Profile

Lisa chairs the firm's top-ranked global data, cyber & privacy practice and is the managing partner of the firm's New York office. Lisa has received widespread recognition for her work in the areas of privacy and cybersecurity. Chambers USA quotes clients who call her a "market leader," noting that she is "widely considered the best." Another client reported that "she is a strong leader with fantastic advice. She does great work on advisory boards and her leadership in the industry has really moved it forward." Chambers and Partners honored Lisa with the 2021 Outstanding Contribution to the Legal Profession award, which is given to only one lawyer each year for exceptional achievements, and noted that a peer enthused, "Lisa Sotto is a legend." Clients have called Lisa "the high priestess of privacy" and "the queen of breach." She was named among The National Law Journal's "100 Most Influential Lawyers," an honor bestowed on practicing attorneys who are making the biggest impact in the legal world, and among Forbes' list of "America's Top Lawyers" in 2025.A preeminent lawyer and dynamic problem solver, Lisa assists clients in identifying, evaluating and managing risks associated with privacy and data security practices. She advises clients on the California Consumer Privacy Act of 2018 and other comprehensive state privacy laws, GLB, HIPAA and state health privacy laws, COPPA, CAN-SPAM, FCRA, VPPA, data breach notification laws, and other U.S. state and federal privacy and cybersecurity requirements (including HR rules), and global data protection laws (including those in the EU, Asia and Latin America). She provides extensive advice on cybersecurity risks, incidents and policy issues, including proactive cyber incident readiness. Through the firm's privacy and security in M&A transactions team, Lisa also guides clients on risks and potential liabilities associated with inadequate privacy and data security practices in high-stakes corporate transactions. She conducts all phases of data privacy assessments and information security policy audits. She also develops corporate records management programs, including policies, records retention schedules and training modules.Lisa has been rated the "No. 1 privacy professional" in all surveys by Computerworld magazine. She is recognized by Chambers and Partners as a "Star" performer (the highest honor) for privacy and data security-the only privacy lawyer in the United States to receive this distinguished ranking. She also is ranked among the leading lawyers in Band 1 for incident response. Lisa is recognized as a leading lawyer for cyber crime, data protection and privacy by The Legal 500 United States. In addition, Hunton Andrews Kurth's privacy and cybersecurity practice has received the topmost national rankings in privacy and data security both from Chambers and Partners and The Legal 500.Lisa speaks frequently at conferences, has testified regularly before the US Congress and other legislative and regulatory agencies, is the author of numerous treatises and articles, has been tapped to lead several industry committees and organizations, is sought after by media outlets and industry publications for her professional insights, and appears regularly on national television and radio news programs. She is the editor and lead author of the Privacy and Cybersecurity Law Deskbook, published by Aspen Publishers, Wolters Kluwer Law & Business.


Bar Admissions

New York

Education
JD, University of Pennsylvania Law School, Law Review

BA, History, Cornell University, distinction in all subjects

Areas of Practice

  • Corporate
  • Privacy and Cybersecurity

Professional Career



Articles

A New Decade in Data Privacy: Complying With the CCPA

Navigating The Digital Age, The Definitive Cybersecurity Guide For Directors and Officers Vol. 3, Lessons From Today's World, How to Manage a Data Breach

2020 Retail Industry Year in Review

A How-To Guide to Information Security Breaches, Privacy and Information Law Report, IAPP Privacy Advisor, BNA Privacy & Security Law Report

A New Decade in Data Privacy: Complying With the CCPA

A New Era: The EU-U.S. Data Privacy Framework, Thomson Reuters' Regulatory Intelligence

AI in M&A: Identifying and Managing the New IP and Data Privacy Risks

Blockchain, Cybersecurity and Global Finance

Board Oversight of Privacy and Cybersecurity Risk: Why Delaware Developments Matter, The Computer & Internet Lawyer

Business Without Borders: The Importance of Cross-Border Data Transfers to Global Prosperity, Hunton & Williams and U.S. Chamber of Commerce

California Consumer Privacy Act and Its Impact on M&A Transactions, Deal Lawyers

California Consumer Privacy Act and Its Impact, Los Angeles Business Journal

California Consumer Privacy Act: A Sea of Change for Retailers, Chain Store Age

California Legislature Passes Bill to Establish the Genetic Information Privacy Act, Pending Governor's Signature, PLI Chronicle

California: New year, new privacy policy: CCPA obligations and obstacles

Comment: Data Protection Outlook for 2011: A Global Discussion, Data Protection Law & Policy

Cybersecurity Risks and Readiness for the Hotel Industry, GMBHA Allied Upgrade eNewsletter

