
Jonathan M. Wilan
Information Security and Data Breaches
Privacy and Cybersecurity
Biography
JONATHAN WILAN has spent more than 25 years advising companies on legal risks arising from cybersecurity, artificial intelligence, privacy, and data-intensive business operations. His practice combines strategic counseling, complex litigation, regulatory matters, and transactional advice across the full lifecycle of data risk.
Jonathan’s work addresses data risks before, during, and after an incident, including proactive counseling and policy development, investigating incidents, advising on regulatory inquiries and customer disputes, and defending the litigation that often follows. He regularly defends companies in courts around the country faced with class action litigation arising from data breaches, including the ongoing MOVEit data breach MDL, one of the largest and most complex multidistrict litigations in history. He also frequently advises companies on commercial disputes arising from cybersecurity incidents, including representing service providers facing significant customer claims.
Jonathan advises on emerging legal requirements around artificial intelligence. Well before the surge in interest in AI, he led the legal aspects of projects involving large-scale implementation, evaluation, and governance of artificial intelligence systems and predictive models to satisfy legal and regulatory obligations for some of the largest companies in the world.
He also advises on the privacy and cybersecurity aspects of complex corporate transactions. Building on his 25 years of experience in this area, he regularly leads cybersecurity and privacy diligence and negotiates related contractual obligations. His work reflects a deep understanding of the legal framework and practical risks that can lead to disputes, allowing him to craft contractual provisions that address real-world scenarios.
Jonathan is recognized as a thought leader on issues related to artificial intelligence, cybersecurity, information governance, and complex litigation. He is a frequent speaker and a former member of the steering committee of The Sedona Conference Working Group 11 on Data Security and Privacy Liability. He is currently an active member of both WG11 and the Sedona Conference Working Group 13 on AI and the Law.
Experience
Representative Matters
Recent matters include:
- Defending a domestic life insurance company in the ongoing MOVEit data breach MDL proceeding in Boston.
- Defending one of the leading mortgage processing companies in the United States in a consolidated data breach class action in Florida federal court related to a prior cybersecurity incident and which resulted in an early settlement following mediation.
- Representing an analytics platform provider to the health industry in New York state class action litigation related to a prior cyber incident. The matter was resolved successfully before motion practice.
- Representing a large global IT vendor in a dispute with corporate customer arising from operationally impactful cyber incident.
- Advising on the development of AI and model development programs and policies including extensive work on model defensibility.
- Advising large money services business on complex multi-year technology implementations and model defensibility and validation obligations in the context of meeting anti-money laundering and consumer protection obligations.
- Conducting cyber diligence and negotiating contract provisions and exhibits related to cyber and privacy risk including recently in the financial services, transportation, retail, information technology, cybersecurity, and pipeline industries.
- Counseling companies on compliance with Telephone Consumer Protection Act (TCPA) obligations.
- Advising companies in the transportation, financial services, insurance, manufacturing, mortgage processing, investment management, technology platform, satellite, and IT services industries on cybersecurity matters including conducting investigations and advising on regulatory obligations and disputes.
- Advising a retail company on integration of privacy controls in the context of large acquisition and prior consent order.
- Counseling on compliance with Federal Acquisition Regulation and DoD standards in the context of cybersecurity and data protection obligations.
- Conducting due diligence and drafting contract provisions related to large third-party vendor agreements and in the context of mergers and acquisitions.
- Researching and preparing a white paper for a non-profit organization to describe data laws, regulations, guidance, and practices relevant to their mission.
Credentials
- District of Columbia
- Virginia
- Harvard Law School, J.D., 1997, cum laude
- University of Maryland, B.A., 1994, magna cum laude