Data Privacy and Security

Members of our data privacy and security team include more than 30 interdisciplinary lawyers on the front lines of this rapidly evolving area of the law. We provide proactive counseling designed to protect the integrity of our clients’ systems, investigative and remediation services that may be required after a breach, and guidance to assist our clients as they develop new relationships and sources of revenue. Whatever the context, the team possesses the experience and professional networks necessary to address all our clients’ global needs in the area of data privacy and security.

Data Privacy Team Overview

Our team includes experienced intellectual property counsel, class action litigators and technology industry professionals to assist clients with transactional matters as well as instances where an alleged breach has led to litigation. Through McGuireWoods Consulting, we also offer lobbying services to ensure that our clients have a voice in shaping precedent-setting and far-reaching legislation. Our goal is to provide a comprehensive solution for our clients by working not only with their lawyers, but also with IT staff, human resources professionals and product specialists. This approach permits us to deliver integrated services that promote information-sharing within the organization and account for the interests of all stakeholders.

Team members regularly advise clients dealing with cybercrime and inadvertent breaches. Further, as new and multiple uses for technology emerge, we help clients respond to unforeseen consequences that require immediate action. As such, team members have become globally recognized legal resources in this practice area, with many clients hailing from diverse industries, including education, energy, financial services, healthcare, insurance and retail, among others.  

International Practice

Because global commerce recognizes no boundaries, the team’s Data Privacy and Security clients rely heavily on our deep international experience. Our team’s international practice helps clients secure their data globally, and navigate through U.S. (federal and state), Canadian, European, Middle Eastern and Asian data security and privacy laws. Team attorneys collectively speak 13 languages and respond to matters relating to international cloud computing, data transfer and international e-discovery matters.

Incident Response

In the event of a breach or other security matter, it is essential to be able to mobilize a broad-based response that includes resources outside of the client and our firm. Our data privacy and security team, which includes several former federal prosecutors, draws upon the resources of a large, external support network composed of qualified computer forensic examiners and law enforcement agents around the world. Among these resources are high-level technical subject matter experts and liaisons with the FBI, U.S. Secret Service, Postal Inspectors, New Scotland Yard and the big four international accounting firms. This network is further expanded through active memberships in InfraGard (FBI) and the Federal Electronic Crimes Task Force (U.S. Secret Service).

Director and Officer Protection

Our team is keenly aware of the dangers that security breaches pose to an organization as a whole, as well as the exposure of directors and officers in the event of such breaches. Therefore, a fundamental part of our practice is regularly counseling directors and executive officers on what they do and don't need to know, what the risks are of not knowing, and procedures and tips for how to stay educated and abreast of regulatory and hostile technology developments within and outside of their organizations. Whatever the risk profile of the company, we help ensure that the individual directors and officers are taking appropriate measures to faithfully fulfill their fiduciary duties, thereby protecting themselves as well as the companies they represent.

Areas of Experience

  • Comprehensive Information Governance program development
  • Data breach compliance, response and remediation, including media relations
  • Proactive data protection audits
  • Cross-border data transfer compliance, including the EU/U.S. Privacy Shield
  • M&A/private equity counseling
  • Vendor contract development and negotiation
  • Privacy policy management
  • HIPAA and state health records laws
  • Cyber insurance counseling
  • Legislative tracking, analysis and lobbying (in partnership with McGuireWoods Consulting)
  • Forensics and technical systems planning (in partnership with forensic consultants)
  • Cybersecurity crisis management

Included in team member credentials are:

  • Chair of the firm’s transactional Intellectual Property practice. Her experience includes auditing and evaluating client data security policies, drafting website privacy policies, negotiating cloud computing agreements from both the vendor and customer perspectives, and providing support in the aftermath of a data breach, including compliance with breach-notification laws.
  • Two Brussels-based partners are members of the European Privacy Association (EPA), a pan-European network of privacy, data protection and security experts, which works closely with the EU institutions. These partners both have experience in all privacy-related issues involving national data protection authorities and EU institutions, as well as broad experience in regulatory issues such as cloud computing, data transfers, coordination with foreign discovery or antibribery teams, interactions with intellectual property rights, re-use of public sector information, employee monitoring, and privacy audits.
  • A London-based partner with extensive experience in European regulatory issues, including data protection and security; cross-border data transfer; privacy; encryption; export controls; technology and EU public procurement regulations. One recent focus has been on technology transfer and regulation in the banking and financial markets sectors.
  • Chair of the firm’s Supply Chain practice, an experienced data privacy and security lawyer, who routinely counsels clients on protective measures to employ in the construction of policies and critical contracts in order to prevent security breaches, investigations, lawsuits and similar harmful events. He focuses on a variety of matters, including data storage, cloud computing and social-media risks and has particular knowledge of the Payment Card Industry Data Security Standards.
  • Fifteen members who hold either the CIPP/U.S. or CIPP/E certification as Certified Information Privacy Professionals from the International Association of Privacy Professionals (IAPP).  
Data Privacy and Security 19401080 istock

