Site Search
Professionals 88 results
Capabilities 56 results
Practice Area
Winston takes a strategic approach to privacy and data security, integrating our extensive capabilities across practices to provide our clients with cutting-edge privacy and data security counseling, crisis management, security incident investigation and notification management, defense of data security class action litigation and regulatory inquiries, and international data protection. Our Global Privacy & Data Security Practice features a core team of privacy professionals and is bolstered by more than 40 attorneys from a variety of other disciplines firmwide. Our team combines compliance counselors, transactional lawyers, former government regulators and federal prosecutors, seasoned investigators, and experienced litigators. Few firms can rival our in-depth, sophisticated, and integrated experience in this area.
Practice Area
Privacy: Regulated Personal Information (RPI)
Winston’s Regulated Personal Information (RPI) Practice offers seamlessly integrated counseling and litigation services to companies looking for practical and solution-oriented assistance navigating the compliance, regulatory, and private class action enforcement risks presented by the emerging patchwork of complex (and often conflicting) privacy laws in the United States and beyond.
Practice Area
Brands across key sectors turn to Winston litigators to defend their reputations in advertising class actions, competitor disputes, and investigations. With litigators based in the U.S.’s busiest jurisdictions—including courts in California, Florida, Illinois, New York, and Texas—we have deep experience and prowess in handling some of the most high-profile and business-essential advertising cases in recent history. These disputes have involved false advertising; unfair competition, unfair business practices, and unjust enrichment; copyright, trade name, and service mark infringement; consumer-protection claims; and violations of the Lanham Act.
Experience 3 results
Experience
|October 1, 2023
Class Action Plaintiff Sent Packing After Winston Secures Enforcement of Binance’s Terms of Use
A Winston team secured a decisive victory for a major cryptocurrency exchange (and provided a potential roadmap for other online businesses seeking to enforce arbitration clauses in their terms of service) this week when a federal judge granted a motion to compel arbitration.
Experience
|August 27, 2021
GenNx360's Majority Investment in Whitsons Culinary Group
Winston & Strawn LLP represented GenNx360 Capital Partners, a New York City-based private equity firm investing in middle market business-to-business industrial and business services companies, in its majority investment in Whitsons Culinary Group, which leads the industry with its customized services, innovative programs, commitment to quality, focus on nutrition, local sourcing, and community support. Its services include school nutrition, residential and healthcare dining, prepared meals, and emergency dining. GenNx360’s operational expertise and track record of building platforms will continue to drive Whitson’s next phase of rapid growth. GenNx360's investment will enable Whitsons to focus on driving their mission of Enhancing Life One Meal at a Time™.
Experience
|July 30, 2021
Winston & Strawn LLP represented Norwest Equity Partners (“NEP”), a leading middle-market investment firm founded in 1961, in the sale of its portfolio company, Focal Point Data Risk (or the “Company”), a leading data risk management services company, to CDW Corporation (Nasdaq: CDW), a leading multi-brand provider of information technology solutions. Serving mid-to-large enterprises and governments in the United States and internationally, Focal Point offers solutions that help companies secure their business so they can grow and innovate without risk. Solutions offered include professional and managed services across identity and access management, cybersecurity and data privacy, cyber defense, cyber skills development, and other risk consulting services.
Insights & News 1,340 results
Recognitions
|April 7, 2026
|Less Than 1 Min Read
Law360 Names Winston Lawyers to 2026 Editorial Advisory Boards
Several Winston & Strawn lawyers have been selected to serve on Law360’s 2026 Editorial Advisory Boards. As board members, they will provide feedback on Law360’s coverage and insights on how to best shape future content. Congratulations to:
Speaking Engagement
|March 10, 2026
Bobby Malhotra, chair of Winston’s eDiscovery and Information Governance Practice, moderated a panel at Legalweek exploring how Legal Data Intelligence can empower legal teams to create scalable, transparent, and risk-aware AI governance frameworks that address the evolving challenges of AI in organizations. The discussion focused on practical strategies for legal professionals to streamline policy development, compliance, risk management, and data governance throughout the entire lifecycle of AI systems.
In the Media
|March 6, 2026
|1 Min Read
Amelia Garza-Mattia Discusses VPPA Consumer Definition Case with Law360
Winston & Strawn's Amelia Garza-Mattia, senior associate in the firm's Global Privacy & Data Security Practice, was quoted in a Law360 article discussing what to expect in oral arguments for the Salazar v. Paramount Global U.S. Supreme Court case. The case asks the justices to consider what criteria consumers need to meet in order to sue under the federal Video Privacy Protection Act (VPPA), a law enacted in 1988 that prohibits the unauthorized disclosure of certain personal information belonging to “consumers” that rent, purchase, or subscribe to “goods and services from a video tape service provider,” and whether that statute applies to a consumer who doesn’t directly subscribe to audiovisual goods or services.
Other Results 60 results
Law Glossary
What Is Privacy Compliance Law?
The area of privacy compliance law addresses how organizations meet legal and regulatory requirements for collecting, processing, or maintaining personal information. Data privacy breaches can lead to regulatory investigations and fines. When privacy is compromised, consumers or employees may respond with civil lawsuits. It is recommended, but not required by a federal law, that companies create and post privacy policies on websites and mobile apps. Once posted, companies must follow these policies or face scrutiny by the Federal Trade Commission. (California and Delaware state law does require privacy policies to be posted on websites and mobile applications, if the site collects personally identifiable information).
Law Glossary
A privacy audit, also known as a privacy compliance audit, is an assessment tool that looks at an organization’s privacy protection policies and procedures, specifically in light of current relevant laws or regulatory requirements. The audits may be conducted by private organizations or by government agencies that are verifying a company’s regulatory compliance. In terms of privacy audit law, the FTC can conduct audits of organizations and take action when a company is improperly securing private information. Action is taken under the FTC Act, which covers unfair trade practices. Health Insurance Portability and Accountability Act audits are also conducted to ensure that providers are following HIPAA law and protecting private health information.


