Overview
Nearly every facet of a company’s operations is subject to a complex array of privacy and cybersecurity challenges. Our clients rely on our in-depth understanding of the law and our ability to partner with them to find practical ways to mitigate risk.
Our 30+ global, interdisciplinary Privacy & Cybersecurity Team includes some of the most respected lawyers in the privacy space, including a lawyer who literally “wrote the book” on data breach, award-winning privacy class action litigation practitioners, and leading incident response practitioners. Not only our many of our team members CIPP certified by the IAPP, but we are active members in the organization, from committee participation to running privacy trainings, underscoring our commitment to the privacy field.
Sheppard Mullin's Privacy Team accolades include being named Law360’s Cybersecurity & Privacy Practice Group of the Year; highly ranked by Legal 500 USA (Cyber Law), Legal 500 Europe (EU Data Protection); and one of only 25 firms ranked in the inaugural ATL Top Law Firm Privacy Practice Index.
Our lawyers have experience in the full breadth of privacy and cybersecurity matters. From high-profile data breaches, regulatory investigations, complex litigation, compliance counseling, we assist a broad array of clients across a spectrum of industries. Clients rely on the integrated nature of our global offering and our ability to address privacy and security issues faced by global brand and retail clients at a senior level.
Areas of Experience:
Our privacy litigators defend clients from landmark class and individual actions based on cutting edge legal theories to claims brought under long-standing privacy laws. Clients rely on the Sheppard Mullin team in what often become bet-the-company cases. From large cases to small, our team is focused on getting the best result for our clients.
Our work includes defending clients in consumer class actions, competitor lawsuits, and government enforcement actions related to privacy claims. We regularly handle complex, high-profile privacy lawsuits and landmark cases involving constitutional privacy rights, state law claims like California’s Song-Beverly and Shine the Light Acts, Illinois Biometric Information Privacy Act (BIPA), claims asserted under the Computer Fraud and Abuse Act (CFAA), and California Invasion of Privacy Act (CIPA). We also represent clients in cases involving penal code wiretapping and call recording claims, the federal Telephone Consumer Protection Act, RICO claims related to privacy, and various other state and federal statutes.
Representative cases include protecting and defending clients in claims that allege violations in handling fingerprints and face prints, those that argue that websites have “eavesdropped” on chatbot conversations, and defending clients in complex and high-profile multi-jurisdictional cases that follow in the aftermath of data breaches.
In all of these matters, our practitioners provide practical and knowledgeable support. What sets us apart is our dual expertise. Our litigators are also privacy counselors, advising clients on compliance with the very privacy laws and issues that form the crux of the complaint. This lets us to craft a more strategic defense, tackling tough questions that lie at the heart of litigation. Another differentiator on which our clients rely is our realistic and practical approach to cases, especially those filed by opportunistic plaintiffs’ counsel. We challenge plaintiffs’ counsel to stand by their case theory, knowing that the prospect of time-consuming and costly litigation often deters them from pursuing the case further when they realize there’s no easy money to be made.
The Sheppard Mullin team assists clients in a wide variety of investigation matters, relying on their experience to successfully represent clients before a wide variety of regulatory bodies.
Our practitioners have experience in assisting clients in investigations brought by an alphabet soup of state and federal regulators. From investigations before the Federal Trade Commission, Federal Communications Commission, Securities and Exchange Commission, Department of Health and Human Services - Office for Civil Rights, and variety of financial services regulators (Consumer Protection Bureau (CFPB), Federal Reserve Board (FRB), New York Department of Financial Services (NYDFS) and others), we are zealous advocates for our clients. We also regularly assist clients in representations before committees of the US Congress.
Additionally, whether in the wake of data breach notifications or other public matters, our clients rely on our ability to advocate on their behalf in investigations brought by state Attorneys General and other regulators.
Sheppard Mullin also has an active government regulatory practice. Our team helps our client navigate growing requests by government to private data. We help clients balance competing priorities and navigate sensitive negotiations around such disclosures with law enforcement, national security, and other government agencies. We use our connections with law enforcement, the intelligence community, and the national security establishment to provide a discreet, strategic, and comprehensive responses.
We leverage our experience in data breach response to help clients prepare for what is often not an “if” but a “when” for incident response. Our knowledge of our clients and their practices helps us guide them through incidents effectively using tools to help mitigate and minimize risk.
