- Other Information
Kitty is one of East Anglia’s leading data protection experts. She advises on all aspects of data protection compliance including undertaking compliance audits and gap analysis, designing compliance programs, negotiating and drafting policies and contracts, managing international data transfers and providing advice and emergency support for subject access requests and data breaches. She also advises on compliance with the PECR regime including in relation to cookie usage and the use of data for marketing purposes. Kitty regularly advises clients on the development of compliant marketing strategies. Kitty is particularly recognised for delivering high quality data protection training solutions and regularly presents at conferences.
Kitty works with a wide range of clients from small start-ups to global groups across all industries and sectors, including charity, technology, public sector, education and healthcare. She regularly works with in-house legal teams, often acting as a valued sounding board and “critical friend” for complex data projects.
Recent examples of Kitty’s work include:
- Advising an international manufacturing group on measures required to enable GDPR-compliant data transfers between group entities across the UK, EEA, USA and Asia following the Schrems II decision.
- Preparing guidance for clients within the insurance sector on the steps required to update their data protection compliance programs as a result of Brexit, including in relation to updating of BCRs, identification of new lead Supervisory Authorities and appointment of EU and UK Representatives.
- Working with an independent school to deliver data protection training, update data protection provisions in the parent contract, draft data protection policies, manage the use of student images, implement a compliant communications policy for alumni and to provide support on complex subject access requests relating to student applications, determination of exam results during the Covid-19 pandemic and pastoral issues.
- Advising a national facilities management company in relation to the management of a data breach and the subsequent handling of compensation claims received from affected data subjects.
- Working with a charity to develop a PECR compliant marketing strategy.
- Assisting the DPO of a clinical trial sponsor to prepare appropriate privacy notices and negotiate data processing agreements with trial sites in multiple jurisdictions.
Kitty is based in our Norwich office.
Kitty has a background in general commercial law with a strong emphasis on IP and IT, which gives her an in-depth understanding of the wider legal and operational issues affecting the use of data and data-driven transactions. She always seeks to identify and implement focused, pragmatic and effective solutions for her clients.
Kitty is recommended and named as a ‘Rising Star’ by Legal 500 [UK 2022]. In an earlier edition sources say that Kitty is “particularly good and easy to work with, she gives clear explanations”.
Working with Kitty Rosser has been an absolute pleasure. The project we worked on was very complex and outside of our skillsets and experience, but Kitty made it a breeze!
Legal 500 [UK 2021]