Faegre Drinker Biddle & Reath LLP, a Delaware limited liability partnership | This website contains attorney advertising.

Privacy, Cybersecurity, Data Ethics & Strategy

Overview

Faegre Drinker helps clients meet the challenges of the information age. Organizations collect, use, and share ever-increasing amounts of data, raising privacy, security, information governance, and other data ethics issues. Our team of attorneys and professionals helps clients build strong data governance programs that support compliance with applicable laws and agile responses to security incidents. 

We help organizations understand the array of laws and guidelines applicable to their data processing. This includes requirements concerning privacy (to what extent can individuals control the use and disclosure of information that relates to them), security (what safeguards are required to protect the confidentiality, integrity, and availability of data assets), transparency (to what extent do organizations need to be transparent about how they are collecting and using personal data), ownership (who owns personal data and information derived from personal data), and fairness (does the outcome of data analysis result in disparate impacts to a specific group of people in a way that causes harm). These issues have been a central part of “data protection” law for decades and are growing in importance as regulators struggle to address new, data-intensive technologies like artificial intelligence.

Faegre Drinker’s multidisciplinary privacy, cybersecurity, data ethics, and strategy team assists organizations in understanding their information flows and creating compliant policies and procedures. We help clients close M&A deals and draft complex data agreements and security provisions. And when incidents threaten a client’s business reputation, we are here to help. We litigate class-action lawsuits, respond to data breaches, answer regulator inquiries, and deliver peace of mind when a crisis arises.

We advise organizations on a wide body of rapidly evolving data laws, regulations, and standards, such as:

  • US state privacy laws, such as the California Consumer Privacy Act (CCPA), Colorado Privacy Act (CPA), Illinois Biometric Information Privacy Act (BIPA), and Washington My Health My Data Act
  • US federal privacy laws, such as the Federal Trade Commission (FTC) Act, Telephone Consumer Protection Act (TCPA), Health Insurance Portability and Accountability Act (HIPAA), Family Educational Rights and Privacy Act (FERPA), Fair Credit Reporting Act (FCRA), and Gramm-Leach-Bliley Act (GLBA)
  • UK and EU data protection and e-privacy laws, such as the General Data Protection Regulation (GDPR) and ePrivacy Directive
  • China’s Personal Information Protection Law (PIPL), Cybersecurity Law (CSL), and Data Security Law (DSL)
  • Standards, such as the Payment Card Industry Data Security Standards (PCI DSS), International Organization for Standardization (ISO) 27001, and National Institute of Standards and Technology Cybersecurity Framework (NIST CSF)
  • Pending legislation, such as the EU AI Act and privacy bills at the US state and federal levels
     

Insights & Events

Latest

Updates September 2026

September 2026 EU Compliance Deadlines for Connected Product Manufacturers

New EU cybersecurity reporting and data-access obligations take effect in September 2026 — with extraterritorial reach for US businesses.
12 min read
Updates September 2026

The White House's Gold Eagle Initiative Scales Back, the AI Kill Switch Act, and Bill Gates' Warnings and Proposals

Artificial Intelligence Briefing
10 min read
Updates August 2026

Different Shoppers, Different Prices

FTC Takes Aim at Personalized Pricing
7 min read
Speaking Engagement Recap August 18, 2026

Life Insurance and Annuity Anti-Fraud Training

Banner Life CLE Webinar
1 min read
Updates August 2026

Frontier AI Models Gone Rogue, DeepMind CEO Calls for Oversight Body, and NY Pauses Data Center Permits

Artificial Intelligence Briefing
12 min read
Updates July 2026

EU AI Act — Commission Confirms Transparency Code of Practice as Adequate and Publishes Final Version of Its Guidelines on Transparency Obligations

Compliance deadline of 2 August 2026 approaches for providers and deployers of GenAI systems.
12 min read
Updates July 2026

Unlocking the Right to Repair: The Expanding Compliance Landscape

Divergent state legislation, federal antitrust litigation, congressional proposals, and an evolving executive-branch posture
20 min read
Speaking Engagement Recap May 11, 2026

Privacy in Motion: Driving MedTech Forward

The MedTech Forum 2026
1 min read
News March 2026

Steve Serfass Honored With Intercompany Long-Term Care Insurance Recognition Award

1 min read
Press Release March 2026

Health Care Attorney Isaac Willett Rejoins Faegre Drinker in Indianapolis

2 min read
Insights
Updates September 2026

September 2026 EU Compliance Deadlines for Connected Product Manufacturers

New EU cybersecurity reporting and data-access obligations take effect in September 2026 — with extraterritorial reach for US businesses.
12 min read
Updates September 2026

The White House's Gold Eagle Initiative Scales Back, the AI Kill Switch Act, and Bill Gates' Warnings and Proposals

Artificial Intelligence Briefing
10 min read
Updates August 2026

Different Shoppers, Different Prices

FTC Takes Aim at Personalized Pricing
7 min read
Updates August 2026

Frontier AI Models Gone Rogue, DeepMind CEO Calls for Oversight Body, and NY Pauses Data Center Permits

Artificial Intelligence Briefing
12 min read
Updates July 2026

EU AI Act — Commission Confirms Transparency Code of Practice as Adequate and Publishes Final Version of Its Guidelines on Transparency Obligations

Compliance deadline of 2 August 2026 approaches for providers and deployers of GenAI systems.
12 min read
Updates July 2026

Unlocking the Right to Repair: The Expanding Compliance Landscape

Divergent state legislation, federal antitrust litigation, congressional proposals, and an evolving executive-branch posture
20 min read
Updates July 2026

Second Quarter 2026 Government Contracts Policy and Regulatory Review

FAR Overhaul rulemaking, proposed grant reforms, and small business program developments portend significant changes for federal contractors and grant recipients.
18 min read
Updates July 2026

New Jersey Enacts Sweeping Data Broker and Data Collector Registration Law

Businesses Must Assess Data Disclosure Practices and Prepare for New Registration Requirements and an Immediate Ban on Sensitive Data Sales
9 min read
Updates July 2026

DoD Suspends CMMC Phase II Third-Party Audit Requirements

Suspension pauses Level 2 third-party audit requirements and Level 3 rollout while DoD conducts “top-to-bottom” review of the CMMC program
7 min read
Updates July 2026

The Intel Report: Quarterly National Security Briefing — 2026 Q2

Key Regulatory Developments and Enforcement Actions Affect National Security Priorities, Risks, and Opportunities across Sectors
24 min read

Meet The Team

Meet The Full Privacy, Cybersecurity, Data Ethics & Strategy Team