Focus Areas
- Served as breach coach for construction consultant with respect to Play ransomware attack; retained digital forensic expert and threat actor negotiators and advised on data breach notification obligations with respect to potential compromise of current and former employees’ sensitive HR data.
- Assisted school district in responding to RansomHub cybersecurity incident, including with respect to threat actor communications, sanctions checks, digital forensics, and drafting and disseminating data subject notices pursuant to FERPA and U.S. state law.
- Assisted client in responding to intrusion into a remote employee’s personal and professional devices, including leading forensic investigation and advising on federal and state data breach notification laws.
- Assisted U.S. chemical and manufacturing company in responding to Akira ransomware including notifying impacted data subjects and regulatory authorities.
- Assisted a global manufacturer in responding to ransomware attack by Black Basta that encrypted its VMware ESXi including providing formal notification to data subjects and regulators.
- Assessed whether inclusion of social security numbers on health plan communications transmitted via mail from business associate would be considered a data breach for purposes of federal and state data breach notification laws for a U.S.-based publicly traded multinational corporation.
- Assisted consumer goods company in investigating and responding to data breach arising from unauthorized access to, and exfiltration of, customer data from the company’s third-party e-commerce platform due to compromise of an employee’s account credentials.
- Assisted global manufacturing company with response to the inadvertent disclosure of export-controlled data to foreign nationals.
- Assessed and identified the current state of organizational policies and procedures across different sectors including manufacturing and consumer to determine its compliance with the CCPA, CDPA, CTDPA and VCDPA.
- Reviewed and revised a global manufacturing company’s existing website data protection policy to reflect EU/UK GDPR, CPRA and VCDPA requirements.
- Drafted internal policies and procedures on how an organization would intake and respond to data subject rights requests, including access, deletion/erasure, correction and opt-outs.
- Drafted website policies and internal data flow guidelines for a consumer goods company and subsidiary operating in the US and Canada.
- Assisted in data protection due diligence by analyzing third-party cookies, pixels, and tags deployed on target’s websites.
- Conducted targeted advertising data protection impact assessment (DPIA) for a global brand.
- Assisted client that engages in direct-to-consumer e-commerce transactions of consumer goods draft and implement data protection impact assessment policy to comply with U.S. state law, including the California Consumer Privacy Act.
- Drafted data protection impact assessment to be used for multiple clients in the e-commerce area who engage in targeted advertising through the use of third-party cookies, pixels and tags.
- Drafted multiple cybersecurity incident notification letters to assist client comply with data breach, with special emphasis on furnishing notice based on multiple and discrete data sets compromised, including social security numbers, driver’s license numbers, financial account and routing numbers, and alien identification numbers.
- Assisted multinational corporation update its mobile application terms of use and data processing addendum to include new EU and UK cross-border clauses.
- Assisted clients review, amend and negotiate data processing agreements.
- Provided formal data breach notifications to individuals and regulatory officials in response to cybersecurity events.
- Drafted online terms and conditions, privacy policies and cookie policies for domestic and global companies.
- Conducted risk analysis concerning client’s information practices and, more specifically, data protection impact assessment (DPIA).
- Prepared data transfer impact assessment (DTIA) for exporting personal data from the European Economic Area (EEA) into the United States.
- Assisted companies in vendor due diligence, including assessing third-party data processing activities and facilitating data protection contractual requirements.
- Assisted in data mapping exercises to identify the purpose, scope and legal authorization for client’s data processing activities.
- Drafted policies and procedures and develop internal compliance programs to fulfill domestic and international laws and statutes, including consumer privacy requirements; employee data privacy notices and policies; digital marketing and targeted advertising.
- Assisted clients to remove spoofing websites through dispute resolution and legal processes.
- Assisted chemical company in responding to a cyber incident in accordance with federal regulations and state law.
- Provided legal analysis to a global manufacturing company on California’s legal consent requirement for two-party phone monitoring.
- Assisted a global software company in determining whether an unauthorized access to a personnel database constitutes a breach under the General Data Protection Regulation (GDPR) that warrants notification to data subjects and the supervisory authority.
- Assisted companies in responding to serious data events, including ransomware attacks and other incidents involving the unauthorized access, acquisition, or disclosure of personal data or confidential information.
- Drafted new, or supplemented existing, internal policies and procedures to streamline client’s intake and response process to data privacy requests (e.g., access, portability, erasure).
- Provided legal analysis on whether an opt-out from a marketing message applies to an entire organization, or just the specific affiliate who was sending the messages within the CANSPAM law.
