Skip to main content
Wilan, Jonathan M.

Jonathan M. Wilan

Partner
Artificial Intelligence
Information Security and Data Breaches
Privacy and Cybersecurity

Biography

JONATHAN WILAN has spent more than 25 years advising companies on legal risks arising from cybersecurity, artificial intelligence, privacy, and data-intensive business operations. His practice combines strategic counseling, complex litigation, regulatory matters, and transactional advice across the full lifecycle of data risk.  

Jonathan’s work addresses data risks before, during, and after an incident, including proactive counseling and policy development, investigating incidents, advising on regulatory inquiries and customer disputes, and defending the litigation that often follows. He regularly defends companies in courts around the country faced with class action litigation arising from data breaches, including the ongoing MOVEit data breach MDL, one of the largest and most complex multidistrict litigations in history. He also frequently advises companies on commercial disputes arising from cybersecurity incidents, including representing service providers facing significant customer claims.

Jonathan advises on emerging legal requirements around artificial intelligence. Well before the surge in interest in AI, he led the legal aspects of projects involving large-scale implementation, evaluation, and governance of artificial intelligence systems and predictive models to satisfy legal and regulatory obligations for some of the largest companies in the world.

He also advises on the privacy and cybersecurity aspects of complex corporate transactions. Building on his 25 years of experience in this area, he regularly leads cybersecurity and privacy diligence and negotiates related contractual obligations. His work reflects a deep understanding of the legal framework and practical risks that can lead to disputes, allowing him to craft contractual provisions that address real-world scenarios.

Jonathan is recognized as a thought leader on issues related to artificial intelligence, cybersecurity, information governance, and complex litigation. He is a frequent speaker and a former member of the steering committee of The Sedona Conference Working Group 11 on Data Security and Privacy Liability. He is currently an active member of both WG11 and the Sedona Conference Working Group 13 on AI and the Law.

Experience

Representative Matters

Recent matters include:

  • Defending a domestic life insurance company in the ongoing MOVEit data breach MDL proceeding in Boston.
  • Defending one of the leading mortgage processing companies in the United States in a consolidated data breach class action in Florida federal court related to a prior cybersecurity incident and which resulted in an early settlement following mediation.
  • Representing an analytics platform provider to the health industry in New York state class action litigation related to a prior cyber incident. The matter was resolved successfully before motion practice. 
  • Representing a large global IT vendor in a dispute with corporate customer arising from operationally impactful cyber incident.
  • Advising on the development of AI and model development programs and policies including extensive work on model defensibility.
  • Advising large money services business on complex multi-year technology implementations and model defensibility and validation obligations in the context of meeting anti-money laundering and consumer protection obligations.
  • Conducting cyber diligence and negotiating contract provisions and exhibits related to cyber and privacy risk including recently in the financial services, transportation, retail, information technology, cybersecurity, and pipeline industries.
  • Counseling companies on compliance with Telephone Consumer Protection Act (TCPA) obligations.   
  • Advising companies in the transportation, financial services, insurance, manufacturing, mortgage processing, investment management, technology platform, satellite, and IT services industries on cybersecurity matters including conducting investigations and advising on regulatory obligations and disputes.
  • Advising a retail company on integration of privacy controls in the context of large acquisition and prior consent order.
  • Counseling on compliance with Federal Acquisition Regulation and DoD standards in the context of cybersecurity and data protection obligations.    
  • Conducting due diligence and drafting contract provisions related to large third-party vendor agreements and in the context of mergers and acquisitions.
  • Researching and preparing a white paper for a non-profit organization to describe data laws, regulations, guidance, and practices relevant to their mission.      

Credentials

Admissions & Certifications
  • District of Columbia
  • Virginia
Education
  • Harvard Law School, J.D., 1997, cum laude
  • University of Maryland, B.A., 1994, magna cum laude

News & Insights

  • Moderator, “Unique Procedural Aspects of Data Breach Class Actions,” Sedona Conference Working Group 11, Annual Meeting, Kansas City, Missouri, May 2026.
  • Panelist, “Commentary on Application of Attorney-Client Privilege in the Cybersecurity Context, Second Edition,” Sedona Conference Working Group 11, Annual Meeting, Kansas City, Missouri, May 2026.
  • Panelist, “Venue, Forum, and Choice of Law in Privacy and Data Breach Class Actions: Time for a Closer Look?,” Sedona Conference Working Group 11, Mid-Year Meeting, Fort Lauderdale, Florida, November 2025.
  • Panelist, “Shifting U.S. Federal Regulatory Priorities in the Privacy and Data Security Landscape,” Sedona Conference Working Group 11, Annual Meeting, Redmond, Washington, May 2025.
  • Panelist, “From Breach to Insight: Incident Response & PII Recovery,” Lexology Masterclass, May 2024.
  • Moderator, “Privacy and Data Security Challenges Presented by Artificial Intelligence,” The Sedona Conference on AI and the Law, Reston, Virginia, April 2024.
  • Panelist, “Protecting Personal Data After a Data Incident,” Masters Conference, Washington, D.C., April 2024.
  • Panelist, “Cyber Incident Response: Practical Guidance & Insights from the Trenches,” Today’s General Counsel, February 2024.
  • Panelist, “AI: Regulatory Landscape,” Sedona Conference Working Group 11, Annual Meeting, Denver, Colorado, May 2023.
  • Moderator, “Balancing Privacy and Data Security Against Efficacy in NextGen Healthcare,” Sedona Conference Working Group 11, Mid-Year Meeting, Cleveland, Ohio, November 2022.
  • Panelist, “When Data Is Held Hostage: A Tripartite Workshop on Best Practices for Preventing, Responding to, and Recovering from a Ransomware Attack,” MER Conference, Indianapolis, Indiana, May 2022.
  • Panelist, Second Edition of The Sedona Conference Commentary on Application of Attorney-Client Privilege and Work-Product Protection to Documents and Communications Generated in the Cybersecurity Context, Phoenix, Arizona, April 2022.