Data, Privacy and Cyber

We can help you harness the power of the data you hold whilst ensuring that you are acting in accordance with legal and regulatory requirements, as well as maintaining customer, employee and public trust. We also support when things go wrong and an urgent response is needed to a cyber-incident, regulator enquiry or privacy claim.

Overview

We can support you with queries of all sizes and complexities, ranging from your everyday needs to strategic advice and complex projects and from one-off misdirected emails to complex ransomware incidents.

Our team is recognised for its practical, pragmatic approach. We pride ourselves on our ability to digest complex issues of law and regulation into accessible, commercial advice, enabling our clients to maximise their use of data and respond to challenges whilst managing complex risks.

We regularly initiate protective legal proceedings for clients, including injunctive relief. Successful proceedings include persons unknown proceedings following cyber-attacks and applications against rogue individuals. We also have extensive expertise and experience in defending individual and mass privacy claims.

Many of our clients are part of a global group. We are able to draw upon expertise across our international offices and network of trusted partners to provide a solution for handling significant projects, or responding to global incidents.

We advise clients across all sectors but have particular expertise in advising clients in financial services (includes insurance); health and social care; real estate; and technology. This sector expertise means that our lawyers are able to advise specifically in the context of industries which have their own, unique challenges.

As well as providing bespoke solutions to our client's needs, we have specific, fully outsourced offerings which includes data protection healthchecks, handling of data subject access requests, corporate due diligence and data breach response planning. We also provide cyber insurance incident response services.

Featured experience

  • Advising a global health tech company using AI to improve patient health outcomes on their entry into the UK market and establishment of a worldwide performance benchmarking programme.
  • Leading a series of complex data protection impact assessments for an insurer relating to the use of personal data for pricing, claims handling and fraud detection.
  • Advising clients facing regulatory action, with successful appeals against regulatory sanctions.
  • Acting in cyber and privacy litigation, including persons unknown injunctions (Ince Group, Pendragon, Armstrong Watson), injunctive proceedings against known persons (Notting Hill Genesis) and some of the leading defensive privacy cases (e.g. Johnson v Eastlight [2021]).
  • Advising an investment bank on complex employee privacy matters and providing a fully outsourced end to end subject access request service.
  • Advising on the use of facial recognition technology.
  • Strategic advice regarding the use of footfall analytics technology.
  • Advising a data science accreditation provider on its data protection strategy including for data transfers post Schrems II.
  • Advising a leading chain of private fitness and leisure clubs in relation to data protection considerations arising out of the launch of a member app.
  • Supporting an international fintech supplier in relation to various data protection issues, including overseas transfers, liability for data protection breaches and obtaining consent for direct marketing contents.

Our sector expertise

Our data, privacy and cyber experts work across a range of sectors.

Overview

We stand out for our skill and expertise in working with organisations across the health and social care sector, whether public or private health providers, government, or MedTech operators.

We understand the critical nature of patient/service user, employee, and public trust and provide expert advice on all areas of information governance, from day-to-day compliance queries to major regional and international strategic projects.

In addition to advising on complex information-sharing frameworks, politically sensitive data breach claims, and enforcement action, our expertise extends to advising on health sector-specific issues such as confidentiality, freedom of information, and access to health record requests.

Key contact

Overview

We support a wide range of insurance sector clients including (re)insurers, brokers, MGAs and industry bodies, including the Association of British Insurers.  

Our vast industry knowledge allows us to provide a comprehensive range of services including strategic , privacy impact assessments and audits, resolving contractual issues and supporting new initiatives such as underwriting powered by AI, automated claims settlements, and partnerships with InsurTechs. 

We offer an end-to-end solution for our clients' needs, drawing on the experience and expertise of our regulatory, IT, and insurance distribution colleagues where required. 

Key contacts

Overview

Our extensive expertise in the technology sector allows us to support a wide range of clients, from growing start-ups to leading global technology organisations.  

Our strong links with the ICO result in us closely following developments in law and guidance, so we are well-positioned to advise on the evolving regulatory landscape as it affects our clients. 

We regularly advise clients on data protection issues commonly arising in the context of technology projects. This includes the use of wearables, IoT, data analytics, Blockchain and other DLTs, augmented/virtual reality, cloud hosting, overseas transfers, use of sub-processors, data processing clauses, data sharing agreements, risk assessments, and managing contractual liability for data protection breaches. Our also regularly advises technology sector clients following security breaches such as ransomware attacks. 

Key contacts

Overview

Our financial services clients range from large financial institutions to FinTech companies and asset managers, so we have experience with all companies regardless of their shape or size. 

We understand that data protection is a key priority in the financial services sector, and our expert team can guide you through all aspects of data, privacy and cyber matters from international data transfers to managing the impact of data breaches if they occur. 

We provide a comprehensive range of advisory services, from managing contractual issues to advising clients in the sector on the ever evolving artificial intelligence. In addition to our advisory services, we offer cyber defence and response services, including training, helplines, response teams, and associated litigation. 

Key contacts

  • Abstract pattern of smooth white wavy lines forming a repetitive surface design.

    DAC Beachcroft has superb industry insight combined with practical, clear advice. Their deliverables are very high quality.

    Chambers & Partners UK, 2026

  • Abstract composition of layered, curved white shapes.

    DAC Beachcroft are knowledgeable, responsive and very professional. Their guidance is detailed, clear and contains practical insights.

    Chambers & Partners UK, 2026

Data, Privacy & Cyber key contacts

Who we are

Why choose DAC Beachcroft?

We’re a broad-based commercial firm serving a wide range of sectors with a strong heritage in insurance,
health and real estate. We combine excellent legal skills and cutting-edge delivery expertise to design
solutions that fit the needs of our clients – often involving clever uses of technology.