- Assisted global manufacturing company in responding to a Lockbit 3.0 ransomware and extortion attack, including providing formal notification to data subjects, regulators and credit monitoring agencies.
- Assisted global manufacturing company respond to a Royal ransomware and extortion attack, including retaining an independent incident response consultant and preparing incident notification to individuals and regulatory officials.
- Drafted webpage privacy policies for e-commerce companies marketing and selling goods, services and products in the EEA.
- Assisted global software company evaluate whether potential data processing activities implicates federal surveillance law.
- Assisted educational institution to determine whether disclosure of educational records constitutes a breach that implicates federal and state breach notification laws.
- Drafted technology agreements, including end-user license agreements for websites and mobile applications.
- Co-author, “Pennsylvania Amends Data Breach Reporting Law; Requires Credit Monitoring for Victims,” Pratt’s Privacy & Cybersecurity Law Report, September 2024
- “Rhode Island Enacts Consumer Data Privacy Law,” Thompson Hine Privacy & Cybersecurity Update, July 2024
- “Pennsylvania Amends Data Breach Reporting Law; Requires Credit Monitoring for Victims,” Thompson Hine Privacy & Cybersecurity Update, July 2024
- “Colorado Adds Biometric Data Requirements to Privacy Law,” Thompson Hine Privacy & Cybersecurity Update, June 2024
- “Minnesota Legislature Passes Consumer Privacy Law,” Thompson Hine Privacy & Cybersecurity Update, May 2024
- “Tennessee Enacts Data Breach Class Action Safe Harbor,” Thompson Hine Privacy & Cybersecurity Update, May 2024
- “SEC Amends Regulation S-P to Address Information Security and Data Breach Response,” Thompson Hine Privacy & Cybersecurity Update, May 2024
- “SEC Issues Update on Cybersecurity Incident Report,” Thompson Hine Privacy & Cybersecurity Update, May 2024
- “Banking Regulators Publish Third-Party Risk Management Guide,” Thompson Hine Privacy & Cybersecurity Update, May 2024
- “Nebraska Enacts Consumer Data Privacy Law,” Thompson Hine Privacy & Cybersecurity Update, April 2024
- “Maryland Poised to Enact Privacy Law; Sets New Standard for Targeted Advertising,” Thompson Hine Privacy & Cybersecurity Update, April 2024
- “CPPA Releases First Enforcement Advisory,” Thompson Hine Privacy & Cybersecurity Update, April 2024
- “Kentucky Poised to Enact Consumer Data Protection Law,” Thompson Hine Privacy & Cybersecurity Update, April 2024
- “Florida and West Virginia Create New Cybersecurity Safe Harbor Laws,” Thompson Hine Privacy & Cybersecurity Update, March 2024
- Co-author, “California Announces Privacy Audits of Connected Vehicles and Related Technologies,” The Journal of Robotics, Artificial Intelligence & Law, Volume 7, No. 2, March-April 2024
- “Effective Immediately: California Privacy Protection Agency Resumes Authority to Enforce Privacy Regulations,” Thompson Hine Privacy & Cybersecurity Update, February 2024
- “New Jersey Enacts Consumer Data Privacy Law,” Thompson Hine Privacy & Cybersecurity Update, January 2024
- “Federal Trade Commission Amends Safeguards Rule and Data Breach Notification Obligations,” The Computer & Internet Lawyer, January 2024
- “New Guidance on SEC Cybersecurity Reporting Regulations,” Thompson Hine Privacy & Cybersecurity Update, December 2023
- “Preparing for SEC Cybersecurity Incident Reporting,” Insights, The Corporate & Securities Law Advisor, December 2023
- “NYDFS Amends Data Breach and Cybersecurity Regulations,” Thompson Hine Privacy & Cybersecurity Update, November 2023
- “Florida’s Digital Bill of Rights and Breach Notification Amendment,” Thompson Hine Privacy & Cybersecurity Update, November 2023
- “FTC Amends Safeguards Rule and Data Breach Notification Obligations,” Thompson Hine Privacy & Cybersecurity Update, November 2023
- “Major Changes to California Privacy Laws,” Thompson Hine Privacy & Cybersecurity Update, October 2023
- “Delaware Personal Data Privacy Act Signed Into Law With 2025 Effective Date,” Thompson Hine Privacy & Cybersecurity Update, September 2023
- “Preparing for Connecticut’s New Telemarketing Law,” Thompson Hine Privacy & Cybersecurity Update, August 2023
