Grace Tang

Associate

Overview

Grace Tang is an associate in Crowell & Moring’s Privacy and Cybersecurity Group, advising clients across a range of industries on technology and privacy-related legal matters. She combines her experience in technology with a strong foundation in privacy as clients often face an overlapping and increasingly complex regulatory landscape – particularly in areas such as online safety and artificial intelligence.

Grace regularly advises on high-value commercial technology and outsourcing arrangements, combining legal insight with a practical understanding of operational and business needs. On data protection matters, Grace has experience with advising on compliance programs, data subject rights and drafting privacy notices, data protection impact assessments and policies.

Having previously trained and qualified into a technology and data team in a London firm, Grace joined Crowell & Moring in 2025. She also gained experience as a paralegal for a few years at an international premium travel and payments company supporting all lines of business and legal operations.

Career & Education

    • University of Law, LPC, 2021
    • London School of Economics and Political Science (LSE), LLB Law, 2018
    • University of Law, LPC, 2021
    • London School of Economics and Political Science (LSE), LLB Law, 2018
    • Solicitor, England and Wales, 2023
    • Solicitor, England and Wales, 2023

Grace's Insights

Client Alert | 4 min read | 08.14.26

License to Hack? The White House Greenlights Private-Sector Offensive Cyber Operations

On August 12, 2026, the White House released a National Security Presidential Memorandum (NSPM), marking a seismic shift in U.S. cybersecurity policy and establishing a framework to authorize private-sector companies to conduct offensive cyber operations—historically strictly prohibited by federal law—against foreign Cyber-Enabled Transnational Criminal Organizations (CE-TCOs).  It builds on an executive order issued in March 2026 that directed federal agencies to develop plans to combat cyber-crimes against Americans....

Grace's Insights

Client Alert | 4 min read | 08.14.26

License to Hack? The White House Greenlights Private-Sector Offensive Cyber Operations

On August 12, 2026, the White House released a National Security Presidential Memorandum (NSPM), marking a seismic shift in U.S. cybersecurity policy and establishing a framework to authorize private-sector companies to conduct offensive cyber operations—historically strictly prohibited by federal law—against foreign Cyber-Enabled Transnational Criminal Organizations (CE-TCOs).  It builds on an executive order issued in March 2026 that directed federal agencies to develop plans to combat cyber-crimes against Americans....