WILLIAM RM LONG Partner

Similar documents
Getting Your Privacy House in Order

Developments in Global Data Protection & Transfer: How They Impact Third-Party Contracts

Developing and Implementing Data Protection Law: Malaysia and Beyond

European Union Agency for Network and Information Security

Data Privacy and Cybersecurity

Plan a Pragmatic Approach to the new EU Data Privacy Regulation

EU DATA PRIVACY COMPLIANCE FOR US DRIVEN PROJECTS

SCCE ECEI 2014 EU DATA PRIVACY COMPLIANCE FOR US DRIVEN PROJECTS. Monica Salgado JANINE REGAN CIPP/E

PROJECT BACKGROUND AND RATIONALE

Cisco Spark and GDPR. Thomas Flambeaux. Collaboration Consulting Solution Engineer, Security and Compliance. Cisco Connect 2018 Copenhagen April 12th

The Role of the Data Protection Officer

Harmonisation of Digital Markets in the EaP. Vassilis Kopanas European Commission, DG CONNECT

encrypted, and that all portable devices (laptops, phones, thumb drives, etc.) be encrypted while in use and while at rest?

Developing Issues in Breach Notification and Privacy Regulations: Risk Managers Are you having the right conversation with the C Suite?

Report of the Working Group on mhealth Assessment Guidelines February 2016 March 2017

HEALTH INFORMATION INFRASTRUCTURE PROJECT: PROGRESS REPORT

U.S. Japan Internet Economy Industry Forum Joint Statement October 2013 Keidanren The American Chamber of Commerce in Japan

Networking Session - A trusted cloud ecosystem How to help SMEs innovate in the Cloud

Exploring the European Commission s Network and Information Security Directive (NIS) What every CISO should know

ENISA s Position on the NIS Directive

Discussion on MS contribution to the WP2018

Privacy Notice - General Data Protection Regulation ( GDPR )

Five Ways that Privacy Shield is Different from Safe Harbor and Five Simple Steps Companies Can Take to Prepare for Certification

AFC Compliance Careers

International Legal Regulation of Cybersecurity U.S.-German Standards Panel 2018

Directive on security of network and information systems (NIS): State of Play

Regulating Cyber: the UK s plans for the NIS Directive

Manuel E. Maisog Partner

Hong Kong s Personal Data (Privacy) Ordinance

Hot Topics in Privacy

Hot Topics in Privacy

PRC Cyber Security Law --- How does it affect a UK business? Xun Yang Of Counsel, Commercial IP and Technology

2017 RIMS CYBER SURVEY

REGIONAL WORKSHOP ON E-COMMERCE LEGISLATION HARMONIZATION IN THE CARIBBEAN COMBATING CYBERCRIME: TOOLS AND CAPACITY BUILDING FOR EMERGING ECONOMIES

13303/17 CB/ek 1 DGE 2B

The GDPR and NIS Directive: Risk-based security measures and incident notification requirements

Block 1: Introduction Overview, Requirements, Knowledge Profiles. FH-Prof. DI Dr. Stefan Sauermann Juliane Herzog, MSc.

Robert Bond. Respecting Privacy, Securing Data and Enabling Trust a view from Europe

BRIEFING COMBATING CYBERCRIME: TOOLS AND CAPACITY BUILDING FOR EMERGING ECONOMIES. Geneva 18 April David Satola

ISACA GEEK WEEK SECURITY MANAGEMENT TO ENTERPRISE RISK MANAGEMENT USING THE ISO FRAMEWORK AUGUST 19, 2015

DIGITAL AGENDA FOR EUROPE

In Accountable IoT We Trust

GEORGIA CYBERSECURITY WORKFORCE ACADEMY. NASCIO 2018 State IT Recognition Awards

Magento GDPR Frequently Asked Questions

Roy E. Hadley, Jr. Overview. Partner. Contact Information. Education.

