Decorative building image

Data Privacy & Security

Data Privacy & Security

Data Privacy & Security

Download PDFDownload PDF
Print
Share

Overview

BCLP’s Global Data Privacy and Security team is composed of lawyers located across the United States, the United Kingdom and continental Europe, and Asia.  We routinely advise clients in a variety of sectors, including hospitality, consumer services, healthcare, software and technology, financial services, travel, manufacturing, and retail. We coordinate advice across multiple jurisdictions for clients working to achieve the most streamlined international data privacy strategy as possible, and we excel at helping companies achieve their business goals while balancing and addressing privacy and security obligations in a practical, business-focused approach.  We pride ourselves on our responsiveness and building teams shaped to meet our clients’ needs. 

AI legislation & regulation trackers

AI legislation & regulation trackers

US state-by-state

AI legislation snapshot

To help companies achieve their business goals while minimizing regulatory risk, our team actively tracks proposed and enacted AI regulatory bills from across the United States to enable our clients to stay informed in this rapidly-changing regulatory landscape.

UK and EU

UK and EU take divergent approaches to AI regulation

As companies increasingly integrate AI into their products, services, processes, and decision-making, they will need to do so in ways that comply with the varying regulatory approaches in the UK and EU.  Our UK and EU AI Regulation Tracker will keep you updated on legislation that, if passed, would directly impact businesses’ development or deployment of AI solutions in the UK and EU.

Privacy Advisory

Our team has extensive experience handling the full scope of complex privacy and security issues.  From a data privacy perspective, we advise clients on the development of comprehensive privacy and data protection programs, data sharing and international mobilization of data, complex transactions involving monetization and licensing of data, as well as with conducting gap assessments to align with international privacy standards, responding to regulatory investigations and inquiries, and defending companies in court and before government agencies in enforcement actions. 

This counseling spans the gamut of US and non-US privacy laws, including the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), the Health Insurance Portability and Accountability Act, the Children’s Online Privacy Protection Act, the Gramm-Leach-Bliley Act, the Fair Credit Reporting Act, state privacy and data breach laws, FTC and state law enforcement issues, as well as emerging laws and regulations around the world.

Incident Response and Preparedness

In the context of incident response and preparedness, we have a world class incident response practice that has helped clients navigate major security incidents and data breaches, including ransomware attacks, O365 mailbox intrusions, malware, credential harvesting, insider threats, and inadvertent disclosure. We leverage that experience to help companies identify and remediate gaps in their readiness and to train companies how to respond to breaches effectively. Should an incident occur, BCLP’s 24-hour data breach hotline connects clients directly with experienced attorneys who will guide companies through all aspects of breach response, from investigation and notification to regulatory investigation or litigation. Our experience and practical approach to data breach response uniquely equip us to assist organizations by understanding both the law and the business implications of data breaches. We help clients get ahead of incident response issues by a providing range of offerings, including bespoke “drill” exercises with c-suite executives, analysis of insurance coverage, contractual analysis to identify business partners and customers who require notification of a breach, and evaluation and engagement of third party providers under privilege (forensics, PR, call centers).

We are continually working to understand new privacy and security issues and to partner with our clients to shape practical, risk-based solutions that can be adapted over time to ever-changing technologies, business priorities and laws.            

Amy de La Lama

Amy de La Lama

Partner; Chair – Global Data Privacy and Security Practice; and Global Practice Group Leader – Technology, Commercial and Government Affairs, Boulder

+1 303 417 8535
Geraldine Scali

Geraldine Scali

Partner and EMEA Lead of Data Privacy and Security, London

+44 (0) 20 3400 4483
Christian M. Auty

Christian M. Auty

Partner and US Lead – Data Privacy and Security , Chicago

+1 312 602 5144
Amy de La Lama

Amy de La Lama

Partner; Chair – Global Data Privacy and Security Practice; and Global Practice Group Leader – Technology, Commercial and Government Affairs, Boulder

+1 303 417 8535
Geraldine Scali

Geraldine Scali

Partner and EMEA Lead of Data Privacy and Security, London

+44 (0) 20 3400 4483
Christian M. Auty

Christian M. Auty

Partner and US Lead – Data Privacy and Security , Chicago

+1 312 602 5144

Meet The Team

Amy de La Lama

Amy de La Lama

Partner; Chair – Global Data Privacy and Security Practice; and Global Practice Group Leader – Technology, Commercial and Government Affairs, Boulder

