Amber Thomson is a partner in Mayer Brown’s Cybersecurity and Privacy practice. She advises clients across industries on operationalizing privacy and cybersecurity compliance. She has deep experience helping organizations build scalable DSAR response programs, navigate complex data mapping challenges, and manage high-risk or sensitive requests.
Patrick focuses exclusively on cybersecurity and data privacy issues. His clients span industries such as banking, healthcare, manufacturing, high-tech, and energy. Patrick helps clients navigate complex and novel regulatory compliance issues associated with the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), Virginia Consumer Data Protection Act (VCDPA), Health Insurance Portability and Accountability Act (HIPAA), Freedom of Information Act (FOIA), and other information technology laws and frameworks.
Session I – Understanding Personal Data Rights Under U.S. Consumer Data Privacy Laws – Patrick J. Austin
During the session, Mr. Austin will address best practices for reviewing and processing data subject requests (including examples of common data subject requests). He will discuss applicable legal and regulatory framework governing data subject requests, such as the EU's General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA). He will also discuss potential penalties for failing to timely process data subject requests (along with applicable enforcement authorities). In addition, he is going to share tips and recommendations that organizations could use to develop data subject policies and protocols.
Key topics to be discussed:
Session II – Operationalizing DSAR Compliance: Real-World Scenarios, Risk Management, and Internal Readiness – Amber Thomson
This session will offer a practical, operations-focused look at Data Subject Access Requests (DSARs), going beyond the legal requirements to explore how organizations can assess, manage, and streamline their response processes. Attendees will examine real-world scenarios, common pitfalls that lead to enforcement, and internal strategies for mapping data, assigning responsibilities, and handling sensitive or high-risk requests. The session also covers how to build effective DSAR protocols and response workflows that align with organizational risk tolerance and compliance goals.
Key topics to be discussed:
This course is co-sponsored with myLawCLE.
Date / Time: September 30, 2025
Closed-captioning available
Amber Thomson | Mayer Brown
Amber Thomson is a partner in Mayer Brown’s Cybersecurity and Privacy practice. She advises clients across industries on operationalizing privacy and cybersecurity compliance. She has deep experience helping organizations build scalable DSAR response programs, navigate complex data mapping challenges, and manage high-risk or sensitive requests. Amber also helps clients with privacy and data security due diligence and facilitates executive and board training on incident response, privacy legal compliance, and the US cybersecurity and privacy law landscape. She is a Certified AI Governance Professional (AIGP) through the IAPP and the Treasurer for the National Bar Association’s Privacy, Cybersecurity and Technology Section.
Patrick J. Austin | Woods Rogers Vandeventer Black PLC
Patrick focuses exclusively on cybersecurity and data privacy issues. His clients span industries such as banking, healthcare, manufacturing, high-tech, and energy. Patrick helps clients navigate complex and novel regulatory compliance issues associated with the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), Virginia Consumer Data Protection Act (VCDPA), Health Insurance Portability and Accountability Act (HIPAA), Freedom of Information Act (FOIA), and other information technology laws and frameworks.
Patrick’s credentials in the field of cybersecurity and data privacy law are extensive. He is a Certified Information Privacy Professional in both U.S. and European law (CIPP/US & CIPP/E) by International Association of Privacy Professionals (IAPP), which is accredited by the American Bar Association. Most recently, Patrick was designated as a Fellow of Information Privacy (FIP) and a Privacy Law Specialist (PLS) by the IAPP.
Patrick received his undergraduate degree from Old Dominion University and his law degree from George Mason University School of Law where he served as Editor-in-Chief of the National Security Law Journal.
Session I – Understanding Personal Data Rights Under U.S. Consumer Data Privacy Laws | 1:00pm – 2:00pm
Break | 2:00pm – 2:10pm
Session II – Operationalizing DSAR Compliance: Real-World Scenarios, Risk Management, and Internal Readiness | 2:10pm – 3:10pm