Update from HIMSS National Privacy & Security. Lisa Gallagher, VP Technology Solutions November 14, 2013

Talenom Plc. Description of Data Protection and Descriptions of Registers

Government Resolution No of February 15, Resolution: Advancing National Regulation and Governmental Leadership in Cyber Security

Promoting Digital Economy in the Eastern Partnership. Vassilis Kopanas European Commission, DG CONNECT

Cyber Security Issues and Responses. Andrew Rogoyski Head of Cyber Security Services CGI UK

Section I. GENERAL PROVISIONS

ISACA National Cyber Security Conference 8 December 2017, National Bank of Romania

Article II - Standards Section V - Continuing Education Requirements

Future-Proof Security & Privacy in IoT

NYDFS Cybersecurity Regulations

Privacy Notice. Lonsdale & Marsh Privacy Notice Version July

Internet Governance in September September 2016

U.S. Private-sector Privacy Certification

Note by the Secretary- General CANDIDACY FOR THE POST OF DIRECTOR OF THE TELECOMMUNICATION STANDARDIZATION BUREAU (TSB)

GDPR Privacy Webinar. Prioritizing Your Path towards GDPR Compliance Annika Sponselee and Nicole Vreeman 28 February 2018

The NIS Directive and Cybersecurity in

Cybersecurity and Privacy Innovation Forum Brussels, 28 April Keynote address. Giovanni Buttarelli European Data Protection Supervisor

State Planning Organization Information Society Department

International Compliance

Data Protection in Switzerland Update Following the Safe Harbor Decision. 21 October 2015 / 6 February 2016 Christian Wyss

Vice President and Chief Information Security Officer FINRA Technology, Cyber & Information Security

MARKETING ALLIANCE MEDIA KIT 2016/17

Virtual Currencies and The Commonwealth. 1 June 2016

The Stakes Are Going Up: Hacking and the New Paradigm of Data Breaches

Cybersecurity Policy in the EU: Security Directive - Security for the data in the cloud

CISI Continuing Professional Development (CPD) Policy

Building YOUR Privacy Program: One Size Does Not Fit All. IBM Security Services

Report on the activities of the Independent Integrity Unit, November 2016 to September 2017

Legal framework of ensuring of cyber security in the Republic of Azerbaijan

Privacy Notice. General Information Protection Regulation ( GDPR )

General Data Protection Regulation (GDPR) The impact of doing business in Asia

Promoting Global Cybersecurity

General Data Protection Regulation April 3, Sarah Ackerman, Managing Director Ross Patz, Consultant

BHConsulting. Your trusted cybersecurity partner

How Cybersecurity Initiatives May Impact Operators. Ross A. Buntrock, Partner

FOUNDED GOAL of New ORGANIZATION. CLEAR Annual Educational Conference Getting the Most Out of CLEAR. St. Louis October 3-5, 2013

8. AUTOMATED DECISION MAKING DURING DATA PROCESSING FURTHER INFORMATION FURTHER INFORMATION AND GUIDANCE CONTACT US...

Investigating Insider Threats

Proposed WEEE Directive A Step-by-Step Analysis

cybersecurity in Europe Rossella Mattioli Secure Infrastructures and Services

Advising the C-Suite and Boards of Directors on Cybersecurity. February 11, 2015

African Theatre Association (AfTA) PRIVACY POLICY


cybersecurity in Europe Rossella Mattioli Secure Infrastructures and Services

EU data security and privacy trends

Connected & Autonomous Vehicles

Mapping to the National Broadband Plan

Embedding Privacy by Design

Workday s Robust Privacy Program

ICT Legal Consulting on GDPR: the possible value of certification in data protection compliance and accountability

How the European Commission is supporting innovation in mobile health technologies Nordic Mobile Healthcare Technology Congress 2015

CASE STUDY CHIEF INFORMATION OFFICER GROUP

DeMystifying Data Breaches and Information Security Compliance

Privacy Policy. You may exercise your rights by sending a registered mail to the Privacy Data Controller.

