“[Andreas’] knowledge of the law is outstanding.”
— Chambers USA 2024
Andreas Kaltsounis has been recognized as a BTI Client Service All-Star and by Chambers USA and Legal 500 for his work in privacy and cybersecurity. Clients appreciate his practical advice, “outstanding” knowledge of the law and ability to anticipate issues, thanks to his 25+ years of legal and technical experience as an attorney, an information security and privacy professional, a leader at an international information security consultancy and a federal agent investigating criminal, regulatory and national security cyber matters.
Andreas works with clients in three keys areas. First, as a strategic advisor, he helps clients anticipate, understand and comply with the rapidly evolving patchwork of global privacy, cybersecurity and data protection laws. He provides comprehensive advice on the California Consumer Privacy Act and other general state privacy laws, consumer health data laws such as the Washington My Health My Data Act, state and federal cybersecurity laws (including how to achieve “reasonable security”) and global data protection laws such as the EU’s GDPR. Focused on more than merely checking regulatory boxes, Andreas works with his clients to identify and operationalize practical solutions to comply with these laws that address risk while supporting an organization's growth.
Second, drawing on his technical and law enforcement background and experience advising clients through some of the largest publicly reported data breaches and privacy incidents, Andreas is a go-to advisor on complex security and privacy incidents, such as those involving widespread network intrusions and technically complex issues.
Third, Andreas defends clients in privacy and cybersecurity regulatory inquiries brought by the FTC, global supervisory authorities and state attorneys general and privacy regulators, including the California Privacy Protection Agency. Andreas also partners with BakerHostetler’s award-winning litigation team to defend against consumer class actions and shareholder actions.
Andreas speaks frequently to industry groups and boards of directors on privacy, data protection and incident response, and combines his extensive on-the-ground experience with leading industry credentials in privacy (FIP, CIPP/US/E, CIPM), information security (CISSP), critical controls auditing and implementation (GCCC), penetration testing (GPEN) and computer forensics (EnCE and SCERS).
Andreas co-leads BakerHostetler’s national Digital Risk Advisory and Cybersecurity team, is a member of the Privacy Governance and Technology Transactions team and serves as the Seattle office's Digital Assets and Data Management Leader.
