Bradley
Blogs Our Story Careers Locations
Insights & Events Services People

Sinan Pismisoglu

Senior Attorney
spismisoglu@bradley.com
Houston P: 713.576.0317 F: 713.576.0301
Washington, D.C. P: 202.393.7150 F: 202.347.1684
Download V-Card
|
Print My Bio
  • Biography
  • Experience
  • Insights & Events
  • Blogs
Blogs
  • Cybersecurity Awareness Month Spotlight: The 5 Most Essential Reads from Online & On Point
    10/21/2024
    Online and On Point
  • Ransomware Reckoning – The New Bill Changes the Game
    8/29/2024
    Online and On Point
  • Can Privacy Be Bought? How Scrutiny of Meta’s Subscription Model Has Wider Implications –PART II
    7/29/2024
    Online and On Point
Area(s) of Focus
  • Cybersecurity & Privacy
  • International Arbitration - Construction
  • International Arbitration, Construction Contract Negotiation, Administration, Dispute Avoidance, & Resolution
  • Energy
  • Cybersecurity & Privacy ‒ Energy
  • Artificial Intelligence (AI)
  • Banking & Financial Services
  • Financial Crime & Economic Sanctions
  • International Arbitration
  • International Arbitration - Investor-State Dispute Resolution
  • Defense & National Security
  • University of Houston Law Center, LL.M., International Law, 2010
  • University of Warwick, LL.M., Economic Law, 2000
  • Ankara University, Faculty of Law, 1998
  • District of Columbia
  • Texas

ANSI Certified Information Privacy Professional (CIPP/US)

IAPP Certified Information Privacy Professional (CIPP/E)

IAPP Certified Information Privacy Technologist (CIPT)

IAPP Certified Information Privacy Manager (CIPM)

ISACA, Cyber Fundamentals

Harvard Certification, Managing Risk in the Information Age

Accolades

CIPP

Certified Information Privacy Professional/Europe

CIPT

Certified Information Privacy Manager Logo

Performed Privacy Impact Assessments and Data Protection Impact Assessments under GDPR to implement network and endpoint-based log monitoring controls that process employee data. Developed and implemented privacy and data security management programs under GDPR, HIPAA, FTC Act, and state privacy laws. Developed information security management and data privacy programs under the ISO 27000, ISO 27017, and ISO 27701 frameworks. Acted as product counsel for implementing privacy controls and social media integration policies on IoT software and apps (PbD) processing consumer health and geolocation data. Acted as product counsel for an online travel agency to implement privacy controls for the secondary use and analysis of de-identified consumer data. Drafted and negotiated data ownership, aggregation, and secondary usage terms in SaaS agreements. Advised on privacy breaches resulting from incorrect privacy settings for the AWS S3 bucket. Created and performed data privacy and data security training programs. Drafted and negotiated DPAs under GDPR, CCPA, and CPRA for controllers, processors, and service providers. Acted as project counsel to perform an information security risk assessment under the NIST Risk Management Framework. Advised global businesses on cross-border data transfers, data sovereignty, localization, and government surveillance. Advised on deidentification of non-public PII shared with product teams: hash & salt of user ID; abstracting geo location; converting device ID to product name; partition and encryption of event fields; and partition of databases together with access controls. Applied privacy requirements to app development models and app interfaces based on security, information type, and provenance requirements under data utility, risk appetite, acceptable risk, control cost, and privacy risk considerations. Represented a global energy company as its incident response counsel. Performed cybersecurity maturity and insider threat assessment. Provided counsel to a U.S. manufacturing company victimized by a business email compromise. Worked with forensic teams to discover the breach’s root cause. Represented a global hotel chain against its vendor that suffered from a breach exposing customers' credit card and PII at over 32,000 hotels across 120 countries. Counseled a nationwide retailer on the breach of consumer PII caused by the injection of keylogger malware. Advised a foreign financial institution in responding to the Equifax data breach for customer communications, contractual obligations, regulatory notifications, and indemnification claims. Designed and played APT ransomware simulation tabletops for a Fortune 500 client. Performed vulnerability assessments; implemented vertically and horizontally interacting multi-regional incident response teams operating on segmented communications platforms. Provided training based on a retail network attack simulation tabletop for a U.S.-based client to assess its compliance with PCI DSS, FTC, and CFPB regulatory framework. Simulated a supply-chain attack for a U.S.-based industrial manufacturer based on Shadowpad and Kingslayer cyberattacks targeting cyber espionage on protected intellectual property. Developed an APT-attack monitoring policy for a U.S.-based client built on indicators of threat analysis. Developed a simplified but comprehensive incident response plan based on various attack vectors. Provided counsel for pen-testing on a U.S.-based smart grid for compliance with the Homeland Security Guidelines on critical infrastructure. Created a risk analysis report for a U.S.-based energy company assessing its zero-trust vulnerabilities. Recommended tailored SIEM technologies based on threat intelligence and geopolitical threat vectors analysis.
Search by Last Name
  1. a
  2. b
  3. c
  4. d
  5. e
  6. f
  7. g
  8. h
  9. i
  10. j
  11. k
  12. l
  13. m
  14. n
  15. o
  16. p
  17. q
  18. r
  19. s
  20. t
  21. u
  22. v
  23. w
  24. x
  25. y
  26. z
Insights & Events
  • Awards & Recognitions
  • Authored Articles
  • Events
  • Firm Alerts
  • Insights
  • Media Mentions
  • Press Releases
Careers
  • Careers
  • Law Students
  • Lateral Lawyers
  • Professional Staff
Offices
  • Atlanta
  • Birmingham
  • Charlotte
  • Chattanooga
  • Dallas
  • Houston
  • Huntsville
  • Jackson
  • Knoxville
  • Montgomery
  • Nashville
  • Tampa
  • Washington, D.C.
Our Story
  • Overview
  • Services
  • Diversity
  • Women's Initiative
  • Pro Bono
  • Community Impact
  • Accolades
Our Blogs
  • Budding Trends
  • BuildSmart
  • Business Divorce
  • Eye on Enforcement
  • Financial Services Perspectives
  • IP IQ
  • It Pays to Be Covered
  • Labor & Employment Insights
  • Online and On Point

Learn about the latest news, announcements and upcoming events on the topics that are important to you and your business.

Subscribe to Mailing Lists
  • CLIENT EXTRANET
  • CONTACT
  • LEGAL DISCLAIMER
  • CCPA/CPRA & VCDPA Notice of Collection, Disclosure, & Privacy Policy
  • Accessibility Statement
  • REMOTE ACCESS
  • ALUMNI
  • World Services Group
  • ATTORNEY ADVERTISING
  • ©2025 BRADLEY ARANT BOULT CUMMINGS LLP