Skip to Main Content

Privacy & Data Security

Overview

Lawyers in this area advise business clients on cyber security issues, including internal security protocols, the collection and storage of personal data, and on how to respond to a data breach. While privacy lawyers are most often called into action in the wake of a data security breach, they also help their clients comply with regulations and counsel on ways to prevent data theft or loss. Lawyers may work on  incidence response teams and can be called on to work long hours after a client’s data has been breached. Data privacy lawyers will also frequently be involved in claims, litigation, and regulatory investigations arising from data security breaches. This is a growing and changing area of law, so lawyers may be regularly dealing with unsettled law and must stay up to date on security technology and emerging threats to IT security, as well as rapidly emerging regulations and case law that can pose challenges to their clients.

Featured Q&A's
Get an insider's view on working in Privacy & Data Security from real lawyers in the practice area.
Sarah Ballard, Associate • Joel C. Griswold, Partner—Digital Assets and Data Management
BakerHostetler

Describe your practice area and what it entails.

Joel: I defend companies that are sued in class actions asserting a myriad of privacy claims. These cases often seek to impose ruinous liability through the imposition of statutory damages.

Sarah: I defend companies in privacy cases, including data breach class actions, the use of web-browsing technologies to track customers, and the use of novel or sensitive technologies, such as the biometric finger scanning in the workplace. I also represent clients in various business-to-business disputes that touch on data privacy, such as in contract negotiations and indemnity demands between a data owner and its breached vendor.

What types of clients do you represent?

Joel: I represent a broad spectrum of clients in SaaS, retail, restaurants, media, insurance and financial services, education, healthcare, transportation, and consumer goods and services.

Sarah: Along with the BakerHostetler privacy and digital risk class action litigation team, I represent clients in all industries (transportation, consumer goods and services, financial services, etc.). Most of my clients are in industries that are highly regulated, such as the healthcare sector.

What types of cases/deals do you work on?

Joel: My colleagues describe my practice as the “alphabet soup” of defending privacy claims because I tend to live in the world of acronyms. I’ve defended hundreds of class putative actions asserting claims brought under an assortment of federal, state, and local consumer and privacy protection laws, including the Video Privacy Protection Act (VPPA), the Electronic Communications Privacy Act (ECPA), the Fair Credit Reporting Act (FCRA), the Fair and Accurate Credit Transactions Act (FACTA), the Americans with Disabilities Act (ADA), the Illinois Biometric Information Privacy Act (BIPA), the Illinois Genetic Information Privacy Act (GIPA), the Illinois Right of Publicity Act (IRPA), and myriad consumer protection and privacy statutes.

Sarah: I work on typical data privacy class actions involving claims for negligence, breach of contract, and various state and federal consumer and privacy protection statutes. I also handle a fair number of state and federal wiretapping cases based on a company’s alleged use of browsing analytics technologies on its website. My favorite cases, however, involve novel legal issues: clients with peculiar defenses/facts, such as they are sovereign, they can claim immunity, etc.; application of a new statute; application of an old statute to a modern-day case, which is usually what we see; or any case that is procedurally or substantively a head-scratcher.

How did you choose this practice area?

Joel: In the course of counseling and defending businesses evolving and employing new technologies, the overlap with emerging privacy concerns and risks eventually consumed my practice. Many of the statutes under which plaintiffs seek to assert liability do not neatly apply to the technologies being challenged. My practice provides daily opportunities for me to be creative and pragmatic in my advocacy. Moreover, because of the rapid pace of technological development, I’m always learning to anticipate and help clients avoid the next area of potential risk.

Sarah: Mostly by happenstance. I had taken some Cybersecurity and Counterterrorism classes in law school and thought I might work for a federal agency or the government in the privacy space. Six years later, I was not working for a federal agency but was at a large, international law firm in its business and tort litigation group. About 18 months into that job, I joined a case defending a target of an SEC cybersecurity enforcement action and really enjoyed it. Several months later, I interviewed for the privacy litigation position at BakerHostetler, and here I am today!

What is a “typical” day like and/or what are some common tasks you perform?

Joel: On a regular basis, I review new complaints to identify developing trends of which my clients should be made aware, communicate areas of potential risk and recommend mitigation strategies, and review and revise policies and terms. At the outset of any litigation, I discuss with my clients their concerns and goals. I investigate the factual allegations and background, develop strategies for defending the case on the merits and defeating efforts at class certification, research cases to support my theories of defense, draft and revise motions, argue motions, take depositions, work with experts, and confer with my clients about the risks and rewards of various strategies. I meet regularly with my team to discuss strategy and assign tasks to ensure that we are efficiently allocating our resources and meeting our deadlines. Additionally, depending on the client’s goals, I negotiate settlements through direct discussions with plaintiffs’ counsel and through mediation.

Sarah: If there is any routine to my days, it is that they are always action-packed and busy. On any given day, I am jumping into meetings to discuss a new cybersecurity incident with a client who wants a litigator to talk to them about next steps: Are there going to be lawsuits? How do we manage stakeholder, employee, customer, etc., expectations? Then, it’s figuring out a plan to terminate or recover from the client’s breached vendor or assuage its angry customers and co-defense calls or attending meet-and-confers with plaintiffs, often multiple times a week, particularly in MDL and when the parties are in discovery. From there, I am responding to emails, Teams messages, and unexpected calls, all while trying to find a moment of deep thought to focus on research, drafting, and preparing for the next day.

What training, classes, experience, or skills development would you recommend to someone who wishes to enter your practice area?

Joel: I recommend developing skills in statutory interpretation, civil procedure, and constitutional law. Every day, the plaintiffs’ bar is pushing the outer limits. These disciplines provide the foundation for the balance of creativity and pragmatism needed to be an effective advocate in this area.

Sarah: I recommend associates get comfortable with federal civil procedure and basic organizational and time management skills. For example, when a large incident occurs involving millions of individuals nationwide, we can expect dozens of lawsuits to be filed in multiple jurisdictions. I would ask an associate to determine and track pending deadlines in each jurisdiction; propose a plan to manage these cases via consolidation, stay, MDL, or something else; and consider the repercussions of each choice.

What do you like best about your practice area?

Joel: While I love the intellectual challenge of dealing with novel theories of liability, I most enjoy the pursuit of the greater good. First, I believe I am working to prevent the erosion of due process because privacy class actions often attempt to exploit vague and outdated laws that were neither contemplated nor meant to apply to current technology. Second, I believe that successfully defending against baseless privacy class actions fosters innovation and contributes to our economic vitality. Finally, I think there is moral integrity in defending companies targeted in privacy class actions. Most companies are not villainous and are not out to harm anyone’s privacy. To the contrary, they are looking to make life and doing business more convenient.

Sarah: I like the intellectual challenge and fast-paced nature of this job. There is always something happening: a new case filed, new cybersecurity incident reported, new technology being used, etc.

What are some typical tasks that a junior lawyer would perform in this practice area?

Joel: Some tasks typically performed by junior lawyers involve researching statutory history and case law, drafting motions, and drafting discovery.

Sarah: We ask junior attorneys to do initial drafts of almost everything (motions, client updates, settlement analysis, etc.) and work with staff to docket upcoming deadlines, etc. As associates become more comfortable handling more and harder tasks, we support them in broadening their experience and skill sets. Although there is a steep learning curve in the first year or so, there is a lot of support. When they’re ready, our team will let them loose.

How do you see this practice area evolving in the future?

Joel: The law has not kept pace with technological advancements, and it will not do so moving forward. As technology finds new and more efficient ways to use data, plaintiffs will seek to expand the application of vague statutory language to assert liability, and legislatures will race to pass new laws. A practitioner in this area will need to stay ahead of the curve by anticipating how existing laws may be exploited and how new laws may impact business practices going forward.