To assist clients in preparing for potential incidents, our team conducts comprehensive reviews of clients’ data storage and security practices, policies, procedures, third-party agreements, and regulatory requirements to plan for data security incidents. We use our connections with forensic security consultants, crisis communications firms, identity-theft protection providers, and law enforcement agencies to benefit our clients. Through table-top exercises, we evaluate clients’ preparedness for cyberattacks or other data incidents.
In the wake of an incident, our team provides strategic, comprehensive support. This includes advising on forensic investigations, and crisis communications. We also interact with law enforcement and regulators on our client’s behalf, and assist in compliance with multi-jurisdictional, global breach notification obligations. Our team is always mindful during the response that litigation or regulatory inquiries are possible, and carefully strategize responses with this in mind. Should claims or investigations begin, we are well poised to assist our clients.
We have supported clients through a wide variety of incidents, including some of the most sophisticated and largest ransomware attacks. Our work includes advising on negotiations with threat actors, proof of life, and decryption. We collaborate with leading third-party intermediaries to ensure secure communication and negotiation with threat actors. If necessary, we assist in establishing a bitcoin account for ransom payment, checking OFAC listings, liaising with the FBI in advance of the payment to ensure it is not flagged and prevented by law enforcement, and to tumble the payment once it is initiated.
Our team of privacy professionals has a breadth of experience helping companies of all sizes and across various industries stay up to date and develop and implement a tailored compliance strategy.
Our lawyers are leaders in the field, and assist major brands, ad agencies, and research companies in interacting with consumers while complying with the ever changing, complex patchwork of privacy laws. When assisting companies with compliance projects our work is informed by our depth of knowledge in US and global privacy laws, including the California Consumer Privacy Act and similar state laws, CalOPPA, the Song Beverly Act, state telemarketing laws, TCPA, CAN-SPAM, COPPA, HIPAA, GLBA, GDPR, and more.
We provide a full suite of assessment and remediation services and assist companies in implementing “privacy by design” principles into their organizations, technologies, products, and services. We understand that designing technologies, products, data transfer mechanisms, apps, and websites with privacy and security protections embedded will help to mitigate future legal and regulatory risks. Work we do includes assisting clients with privacy policies and procedures, training, and developing practical and implementable remediation solutions.
Our team has experience in a variety of industries. From health care, financial services, retail, and representation of companies who contract with government entities, we work with a wide breadth of clients. For those selling to the government, we leverage our strong ties with government officials to guide clients through the complex laws, standards, and regulations related to cybersecurity and cloud computing.
Recognitions
- JD Supra, 03.03.2025
- Chambers Global, 02.13.2025
- San Diego Business Journal, 10.28.2024
- Legal 500 US, 06.12.2024
- Lawdragon, 05.02.2024
- Cybersecurity Docket, 04.19.2024
- JD Supra, 03.04.2024
- Crain’s Chicago Business, 02.19.2024
- Chambers Global, 02.15.2024
- The National Law Journal, 11.01.2023
