Rohan Massey
Partner
Rohan Massey is a leader of the firm’s Data, Privacy and Cybersecurity practice and focuses his practice on data protection, data security, e-commerce, and IT. As well as advising on complex global data protection and security compliance programs, Rohan also advises on issues of risk and value in relation to data and intellectual property in corporate transactions. Rohan’s expertise focuses on the intersection of the extra-territorial scope of national data protection laws and data transfer issues for multinational organisations. Rohan has advised on a number of leading breach data management cases, and has assisted clients in successfully obtaining BCR approval from EU regulators. His industry-focused expertise covers asset management and financial services; life sciences and clinical trials; as well as media, sponsorship, advertising, sales promotions, and intellectual property issues, marketing issues in the sports apparel and food and drink sectors. His client base is international in scope, as he works extensively across Europe, the U.S. and Asia.
Rohan has recently been elected to Chair of the Sedona Conference’s 12th Annual Sedona Conference International Programme, and sits on The Sedona Conference’s WG 11. The mission of WG11 is to identify and comment on trends in data security and privacy law, in an effort to help organizations prepare for and respond to data breaches, and to assist attorneys and judicial officers in resolving questions of legal liability and damages.
Rohan is also the Secretary of the City of London Law Society Commercial Committee, and a member and active participant of the IAPP, having spoken at numerous conferences and events.
Rohan regularly writes for various industry publications. He is also a member of the editorial board of E-Commerce Law and Policy.
Articles Rohan has authored or co-authored include: “The UK’s Proposed Framework Code of Practice for Sharing Information,” World Data Protection Report; “Transfers of Clinical Research Data from the European Union to the United States,” BNA’s Medical Research Law and Policy Report; “The Growing Concerns of Identity Theft,” Electronic Business Law; “Sales Promotion in The International Sales and Marketing Practice,” Practical Law Company; “Ambush Marketing,” International Chamber of Commerce UK Handbook; “The Distance Marketing of Financial Services – A UK Overview,” Journal of Financial Services Marketing. Rohan also contributes to “Law in Action” on BBC Radio 4. World Trademark Review 1000 2016 – Recognized Rohan as being a “licensing and IP transactions cognoscente” who “manoeuvres shrewdly in the heavily regulated alcoholic beverage sector and backs up his IP know-how with expertise in ancillary areas such as privacy.”
Experience
- 3i Group plc, a leading international investment manager focused on mid-market private equity and infrastructure, and GartenHaus on the acquisition of Outdoor Toys, one of the UK’s leading online retailers of outdoor garden toys
- Integrated Media Company (IMC), a TPG platform dedicated to the new media ecosystem, on the acquisition of a majority stake in Goal from the DAZN Group
- Bain Capital on its acquisition of NGA UK, a UK payroll and HR Business from NGA Human Resources
- A UK client on the handling and reporting of a data breach relating to a customer database, which lead to the arrest of an individual charged with a criminal offence under the UK’s Data Protection Act
- A multinational client on global data privacy strategies, as well as drafting and implementing data privacy policies and procedures
- Oakley Capital on the acquisition of TechInsights, a technology patent analysis business
- Various international banks, multinationals and internet start-ups on e-commerce compliance audits and advising on website creation and disclaimers, online contracting and digital distribution as well as e-procurement, outsourcing and security issues
- On the intellectual property and technology issues arising in corporate transactions ranging from public market flotations to sale and acquisition of business