Sarah: As it’s already happening, I expect we will continue to see enterprising plaintiffs’ attorneys carve out novel theories of liability against defendants. These initial test cases, if they survive a motion to dismiss, are often followed by a flood of litigation, which gradually dies out as a new trend takes their place. I also think we are going to see far fewer cases settling as more plaintiffs’ attorneys enter the space, more lawsuits are filed, and the overall cost of settling in general increases—which is also happening right now.

Given how quickly technology is evolving, how do you stay ahead of the curve and prepare for issues that may arise?

Joel: I read new class action complaints to identify developing theories of liability being pursued, receive updates on various federal and state privacy legislation that is being proposed, and attend continuing legal education courses. Also, gaining exposure to different technologies helps me brainstorm where plaintiffs may be going with their next theory. Finally, I am fortunate to be at a law firm with tremendous lawyers who practice at the cutting edge of technology and are amazing colleagues with whom I can collaborate to stay ahead of what comes next.

Sarah Ballard defends clients in high-stakes privacy class actions. Focusing her practice on novel, complex legal issues, Sarah represents a client in one of the first pixel/online tracking cases and currently represents over a dozen firm clients in the high-profile MOVEit multidistrict litigation (MDL). She also represents clients with unique legal issues, such as sovereign immunity (for Sarah’s Native American clients) and statutory preemption (Southwest Airlines). Her work on these and other matters has earned her recognition as a 2025 Law360 Rising Star.

Joel Griswold defends clients in cutting-edge privacy class actions and mass arbitrations implicating the treatment of alleged personally identifiable information. As these claims regularly seek to impose ruinous statutory damages, Joel is often called on to defend companies facing litigation that poses an existential threat.

Additionally, Joel regularly counsels clients on compliance with laws governing these areas and risk mitigation. He regularly represents a wide array of SaaS companies and clients across virtually all industries, including insurance and financial services, retail, restaurants, hospitality, healthcare, education, manufacturing, and transportation.

Danielle Dobrusin, Counsel—Global Privacy and Cybersecurity Practice
Hunton Andrews Kurth LLP

Describe your practice area and what it entails.

Hunton’s top-ranked global privacy and cybersecurity practice helps companies manage data and mitigate risks at each step of the information life cycle. We advise clients in identifying, evaluating, and managing complex global privacy and information security risks and compliance issues. We advise clients on U.S. state and federal and international privacy laws and help them practically apply the requirements of these laws. The counsel can range from one-off questions requiring analyses of legal requirements with respect to certain use cases to full-scale holistic compliance programs. It can also include responding to and managing regulatory inquiries and investigations with respect to privacy matters.

We also counsel companies on managing risk in connection with leading-edge and innovative technologies, such as AI and machine learning. We frequently work with local counsel in myriad jurisdictions to provide global services to our clients. For cybersecurity matters, we advise large, multinational companies on all aspects of catastrophic cybersecurity incidents, including providing strategic and legal advice on investigating and remediating the incident; fulfilling their data breach notification responsibilities; responding to multi-juris-dictional regulatory investigations; and managing inquiries from customers, business partners, media, and regulators.

What types of clients do you represent?

We represent a diverse group of clients of all sizes, including retailers, consumer goods companies and manufacturers, energy companies and utilities, technology companies, financial institutions and private equity firms, fintech startups, insurance providers, healthcare providers, media companies, hospitality and gaming companies, and government agencies. Data privacy and security are critical to all types of industries.

What types of cases/deals do you work on?

We advise clients on

  • Compliance with all U.S. federal and state privacy and cybersecurity requirements and international data protection laws.
  • Cybersecurity and data breach incident response.
  • Drafting and negotiating complex privacy and data security provisions and indemnities in vendor agreements, including complex data transactions.
  • Managing federal, state, and international regulatory inquiries in connection with alleged privacy and data security violations.
  • Evaluating cybersecurity and privacy risks and negotiating purchase agreements in connection with potential M&A and other corporate transactions.
  • AI governance and other cutting-edge technology issues.
  • Cross-border data transfer strategies.
  • Designing and evaluating privacy impact assessments.
  • Developing and enhancing comprehensive records management programs.
  • Information product life cycle issues, including marketing and analytics activities.

How did you choose this practice area?

I would say that I was very fortunate to fall into this practice area. When I started as a summer associate at Hunton, I had little sense of what type of law I wanted to practice. Brittany Bacon, who is a partner on the privacy team, quickly took me under her wing. The assignments she gave me were exciting and challenging. I think one of the first ones was analyzing use of facial recognition technologies in retail locations. Because this is such a new and rapidly evolving area of the law, I felt like the work I was doing was meaningful and I could add value and expertise even while at a junior level.

What is a “typical” day like and/or what are some common tasks you perform?

No two days look the same! One of the exciting things about this practice area is that the work is constantly changing depending on the client and project at hand. I would say most days involve some combination of getting to speak directly with clients on calls, responding to “quicker” one-off questions via email, brainstorming, problem-solving with partners on my team, and mentoring and providing feedback to more-junior associates.

What training, classes, experience, or skills development would you recommend to someone who wishes to enter your practice area?

Privacy and cybersecurity continue to be top focus areas among companies and in-house counsel. As a result, there are a number of resources available to learn about this practice area. Follow the news and various industry publications and learn as much as possible. Additionally, I encourage law students and lateral associates to subscribe to Hunton’s Privacy and Cybersecurity Law blog, which we update on a near-daily basis with news items and analysis. Our team has also published a privacy and cybersecurity law treatise, updated annually, which provides a comprehensive primer on U.S. and international privacy and data protection laws. Organizations such as the International Association of Privacy Professionals are great resources as well.

What is the most challenging aspect of practicing in this area?

I think the most challenging aspect of this practice area is that it is rapidly evolving. The U.S. privacy landscape looks entirely different now from when I started; there has been an avalanche of state consumer privacy laws and other state privacy laws related to specific topics such as minors’ and children’s privacy, health privacy, biometric data, and AI. It is not uncommon to spend a week drafting a detailed and complicated memo and then have a new law or regulatory action come out that materially changes the analysis. It is critical to constantly stay on top of recent developments.

What do you like best about your practice area?

Because privacy law is always changing, it means that there are endless opportunities to grow. This is a fantastic practice area for someone who is driven and wants to take initiative. Even as a junior associate, you can become your team’s go-to expert on a specific law or topic. You will never be bored as a privacy attorney!

How do you see this practice area evolving in the future?

It is hard to predict exactly how this practice area will evolve because so much of it depends on how technology evolves and is used. Lawmakers tend to pass laws reactively, and businesses continue to innovate, so there will constantly be new laws and regulations in this area. I certainly see the need for privacy and cybersecurity attorneys continuing to grow.

What kinds of experiences can summer associates gain in this practice area at your firm?

When we work with summer associates, we treat them as true members of our team and rely on them for substantive work. Summer associates frequently contribute to Hunton’s Privacy and Information Security Law blog, participate in client calls, assist with data breach incident response, conduct research, and compile charts comparing key requirements under various privacy and security laws.

Danielle Dobrusin is counsel with Hunton’s global privacy and cybersecurity practice and advises clients on compliance with U.S. federal and state and international privacy and data security laws. Danielle regularly works with clients in developing privacy compliance programs designed to satisfy applicable obligations under all U.S. federal and state privacy and information management requirements, including comprehensive state consumer privacy laws, such as the California Consumer Privacy Act of 2018, and other emerging privacy legislation. She works with clients to revise online privacy notices, implement processes to respond to consumer rights requests, and amend vendor contract templates to comply with new regulations. In addition, Danielle particularly focuses counseling on compliance with the federal Children’s Online Privacy Protection Act and state children and teen privacy and social media laws. Danielle also assists clients with privacy-related issues in the AI and ad tech spaces.

