Privacy & CybersecurityOverviewPrivacy & Cybersecurity are top concerns in today’s boardrooms—with good reason. Regulations have proliferated, cyberattacks are commonplace, and companies are being fined millions of dollars for poor data handling practices. Michael Best’s Privacy & Cybersecurity team provides legal counseling to support risk mitigation strategies across the enterprise, and help clients to stay ahead of emerging threats. Our attorneys have in-house experience and extensive backgrounds working with the highest levels of federal, state, regulatory agencies. This gives us a combination of advanced insight into the thinking of regulators and direct experience in solving real-world privacy and security challenges. We will serve as your Privacy General Counsel and become an integral member of your team to develop, implement, and maintain a reliable corporate cybersecurity strategy. Our proactive approach involves assessing how data is managed across the whole enterprise, identifying your vulnerabilities, and building a customized compliance program to meet your specific needs. We work with all sizes and types of clients, including those in heavily regulated or critical infrastructure industries such as communications, energy, financial services, healthcare, retail, and information technology.
Service Areas
Regulatory Compliance & Data Protection
Michael Best provides full-service compliance counseling across the evolving spectrum of global privacy and cybersecurity law, under U.S. federal and state regulations and industry standards (e.g., CAN-SPAM, COPPA, GLBA, HIPAA, NYDFS, PCI-DSS, and FTC/FCC regulation); European Union regulations, including GDPR; and Latin America and Asia-Pacific regional standards.
We take an innovative approach to managing regulatory issues, with the Best Privacy & Cybersecurity Toolkit, which is an online platform that helps our clients manage compliance with a variety of regulatory frameworks including the NIST Cybersecurity Framework and GDPR.
In addition to our Toolkit, we provide ongoing support in mitigating risk and maintaining compliance with GDPR, as further guidance’s are published.
We also provide counsel on privacy and cybersecurity e-commerce issues including CAN-SPAM, TCPA, Do Not Call, E-Sign, internet privacy, and many others, keep our clients compliant with every changes rules and regulations, enabling our clients to achieve their business objectives.
Public Sector Privacy & Cybersecurity
Our team, which has in-house experience in government and business, has critical insight into how federal and state governments define, enact, and manage cybersecurity policy and regulations.
Incident Preparedness & Response
We help clients develop incident response plans, conduct on-site tabletop exercises, remediate data breaches, respond to third party investigations or claims, and manage crisis communications.
We partner with trusted resources to manage and investigate small and large scale breaches arising from all varieties of cybercrimes and threats, engaging third party resources, preserving the attorney-client privilege.
We tailor the tabletop exercise to their business, their people. Through the response to the exercise, we update/craft a response plan to assist in mitigating future risk, in accordance with applicable regulatory requirements.
Governance & Risk Management
We develop robust risk mitigation strategies to help you defend reputational and legal challenges through our customized, integrated approach to policy, procedure, and risk assessment and management.
Investigations, Dispute Resolution & Litigation
We represent clients throughout internal audits and investigations, third-party disputes, federal and state government investigations, and regulatory enforcement actions, helping them navigate federal and state agencies and external auditors.
Our team also focuses on stakeholder preparation and counseling, working with individuals who are externally facing, to prepare them for media spotlight, testimony, depositions, and other public statements.
We strategically partner with our litigation team to provide clients a full range of resources if litigation is imminent. Our team advises and provides support to the litigation team throughout the litigation process, assisting with case evaluation, discovery and settlement strategy, evaluating the merits of the claim, seeking indemnification where available, tendering to cyber insurance carriers and following protocols, all to achieve a beneficial outcome for our clients.
Supply Chain & Vendor Management
We advise customers and suppliers on privacy and cybersecurity risk concerns, including pre-contract diligence, contract preparation and negotiations, and post-contract audits.
Our team is available to assist through the entire life cycle, starting with vendor selection process through contract termination and exit strategy.
Emerging Technologies
When clients are developing or adopting new technologies (e.g., IoT or blockchain), we help them achieve business objectives while being mindful of emerging law and interpretations.
Our team helps clients integrate privacy and cybersecurity into their new technologies and projects from the onset, incorporating the principles of Privacy by Design and Default.
Click here for additional resources.
