Latham & Watkins advises the businesses and institutions that power the global economy. We bring together the world’s best legal talent in every major jurisdiction to shape the deals and win the disputes that transform markets. Our experience at the cutting edge of commercial, financial, and legal innovation enables us to deliver results that fuel our clients’ success.  

Latham’s highly ranked, interdisciplinary privacy and cyber practice delivers full-spectrum legal support around the globe to solve today’s complex and dynamic compliance, regulatory, litigation, and transactional challenges. Our innovative strategies and standard of excellence promote the best outcomes and long-term success for our clients.

Editors

Jennifer Archie, leads the industry in crisis management and response, regulatory investigations, and overall compliance within the data privacy, cybersecurity, and consumer protection sector. She represents clients across the full spectrum of enforcement and advisory matters implicating cybersecurity, data privacy, and consumer protection issues. Drawing on her 35-year career at Latham, Jennifer guides a broad range of clients — from emerging companies to global enterprises across all market sectors — on matters involving: computer fraud and cybercrime; privacy and data security compliance; compliance program design and management; advertising and marketing practices; and consumer fraud.

Jennifer is highly experienced, and recognized, in defending clients in Federal Trade Commission (FTC) and state privacy, security and consumer protection investigations and leading the response to large-scale data breach incidents.

Working in close coordination with Latham colleagues in Europe, Asia, and the Middle East, she regularly advises global enterprises on complex cross-border compliance and data transfer challenges, compliance with US privacy and data security requirements, and leads assessments of internal privacy or security management programs, under FTC, HIPAA, NIST, financial regulatory, and governmental or private standards.

She also represents companies facing fallout from major cyberattacks, data leakage or theft, and suspected trade secrets and intellectual property theft.

An industry trailblazer, Jennifer has been engaged significantly in the computer crime and cybersecurity field since 1999, when she became lead outside counsel for America Online for all matters pertaining to the security of the world’s then-largest email system. She investigated, filed, and prosecuted dozens of civil lawsuits against more than 100 individual spammers/phishers and those who aided and abetted, resulting in the collection of millions of dollars in damages, permanent injunctions, novel and favorable legal precedents, and new state and federal laws on which she advised and that she personally drafted.

Robert Blamires leads strategic counseling and transactional work on cutting-edge regulatory compliance issues in the firm’s Privacy & Cyber and Data & Technology Transactions Practices. He works with some of the world’s largest and most cutting-edge companies and on some of the most complex, market-making transactions.

A seasoned leader, Robert draws on more than two decades of practice, and his multi-jurisdictional qualifications and experience, to guide US and international clients on data privacy, cyber, and related regulatory issues (covering both US federal/state and UK/EU data privacy laws), in the context of: M&A, private equity, IPO, venture capital and other corporate and commercial transactions, including pivotal strategic decisions and structuring, highly bespoke diligence, drafting, and negotiation; compliance strategies and implementation; growth strategies, including international expansion and associated cross-border/multijurisdictional issues; incident response, containment, and management.

Robert helped grow the firm’s US Privacy & Cyber Group and leads US Transactional Privacy & Cyber. He also sits on the firm’s Technology and Security Committees, and is a member of the firm’s AI Practice.

Marissa Boynton advises US and global clients across all market sectors on cybersecurity and data privacy, data breach response, and consumer protection.

Marissa provides comprehensive advice on regulatory compliance, investigations, and litigation related to: privacy and data security-related regulatory enforcement; privacy and data security compliance and program management; complex data breach incidents, including forensic investigations; computer fraud and cybercrime; advertising and marketing practices, as well as other consumer protection issues.

Marissa represents a broad range of clients from emerging companies to global market leaders. She has particular knowledge of the technology, healthcare, retail, and professional services sectors.