Katy Linsky, Partner • David Sorenson, Associate—Privacy & Cybersecurity
McDermott Will & Schulte

Describe your practice area and what it entails.

Katy: My practice is focused on counseling, advisory, and regulatory compliance work. I help clients build and bring to market products and services and evaluate and comply with the requirements of various privacy and cybersecurity regulations that apply to them on an enterprise level. I also help clients with day-to-day privacy and security questions by, for example, responding to data subject requests and negotiating agreements.

David: Privacy and cybersecurity law involves many different types of projects, which are grounded in our clients’ need to protect the information entrusted to them. Our work typically includes conducting risk assessments to identify potential weaknesses that can be remediated; ensuring that clients understand their obligations under applicable laws, how these obligations apply to new products or projects, and how to design these products to comply with their obligations; and negotiating appropriate agreements where information is shared between multiple parties. We also assist clients in responding to security incidents, where necessary, which typically involves directing the investigation and documenting the incident itself, engaging third parties to assist in the investigation, advising the client on any notification obligations they have, and assisting in addressing any risks that the incident uncovers.

What types of clients do you represent?

Katy: I represent a wide range of clients in varying industries. Some of my clients include Big Tech, entertainment, and media companies; financial institutions; automobile manufacturers; and SaaS providers.

David: I represent all types of clients, including business-to-business, direct-to-consumer, and professional services firms, including law firms and accounting firms. These clients are unique in that, in addition to any legal obligations that most companies have, they also have professional obligations to protect their clients’ data.

What types of cases/deals do you work on?

Katy: My practice is primarily focused on daily counseling tasks and compliance projects. For example, each time a new regulation is introduced that impacts a client or new case law or regulatory enforcement is made available that may impact a client’s risk analysis or exposure, I work with the client to update their practices, policies, and procedures to address the new requirements. When a client is considering building a new product or service, I help them identify and work through any privacy or security issues that may arise.

David: I mainly work with clients in designing and implementing their privacy compliance programs or reviewing and improving their security programs. This frequently includes helping clients understand and strategically incorporate novel technologies, like generative AI. If a client has a security incident, I may also assist in investigating and in notifying individuals and regulators as necessary.

How did you choose this practice area?

Katy: I was introduced to this practice area as a first-year associate at a BigLaw firm. I was asked to help write an article about cyberinsurance, which was a new offering at the time. I was drawn to the novelty of the subject matter and recognized that the field would continue to grow in importance and complexity.

David: I chose this practice area because I am interested in the systematic implementation and development of technology and studied engineering as an undergraduate. I have really enjoyed the dynamic nature at the intersection of technological and legal issues and appreciate that it seems unlikely to settle on any typical set of challenges in the near future.

What is a “typical” day like and/or what are some common tasks you perform?

Katy: Every day is different, which is part of what is so exciting about this practice area. I may be negotiating an agreement one minute, working on a risk analysis for a new product the next, and researching a new law or regulatory framework after that. I meet regularly with my clients to issue-spot and provide gut checks based on ideas the business has brought to them that week.

David: My typical day includes a little bit of everything. Many of my clients are on the East Coast, so my morning often starts with meetings to discuss our projects and any other issues that have arisen. The rest of my workday is typically spent working on these matters or connecting with other McDermott lawyers. Usually, I get to spend my afternoon implementing the issues we discussed in our meetings, like revising contracts, but sometimes urgent new issues, like cyberattacks, require my immediate attention.

What training, classes, experience, or skills development would you recommend to someone who wishes to enter your practice area?

Katy: Anyone looking to get into privacy and cybersecurity should find a way to demonstrate commitment to the field. Stay up-to-date with new laws and developments and seek out relevant internships and classes where available. The International Association of Privacy Professionals is also a great resource for attorneys looking to develop their privacy and cybersecurity skills.

David: If you have the opportunity, take an Introduction to Programming class. This will help you understand how data and computer systems work, which is critical background when determining how laws apply, how companies can comply with applicable laws, whether contractual terms are reasonable, and other similar issues. I also find that contracts—with their definitions and internal references—can be structured similar to computer programs, so it can help to think of a contract like the source code for a relationship between parties. You probably won’t need to write programs as a privacy and cybersecurity attorney, but this background can help you understand things such as how cookies work, how companies store data, or how companies can protect data when sharing it.

What is the most challenging aspect of practicing in this area?

Katy: In our practice, the most important things are flexibility, practicality, and comfort with the unknown. This field is constantly evolving, and regulation does not keep pace with the advancement of new technologies. One of the most challenging (and critical) aspects is keeping up with new developments and sifting through the noise to understand what’s really important from a risk perspective.

David: The most challenging aspect of privacy and cyber-security is ensuring that clients remain aware of relevant obligations under a rapidly changing legal landscape. Legislation related to privacy has matured significantly over the past decade and has expanded within the United States. Depending on their industry, companies may also be subject to industry-specific laws or standards. Understanding both these laws and our clients’ businesses is very important in advising them of not only their current obligations but also how they should anticipate new laws and regulations that will apply.

What do you like best about your practice area?

Katy: Privacy and cybersecurity is an exciting space with a lot of opportunity. My practice changes all the time, and every day, I am faced with complex questions that require thought and collaboration to work through. It’s never boring!

David: Privacy and cybersecurity is a relatively new field of law that comes with significant implications for every other field of law. I often get to work with and learn from experts in other fields, and usually I need to figure out a new issue that hasn’t been clearly answered before. As a result, I get to engage in very abstract and open-ended problem-solving, which I find very challenging but also fun and interesting.

What are some typical tasks that a junior lawyer would perform in this practice area?

Katy: Junior lawyers might help with implementing basic compliance requirements such as drafting privacy policies or taking a first pass at reviewing agreements. Junior lawyers can also help to evaluate and interpret new laws and regulations.

David: As a regulatory practice, junior lawyers will likely start by researching for specific projects and reviewing contracts. These research projects likely address specific questions under the law, such as whether a company can use a web form to receive data subject requests in certain jurisdictions. The contracts will likely be a mixture of data protection agreements and security addenda. Junior lawyers may also be staffed on data breaches, which are always unique and provide the junior lawyer an opportunity to demonstrate their adaptability. As junior lawyers gain experience in these areas, they will develop an ability to understand structural similarities and differences between different types of laws and to address the relative priorities of their clients.

How do you see this practice area evolving in the future?

Katy: This practice area will continue to grow and evolve. We may see additional sector-specific regulation requiring additional specialization within the privacy and cybersecurity umbrella. The practice will also shift with the introduction of new technologies, which we are already seeing in the AI space.

David: In the short term, I expect that we will see laws around the United States and around the world maturing to account for emerging technologies, including AI, and as technology expands further into our common, daily tools, it will become even more critical for companies to emphasize privacy and security at an early stage. Staying on top of the regulatory landscape will require understanding these laws and technologies so that we can properly advise clients on how, for example, “reasonable security” has changed such that it typically requires more controls than it did a decade ago.

Katy Linsky is a New York-based privacy and cybersecurity partner at McDermott Will & Schulte who counsels on data practices throughout the information life cycle. She represents a wide range of clients and advises on regulatory and compliance matters, data use and business strategy, incident response and preparedness, and transactions. Katy has a global practice and focuses on providing practical, risk-based advice to legal and business leaders with an emphasis on privacy by design, development, and innovation. Katy worked in-house at a multinational technology company where she supported AI.