- Corporate clients on the structuring of intra-group licensing to maximise the commercial benefit from the exploitation of group-wide and subsidiary based intellectual property
- On promotion and marketing matters, including promotions and labelling, as well as trademarks, copyright, licensing and distribution issues
- Major sports teams and events in negotiating sponsorship deals
Publications
Publications- Quoted, “UK’s Move to Circumvent Encryption Has Some Lawyers Concerned,” LegalTech News (March 17, 2023)
- Co-author, "Comparative analysis of the proposed Chinese standard contract and EU standard contractual clauses," Global Data Review (December 14, 2022)
- Co-author, “Data Protection and Digital Information Bill: Key Proposals For Reform of the UK’s Data Protection Framework,” Entertainment Law Review (November 11, 2022)
- Co-author, “Cyber Trends and Investigations in Europe: A Practitioner’s Perspective,” The Guide to Cyber Investigations, second edition (2021)
- Co-author, “The GDPR and AI: Ensuring Data Protection From the Start,” Bloomberg Law (October 22, 2020)
- Author, “GDPR enforcement trends identified in EDPB's register of one-stop-shop decisions,” Global Data Review (June 29, 2020)
- Author, “European Data Protection Board updates GDPR territorial scope guidelines,” Issue of Comms Law (June 2020)
- Author, “GDPR: Navigating the Risks of Processing Special Categories of Personal Data Aided by UK's ICO Guidance,” CLTR Issues (March 2020)
- Author, “EDPB Guidelines on RTBF,” Issue 4 Ent LR (February 20, 2020)
- Author, “Planet49: CJEU Rules Out Opt-Out Consent for Cookies,” Issue 2 Ent LR Review (February 2020)
- Author, “GDPR - Navigating the risks of processing special categories of personal data aided by UK’s ICO Guidance,” Issue 3 CLTR (January 7, 2020)
- Co-author, “5 UK Privacy And Data Protection Predictions For 2019,” Law360 (February 25, 2019)
- Co-author, “Guidance Regarding Interaction Between GDPR and EU Clinical Trials Regulation Leaves Several Questions Unanswered,” Bloomberg Law (February 14, 2019)
- Author, “GDPR Consent-UK’s ICO Guidance Re-Delivers the Message that “consent is not the silver bullet for GDPR compliance,” Entertainment Law Review (November 1, 2018)
- Author, “ICO fines medical insurer £175,000 after rogue employee steals customer records to sell on the dark web,” Cyber Security Practitioner (October 2018)
- Quoted, “Morrisons faces 'vast' data leak compensation payment,“ Sky News (October 22, 2018)
- Co-author, “DCMS publishes report on IoT security, privacy and safety including draft code of practice for security in consumer IoT products and associated services,” Thomson Reuters’ Computer and Telecommunications Law Review (August 17, 2018)
- Author, “GDPR requirement to maintain a record of processing activities,” Westlaw Practitioners Insight Commentaries (May 30, 2018) republished in Westlaw Journal Computer & Internet (June 15, 2018)
- Author, “GDPR emails highlight variable advice ahead of new data regime,” Financial Times, (May 18, 2018)
- Co-author, “New Draft Guidelines on GDPR Consent Requirement’s Application to Scientific Research,” Bloomberg BNA’s Medical Law & Research Policy Report (January 17, 2018)
- Co-author, “Global Perspectives On High Court Microsoft Warrant Case,” Law360 (January 10, 2018)
- Author, “Brexit & International Data Flows: Still in Choppy Waters,” Bloomberg Law, Privacy and Security Report (January 2018)
- Author, “UK Employer Held Vicariously Liable for Rogue Employee Lawful Disclosure of Payroll Data,” CLTR (January 2018)
- Co-author, “Extraterritorial Effect of the GDPR and Implications for U.S. Academic Medical Centers Treating EU Patients,” Bloomberg BNA’s Medical Law & Research Policy Report (November 1, 2017)
- Co-author, “EU-U.S. Privacy Shield Review—Not Bad but ‘Room for Improvement,’” Bloomberg BNA’s Privacy and Security Law Report (October 25, 2017)
