Data Privacy and Security

Members of our data privacy and security team include more than 30 interdisciplinary lawyers on the front lines of this rapidly evolving area of the law. We provide proactive counseling designed to protect the integrity of our clients’ systems, investigative and remediation services that may be required after a breach, and guidance to assist our clients as they develop new relationships and sources of revenue. Whatever the context, the team possesses the experience and professional networks necessary to address all our clients’ global needs in the area of data privacy and security.

Data Privacy Team Overview

Our team includes experienced intellectual property counsel, class action litigators and technology industry professionals to assist clients with transactional matters as well as instances where an alleged breach has led to litigation. Through McGuireWoods Consulting, we also offer lobbying services to ensure that our clients have a voice in shaping precedent-setting and far-reaching legislation. Our goal is to provide a comprehensive solution for our clients by working not only with their lawyers, but also with IT staff, human resources professionals and product specialists. This approach permits us to deliver integrated services that promote information-sharing within the organization and account for the interests of all stakeholders.

Team members regularly advise clients dealing with cybercrime and inadvertent breaches. Further, as new and multiple uses for technology emerge, we help clients respond to unforeseen consequences that require immediate action. As such, team members have become globally recognized legal resources in this practice area, with many clients hailing from diverse industries, including education, energy, financial services, healthcare, insurance and retail, among others.  

International Practice

Because global commerce recognizes no boundaries, the team’s Data Privacy and Security clients rely heavily on our deep international experience. Our team’s international practice helps clients secure their data globally, and navigate through U.S. (federal and state), Canadian, European, Middle Eastern and Asian data security and privacy laws. Team attorneys collectively speak 13 languages and respond to matters relating to international cloud computing, data transfer and international e-discovery matters.

Incident Response

In the event of a breach or other security matter, it is essential to be able to mobilize a broad-based response that includes resources outside of the client and our firm. Our data privacy and security team, which includes several former federal prosecutors, draws upon the resources of a large, external support network composed of qualified computer forensic examiners and law enforcement agents around the world. Among these resources are high-level technical subject matter experts and liaisons with the FBI, U.S. Secret Service, Postal Inspectors, New Scotland Yard and the big four international accounting firms. This network is further expanded through active memberships in InfraGard (FBI) and the Federal Electronic Crimes Task Force (U.S. Secret Service).

Director and Officer Protection

Our team is keenly aware of the dangers that security breaches pose to an organization as a whole, as well as the exposure of directors and officers in the event of such breaches. Therefore, a fundamental part of our practice is regularly counseling directors and executive officers on what they do and don't need to know, what the risks are of not knowing, and procedures and tips for how to stay educated and abreast of regulatory and hostile technology developments within and outside of their organizations. Whatever the risk profile of the company, we help ensure that the individual directors and officers are taking appropriate measures to faithfully fulfill their fiduciary duties, thereby protecting themselves as well as the companies they represent.

Areas of Experience

  • Comprehensive Information Governance program development
  • Data breach compliance, response and remediation, including media relations
  • Proactive data protection audits
  • Cross-border data transfer compliance, including the EU/U.S. Privacy Shield
  • M&A/private equity counseling
  • Vendor contract development and negotiation
  • Privacy policy management
  • HIPAA and state health records laws
  • Cyber insurance counseling
  • Legislative tracking, analysis and lobbying (in partnership with McGuireWoods Consulting)
  • Forensics and technical systems planning (in partnership with forensic consultants)
  • Cybersecurity crisis management

Included in team member credentials are:

  • Chair of the firm’s transactional Intellectual Property practice. Her experience includes auditing and evaluating client data security policies, drafting website privacy policies, negotiating cloud computing agreements from both the vendor and customer perspectives, and providing support in the aftermath of a data breach, including compliance with breach-notification laws.
  • Two Brussels-based partners are members of the European Privacy Association (EPA), a pan-European network of privacy, data protection and security experts, which works closely with the EU institutions. These partners both have experience in all privacy-related issues involving national data protection authorities and EU institutions, as well as broad experience in regulatory issues such as cloud computing, data transfers, coordination with foreign discovery or antibribery teams, interactions with intellectual property rights, re-use of public sector information, employee monitoring, and privacy audits.
  • A London-based partner with extensive experience in European regulatory issues, including data protection and security; cross-border data transfer; privacy; encryption; export controls; technology and EU public procurement regulations. One recent focus has been on technology transfer and regulation in the banking and financial markets sectors.
  • Chair of the firm’s Supply Chain practice, an experienced data privacy and security lawyer, who routinely counsels clients on protective measures to employ in the construction of policies and critical contracts in order to prevent security breaches, investigations, lawsuits and similar harmful events. He focuses on a variety of matters, including data storage, cloud computing and social-media risks and has particular knowledge of the Payment Card Industry Data Security Standards.
  • Fifteen members who hold either the CIPP/U.S. or CIPP/E certification as Certified Information Privacy Professionals from the International Association of Privacy Professionals (IAPP).  
Data Privacy and Security 19401080 istock

