The combination of privacy, cyber security, and data breach represents one of the most rapidly evolving areas of the law and a significant concern facing businesses of all types in an ever-increasing digital world.

From financial services companies and multinational corporations, to smaller local businesses, and just about everything in between, privacy and information security must be at the forefront of any company’s business plans and strategic objectives. At SGK, our Privacy & Cyber Security Services Group offers comprehensive legal services to the widest range of business entities to address these complex and evolving issues. We use a multi-disciplinary approach within the firm to identify and minimize potential exposure that could result from a data breach or the legal exposure from regulators for having inadequate information security programs. Our Privacy & Cyber Security Services team includes attorneys who are highly experienced in data security and privacy, litigation, cyber insurance coverage, human resources and business counseling, to provide a holistic approach to representation in all areas related to cyber security and privacy.

Data Breach Crisis Assistance

In the event of a data breach or threatened breach, our Privacy & Cyber Security Services Group provides clients a multi-disciplined approach to rapidly and efficiently coordinate a breach response in order to effectively curtail and mitigate the legal and reputational impacts and the corresponding exposure to the client and its customers. Our veteran professionals provide critical aid to the client during this emergency, helping to craft legally sufficient client notifications when required, working with the client’s employees to develop answers to the most commonly asked questions that impacted customers may ask, and acting as a medium through which the client may interact with various state or federal agencies, regulators and investigators, or the press. In a data breach crisis event, where every hour counts and customer interaction is of the utmost importance, SGK’s clients can rely on our team’s distinctive combination of client familiarity and resourceful experience.

Upon resolution of the crisis event, the Privacy & Cyber Security Services Group of SGK can quickly pivot to address any affirmative ongoing action a client may need to take to protect its customers’ interests, or prepare to vigorously defend a suit or threatened suit or regulatory action. We can effectively position our clients to take the most advantageous strategic position, never losing sight of the client’s business needs.

Emerging Privacy Legal Requirements

Throughout the United States, and indeed the globe, states and countries are strengthening privacy and data security laws. Any business that maintains a website and collects data, including cookies, must have a plan in place to comply with the myriad requirements of these various jurisdictions. At the forefront is having a Privacy Policy. Our Privacy & Cyber Security Services Group has deep experience in assisting our clients in preparing Privacy Policies that are compliant with the applicable privacy laws based on where the website targets customers and individuals. A Privacy Policy is the most visible marker of having a compliant privacy and data security program.

Representative Services

  • Performing risk assessments, and inventories of systems, devices and data
  • Creating compliant Privacy Policies for client websites
  • Developing Information Security Programs designed to fit the unique needs and risk profile of the client and its business
  • General counseling relating to cyber security, data protection and privacy laws, including:
    • Gramm-Leach-Bliley (GLB)
    • Health Insurance Portability and Accountability Act (HIPAA)
    • The Federal Trade Commission (FTC) Act
    • Industry-specific requirements for financial services, health care, utilities, transportation, education, and government contractors
    • State data breach notice laws
  • Assessing existing information security programs with recommendations to update and expand to cover wider types of data requiring protection
  • Developing Disaster Recovery Plans (DRP) tailored to the size and risk profile of the client
  • Representing financial institutions in connection with major credit card data breaches and recovering costs associated with the breach from the Card Associations and the merchant
  • Developing comprehensive privacy and data security training for a major financial institution and roll out wide-scale client training across the enterprise
  • Investigating data breach threats and developing mitigation strategies, including dealing with law enforcement, insurers, public relations, and stakeholders
  • Bringing the right team of professionals across different disciplines together, including IT resources and forensic analysts to assist in data breach response activities
  • Additionally, in business transactions where data is an element of ownership:
    • Optimizing ownership, rights and monetization of data
    • Securing data rights in licenses and other transactions
    • Due diligence on data management/compliance in M&A and other key transactions
    • Negotiating key provisions pertaining to data protection and disaster recovery in agreements that include cloud services, software as a service (SaaS), hosting and other agreements.

We’re Here to Help

With the experience of the Privacy & Cyber Security Services Group of SGK available to assist in protecting the most critical data of its clients, there is no reason to go it alone when building an increasingly needed plan of information protection. SGK’s Privacy & Cyber Security Services Group is a key member of the planning and response team for cyber security threats and incidents.

Contact Us