David Sorenson is an associate in McDermott’s Los Angeles office, specializing in privacy and cybersecurity matters. David represents a wide range of clients, including professional services firms, large consumer goods companies, and social media companies. David advises these clients on international data privacy compliance programs, state privacy laws, international privacy laws, and data subject requests. While at McDermott, David has advised clients by investigating and responding to complex and, in some cases, ongoing security incidents. David also advises his clients on strategic technology transactions, international data transfers, implementation of AI, data breaches, and combating internet fraud.

Amisha R. Patel, Partner—Cyber, Privacy & Data Innovation
Orrick

Describe your practice area and what it entails.

Privacy and data security law sits at the intersection of technology, consumer protection, and regulatory compliance. My practice focuses on defending companies in cybersecurity incidents, data breach class actions, privacy litigation, and regulatory investigations. This includes managing the immediate response to a breach, coordinating with internal and external stakeholders, and navigating the complex web of state, federal, and international privacy laws. We advise clients on risk mitigation, regulatory inquiries, and litigation strategy, often in matters attracting significant media and reputational scrutiny. Our work is both proactive—helping clients build resilient data practices—and reactive—guiding them through crisis management, litigation, and resolution.

What types of clients do you represent?

My clients span the technology, financial services, consumer products, and life sciences sectors. I have represented major technology companies, banks, and consumer brands. We also advise startups, energy companies, and global brands facing privacy and cybersecurity risks. Our clients rely on us for practical, business-oriented solutions in high-stakes disputes and regulatory matters. Many engagements begin with a crisis, such as a data breach or regulatory investigation, and evolve into long-term partnerships, with clients entrusting us to manage litigation risk, regulatory compliance, and incident response.

What types of cases/deals do you work on?

I work on a wide range of matters, including data breach class actions, consumer privacy litigation, commercial disputes involving technology and financial services, and regulatory investigations. Recent cases include consolidating and defending over 40 data breach class actions for Evolve Bank & Trust following a cybersecurity incident, managing multidistrict litigation (MDL) in federal court, and negotiating resolution of the MDL. Most recently, I argued a dispositive motion in a commercial dispute of $100 million. I also man-age smaller matters in state and federal court and arbitration, as well as advise clients on claims under the California Consumer Privacy Act and auto-renewal laws.

How did you choose this practice area?

My path to privacy and data security law was shaped by a passion for technology and complex litigation. Early in my career, I had the privilege of representing major technology clients in bet-the-company disputes. The dynamic nature of privacy and cybersecurity—where legal, technical, and reputational issues converge—drew me in. I was inspired by mentors who excelled in crisis management and strategic litigation, and I saw the opportunity to make a meaningful impact for clients navigating rapidly evolving risks. The collaborative, cross-disciplinary environment at Orrick coupled with the challenge of high-profile, press-sensitive matters made privacy and data security a natural fit.

What is a “typical” day like and/or what are some common tasks you perform?

A typical day may involve developing case strategy, coordinating with clients and colleagues, drafting and preparing for argument for all types of motions, managing discovery, and negotiating settlements. Crisis management—responding to incidents, triaging urgent issues, and communicating with stakeholders to manage regulatory and reputational risk—is a key part of the role. While doing this, I also look for opportunities to mentor junior lawyers and collaborate with colleagues across offices. No two days are alike in my practice. The pace is fast, and the stakes are high, requiring disciplined project management and clear communication.

What training, classes, experience, or skills development would you recommend to someone who wishes to enter your practice area?

A strong foundational litigation practice is essential. Courses in civil procedure, evidence, and federal courts are invaluable, as are classes in privacy, cybersecurity, and information governance. Practical experience (i.e., clerkships, internships, or summer associate roles in litigation or regulatory groups) is also an invaluable asset; these experiences help build critical skills. Technical literacy is increasingly important: Understanding how data flows, how breaches occur, and how technology impacts legal risk sets practitioners apart. Skills in crisis management, negotiation, and client communication are vital. Seek mentors who excel in strategic thinking and cross-practice collaboration and pursue opportunities to work on press-sensitive, high-stakes matters.

What is the most challenging aspect of practicing in this area?

The most challenging aspect of privacy and data security practice is managing the fast-moving intersection of legal, technical, and reputational risk. Cybersecurity incidents and privacy litigation often unfold in real time, with incomplete information and intense external scrutiny from regulators, the media, and affected consumers. Clients expect decisive, practical guidance, even when the facts are evolving and the financial, regulatory, and reputational stakes are significant. Coordinating multi-jurisdictional litigation, keeping pace with rapidly changing laws, and balancing client interests with regulatory demands require strategic judgment, adaptability, and a calm approach under pressure.

What misconceptions exist about your practice area?

A common misconception is that privacy and cybersecurity law is purely technical or limited to regulatory advice. In reality, it is a high-stakes litigation practice that requires strategic thinking, crisis management, and cross-disciplinary collaboration. Another misconception is that privacy litigation is only about data breaches; in fact, it encompasses consumer protection, commercial disputes, regulatory investigations, and emerging issues such as AI, biometrics, and digital identity. The field is fast-paced and constantly evolving, with opportunities for creative advocacy and helping shape new law.

What are some typical tasks that a junior lawyer would perform in this practice area?

Junior lawyers in privacy and data security litigation gain hands-on experience with fact development, legal research, drafting pleadings and motions, managing discovery, and preparing for depositions. They may assist with crisis response, coordinate with clients and internal teams, and help develop litigation strategy. At Orrick, junior lawyers are encouraged to take ownership of tasks, participate in client communications, and contribute to building litigation playbooks. They also have opportunities to work on cross-practice matters and receive mentorship from senior attorneys.

Given how quickly technology is evolving, how do you stay ahead of the curve and prepare for issues that may arise?

Staying ahead in privacy and data security requires continuous learning and adaptability. I regularly monitor legal and technological developments, attend industry conferences, and participate in professional networks. Orrick’s collaborative environment fosters knowledge sharing across practice groups, and we leverage AI-enabled tools and analytics to streamline workflows and surface emerging risks. Building relationships with in-house counsel, regulators, and technology experts helps us anticipate issues and deliver practical, forward-thinking advice. We also invest in training and mentorship to ensure that our team is prepared for new challenges.

Amisha R. Patel is a litigator in Orrick’s cyber, privacy and data innovation group based in Boston. With over a decade of experience, Amisha specializes in high-stakes cybersecurity and privacy litigation, data breach class actions, commercial disputes, and regulatory investigations. She is known for her strategic approach, calm leadership under pressure, and ability to manage complex multi-jurisdictional matters. Amisha has represented major technology, financial services, and life sciences clients and is trusted by them for her practical advice and decisive case management. She maintains an active pro bono practice focused on immigration and civil rights issues and is a leader in the South Asian Bar.

Jiwon (Jamie) Kim, Associate • Jennifer Mitchell, Partner
BakerHostetler

Describe your practice area and what it entails.

We are members of the privacy governance and technology transactions team within the digital asset and data management practice group at BakerHostetler, and we focus our practice on helping clients comply with international, federal, and state privacy laws. Our work often starts with analyzing what privacy laws are in scope for a client in this increasingly complex privacy landscape. From there, we provide guidance on all components of achieving privacy requirements under the applicable laws by, for example, drafting privacy policies, designing consent strategies, advising on technical website and ad tech implementation, and negotiating data processing addenda with vendors. We are also supporting an increasing number of privacy regulatory investigations at the federal and state levels. 

What types of clients do you represent?

Our team represents a wide range of clients, including multinational retailers, hospitality services, medical device and life sciences, financial services, tech conglomerates, hospitals, publishers, school districts, universities, media and entertainment companies, and research organizations. 

What types of cases/deals do you work on? 