- Co-author, “Reconciling Personal Data Consent Practices in Clinical Trials with the EU General Data Protection Regulation,” Bloomberg BNA’s Medical Research Law & Policy Report (September 20, 2017)
- Author, “European Parliament LIBE Committee Joins Chorus of Disapproval Over Aspects of the Proposed ePrivacy Regulation,” Bloomberg BNA’s Privacy Law Watch (August 7, 2017)
- Author, “UK Data Breach Fine Provides Warning as GDPR Looms,” Law360 (August 3, 2017)
- Co-author, “Countdown to Compliance: 1 Year to Go Until GDPR Enforcement,” Law360 (May 26, 2017)
- Author, “Thoughts on EU’s Draft E-Privacy Regulation,” Law360 (April 10, 2017)
- Co-author, “How The GDPR Will Impact Life Sciences And Health Care,” Law360 (February 21, 2017)
- Co-author, “The GDPR – Possible Impact on the Life Sciences and Healthcare Sectors” Law360 (February 14, 2017)
- Author, “AG Opinion on compatibility of data retention with EU law,” Cyber Security & Law Practice (August 2016)
- Author, “Tips for U.S. Companies in the Age of the EU GDPR and Privacy Shield,” Bloomberg Law’s Privacy & Security Law Report (July 11, 2016)
- Author, “Brexit's Impact on International Data Transfers,” Bloomberg BNA Privacy & Data Security Law Report (July 11, 2016)
- Co-author, “Privacy Shield Takes a Hit, While GDPR Gets A Boost,” Ropes & Gray Alert (April 15, 2016)
- Co-author, “The EU-U.S. Privacy Shield–Challenges and Observations,” Bloomberg BNA World Data Protection Report (March 2016)
- Co-author, “Impact of the European Union’s Approved General Data Protection Regulation On Scientific Research and Secondary Uses of Personal Data,” Bloomberg BNA Medical Research Law & Policy Report (February 17, 2016)
- Author, “A Cloak of Invisibility—Agreement on the EU-U.S. Privacy Shield,” Bloomberg BNA: World Data Protection Report , Vol. 16, Number 2 (February 2016)
- Co-author, “The US-EU Safe Harbor Framework is Invalid: Now What?,” The Journal of E-Commerce, Technology and Communications (2016)
- Co-author, “The Council of the European Union’s Draft of the General Data Protection Regulation: Stakeholders’ Comments on Key Issues,” Bloomberg BNA World Data Protection Report (September 2015)
- “The European Commission’s Ambitious Strategy For Unleashing The Potential Of Cloud Computing,” Bloomberg BNA: World Data Protection Report, Vol. 12, Number 10 (October 2012)
- “What does it take to avoid costly data breach mistakes?,” The Privacy Advisor: Official Newsletter of the IAPP, Vol. 12, Number 7 (September 2012)
- “The Article 29 Working Party: Opinion on Cloud Computing,” E-Commerce Law & Policy (August 16, 2012)
- “High Court rules on threats and jurisdiction in declaration for non-infringement,” World Trademark Review Daily (May 21, 2012)
- “Crackdown on Unjustified Procedural Delays in Trademark Infringement Actions,” World Trademark Review Daily (April 26, 2012)
- “The UK ICO’s Updated Guidance On The New Cookie Regime: There’s Work To Be Done,” Bloomberg BNA: World Data Protection Report, Vol. 12, Number 1 (January 2012)
- “European Commission Finds Social Networks Can Do More To Protect The Privacy Of Minors,” Bloomberg BNA: World Data Protection Report, Vol. 11, Number 12 (December 2011)
- “Extension of Compulsory Audits to Additional Sectors Sought by ICO,” Bloomberg BNA: World Data Protection Report, Vol. 11, Number 11 (November 2011)
- “The EU Article 29 Working Party Opinion On The Definition Of Consent: An Unambiguous View Of The Future,” Bloomberg BNA: World Data Protection Report, Vol. 11, Number 8 (August 2011)
- “The UK’s Proposed Framework Code of Practice for Sharing Information,” World Data Protection Report
- “Transfers of Clinical Research Data from the European Union to the United States,” BNA’s Medical Research Law and Policy Report
- “The Growing Concerns of Identity Theft,” Electronic Business Law; “Sales Promotion in The International Sales and Marketing Practice”, Practical Law Company
- “Ambush Marketing,” International Chamber of Commerce UK Handbook
- “The Distance Marketing of Financial Services – A UK Overview,” Journal of Financial Services Marketing