+1 303 417 8535
Geraldine Scali

Geraldine Scali

Partner and EMEA Lead of Data Privacy and Security, London

+44 (0) 20 3400 4483
Christian M. Auty

Christian M. Auty

Partner and US Lead – Data Privacy and Security , Chicago

+1 312 602 5144

Experience

  • Defending a major online fashion retailer in a lawsuit alleging violation of the Video Privacy Protection Act.  The suit alleges that the client hosts video content on its website and that by also using Facebook pixels on its website to track usage statistics, it is unlawfully sharing personally identifiable information concerning videos viewed by users with a third party, in violation of the VPPA.
  • Defending a provider of crypto currency trading software in a class action lawsuit filed in the wake of disclosures that the company was the victim of criminal hacking. The hacking resulted in the unauthorized disclosure of API keys, which were allegedly used by the hackers to consummate unauthorized trades in user accounts on various crypto currency exchanges.

Representative Clients

  • Red Robin – Casual dining restaurant chain operating in the U.S.
  • Delaware North – Manages and provides food and beverage concessions, dining, entertainment and lodging at high-profile locations throughout the world
  • Best Western International – One of the top five largest hotel chains in the world.
  • World Wide Technology, Inc.  – One of the 100 largest privately held companies in the United States; provides technology needs to national and multi-national companies with revenues in excess of $7.4 billion annually
  • Grindr LLC – Grindr is the premiere platform for the global LGBTQ+ community to connect, learn and champion their rights. With more than 3.8 million daily active users in more than 190 countries, Grindr empowers people to be themselves in a safe and meaningful way. Given the sensitive nature of information disclosed in-app, the company is focused on global compliance with data privacy and security laws.
  • Washington University in St. Louis. – Washington University is routinely ranked as one of the top 15 universities within the United States, and one of the top 5 medical schools in the United States.
  • IHS Markit Ltd. – Global diversified provider of critical information, analytics, and solutions
  • Dillard’s Inc. – An upscale department store chain in the U.S. with more than 325 stores in 28 states
  • eClinicalWorks – One of the main providers of electronic medical records to physicians and health groups
  • Backstop Solutions – Provider of portfolio management technology to financial advisors and hedge funds

Related Insights

Insights
Dec 19, 2024

Out with the old and in with the new- The Data (Use and Access) Bill

On 23 October 2024, the Data (Use and Access) Bill (the “DUAB”) was introduced to Parliament. The DUAB is the Labour government’s answer to the perceived shortfalls of the since-abandoned Data Protection and Digital Information Bill (the “DPDI” Bill). We unpack below the elements from the DPDI Bill that were abandoned, those retained, and the newly added ones introduced by the DUAB.
Insights
Dec 10, 2024

AI in HR - what you need to know

BCLP recently hosted a seminar on AI in HR. In this thought-provoking session, we considered how AI is used in HR and its regulation in the EU and the UK, and then engaged in some discussions around two theoretical scenarios. For those who were not able to attend, we have put together a summary of the key takeaways. 
Insights
Dec 06, 2024

Data and Cybersecurity - European Union Legislation and Proposals

The pace of new EU law continues unabated, with IoT, cyber security and digital services being key areas of activity. The BCLP Data Privacy & Security team is tracking EU law developments relevant to data and cyber security. In our tracker we (1) provide a snapshot, (2) explain who is impacted and (3) confirm the status and timeline for each of: the Digital Services Act, the Digital Markets Act, the Data Governance Act, the Data Act, the NIS2 Directive, the Cybersecurity Act and the Cybersecurity Resilience Act.
Insights
Dec 06, 2024

What is the impact of the EU's new Network and Information Systems Directive for Businesses?

Forming part of the EU’s broader digital and cyber security strategy, the new Network and Information Systems Directive 2022/2555 (NIS2) came into effect on 18 October 2024 (this being the deadline by which the directive is required to be implemented into national law, although this process is not yet complete).  It replaces NIS Directive 2016/1148 and complements the EU’s Cyber Resilience Act (discussed in a recent BCLP insight).  The revised directive is intended to cast a wider net and bring more industries and sectors directly within its regulatory remit.  In-scope businesses will therefore need to ensure appropriate risk-management procedures are embedded across their organisations.  Senior management also need to understand the oversight which they are required to exercise, given the personal liability for cybersecurity failings which NIS2 now mandates.   
Insights
Dec 04, 2024

