small-logo
ProfessionalsCapabilitiesInsights & NewsCareersLocations
About UsAlumniOpportunity & InclusionPro BonoCorporate Social Responsibility
Stay Connected:
facebookinstagramlinkedintwitteryoutube
Site Search
  • Professionals (171)
  • Capabilities (64)
  • Experience (27)
  • Insights & News (1,976)
  • Other Results (76)

Professionals 171 results

Alessandra Swanson
Alessandra Swanson
Partner
  • Chicago
Email
+1 312-558-7435
vCard

Partner

  • Chicago
Sean G. Wieber
Sean G. Wieber
Partner
  • Chicago
Email
+1 312-558-5769
vCard

Partner

  • Chicago
John Rosenthal
John Rosenthal
Partner
  • Washington, DC
Email
+1 202-282-5785
vCard

Partner

  • Washington, DC
View All Professionals

Capabilities 64 results

Practice Area

Privacy & Data Security

Winston takes a strategic approach to privacy and data security, integrating our extensive capabilities across practices to provide our clients with cutting-edge privacy and data security counseling, crisis management, security incident investigation and notification management, defense of data security class action litigation and regulatory inquiries, and international data protection. Our Global Privacy & Data Security Practice features a core team of privacy professionals and is bolstered by more than 40 attorneys from a variety of other disciplines firmwide. Our team combines compliance counselors, transactional lawyers, former government regulators and federal prosecutors, seasoned investigators, and experienced litigators. Few firms can rival our in-depth, sophisticated, and integrated experience in this area....Read more

Practice Area

Privacy: Regulated Personal Information (RPI)

Winston’s Regulated Personal Information (RPI) Practice offers seamlessly integrated counseling and litigation services to companies looking for practical and solution-oriented assistance navigating the compliance, regulatory, and private class action enforcement risks presented by the emerging patchwork of complex (and often conflicting) privacy laws in the United States and beyond....Read more

Practice Area

Class Actions & Group Litigation

Winston has developed a consistent record of success handling class action cases in state and federal courts. The practice is anchored by seasoned class action lawyers, many of whom have been recognized by Chambers USA and other ranking organizations as being top practitioners in their field. Our clients rely on us to steer them through class action matters by drawing on the firm’s significant experience in resolving complex litigation using creative and aggressive arguments, across a broad range of class, collective, coordinated, and mass actions, as well multidistrict litigation. We also have succeeded at trial in several class actions—a rare occurrence....Read more

Experience 27 results

Experience

|

November 13, 2024

Winston advised Astorg on the acquisition of a majority stake in Redslim, in partnership with its founders and management team

Experience

|

December 8, 2023

Winston Represented Interlock Equity in Investment in evolv Consulting

Experience

|

October 3, 2023

Nauticus Robotics, Inc. acquires 3D at Depth, Inc.

View All Experience

Insights & News 1,976 results

Investigations, Enforcement, & Compliance Alerts

|

August 18, 2025

|

2 Min Read

PE Fund on Hook for Portco’s False Claims Act Cybersecurity Violations

DOJ False Claims Act (FCA) settlements related to cybersecurity typically have focused on false representations by a government contractor of its compliance with cybersecurity requirements. A recently announced settlement shows that private equity owners are not immune from potential FCA liability.

Client Alert

|

August 11, 2025

|

9 Min Read

The Current Debate about “Debanking”: Navigating Legal, Regulatory, and Reputational Challenges for Financial Institutions

Debanking—closing accounts or refusing to open accounts for customers perceived to be high risk—has become a hotly debated topic in recent years among groups on both sides of the political aisle. The debate involves allegations that banks have improperly debanked customers for political, rather than risk-based, reasons. Such accusations have shined a spotlight on banks’ account management practices, resulting in changes to regulatory practices and a new executive order from President Trump requiring additional regulatory changes and investigations. All of which will mean increased risk for financial institutions....Read more

News

|

August 4, 2025

|

3 Min Read

Key Takeaways from Winston’s Fifth Annual Health Care & Life Sciences Summit

Winston & Strawn was pleased to host its fifth annual Health Care & Life Sciences Summit. This year’s event brought together clients, colleagues, and industry leaders for an afternoon of insightful discussions, networking, and perspectives on the shifting dynamics across the health care and life sciences sector....Read more
View All Insights & News

Other Results 76 results

Law Glossary

What Is Privacy Compliance Law?

The area of privacy compliance law addresses how organizations meet legal and regulatory requirements for collecting, processing, or maintaining personal information. Data privacy breaches can lead to regulatory investigations and fines. When privacy is compromised, consumers or employees may respond with civil lawsuits. It is recommended, but not required by a federal law, that companies create and post privacy policies on websites and mobile apps. Once posted, companies must follow these policies or face scrutiny by the Federal Trade Commission. (California and Delaware state law does require privacy policies to be posted on websites and mobile applications, if the site collects personally identifiable information)....Read more

Law Glossary

What Is Data Breach and Data Security Law?

Within 48 U.S. states and the District of Columbia, data breach and data security laws require organizations and government agencies to provide notifications of security breaches when they involve personally identifiable information. Companies may also be required by state data breach laws to act to minimize the effects of a breach. The FTC can investigate companies that do not adhere to their stated privacy policies and do not have safeguards to protect customer data, but no broad federal law exists regarding breach notifications. However, these U.S. data security laws and government agency rules are enforced:...Read more

Law Glossary

What Is the General Data Protection Regulation (GDPR) Law?

The European Union General Data Protection Regulation (GDPR) law is an act, applied across the Union, which directs data privacy. The GDPR law is designed to protect the data privacy of all EU citizens and guide organizational approaches to handling data, as well as transferring it across borders. Under the GDPR, breach notification is mandatory within 72 hours if the breach is likely to “result in a risk for the rights and freedoms of individuals.” The GDPR applies to organizations within the EU as well as those outside of the EU if they offer goods or services to European citizens. It also applies to organizations that monitor the behavior of data subjects online....Read more
Logo
facebookinstagramlinkedintwitteryoutube

Copyright © 2025. Winston & Strawn LLP

AlumniCorporate Transparency Act Task ForceDEI Compliance Task ForceEqual Rights AmendmentLaw GlossaryThe Oval UpdateWinston MinutePrivacy PolicyCookie PolicyFraud & Scam AlertsNoticesSubscribeAttorney Advertising