Faegre Drinker Biddle & Reath LLP, a Delaware limited liability partnership | This website contains attorney advertising.

Privacy, Cybersecurity, Data Ethics & Strategy

See All Services Meet The Team

Overview

Faegre Drinker helps clients meet the challenges of the information age. Organizations collect, use and share ever-increasing amounts of data, raising privacy, security, information governance and other data ethics issues. Our team of attorneys and professionals helps clients build strong data governance programs that support compliance with applicable laws and agile responses to security incidents. 

We help organizations understand the array of laws and guidelines applicable to their data processing. This includes requirements concerning privacy (to what extent can individuals control the use and disclosure of information that relates to them), security (what safeguards are required to protect the confidentiality, integrity, and availability of data assets), transparency (to what extent do organizations need to be transparent about how they are collecting and using personal data), ownership (who owns personal data and information derived from personal data) and fairness (does the outcome of data analysis result in disparate impacts to a specific group of people in a way that causes harm). These issues have been a central part of “data protection” law for decades and are growing in importance as regulators struggle to address new, data-intensive technologies like artificial intelligence.

Faegre Drinker’s multidisciplinary privacy, cybersecurity, data ethics and strategy team assists organizations in understanding their information flows and creating compliant policies and procedures. We help clients close M&A deals and draft complex data agreements and security provisions. And when incidents threaten a client’s business reputation, we are here to help. We litigate class-action lawsuits, respond to data breaches, answer regulator inquiries, and deliver peace of mind when a crisis arises.

We advise organizations on a wide body of rapidly evolving data laws, regulations and standards, such as:

  • U.S. state privacy laws, such as the California Consumer Privacy Act (CCPA), Colorado Privacy Act (CPA), Illinois Biometric Information Privacy Act (BIPA) and Washington My Health My Data Act.
  • U.S. federal privacy laws, such as the Federal Trade Commission (FTC) Act, Telephone Consumer Protection Act (TCPA), Health Insurance Portability and Accountability Act (HIPAA), Family Educational Rights and Privacy Act (FERPA), Fair Credit Reporting Act (FCRA) and Gramm-Leach-Bliley Act (GLBA).
  • UK and EU data protection and e-privacy laws, such as the General Data Protection Regulation (GDPR) and ePrivacy Directive.
  • China’s Personal Information Protection Law (PIPL), Cybersecurity Law (CSL) and Data Security Law (DSL).
  • Standards, such as the Payment Card Industry Data Security Standards (PCI DSS), International Organization for Standardization (ISO) 27001, and National Institute of Standards and Technology Cybersecurity Framework (NIST CSF).
  • Pending legislation, such as the EU AI Act and privacy bills at the U.S. state and federal levels.
     

Insights & Events

Latest

Updates February 2025

Permission to Record: Considerations for AI Meeting Assistants

Taking Into Account Individualized Business Operations, Industry Standards & Legal/Regulatory Requirements
10 min read  
Blog Post February 2025

Lessons from PayPal’s $2 Million Cybersecurity Settlement with the New York State Department of Financial Services

Discerning Data blog
1 min read  
Media Mentions February 2025

Doriann Cain Provides Insight in Navigating HIPAA Compliance With Becker’s Hospital Review

1 min read  
Blog Post February 2025

Oh No, Canada! Takeaways from the Indictment of a Canadian National Allegedly Responsible for $65 Million DeFi Cryptocurrency Theft

Discerning Data blog
1 min read  
Updates February 2025

Supreme Court Hears Oral Argument in Case Regarding FCC’s Authority to Interpret Telephone Consumer Protection Act

McLaughlin Chiropractic Associates Inc. et al. v. McKesson Corporation
6 min read  
Updates February 2025

The Department of Justice’s Policy Changes — Key Takeaways for the Business Community

Staying Informed and Prepared Will Be Key
8 min read  
Speaking Engagement Recap February 06, 2025

Website AdTech Compliance – Mitigating Legal Risks in Modern Marketing Practices

2025 Midwest Legal Conference on Data Privacy & Cybersecurity
1 min read  
News December 2024

Faegre Drinker Attorneys Recognized in 2024 Lexology Index Reports

3 min read  
Speaking Engagement Recap November 20, 2024

Managed Care, Enforcement and Compliance

Healthcare Enforcement Compliance Conference
1 min read  
Press Release September 2024

Faegre Drinker Expands New York Litigation Practice With Former EDNY National Security Deputy Chief Craig Heeren

3 min read  
Insights
Updates February 2025

Permission to Record: Considerations for AI Meeting Assistants

Taking Into Account Individualized Business Operations, Industry Standards & Legal/Regulatory Requirements
10 min read  
Blog Post February 2025

Lessons from PayPal’s $2 Million Cybersecurity Settlement with the New York State Department of Financial Services

Discerning Data blog
1 min read  
Media Mentions February 2025

Doriann Cain Provides Insight in Navigating HIPAA Compliance With Becker’s Hospital Review

1 min read  
Blog Post February 2025

Oh No, Canada! Takeaways from the Indictment of a Canadian National Allegedly Responsible for $65 Million DeFi Cryptocurrency Theft

Discerning Data blog
1 min read  
Updates February 2025

Supreme Court Hears Oral Argument in Case Regarding FCC’s Authority to Interpret Telephone Consumer Protection Act

McLaughlin Chiropractic Associates Inc. et al. v. McKesson Corporation
6 min read  
Updates February 2025

The Department of Justice’s Policy Changes — Key Takeaways for the Business Community

Staying Informed and Prepared Will Be Key
8 min read  
Updates February 2025

FTC Sends a Reminder to Facial Recognition Tech Companies to Do What They Say and Say What They Do

Enforcement Against False Claims of Error-Free Algorithms
8 min read  
Updates January 2025

Proposed HIPAA Security Rule Updates — Implications for Covered Entities and Their Information Security Programs

6 min read  
Updates January 2025

UK Government Launches Consultation on Ransomware Payments

Businesses, Cybersecurity Experts and the Public Are Invited to Contribute Their Views
6 min read  
Updates January 2025

Four Trade Secret Developments to Follow in 2025

DTSA’s Extraterritorial Reach, AI, Large Damages Awards & Noncompete Ban
8 min read  

Related Legal Services