About Fred Bingham

Fred Bingham counsels companies on privacy compliance and data governance, artificial intelligence (AI) strategy and governance, cybersecurity, technology transactions and related regulatory, enforcement and litigation matters. He advises clients across the technology, media and entertainment, video games, financial services, healthcare, retail and e-commerce, hospitality, transportation and automotive, insurance, real estate and private equity sectors. Drawing on his experience in both private practice and executive in-house roles, Fred translates complex legal and technical requirements into practical guidance for legal, product, technology, security, marketing, human resources and business teams.

In-house, technical and litigation perspective

Before returning to private practice, Fred served as Vice President, Technology and Privacy Counsel at Skydance Media, where he advised legal, business, product, technology and security teams on privacy, AI, cybersecurity, data governance and technology transactions.

That in-house experience complements Fred's technical background. He is a Certified Information Systems Security Professional (CISSP) and Certified Cloud Security Professional (CCSP) through the International Information System Security Certification Consortium (ISC2), and holds the CIPP/US, CIPP/E, CIPP/C, CIPP/A, CIPM, CIPT and AIGP certifications from the International Association of Privacy Professionals (IAPP). He also previously volunteered with the IAPP as an exam item writer, helping develop examination materials for IAPP certification programs.

Fred also brings a substantial disputes perspective to his counseling practice. Earlier in his career, he served as a judicial law clerk to the now-retired Hon. Peter C. Lewis in the US District Court for the Southern District of California. Additionally, Fred’s litigation and arbitration experience informs his approach to compliance, investigations, documentation, risk mitigation and dispute strategy.
 

Practice Focus

  • Global privacy, marketing, technology and AI counseling
  • Technology transactions, including data processing agreements, intercompany data governance and sharing agreements, vendor agreements, API and developer terms, EULAs, website terms of service and other technology agreements
  • Commercial and product counseling on AI, privacy, marketing and technology regulations
  • Compliance program development across emerging technologies
  • Platform and digital service regulations, content moderation and online safety counseling, including the Children’s Online Privacy Protection Act (COPPA), Digital Services Act (DSA) and Online Safety Act (OSA)
  • Regulatory investigations and litigation related to privacy, AI, cybersecurity and marketing, including claims brought by state and federal regulators, EU/UK regulators and private litigants under California’s Invasion of Privacy Act (CIPA), the Video Privacy Protection Act (VPPA), wiretapping statutes, the Telephone Consumer Protection Act (TCPA), the Electronic Communications Privacy Act (ECPA) and other regulations
  • Cyber incident response planning, tabletops and breach coaching
  • Proactive cybersecurity counseling, including written information security (WISP) policy development and compliance with US and global security laws, such as the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), GLBA Safeguards Rule and NYDFS Cybersecurity Regulation 
  • Comprehensive state privacy laws, including the CCPA/CPRA, CPA, UCPA, CTDPA  and VCDPA 
  • Data broker laws, including the California Delete Act, Nevada SB-260 and similar laws in other states, including Texas, Oregon, Vermont, Connecticut and New Jersey
  • Global privacy regimes, including the GDPR and UK GDPR, Canada’s PIPEDA and Quebec Law 25, Brazil’s LGPD, Australia’s Privacy Act, India’s Digital Personal Data Protection Act and Switzerland’s Federal Act on Data Protection
  • Marketing laws, including the TCPA, CAN-SPAM Act, ePrivacy Directive, and related US and EEA requirements
  • Consumer health data laws, such as the Washington My Health My Data Act and Nevada SB-370 
  • The Health Information Portability and Accountability Act (HIPAA) Security and Privacy Rules, and related implementing regulations
  • Biometric privacy laws, including FERPA, BIPA and CUBI 
  • Section 5 of the Federal Trade Commission (FTC) Act, and related state unfair or deceptive practices laws
  • Consumer financial data protection laws, including the Gramm-Leach-Bliley Act (GLBA) and the Fair Credit Reporting Act (FCRA) 
  • The US Department of Justice’s Bulk Sensitive Data Rule under Executive Order 14117
  • Cross-border transfer requirements and frameworks, including Schrems II, Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework
  • Global AI regulations, including the EU AI Act, Colorado AI Act, California Generative AI laws (AB 2013, SB 942, AB 3030), Connecticut SB 5 and Utah AI Policy Act

Representative Experience

  • Counseled companies on enterprise AI governance, including agentic AI, automated decision-making, AI asset inventories, risk assessments, policies, model and vendor diligence, human oversight, training and contractual allocation of AI risk. *
  • Designed and operationalized US and global privacy and data-governance programs under comprehensive state, federal and international privacy, marketing, consumer-health, youth, biometric and sector-specific requirements. *
  • Regularly counseled employers on employee and applicant privacy notices, employee handbooks, workplace privacy, cybersecurity and AI policies, workforce monitoring, employee data use, vendor access and governance for HR systems and workplace technologies. *
  • Advised on AdTech, cookies, pixels, analytics, session-replay technologies, consent-management platforms, targeted advertising, marketing compliance, and related regulatory and litigation risk. *
  • Advised hospitality companies, including a major hotel and casino, on global privacy, cybersecurity and data-governance programs, website AdTech, vendor management and related compliance issues. *
  • Advised transportation and vehicle companies on privacy, cybersecurity and data-governance requirements involving telematics, connected-vehicle and tracking technologies, AI, and other data-intensive products and services. *
  • Counseled critical-infrastructure organizations on cybersecurity preparedness and federal cyber incident-reporting requirements, including CIRCIA applicability and reporting preparedness. *
  • Managed cyber incident response for clients in the United States and Europe from detection and notification through post-incident planning, tabletop exercises and development of policies and procedures to remediate and mitigate risk. *
  • Structured cross-border transfer and data-governance programs and advised on Standard Contractual Clauses, the EU-US Data Privacy Framework, localization, intercompany data sharing and other international transfer requirements. *
  • Negotiated DPAs, SaaS and cloud agreements, data-licensing and data-sharing arrangements, vendor and technology agreements, and privacy, security, AI and data-use terms for customers and service providers. *
  • Advised on privacy, cybersecurity, AI and data-governance issues in buy- and sell-side M&A matters, including diligence, risk allocation, remediation, disclosure schedules and post-closing integration. *
  • Served as Vice President, Technology and Privacy Counsel at Skydance Media, counseling legal and business stakeholders on privacy, AI, cybersecurity, data governance and technology matters. *
  • Advised healthcare and other regulated organizations on cybersecurity and privacy compliance, including HIPAA Security Rule risk assessments, privacy and security policies, breach notification and remediation. *
  • Advised clients in California Privacy Protection Agency, state attorney general, HHS Office for Civil Rights and other regulatory inquiries and investigations, including factual development, written submissions, engagement with enforcement personnel and compliance remediation. *
  • Advised on privacy and consumer-protection disputes involving CIPA and other wiretapping laws, the VPPA, online tracking, advertising technologies and session replay, including individual and class claims and mass-arbitration risk. *
  • Defended TCPA and FCRA class actions, including motion-to-dismiss practice, initial disclosures and settlement. *
  • Handled significant commercial, privacy and intellectual-property litigation, including dispositive motions, motions in limine, post-trial and discovery motions, fact and expert depositions, jury trial work, first- and second-chair arbitrations and appellate briefing in the Ninth Circuit and California Courts of Appeal. *
* Experience prior to Katten