Data protection and cyber security

We help you strengthen your business and leverage value in your data assets.

Our specialist data protection and cyber security team provides clear and tailored guidance to ensure your business stays compliant and prepared

Technology is evolving fast and data breaches and cyber security incidents are increasingly high profile and complex. Today securing your data is more than a legal obligation – it’s essential to thrive. We excel at navigating complex data protection challenges and helping clients across sectors to achieve lasting security.

Our experience includes:

  • Advising Aspects Beauty, a distribution and brand management company based in the UK and Ireland, on its privacy notice, its data protection policies and procedures, and on data protection marketing rules.
  • Acting as leading car manufacturer's external legal counsel for all data protection matters, taking into account complicated flows of data and interrelation between different entities and data protection regimes internationally. Advice on third-party personal data processing arrangements has involved smart TVs, Alexa, Facebook and Google.
  • Advising Oncoheroes Biosciences Inc., which develops and licences drugs specific to treating childhood cancers, to ensure data transfers from the EU and UK to the United States related to adverse events were compliant under data protection laws.
  • Acting for the owner of a large number of luxury fashion and beauty brands on data protection matters including an intragroup data processing agreement, in particular covering UK GDPR rules on international transfers; the use of online facial scanning technology; responding to data subject access requests (DSARs); and updating records of processing.
  • Advising a business intelligence organisation on a complex project to update various policies and procedures in light of the intelligence services it provides to clients, including updates to standard client terms; updates to standard contractor terms, including allowing for international data transfers; updates to its privacy notice; and a data subject access request (DSAR) compliance flow chart.

How we help:

Data protection

  • Ensuring GDPR compliance and guiding you through ongoing obligations.
  • Advising on complex cross-border data transfer arrangements.
  • Advising on data sharing issues, to help leverage value in data and manage risk.
  • Helping navigate the controller and processor relationship, including advising on the appointment of processors and associated documentation.
  • Assisting with data subject rights, including subject access requests and requests for data erasure, whether in an external (e.g. customers) or internal (e.g. employment) context.
  • Providing data protection guidance within the employment setting, including surveillance issues.

Electronic marketing

Advising on e-privacy matters, including electronic marketing and deployment of cookies and other similar technologies.

Cybersecurity

  • Drafting and reviewing cybersecurity policies.
  • Advising on the implementation of cybersecurity products and processes.
  • Offering practical steps for addressing data security issues in the workplace.

Freedom of information

  • Advising on strategies to resist Freedom of Information Act (FOIA) requests, including applying relevant exemptions to disclosure rules.
  • Supporting businesses in leveraging FOIA to access information on public authority transactions.
  • Advising on obligations and exemptions under The Environmental Information Regulations 2004, including handling requests for environmental information and managing disclosures.