OUR LAWYERS

Wayne Cleghorn

Partner in Technology, Data Protection, Privacy, Cybersecurity and Artificial Intelligence

+44 (0)345 2579449

Contact Wayne

  • This field is for validation purposes and should be left unchanged.
  • This field is hidden when viewing the form

Wayne Cleghorn is an experienced and specialist Senior Technology Lawyer focusing on data protection, global data privacy, cybersecurity, cyber attacks, data breach response, and new technology governance, including artificial intelligence. He advises clients across a wide range of technology contracts. He engages effectively with clients, identifies the key issues, gives practical advice, and offers unique insights because of his diverse experience. His advice and guidance are always risk-based, pragmatic, and commercially astute.

Wayne’s practice includes advising UK, European, US, and international data protection programmes, leading data protection audits, drafting data privacy policies, updating GDPR procedures and documentation. His work includes responding to large data breaches, including ransomware, strategically responding to complex subject access requests, advising on regulator investigations, and helping organisations respond effectively to regulators and enforcement measures. He also drafts commercial contracts, negotiates IT contracts, negotiates data processing agreements, and arranges international data transfers via Standard Contractual Clauses, Binding Corporate Rules, and other tools. He has advised a wide range of sectors, including financial services, fintech, technology, manufacturing, retail, ecommerce, health, biotechnology, universities, and government bodies.

Wayne has worked in private practice, in-house, as a government lawyer, and a Management Consultant. He is also a certified Project Manager and a Lead Data Protection Officer (DPO).

Wayne's Experience

Led the work programme at a Fortune 500 US Silicon Valley global cloud services provider to review and update GDPR Privacy by Design policy and procedures, Data Protection Impact Assessments (DPIAs), Privacy Impacts Assessments (PIAs) and Privacy Risk Registers of over 100 infrastructure, hardware, software products and digital services. Led AI services projects, AI software risk assessments and pre / post M&A global data privacy compliance due diligence.

Provided statutory Data Protection Officer services to a UK Central Government Department and Non-Departmental bodies for a big data project with 15 parties and income of £20 billion to combine trade, transport, security and private sector data.  

Advised Nasdaq–listed Dutch–US biotechnology and pharmaceutical company on UK post–Brexit data protection, UK supply chain reviews and improve US data transfer practices. 

Advised UK based Application developers to launch a global education App by imbedding UK ICO’s Appropriate Design Children’s Code, drafted Terms and Conditions, Data Protection Policy, GDPR FAQ, UX data minimisation and set user consent protocols.

Worked with the CEO and Head of Marketing of an international luxury goods manufacturer and ecommerce company to update its online marketing strategy, improve customer journeys, increase online sales, grow customer interactions on the marketing platforms, resolve US customer data complaints and comply with UK and EU ePrivacy regulations, GDPR, sector standards and industry good practice.

Helped a UK and European retail bank and fintech to increase its data science, big data analytics and debt-risk intelligence data capabilities. Included data brokers and credit reference agency contracts, negotiations, risk analysis and artificial intelligence services.

Responded to a major health data ransomware attack by Black Basta (linked to the Conti and REvil groups) that required recording and breach response under GDPR, California law, 25 US states and the US Health Insurance Portability and Accountability Act (HIPAA).

Led and advised on the legal and operational aspects of a major cyber attack on the HR department of a leading provider of IT and security services. Key outcomes included IT systems forensic analysis, IT system rebuilds, regulator notifications, customer notifications, cyber insurance policy claims, and litigation preparation.

Led a project to assess, limit and remediate the EU and US insurance and healthcare supply chain effects of Australia’s Medibank data breach in 2022.  

2007

Keen interest in travel, photography and gospel music. Always seeking opportunities to develop French language skills.  

Oxford Artificial Intelligence Programme Certificate – Said Business School, Oxford University

Berkeley Law AI Institute Certificate – University of California, Berkeley Law School

Certified Prince 2 Project Manager (Professional)

Member of the International Association of Privacy Professionals (IAPP), with certifications:  FIP (Fellow), CIPP/E (Europe), CIPP/US (United States) and CIPT (Technology) 

Professional Member of the BCS, the Chartered Institute for IT – MBCS 

International Bar Association (IBA)

Mastering AI Cyber Security Risks for Advice Firms (The Financial Times: FT Adviser)

https://www.ftadviser.com/content/1eb5719a-06a6-4882-a2bb-2faedde06bf8

 

What Businesses should learn from the AWS, Azure and Cloudflare IT Outages (Excello Law News)

https://excellolaw.co.uk/what-businesses-should-learn-from-the-aws-azure-and-cloudflare-it-outages/

 

New AI Code of Practice Enables Compliance with World’s First Legal Framework on AI (R&D Today)

https://www.rndtoday.co.uk/impact-of-ai/new-ai-code-of-practice/

 

EU AI Code of Practice is Now Live – Time to Act (Artificial Lawyer)

https://www.artificiallawyer.com/2025/08/04/eu-ai-code-of-practice-is-now-live-time-to-act/

 

New AI Regulation Impacts UK Businesses (Solicitors Journal)

https://www.solicitorsjournal.com/sjarticle/new-ai-regulation-impacts-uk-businesses?pass=bmibfewa8m

 

I am a Data Security expert and here are 5 Lessons on Cyber Security from the Legal Aid Agency Cyberattack (TechRadar Pro)

https://www.techradar.com/pro/i-am-a-data-security-expert-and-here-are-5-lessons-on-cyber-security-from-the-legal-aid-agency-cyberattack

 

ICO Fines Data Processor over £3 million for Ransomware and Data Protection Failures (Excello Law News)

https://excellolaw.co.uk/ico-fines-advanced-over-3-million-for-data-protection-failures/

 

Five Cyber Attack Trends to Prepare for in 2025 (Architecture and Governance Magazine)

https://www.architectureandgovernance.com/applications-technology/five-cyber-attack-trends-to-prepare-for-in-2025/

Understanding Europe’s Big Six Data Protection Regulators (PrivacySolved Insights) 

https://www.privacysolved.com/understanding-europes-big-six-data-protection-regulators/  

 

International Data Transfers: New UK Standard Contractual Clauses (PrivacySolved Insights) 

https://www.privacysolved.com/international-data-transfers-new-uk-standard-contractual-clauses/  

 

The Ransomware Problem: Five Steps to Success (PrivacySolved Insights) 

https://www.privacysolved.com/the-ransomware-problem-five-steps-to-success/  

 

Testimonials

“I appreciate your dedication to improving our global privacy programme. Please know that we will continue to make progress on this plan and our overall programme.”   

Vice President & Chief Privacy Officer, Fortune 500 Technology Company 

“Thank you for the hard work on this. We appreciate the assistance and collaboration (and advice) we have received over the course of this process. Thanks a lot, on behalf of our team!”       

Director, Cloud Solutions Architecture, Global Cloud Services Company 

“Thanks for your willingness to continue supporting our Group. It was a pleasure.”                  

Group Executive Committee Member & Group General Counsel, Global Consulting, Technology and Digital Company  

Wayne's Updates