Liisa Thomas, a partner based in the Chicago and London offices, is Leader of the firm's Privacy and Cybersecurity Team.
Areas of Practice
Liisa's clients rely on her ability to provide clarity in a sea of confusing legal requirements and describe her as "extremely responsive, while providing thoughtful legal analysis combined with real world practical advice." She is the author of two treatises: Thomas on Data Breach: A Practical Guide to Handling Worldwide Data Breach Notification, which has been described as "a no-nonsense roadmap for in-house and external practitioners alike;" and Thomas on Big Data, praised for being a "comprehensive and detailed analysis of the complex and rapidly changing world of privacy law."
Liisa is known as an industry leader in the privacy and data security space and has been recognized by Best Lawyers in America, Leading Lawyers Network, Chambers and The Legal 500, as well as noted by leading publications and organizations for her "broad depth of privacy knowledge." Among other honors, she was named Lawyer of the Year – Privacy and Data Security 2022 by Best Lawyers; to Cybersecurity Docket's "Incident Response 30," honoring 30 incident response professionals critical to managing data breaches, in both 2016 and 2018; recognized as the 2017 "Data Protection Lawyer of the Year - USA" by Global 100; honored as the 2017 "U.S. Data Protection Lawyer of the Year" by Finance Monthly; and the recipient of the "Best in Data Security Law Services" at Corporate LiveWire’s 2017 Global Awards.
Liisa, who was born in Finland and previously lived in France, Egypt and Spain, frequently coordinates global efforts in the privacy area for her clients. Clients value her global insights and familiarity with business systems outside of the U.S. With Liisa’s assistance, her clients – which include major consumer brands, advertising agencies and consumer research companies – are able to navigate thorny data breach disclosure issues, use emerging interactive advertising techniques and create compliant security programs, all while effectively managing their legal risks. Clients praise Liisa’s ability to add real value to their businesses, and describe her as "keeping [clients] one step ahead of where [they] need to be."
Liisa is an active advocate of women and minorities in the legal industry and was honored for her leadership in the legal field by the Illinois Diversity Council. She is currently an adjunct professor in Northwestern University Law School where she is the recipient of the Edward Avery Harriman Law School Lectureship. She formerly taught privacy courses at several other Chicago-area law schools, including her alma mater, the University of Chicago. Liisa is the Vice-Chair of the Board of Trustees of the Chicago Symphony Orchestra, Chair of the CSO’s Negaunee Music Institute Board and plays violin in the Chicago Bar Association Symphony Orchestra, an orchestra made up of lawyers and judges.
Recent Privacy and Data Security Experience:
- Assisting clients with GDPR preparedness projects, including compliance assessments and implementation of remediation plans.
- Assessing the scope of possible breaches of personally identifiable information through use of forensic experts and extensive on-site due diligence.
- Creating data breach assessment and notification programs (both post-breach and pro-active pre-breach plans) for Fortune 100 companies.
- Assisting clients to develop e-mail marketing campaigns, text message campaigns, pre-recorded call campaigns and online information collection programs in compliance with CAN-SPAM and COPPA, among other laws.
- Developing internal policies for safeguarding personally identifiable information gathered online and from employees.
- Developing privacy compliance policies, procedures, monitoring programs and reporting plans.
- Training management on the requirements of the law, including those with respect to the maintenance and retention of employee records.
- Developing cross-border data transfer programs for multiple Fortune 100 and Fortune 500 companies.
- Helping a U.S.-based multinational corporation create binding corporate rules.
- Lawyer of the Year - Privacy and Data Security, Best Lawyers, 2022
- Best Lawyers in America, Best Lawyers, 2020-2022
- Named to Cybersecurity Docket's "Incident Response 40" (2021) and "Incident Response 30" (2016, 2018), honoring 30 incident response professionals critical to managing data breaches
- Notable Women in Law, Crain’s Chicago Business, 2020
- Legacy Award, Illinois Legal Aid Online, 2020
- The Legal 500 Hall of Fame – Cyber Law, Legal 500, 2020-2021
- Notable Minorities in Accounting, Consulting & Law, Crain’s Chicago Business, 2020
- Thought Leader on Cybersecurity, National Law Review, 2019
- Notable Women Lawyers, Crain's Custom Media, 2018
- Leading Lawyer, Cyber Law, Legal 500 USA, 2016-2021
- Leading Lawyer, Chambers Global, Privacy & Data Security, 2015-2021
- Leading Lawyer, Chambers USA, Nationwide Privacy & Data Security, 2014-2021
- Leading Lawyer, Chambers Illinois, Media & Entertainment: Transactional, 2013-2018
- Illinois Super Lawyer, Intellectual Property, Super Lawyers, 2006, 2018-2021
- Leading Lawyer, Leading Lawyers, 2016-2021
- Leading Woman Lawyer, Chicago Lawyer Magazine’s Diversity Issue, 2018
- "Data Protection Lawyer of the Year – USA," Global 100, 2017
- "U.S. Data Protection Lawyer of the Year," Finance Monthly, 2017
