Skip to Main Content
Go to Why Work Here page
BakerHostetler logo

BakerHostetler

The following is an excerpt from Practice Perspectives: Vault's Guide to Legal Practice Areas.

Sarah Ballard defends clients in high-stakes privacy class actions. Focusing her practice on novel, complex legal issues, Sarah represents a client in one of the first pixel/online tracking cases and currently represents over a dozen firm clients in the high-profile MOVEit multidistrict litigation (MDL). She also represents clients with unique legal issues, such as sovereign immunity (for Sarah’s Native American clients) and statutory preemption (Southwest Airlines). Her work on these and other matters has earned her recognition as a 2025 Law360 Rising Star.

Joel Griswold defends clients in cutting-edge privacy class actions and mass arbitrations implicating the treatment of alleged personally identifiable information. As these claims regularly seek to impose ruinous statutory damages, Joel is often called on to defend companies facing litigation that poses an existential threat.

Additionally, Joel regularly counsels clients on compliance with laws governing these areas and risk mitigation. He regularly represents a wide array of SaaS companies and clients across virtually all industries, including insurance and financial services, retail, restaurants, hospitality, healthcare, education, manufacturing, and transportation.

Describe your practice area and what it entails.

Joel: I defend companies that are sued in class actions asserting a myriad of privacy claims. These cases often seek to impose ruinous liability through the imposition of statutory damages.

Sarah: I defend companies in privacy cases, including data breach class actions, the use of web-browsing technologies to track customers, and the use of novel or sensitive technologies, such as the biometric finger scanning in the workplace. I also represent clients in various business-to-business disputes that touch on data privacy, such as in contract negotiations and indemnity demands between a data owner and its breached vendor.

What types of clients do you represent?

Joel: I represent a broad spectrum of clients in SaaS, retail, restaurants, media, insurance and financial services, education, healthcare, transportation, and consumer goods and services.

Sarah: Along with the BakerHostetler privacy and digital risk class action litigation team, I represent clients in all industries (transportation, consumer goods and services, financial services, etc.). Most of my clients are in industries that are highly regulated, such as the healthcare sector.

What types of cases/deals do you work on?

Joel: My colleagues describe my practice as the “alphabet soup” of defending privacy claims because I tend to live in the world of acronyms. I’ve defended hundreds of class putative actions asserting claims brought under an assortment of federal, state, and local consumer and privacy protection laws, including the Video Privacy Protection Act (VPPA), the Electronic Communications Privacy Act (ECPA), the Fair Credit Reporting Act (FCRA), the Fair and Accurate Credit Transactions Act (FACTA), the Americans with Disabilities Act (ADA), the Illinois Biometric Information Privacy Act (BIPA), the Illinois Genetic Information Privacy Act (GIPA), the Illinois Right of Publicity Act (IRPA), and myriad consumer protection and privacy statutes.

Sarah: I work on typical data privacy class actions involving claims for negligence, breach of contract, and various state and federal consumer and privacy protection statutes. I also handle a fair number of state and federal wiretapping cases based on a company’s alleged use of browsing analytics technologies on its website. My favorite cases, however, involve novel legal issues: clients with peculiar defenses/facts, such as they are sovereign, they can claim immunity, etc.; application of a new statute; application of an old statute to a modern-day case, which is usually what we see; or any case that is procedurally or substantively a head-scratcher.

How did you choose this practice area?

Joel: In the course of counseling and defending businesses evolving and employing new technologies, the overlap with emerging privacy concerns and risks eventually consumed my practice. Many of the statutes under which plaintiffs seek to assert liability do not neatly apply to the technologies being challenged. My practice provides daily opportunities for me to be creative and pragmatic in my advocacy. Moreover, because of the rapid pace of technological development, I’m always learning to anticipate and help clients avoid the next area of potential risk.

Sarah: Mostly by happenstance. I had taken some Cybersecurity and Counterterrorism classes in law school and thought I might work for a federal agency or the government in the privacy space. Six years later, I was not working for a federal agency but was at a large, international law firm in its business and tort litigation group. About 18 months into that job, I joined a case defending a target of an SEC cybersecurity enforcement action and really enjoyed it. Several months later, I interviewed for the privacy litigation position at BakerHostetler, and here I am today!

What is a “typical” day like and/or what are some common tasks you perform?

