
Governance & Compliance
Data Breach Lawyers
We are Punter Southall Law, compliance lawyers with expertise in dealing with a data breach in the UK, Europe and beyond.
Our respected team of experienced compliance lawyers is committed to the resolution of complex legal issues in the UK & abroad.
If you require advice, Contact Us to arrange an appointment.
A Pleasure to Partner and Work With
I have had the opportunity to work with Lilian for a number of years. Her insights and guidance are always well balanced, she is extremely responsive, highly knowledgeable and most importantly a pleasure to partner and work with.
Anonymous
Unparalleled Knowledge
I am incredibly grateful for the outstanding and always fast service provided by Lilian. Her unparalleled knowledge, practical approach and unwavering dedication have been instrumental in navigating complex regulatory matters with ease. I wholeheartedly recommend her to anyone seeking top-tier legal counsel in the UK financial services industry.
Anonymous
Pragmatic and Commercial Approach
Lilian is a highly skilled regulatory lawyer who has excellent client relationship skills and has a pragmatic and commercial approach to issues. Having been instructed on short notice to assist on an ongoing project she impressed the whole team with her approach and input. Her support was invaluable.
Anonymous
A Tower of Strength and Support
Lilian has been a tower of strength and support. She is incredibly bright and knowledgeable. She is also pragmatic and determined. A rock to have by your side as a first-class lawyer and as a very thoughtful person.
Anonymous
Dealing with a Data Breach
Data breaches can have real consequences for organisations large and small. Legal reporting obligations mean you will need to move quickly. We know that even the best of plans can go wrong. Any company – large or small – can have a data breach. When this happens it is important to get good advice quickly. We have helped deal with dozens of data breaches. We have helped companies in different sectors, including health and financial services.
Recognised in The Legal 500
Punter Southall Law is recognised in The Legal 500 for our expertise in Data Protection, Privacy and Cybersecurity. The guide highlights the firm’s strong capability in advising on complex compliance mandates and responding to high-stakes data breaches.
Our experience tells us that you are likely to need help in 4 main areas:
- Investigate
- Assess
- Remediate
- Mitigate
Investigate a data breach
Our lawyers are used to investigating data breaches. We know about most kinds of technology so there is less chance that you will need to spend precious time explaining the breach to us. We are used to dealing with hard copy breaches too, like lost files or diaries. We structure our investigations under legal standards of confidentiality and privilege.
Assess a data breach
It is important that you know the consequences as soon as possible. You will likely want to brief your board at a very early stage and they will want to know what is likely to happen. Whilst there is much talk of fines of 4% of annual revenue or €20m under GDPR, it is not that simple. Different breaches attract different levels of fines. Regulators also have a discretion and you might want to persuade them to exercise that discretion in your favour.
Data protection regulators might not be your only concern. Depending on what you do you might have a duty to report to other regulators as well – some of those regulators operate on even tighter time limits than the 72 hours under GDPR.
We have done a lot of work on assessing the likely levels of fines under GDPR. In addition, we can help assess:
- What your customers’ reaction might be.
- Whether there is a potential for civil liability, for example with the enhanced ability of individuals to start proceedings for data protection infringements.
- What the potential press reaction might be.
- What the consequences for individuals within your business could be.
We deliver our advice quickly in a way that your management can understand.
Remediate a data breach
It is important to do what you can to minimise the effects of a breach quickly. Putting remedial measures in place quickly might also help you mitigate the affects of the breach.
We will help you put remedial measures in place which could include:
- Quick reactive training to ensure that the same mistakes are not made again.
- A programme of victim outreach to help lessen or eliminate harm. This might include FAQs for call handlers or directly engaging with victims or their lawyers on your behalf. It might also include helping you respond to Subject Access Requests which we have found increase after an incident.
- New policies and procedures to make sure that the same thing does not happen again.
- Holding vendors to account if they have been responsible for the breach.
Since we’ve handled many data breaches, we’ve lots of knowledge on remediation that works and the types of remediation plan a regulator would expect to see.
Mitigating the outcome of a data breach
Even under GDPR regulators have a discretion on the action they take – or whether they take any action at all. Regulatory penalties range from a non-public admonition to 4% of global revenue or €20m. We have studied regulatory findings and we know in any given scenario what a regulator is likely to find important.
In some countries a DPA will inform the organisation concerned of its plan to impose a penalty (for example) by issuing a so-called Notice of Intent. The organisation then has the possibility of making representations about the imposition and level of the penalty. Making properly considered, well presented representations to the regulator will be crucial. We can help. We will also help liaise with regulators in different countries and in local language where required. Sometimes there will still be regulatory findings that you do not agree with.
In some respects the GDPR fining mechanism is based on the EU’s competition law regime. Our team has experience of handling appeals under that regime. In many cases successful challenges have been brought to the courts in Europe against regulatory fines and the indications are that appeals against GDPR fines might follow the same path. The success rate on appeals against GDPR fines has been high so far. We can help you assess whether your outcome is reasonable and what your options are if it is not.
Speak with a London-based data breach solicitor or consultant lawyer
For bespoke legal advice on all data breach matters, speak with one of our lawyers. We are ready to assist you with your regulatory or compliance needs and work with you on achieving your objectives.
Contact Us to arrange a consultation.
Read our governance & compliance articles
EU DORA Regulation & Operational Resilience Requirements
One of the most talked about topics currently in legal, financial services and cyber security circles is on the implementation of DORA, or to give it its formal name the…
21 Min Read
Read More EU DORA Regulation & Operational Resilience RequirementsGDPR Glossary: EU data protection key terms & acronyms
We’ve put together this glossary to help explain some of the terms used in data protection and in GDPR. If there’s a term you think we should add, or you’d…
17 Min Read
Read More GDPR Glossary: EU data protection key terms & acronymsThe EU’s NIS2 Directive
What’s this all about? NIS2 is about cybersecurity. The NIS2 Directive entered into force on 16 January 2023. The deadline for Member States to transpose this into national law was…
14 Min Read
Read More The EU’s NIS2 Directive