Marissa advises clients on various laws governing data privacy and consumer protection, including those under the California Consumer Protection Act (CCPA), Health Insurance Portability and Accountability Act (HIPAA), Gramm Leach Bliley, Children’s Online Privacy Protection Act (COPPA), Federal Trade Commission Act, CAN-SPAM, and telemarketing laws, as well as self-regulatory and online behavioral advertising guidelines.

Marissa frequently represents clients before the Federal Trade Commission (FTC), state attorneys general, and other government agencies and bodies. Marissa has also represented clients in high stakes litigation matters in state and federal courts.

Gail Crawford helps clients navigate complex data privacy and security matters, as well as to license, develop, and exploit disruptive technology. She previously served as Global Chair of Latham’s Data & Technology Transactions Practice and as Co-Chair of Latham’s Privacy & Cyber Practice. Gail advises many of the world’s leading global technology companies on multifaceted and precedent-defining data privacy and security matters. Highlighted in the market for combining an impressive technology practice with an in-depth understanding of data protection laws, Gail is highly sought after by tech giants for her knowledge of compliance in technology sectors.

Tony Kim represents clients across the full spectrum of advisory and enforcement matters implicating cybersecurity, data privacy, and consumer protection issues.

Tony helps companies navigate crises to avoid legal, risk, and reputational landmines. He also defends clients in regulatory investigations and enforcement actions by the Federal Trade Commission (FTC), State Attorney General Offices (AGOs), the Securities & Exchange Commission (SEC), and various sector regulators, as well as in litigation matters, involving the following areas: cybersecurity resiliency and incident response; privacy implications of innovative data use-cases; consumer protection issues, including in sales and marketing and advertising contexts with a particular focus on global e-commerce, fintech, and platform businesses.

In each of these areas, Tony partners with stakeholders in legal, IT/infoSec, product, growth, engineering, marketing, investor relations, communications, the c-suite, and the board/audit committee across governance, compliance, and crisis management contexts.

James Lloyd advises clients on cybersecurity, data privacy, AI, and digital regulatory risk, focusing on complex technologies, products, and platforms that attract regulatory scrutiny, enforcement risk, or crisis response.

His practice spans the regimes regulating the digital world, including cybersecurity and information security, data protection and privacy, AI, online platforms and content regulation, and related technology legislation. He supports clients on litigation-grade advisory work, regulatory engagement and investigations, incident response, enforcement action, and disputes.

James brings a disputes and enforcement mindset to advisory matters, helping clients build defensible positions around high-risk technologies and incidents that are designed to withstand regulator, board, insurer, and litigation scrutiny. He is valued for calm, strategic advice in complex or fast-moving situations and for translating novel regulatory issues into practical decisions.

Fiona Maclean, Global Vice Chair of the firm’s Data & Technology Transactions and Artificial Intelligence practices as well as the Technology Industry Group, advises market-leading clients on complex technology transactions and data privacy compliance, with a particular focus on AI, cloud computing, and data strategy.

Fiona combines commercial pragmatism with her sophisticated understanding of the global data privacy and AI regulatory landscape to help leading tech clients navigate complex, multijurisdictional transactions, and compliance projects.

Her work at the nexus of the commercial and data worlds includes advising on operational resiliency risks, AI governance, and some of the most transformational cloud deals in the global market.

Fiona has been recognized for her market-changing work from leading industry publications including Chambers, Legal 500, The Lawyer, and Law360.

Fiona serves on Latham’s Training and Career Enhancement (TACE) Committee.

Clayton Northouse counsels clients on transactional, regulatory, and litigation matters relating to global data protection and consumer privacy. Clayton helps technology, telecommunications, and healthcare companies navigate complex cybersecurity and consumer privacy issues relating to: transactional due diligence; incident response; surveillance and information sharing; cross-border data transfers; regulatory compliance with the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other US state, federal, and global requirements; governance policies and procedures; state attorneys general, Federal Communications Commission (FCC), Federal Trade Commission (FTC), and congressional investigations.