Joel: On a regular basis, I review new complaints to identify developing trends of which my clients should be made aware, communicate areas of potential risk and recommend mitigation strategies, and review and revise policies and terms. At the outset of any litigation, I discuss with my clients their concerns and goals. I investigate the factual allegations and background, develop strategies for defending the case on the merits and defeating efforts at class certification, research cases to support my theories of defense, draft and revise motions, argue motions, take depositions, work with experts, and confer with my clients about the risks and rewards of various strategies. I meet regularly with my team to discuss strategy and assign tasks to ensure that we are efficiently allocating our resources and meeting our deadlines. Additionally, depending on the client’s goals, I negotiate settlements through direct discussions with plaintiffs’ counsel and through mediation.

Sarah: If there is any routine to my days, it is that they are always action-packed and busy. On any given day, I am jumping into meetings to discuss a new cybersecurity incident with a client who wants a litigator to talk to them about next steps: Are there going to be lawsuits? How do we manage stakeholder, employee, customer, etc., expectations? Then, it’s figuring out a plan to terminate or recover from the client’s breached vendor or assuage its angry customers and co-defense calls or attending meet-and-confers with plaintiffs, often multiple times a week, particularly in MDL and when the parties are in discovery. From there, I am responding to emails, Teams messages, and unexpected calls, all while trying to find a moment of deep thought to focus on research, drafting, and preparing for the next day.

What training, classes, experience, or skills development would you recommend to someone who wishes to enter your practice area?

Joel: I recommend developing skills in statutory interpretation, civil procedure, and constitutional law. Every day, the plaintiffs’ bar is pushing the outer limits. These disciplines provide the foundation for the balance of creativity and pragmatism needed to be an effective advocate in this area.

Sarah: I recommend associates get comfortable with federal civil procedure and basic organizational and time management skills. For example, when a large incident occurs involving millions of individuals nationwide, we can expect dozens of lawsuits to be filed in multiple jurisdictions. I would ask an associate to determine and track pending deadlines in each jurisdiction; propose a plan to manage these cases via consolidation, stay, MDL, or something else; and consider the repercussions of each choice.

What do you like best about your practice area?

Joel: While I love the intellectual challenge of dealing with novel theories of liability, I most enjoy the pursuit of the greater good. First, I believe I am working to prevent the erosion of due process because privacy class actions often attempt to exploit vague and outdated laws that were neither contemplated nor meant to apply to current technology. Second, I believe that successfully defending against baseless privacy class actions fosters innovation and contributes to our economic vitality. Finally, I think there is moral integrity in defending companies targeted in privacy class actions. Most companies are not villainous and are not out to harm anyone’s privacy. To the contrary, they are looking to make life and doing business more convenient.

Sarah: I like the intellectual challenge and fast-paced nature of this job. There is always something happening: a new case filed, new cybersecurity incident reported, new technology being used, etc.

What are some typical tasks that a junior lawyer would perform in this practice area?

Joel: Some tasks typically performed by junior lawyers involve researching statutory history and case law, drafting motions, and drafting discovery.

Sarah: We ask junior attorneys to do initial drafts of almost everything (motions, client updates, settlement analysis, etc.) and work with staff to docket upcoming deadlines, etc. As associates become more comfortable handling more and harder tasks, we support them in broadening their experience and skill sets. Although there is a steep learning curve in the first year or so, there is a lot of support. When they’re ready, our team will let them loose.

How do you see this practice area evolving in the future?

Joel: The law has not kept pace with technological advancements, and it will not do so moving forward. As technology finds new and more efficient ways to use data, plaintiffs will seek to expand the application of vague statutory language to assert liability, and legislatures will race to pass new laws. A practitioner in this area will need to stay ahead of the curve by anticipating how existing laws may be exploited and how new laws may impact business practices going forward.

Sarah: As it’s already happening, I expect we will continue to see enterprising plaintiffs’ attorneys carve out novel theories of liability against defendants. These initial test cases, if they survive a motion to dismiss, are often followed by a flood of litigation, which gradually dies out as a new trend takes their place. I also think we are going to see far fewer cases settling as more plaintiffs’ attorneys enter the space, more lawsuits are filed, and the overall cost of settling in general increases—which is also happening right now.

Given how quickly technology is evolving, how do you stay ahead of the curve and prepare for issues that may arise?

Joel: I read new class action complaints to identify developing theories of liability being pursued, receive updates on various federal and state privacy legislation that is being proposed, and attend continuing legal education courses. Also, gaining exposure to different technologies helps me brainstorm where plaintiffs may be going with their next theory. Finally, I am fortunate to be at a law firm with tremendous lawyers who practice at the cutting edge of technology and are amazing colleagues with whom I can collaborate to stay ahead of what comes next.