Data Breach Notification: what EU law means for your information security strategy

Transcription:

Partner London +44 20 7360 3600 +44 20 7626 7937 wlong@sidley.com PRACTICES Banking and Financial Services Healthcare Privacy, Data Security and Information Law INDUSTRIES Financial Services Life Sciences AREAS OF FOCUS Business Transactions Involving Financial Institutions Clinical Trials Consumer Protection and Unfair Trade Practices Cybersecurity, Cybercrime and Data Breaches Electronic and Mobile Commerce EU - Food, Drug and Medical Device Regulatory EU and International Privacy FCPA/Anti-Corruption Financial Industry and Payment Processing Financial Information and Privacy Law Financial Institutions Counseling Financial Services Legislation Global Financial Services Healthcare Information and Privacy Healthcare Regulatory Information Security and Data Breaches Internal Investigations Internet, Social Media and E-Commerce IT Procurement and Outsourcing Life Sciences Transactions Mass Media Communications Medical Devices Payments Pharmaceuticals Retail Financial Services Technology, Media and Privacy Law Telecommunications, Broadband and Video WILLIAM LONG advises international clients on a wide variety of data protection, privacy, information security, social media, e-commerce and other regulatory matters. William has been a member of the European advisory board of the International Association of Privacy Professionals (IAPP) and has experience with EU and international data protection and e-commerce projects working for clients in financial services and life sciences, as well as other sectors. Representative matters have included: Advising a global e-commerce company on dealing with an international data security breach. Assisting a global manufacturing company with a global data protection project including implementation of Binding Corporate Rules. Assisting a global medical device manufacturer with a global data protection project including 1

implementation of Binding Corporate Rules, dealing with cross-border data transfer issues and assisting with data protection filings. William was previously in-house counsel to one of the world s largest international financial services groups. He has been a member of a number of working groups in London and Europe looking at the EU regulation of e-commerce and data protection and spent a year at the UK s Financial Law Panel (established by the Bank of England), as assistant to the Chief Executive working on regulatory issues with online financial services. William is recognized in Chambers UK 2016 for Data Protection and Information Law, with sources telling the publication he is very knowledgeable, has his finger on the pulse and a very good collaborative spirit. He is also recognized in the LMG Life Sciences Guide for Intellectual Property. Most recently, William is recommended for both Data Protection and Pharmaceuticals and Biotechnology in The Legal 500 UK 2015, with clients describing him as academically brilliant and very commercially astute. He is also listed in the 2015 edition of Best Lawyers in Privacy & Data Protection. William is on the editorial board for ehealth Law & Policy and efinance & Payments Law & Policy and is on the DataGuidance panel of data protection lawyers. He is a contributor to a number of books on data protection including leading legal text books published by BNA in the area of privacy including ones on cloud computing and the use of health data. William also contributed to a major global survey of Privacy, Data Protection and Cybersecurity law covering 62 international jurisdictions which was published in late 2014 by Law Business Research. He has also been interviewed widely for his thought leadership, including in such leading publications as the Financial Times and International New York Times and writes for a number of publications including Computer Weekly, Cloud Pro and CIO Today. PUBLICATIONS The Impact of the Court of Justice of the EU s Judgment Declaring The European Commission s EU-U.S. Safe Harbor Decision Invalid, co-authored with Cam Kerry, BNA's Privacy and Security Law Report, November 23, 2015 Cross-border overview: data privacy and transfer, co-authored with Michele Tagliaferri, The European, Middle Eastern and African Investigations Review, August 2015 Proposed EU Data Regulations Will Impact California, Daily Journal, July 13, 2015 EU General Data Protection Regulation comes into sharper focus, ComputerWeekly, June 29, 2015 Final Negotiations Set To Begin On EU Data Privacy Law, co-authored with Francesca Blythe, Law360, June 22, 2015 Generational interpretations and expectations of privacy, co-authored with Geraldine Scali and Francesca Blythe, Data Protection Law & Policy, February 2015 European Union Overview, and United Kingdom, in The Privacy, Data Protection and Cybersecurity Law Review, November 2014 What to Expect from Europe s NIS Directive, ComputerWeekly, September 2014 Significant Impact of New EU Data Protection Regulation on Financial Services, Global Banking & Finance Review, April 18, 2014 CIOs and the changing legal landscape, CIO Today UK, March 2014 Proposed EU communications network will impact US businesses, CA Daily Journal, March 6, 2014 A Safe Direction, European Pharmaceutical Contractor, March 1, 2014 European Cloud Computing Strategy to create 2.5 million new jobs, ComputerWeekly, January 7, 2014 2

