The following is an excerpt from Practice Perspectives: Vault's Guide to Legal Practice Areas.
Holly Brady is counsel in the firm’s Richmond, VA, office. She assists clients in identifying, evaluating, and managing global privacy and cybersecurity risks and compliance issues. Holly advises on the development of comprehensive privacy compliance and risk management programs by, for example, drafting privacy policies, procedures, and notices. She also has extensive experience negotiating complex data transactions and managing cybersecurity incidents. Prior to joining the firm, Holly managed the data privacy program at a Fortune 500 company, where she advised on data privacy compliance and risk management for the company’s U.S. and international operations. She also is an adjunct professor of Cybersecurity Law at William & Mary School of Law, where she enjoys teaching the next generation of cybersecurity lawyers.
Describe your practice area and what it entails.
Hunton Andrews Kurth’s top-ranked global privacy and cybersecurity practice helps companies manage data and mitigate risks at every step of the information life cycle. We advise clients in identifying, evaluating, and managing complex global privacy and information security risks and compliance issues. For cybersecurity matters, we advise large, multinational companies on all aspects of catastrophic cybersecurity incidents, including providing strategic and legal advice in investigating and remediating the incident, fulfilling their notification responsibilities; responding to multi-jurisdictional regulatory investigations; and managing inquiries from customers, business partners, media, and regulators. We also advise clients on conducting proactive cyber incident preparedness activities, including developing incident response plans and information security policies, running executive-level tabletops, performing information security assessment and tests, and engaging third-party experts in advance of an incident. In relation to our privacy compliance practice, we advise clients on state, federal, and international privacy laws; conduct privacy and data security impact assessments; and counsel companies on managing risk in connection with leading-edge and innovative technologies.
Our privacy and cybersecurity practice is augmented by The Centre for Information Policy Leadership at Hunton Andrews Kurth, a privacy think tank associated with the firm.
What types of clients do you represent?
We represent a diverse group of clients of all sizes, including retailers, consumer goods companies and manufacturers, energy companies and utilities, technology companies, financial institutions and private equity firms, fintech startups, insurance providers, healthcare providers, media companies, hospitality and gaming companies, direct marketers, telecommunications and Internet service providers, cloud providers, cybersecurity companies, government agencies, and risk management specialists.
What types of cases/deals do you work on?
We advise clients on the following matters:
- Compliance with all U.S. federal and state privacy and cybersecurity requirements and international data protection laws.
- Cybersecurity and data breach incident response.
- Drafting and negotiating complex privacy and cybersecurity provisions and indemnities in agreements, including complex data transactions.
- Managing federal, state, and international regulatory inquiries in connection with alleged privacy and data security violations.
- Evaluating cybersecurity and privacy risks and negotiating purchase agreements in connection with potential mergers, acquisitions, and other corporate transactions.
- Advising on cross-border data transfer strategies.
- Designing and evaluating privacy impact assessments.
- Developing and enhancing comprehensive records management programs.
- AI governance and other cutting-edge technology issues.
- Information product life cycle issues, including marketing and analytics activities.
- Advising on adtech and retail media compliance and contractual issues.
How did you choose this practice area?
When I first started practicing, I advised on technology transactions, which regularly involved tackling data privacy and cybersecurity issues. After a few years, my focus shifted to exclusively advising on data privacy and cybersecurity. Now our practice also increasingly includes advising on issues that arise from advancements in AI.
What is a “typical” day like and/or what are some common tasks you perform?
In this space, every day is unique and unpredictable. On any given day, we advise on issues ranging from complex data transactions, cybersecurity incident response, and data privacy compliance to issues arising from AI and automated decision-making.
What training, classes, experience, or skills development would you recommend to someone who wishes to enter your practice area?
Data privacy and cybersecurity continue to be a critical area of focus for all types of organizations and industry sectors, and there are numerous resources from industry publications to educational programs and industry presentations. Additionally, I encourage law students, associates, and clients that are new to the space to subscribe to Hunton’s Privacy and Information Security Law Blog, www.huntonprivacyblog.com, which we update on a nearly daily basis with news items and analysis. Our team has also published a treatise, the Privacy and Cybersecurity Law Deskbook, which is updated annually and provides a comprehensive primer on U.S. and international privacy and data protection laws. Organizations like the International Association of Privacy Professionals are great resources as well.
What do you like best about your practice area?
The best part of this practice area is that it lives at the intersection of law, technology, and business. To effectively advise in this space, you have to be willing to dive into the technology and business underpinnings of cybersecurity and data privacy issues, in addition to understanding the legal landscape. You can have the most meaningful impact in this practice area by understanding how the legal, technology, and business issues relate to each other.
What misconceptions exist about your practice area?
One common misconception is that you need deep technology expertise to start out in this practice area. That is not necessarily the case, and what is more important is a willingness to ask questions and learn from others who have relevant technology expertise. We work on a regular basis with non-lawyers who are experts in cyber forensics, data science, and other cybersecurity- and privacy-related disciplines. If you are open to learning from others and are willing to ask questions, there are many opportunities to quickly expand your technology expertise.
What is unique about your practice area at your firm?
Our team is uniquely collaborative, which is invaluable in a practice area that has been evolving at a breakneck pace and shows no signs of slowing down. One of the many benefits of our high level of collaboration is that it helps accelerate the learning curve of new team members, especially for lawyers who are new to this practice area.
Given how quickly technology is evolving, how do you stay ahead of the curve and prepare for issues that may arise?
To effectively practice in this space, it is critical to keep pace with advancements in technology because it directly impacts the advice we give on a day-to-day basis. Team collaboration is a significant part of how we stay ahead of the curve, and we also contribute to the practice area through publications, speaking engagements, and teaching and mentoring, which help us stay sharp and on the leading edge of evolving issues in the technology and legal landscape.