Associate
Languages spoken
English | Filipino (Tagalog)
Gicel Tomimbang is an associate in the Corporate Practice based in our Los Angeles office. She counsels clients in the manufacturing, professional services, healthcare and technology sectors on corporate transactions, complex commercial agreements, privacy and cybersecurity matters and related regulatory and business matters.
Gicel’s background includes service as a deputy attorney general for the California Department of Justice Office of the Attorney General, and as an investigator for the US Department of Health and Human Services, as well as experience in a corporate legal department. Her multidisciplinary perspective enables her to approach client matters with an understanding of business operations, government enforcement and transactional risk.
Gicel is a certified information privacy professional (CIPP/US and CIPP/E), a certified information privacy manager (CIPM) and an International Association of Privacy Professionals (IAPP) fellow of information privacy (FIP). She invests in her community through her active membership in professional and community organizations, including the Los Angeles County Bar Association, the IAPP and the Junior League of Los Angeles. Within the firm, she is a member of the Summer Associate Committee and the Squire Patton Boggs Foundation Mentoring Subcommittee.
Served as the primary deal associate on domestic and cross-border mergers and acquisitions involving manufacturing, professional services, healthcare and technology companies, including coordinating multidisciplinary due diligence and supporting deal execution.
Led privacy and cybersecurity diligence in mergers and acquisitions, including assessing incident history, data governance, regulatory exposure, technology agreements, compliance programs and cross-border data risks.
Advised US subsidiary of a multinational food and beverage company on commercial agreements and general business matters.
Counseled clients on privacy and cybersecurity incidents and regulatory inquiries, including response, notification, remediation strategy and execution and communications with regulators.
Advised global technology and social media companies on information technology, cybersecurity, data protection and related risk allocation in vendor and strategic partner agreements, including drafting contract provisions and developing negotiation strategies for in-house legal teams.
Developed cybersecurity incident response plan and cybersecurity policies, including procedures for assessing and reporting material cybersecurity incidents in public filings for publicly traded financial technology company.
Counseled a publicly traded technology company on policies and training supporting compliance with Executive Order 14117 (Preventing Access to Americans’ Bulk Sensitive Personal Data and US Government-related Data by Countries of Concern), which regulates access by countries of concern to Americans’ bulk sensitive personal data and US government-related data.
Developed and executed the response and regulatory investigation strategy for a complex, multiyear investigation by the US Department of Health and Human Services, Office for Civil Rights involving state health agencies, achieving resolution without enforcement action.
Member, IAPP Advisory Board, Privacy Bar Section
Active member, Junior League of Los Angeles, Donor & Relationship Stewardship Committee
Executive Committee, Los Angeles County Bar Association, Privacy & Cybersecurity Section