CONTACTS

C. Andrew Konia Partner T: +1 703 712 5071
Results 1-20 of 26
Show All
Representative Matter

Voluntary dismissal of TCPA class action involving “one-click” dialing

Secured the voluntary dismissal of a putative TCPA class action against a market research company after convincing plaintiff’s counsel through informal discovery that the cell phone calls at issue were not placed by an ATDS.
Representative Matter

A2 Access LLC

Representation of A2 Access LLC, a leader in corporate access information, in connection with its sale to Dealogic.
Representative Matter

Client

Advising a client concerning the transfer of personal data from EU to the U.S. to comply with U.S. regulatory rules relating to a contract with the U.S. government.
Representative Matter

Communications company

Advising a company on all aspects of IT security and data protection compliance in its negotiation with its main IT service provider.
Representative Matter

International group

Advising an international group concerning the data protection compliance of an internal HR network.
Representative Matter

International group

Advising an international group concerning the data protection compliance of its e-commerce website (privacy notice, cookies, transfer of personal data to third parties for direct marketing purposes, etc.).
Representative Matter

Credit card issuer

Advice to a credit card issuer in IT and data protection compliance.
Representative Matter

German company

Advice to a German company concerning direct marketing operation in some European countries and in the United States.
Representative Matter

International counsel

Advice to international counsel as part of a team of U.S. and European lawyers, on a data breach investigation and reporting.
Representative Matter

U.S. company

Advice to a U.S. company concerning the introduction of a whistleblowing scheme in several Belgian entities.
Representative Matter

U.S. telecom operator

Advice to a U.S. telecom operator concerning a project that will collect automobilists' personal data in France in order to offer them various services.
Representative Matter

Fortune 500 wireless carrier

Assisting a Fortune 500 wireless carrier with evaluation of device financing proposals for postpaid and prepaid brands.
Representative Matter

International counsel

Advice to international counsel on direct marketing operation in France.
Case Study

Los Angeles and Pittsburgh teams secure win for GNC

In a case profiled in National Law Journal, McGuireWoods defeated a motion for class certification in an action brought against General Nutrition Corporation (GNC) in the U.S. District Court for the Central District of California alleging violations of California Civil Code section 1747.08 (the Song-Beverly Credit Card Act).

The Song-Beverly Credit Card Act (the "Act") was intended to stop businesses from gathering and storing unnecessary personal information from their consumers. The California Legislature passed the Act to address two important privacy concerns. First, corporations were needlessly storing consumer information and using it for their own marketing purposes or selling the information to other marketers. Second, store clerks who obtained customers' personal information engaged in acts of harassment and violence.

Representative Matter

European association

Advice to a European association on processing of sensitive data (judicial data) in matter of inside betting.
Representative Matter

Food and beverage company

Advice to a food and beverage company on data transfers for an US discovery procedure.
Representative Matter

Regional tourism promotion institution

Coordinating national compliance (inside and outside the EU) and data transfer from the EU to the United States and Japan for a regional tourism promotion institution.
Representative Matter

Consultant company

Advising a consultant company on IT breach tests and audits.
Representative Matter

Copyright owner

Advised a copyright owner against the Belgian State and other companies in  litigation concerning a possible copyright infringement of software relating to citizens' electronic identification.
Representative Matter

Data protection and EU direct marketing

Advice to a credit card issuer on direct marketing (marketing messages and Cookies).
Results 1-20 of 26
Results 1-25 of 52
Show All
Mike Adams Michael J. Adams
Partner - Not admitted in North Carolina, motion for admission in North Carolina pending; admitted in Virginia
201 North Tryon Street
Suite 3000
Charlotte, NC 28202-2146