- Lawdragon, 07.07.2023
- Legal 500 US, 06.07.2023
Insights
Podcasts & Webinars
Articles
- Law360, 03.25.2025
- Law360, 03.24.2025
- Change Management Can Help Leaders Get on Board With ComplianceBloomberg Law, 03.14.2025
- American Bar Association , 03.06.2025
- Law360, 01.28.2025
- 01.21.2025
- Law360, 01.16.2025
- Law360, 01.09.2025
- Law360, 12.12.2024
- California Neural Privacy Law Spurs Fresh Compliance HeadacheBloomberg Law, 10.04.2024
- Federal News Network, 06.05.2024
- HIMSS TV, 05.09.2024
- Law360, 05.03.2024
- American Health Law Association, 04.12.2024
- Law360, 04.12.2024
- Law360, 04.02.2024
- Bloomberg Law, 03.28.2024
- Law360, 03.27.2024
- RealTime Cyber, 03.13.2024
- Federal Drive, 03.06.2024
- 02.15.2024
- Nine Impacts of New Jersey and New Hampshire Privacy LawsCybersecurity Law Report, 02.14.2024
- 02.01.2024
- 01.26.2024
- Bloomberg Law, 01.16.2024
- IT Brew, 01.10.2024
- Law360, 01.08.2024
- Law.com, 12.26.2023
- Law360, 12.22.2023
- Hotel Business Review, 12.11.2023
- Law360, 11.30.2023
- LinkedIn News, 11.16.2023
- Governance Institute, 11.08.2023
- Law360, 11.03.2023
- LexisNexis Practical Guidance, 11.01.2023
- LexisNexis Practical Guidance, 11.01.2023
- LexisNexis Practical Guidance, 11.01.2023
- LexisNexis Practical Guidance, 11.01.2023
- LexisNexis Practical Guidance, 11.01.2023
- LexisNexis Practical Guidance, 11.01.2023
- International Trademark Association, 11.01.2023
- Law360, 10.25.2023
- Federal News Network, 10.10.2023
- Law360, 09.19.2023
- Law360, 09.18.2023
- Law360, 09.12.2023
- Chicago Lawyer Magazine, 09.06.2023
- CPO Magazine, 06.26.2023
- Legaltech News, 06.22.2023
- Managed Healthcare Executive, 05.2023
- Bloomberg Law, 05.02.2023
- 04.17.2023
- LexisNexis Practical Guidance, 04.06.2023
- LexisNexis Practical Guidance, 04.06.2023
- AdAge, 03.28.2023
- SME, 02.09.2023
- 01.20.2023
- Law360, 01.02.2023
- HR Dive, 11.08.2022
- Risk & Compliance, October-December 2022 issue
- Legaltech News, 10.14.2022
- Consumer Electronics Daily , 09.19.2022
- Law.com's Legaltech News, 08.12.2022
- Law360, 05.23.2022
- Sports Litigation Alert, 03.25.2022
- 01.11.2022
- Law360, 01.07.2022
- Daily Journal, 08.23.2021
- The Review of Banking & Financial Services, July 2021
- Legal Evolution, 07.11.2021
- Rick & Compliance Magazine, July - September 2021 issue
- Bloomberg Law, 07.06.2021
- Bloomberg Law, 07.01.2021
- Esports Insider, 06.24.2021
- Bloomberg Law, 05.12.2021
- SC Media, 04.15.2021
- GDR News, 01.14.2021
- Law360, 01.03.2021
- Law360, 12.22.2020
- Forbes, 12.17.2020
- The Wall Street Journal, 12.08.2020
- Law360, 03.27.2020
- Law360, 01.13.2020
- CBS Newspath, 01.13.2020
- Law360, 01.13.2020
- Law360, 01.01.2020
- KUSI Newsroom, 11.05.2019
- San Diego Defense Lawyers, Fall 2019
- The National Law Review, Fall 2019
- Info Governance World, 10.18.2019
- The Fox News Rundown Podcast, 10.15.2019
- CNBC, 06.26.2019
- Lawyer: Illinois businesses should take steps to limit BIPA liability after reform legislation failsCook County Record, 04.30.2019
- Information Governance World, 03.2019
- Law360, 01.23.2019
- 01.11.2019
- Law360, 01.01.2019
- Law360, 01.01.2019
- Insights, 10.2018
- National Defense, 07.03.2018
- Data Protection Leader, 05.2018
- Law360, 04.30.2018
- Bloomberg Law Privacy and Security Law Report, 05.29.2017
- Best Lawyers "Women in the Law" Spring Business Edition, 03.31.2017
- DC Circ.'s Delay On Net Neutrality Points To Wider HoldupLaw360, 03.15.2017
- Companies Await D.C. Circuit’s Robocall Autodialer DefinitionBloomberg Law, 03.07.2017
- Telco Transformation, 03.06.2017
- Law360, 02.24.2017
- The Government Contractor, 02.22.2017
