Our expert cyber, privacy and data protection team works closely with organisations across a wide range of sectors. We help clients to:

  • comply with their cyber and privacy legal and regulatory obligations
  • prepare for and manage cyber and data risks and build cyber resilience through incident response planning, simulation exercises, education and board advisory 
  • respond effectively to cyber incidents and data breaches, including ransomware events and data extortion, insider threats and supply chain attack,s and to manage subsequent regulatory investigations, enforcement, insurance claims, third-party disputes and litigation.

We work seamlessly with international advisors on global privacy and regulatory reviews and on cyber and data breach incidents involving and affecting clients across multiple jurisdictions.

Our clients include leading Australian and multi-national organisations operating in highly regulated sectors such as technology, telecommunications, healthcare, financial services, energy & resources, transport and defence. 

Our multi-disciplinary team includes experts in information security, digital forensics, privacy, regulatory compliance, disputes, employment and corporate governance. We have extensive experience in privacy compliance and audits, artificial intelligence, critical infrastructure, data due diligence, electronic surveillance, digital health, data commercialisation and data governance. 

Members of our team are recognised for their pragmatic, commercial advice and market-leading insights.

Before:

Before:

Preparatory advice and risk management 

  • Incident response and crisis management plan/playbook development and review
  • Board advisory 
  • Cyber simulation exercises
  • Regulatory compliance reviews 
  • Privacy Impact Assessments 
  • Critical infrastructure compliance 
  • Cyber insurance advisory 
  • Third party contract reviews
  • Cyber due diligence 
During:

During:

Incident Response

  • Incident management 
  • Regulatory compliance (incl. market disclosure) 
  • Regulator, law enforcement and government engagement 
  • Third-party coordination (e.g. forensics/negotiators) 
  • Communications drafting and review 
  • Stakeholder management 
  • Board advisory 
  • Insurance compliance 
  • Data review 
After:

After:

Post Incident Support

  • Regulatory and litigation management 
  • Post incident reviews 
  • Supplier and customer disputes 
  • Cyber insurance recovery
Work highlights

Australian healthcare services group

Comprehensive audit of the group's data handling practices and compliance with the Privacy Act and Spam Act, followed by support with uplifts to the group's data governance frameworks including privacy policy and collection notices, data breach and cyber incident response plans and a Spam Act compliance guide. We provide ongoing on-call support in relation to privacy, e-marketing and cyber matters.

Australian financial services group

End-to-end review and uplift of its privacy policies and procedures framework, following advice on privacy compliance risks across the group, advice on obligations in relation to document retention and the destruction/de-identification of redundant personal information and a summary of relevant regulatory guidance and decisions.

Major telecommunications group

Content and hardware collaboration with a media group, including contract negotiations and advice on a range of complex competition, privacy, Spam Act and e-marketing issues arising from the deal.

Global IT provider

Software malfunction and resulting data breach incident, including assisting with data breach assessment and notification obligations, engagement with impacted customers and responses to inquiries from the Australian data protection regulator, the Office of the Australian Information Commissioner (OAIC).

Global cold storage and logistics provider

Advice on the scope and practical implications of its cyber security, data protection and reporting obligations as responsible entity for critical infrastructure assets under the Security of Critical Infrastructure Act 2018 (Cth) (SOCI Act).

Various international and ASX-listed companies

Providing support in relation to significant data breach matters, including ransomware, nation-state and insider attacks. Supporting with incident response, communications, law enforcement engagement, regulatory compliance and engagement, data review, board advisory and managing third-party claims.

Our Cyber, Privacy & Data Protection team is consistently recognised as a leading practice.

Chambers & Partners, Legal 500, Lexology Index (previously Who’s Who Legal) and Best Lawyers