1750 Tysons Boulevard
Suite 1800
Tysons, VA 22102-4215

T: +1 704 373 8847
F: +1 704 444 8747
vCard

T:+1 703 712 5135
F: +1 704 444 8747

Evan Bayh Evan Bayh
Partner
2001 K Street N.W.
Suite 400
Washington, DC 20006-1040

T: +1 202 828 2825
F: +1 202 828 3331
vCard
Joshua D Davey Joshua D. Davey
Partner
201 North Tryon Street
Suite 3000
Charlotte, NC 28202-2146

T: +1 704 343 2167
F: +1 704 805 5019
vCard
Kevin Denny Kevin L. Denny
Associate
201 North Tryon Street
Suite 3000
Charlotte, NC 28202-2146

T: +1 704 373 8058
F: +1 704 353 6206
vCard
Mehboob R Dossa Mehboob R. Dossa
Partner
11 Pilgrim Street
London EC4V 6RN
United Kingdom

T: +44 20 7632 1627
F: +44 20 7632 1638
vCard
Shawna English Shawna J. English
Associate
Tower Two-Sixty
260 Forbes Avenue
Suite 1800
Pittsburgh, PA 15222-3142

T: +1 412 667 7922
F: +1 412 667 7972
vCard
Jason D Evans Jason D. Evans
Partner
201 North Tryon Street
Suite 3000
Charlotte, NC 28202-2146

T: +1 704 343 2050
F: +1 704 444 8774
vCard
Steve Gold Steve Gold
Partner
77 West Wacker Drive
Suite 4100
Chicago, IL 60601-1818

T: +1 312 321 7664
F: +1 312 698 4583
vCard
David L Greenspan David L. Greenspan
Partner
1750 Tysons Boulevard
Suite 1800
Tysons, VA 22102-4215

T: +1 703 712 5096
F: +1 703 712 5214
vCard
default mcguire woods image A. Brooks Gresham
Partner
1800 Century Park East
8th Floor
Los Angeles, CA 90067-1501

T: +1 310 315 8291
F: +1 310 956 3104
vCard
J. Curtis Griner J. Curtis Griner
Associate
201 North Tryon Street
Suite 3000
Charlotte, NC 28202-2146

T: +1 704 343 2013
F: +1 704 373 8833
vCard
Mary Grob Mary K. Grob
Associate
201 North Tryon Street
Suite 3000
Charlotte, NC 28202-2146

T: +1 704 343 2274
F: +1 704 353 6204
vCard
Kate Hardey Kate W. Hardey
Partner
1750 Tysons Boulevard
Suite 1800
Tysons, VA 22102-4215

T: +1 703 712 5337
F: +1 703 712 5192
vCard
Karl Hemingway Karl Hemingway
Associate
11 Pilgrim Street
London EC4V 6RN
United Kingdom

T: +44 20 7632 1647
F: +44 20 7632 1638
vCard
Catherine Hess Catherine L. Hess
Senior Counsel
2001 K Street N.W.
Suite 400
Washington, DC 20006-1040

T: +1 202 857 1708
F: +1 202 828 3334
vCard
Melanie Holloway Melanie C. Holloway
Counsel
Gateway Plaza
800 East Canal Street
Richmond, VA 23219-3916

T: +1 804 775 1019
F: +1 804 698 2027
vCard
Jakarra J Jones Jakarra J. Jones
Associate
Gateway Plaza
800 East Canal Street
Richmond, VA 23219-3916

T: +1 804 775 1132
F: +1 804 698 2054
vCard
Photo of Elliot Katz Elliot Katz
Partner
Two Embarcadero Center
Suite 1300
San Francisco, CA 94111-3821

T: +1 415 844 1963
F: +1 415 844 1939
vCard
C. Andrew Konia C. Andrew Konia
Partner
1750 Tysons Boulevard
Suite 1800
Tysons, VA 22102-4215

201 North Tryon Street
Suite 3000
Charlotte, NC 28202-2146

T: +1 703 712 5071
F: +1 704 444 8834
vCard

T:+1 704 343 2070
F: +1 704 444 8834

Nathan A Kottkamp Nathan A. Kottkamp
Senior Counsel
Gateway Plaza
800 East Canal Street
Richmond, VA 23219-3916

