had experienced a cyberattack. We managed the overall approach to incident response arising from a cyberattack, including containment, remediation, indicators of compromise, legal obligations, management-level briefings, public relations and related issues.
-
Assisted a US-based global manufacturer of electronic instruments and electromechanical devices with more than 220 manufacturing sites worldwide to bring its EU operations into GDPR compliance. Our team developed a GDPR compliance program to support the processing of HR-related personal data in the US, in a centralized manner.
- Advised a US multinational engineering and construction company on a global privacy project that involved assessing the client’s flows of personal data across its global operations—spanning more than 50 countries in Europe, Asia, North America, Latin America, the Middle East, and Africa—and designing and implementing a compliance program to ensure the lawful cross-border transfer of the data.
- Advised a multinational corporation in the memory technology industry on a global data protection project that involved auditing the company’s collection, use, transfer, disclosure, and retention of human resources data among its operations throughout Asia, Europe, North and Latin America, and the Middle East, and formulating a strategy to ensure the company’s lawful cross-border transfer of that data.
- Conducted a security breach analysis for a major health plan, which involved an extensive investigation, HIPAA risk analysis, and state database security breach analysis involving a short-term computer system vulnerability that was not exploited and was ultimately determined not to be a breach under applicable laws.
- Advised a client who had experienced a HIPAA privacy breach by a third-party administrator with regard to mitigating the damage and documenting the breach in an investigative report, as well as represented the company with regard to the third-party administrator’s breach of the business associate agreement. The incident resulted in an employee filing a privacy complaint with Health and Human Services/Office of Civil Rights, which the client was able to close with no penalties by producing the investigation report and other documentation prepared by Seyfarth’s Privacy & Security team.
- Negotiated and completed the outsourcing agreements for a financial services company for offshore vendors to provide business process services, including the security and privacy of customer financial and other protected information.
-
Aided multiple clients in maturing their cyber programs through a variety of methods including maturity assessments, red team penetration, audits, table top exercises and other activities.
-
Managed the investigation and response and dealt with issues arising from a systems comprise for a client that experienced a systems breach by a former IT employee.
-
Developed scenarios and managed attacks for a client that desired to extensively test their systems through sophisticated red team activities, simulating attackers of varying skills sets.
-
Represented a HR services and technology client in its $426 million CDN acquisition of a leading global EAP and wellness provider. The deal included a significant data protection component due to the target company's industry and jurisdiction (Canada), which has strong data protection laws.
Related Trends
Related News & Insights
-
Speaking Engagement
11/21/2024
Kathleen McConnell and Jaime Raba to Present at Global GRC, Data Privacy & Cyber Security ConfEx
-
Blog Post
08/07/2024
Malaysian Parliament Passes Personal Data Protection (Amendment) Bill 2024
-
Webinar
05/21/2024
British Chamber of Commerce in Hong Kong Webinar: Seyfarth Presents the Global Data Privacy and Cybersecurity Landscape
-
Seyfarth Event
05/21/2024
Seyfarth Privacy Salon: Roundtable on Cross-Border Data Transfers, Privacy, and Cybersecurity
Recognition
-
Recognition
10/17/2024
Seyfarth Recognized for Multiple Litigation Honors, Including “Powerhouse,” in 2025 BTI Litigation Outlook
-
Recognition
08/17/2023
210 Seyfarth Attorneys Chosen as Leaders in Their Fields by Best Lawyers in America 2024
-
Recognition
06/08/2022
Seyfarth Earns Top Rankings in Legal 500 US 2022
-
Recognition
02/08/2022
Clients Name Seyfarth Lawyers to 2022 BTI Client Service All-Star Team
While news headlines demonstrate the daily risks associated with handling data, smart companies know the mastery of privacy and cybersecurity can be a market differentiator. From day-to-day protective measures to navigating the increasing complexity of the global regulatory landscape, companies have the opportunity to protect their assets and their brands by properly collecting, processing, and transmitting data.
HOW WE HELP
Seyfarth’s Privacy & Cybersecurity team advises clients on cutting-edge topics—from automotive telematics, to the Internet of Things, big data, and usage-based insurance—as well as the latest US and international regulations. In particular, General Data Protection Regulation (GDPR)—the most significant change in data privacy regulation in the past 20 years—continues to have far-reaching impact, and our attorneys have been at the forefront of this issue, preparing clients for compliance and assisting with ongoing concerns.
Our attorneys provide a thoughtful, holistic approach to addressing clients’ privacy- and cybersecurity-related needs. Seyfarth’s team understands that data privacy and cybersecurity is a complex and multidimensional business issue that demands an integrated, cross-departmental approach to compliance, incident management, litigation, and vendor and technology transactions services.
Leading companies across diverse industries—including financial institutions, hotel franchisees, transportation companies, real estate management firms, software-as-a-service providers, health care and life sciences companies, consumer electronics manufacturers, grocery stores, and online retailers—have enlisted our Privacy & Cybersecurity team for guidance on these mission-critical areas of business.
OUR SERVICES
Compliance. Our attorneys prevent issues by creating comprehensive internal practices and policies aimed at regulatory compliance. With experience developing policies and procedures for clients doing business in every corner of the world, the team counsels employers and consumer-focused companies on domestic and international data compliance programs.
Incident Management. The unauthorized disclosure or use of information requires a quick yet thoughtful response. Seyfarth’s rapid-response team stands at the ready to investigate such incidents and assess clients' responsibilities under applicable domestic and international laws and contracts. In the event of a breach related to personal information, our attorneys advise on communicating with law enforcement, regulators, consumer reporting agencies, and the public. Our Privacy & Cybersecurity team also develops appropriate remedial measures to guard against a similar breach down the road.