Quotations
- Quoted, “New UK Data Bill Only The End of The Beginning,” Global Data Review (March 13, 2023)
- Quoted, “E.U. Regulators Bar Meta from Requiring Users to Pay with Their Data,” Cybersecurity Law Report (January 25, 2023)
- Quoted, “First CLOUD Act agreement to accelerate prosecutors’ access to data, documents,” GIR (December 7, 2022)
- Quoted, “How North Korea Became a Mastermind of Crypto Cyber Crime,” Financial Times (November 14, 2022)
- Quoted, “ICO’s call for G7 collaboration on cookie pop-ups raises questions,” Global Data Review (September 7, 2021)
- Quoted, “Data Lawyers React To Mammoth Amazon Fine, Spy Opportunities For Law Firms,” The Recorder (August 6, 2021)
- Quoted, “Linklaters posts stellar trainee retention score of 94%,” RollOnFriday (July 23, 2021)
- Quoted, “Three Years Later, GDPR Compliance Still a Challenge,” Bloomberg Law (July 21, 2021)
- Quoted, “Legal Insights of the Week,” Edward Fennell's Legal Diary (July 7, 2021)
- Quoted, “Three Years In, the GDPR Legal Landscape Remains in Flux,” Anti-Corruption Report (June 23, 2021)
- Quoted, “GDPR ‘out of date’ and needs revising, says one of its architects,” GRC World Forums (March 3, 2021)
- Quoted, “UK looks to forge own path in data protection,” Global Data Review (March 2, 2021)
- Quoted, “UK declared adequate,” Global Data Review (February 19, 2021)
- Quoted, “Facebook Belgium: door left open for GDPR enforcement jostling,” Global Data Review (January 13, 2021)
- Quoted, “ANALYSIS: Will Schrems II Cause Five Eyes to Blink?,” Bloomberg Law (November 16, 2020)
- Quoted, “The Atlantic is now an ocean for data to cross,” The Times (July 30, 2020)
- Quoted, “Schrems II: the data protection community reacts,” GDR (July 17, 2020)
- Quoted, “Is your boss spying on you as you work from home?,” BBC News (June 3, 2020)
- Quoted, “Covid-19: UK health service forced to disclose patient data,” Global Data Review (April 9, 2020)
- Quoted, “Morrisons not liable for rogue employee data breach,” Global Data Review (April 1, 2020)
- Quoted, “What's Next: Our Privacy in the Midst of Pandemic,” Law.com (March 25, 2020)
- Quoted, “How to Heed Privacy Law in the Midst of a Pandemic,” The Recorder (March 25, 2020)
- Quoted, “UK makes adequacy sales pitch,” Global Data Review (March 18, 2020)
- Quoted, “Private Equity Steps Up Cyber Diligence as Data Breach Fears Rise,” WSJ Pro Private Equity (March 7, 2020)
- Quoted, “Bank of England audio leak gave head start on briefings,” Reuters (December 19, 2019)
- Quoted, “EU Data Chief Leaves Behind Global Privacy Legacy,” Bloomberg Law (August 21, 2019)
- Quoted, “Parental Liability in the E.U.: Rebuttable Presumption of Decisive Influence and Four Misconceptions About Avoiding Liability (Part Two of Three),” The Private Equity Law Report (June 4, 2019)
- Quoted, “Parental Liability in the E.U.: 'Undertakings' and Potential Scope of Risk for PE Sponsors (Part One of Three),” The Private Equity Law Report (May 21, 2019)
- Quoted, “GDPR: One Year On,” HFMCompliance (May 2019)
- Quoted, “ICO to support GDPR certification schemes,” Computer Weekly (May 20, 2019)
- Quoted, “Google to ‘work with’ member states after Copyright Directive approval,” World Intellectual Property Review (March 27, 2019)
- Quoted, “Warnings issued over controversial copyright law in wake of European Parliament approval,” World Trademark Review (March 27, 2019)
- Quoted, “As More Countries Seek Adequacy Decisions With EU, Will US Get Left Behind?“ Corporate Counsel (also appeared in Legal Week and The Asian Lawyer) (February 26, 2019)
- Quoted, “Cyber security and privacy issues likely to prevail in 2019 highlighted by Ropes & Gray,” Risk UK (January 2, 2019)
- Quoted, “ePrivacy hits new delays,” Global Data Review (December 7, 2018)
- Quoted, “Crack down on political campaigns that use personal data, watchdog tells MPs,” The Times (November 7, 2018)
- Quoted, “UK supermarket loses appeal against data breach vicarious liability,” Global Data Review (October 22, 2018)