Privacy & Cybersecurity Education & Training
Our training programs empower your organization to develop a first line of defense in privacy and cybersecurity risk management, by creating a structured program to identify key cybersecurity and privacy issues.
Interactive Gaming & Online Sports Books
We counsel gaming industry clients on crucial privacy and data security issues, creating customized compliance programs for risk mitigation. We advise on the full spectrum of privacy and cybersecurity regulations at the state, federal, and global level. Our experience includes developing privacy policies and terms of service that address gaming regulations across multiple states; counsel on issues related to third-party data transfers; and data breach incident preparation and response.
Experience
- Represented various clients in assessing and responding to data breaches, managing multi-state breach notifications, including notification to regulators, and providing credit monitoring
- Negotiated data aggregation agreement between client and major financial institution to allow sharing of financial institution customer information with third parties
- Counseled on sharing of financial institution nonpublic personal information with non-affiliated third parties under joint marketing agreements and service provider agreements in order to increase and refine targeted marketing efforts
- Advised on FCRA issues relating to firm offers of credit involving financial institution, credit bureau, and multiple service providers
Related PeoplePreview Attorney's BiographyRobb brings a wealth of experience to his role at Michael Best, where he focuses on privacy, artificial intelligence, and data protection strategy. With a solid foundation built during his tenure at one of the largest insurance companies in the U.S, Robb has honed his skills in navigating complex legal landscapes, particularly in the realms of privacy compliance and emerging technologies.In his previous role, Robb served as lead counsel on various global initiatives, including HR transformation ... Preview Attorney's BiographyDaniel assists companies with privacy and cybersecurity matters, from proactive approaches to breach response. He began his career with Michael Best as a law clerk, joining the firm as an associate attorney after obtaining his law degree from the University of Denver Sturm College of Law. Preview Attorney's BiographyAriel brings extensive knowledge to his role at Michael Best, where he focuses on Privacy, Cybersecurity, and AI counseling. With more than a decade of experience spanning from government service, to management and technology consulting, to leading digital entertainment hardware, software, and services companies, Ariel has accrued a unique set of skills in complex data legal, policy, and management matters.In his most recent role, Ariel served as a legal director and Global Privacy Officer at So ... Preview Attorney's BiographyLinda is a data privacy, security, and technology lawyer with a wealth of experience helping clients navigate the complex world of data privacy and security laws and compliance. Preview Attorney's BiographySam brings a wealth of knowledge and hands-on experience to Michael Best. With more than two decades of experience spanning both in-house, government and private practice roles, Sam has cultivated a unique blend of skills in global privacy and data security counseling, investigations and labor and employment law.Before joining Michael Best, Sam served in several roles at a leading provider of industrial automation and digital transformation technologies, including assistant general counsel, empl ... Preview Attorney's BiographyRyan is a paralegal in the firm’s Corporate Practice Group. He assists Michael Best attorneys with a variety real estate, corporate, and data privacy matters. He conducts property and tax assessment research, performs due diligence, ALTA/NSPS land survey analysis, title and policy review, evaluation of agricultural foreclosures, and manages closings for commercial, residential, and agricultural real estate transactions throughout the country. Ryan L. Habeck* *Names that appear with an asterisk indicate a Michael Best professional not admitted to practice law. Preview Attorney's BiographyChelsea counsels clients on data privacy and security matters including building compliance frameworks under applicable state, federal, and international privacy laws. Chelsea also advises on data security best practices and responding to data breaches.
Before joining Michael Best, Chelsea was an Assistant Attorney General Fellow in the Colorado Attorney General's Office. There, she enforced Colorado’s data security laws, supported the Colorado Privacy Act rulemaking, and drafted priv ... Preview Attorney's BiographyGuy counsels clients on privacy and data security matters including compliance with U.S. and E.U. data protection and privacy laws, the development of company privacy programs, and responding to and mitigating data breaches. Preview Attorney's BiographyLiz counsels clients on privacy and data security matters including compliance with applicable data privacy regulations and implementation of proactive cybersecurity measures. She also helps guide clients through all aspects of data security incidents. Liz holds the Certified Information Privacy Professional/United States (CIPP/US) credential through the International Association of Privacy Professionals.
|