Data protection challenges in the new era of Big Data, co-authored with Geraldine Scali, Data Protection Law & Policy, January 2014 Time for CIOs to Act on Proposed EU Data Privacy Laws, I-CIO, December 2013 EU Data Protection Regulation: Fines Up to 100 million Proposed, Computer Weekly, November 13, 2013 Safe Harbor for the cloud - not any port in the storm, Contributor, CloudPro, August 28, 2013 The New EU Data Protection Regulation: What will the Impact be on the Life Sciences Industry? March 2012 First Look: Leaked Draft of New EU Data Protection Regulation Suggests Significant Impacts for Global Businesses, December 9, 2011 EU Implementation of New Website Cookie Law, Data Protection Law & Policy, August 2011 European Shift to Concrete Cost Analysis of Data Protection, March 14, 2011 Pharmacovigilance and Data Protection, Data Protection Law & Policy, December 2010 Data Security and payments: dynamic Phorm of development, E-Finance Law & Policy, April 2009 Assessing the EU Working Party s Guidance on Harmonizing U.S. Discovery and EU Data Protection Requirements, March 9, 2009 Data Security breaches: the changing legal landscape, E-Finance Law & Policy, October 2008 New International Guidelines on the Transfer of Personal Health Data, Medical Research Law & Policy Selected Sidley Updates: Political Agreement Reached on EU Data Protection Regulation - December 18, 2015 Call for Safe Harbor 2.0; Companies Have Three Months to Assess Solutions - October 16, 2015 European Court of Justice Declares Safe Harbor Invalid - October 7, 2015 Opinion by ECJ Advocate General Finds Safe Harbor Invalid - September 24, 2015 One Step Closer to the EU Data Protection Regulation - June 15, 2015 Google Inc. v. Vidal-Hall: Opening the Doors to EU Data Protection Litigation? - May 12, 2015 UK Government launches new Cyber Essentials measures - June 18, 2014 European Parliament Votes to Approve New EU Data Protection Regulation and Immediate Suspension of Safe Harbor - March 17, 2014 European Parliament s Civil Liberties Committee Report calls for immediate suspension of Safe Harbor - January 10, 2014 European Commission makes recommendations to strengthen Safe Harbor - December 3, 2013 MEMBERSHIPS & ACTIVITIES Member of the International Association of Privacy Professionals (IAPP) European Advisory Board Member of the American Chamber of Commerce Co-founder of the Social Media Governance Forum Previous Member of the Centre for European Policy Studies Working Group on ecommerce Regulation 3

EVENTS Speaking Engagements Safe Harbor Data Privacy Briefing: Your Questions Answered by Giovanni Buttarelli, DataGuidance Webinar, October 20, 2015 Safe Harbor Data Privacy Briefing: Your Questions Answered, DataGuidance Webinar, October 8, 2015 The Impact on Business & Diplomatic Organizations, Cybersecurity & Management Challenges, Lugano, September 30, 2015 The Impact of the GDPR on Outsourcing, DataGuidance Webinar, September 23, 2015 Update on EU Data Privacy Issues, dplegal bi-annual meeting, Geneva, June 16-17, 2015 How to implement privacy programmes in practice, dplegal bi-annual meeting, Geneva, June 16-17, 2015 Big Data and Privacy, DataGuidance Webinar, May 20, 2015 EU Data Protection Regulation Implications for the Life Sciences Industry, Life Sciences College, London, May 13, 2015 How to Implement the Data Protection Regulation in Practice, IAPP Europe Data Protection Intensive, London, April 15, 2015 Update on the proposed EU Data Protection Regulation, Association of Corporate Counsel Webinar, April 9, 2015 DataGuidance Data Protection Financial Services Day, January 29, 2015 Cybersecurity Breakfast Roundtable, London, November 2014 DataGuidance Webinar, Information Security, December 2014 How to deal with cyber security risks, DataGuidance Webinar, July 2014 Privacy Laws & Business Conference, Queen s College, Cambridge University, Cambridge, June/July 2014 Life Sciences College, Brussels, May 2014 ABI Cyber Risks and Cyber Opportunities Seminar, London, May 2014 IAPP Europe Data Protection Intensive, London, April 2014 dplegal webinar on data privacy issues with disclosure of clinical trial reports, March 2014 Cloud Computing and Data Protection Roundtable, London, March 2014 Stafford Publications webinar on data privacy compliance in global transactions, March 2014 ehealth Law & Policy conference on e-health and data protection issues, London, February 2014 Webinar on social media and data protection issues, February 2014 DataGuidance webinar on Legal Developments with Information Security, January 2014 Risk & Opportunity: Big Data, Data Protection & Financial Services event in conjunction with DataGuidance, January 30, 2014 How to Build Your Data Breach Toolkit, IAPP Europe Data Protection Congress, December 10-12, 2013 4