We counsel clients on compliance with international, federal, and state privacy laws, including the General Data Protection Regulation, Health Insurance Portability and Accountability Act, Family Educational Rights and Privacy Act, and California Consumer Privacy Act. We also specialize in scoping the applicability of enacted and pending U.S. state privacy laws, as well as state-level consumer health data and biometric laws. We help create and implement privacy programs, including drafting and implementing consumer-facing and employee privacy notices and policies, conducting privacy risk assessments, and advising on privacy-by-design for product launches and new data initiatives. Additionally, we negotiate vendor contracts to ensure legal and regulatory compliance, which includes assisting data importers and exporters with international data transfer restrictions and data localization requirements. We also provide privacy legal strategy for global acquisitions and divestitures, performing due diligence to identify privacy risks and develop post-close strategies. 

How did you choose this practice area?

Jamie: I began my legal career thinking that I would be an intellectual property litigator because I was drawn to the intersection of science and law. I realized that privacy work offered a unique opportunity to address complex issues at the intersection of technology, law, and human behavior. Transitioning to privacy governance allowed me to leverage the skills developed during my years as a litigator while focusing on proactive strategies to ensure compliance with privacy regulations in a practical fashion for businesses.

Jen: My interest in privacy began when I was a white collar and government investigations lawyer, which is where my legal practice started. I had always enjoyed the fact-finding, strategy, and creative problem-solving components of my white collar practice, and these skills are also key to our privacy practice. I first pivoted from a white collar to a full-time privacy role at an academic medical center and never looked back. I love how dynamic our practice area is and the variety that this unique discipline brings to our daily work.

What is a “typical” day like and/or what are some common tasks you perform?

Jamie: My tasks are focused on helping clients navigate privacy laws and maintain robust data protection practices, such as drafting privacy policies, reviewing data ingestion points on websites and apps, and analyzing cookies in relation to a business’ opt-out posture. I also review vendor agreements to ensure legal compliance and revise website terms of use to reflect evolving cookie litigation mitigation practices. 

Jen: Most of my day is spent on video calls counseling clients on a range of privacy matters. Sometimes, we are working on large, ongoing projects together, and sometimes, we are responding to a discrete matter that just arose. Every day is different, and I enjoy pivoting between clients from different industries, sizes, and stages in their privacy program development. I also spend time each day collaborating internally with my partners and associates on legal developments, interpretation of laws, and client strategies. 

What training, classes, experience, or skills development would you recommend to someone who wishes to enter your practice area?

There are a number of privacy certifications available through the International Association of Privacy Professionals. We also publish numerous articles and blogs through our website, https://www.bakerdatacounsel.com. Privacy practitioners need to stay continually informed of privacy updates, as information gets stale quickly. 

What is the most challenging aspect of practicing in this area?

The U.S. privacy landscape is rapidly evolving and becoming increasingly complex to harmonize when building and maintaining a privacy program. It can be challenging for busy in-house lawyers to keep up with these requirements, so it is our job to be proactive and make our clients aware of changes in the law and ways that we can update their privacy program and try to future-proof it within the resources that they have. We understand that there may be some fatigue caused by the magnitude of privacy changes in the past five years or so, and our job is to support our clients and to efficiently solve problems with them.

What do you like best about your practice area?

Privacy compliance work offers an incredible amount of variety. No client’s privacy strategy is ever the same as another’s, which means we are constantly facing new challenges and opportunities to learn. Additionally, the intersection of different privacy laws creates interesting fact patterns, making the work intellectually stimulating. This diversity keeps privacy work engaging and allows us to develop creative solutions tailored to each client’s unique needs. There is never a one-size-fits-all approach.

How do you see this practice area evolving in the future?

As technology continues to advance and data becomes an even more critical asset, the complexity of privacy laws and regulations will undoubtedly increase. This will require privacy counselors to stay ahead of the curve by continuously updating their knowledge and adapting to new legal frameworks.

For example, the increasing focus on state consumer rights and data transparency in the absence of a U.S. federal consumer privacy law will continue to drive demand for more robust privacy programs. This demand will only increase as we gain more clarity from regulators through rulemaking, guidance, and enforcement examples. As a result, more businesses will need to implement comprehensive privacy policies, conduct regular risk assessments, and ensure compliance with evolving laws. Additionally, the rise of automated decision-making and AI will introduce new privacy challenges, requiring innovative legal strategies to address issues such as data bias, transparency, and vendor liability.

What are some typical career paths for lawyers in this practice area?

The possibilities are endless, as this is a very marketable area where skilled privacy attorneys remain in high demand. We enjoy the variety of work that private practice offers, but other enriching career paths are available in-house and in government and public policy roles. In private practice, attorneys work with diverse clients, helping them navigate privacy regulations and develop data protection strategies. In-house privacy roles are integral parts of a business’ operations, and in-house attorneys work closely with different departments to ensure compliance with privacy laws and to manage data protection initiatives. Government roles include developing and enforcing privacy laws, leading investigations, and shaping public policy. Each path offers unique opportunities and fulfillment.

Jiwon (Jamie) Kim assists clients in navigating the legal and technical landscape to ensure compliance with developing privacy laws. Additionally, Jamie leverages her background in neuroscience to integrate legal requirements in the emerging areas of machine learning and generative AI with technical capabilities and business operations. 

As BakerHostetler’s Los Angeles, San Francisco, and Orange County digital assets and data management leader and the co-leader of the media and telecommunications industry team, Jennifer Mitchell leverages more than 15 years of legal, compliance, and operational experience as she helps clients navigate the complex landscape of global and strategic privacy matters. Having most recently served in executive privacy leadership roles for two global Fortune 100 companies, Jennifer provides practical business solutions for maintaining compliance with evolving privacy laws.

Holly Brady, Counsel
Hunton Andrews Kurth LLP

Describe your practice area and what it entails.

Hunton Andrews Kurth’s top-ranked global privacy and cybersecurity practice helps companies manage data and mitigate risks at every step of the information life cycle. We advise clients in identifying, evaluating, and managing complex global privacy and information security risks and compliance issues. For cybersecurity matters, we advise large, multinational companies on all aspects of catastrophic cybersecurity incidents, including providing strategic and legal advice in investigating and remediating the incident, fulfilling their notification responsibilities; responding to multi-jurisdictional regulatory investigations; and managing inquiries from customers, business partners, media, and regulators. We also advise clients on conducting proactive cyber incident preparedness activities, including developing incident response plans and information security policies, running executive-level tabletops, performing information security assessment and tests, and engaging third-party experts in advance of an incident. In relation to our privacy compliance practice, we advise clients on state, federal, and international privacy laws; conduct privacy and data security impact assessments; and counsel companies on managing risk in connection with leading-edge and innovative technologies.

Our privacy and cybersecurity practice is augmented by The Centre for Information Policy Leadership at Hunton Andrews Kurth, a privacy think tank associated with the firm.

What types of clients do you represent?

We represent a diverse group of clients of all sizes, including retailers, consumer goods companies and manufacturers, energy companies and utilities, technology companies, financial institutions and private equity firms, fintech startups, insurance providers, healthcare providers, media companies, hospitality and gaming companies, direct marketers, telecommunications and Internet service providers, cloud providers, cybersecurity companies, government agencies, and risk management specialists.

What types of cases/deals do you work on?

