Melissa Hall is a Legal Director in our Commercial team, advising organisations across the private, public and third sectors on data protection, governance, technology and commercial matters.
She helps clients navigate increasingly complex regulatory and digital landscapes, providing practical advice that is both legally robust and easy to implement.
Melissa has particular expertise in data protection and UK GDPR, commercial and IT contracts, artificial intelligence, intellectual property, anti-bribery and corruption, and charity governance. She works closely with organisations to manage risk, support innovation and ensure compliance, while helping them achieve their wider strategic objectives. Her data protection practice includes advising on data subject access requests, personal data breaches, marketing practices and contractual arrangements for data processing, as well as delivering tailored training to organisations.
Known for her pragmatic and sector-focused approach, Melissa delivers clear, commercial solutions that help clients make confident decisions. She works extensively with organisations in the technology, life sciences and charity sectors, advising on emerging issues relating to data, cyber security and AI, as well as governance, fundraising and brand protection. As co-lead of MFMac's Life Sciences sector, she supports organisations operating in a highly regulated and fast-evolving environment, helping them navigate legal and commercial challenges at every stage of growth.
Melissa is recognised by both Legal 500 and Chambers for her work in the technology and charity sectors, and is also a Notary Public. She is accredited by the Law Society of Scotland as a Specialist in Freedom of Information and Data Protection Law.
Commercial Contracts
Intellectual Property
Regulatory & Compliance
Data Protection & UK GDPR
Charities & Third Sector
Healthcare & Life Sciences
Manufacturing, Media & Technology
Technology
MedTech, BioTech & Digital Health
Cyber Security & Cyber Crime
Data & Cyber Security Incidents
Information Technology

The ICO's draft guidance signals a more sophisticated and risk-based approach to research governance. Organisations operating in life sciences should view anonymisation, pseudonymisation, TREs, privacy-enhancing technologies and documented identifiability assessments as increasingly important components of responsible research and innovation. Given the draft status of the guidance, a degree of "watching brief" is appropriate.

Age assurance is a key part of complying with the Online Safety Act and protecting children online. Organisations must use effective age verification measures while ensuring any personal data collected is handled in line with UK data protection laws and the ICO's Children's Code.

Using wearable health technology as a practical case study, MFMac's Glasgow Tech Week event on Innovation, Regulation and Real Time Health Monitoring will examine how data protection, cyber security and product liability risks shape innovation across the product lifecycle.