The following is an excerpt from Practice Perspectives: Vault's Guide to Legal Practice Areas.
Molly O’Malley Clarke is an associate in the Los Angeles office of Latham & Watkins and a member of the privacy and cyber practice and connectivity, privacy, and information group. Molly also serves on the firm’s Training and Career Enhancement Committee. She represents clients in government and internal investigations and enforcement matters spanning privacy, cybersecurity, white collar, and related consumer protection issues. She also advises public and private organizations on regulatory risks and compliance issues relating to privacy and cybersecurity, including compliance program design.
Michael Rubin serves as Global Co-chair of the privacy and cyber practice, Global Vice Chair of the technology industry group, and Global Chair of the artificial intelligence practice. He draws on more than two decades of experience at the leading edge of legal issues in Silicon Valley to regularly provide counsel on and representation for privacy, cybersecurity, consumer protection incidents and on matters arising under U.S. and global regulations, including FTC Section 5; AI matters ranging from design, governance, regulatory compliance and defense to litigation; and emerging technologies and novel business and regulatory issues.
Michael repeatedly earns recognition for his market-changing work from leading industry publications, including Law360, The National Law Journal, and Chambers.
Describe your practice area and what it entails.
Michael: I represent technology companies in high-stakes litigation and regulatory matters at the cutting edge, including companies in the AI and other emerging technology sectors. I also lead Latham’s global AI intelligence practice, a cross-border and cross-disciplinary team that includes more than 150 lawyers from 30 practice areas and 15 offices around the globe. We advise at every layer of the tech stack to help clients as they develop, implement, or just explore AI technologies that are transforming business.
Molly: My practice is really to support and advise clients throughout the full compliance life cycle on privacy, cyber, and related consumer protection issues. What we call the “front end” of the life cycle involves advising on the development of or changes to a product, service, or process, whereas the “back end” involves representing our clients in internal or regulatory investigations, inquiries, and enforcement actions, as well as any related litigation that might result.
What types of clients do you represent?
Michael: I primarily represent and advise tech companies—both the major players and startups, the industry stalwarts, and the next-generation leaders—on privacy, cybersecurity, and consumer protection matters, AI matters, and novel business or regulatory issues that arise from emerging technologies.
Molly: Like Michael, I represent a wide range of clients, from market leaders to startups with a single app. There was a time when I would have said that I mostly represent tech companies with tech problems. But these days, virtually every company has “tech problems,” and our client base is increasingly composed of companies not traditionally considered tech companies in sectors like retail or healthcare. We sometimes joke that if your employees use the Internet, you might need our advice.
What types of cases/deals do you work on?
Michael: I advise on everything from developing tech products from the ground up, incorporating AI into all facets of clients’ businesses, and defending litigation or regulatory matters on all manner of issues that involve the use of data and that have been represented to consumers, especially novel and complex issues related to privacy, cybersecurity, integrity, and governance, and the full slate of new AI laws that have emerged.
Molly: I split my time working on matters across the life cycle that I mentioned earlier, which I think holds true for most of us in the practice. On the counseling side, I advise on matters ranging in size from changes to a single feature or product up to a total overhaul of a client’s privacy or cybersecurity program. The breadth of our regulatory work also runs the gamut. Sometimes I’m representing a client receiving a few targeted questions from a single state attorney general; other times, a client is facing a coordinated investigation by state, federal, and even sometimes overseas regulators about all of the company’s privacy or data practices.
How did you choose this practice area?
Michael: What drew me to tech originally is the same thing really that draws me to the area I practice in now: innovation and the ability to work with the most innovative companies on their hardest problems. When I started my practice in 2000, privacy and cybersecurity wasn’t really on anyone’s radar, but over the next decade, I saw these issues come to the forefront, so I began working with clients on what I would call “innovation protection work.” As the industry has evolved, so has my practice.
Molly: For me, entering this practice area was a result of aligning the “how” of my work with the “what” of the subject matter that kept me engaged and challenged and then finding the right opportunities. I knew early that I loved the fact development, critical thinking, and creative analytical processes that are core to counseling and investigations work, and my coursework in national security piqued my curiosity in the legal implications of technology as it evolves. From there, it was a matter of figuring out how to marry those things—and finding the right team to do it with—that led me to my current role.
What is a “typical” day like and/or what are some common tasks you perform?
Michael: Given the vast scope of the practice, my days usually involve some combination of revising briefs, taking a deposition, discussing complex questions with my clients as they wrestle with them, and developing strategies for them as they navigate the global regulatory landscape.