He draws on extensive experience representing companies that have suffered cybersecurity attacks and consumer privacy incidents to craft defenses to litigation, congressional inquiries, and regulatory investigations.

A skilled litigator, Clayton has co-authored briefs and motions in the US Supreme Court, the US Courts of Appeals, and US District Courts.

Michael H. Rubin, Global Chair of the Artificial Intelligence Practice, Global Chair of the Privacy & Cyber Practice, and Global Vice Chair of the Technology Industry Group, represents leading technology companies in high-stakes and regulatory matters in the US and globally.

Michael draws on more than two decades of experience at the leading edge of legal issues in Silicon Valley. As a seasoned litigator, he has the strategic judgment to minimize exposure in enterprise-threatening disputes; securing the best possible outcomes in court and matters before the Federal Trade Commission, state attorneys general, and other regulators. As a pioneering technology lawyer, he has the perspective to counsel companies active in the artificial intelligence and other emerging technologies sectors on product design and business model development. And as an accomplished leader, he assembles top-notch cross-practice and cross-jurisdictional teams to respond quickly to crises and help companies at all stages of their life cycle realize their business objectives.

Michael regularly provides counsel and representation on: privacy, cybersecurity, and consumer protection incidents and matters arising under US and global regulations — including FTC Section 5; artificial intelligence matters ranging from design, to governance, to regulatory compliance and defense, to litigation; emerging technologies and novel business and regulatory issues.

Serrin Turner, represents clients in their highest-stakes cybersecurity and privacy-related matters. A former federal prosecutor, Serrin is an experienced trial and appellate lawyer who advises clients on a wide range of cybersecurity and privacy-related matters, including: class action litigation; regulatory investigations; commercial disputes; incident response.

Serrin joined Latham following six years as an Assistant US Attorney for the Southern District of New York, where he served as the Office’s lead cybercrime prosecutor. In that role, Serrin handled numerous cutting-edge cybercrime investigations and prosecutions, including matters involving computer hacking, data breaches, trade-secret theft, black-market websites, trafficking in stolen payment card and personal identity information, and money laundering through digital currencies. Serrin also handled high-profile litigation involving US electronic surveillance statutes, including Amnesty International v. Clapper, a constitutional challenge to a key foreign-intelligence surveillance statute, as well In re Microsoft Search Warrant, a challenge brought by a leading email provider to a search warrant for data stored overseas.

Prior to his service at the US Attorney’s Office, Serrin served in the Civil Division of the US Department of Justice. He is a two-time recipient of the Attorney General’s Award for Distinguished Service, the Justice Department’s second-highest award, and he has also received the John Marshall Award for Trial of Litigation, the Justice Department’s highest award for trial litigators.

Tim Wybitul, is a leading EU data, privacy, cyber, and technology lawyer and the Global Vice Chair of the firm’s Privacy & Cyber Practice. Tim advises global technology companies on the EU’s digital rulebook, including the GDPR, the AI Act, the Data Act, and the Digital Markets Act (DMA), and on the litigation, enforcement, and regulator-facing strategy these regimes demand. He is the go-to specialist for challenging GDPR questions, pairing hands-on digital regulation work with genuine top-tier GDPR litigation depth. He regularly represents clients in high-stakes data litigation and before EU regulators, including before the European Court of Justice (CJEU) and the highest national courts in the EU and in other data-related disputes.

His work includes: fine defense: defense against fines for alleged violations of the EU Digital Acts, including before the CJEU; regulator communication: communication and negotiations with the EU authorities, including settlements; data advice and litigation: advice on the application and implementation of the GDPR, the EU AI Act, and other EU Digital Acts, including court litigation; reconciling conflicting digital-law regimes: advising on reconciling conflicting requirements of the EU Digital Acts, including data minimization and security obligations under the GDPR versus data-sharing obligations under the DMA and the Data Act; and cybersecurity: response to cybersecurity incidents, whether global or limited to individual jurisdictions.