aaaa

Carolyn Bigg

Partner
Global Co-Chair of Data Protection, Privacy & Security Group
Carolyn is a rare gem in the market and has made great contributions to the data protection area. We are fortunate to have her and her team solve our legal problems.
Client comment, Chambers, 2026
About

Carolyn Bigg is Global Co-Chair of our Data Protection, Privacy and Cyber group, and leads on data and AI governance across Asia.

Carolyn is a leading, experienced data lawyer, focusing on APAC data compliance and international data transfers. Carolyn advises businesses on the best practice approach to navigating regional and international data privacy compliance, to help them seize opportunities to make the most of their data and digital opportunities in APAC within a compliant governance framework. She is also experienced in helping China- and Asia-headquartered businesses tackle global data governance as part of market expansion.

Carolyn has extensive experience of managing cyber incidents across the APAC region. Her experience gives her clients the benefit of on-the-ground practical advice to navigate the realities of enforcement priorities and risks in different Asia jurisdictions.

Carolyn also advises her clients on AI governance, including on building AI governance frameworks, navigating regional regulatory priorities, using and managing data as inputs and outputs to AI, and deployment of third-party AI tools (both Western and Chinese) across multi-nationals.

As a result of her leading work and outreach in the field, Carolyn is top ranked and recognised as a leading data practitioner by Chambers and Legal 500. She was named in the inaugural “Women in Data” list by Global Data Review in 2019 and is ranked Pre eminent by Doyle’s Guide. Carolyn is regularly quoted in major media outlets, including the Financial Times, and from 2021–2023 she served on the IAPP’s Asia Advisory Board.

Professional QualificationsSolicitor of the High Court of Hong KongSolicitor of the Senior Courts of England and Wales

EXPERIENCE

  • Supporting a global insurer on management of a major ransomware attack, including liaising with insurance and privacy regulators in three APAC jurisdictions. 
  • Supporting a number of luxury brands on management of a variety of cyber incidents involving consumer and loyalty programme data in APAC, including incidents involving Mainland China, Taiwan, Hong Kong and Singapore.
  • Appointed cyber counsel for an Asia-headquartered global hotel chain.
  • Supported a global bank on creating and operationalising a breach notification compliance register, to support breach response processes.
  • Supporting a wide range of clients across diverse industries on data mapping and decision-making on their China cross-border data transfers route(s) and their assessment submission to the authorities, covering personal, important and other regulated data.
  • Advising a global bank on the creation and operationalization of a data sovereignty programme across its international operations.
  • Advising a number of international hotel chains on rollout of their updated privacy compliance programmes, including in connection with digital initiatives and strategic business partnerships in Greater China. 
  • Advising a global retailer on implementing new or refreshed privacy compliance programmes in China, Thailand, Singapore, Australia and New Zealand to reflect new or updated data protection laws. 
  • Advising numerous SaaS platforms on data and regulatory licensing issues to support their MNC clients using their platforms in Mainland China and across Asia Pacific.
  • Advised a multinational automobile manufacturer on the establishment of a China data lake and associated use case guidelines, to support complex analytics of vehicle and customer data.   
Languages
  • English

Awards

  • Ranked as a Band 1 lawyer in the Chambers TMT: Data Protection & Privacy Guide (2024–2026)
  • Recognised as a Leading Partner for Data Protection and Cybersecurity by Legal 500 (2024 -2026)
  • Ranked Highly Recommended in Lexology’s Who’s Who Legal for Data Privacy & Protection and Data Security (2024–2026)
  • Highly Recommended for Data – Data Privacy & Protection; Lexology Index 2026
  • Highly Recommended for Data – Data Security; Lexology Index 2026
  • Recommended for Data, Mainland China, Hong Kong SAR and Macao SAR; Lexology Index 2026
  • Recognised as a Preeminent Individual in the 2026 Doyle's List for Leading Technology, Media & Telecommunications Lawyers – Hong Kong

Clients note that:

  • “Carolyn is outstanding, hardworking and practical… able to give us clear and to‑the‑point valuable legal advice and provide a clear game plan for handling the various data protection issues that arise.” — Legal 500, 2026
  • “Carolyn has a deep understanding of, and insight into, Chinese data privacy laws and rich experience in dealing with complicated data privacy compliance matters. Her advice and guidance is invaluable. I particularly like her pragmatic and hands‑on approach to complicated and nuanced compliance questions.” — Chambers Greater China, 2025
  • “Carolyn Bigg is very good at offering pragmatic solutions, and her commercial and pragmatic approach is very important to us.” — Chambers Greater China, 2022
Education
  • University of Cambridge, B.A. Hons, M.A. (Cantab)

Publications

  • Asia correspondent for Privacy & Data Protection journal.
  • Author of a chapter on services agreements for the Law Society’s Commercial Law Handbook (2009)
  • Co-authored a chapter on rights of access to information in the Law Society’s Freedom of Information Handbook (2nd edition 2008)
  • "The right to be forgotten: the Asian perspective", published in Privacy & Data Protection journal (April 2016).

Seminars

  • Carolyn is a regular speaker at external conferences, client training and internal seminars on a variety of technology and data topics, including cloud computing, outsourcing, international data transfers and cyber security. 

Memberships And Affiliations

  • Carolyn previously served as a member of IAPP's Asia Advisory Board.