- Quoted, “UK government releases IOT security code of practice,” Global Data Review (October 15, 2018)
- Quoted, “UK could lose out on database rights, government warns,” Global Data Review (September 28, 2018)
- Quoted, “EU Eyes Facebook Privacy Practices, Are Other Social Media Next?” Bloomberg Law: Privacy & Data Security (September 24, 2018)
- Quoted, “Inside The Spinner: a real-life inception project,” The Financial Times (August 3, 2018)
- Quoted, “U.S. Firms Brace for GDPR Impact,” Private Equity News (May 25, 2018)
- Quoted, “Private Equity Could Pay if Companies Violate GDPR,” Private Equity News (May 21, 2018)
- Quoted, “The Morning Risk Report: GDPR Is Newest Human Resources Headache,” The Wall Street Journal (May 18, 2018)
- Quoted, “The Morning Risk Report: GDPR Is Newest Human Resources Headache,” Dow Jones (May 18, 2018)
- Quoted, “GDPR Heralds More Transparency in Managing Employee Data,” The Wall Street Journal (May 17, 2018)
- Quoted, “10 Things You Should Know Before the GDPR Deadline Is Here,” Legaltech News (May 14, 2018)
- Quoted, “As GDPR Looms, Law Firms Do Double Duty on Compliance,” The American Lawyer (May 1, 2018)
- Quoted, “New EU privacy regulations could affect US businesses,” Food Engineering Magazine (April 13, 2018)
- Quoted, “GDPR will impact US M&A,” International Financial Law Review (April 4, 2018)
- Quoted, “Non-EU firms unaware of GDPR compliance,” International Financial Law Review (March 16, 2018)
- Quoted, “How 6 Companies Were Put to Test on Personal Data,” The Financial Times (February 7, 2018)
- Quoted, “Our Editorial Board look forward to the year ahead,” Digital Business Lawyer (January 2018)
- Quoted, “How Much Will the GDPR Change Consumer Technology?,” Legaltech News (December 28, 2017)
- Quoted, “GDPR Rules Put Privacy, Anti-Bribery Enforcement on Collision Course,” WSJ Pro Cybersecurity (December 12, 2017)
- Quoted, “US funds may be caught off guard by EU data rules,” Fund Action (December 4, 2017)
- Quoted, “GDPR: It’s time for action,” HFM Week (October 24, 2017)
- Quoted, “The UK Government publishes its draft Data Protection Bill 2017,” Digital Business Lawyer (October 2017)
- Quoted, “The implications of GDPR on cybersecurity,” Private Equity Wire (July 12, 2017)
- Quoted, “Amazon's Whole Foods Deal Offers Lessons for Acquiring Data,” WSJ Pro Cybersecurity (July 10, 2017)
- Quoted, “Legal Costs, Notification Fees Inflate U.S. Data Breach Costs,” WSJ Pro Cybersecurity (June 27, 2017)
- Quoted, “Europe's data privacy rules could hit private equity,” The Deal (January 27, 2017)
- Quoted, “Uncertainty Abounds in Europe’s Data Privacy Overhaul,” The Wall Street Journal (April 25, 2016)
- Quoted, “Preparing for the EU’s New Data Protection Rule,” Compliance Week (January 26, 2016)
- Quoted, “Nutmeg customers caught in data breach,” Financial Times (November 13, 2015)
- Quoted, “Data Security Impasse Overturns Safe Harbor Program,” Compliance Week (October 6, 2015)
Presentations
- Presenter, “International Transfers in 2022 and Beyond,” Privacy & Security Forum Spring Academy (March 25, 2022)
- Panelist, “Governance,” London Stock Exchange: Issuer Services Cyber Security Masterclass, London, UK (October 24, 2018)
- Presenter, “Data Governance: Reducing Proprietary & Sensitive Data Risks,” Assent Compliance Supply Chain Summit, London, UK (September 26, 2018)
- Panelist, “International data security and privacy developments: EU, South America, APAC and Canada,” The Sedona Conference: Working Group 11 Midyear Meeting 2018, Los Angeles, CA (September 13, 2018)
- Presenter, “Networked Medical Devices and Current Security Risks,” Ropes & Gray Webinar (July 16, 2018)
- Panelist, “The Full Implementation of the EU General Data Protection Regulation (GDPR): Implementation Challenges and New Guidance,” The 10th Annual Sedona Conference International Programme on Cross-Border Data Transfers and Data Protection Laws, Budapest, Hungary (June 18, 2018)
