Nicholas de Lacy-Brown

Legal Director (data, cyber and digital regulation) at DLA Piper

London, England, United Kingdom

About

Legal Director specialising in data privacy, cyber and AI governance and digital regulation, with deep expertise across GDPR/UK GDPR, cyber and digital regulation, and the EU Digital Decade legislative programme including NIS2, Cyber Resilience Act and EU AI Act. I provide high quality legal support in complex IT and general commercial transactions, negotiations and projects, with a particular focus on the technology and life sciences sectors. I have particular experience advising clients in life sciences, pharmaceutical, technology and public sector environments, including advising on the processing of health and sensitive personal data within regulated industries. I am an advanced specialist in the second EU Network and Information Security (NIS2) Directive and associated EU Digital Decade laws, leading a dynamic practice helping global organisations to navigate complex regulatory requirements pragmatically and cost-effectively. My career spans senior in-house and private practice roles. As DPO at HMRC, I led enterprise-wide data protection strategy and culture transformation across a 65,000-person organisation, building and leading a 50-person data privacy function. I now practise at DLA Piper, advising multinational clients on complex data privacy, governance and cyber regulatory matters across European jurisdictions. I have a proven track record of advising C-suite stakeholders and senior governance boards, leading engagement with data protection authorities including the ICO, and coordinating multi-jurisdictional compliance programmes across the EU/EEA. I believe my role as an effective lawyer is to get under the skin of the objectives of my client, to develop strong client relationships first and foremost and to use those as the springboard for pragmatic, targeted and clear advice which considers the bigger picture of benefit and risk. I bring great commitment, integrity and enthusiasm to any role, as well as the aptitude to operate effectively in a leading, strategic role, or as part of a collaborative team environment. I am an experienced advocate, able to communicate with confidence and conviction, and to operate effectively and with ease in diverse social and professional situations. I enjoy management and mentoring and believe passionately in the development of myself and others as the route to ultimate job satisfaction.

Experience

  • DLA Piper (Full-time · 4 yrs 4 mos)
    • Legal Director - Tech & Sourcing and Data, Privacy and Cyber teams (IPT)
      Jul 2024 - Present · 2 yrs

    • Senior Associate - Tech & Sourcing (IPT)
      Mar 2022 - Jun 2024 · 2 yrs 4 mos

      Specialising in data protection, cyber and AI regulation and governance including across the data, digital and cyber laws which form part of the EU Digital Decade strategy. Expert in complex technology outsourcing transactions including all aspects of commercial contract negotiation and drafting. My practice includes a strong life sciences focus, helping clients in the pharmaceuticals, clinical research and medical device manufacturers to understand and act on their enhanced compliance burden under data and digital regulation. I also have a public sector and charities focus, helping UK Government to navigate the requirements of public procurement law to design, procure and manage end-to-end technology solutions which are crucial to the delivery of national critical infrastructure.

  • HM Revenue & Customs (5 yrs 1 mo)
    • Data Protection Officer
      Jul 2020 - Mar 2022 · 1 yr 9 mos

      Safeguarding the personal data of millions of tax payers and thousands of departmental staff in one of HM Government's most data rich departments. Ensuring that a culture of personal data protection permeates every area of HMRC's work through influencing transformation and compliance programmes, leading on awareness and communications campaigns, building key stakeholder relationships and undertaking assurance exercises. The role entailed management of a large supporting staff, membership of various boards and governance bodies, and supervision of associated GDPR risk remediation projects. Advising and presenting to senior executive governance boards, providing strategic data protection counsel to departmental leadership.