We advise clients on the following matters:

  • Compliance with all U.S. federal and state privacy and cybersecurity requirements and international data protection laws.
  • Cybersecurity and data breach incident response.
  • Drafting and negotiating complex privacy and cybersecurity provisions and indemnities in agreements, including complex data transactions.
  • Managing federal, state, and international regulatory inquiries in connection with alleged privacy and data security violations.
  • Evaluating cybersecurity and privacy risks and negotiating purchase agreements in connection with potential mergers, acquisitions, and other corporate transactions.
  • Advising on cross-border data transfer strategies.
  • Designing and evaluating privacy impact assessments.
  • Developing and enhancing comprehensive records management programs.
  • AI governance and other cutting-edge technology issues.
  • Information product life cycle issues, including marketing and analytics activities.
  • Advising on adtech and retail media compliance and contractual issues.

How did you choose this practice area?

When I first started practicing, I advised on technology transactions, which regularly involved tackling data privacy and cybersecurity issues. After a few years, my focus shifted to exclusively advising on data privacy and cybersecurity. Now our practice also increasingly includes advising on issues that arise from advancements in AI.

What is a “typical” day like and/or what are some common tasks you perform?

In this space, every day is unique and unpredictable. On any given day, we advise on issues ranging from complex data transactions, cybersecurity incident response, and data privacy compliance to issues arising from AI and automated decision-making.

What training, classes, experience, or skills development would you recommend to someone who wishes to enter your practice area?

Data privacy and cybersecurity continue to be a critical area of focus for all types of organizations and industry sectors, and there are numerous resources from industry publications to educational programs and industry presentations. Additionally, I encourage law students, associates, and clients that are new to the space to subscribe to Hunton’s Privacy and Information Security Law Blog, www.huntonprivacyblog.com, which we update on a nearly daily basis with news items and analysis. Our team has also published a treatise, the Privacy and Cybersecurity Law Deskbook, which is updated annually and provides a comprehensive primer on U.S. and international privacy and data protection laws. Organizations like the International Association of Privacy Professionals are great resources as well.

What do you like best about your practice area?

The best part of this practice area is that it lives at the intersection of law, technology, and business. To effectively advise in this space, you have to be willing to dive into the technology and business underpinnings of cybersecurity and data privacy issues, in addition to understanding the legal landscape. You can have the most meaningful impact in this practice area by understanding how the legal, technology, and business issues relate to each other.

What misconceptions exist about your practice area?

One common misconception is that you need deep technology expertise to start out in this practice area. That is not necessarily the case, and what is more important is a willingness to ask questions and learn from others who have relevant technology expertise. We work on a regular basis with non-lawyers who are experts in cyber forensics, data science, and other cybersecurity- and privacy-related disciplines. If you are open to learning from others and are willing to ask questions, there are many opportunities to quickly expand your technology expertise.

What is unique about your practice area at your firm?

Our team is uniquely collaborative, which is invaluable in a practice area that has been evolving at a breakneck pace and shows no signs of slowing down. One of the many benefits of our high level of collaboration is that it helps accelerate the learning curve of new team members, especially for lawyers who are new to this practice area.

Given how quickly technology is evolving, how do you stay ahead of the curve and prepare for issues that may arise?

To effectively practice in this space, it is critical to keep pace with advancements in technology because it directly impacts the advice we give on a day-to-day basis. Team collaboration is a significant part of how we stay ahead of the curve, and we also contribute to the practice area through publications, speaking engagements, and teaching and mentoring, which help us stay sharp and on the leading edge of evolving issues in the technology and legal landscape.

Holly Brady is counsel in the firm’s Richmond, VA, office. She assists clients in identifying, evaluating, and managing global privacy and cybersecurity risks and compliance issues. Holly advises on the development of comprehensive privacy compliance and risk management programs by, for example, drafting privacy policies, procedures, and notices. She also has extensive experience negotiating complex data transactions and managing cybersecurity incidents. Prior to joining the firm, Holly managed the data privacy program at a Fortune 500 company, where she advised on data privacy compliance and risk management for the company’s U.S. and international operations. She also is an adjunct professor of Cybersecurity Law at William & Mary School of Law, where she enjoys teaching the next generation of cybersecurity lawyers.

Molly O'Malley Clarke, Associate • Michael Rubin, Partner
Latham & Watkins

Describe your practice area and what it entails.

Michael: I represent technology companies in high-stakes litigation and regulatory matters at the cutting edge, including companies in the AI and other emerging technology sectors. I also lead Latham’s global AI intelligence practice, a cross-border and cross-disciplinary team that includes more than 150 lawyers from 30 practice areas and 15 offices around the globe. We advise at every layer of the tech stack to help clients as they develop, implement, or just explore AI technologies that are transforming business.

Molly: My practice is really to support and advise clients throughout the full compliance life cycle on privacy, cyber, and related consumer protection issues. What we call the “front end” of the life cycle involves advising on the development of or changes to a product, service, or process, whereas the “back end” involves representing our clients in internal or regulatory investigations, inquiries, and enforcement actions, as well as any related litigation that might result.

What types of clients do you represent?

Michael: I primarily represent and advise tech companies—both the major players and startups, the industry stalwarts, and the next-generation leaders—on privacy, cybersecurity, and consumer protection matters, AI matters, and novel business or regulatory issues that arise from emerging technologies.

Molly: Like Michael, I represent a wide range of clients, from market leaders to startups with a single app. There was a time when I would have said that I mostly represent tech companies with tech problems. But these days, virtually every company has “tech problems,” and our client base is increasingly composed of companies not traditionally considered tech companies in sectors like retail or healthcare. We sometimes joke that if your employees use the Internet, you might need our advice.

What types of cases/deals do you work on?

Michael: I advise on everything from developing tech products from the ground up, incorporating AI into all facets of clients’ businesses, and defending litigation or regulatory matters on all manner of issues that involve the use of data and that have been represented to consumers, especially novel and complex issues related to privacy, cybersecurity, integrity, and governance, and the full slate of new AI laws that have emerged.

Molly: I split my time working on matters across the life cycle that I mentioned earlier, which I think holds true for most of us in the practice. On the counseling side, I advise on matters ranging in size from changes to a single feature or product up to a total overhaul of a client’s privacy or cybersecurity program. The breadth of our regulatory work also runs the gamut. Sometimes I’m representing a client receiving a few targeted questions from a single state attorney general; other times, a client is facing a coordinated investigation by state, federal, and even sometimes overseas regulators about all of the company’s privacy or data practices.

How did you choose this practice area?

Michael: What drew me to tech originally is the same thing really that draws me to the area I practice in now: innovation and the ability to work with the most innovative companies on their hardest problems. When I started my practice in 2000, privacy and cybersecurity wasn’t really on anyone’s radar, but over the next decade, I saw these issues come to the forefront, so I began working with clients on what I would call “innovation protection work.” As the industry has evolved, so has my practice.

Molly: For me, entering this practice area was a result of aligning the “how” of my work with the “what” of the subject matter that kept me engaged and challenged and then finding the right opportunities. I knew early that I loved the fact development, critical thinking, and creative analytical processes that are core to counseling and investigations work, and my coursework in national security piqued my curiosity in the legal implications of technology as it evolves. From there, it was a matter of figuring out how to marry those things—and finding the right team to do it with—that led me to my current role.

What is a “typical” day like and/or what are some common tasks you perform?

Michael: Given the vast scope of the practice, my days usually involve some combination of revising briefs, taking a deposition, discussing complex questions with my clients as they wrestle with them, and developing strategies for them as they navigate the global regulatory landscape.

Molly: My days usually include a mix of product counseling work and tasks in service of ongoing regulatory matters. Most days involve some combination of quick-burn, high-priority asks that usually contain a more targeted scope, especially on the advising side, and then longer-term work on investigations and enforcement actions.

What training, classes, experience, or skills development would you recommend to someone who wishes to enter your practice area?

Michael: I recommend that all law students follow the Renaissance model—try to learn as much and as broadly as you can. Once you start practicing law, you’ll have plenty of opportunity to specialize, but in the early stages of your career, you want the broadest base of education and the widest legal footing to figure out where to direct your practice.

