Overview
Lindsay brings extensive data privacy experience gained from nearly 15 years of practice in highly regulated industries, including three in-house privacy secondments with a national retail pharmacy, medical device company, and a bank. Her practice specializes in day-to-day privacy counseling and building privacy compliance programs from the ground up.
Lindsay has also worked for the American Medical Association, American Dental Association, Rehabilitation Institute of Chicago, and the Illinois Office of Health Information Technology. These experiences inform her ability to counsel domestic and international clients across all industries, with a specialty in healthcare and technology.
She helps clients optimize personal data, design websites and mobile apps, negotiate privacy contracts, establish privacy-minded processes for onboarding vendors and new technologies, and counsels on data breach incidents, risk analysis, and risk management processes.
Her work includes advising on email, phone, and text messaging practices, crafting privacy policies, procedures, guidelines, and flowcharts, and evaluating privacy notices, consents, and other consumer-facing documents.
Lindsay also negotiates data processing agreements, business associate agreements, and other required privacy contracts, and she drafts privacy language for software, cloud, and data services transactions.
In addition to counseling on data privacy matters, Lindsay collaborates with the Firm’s litigators to defend clients in regulatory matters focused on biometric data, including claims filed under BIPA.
Experience
Representative Work
- Advised on local, state, federal, and international privacy laws including HIPAA, GDPR, CCPA, and similar state laws, FTC, TCPA, COPPA, CIPA, and CANSPAM.*
- Established comprehensive HIPAA compliance programs for health plans, health care providers, and business associates.*
- Advised on the HIPAA risk analysis process under the HIPAA Security Rule.*
- Developed and delivered onsite customized privacy training for clients.*
- Conducted website technology scans to identify privacy risks and revise website privacy policies and cookie banners.*
- Negotiated privacy contracts and provisions including business associate agreements and data processing agreements.*
- Drafted and implemented internal and external-facing privacy notices, policies, privacy impact assessments, and consents.*
- Analyzed proposed marketing and advertising campaigns involving personal information.*
- Conducted data mapping interviews to identify and carry out privacy remediation work.*
- Configured privacy-minded websites, mobile apps, portals, cookie banners, and consent management platforms.*
- Collaborated with business owners to assess, select, and deploy new technologies from a privacy perspective.*
- Counseled on the investigation, determination, and notification of a breach involving personal information.*
- Leveraged, optimized, and protected sensitive categories of personal information to achieve key business objectives.*
- Advised on the use of email and telephone texting practices.*
- Created privacy-oriented vendor management policies and due diligence procedures.*
* Experience occurred prior to joining Dorsey.
Industries & Practices
California Consumer Privacy Act (CCPA)
Explore This Practice View resources related to this practice- Advertising & Marketing
- Benefits & Compensation
- California Consumer Privacy Act (CCPA)
- Cybersecurity
- Digital Health
- Emerging Companies
- Healthcare Transactions & Regulations
- Hospitality
- Labor & Employment
- Privacy & Social Media
- Technology
- Technology Commerce