- Panelist, “Worldwide Trends in Class Action Litigation: Leveraging Global Experience in a Locally Changing Landscape,” Ropes & Gray Privacy & Cybersecurity Summit, New York, NY (February 8, 2018)
- Speaker, “Complying With the EU GDPR Requirements in Clinical Trials,” Ropes & Gray Roundtable Discussion (December 2017)
- Panelist, “Practical considerations and impact of the proposed E-privacy Regulation,” Thomson Reuters Future of Data Protection Conference, London, UK (October 5, 2017)
- Presenter, “The Ever-Changing Privacy and Cybersecurity Landscape and its Impact on Health Care Companies,” Ropes & Gray Webinar (July 20, 2017)
- Moderator, “The Ever-Changing Privacy and Cybersecurity Landscape and its Impact on Private Equity Firms,” Ropes & Gray Roundtable (May 9-10, 2017)
- Moderator, “How to GDPR-ify Your Vendor Management Program,” IAPP Global Privacy Summit (April 20, 2017)
- Moderator, “OBA: All Cards on the Table or Is There Too Much that Cannot Stand in the Daylight?” Forum on International Privacy Law, Konigstein, Germany (March 22, 2017)
- Moderator, “Cybersecurity – the reality, the challenge and the May ’18 deadline,” Enterprise GC (March 13-14, 2017)
- Speaker, “The EU GDPR and International Dataflows – What, When, and Where Should You Be Now,” ACC-SFBA CLE Lunch Seminars (September 19-20, 2016)
- Speaker, “Cybersecurity Law (NIS) and the GDPR Together: A Perfect Regulatory Storm?,” IAPP Privacy. Security. Risk., San Jose, CA (September 15, 2016)
- Co-Presenter, “The General Data Protection Regulation (GDPR), its practical implications from the perspectives of a data controller and data processor, and what companies should be doing to prepare,” IAPP KnowledgeNet Boston (January 2016)
- Co-Presenter, “Privacy—A Brand Value and Value to the Brand,” IAPP Europe Data Protection Intensive, London, UK (April 29-May1, 2014)
- Co-Presenter, “Fraud Investigations & Navigating the European Legal Landscape,” ISMG Fraud Summit, London, UK (September 23, 2014)
- Co-Presenter, “State of the Union for Global Data Privacy Regimes,” IAPP Global Privacy Summit, Washington DC (March 2013)
- Co-Presenter, “Be Careful What You Wish For: Lessons Learned on Security Breach Response,” IAPP Europe: Data Protection Congress 2012, London, UK (November 13, 2012)
- Contributor, “Law in Action,” BBC Radio 4
Disclaimer
Ropes & Gray International LLP is a limited liability partnership registered in Delaware, United States of America and is a recognised body regulated by the Solicitors Regulation Authority (with registered number 521000).Education
- LPC (Pass), College of Law, London, 1998
- Post Graduate Diploma in Law (Pass), City University, London, 1997
- BA (Hons), University College London, 1994
Admissions / Qualifications
Qualifications
- England and Wales, Solicitor, 2000
Awards
- Cybersecurity Docket Incident Response 50 (2023)
- Legal 500 – noted as “very personable, knowledgeable and demonstrates clear expertise”
- Chambers UK – described as “a very good lawyer” who is “careful, practical, diligent and commercial,” “good at anticipating developments in the law” and "always brings great value to the discussion and has a deep knowledge of data protection laws, the markets and the legal developments”
- World Trademark Review 1000 2016-2017 – recognized as being a “licensing and IP transactions cognoscente” who “manoeuvres shrewdly in the heavily regulated alcoholic beverage sector and backs up his IP know-how with expertise in ancillary areas such as privacy”
- World Trademark Review 1000 2014 – recognized as a ‘….mastermind’ with commentators lauding Rohan’s “deep understanding of the relevant law and ability to apply it in a practical way – he speaks in plain English and is approachable and energetic”
- World Trademark Review 1000 2012 – described as being a “well-versed IP lawyer providing superb advice on difficult points” who “understands the commercial context well and knows the law extremely thoroughly”
- Legal 500 UK 2011 - recommended his focus on commercial IP, he is described as “approachable, friendly and knowledgeable”