For privacy and cyber, consider taking courses in subjects like antitrust and intellectual property, as these areas increasingly intersect with privacy and AI law. As for the technological component of these practices, stay abreast of technology and don’t be afraid of it. Law students who are comfortable with tech will have an edge in understanding and leveraging generative AI and other emerging tools in their practice.

Molly: I also think attitude is important: Adaptability, curiosity, and a willingness to learn play critical roles in finding success in this practice. The technology we work with changes every day, and the laws and regulations applicable to what we do also constantly evolve.

If your school offers a privacy law course that provides an overview of the various legal regimes at play, you may find that beneficial, but keep in mind individual privacy laws that exist today will likely be different by the time you start practicing. Instead, focus on understanding the broader concepts and developing the ability to quickly adapt to new information.

What do you like best about your practice area?

Michael: Practicing in this space for nearly 25 years, I’ve witnessed rapid growth and transformation firsthand. When I moved to San Francisco, the tech industry had the wind at its back; now, we’re standing with a gale force wind in our face. Navigating through a landscape marked by constant innovation and regulatory developments has its challenges but also keeps the practice exciting. We’re not confined to a single jurisdiction or regulatory framework; instead, we address legal issues that span different countries and various technologies. We ride the wave of public perception and public viewpoints, which keeps us on our toes and means the work is never static. To put this into perspective, three years ago, we didn’t have a formal AI practice, and now look at what our capabilities have grown into.

Molly: The best part of practicing in the privacy and data security space is also the biggest challenge—both the facts and the law we deal with change seemingly every single day.

Our clients keep developing new technology and innovating, and the applicable legal regimes respond in kind. So while the advice we provided last month may no longer be the advice we would provide today, it keeps all of us in the practice engaged and entertained, and there’s always a new challenge to take on.

What is unique about your practice area at your firm?

Michael: This is a completely cross-jurisdictional, cross-disciplinary practice. That alone doesn’t make us unique from others, but the degree of the cross-functional and global work that we do sets us apart, whether you’re a partner or an associate.

Molly: We also integrate deeply with our clients in a way that I think sets us apart by forming long-term relationships that allow us to understand their tech and help develop it. This means we have critical context at the outset of any new project—there’s less for them to explain and allows us to assist more efficiently and effectively.

What kinds of experience can summer associates gain at this practice area at your firm?

Michael: We create a very immersive experience for our summer associates, who operate within the practice similarly to our junior lawyers (including the team bonding aspects—I’m personally a fan of taking my team out for big dinners). Summers can expect to assist on regulatory investigations and litigation matters, attend team calls, and help research and develop strategies for the thorny questions that arise with new technologies. We integrate our summer associates into the practice as much as possible to provide them with the true experience of what it’s like to work at Latham.

Molly: We’ll often see a summer step up to become a subject matter expert on some developing technology or brand new regulation, which opens a lot of doors for the types of matters and tasks they work on.

As a case in point, we’re excited about pro bono work in this practice area, and a few years ago I had the opportunity to bring in a summer associate to handle the response to a ransomware attack against a small nonprofit entity. During his time as a summer associate, he got to see the matter through to completion—a valuable experience for someone beginning their legal career.

Given how quickly technology is evolving, how do you stay ahead of the curve and prepare for issues that may arise?

Michael: Staying ahead of the curve in such a fast-paced technological landscape requires a combination of vigilance, client engagement, and forward-thinking strategies. At Latham, we prioritize cultivating long-term relationships with our clients. We don’t just handle individual cases; we’re deeply involved in understanding their product roadmaps and future directions. This close relationship allows us to anticipate potential legal challenges and regulatory changes.

Molly: We also maintain a global perspective, constantly monitoring regulatory and legislative developments across various jurisdictions from the FTC in the United States to the European Commission and regulatory bodies in the Asia-Pacific (APAC) region so that we can help our clients see around corners and plan for what’s coming. And we do so as a collective unit, coordinating across offices and teams so that everyone, from partners to first years, can access and call on the full scope of Latham’s expertise.

Molly O’Malley Clarke is an associate in the Los Angeles office of Latham & Watkins and a member of the privacy and cyber practice and connectivity, privacy, and information group. Molly also serves on the firm’s Training and Career Enhancement Committee. She represents clients in government and internal investigations and enforcement matters spanning privacy, cybersecurity, white collar, and related consumer protection issues. She also advises public and private organizations on regulatory risks and compliance issues relating to privacy and cybersecurity, including compliance program design.

Michael Rubin serves as Global Co-chair of the privacy and cyber practice, Global Vice Chair of the technology industry group, and Global Chair of the artificial intelligence practice. He draws on more than two decades of experience at the leading edge of legal issues in Silicon Valley to regularly provide counsel on and representation for privacy, cybersecurity, consumer protection incidents and on matters arising under U.S. and global regulations, including FTC Section 5; AI matters ranging from design, governance, regulatory compliance and defense to litigation; and emerging technologies and novel business and regulatory issues.

Michael repeatedly earns recognition for his market-changing work from leading industry publications, including Law360, The National Law Journal, and Chambers.

Joseph Santiesteban, Partner—Cyber, Privacy, and Data Innovation
Orrick

Describe your practice area and what it entails.

I’m clients’ first or second call after a data breach. I provide strategic legal advice regarding stopping the attack, investigating, and communicating. This involves directing forensics investigations and guiding clients through the complex web of statutory, regulatory, and contractual breach notification requirements. I also provide advice regarding cyber breach-related issues like engaging with law enforcement, cyber insurers, and auditors. I also lead internal investigations where we collect and review evidence, conduct interviews, and provide findings. When data breaches result in regulatory investigations or litigation, I defend clients.

When not responding to data breaches, I partner with clients to help reduce cybersecurity legal risk. This includes counseling on cybersecurity laws, contractual issues, and incident preparedness activities like tabletop exercises, as well as cybersecurity education and training.

What types of clients do you represent?

I focus on cybersecurity issues in the technology, finance, and energy and infrastructure sectors. I represent industry leaders in telecommunications, social networking, renewable energy, and SaaS businesses, as well as financial institutions. These clients vary in size from startups to large public companies. All companies face cybersecurity legal risks, and my goal is to provide accessible and right-sized advice across the spectrum.

What types of cases/deals do you work on?

  • Advised in a forensic investigation, notification, and disclosure for one of the largest breaches in history, at a multinational telecommunications company.
  • Responded to a ransomware event at a solar and wind farm company.
  • Provided day-to-day cybersecurity and incident preparedness counseling to one of the largest social networks.
  • Provided free counseling sessions to startups regarding key cyber risk areas, incident preparedness and cyber insurance.

How did you choose this practice area?

I wanted a fast-paced practice where I could learn about a fun area of law and about technology at the same time. I also like solving problems with clients rather than for clients, and breach response tends to generate high-pressure situations in which cross-functional teams must collaborate.

What is a “typical” day like and/or what are some common tasks you perform?

Today, I revised responses to a state attorney general inquiry, provided advice on a breach investigation kickoff call, drafted a letter regarding a data breach damages claim, and conducted an interview for a project where we’re revising an incident response plan. This is fairly typical.

What training, classes, experience, or skills development would you recommend to someone who wishes to enter your practice area?

Honing your core law school skills like analyzing, summarizing, and persuading will help. We solve complex problems quickly and explain solutions clearly and succinctly. This takes practice and experience.

Classes in privacy or cybersecurity would help. Cybersecurity law also relies heavily on tort and admin law. More directly, we work with 50 state breach notification laws, more than a dozen federal cyber laws and regulations, and a variety of industry standards and frameworks. There’s no need to know these ahead of time, but general knowledge gives you a head start.