Data Breach! Correct Response Crucial, New York Law Journal

Data Due Diligence in M&A Deals (Sotto featured), Corporate Secretary

Data Protection & Privacy 2016, United States, Getting the Deal Through

Data Protection & Privacy 2027 ‒ Global Overview

Data Protection & Privacy 2018, United States, Getting the Deal Through

Data Protection & Privacy 2019, Introduction, Getting the Deal Through

Data Protection & Privacy 2019, United States, Getting the Deal Through

Data Protection & Privacy 2020, Introduction, Getting the Deal Through

Data Protection & Privacy 2020, United States, Getting the Deal Through

Data Protection & Privacy 2021, Introduction, Getting the Deal Through

Data Protection & Privacy 2021, United States, Getting the Deal Through

Data Protection & Privacy 2022, Introduction, Getting the Deal Through

Data Protection & Privacy 2022, United States, Getting the Deal Through

Data Protection & Privacy 2023, Introduction, Getting the Deal Through

Data Protection & Privacy 2023, USA, Getting the Deal Through

Emerging Privacy Issues in Bankruptcy, New York Law Journal

ESG Hot Topics

EU-US Privacy Shield: A Path Forward, Corporate Compliance Insights

Facebook pivots from facial recognition system following biometric privacy suit; more biometric privacy litigation on the horizon, Westlaw Today

FTC's Red Flags Rule: Delays Suggest Confusion on the Part of the Industry, Privacy & Data Security Law Journal

HITECH Breaches: A How-To Guide, BNA's Health Law Reporter and Privacy & Security Law Report

Hottest Practice Area? (Sotto featured), Legal Bisnow

How to Safeguard Privacy and Data Security in Corporate Transactions, Corporate Counsel

INSIGHT: Illinois Biometric Privacy Law Doesn't Require Actual Injury-What's Next?, Bloomberg Law

INSIGHT: Six Flags Fingerprint Privacy Case Puts Illinois Biometric Law to Test, Bloomberg Law

Legal Viewpoint: Critical Next Steps to Avoid Litigation, Notifying Law Enforcement, and Choosing Response Vendors, Symantec White Paper

Lisa Sotto Shares Insights on Cybersecurity, CCPA, Wolters Kluwer

Maximillian Schrems v. Data Protection Commissioner, E-Commerce Law Reports, volume 15 Issue 5

Navigating Privacy and Data Security Issues in M&A and Other Transactions, Bloomberg Law

New Cyber Guidance on the Horizon-Be Prepared, LexisNexis Corporate Counsel Advisory

Notice and Choice Paradigm in the US: Shifting the Focus, Data Protection Law & Policy

NYDFS Proposes Updated Second Amendment to Its Cybersecurity Regulation, NYU Law's Program on Corporate Compliance and Enforcement Blog

Online Behavioral Advertising: A User's Guide, IP Litigator

Preservation and Monitoring of Corporate Messaging, New York Law Journal

President Biden's Executive Order Enables Agencies to Address Key Artificial Intelligence Risks, Privacy & Cybersecurity Law Report

Preventive Measures: Records and Information Management Companies Need to Take Steps to Comply with the Newly Adopted HIPAA Omnibus Rule, Storage & Destruction Business Magazine

Privacy & Data Security: The Future of the US-EU Safe Harbor, Practical Law

Privacy and Cybersecurity Risks in the Metaverse: 5 Steps to Protect Your Data, Legaltech News

Privacy and Data Security in ESG, Corporate Counsel

Privacy and Data Security Risks in Cloud Computing, BNA Electronic Commerce & Law Report

Privacy Shield Redux: Looking Ahead to a New EU-U.S. Data Transfer Framework, CPO Magazine

Ransomware Attacks Raise Key Legal Considerations, Law360

Recent developments under BIPA: Examining Spokeo's impact and more, Westlaw Journal Computer and Internet

SEC Cybersecurity Investigations: A How-To Guide, Westlaw Journal: Securities Litigation & Regulation

Sounding the Alert on Data Breaches, New York Law Journal

Spokeo's Impact and More, Westlaw Journal

Strategic Information Management, BNA Privacy and Security Law Report

Surviving an FTC Investigation After a Data Breach, New York Law Journal

Technology: The privacy perils of mobile technology, InsideCounsel

The Boucher Bill: Shaping the Privacy Landscape in the U.S., Data Protection Law & Privacy

The California Consumer Privacy Act is HERE: Are You Litigation Ready?, Cybersecurity Law & Strategy

The California Privacy Rights Act of 2020: CCPA Redux

The EU AI Act: Guide for In-House Lawyers

The EU-US Privacy Shield: A How-To Guide, Law360

The Lurking Dangers of Data Security (Sotto interviewed), Lodging Hospitality

The Move Toward a More Comprehensive Privacy Regime in the US (Sotto featured), Ernst & Young: 2012 Privacy Top Trends, Insights on IT Risk

The Queen of Breach: Privacy Expert Lisa Sotto Goes Public (Sotto featured), Super Lawyers

The Shifting Sands of Data Protection and Resulting Privacy Pitfalls, State Bar of Texas - 10th Annual Advanced In-House Counsel Course

Thought Leaders in Privacy, DataGuidance (Sotto interviewed)

Virginia and Colorado Add to the Evolving US Privacy Landscape, Retail Industry 2021 Year in Review

Watch for the Expansion of BIPA Claims to New Use Cases and Jurisdictions, Pratt's Privacy and Cybersecurity Law Report

What Every U.S. Employer Should Know About Workplace Privacy (Parts One and Two), ALM's Privacy & Data Protection Legal Reporter

Where Calif. Privacy Law and Employee Benefits Data Collide

Women in IT Security: Women of Influence (Sotto featured), SC Magazine

Meet our Firms and Professionals

WSG’s member firms include legal, investment banking and accounting experts across industries and on a global scale. We invite you to meet our member firms and professionals.