Lisa Sotto, Law and Ethics Advisor

Lisa Sotto

Lisa J. Sotto

Partner, Hunton & Williams




Lisa Sotto is a partner in the New York City office of Hunton & Williams. She concentrates her practice on privacy and information management issues. She assists clients in identifying, evaluating and managing risks associated with privacy and information security practices of companies and third parties and conducts all phases of privacy and data protection assessments and information security audits. She further advises clients on the Gramm-Leach-Bliley Act, HIPAA, COPPA, CAN-SPAM and other U.S. state and federal privacy requirements (including HR requirements); the Canadian Personal Information Protection and Electronic Documents Act (PIPEDA); and global data protection laws (including those in the EU and Latin America). Ms. Sotto drafts and negotiates contractual agreements concerning data uses and confidentiality and develops corporate records management programmes, including policies, procedures and records retention schedules.

Ms. Sotto was appointed vice chairperson of the Department of Homeland Security's Data Privacy and Integrity Advisory Committee to advise the Secretary of the department and its Chief Privacy Officer on privacy, data integrity and data interoperability matters. In another matter, Ms. Sotto conducted a full-scale privacy assessment for a Fortune 15 consumer goods company, including preparation of data flow maps; contractual privacy, confidentiality and information security provisions; multiple data disposition documents; numerous privacy notices, policies and procedures; and employee and vendor training materials. She prepares multiple privacy policies, procedures and notices for online and offline clients in financial services, consumer goods, retail, publishing and health care industries.

Ms. Sotto is a graduate of the University of Pennsylvania Law School where she was Comment Editor of the Law Review and Cornell University. She is admitted to practice in New York and the District of Columbia.

grc community

Learn & NetworkSAI Global GRC Community

News, insights, opinions, events, and resources of value to compliance, legal, risk, ethics and audit professionals.

whitepaper

Why Training is No Longer Optional Privacy Whitepaper

Essential reading when adding privacy and data protection training as a key component of your complete risk management programme.

Webcast

Is Privacy a Legal Compliance Issue?Privacy Webcast

Lisa Sotto and Larry Ponemon discuss and debate the latest trends in privacy and data protection and how to encourage employee awareness.

an integrated risk management solution

Gain a single view of risks, obligations & controlsRisk Management Solution

Create the compliance reports your Board demands with an integrated software solution.

free trial online privacy database

Privacy KnowledgebasePrivacy Database Free trial

Our online searchable Privacy database includes 70 country profiles and industry sector guidance for the US, UK and Australia.