Litigation. Cybersecurity breaches often lead to litigation. Our Privacy & Cybersecurity attorneys defend clients in actions brought by civil plaintiffs and regulators—including local data protection authorities, the Federal Trade Commission, and state attorney generals—as well as litigate issues arising from computer and e-mail hacking. Beyond cybersecurity breaches, our experienced team litigates other types of privacy issues, such as obtaining information regarding anonymous/pseudonymous parties from Internet service providers and in building cases involving defamation, misappropriation, disparagement, and spoofing on websites.
Vendor & Technology Transactions. Our team advises the world’s largest companies—as well as innovative startups and emerging growth companies—on the data privacy and cybersecurity issues inherent in technology transactions and related contracts, from complex multinational sourcing and joint venture arrangements to mergers and acquisitions.
THE SEYFARTH EXPERIENCE
Our attorneys provide both the technological proficiency and legal knowledge needed to evaluate a company’s data privacy and cybersecurity practices. With backgrounds in data security and encryption, our team helps clients proactively prevent data breaches and implement effective remediation strategies if a breach occurs. Seyfarth’s tech-savvy attorneys have the skills to handle the forensic analysis essential to the breach management process and can tap into valuable vendor relationships for additional support when needed.
Our team frequently collaborates with Seyfarth’s world-class professionals in health care, electronic discovery, corporate transactions, and labor and employment to deliver seamless, comprehensive data privacy and cybersecurity solutions with a highly integrated, cross-functional approach.
To see our team in action, watch this video produced in collaboration with the American Health Law Association on the topic of Health Law Disruption: Cybersecurity and Emerging Data Risks.
Related Key Industries
Blogs
-
Health Care Privacy and Data Security
Health Care Privacy and Data Security
Examples of our recent work include:
- Advised a commercial manufacturer that had experienced several cyberattacks. We managed the overall approach to incident response including containment, remediation, indicators of compromise, legal obligations, management-level briefings, and public relations related issues. We also led an overall cyber maturity assessment for the organization and provide ongoing cyber advice to the client.
- Advised an employee screening company that had experienced a cyberattack. We managed the overall approach to incident response arising from a cyberattack, including containment, remediation, indicators of compromise, legal obligations, management-level briefings, public relations and related issues.
-
Assisted a US-based global manufacturer of electronic instruments and electromechanical devices with more than 220 manufacturing sites worldwide to bring its EU operations into GDPR compliance. Our team developed a GDPR compliance program to support the processing of HR-related personal data in the US, in a centralized manner.
- Advised a US multinational engineering and construction company on a global privacy project that involved assessing the client’s flows of personal data across its global operations—spanning more than 50 countries in Europe, Asia, North America, Latin America, the Middle East, and Africa—and designing and implementing a compliance program to ensure the lawful cross-border transfer of the data.
- Advised a multinational corporation in the memory technology industry on a global data protection project that involved auditing the company’s collection, use, transfer, disclosure, and retention of human resources data among its operations throughout Asia, Europe, North and Latin America, and the Middle East, and formulating a strategy to ensure the company’s lawful cross-border transfer of that data.
- Conducted a security breach analysis for a major health plan, which involved an extensive investigation, HIPAA risk analysis, and state database security breach analysis involving a short-term computer system vulnerability that was not exploited and was ultimately determined not to be a breach under applicable laws.
- Advised a client who had experienced a HIPAA privacy breach by a third-party administrator with regard to mitigating the damage and documenting the breach in an investigative report, as well as represented the company with regard to the third-party administrator’s breach of the business associate agreement. The incident resulted in an employee filing a privacy complaint with Health and Human Services/Office of Civil Rights, which the client was able to close with no penalties by producing the investigation report and other documentation prepared by Seyfarth’s Privacy & Security team.
- Negotiated and completed the outsourcing agreements for a financial services company for offshore vendors to provide business process services, including the security and privacy of customer financial and other protected information.
-
Aided multiple clients in maturing their cyber programs through a variety of methods including maturity assessments, red team penetration, audits, table top exercises and other activities.
-
Managed the investigation and response and dealt with issues arising from a systems comprise for a client that experienced a systems breach by a former IT employee.
-
Developed scenarios and managed attacks for a client that desired to extensively test their systems through sophisticated red team activities, simulating attackers of varying skills sets.
-
Represented a HR services and technology client in its $426 million CDN acquisition of a leading global EAP and wellness provider. The deal included a significant data protection component due to the target company's industry and jurisdiction (Canada), which has strong data protection laws.
Related Trends
Related News & Insights
-
Speaking Engagement
11/21/2024
Kathleen McConnell and Jaime Raba to Present at Global GRC, Data Privacy & Cyber Security ConfEx
-
Blog Post
08/07/2024
Malaysian Parliament Passes Personal Data Protection (Amendment) Bill 2024
-
Webinar
05/21/2024
British Chamber of Commerce in Hong Kong Webinar: Seyfarth Presents the Global Data Privacy and Cybersecurity Landscape
-
Seyfarth Event
05/21/2024
Seyfarth Privacy Salon: Roundtable on Cross-Border Data Transfers, Privacy, and Cybersecurity
Recognition
-
Recognition
10/17/2024
Seyfarth Recognized for Multiple Litigation Honors, Including “Powerhouse,” in 2025 BTI Litigation Outlook
-
Recognition
08/17/2023
210 Seyfarth Attorneys Chosen as Leaders in Their Fields by Best Lawyers in America 2024
-
Recognition
06/08/2022
Seyfarth Earns Top Rankings in Legal 500 US 2022
-
Recognition
02/08/2022
Clients Name Seyfarth Lawyers to 2022 BTI Client Service All-Star Team