Having curiosity and enthusiasm for technology is a must. The abilities to empathize and collaborate help too. Breach response creates high pressure for quick decisions. You need to understand and appreciate everyone’s views and values, and then work together.

What is the most challenging aspect of practicing in this area?

The intensity. A data breach is often a critical moment for the client. They are stressed and want help fast. You have to be available, committed, and cool-headed.

What is unique about your practice area at your firm?

Orrick has an amazing client base for a cybersecurity practice. For a data-focused practice, you want clients that innovate and push boundaries with data. Managing cyber legal risk is a core component of their growth. That creates interesting problems to solve.

What are some typical tasks that a junior lawyer would perform in this practice area?

Participate on forensic investigation calls; develop timelines; perform notification analyses; prepare for and conduct interviews; draft individual, business, and regulator notifications; and revise contracts.

Joseph Santiesteban is a trusted cyber law advisor. He has worked on some of the largest data breaches in history and regularly advises clients regarding cyber breach response, as well as litigation and government enforcement actions that arise from cyber breaches. He also partners with clients on ways to reduce cyber legal risk while supporting innovation, delivering value to the business, and solidifying brand and consumer trust. He also provides strategic advice to cybersecurity companies, including those looking to push technological and defense boundaries in cyber defense, incident response, and threat intelligence.

Lauren Tsuji, Partner—Commercial Litigation
Perkins Coie LLP (Legacy Profile)

Describe your practice area and what it entails.

I defend clients in privacy-related consumer class actions, including cases seeking novel applications of laws such as the Illinois Biometric Information Privacy Act, the California Invasion of Privacy Act, and the Video Privacy Protection Act. I also represent online service providers in opposing civil and criminal requests for records stored on behalf of users, such as subpoenas, court orders, and search warrants, that would violate the Stored Communications Act or Fourth Amendment. Pro bono work is also an important part of my practice, and I regularly litigate cases involving the privacy rights of survivors and witnesses of sexual assault and domestic violence.

What types of clients do you represent?

My clients are mostly industry-leading global technology companies, including Google, Microsoft, and Amazon. I also represent smaller technology firms and companies offering consumer-facing products and services online.

What types of cases/deals do you work on?

The cases I handle are diverse, but most are class action lawsuits challenging some aspect of a company’s use of consumer data. For instance, I am currently defending cases involving claims about what constitutes unlawful collection or possession of biometric data, a case challenging a company’s alleged use of a dataset to improve facial recognition technology, and a case challenging a company’s alleged use of cookies and other tracking technologies on its website. Beyond litigation, I also advise clients on designing products, services, and websites to comply with data privacy laws and minimize litigation risk.

How did you choose this practice area?

After graduating from law school, I started my legal career practicing patent litigation at another firm. I loved learning about complex technologies and working with innovative clients to understand their products and services, but I craved greater variety in the types of cases I was working on. When I joined Perkins Coie as a lateral associate, I quickly found privacy litigation to be a natural fit, as it allowed me to combine my interest in technology with a desire to address issues relevant to our digital society. The cases I get to work on are high-stakes, impactful, and intellectually stimulating, and I am fortunate to have some of the brightest minds in the industry as my colleagues.

What is a “typical” day like and/or what are some common tasks you perform?

One of the aspects I love most about my practice is that there is no “typical” day. Each case presents unique challenges and opportunities to learn about different facts, laws, and jurisdictions, and no case is the same. As a partner, my work involves strategizing about the best way to position my clients for successful litigation outcomes by, for example, figuring out what defenses to raise to eliminate or narrow the claims at the outset, how to maximize efficiencies in discovery, how to defeat class certification and position the claims for summary judgment, and whether and when to consider settlement. A typical day might involve meeting with my case teams to discuss strategy; supervising associates on legal research; reviewing and revising legal briefs; meeting with expert witnesses, product managers, and engineers to understand the technologies at issue; and negotiating with opposing counsel. Depending on the status of the cases I’m working on and where they are procedurally, I might also be preparing corporate witnesses for depositions, arguing motions in court, or working on an appeal.

What training, classes, experience, or skills development would you recommend to someone who wishes to enter your practice area?

For aspiring privacy litigators, critical thinking, organization, and strong legal research and writing skills are essential. While substantive knowledge of privacy law is beneficial, it’s more important to be curious, willing to learn, and capable of producing high-quality written work. I recommend seeking opportunities to practice legal research and writing through classes, extracurriculars, and internships. For me, participating in a law school clinic was invaluable. In addition to those skills, it taught me case and client management and helped me find my voice as a lawyer.

What is the most challenging aspect of practicing in this area?

The most challenging aspect of privacy litigation is also what makes it the most exciting: That is, the landscape is constantly changing. Governments and regulators are increasingly focused on privacy and are enacting new laws in this space every day. Private litigants are always exploring ways to expand existing laws to cover new technologies they were never intended to reach. This requires staying current on legal developments and tracking evolving trends in class actions, which can be challenging to balance with day-to-day work. However, it also provides opportunities to think creatively and litigate issues of first impression, which makes it deeply rewarding.

What is unique about your practice area at your firm?

Perkins Coie has one of the country’s largest, most longstanding, and most experienced privacy and data security groups. What makes our group unique is that we cover a broad range of subspecialties. For example, in my litigation practice, I often collaborate with colleagues who are leading experts in security breach response, cybercrime, and regulatory investigations. We also have the nation’s preeminent Electronic Communications Privacy Act practice representing online communications companies in responding to requests for user data. So, in addition to defending my clients in litigation, I can connect them with other lawyers who can help design their privacy programs to avoid litigation in the first place.

What are some typical tasks that a junior lawyer would perform in this practice area?

The junior associates I work with are given a lot of responsibility. It’s not uncommon for first- or second-year associates to draft dispositive briefings or argue motions in court. For example, this week, I’m working with junior associates on drafting an answer and affirmative defenses to a class action complaint, revising a mediation brief, identifying documents for an upcoming deposition, and drafting an opposition to a motion to compel in a pro bono case.

How do you see this practice area evolving in the future?

Generative AI and related technologies are set to revolutionize the practice of law, and privacy litigation is no exception. Among other things, these technologies will help us stay updated on the latest legislation, summarize and predict trends in case law, and assist clients in making informed, data-driven decisions using fewer resources. At the same time, the collection and use of data to train these systems— especially personal data—will give rise to new types of privacy-related legal claims and regulatory risks.

Lauren Tsuji represents clients facing consumer class actions with a focus on privacy and data security litigation. She routinely litigates disputes involving the Illinois Biometric Information Privacy Act, the California Invasion of Privacy Act, the Stored Communications Act, the Video Privacy Protection Act, and other state and federal privacy and consumer protection statutes.

Lauren has managed all stages of civil litigation, including discovery, briefing and arguing dispositive motions, and trial preparation, and has represented clients in jury trials for patent infringement, resulting in findings of non-infringement and invalidity. In addition to her litigation practice, Lauren counsels clients on compliance with privacy and data protection laws, including laws addressing the collection and use of biometric data, and issues related to government surveillance and demands for user information.

In her pro bono practice, Lauren represents survivors of domestic violence in restraining order proceedings and litigates to defend the privacy rights of victims and witnesses in felony domestic violence and sexual assault cases.

Lauren is dedicated to building an inclusive and intersectional community and supporting women lawyers of color and serves as Co-chair of the Women of Color Resource Group at Perkins Coie.

Related Vault Guides
Check out some of Vault's guides that are related to this field.
Top Ranked Firms
Check out the top-ranked law firms in Privacy & Data Security.