- Cyber Spies: In-House Legal Fights Back Against CyberespionageLegaltech News, 02.09.2017
- Bloomberg BNA, 02.2017
- Lorman, 01.2017
- Bloomberg BNA Privacy Law Watch Bulletin, 01.06.2017
- Privacy Cases To Watch In 2017Law360, 01.02.2017
- Retail Legislation And Regulation To Watch In 2017Law360, 01.02.2017
- Privacy Legislation And Regulation To Watch In 2017Law360, 01.02.2017
- Corporate Counsel, 12.2016
- Law360, 12.20.2016
- Metropolitan Corporate Counsel, 12.07.2016
- Entrepreneur, 12.06.2016
- Law360, 11.17.2016
- Law360, 11.14.2016
- Law360, 10.04.2016
- Law360, 09.13.2016
- "Hospitality's Move to Mobile Raises Legal Risks"HOTELS Magazine, 09.13.2016
- Law360, 08.30.2016
- Bloomberg BNA, 07.15.2016
- Law360, 06.28.2016
- Bloomberg BNA: Privacy Law Watch, 06.24.2016
- Variety, 06.17.2016
- Cnet, 06.15.2016
- Law360, 06.15.2016
- Law360, 06.14.2016
- Bloomberg BNA, 06.14.2016
- ALM Media, 06.06.2016
- Law360, 06.30.2015
- Law360, 10.03.2014
- The Metropolitan Corporate Counsel, 03.17.2014
- Law360, 11.27.2013
- Law360, 10.11.2013
- Law360, 08.26.2013
- Law360, 08.20.2013
- Law360, 08.01.2013
- Bloomberg BNA, 02.11.2013
- The Metropolitan Corporate Counsel, 02.2013
- Bloomberg BNA, 07.19.2012
- The Metropolitan Corporate Counsel, 09.2011
- Law360, 06.23.2011
- The Metropolitan Corporate Counsel, 06.2011
- The National Law Journal, 06.08.2009
Events
Events
- Nashville, TN, 05.15.2025
- 04.28.2025
- Washington, D.C., 04.22.2025
- New York, NY, 03.27.2025
- Webinar, 03.04.2025
- Washington, D.C., 02.12.2025
- Webinar, 01.28.2025
- Falls Church, VA, 11.20.2024
- Webinar, 10.30.2024
- Los Angeles, CA, 09.22.2024
- Webinar, 09.19.2024
- Washington, D.C., 09.12.2024
- Webinar, 08.28.2024
- 06.03.2024
- Fairfield Inn & Suites Manhattan Times Square South, New York, NY, 05.29.2024
- Webinar, 05.15.2024
Resources
Resources
The world of privacy and data security laws is vast and complex. Companies trying to address obligations that exist at an entity (health care, financial services) or activity (texting, online behavioral advertising) level have to keep a myriad of obligations in mind. To say nothing of laws that exist based on the type of individual with whom the company is interacting (COPPA, for example). These resources are intended not to serve as legal advice, but instead planning and preparation materials to help companies as they navigate through the ever-changing landscape of privacy and data security laws.
Blog Feed
-
04.16.2025
-
04.14.2025
-
04.10.2025
- 01.14.2025
- 09.08.2021
- 02.23.2021
- 08.19.2020
- 01.08.2020
- 11.27.2019
- 07.02.2019
- 06.11.2019
- 04.03.2019
- 02.27.2019
News
- 04.02.2025
- 03.03.2025JD Supra
- 02.18.2025
- 02.13.2025Chambers Global
- 10.28.2024San Diego Business Journal
- 06.12.2024Legal 500 US
- 05.02.2024Lawdragon
- 04.19.2024Cybersecurity Docket
- 03.04.2024JD Supra
- 02.21.2024
- 02.19.2024Crain’s Chicago Business
- 02.15.2024Chambers Global
- 11.01.2023The National Law Journal
- 07.07.2023Lawdragon
- 06.07.2023Legal 500 US
- 06.05.2023
- Brian D. Anderson
- Townsend L. Bourne
- Dane C. Brody Chanove
- Craig Cardon
- Tracy Chau
- Anne-Marie D. Dao
- Samantha K. Davis
- Wynter L. Deagle
- Snehal Desai
- A.J. S. Dhaliwal
- Charles Glover
- Oliver Heinisch
- Rachel Tarko Hudson
- Samuel Z. Hyams-Millard
- Julia K. Kadish
- Sieun J. Lee
- Carolyn V. Metnick
- Jonathan E. Meyer
- Elfin L. Noce
- Genevieve Perez
- Shannon Z. Petersen
- David M. Poell
- Jay Ramsey
- Alexis Robinson
- Tenaya Rodewald
- Kari M. Rollins
- Patrick D. Rubalcava IV
- Bridget Russell
- Daniel E. Schnapp
- Moorari K. Shah
- Sara Helene Shanti
- Kathryn Smith
- Alyssa Sones
- Liisa M. Thomas
- Brittany Walter
- Y. Douglas Yang
- Michael X.Y. Zhang