Practice Expertise

  •  
  •  
  •  
  •  

Areas of Practice

  • Artificial Intelligence
  • Aviation
  • Blockchain and Digital Assets
  • California Consumer Privacy Act of 2018 ...
  • Children's Privacy
  • Corporate
  • Crisis Management
  • Cybersecurity Incidents
  • Data, Cyber & Privacy
  • European Data Protection and Privacy
  • Financial Services
  • FinTech
  • Global Economic Development, Commerce, and ...
  • Hospitality
  • Hotels and Hospitality
  • National Security
  • Privacy and Cybersecurity
  • Records Management
  • Retail and Consumer Products
  • Technology
  • View More

Profile

Lisa chairs the firm's top-ranked global data, cyber & privacy practice and is the managing partner of the firm's New York office. Lisa has received widespread recognition for her work in the areas of privacy and cybersecurity. Chambers USA quotes clients who call her a "market leader," noting that she is "widely considered the best." Another client reported that "she is a strong leader with fantastic advice. She does great work on advisory boards and her leadership in the industry has really moved it forward." Chambers and Partners honored Lisa with the 2021 Outstanding Contribution to the Legal Profession award, which is given to only one lawyer each year for exceptional achievements, and noted that a peer enthused, "Lisa Sotto is a legend." Clients have called Lisa "the high priestess of privacy" and "the queen of breach." She was named among The National Law Journal's "100 Most Influential Lawyers," an honor bestowed on practicing attorneys who are making the biggest impact in the legal world, and among Forbes' list of "America's Top Lawyers" in 2025.

A preeminent lawyer and dynamic problem solver, Lisa assists clients in identifying, evaluating and managing risks associated with privacy and data security practices. She advises clients on the California Consumer Privacy Act of 2018 and other comprehensive state privacy laws, GLB, HIPAA and state health privacy laws, COPPA, CAN-SPAM, FCRA, VPPA, data breach notification laws, and other U.S. state and federal privacy and cybersecurity requirements (including HR rules), and global data protection laws (including those in the EU, Asia and Latin America). She provides extensive advice on cybersecurity risks, incidents and policy issues, including proactive cyber incident readiness. Through the firm's privacy and security in M&A transactions team, Lisa also guides clients on risks and potential liabilities associated with inadequate privacy and data security practices in high-stakes corporate transactions. She conducts all phases of data privacy assessments and information security policy audits. She also develops corporate records management programs, including policies, records retention schedules and training modules.

Lisa has been rated the "No. 1 privacy professional" in all surveys by Computerworld magazine. She is recognized by Chambers and Partners as a "Star" performer (the highest honor) for privacy and data security-the only privacy lawyer in the United States to receive this distinguished ranking. She also is ranked among the leading lawyers in Band 1 for incident response. Lisa is recognized as a leading lawyer for cyber crime, data protection and privacy by The Legal 500 United States. In addition, Hunton Andrews Kurth's privacy and cybersecurity practice has received the topmost national rankings in privacy and data security both from Chambers and Partners and The Legal 500.

Lisa speaks frequently at conferences, has testified regularly before the US Congress and other legislative and regulatory agencies, is the author of numerous treatises and articles, has been tapped to lead several industry committees and organizations, is sought after by media outlets and industry publications for her professional insights, and appears regularly on national television and radio news programs. She is the editor and lead author of the Privacy and Cybersecurity Law Deskbook, published by Aspen Publishers, Wolters Kluwer Law & Business.

Bar Admissions

    Education
    JD, University of Pennsylvania Law School, Law Review

    BA, History, Cornell University, distinction in all subjects

    Areas of Practice

    • Artificial Intelligence
    • Aviation
    • Blockchain and Digital Assets
    • California Consumer Privacy Act of 2018 (CCPA)
    • Children's Privacy
    • Corporate
    • Crisis Management
    • Cybersecurity Incidents
    • Data, Cyber & Privacy
    • European Data Protection and Privacy
    • Financial Services
    • FinTech
    • Global Economic Development, Commerce, and Government Relations Group
    • Hospitality
    • Hotels and Hospitality
    • National Security
    • Privacy and Cybersecurity
    • Records Management
    • Retail and Consumer Products
    • Technology

    Blogs

    Hunton Immigration and Nationality Law

    The Hunton & Williams LLP Immigration practice, part of the firm's Labor and Employment Team, is concentrated in two major areas. First our work involves advising American and foreign businesses about obtaining the most appropriate temporary and permanent work visas for executives, professionals, and other skilled foreign workers. Careful planning and documentation are necessary to ensure the greatest chance of success. We also represent our clients in any negotiations or administrative...

    Privacy and Information Security Law Blog

    Global privacy and cybersecurity law updates and analysis. Computerworld magazine has named Hunton & Williams the top firm for privacy for the fourth consecutive year based on a survey of more than 4,000 corporate privacy professionals. In addition, Chambers and Partners rated Hunton & Williams the top Privacy and Data Security practice in its Chambers Global, Chambers USA and Chambers UK guides, noting that the firm "is highly regarded for the strength of its excellent team."

    Meet our Firms and Professionals

    WSG’s member firms include legal, investment banking and accounting experts across industries and on a global scale. We invite you to meet our member firms and professionals.