    • Senior Technology and Privacy Lawyer
      Jun 2018 - Jul 2020 · 2 yrs 2 mos

      Senior commercial advisory lawyer working largely in the field of digital and technology, specialising in high value commercial transactions and leading on significant projects steering the implementation of new laws and procuring dynamic digital services for HMRC. Advising on technology outsourcing including cloud and digital transformation services and public procurement regulations, together with complex contract drafting and associated negotiations. Specialisation in data protection law/ GDPR, including advising on complex data sharing agreements, data incident response, data offshoring and associated third party/ cyber security risks. Providing strategic risk-based advice on numerous aspects of public and administrative law including procurement and judicial review challenges, human rights and state aid, as well as complex commercial and information law issues relating to Brexit. Project lead for the drafting and maintenance of HMRC's suite of model IT contracts as well as accompanying collaboration provisions. Lead lawyer for HMRC's most valuable business-critical IT contract, entailing complex business-as-usual advice as well as support on major extension renegotiations and accompanying contract drafting. Delivery and creation of a number of commercial training packages including presentations on the implementation of GDPR, the implications for contract managers one year after GDPR implementation, procurement timelines, negotiation skills and liability clauses. Significant contributor to the corporate operation of HMRC's wider legal office, including work on personnel induction and retention, as well as branding strategies and recruitment campaigns.

    • Commercial Technology Lawyer
      Mar 2017 - Jun 2018 · 1 yr 4 mos

      Lawyer in a high profile advisory team assisting HM Revenue and Customs in renegotiating the largest IT contract in Government as part of the biggest IT transformation programme in Europe as well as providing additional legal support for the vast HMRC IT estate. General legal contributions and advice across HMRC's key business channels with a particular focus on public law issues, public procurement law, contract negotiations and drafting, contract interpretation and project management. Leading role in assisting HMRC to implement GDPR drafting across multiple business-critical contracts.

  • Director of Marketing, Art and Communications at Grupo Cappuccino
    Nov 2014 - Jan 2017 · 2 yrs 3 mos

    Lead executive role in large Spanish hospitality company comprising 23 restaurants in Spain and the Middle East, effectively managing the presence, advancement and publicity of 4 distinct restaurant brands. Active role steering company direction and future expansion objectives, including the 2017 opening of the Group’s first luxury hotel, as well as ensuring cross-company commitment to the realisation of its marketing strategy in line with the principles of the marketing mix. Management of a team of marketing professionals as well as coordinating relationships with external communication agencies and digital programmers/ Google positioning experts. Design and implementation of significant transnational publicity campaigns, brand enhancement strategies (Cappuccino magazine, Cappuccino music, Cappuccino radio station, publication of Cappuccino book), social media strategies and all aspects of CRM engagement and response. Editor and content writer for 4 issues of Cappuccino’s magazine, and responsibility for advertiser negotiations. Management of all partner and stakeholder relationships including international marketing relationships and corporate-level partnerships (Air Europa, Melia Hotel Group). Overarching responsibility for restaurant design and art installations. Coordination of large events, public relations actions, press management and control, planning and accountability of marketing department budget. Work conducted in English and Spanish.

  • Tax advisory lawyer and NMW compliance lead at HM Revenue & Customs
    Apr 2012 - Oct 2014 · 2 yrs 7 mos

    Advisory Lawyer and In-house Counsel for the British Government specialising in the law of personal taxation, National Insurance Contributions and charities. Advising in a fast-paced, politically-charged and dynamic legal environment, identifying risk areas (Human Rights and EU laws, competition law, public law conflicts) and helping the Government to present fiscal policy in a positive and politically sensitive light. Creation of secondary legislation as well as drafting and advisory work on the annual Finance Bill (resulting from the annual Budget). Lead Lawyer for National Minimum Wage policy and enforcement which included the control of litigation on legislative interpretation and implementation, as well as management of four paralegal assistants. Additional corporate role designing and implementing through effective internal communications a wholesale restructuring of the Department’s Induction and training procedures in an office of 600 people. Leading role coordinating HMRC’s extensive annual learning programme, designing digital and printed publicity, instigating and managing a new “Legal Learning” brand and organising and presenting talks and learning events.

  • Pupil Barrister at Crown Office Chambers
    Oct 2008 - Aug 2011 · 2 yrs 11 mos

    Pupillage spread over three years owing to orthopaedic difficulties with my leg. Gained comprehensive experience of personal injury and medical negligence fields, as well as commercial litigation, common law disputes, insurance and reinsurance.