Privacy rules are often implicated during the sale or purchase of a business asset, such as customer databases or client lists that contain personal data; the acquisition or divestiture of a business that involves employee information; business restructurings that materially alter how an organization processes customer or staff information; and due diligence exercises involving the disclosure of personal information. In each of these circumstances, Covington’s privacy and data security lawyers draw upon their expertise to ensure that the transfer of personal information is effected in accordance with applicable laws, regulations, and recommended practices. We also closely examine the underlying privacy policies and practices of the entities involved to confirm both that data is handled in accordance with such policies, and that the policies themselves meet appropriate standards and are consistent with the transaction’s objectives.
We are involved throughout the transactional process to ensure that documentation adequately addresses relevant privacy issues, including contractual rights and limitations governing the ownership, collection, use, distribution, and security of personal and aggregate information. We regularly craft confidentiality agreements, security protocols, transfer agreements, and related policies for data rooms (both online and off-line), and we also attend to various post-transaction privacy-related tasks. In addition, we offer continuing transactional advice to clients as they grow and expand their business. In this regard, we often prepare notices, consent forms, disclosure documents, vendor contracts, transfer documents, certification documents under the US-European Union (EU) Safe Harbor regime, and other agreements in the context of employment or third party relationships.
Representative Matters
- Handled the data privacy implications arising from the acquisition of an EU pharmaceutical company by a US-based company, including restructuring intra-company data flows following the transaction.
- Conducted due diligence regarding a target company’s privacy and data security practices on behalf of a client seeking to acquire a healthcare information products company.
- Negotiated and drafted content-sharing agreements to acquire news and other content for a health-oriented website.
- Assisted several multinational companies fulfill their registration and notification obligations in multiple jurisdictions, including numerous European countries.
|
|