From collection, use, selling and cross-border sharing to protecting and disposing of data, we work with clients to navigate the ever-changing patchwork of domestic and global privacy and data security laws and regulations.  We have also guided companies’ responses to some of the earliest and largest data breaches in the U.S. and have led precedent-setting litigation stemming from those incidents.

Who We Represent

We advise a range of clients on the full spectrum of privacy and data security matters, from representing one of the nation’s largest financial institutions in litigation involving the reported theft of nearly 50 million payment cards to serving as compliance advisor to global retailers – including many that are headquartered steps away from Vorys’ office in Columbus, Ohio.

We counsel clients on privacy and data security matters in a wide range of industries, such as:

  • Nearly one-third of the National Retail Federation’s Top 100 list, including more than half of the Top 25 retailers
  • More than 150 financial institutions, including 50 national and regional banks
  • National grocery chains, restaurant chains, and franchises
  • Manufacturers
  • Defense contractors
  • Insurance companies
  • Large health care providers
  • International energy companies
  • Colleges and universities
  • eCommerce merchants
  • Hotels

Our 360-Degree Approach

Whether by conducting privacy audits, refining data security and privacy policies, negotiating data processing agreements, or developing incident response and crisis communication plans, we help our clients comply with constantly changing domestic and global regulations and implement best practices.  We routinely counsel clients through the complete data lifecycle:

  • Developing internal and external-facing policies and procedures for management of the collection, use, sharing, selling, storage, transfer and disposal of regulated data
  • Negotiating privacy and security contract provisions with service providers, vendors and customers
  • Mapping the collection, use and sharing of regulated data
  • Assisting with management of individual privacy rights requests
  • Developing incident response and crisis communication plans
  • Conducting training exercises from the C-Suite to frontline employees
  • Responding and reporting to regulatory inquiries and investigations
  • Managing responses to data security breaches
  • Conducting privileged and non-privileged forensic investigations
  • Conducting gap assessments and reviews against applicable security frameworks
  • Litigation over privacy and cybersecurity claims
When clients experience data breaches despite their prevention efforts, we represent them in regulatory investigations ranging from the Federal Trade Commission (FTC) to multi-state attorneys general investigations, negotiate consent decrees and advise clients on applicable breach notification laws.  Our crisis management team is available 24/7 to help clients through cybersecurity emergencies and can be reached by calling the Vorys’ emergency hotline: (833) 525-2100.  When legal disputes arise, we mobilize Vorys’ nationwide bench of trial and appellate lawyers to defend clients in state and federal courts across the country.

National Recognition

Vorys is consistently recognized as a top firm for advising clients in a range of industries that are particularly vulnerable to data breaches and privacy-related litigation.

We have earned a nationwide ranking for retail in the prestigious Chambers USA guide for the past seven years.  In a recent edition, Chambers notes Vorys’ “broad range of strengths in the retail sector,” including data security adding that Vorys is “frequently engaged by retailers facing consumer class actions.

In the guide, Chambers also recognizes the firm’s representation of clients in health care matters and states that Vorys “is noted for its work on HIPAA matters and IT issues.”


  • 24/7 Cyber
    24/7 Cyber
    Incident Response Team

    Vorys’ cyber lawyers provide legal strategy, privileged and non-privileged investigations and support, and assisting clients with media relations issues surrounding data breaches and cybersecurity incidents.  Your organization may have legal obligations to report an incident within hours of its discovery.  Our team is available 24/7 through our hotline at (833) 525-2100.

    grey faded arrow
Jump to Page