- "Best in Data Security Law Services," Corporate LiveWire’s Global Awards, 2017
- Recipient, National Law Journal's Cybersecurity Trailblazer Award, 2016
- Recipient, Lexology/ILO's Client Choice Award for IT and the Internet, 2016
Liisa has published extensively in the area of privacy and data security. She is the author of two treatises: Thomas on Data Breach: A Practical Guide to Handling Worldwide Data Breach Notification (Thomson Reuters, 2018), which has been described as "a no-nonsense roadmap for in-house and external practitioners alike;" and Thomas on Big Data (Thomson Reuters, 2021), praised for being a "comprehensive and detailed analysis of the complex and rapidly changing world of privacy law." Liisa is also the editor of the firm’s eyeonprivacy.com blog, a recap of recent developments in the privacy and cyber space. A few of her more recent additional publications include:
- "Identifying and Preparing for Privacy and Cyber Security Risks," Risk & Compliance Magazine, July-Sept 2021 issue
- Co-Author, "Playing with Privacy? Privacy and Cybersecurity Considerations in Esports," esportsinsider, June 24, 2021
- "Changing the Conversation," Legal Management Magazine, June 16, 2021
"How to Take a Holistic Approach to Privacy Compliance in an Ever-Changing Legal Landscape," Global Data Review, January 14, 2021
"2020 Privacy Law Trends And How They Affect Compliance," Law360, December 22, 2020
- "3 Privacy Law Predictions For The New Year," Law360, January 1, 2020
- "4 Privacy Law Predictions for 2019," Law360, January 23, 2019
- Co-Author with A. Thomson, "From Panic to Pragmatism: De-Escalating and Managing Commercial Data Breaches," Cyber Security: A Peer Reviewed Journal, Vol. 2, No. 1, Summer 2018 issue
- "Dealing with US Biometric Laws and Litigation," Data Protection Leader, May 2018
- "USA - Behavioural Advertising," Data Guidance, May 8, 2017
- "CFPB Provides Guidance on Consumer Data Protection," Financial Regulation Journal, November 23, 2017
- Illinois Legal Aid Online, 10.07.2021
- Legal Evolution, 07.11.2021
- Bloomberg Law, 07.01.2021
- Law360, 03.27.2020
- Law360, 01.01.2019
- Law360, 01.01.2019
- Data Guidance, 06.2018
- Bloomberg Law, 05.23.2018
- Commercial Dispute Resolution, 10.11.2017
- Sheppard Mullin Adds Practice Leader to Grow Winston Lateral RosterThe American Lawyer, 09.26.2017
- Sheppard Mullin Nabs Leading Cybersecurity PartnerLaw360, 09.25.2017
- FTC Takes First EU-U.S. Privacy Shield Enforcement ActionsBloomberg Law: Privacy & Data Security, 09.08.2017
- Panelist, “Legal trends to watch: from influencer missteps to privacy pitfalls,” Ad Age Next: CMO Conference, December 1, 2021
- Speaker and faculty, “Technotainment” 2021: Distributing Content Across Multiple Platforms, Practising Law Institute, September 17, 2021
- "Technotainment" 2021: Distributing Content Across Multiple Platforms, In-person or virtual, 09.17.2021
- Virtual, 6.10.2021-6.11.2021
- Practical Insights for Turbulent Times: WSJ Risk & Compliance Forum, Virtual, 05.05.2021
- ANA Law & Public Policy Conference, In-person or virtual, 04.28.2021
- Webinar, 01.27.2021
- Virtual, 11.10.2020-11.12.2020
- Practising Law Institute Webcast, In-person or virtual, 10.15.2020-10.16.2020
- Hot Topics in Privacy and Cyber Security in Uncertain Times: A Virtual Resource for In-House Privacy TeamsWebinar, 07.15.2020
- Webinar, 04.07.2020
- Practising Law Institute, October 17-18, 2019
- IAPP Privacy. Security. Risk. 2019, 09.23.2019
- Practising Law Institute, 09.13.2019
- Association of Corporate Counsel, 06.05.2019
- May 18-22, 2019
- IAPP Data Protection Intensive: UK 2019, 03.12.2019
- Third Thursday Emerging Company Webinar Series, via GlobalMeet, 12.05.2018
- IAPP Europe Data Protection Congress, 11.27.2018
- IAPP's Privacy, Security, Risk Conference, 10.17.2018
- SIM Women’s Leadership Summit, 09.28.2018
- PLI's Advertising Law Institute, September 13-24
- ACI’s Digital Advertising Law and Compliance Conference, New York City, 06.25.2018
- New York, 06.07.2018
- Bloomberg Law Leadership Forum, New York, 05.23.2018
- University of Chicago Law School, Chicago Symphony Orchestra Club, 05.17.2018
- Interactive Data Breach Simulation, 04.25.2018
- IAPP Europe Data Protection Intensive 2018, London, 04.17.2018
- at ACI's Cyber Risk & Data Security Conference, Chicago, April 10-12, 2018
- IAPP Global Privacy Summit 2018, Washington, D.C., 03.26.2018
- Data Breach Bootcamp, SQUARE - Brussels Meeting Centre, 11.06.2017
- PLI Practising Law Institute, PLI California Center, 10.17.2017
- Data Breach Bootcamp, Renaissance San Diego, 10.2017
- Hands-On Data Breach Simulation: Understanding the Roles of Legal, Forensics/IT, and PR, George Washington University The Marvin Center, 10.04.2017
Training Advisory Board, International Association of Privacy Professionals (IAPP)
- Executive Committee of the Board of Trustees, Chicago Symphony Orchestra (CSO)
- Chair, Negaunee Music Institute Board, CSO
- Subcommittee Chair, INTA Building Bridges Committee, International Trademark Association
- Member, International Association of Privacy Professionals
- Member, Women’s Foodservice Forum
- Adjunct Professor, Northwestern University School of Law
- Member, Leading Lawyers Network
- Violinist, Chicago Bar Association Symphony Orchestra
- Privacy and Cybersecurity
- Intellectual Property
- Entertainment, Technology and Advertising
J.D., University of Chicago, 1996
B.A., Haverford College, 1993
- District of Columbia