In an uncertain world of evolving data security threats and increased regulatory requirements, we provide our clients with peace of mind through crisis preparation, compliance oversight, risk mitigation, and incident response.
Overview
Attorneys
Resources
Overview
Our multidisciplinary Privacy and Data Security team counsels clients along the entire privacy and data security spectrum, including pre-breach preparation and risk management, security and vulnerability assessments, policy and procedure creation and review, breach response planning and drills, table-top exercises, as well as board and management education on reducing cyber risk.
What We Provide
Industry-leading qualifications Harter Secrest and Emery is an authorized NetDiligence® Breach Coach®, a designation only extended to law firms that demonstrate competency and sophistication in data breach response. Several members of our team are also recognized by the International Association of Privacy Professionals (IAPP), the global gold standard for privacy professionals, as a Certified Information Privacy Professional in both the United States (CIPP/US) and Europe (CIPP/E). Additionally, F. Paul Greene, the head of our team, is also a Distinguished Fellow of the Ponemon Institute, the pre-eminent research center dedicated to privacy, data protection and information security policy. Our exceptionally qualified attorneys have experience at Am Law 100 firms, judicial clerkships, handling high-stakes litigation, and have earned many accolades in respected law firm ranking programs, including Chambers USA, The Best Lawyers in America®, Best Lawyers: Ones to Watch in America, and Super Lawyers.
Deep industry experience We are trusted privacy and data security advisors to organizations of all sizes—from start-ups to Fortune 100 corporations—in numerous industries including retail, health care, financial services, defense manufacturing, critical infrastructure, information technology, software development and sales, higher education, not-for-profit organizations and more. This enables our team to provide deep insight across a number of regulatory spaces, giving our clients a broader view of how best to manage regulatory risk.
Efficiency, cost-effectiveness and plain talk The deep knowledge of each of our team members allows us to provide robust analysis and advice, without multiple layers of review. Moreover, clients tell us that we explain complex issues in a way they can understand, as we advise them on the full range of privacy and data security issues, such as:
Breach notification requirements under federal and state laws
Privacy and breach notification policies
Data security/Privacy risk assessments
Preparing for and avoiding a data breach or loss
Incident response tabletop exercises
Contracts with data security and privacy concerns
Organizational readiness for a breach
Comprehensive privacy management programs
Crisis management and remediation in response to a data breach
Internal investigations arising out of a data breach, including interaction with law enforcement and regulators
Indemnification and insurance claims
Potential litigation related to data breaches
Transactional due diligence concerning privacy and data security
Health Insurance Portability and Accountability Act (HIPAA)
California Consumer Privacy Act (CCPA)
The EU’s General Data Protection Regulation (GDPR)
The NY SHIELD Act
23 N.Y.C.R.R. Part 500
Health Information Technology for Economic and Clinical Health Act (HITECH)
Payment Card Information Data Security Standard (PCI-DSS)
Family Educational Rights and Privacy Act (FERPA)
Gramm-Leach-Bliley Act (GLBA)
Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA)
Fair and Accurate Credit Transactions Act (FACTA)
Freedom of Information Act (FOIA)
Fair Credit Reporting Act (FCRA)
Americans with Disabilities Act (ADA)
For immediate access to our Privacy and Data Security team and their deep connections with information security professionals, forensic investigators, crisis communication professionals, with maximum protection offered by the attorney-client privilege, call our Cybersecurity Incident and Breach Response Line at 1-800-232-3021.
What We See On the Horizon
Comprehensive State Privacy Legislation Almost two dozen states have now adopted comprehensive privacy regimes that provide rights to consumers similar to those found under California’s Consumer Privacy Act (CCPA) and the European Union’s General Data Protection Regulation (GDPR). Differences abound between regimes, however, and finding a common compliance path can be difficult. With more states considering adoption, finding the right compliance approach should be a high priority for many organizations.
Website Tracking Technologies Estimates indicate that roughly 85% of all websites employ tracking technologies that collect and monitor consumer activity (via cookies, pixels or similar devices), sometimes unbeknownst to the website owner. Almost a dozen states have now passed Universal Opt-Out legislation that would require recognition of automatic opt-out signals by organizations that sell or share consumer information. Although most of these requirements go into effect in 2025, many organizations lack a comprehensive understanding of their tracking activities and are not ready to recognize Universal Opt-Out signals.
Recent Attack Vectors If there’s another certainty in this world aside from death and taxes, it’s that bad actors will continue to find novel ways to extort money from targets. “Ransomware as a Service” (RWaaS) is just such an approach, which farms out malware detonation and extortion to third parties. For example, one RWaaS group allows its “affiliates” to keep 90% of the ransom collected, with 10% going back to the group. This great rate of return for RWaaS has brough a lot of new players into the field, with varying levels of reliability and “professionalism,” for lack of a better term. In addition to RWaaS, bad actors are increasingly threatening publication of stolen information on their dark-web “leak sites,” thereby increasing their leverage in hopes of a higher ransom payment.
New TCPA Rules Several modifications to the rules implementing the Telephone Consumer Protection Act (TCPA) will come into effect, further empowering consumer choice and imposing additional compliance requirements on businesses engaging in telemarketing or SMS outreach. For example, effective April 11, 2025, consumers will be allowed to flexibly opt-out of commercial messaging, using any “reasonable” means available. Additionally, the time for businesses to honor do-not-call (DNC) and consent revocation requests has also been reduced from thirty days to ten business days. The Federal Communications Commission may also revisit proposed rules, like the proposed “one-to-one consent” requirement, that would impose additional considerations for businesses obtaining prior express written consent under the TCPA.
Artificial Intelligence (AI) Given the ongoing hype and excitement surrounding AI, organizations of all sizes are investing heavily in AI solutions. Fear of missing out tends to drive many of these decisions, however. Meanwhile, multiple jurisdictions are scrambling to adopt regulatory measures to protect legitimate public interests, for example the EU AI Act and Local Law 144 in New York City. This has become an arms race of sorts, and organizations would be well-served by taking the time to adopt a robust AI risk management program before they find themselves required to do so by law.
“Paul is a luminary in privacy and data security. Our Institute recently had the opportunity to work with him on our recent study on Countdown to Compliance: Is the Financial Services Industry Ready for New York State’s Cybersecurity Regulations? His insights and knowledge about the impact of these regulations on corporations were key to the success of this research.”
“They are a great team of bright, talented people who are incredibly knowledgeable, very customer-oriented and very good at meeting deadlines.”
Certifications:
In an uncertain world of evolving data security threats and increased regulatory requirements, we provide our clients with peace of mind through crisis preparation, compliance oversight, risk mitigation, and incident response.
Our website uses cookies. By continuing to use our site, you agree to our use of cookies in accordance with our Privacy Policy