Molly: My days usually include a mix of product counseling work and tasks in service of ongoing regulatory matters. Most days involve some combination of quick-burn, high-priority asks that usually contain a more targeted scope, especially on the advising side, and then longer-term work on investigations and enforcement actions.
What training, classes, experience, or skills development would you recommend to someone who wishes to enter your practice area?
Michael: I recommend that all law students follow the Renaissance model—try to learn as much and as broadly as you can. Once you start practicing law, you’ll have plenty of opportunity to specialize, but in the early stages of your career, you want the broadest base of education and the widest legal footing to figure out where to direct your practice.
For privacy and cyber, consider taking courses in subjects like antitrust and intellectual property, as these areas increasingly intersect with privacy and AI law. As for the technological component of these practices, stay abreast of technology and don’t be afraid of it. Law students who are comfortable with tech will have an edge in understanding and leveraging generative AI and other emerging tools in their practice.
Molly: I also think attitude is important: Adaptability, curiosity, and a willingness to learn play critical roles in finding success in this practice. The technology we work with changes every day, and the laws and regulations applicable to what we do also constantly evolve.
If your school offers a privacy law course that provides an overview of the various legal regimes at play, you may find that beneficial, but keep in mind individual privacy laws that exist today will likely be different by the time you start practicing. Instead, focus on understanding the broader concepts and developing the ability to quickly adapt to new information.
What do you like best about your practice area?
Michael: Practicing in this space for nearly 25 years, I’ve witnessed rapid growth and transformation firsthand. When I moved to San Francisco, the tech industry had the wind at its back; now, we’re standing with a gale force wind in our face. Navigating through a landscape marked by constant innovation and regulatory developments has its challenges but also keeps the practice exciting. We’re not confined to a single jurisdiction or regulatory framework; instead, we address legal issues that span different countries and various technologies. We ride the wave of public perception and public viewpoints, which keeps us on our toes and means the work is never static. To put this into perspective, three years ago, we didn’t have a formal AI practice, and now look at what our capabilities have grown into.
Molly: The best part of practicing in the privacy and data security space is also the biggest challenge—both the facts and the law we deal with change seemingly every single day.
Our clients keep developing new technology and innovating, and the applicable legal regimes respond in kind. So while the advice we provided last month may no longer be the advice we would provide today, it keeps all of us in the practice engaged and entertained, and there’s always a new challenge to take on.
What is unique about your practice area at your firm?
Michael: This is a completely cross-jurisdictional, cross-disciplinary practice. That alone doesn’t make us unique from others, but the degree of the cross-functional and global work that we do sets us apart, whether you’re a partner or an associate.
Molly: We also integrate deeply with our clients in a way that I think sets us apart by forming long-term relationships that allow us to understand their tech and help develop it. This means we have critical context at the outset of any new project—there’s less for them to explain and allows us to assist more efficiently and effectively.
What kinds of experience can summer associates gain at this practice area at your firm?
Michael: We create a very immersive experience for our summer associates, who operate within the practice similarly to our junior lawyers (including the team bonding aspects—I’m personally a fan of taking my team out for big dinners). Summers can expect to assist on regulatory investigations and litigation matters, attend team calls, and help research and develop strategies for the thorny questions that arise with new technologies. We integrate our summer associates into the practice as much as possible to provide them with the true experience of what it’s like to work at Latham.
Molly: We’ll often see a summer step up to become a subject matter expert on some developing technology or brand new regulation, which opens a lot of doors for the types of matters and tasks they work on.
As a case in point, we’re excited about pro bono work in this practice area, and a few years ago I had the opportunity to bring in a summer associate to handle the response to a ransomware attack against a small nonprofit entity. During his time as a summer associate, he got to see the matter through to completion—a valuable experience for someone beginning their legal career.
Given how quickly technology is evolving, how do you stay ahead of the curve and prepare for issues that may arise?
Michael: Staying ahead of the curve in such a fast-paced technological landscape requires a combination of vigilance, client engagement, and forward-thinking strategies. At Latham, we prioritize cultivating long-term relationships with our clients. We don’t just handle individual cases; we’re deeply involved in understanding their product roadmaps and future directions. This close relationship allows us to anticipate potential legal challenges and regulatory changes.
Molly: We also maintain a global perspective, constantly monitoring regulatory and legislative developments across various jurisdictions from the FTC in the United States to the European Commission and regulatory bodies in the Asia-Pacific (APAC) region so that we can help our clients see around corners and plan for what’s coming. And we do so as a collective unit, coordinating across offices and teams so that everyone, from partners to first years, can access and call on the full scope of Latham’s expertise.