T: +1 804 775 1092
F: +1 804 698 2072
vCard
Raphael Krowicki Raphaël Krowicki
Associate
rue des Colonies 56 - box 3
1000 Brussels

T: +32 2 629 42 50
F: +32 2 629 42 22
vCard
Annie Cai Annie Cai Larson
Associate
Gateway Plaza
800 East Canal Street
Richmond, VA 23219-3916

T: +1 804 775 1127
F: +1 804 698 2114
vCard
Kurt Lentz Kurt E. Lentz
Associate
Promenade
1230 Peachtree Street, N.E.
Suite 2100
Atlanta, GA 30309-3534

T: +1 404 443 5739
F: +1 404 443 5797
vCard
Rebecca Levinson Rebecca B. Levinson
Counsel
2001 K Street N.W.
Suite 400
Washington, DC 20006-1040

T: +1 202 828 2816
F: +1 202 828 3322
vCard
Clare McGovern Clare M. Lewis
Associate
Court Square Building
310 Fourth Street, N.E.
Suite 300
Charlottesville, VA 22902-1288

T: +1 434 977 2530
F: +1 434 980 2256
vCard
Results 1-20 of 55
Show All
Event

6th Annual European Data Protection and Security Conference

November 15, 2017
Complimentary Seminar
London
Event

SEC Compliance and Disclosure Update

October 24, 2017
Complimentary Webinar
Speaking Engagement

GDPR Summit London

October 9, 2017
Event

SEC Compliance and Disclosure Update

September 26, 2017
Complimentary Webinar Series
Speaking Engagement

2017 Round Up: Texas Association of Life & Health Insurers

September 24-26, 2017
Austin, TX
Event

HIPAA Hot Topics

Recent Developments and Enforcement Actions

September 14, 2017
Complimentary Webinar
Speaking Engagement

Summer Course on European Data Protection Law

September 11-15, 2017
Trier
Event

CLE: Ethics and Compliance

August 29, 2017
Pittsburgh, PA
Speaking Engagement

General Data Protection Regulation Conference Belgium

June 21, 2017
Lint
Speaking Engagement

2017 Annual Conference on EU Law in the Insurance sector

May 18-19, 2017
Trier
Event

Phish and Chips

Protecting You and Your Business From Cybercrime

May 17, 2017
London
Event

Compliance in the Real World

A Practical Discussion About Today’s Top Issues

May 17, 2017
Chicago, IL
Speaking Engagement

7th European Data Protection Days

May 15-17, 2017
Berlin
Speaking Engagement

ASSO DPO: 2017 Annual Congress

May 8-9, 2017
Milan
Event

SEC Compliance and Disclosure Update

April 18, 2017
Complimentary Webinar Series
Event

The Data Breach Class Action

April 5, 2017
Complimentary Webinar
Speaking Engagement

ITechLaw: 2017 India Conference

February 1-3, 2017
New Delhi
Results 1-20 of 55
Results 1-20 of 318
Show All
Article

GDPR Subject Access Requests

GDPR: Report
November 20, 2017
Legal Alert

Evolving Behavioral Advertising Technologies: What Companies Need to Know

Password Protected
November 9, 2017
Legal Alert

OCR Issues Statement on Data Privacy Risk of Mobile Device Use

Password Protected
November 6, 2017
Legal Alert

The Politics of Access to Student Data

Password Protected
October 25, 2017
Legal Alert

New CFPB Consumer Protection Principles

Password Protected
October 23, 2017
Legal Alert

Data Breach Risks and Costs in Vendor Contracts

Password Protected
October 19, 2017
Legal Alert

Delaware Strengthens Cybersecurity Law

Password Protected
October 10, 2017
Legal Alert

FTC Monitors Claims of Privacy Shield Compliance

Password Protected
September 27, 2017
Legal Alert

Cyberattacks—Are You Ready?

Password Protected
September 26, 2017
Legal Alert

The Equifax Breach: How to Protect Your Company and Your Customers

Password Protected
September 22, 2017
Article

Transfers of Personal Data to Third Countries

ERA Forum, Journal of the Academy or European Law
September 15, 2017
Legal Alert

FTC Provides Guidance on Data Security in Its “Stick With Security” Blog

Password Protected
September 13, 2017
Legal Alert

Government Response to Increasing Cyber Threats

Password Protected
September 12, 2017
Results 1-20 of 318