AI Tools in Recruitment – Key Takeaways from the ICO Report

On 6 November 2024, the ICO published an outcomes report on AI tools in recruitment (the “Report”). This Report follows consensual audit engagements carried out by the ICO with developers and providers of AI tools to be used in recruitment between August 2023 and May 2024 and is part of the ICO’s ongoing upstream monitoring of the wider AI ecosystem to ensure compliance with UK data protection law.
Insights
Nov 25, 2024

Key insights on the EU Cyber Resilience Act – what businesses need to know

The Cyber Resilience Act (CRA) is a groundbreaking piece of legislation designed to enhance the cybersecurity of digital products and services made available in the EU. Published last week in the Official Journal of the European Union, it marks the start of a phased 3 year implementation period.  The CRA aims to strengthen the resilience of the EU’s digital economy by imposing stricter requirements on manufacturers, importers, and distributors of products or software with a digital component and will therefore have significant compliance consequences for businesses.

Related Insights

Insights
Dec 19, 2024
Out with the old and in with the new- The Data (Use and Access) Bill
On 23 October 2024, the Data (Use and Access) Bill (the “DUAB”) was introduced to Parliament. The DUAB is the Labour government’s answer to the perceived shortfalls of the since-abandoned Data Protection and Digital Information Bill (the “DPDI” Bill). We unpack below the elements from the DPDI Bill that were abandoned, those retained, and the newly added ones introduced by the DUAB.
Insights
Dec 16, 2024
TCPA landscape set to shift with Supreme Court's grant of certiorari to McLaughlin junk fax case
Insights
Dec 10, 2024
AI in HR - what you need to know
BCLP recently hosted a seminar on AI in HR. In this thought-provoking session, we considered how AI is used in HR and its regulation in the EU and the UK, and then engaged in some discussions around two theoretical scenarios. For those who were not able to attend, we have put together a summary of the key takeaways. 
Insights
Dec 06, 2024
Data and Cybersecurity - European Union Legislation and Proposals
The pace of new EU law continues unabated, with IoT, cyber security and digital services being key areas of activity. The BCLP Data Privacy & Security team is tracking EU law developments relevant to data and cyber security. In our tracker we (1) provide a snapshot, (2) explain who is impacted and (3) confirm the status and timeline for each of: the Digital Services Act, the Digital Markets Act, the Data Governance Act, the Data Act, the NIS2 Directive, the Cybersecurity Act and the Cybersecurity Resilience Act.
Insights
Dec 06, 2024
What is the impact of the EU's new Network and Information Systems Directive for Businesses?
Forming part of the EU’s broader digital and cyber security strategy, the new Network and Information Systems Directive 2022/2555 (NIS2) came into effect on 18 October 2024 (this being the deadline by which the directive is required to be implemented into national law, although this process is not yet complete).  It replaces NIS Directive 2016/1148 and complements the EU’s Cyber Resilience Act (discussed in a recent BCLP insight).  The revised directive is intended to cast a wider net and bring more industries and sectors directly within its regulatory remit.  In-scope businesses will therefore need to ensure appropriate risk-management procedures are embedded across their organisations.  Senior management also need to understand the oversight which they are required to exercise, given the personal liability for cybersecurity failings which NIS2 now mandates.   
Insights
Dec 04, 2024
AI Tools in Recruitment – Key Takeaways from the ICO Report
On 6 November 2024, the ICO published an outcomes report on AI tools in recruitment (the “Report”). This Report follows consensual audit engagements carried out by the ICO with developers and providers of AI tools to be used in recruitment between August 2023 and May 2024 and is part of the ICO’s ongoing upstream monitoring of the wider AI ecosystem to ensure compliance with UK data protection law.
Insights
Dec 02, 2024
Navigating Consumer Opt-Outs in Corporate Transactions: Insights on California’s AB 1824
Insights
Nov 25, 2024
Key insights on the EU Cyber Resilience Act – what businesses need to know
The Cyber Resilience Act (CRA) is a groundbreaking piece of legislation designed to enhance the cybersecurity of digital products and services made available in the EU. Published last week in the Official Journal of the European Union, it marks the start of a phased 3 year implementation period.  The CRA aims to strengthen the resilience of the EU’s digital economy by imposing stricter requirements on manufacturers, importers, and distributors of products or software with a digital component and will therefore have significant compliance consequences for businesses.
Blog Post
Nov 06, 2024
The SEC is watching: four companies charged for misleading cyber disclosures