Skip to content
This is available in:

Cyberattacks, data breaches, privacy incidents, and technology challenges have increased dramatically in recent years, making it critical for companies worldwide to understand the privacy-related legal risks they face in the course of doing business.

Sidley’s Privacy and Cybersecurity practice established itself over two decades ago as a leading source for privacy and cybersecurity advice. Practicing actively in this area since 1998, the group has been at the forefront of cyberlaw.

“Excellent practice recognized for its litigation strengths and compliance expertise, maintaining a respected incident response and data breach team.”
Chambers USA 2021, Nationwide: Privacy & Data Security – The Elite

Our group represents businesses in complex cybersecurity, privacy, and novel technology matters, as well as related regulatory, litigation, investigation, and law enforcement issues. Comprising more than 70 lawyers, the global team focuses on cutting-edge matters related to cybersecurity preparedness, confidential information and intellectual property, incident and data breach response, and privacy and data protection. From Fortune 100 corporations to emerging startups, our cyberlaw lawyers guide companies through data security crises of all sizes, and help them respond to rapidly evolving global threats to data assets.

See our Recent Deals

Contacts

As a top-tier global privacy and cybersecurity law firm, we assist clients with cybersecurity compliance and digital governance programs, privacy, data and consumer protection, information security, data security litigation and investigations, and multijurisdictional regulatory, law enforcement, and policy issues. We assist companies in managing data security crises as well as more routine incidents, and help them respond to sophisticated threats to their data assets. Our lawyers have deep experience in the rapidly developing areas of information security, cyber, and technology, advising clients on challenging issues related to the Internet of Things, big data analytics, artificial intelligence (AI), adtech, data governance, data ethics, and other innovative business applications. We also work with C-suite executives and corporate boards to address their public disclosure obligations and fiduciary responsibilities to shareholders and other stakeholders.

Few other privacy and cybersecurity law firms can match the depth and breadth of Sidley’s global cyberlaw platform. We bring value to clients in the following ways:

  • Integrated Services: We leverage the firm’s vast range of legal disciplines, resources, and cross-servicing opportunities for our clients, working across offices and disciplines to ensure they benefit from our collective experience. Our cyberlaw team works closely with colleagues from the firm’s Banking and Financial Services, Securities Enforcement, Life Sciences, Litigation, International Trade, Technology and Life Sciences Transactions, Telecom and Internet Competition, and Government Strategies practices to provide seamless advice on complex privacy and cybersecurity law issues.
  • Cyber Investigations and Litigation: We represent clients on the full scope of investigation, enforcement and litigation arising from cybersecurity incidents. We conduct confidential internal investigations for a diverse range of businesses, often advising on corporate governance issues and compliance programs. Our lawyers have achieved victory in several high-profile class action cases and numerous FTC and State AG investigations.
  • U.S. and International Regulatory Insight: Members of our team have been involved in the development of cyberlaw regulation and enforcement, having formerly served in senior government roles. We are active in Washington, D.C. with respect to investigations and guidance by the FTC, the expanding cybersecurity agenda of the SEC, state attorneys general and the new federal privacy legislative initiatives. Our lawyers have in-depth knowledge of EU and UK regulations and have developed strong relationships with a number of European regulators. Lawyers in the group also advise clients regarding privacy law requirements and developments in the Asia Pacific region.
  • Industry Advocate: Our privacy and cybersecurity lawyers remain on the leading edge of cyberlaw with innovative thought leadership. In addition to frequent speaking engagements, news alerts, webinars and publications, we keep clients abreast of emerging issues through our industry-leading blog: Data Matters, and through organizing many industry privacy and cyber networks and benchmarking roundtables including Women in Privacy and dplegal. We also provide frequent insights and developments on the California Consumer Privacy Act and the General Data Protection Regulation.

A Strategic Approach to Cyberlaw

INCIDENT PREPAREDNESS AND RESPONSE PLANS

  • Design incident response plans and “play books” in light of a variety of GDPR, CCPA, and other U.S. and international regulatory regimes
  • Arrange statements of work with forensic providers, PR agencies and credit monitoring providers with legal privilege as a paramount consideration
  • Partner with forensic firms to conduct technical reviews of IT systems and vulnerability mitigation
  • Serve as “stand-by” cybersecurity counsel

DATA GOVERNANCE

  • Conduct internal cybersecurity and digital governance legal assessments and due diligence on behalf of boards and senior executives
  • Design and implement data governance systems (such as “ethical stewardship” of data) for operational and innovative data use, including risk mitigation for AI deployments
  • Design data governance architecture that classifies information by sensitivity and significance
  • Deliver operational and board-level training on cybersecurity matters

TABLETOP TRAINING

  • Develop custom tabletop scenarios based on client’s business needs
  • Conduct on-site incident scenario exercise working with stakeholders to assess decision points
  • Debrief the client and provide observation, gaps, and recommendations
  • Team up with forensic firms to provide an added layer of complexity by engaging the IT department

CRISIS MANAGEMENT AND DATA BREACH INCIDENT RESPONSE

  • Respond to complex multi-jurisdictional data breaches worldwide, including advanced persistent threats
  • Assess legal obligations under various EU, U.S., and international regulations and contractual commitments
  • Engage and manage forensic service providers and other service providers
  • Liaise with regulators and law enforcement agencies in the EU, U.S., and internationally

CYBERSECURITY INVESTIGATIONS AND LITIGATION

  • Defend companies in class, representative, or group litigation arising out of data breach incidents
  • Respond to enforcement actions brought by EU data protection authorities, the FTC, state attorneys general, the SEC, FCC, and other government agencies
  • Assist in responding to EU, U.S. and international law enforcement agencies
  • Conduct internal investigations on behalf of board of directors with respect to corporate incidents and preparedness

CYBERSECURITY IN FINANCIAL SERVICES — CONFIDENTIALITY AND BANK SECRECY

  • Advise on cybersecurity obligations under EU and UK financial services laws, including under EU’s Market Abuse Regulations and UK’s Financial Conduct Authority rules and Takeover Code
  • Counsel on the U.S.’s Fair Credit Reporting Act and FACTA, the Gramm-Leach-Bliley Act and the Right to Financial Privacy Act, as well as numerous state privacy, data security, and data breach statutes

PHARMACEUTICAL, HEALTHCARE AND DIGITAL HEALTH AND WELLNESS

  • Provide counsel on cybersecurity obligations under EU laws, including those applicable to clinical trials and UK’s National Health Service
  • Advise on cybersecurity requirements under the U.S. HIPAA and HITECH, state, and EU data protection requirements for health information

PUBLIC POLICY AND GOVERNMENT STRATEGIES

  • Engage with the FTC, Secret Service, DOJ, Department of Homeland Security, elements of the intelligence community and state attorneys general
  • Interact with the European Data Protection Board and data protection authorities in various EU Member States
  • Communicate with the UK’s ICO, the National Cybersecurity Centre, and the Serious Fraud Office