CONTACTS

C. Andrew Konia Partner T: +1 703 712 5071
Results 1-20 of 28
Show All

RESULTS DEPEND ON A VARIETY OF FACTORS UNIQUE TO EACH CASE. PRIOR RESULTS DO NOT GUARANTEE OR PREDICT A SIMILAR OUTCOME.

Representative Matter

Voluntary dismissal of TCPA class action involving “one-click” dialing

Secured the voluntary dismissal of a putative TCPA class action against a market research company after convincing plaintiff’s counsel through informal discovery that the cell phone calls at issue were not placed by an ATDS.
Representative Matter

A2 Access LLC

Representation of A2 Access LLC, a leader in corporate access information, in connection with its sale to Dealogic.
Representative Matter

Client

Advising a client concerning the transfer of personal data from EU to the U.S. to comply with U.S. regulatory rules relating to a contract with the U.S. government.
Representative Matter

Communications company

Advising a company on all aspects of IT security and data protection compliance in its negotiation with its main IT service provider.
Representative Matter

International group

Advising an international group concerning the data protection compliance of an internal HR network.
Representative Matter

International group

Advising an international group concerning the data protection compliance of its e-commerce website (privacy notice, cookies, transfer of personal data to third parties for direct marketing purposes, etc.).
Representative Matter

Data protection compliance

Advising multinationals in the implementation of corporate-wide compliance with the EU data protection directive, for instance concerning Human Resources Management systems.
Representative Matter

U.S. export controls and EU data protection rules governing whistleblowing

Advising a large international chemicals manufacturer on the interaction between US export control rules and EU data protection law, and how to export to the US data relating to EU employees in order to comply with a US obligation to report crimes by company employees.
Representative Matter

Credit card issuer

Advice to a credit card issuer in IT and data protection compliance.
Representative Matter

German company

Advice to a German company concerning direct marketing operation in some European countries and in the United States.
Representative Matter

International counsel

Advice to international counsel as part of a team of U.S. and European lawyers, on a data breach investigation and reporting.
Representative Matter

U.S. company

Advice to a U.S. company concerning the introduction of a whistleblowing scheme in several Belgian entities.
Representative Matter

U.S. telecom operator

Advice to a U.S. telecom operator concerning a project that will collect automobilists' personal data in France in order to offer them various services.
Representative Matter

Fortune 500 wireless carrier

Assisting a Fortune 500 wireless carrier with evaluation of device financing proposals for postpaid and prepaid brands.
Representative Matter

International counsel

Advice to international counsel on direct marketing operation in France.
Case Study

Los Angeles and Pittsburgh teams secure win for GNC

In a case profiled in National Law Journal, McGuireWoods defeated a motion for class certification in an action brought against General Nutrition Corporation (GNC) in the U.S. District Court for the Central District of California alleging violations of California Civil Code section 1747.08 (the Song-Beverly Credit Card Act).

The Song-Beverly Credit Card Act (the "Act") was intended to stop businesses from gathering and storing unnecessary personal information from their consumers. The California Legislature passed the Act to address two important privacy concerns. First, corporations were needlessly storing consumer information and using it for their own marketing purposes or selling the information to other marketers. Second, store clerks who obtained customers' personal information engaged in acts of harassment and violence.

