Heather Egan is a leading practitioner in cybersecurity, privacy, incident response, and information management. For nearly 25 years, Heather has advised on privacy and cybersecurity laws worldwide, developing a broad understanding of how multinational businesses have adapted their practices to evolving laws. She provides strategic advice to clients, including some of the world’s most recognizable brands, seeking to leverage emerging technologies, including artificial intelligence and advertising technology. Chambers recognizes her as “really sharp and impressive” and “thoughtful, strategic, and proactive.” Whether helping clients navigate a cyber crisis, build global privacy compliance programs, or deploy new products or services in an uncertain regulatory environment, Heather assists companies in solving their most pressing cybersecurity and privacy challenges.
Heather helps companies navigate security and privacy incidents and guides them through investigation, remediation, notification, and any ensuing government inquiries. Heather provides comprehensive crisis management support managing the legal risks of cyber crises, investigations and government enforcement actions.
To help clients navigate complex global regulatory compliance challenges, Heather builds global privacy programs, leads comprehensive cybersecurity and privacy assessments, vets risks in corporate transactions, conducts internal investigations stemming from data incidents, and drafts and negotiates contracts concerning data-related vendors and arrangements. She frequently counsels businesses on ways to mitigate risks associated with the collection, use, retention, disclosure, transfer, and disposal of personal data.
Heather routinely guides clients through the existing patchwork of laws impacting privacy and cybersecurity around the globe, including, Controlling the Assault of Non-Solicited Pornography And Marketing Act (CAN-SPAM), Electronic Communications Privacy Act (ECPA), Fair Credit Reporting Act (FCRA), Gramm–Leach–Bliley Act (GLBA), Health Insurance Portability and Accountability Act (HIPAA) and the Telephone Consumer Protection Act (TCPA). She also works with clients on state breach notification laws, state data security laws, self-regulatory frameworks (advertising and payment card processing) and several state privacy laws: California’s Consumer Privacy Act (CCPA) California Privacy Rights Act (CPRA), Colorado Privacy Act (CPA), Connecticut Data Privacy Act (CTDPA), Utah Consumer Privacy Act (UCPA) Virginia Consumer Data Protection Act (VCDPA), and the increasing number of US state privacy laws, designing flexible, scalable compliance programs that meet clients’ needs.
Listed, Hall of Fame, Cyber Law (including data privacy and data protection), Legal 500 (2024)
Listed, Technology Transactions, Super Lawyers (2024)
Listed, “Incident Response 40,″ Cybersecurity Docket’s (2020-2024)
Named, "AI Visionaries," Relativity (2022)
Named, Client Service All-Star, BTI Consulting Group (2022)
Named, Go To Lawyers, Cybersecurity & Data Privacy, Massachusetts Lawyers Weekly (2022)
Ranked, Band 2, Privacy & Data Security, USA, Chambers Global (2024)
Ranked, Band 1, Nationwide, Privacy & Data Security: Adtech, Chambers USA
Ranked, Band 2, Nationwide, Privacy & Data Security: Cybersecurity, Chambers USA
Ranked, Band 2, Nationwide, Privacy & Data Security: Privacy, Chambers USA
Member, Boston Bar Association, Intellectual Property Law Section Steering Group
Member, International Association of Privacy Professionals