IAPP Europe Conference, Information Security, Brussels, November 2013 Cloud Computing Roundtable, London, November 2013 ABI Cybersecurity Conference, London, September 2013 Cloud Computing Roundtable, London, September 2013 EU Life Sciences Update on social media and data protection, Palo Alto, July 2013 Privacy Laws & Business Conference at Queen s College, Cambridge University, Cambridge, July 2013 Pharmacovigilance Conference on UK data protection, London, July 2013 Global Life Sciences European Law Seminar, Palo Alto, July 2013 Cloud Computing Roundtable, London, June 2013 dplegal bi-annual meeting at the offices of Leo Pharma, Denmark, June 2013 Financial Services webinar in conjunction with DataGuidance, June 27, 2013 Legal Issues Affecting the Middle Market, CPI s EMEA Middle Market Conference, June 11, 2013 Update on the Proposed EU Data Protection Regulation and Its Impact on the Life Sciences Industry, Life Sciences College, April 17-18, 2013 IAPP Europe Data Protection Intensive, London, April 2013 Draft EU Parliament LIBE Committee s Report, cyber security and anti-money laundering, DataGuidance Financial Services Group, March 20, 2013 IAPP Webinar on Binding Corporate Rules, February 2013 DataGuidance Webinar on the EU Data Protection Regulation, January 2013 Cloud Computing Conference, London, December 2012 IAPP Europe Conference, Brussels, November 2012 dplegal launch event, Brussels, November 2012 DataGuidance Annual Financial Services Conference, London, November 2012 Secondary research issues at ctlegal bi-annual meeting, Amsterdam, October 2012 ABPI - The Future of Data Protection Seminar, London, July 2012 Sidley Life Sciences and Data Privacy Day, Brussels, July 2012 Mobile apps session at Privacy laws & Business Conference, Cambridge, July 2012 Brussels Data Protection Roundtable, Brussels, June 2012 European Direct Selling Association, Brussels, May 2012 Georgetown University Corporate Counsel Institute, Madrid, May 2012 Life Sciences and Data Privacy Day, Palo Alto, April 17, 2012 California Biotech conference on data privacy, California, March 9, 2012 IAPP Europe Data Protection Congress, Paris, November 29-30, 2011 SCL Seminar on Risk and Governance for IT Companies, London, November 17, 2011 5

Life Sciences & Data Privacy Day, New York, November 9, 2011 Global Forum, Brussels, November 7-8, 2011 Data Privacy, IAPP Training Day, London, October 18-19, 2011 DataGuidance Annual Data Protection in Financial Services Intensive, London, October 12, 2011 RSA Conference Europe 2011 efraud Network (efn) Forum, London, October 10, 2011 Social Media Governance Forum, London, July 19, 2011 and September 26, 2011 Privacy Laws & Business 24th Annual International Conference, Cambridge, July 11-14, 2011 DataGuidance Financial Services Group Forum, London, July 5, 2011 Life Sciences & Data Privacy Day, London, June 9, 2011 Data Privacy, EuroForum Conference on Clinical Trial Safety & Pharmacovigilance, Denmark, June 8, 2011 European DataGuidance Data Protection Intensive, London, May 26-27, 2011 Data Privacy at the Cloud Computing Forum, London, May 19, 2011 DataGuidance Financial Services Group Forum, London, January 18, 2011 ADMISSIONS & CERTIFICATIONS England and Wales (Solicitor), 1993 EDUCATION Queen Mary College, London, LL.B., 1989 6