Representative Matter

European association

Advice to a European association on processing of sensitive data (judicial data) in matter of inside betting.
Representative Matter

Food and beverage company

Advice to a food and beverage company on data transfers for an US discovery procedure.
Representative Matter

Regional tourism promotion institution

Coordinating national compliance (inside and outside the EU) and data transfer from the EU to the United States and Japan for a regional tourism promotion institution.
Representative Matter

Consultant company

Advising a consultant company on IT breach tests and audits.
Results 1-20 of 28
Results 1-25 of 52
Show All
Mike Adams Michael J. Adams
Partner - Not admitted in NC; has applied for admission by motion
201 North Tryon Street
Suite 3000
Charlotte, NC 28202-2146

T: +1 704 373 8847
F: +1 704 444 8747
vCard
Vassilis Akritidis Vassilis Akritidis
Partner
rue des Colonies 56 - box 3
1000 Brussels

T: +32 2 629 42 53
F: +32 2 629 42 22
vCard
Evan Bayh Evan Bayh
Partner
2001 K Street N.W.
Suite 400
Washington, DC 20006-1040

T: +1 202 828 2825
F: +1 202 828 3331
vCard
Kenneth D Bell Kenneth D. Bell
Partner
201 North Tryon Street
Suite 3000
Charlotte, NC 28202-2146

T: +1 704 373 4620
F: +1 704 373 8836
vCard
Robert Bittman Robert J. Bittman
Partner
2001 K Street N.W.
Suite 400
Washington, DC 20006-1040

T: +1 202 857 2472
F: +1 202 828 2962
vCard
Caitlin Bradley Caitlin O. Bradley
Associate
Gateway Plaza
800 East Canal Street
Richmond, VA 23219-3916

T: +1 804 775 1126
F: +1 804 698 2031
vCard
Joshua D Davey Joshua D. Davey
Partner
201 North Tryon Street
Suite 3000
Charlotte, NC 28202-2146

T: +1 704 343 2167
F: +1 704 805 5019
vCard
Kevin Denny Kevin L. Denny
Associate
201 North Tryon Street
Suite 3000
Charlotte, NC 28202-2146

T: +1 704 373 8058
F: +1 704 353 6206
vCard
Mehboob R Dossa Mehboob R. Dossa
Partner
11 Pilgrim Street
London EC4V 6RN
United Kingdom

T: +44 20 7632 1627
F: +44 20 7632 1638
vCard
Jasen Eige J. Jasen Eige
Partner
Gateway Plaza
800 East Canal Street
Richmond, VA 23219-3916

T: +1 804 775 1929
F: +1 804 775 1061
vCard
Shawna English Shawna J. English
Associate
EQT Plaza
625 Liberty Avenue
23rd Floor
Pittsburgh, PA 15222-3142

T: +1 412 667 7922
F: +1 412 667 7972
vCard
Jason D Evans Jason D. Evans
Partner
201 North Tryon Street
Suite 3000
Charlotte, NC 28202-2146

T: +1 704 343 2050
F: +1 704 444 8774
vCard
Steve Gold Steve Gold
Partner
77 West Wacker Drive
Suite 4100
Chicago, IL 60601-1818

T: +1 312 321 7664
F: +1 312 698 4583
vCard
Larry R Goldstein Larry R. Goldstein
Senior Counsel
77 West Wacker Drive
Suite 4100
Chicago, IL 60601-1818

T: +1 312 849 8216
F: +1 312 920 3692
vCard
David L Greenspan David L. Greenspan
Partner
1750 Tysons Boulevard
Suite 1800
Tysons, VA 22102-4215

T: +1 703 712 5096
F: +1 703 712 5214
vCard
Louis Greenstein Louis D. Greenstein
Partner
2001 K Street N.W.
Suite 400
Washington, DC 20006-1040

1345 Avenue of the Americas
7th Floor
New York, NY 10105-0106

T: +1 202 857 2415
F: +1 202 828 3310
vCard

T:+1 212 548 7068
F: +1 212 548 2150

default mcguire woods image A. Brooks Gresham
Partner
1800 Century Park East
8th Floor
Los Angeles, CA 90067-1501

T: +1 310 315 8291
F: +1 310 956 3104
vCard
Mary Grob Mary K. Grob
Associate
201 North Tryon Street
Suite 3000
Charlotte, NC 28202-2146

T: +1 704 343 2274
F: +1 704 353 6204
vCard
Bo Harvey Bo Harvey
Associate
1800 Century Park East
8th Floor
Los Angeles, CA 90067-1501

1345 Avenue of the Americas
7th Floor
New York, NY 10105-0106

T: +1 310 315 8293
F: +1 310 956 3162
vCard

T:+1 212 548 2188
F: +1 212 715 6261

Melanie Holloway Melanie C. Holloway
Counsel
Gateway Plaza
800 East Canal Street
Richmond, VA 23219-3916

T: +1 804 775 1019
F: +1 804 698 2027
vCard
Jakarra J Jones Jakarra J. Jones
Associate
Gateway Plaza
800 East Canal Street
Richmond, VA 23219-3916

T: +1 804 775 1132
F: +1 804 698 2054
vCard
C. Andrew Konia C. Andrew Konia
Partner
1750 Tysons Boulevard
Suite 1800
Tysons, VA 22102-4215

201 North Tryon Street
Suite 3000
Charlotte, NC 28202-2146

T: +1 703 712 5071
F: +1 704 444 8834
vCard

T:+1 704 343 2070
F: +1 704 444 8834

Nathan A Kottkamp Nathan A. Kottkamp
Partner
Gateway Plaza
800 East Canal Street
Richmond, VA 23219-3916

T: +1 804 775 1092
F: +1 804 698 2072
vCard
Raphael Krowicki Raphaël Krowicki
Associate
rue des Colonies 56 - box 3
1000 Brussels

T: +32 2 629 42 50
F: +32 2 629 42 22
vCard
Annie Cai Annie Cai Larson
Associate
Gateway Plaza
800 East Canal Street
Richmond, VA 23219-3916

T: +1 804 775 1127
F: +1 804 698 2114
vCard
Results 1-20 of 42
Show All
Speaking Engagement

2017 Annual Conference on EU Law in the Insurance sector

May 18-19, 2017
Trier
Event

Compliance in the Real World

A Practical Discussion About Today’s Top Issues

Wednesday, May 17, 2017
Chicago, IL
Speaking Engagement

7th European Data Protection Days

May 15-17, 2017
Berlin
Speaking Engagement

ASSO DPO: 2017 Annual Congress

May 8-9, 2017
Milan
Event

The Data Breach Class Action

Wednesday, April 5, 2017
Speaking Engagement

ITechLaw: 2017 India Conference

February 1-3, 2017
New Delhi
Speaking Engagement

Houston CFO Cybersecurity Roundtable

December 7, 2016
Houston, TX
Speaking Engagement

FireEye Cyber Defense Summit 2016

November 28-30, 2016
Washington, DC
Event

Hot Topics in Employee Benefits

November 10, 2016
Complimentary Webinar
Speaking Engagement

Summer Course on European Data Protection

September 12-16, 2016
ERA Academy of European Law e-Learning Course
Event

HIPAA Webinar Series

March 30 & April 6, 2016
Complimentary Healthcare Webinars
Speaking Engagement

ITechLaw: International India Conference

January 27-29, 2016
Bangalore
Speaking Engagement

ITechLaw Asia-Pacific Conference

January 29, 2015
Bangalore
Results 1-20 of 42
Results 1-20 of 257
Show All
Legal Alert

Brexit - UK Files for Divorce From European Union

What Should Companies Do Now to Prepare?

March 29, 2017
Legal Alert

21st Century Data Breaches: Not All Fun and Games

Password Protected
March 22, 2017
Legal Alert

Court Confirms Right to Be Forgotten Is Not Absolute

Password Protected
March 15, 2017
Legal Alert

Court Gives Broad Reading to Illinois Biometric Privacy Act

Password Protected
March 13, 2017
Legal Alert

Three Major Security Issues to Consider with SaaS and Cloud Solutions

Password Protected
March 10, 2017
Legal Alert

The Validity of EU-U.S. Personal Data Export Tools: A Pending Issue

Password Protected
March 8, 2017
Legal Alert

Eighth Circuit Undoes Target Data Breach Settlement Class

Password Protected
February 20, 2017
Legal Alert

ALERT: Beware of W-2 Scam!

Password Protected
February 16, 2017
Legal Alert

ERISA Advisory Council Issues 2016 Report on Benefit Plan Cybersecurity

Password Protected
February 6, 2017
Legal Alert

FTC Cautions Companies on Cross-Device Tracking Disclosures

Password Protected
February 2, 2017
Legal Alert

Cybersecurity and Data Privacy in 2017: Eight Topics to Follow

Password Protected
January 31, 2017
Legal Alert

Data Privacy Class Actions Post-Spokeo

Password Protected
December 28, 2016
Legal Alert

Obama’s National Cybersecurity Recommendations to Trump

Password Protected
December 21, 2016
Legal Alert

General Data Protection Regulation (GDPR): An Employer’s Guide

Password Protected
December 16, 2016
Results 1-20 of 257