- “California Announces Privacy Audits of Connected Vehicles and Related Technologies,” Thompson Hine Privacy & Cybersecurity Update, August 2023
- “SEC Finalizes Rules Requiring Mandatory Cybersecurity Disclosure,” Thompson Hine Securities Law Update, July 27, 2023
- “New Data Security and Breach Notification Obligation for DHS Contractors,” Thompson Hine Privacy & Cybersecurity Update, July 2023
- “California Investigates Employee/HR Data Processing in Privacy Enforcement Actions,” Thompson Hine Privacy & Cybersecurity Update, July 2023
- “Oregon Legislature Passes Privacy Law,” Thompson Hine Privacy & Cybersecurity Update, July 2023
- “California Privacy Law Enforcement Delayed Until 2024,” Thompson Hine Privacy & Cybersecurity Update, July 2023
- “FBI Issues Business Email Compromise Alert,” Thompson Hine Privacy & Cybersecurity Update, June 2023
- “Texas Enacts Privacy Law; Amends Data Breach Notification Law,” Thompson Hine Privacy & Cybersecurity Update, June 2023
- “Washington State Enacts My Health, My Data Act,” Thompson Hine Privacy & Cybersecurity Update, May 2023
- “Data Privacy Update: Several U.S. States Enact Privacy Legislation in 2023,” Thompson Hine Privacy & Cybersecurity Update, May 2023
- “California and Colorado Finalize Privacy Regulations,” Thompson Hine Privacy & Cybersecurity Update, April 2023
- “California Consumer Privacy Act Enforcement and Preparing for 2023 Data Privacy Rules,” Pratt’s Privacy and Cybersecurity Report, January 2023
- “CCPA Enforcement and Preparing for 2023 Data Privacy Rules,” Thompson Hine Privacy & Cybersecurity Update, September 2022
- “California Issues New Draft Privacy Regulations,” Thompson Hine Privacy & Cybersecurity Update, June 2022
- “Connecticut Enacts New Consumer Data Privacy Law,” Thompson Hine Privacy & Cybersecurity Update, May 2022
- “New York Enacts Employee Privacy Law,” Thompson Hine Privacy & Cybersecurity Update, May 2022
- “Artificial Intelligence, Personal Data, and Developments in U.S. Law,” PRIS News Flash, March 28, 2022
- “Utah Enacts New Consumer Data Privacy Law,” Thompson Hine Privacy & Cybersecurity Update, March 2022
- “Responding to COVID-19: Privacy Implications of the Rapid Adoption of ICTs”
- Co-author, “Older Adults Use of Technology for Decision-Making: A Systematic Literature Review,” ResearchGate, October 2022
- Co-author, “Illuminating Privacy and Security Concerns in Older Adults’ Technology Adoption,” ResearchGate, October 2022
- “Data Ownership: Legalities Concerning Wearable Technologies,” Privacy Concerns Surrounding Personal Information Sharing on Health and Fitness Mobile Apps, 2021
- Co-author, “Coronavirus Pandemic: The Use of Technology for Education, Employment and Livelihoods,” Journal of Assistive Technology, 2021
- Co-author, “Chapter 5: Responding to COVID-19: Privacy Implication of Adopting ICTs,” Social Vulnerability to COVID-19: Impacts of Technology Adoption and Information Behavior, 2021
- “Information Privacy: A Review of Levels of Analysis and Theories in IS,” New York Celebration of Women in Computing Conference, 2021
- Co-creator, poster: “Assessment of Post-deployment AI Ethical Risks,” presented at Society for Risk Analysis 2020 Risk Science for Sustainability conference, 2020
- “Privacy: A Conceptual Analysis at the Intersection of Information Science, Psychology & Law,” New York Celebration of Women in Computing Conference, 2019
Professional Associations
- American Bar Association: member, Young Lawyers & Professionals Advisory Panel, Privacy and Information Security Committee (2021–2022) (2022-2023); Young Lawyer Representative, Advertising Disputes and Litigation Committee (2021–2022)
- International Association of Privacy Professionals
- New York State Bar Association
- New York City Bar
Education
- State University of New York at Albany, Ph.D., 2024
- State University of New York at Buffalo, J.D., 2018
- State University of New York at Buffalo, M.B.A., 2018
- University of Phoenix, B.S., 2010
Bar Admissions
- New York
- Pennsylvania Amends Data Breach Reporting Law; Requires Credit Monitoring for Victims,
Pratt’s Privacy and Cybersecurity Report
, September 23, 2024 - Rhode Island Enacts Consumer Data Privacy Law,
Privacy & Cybersecurity Update
, July 5, 2024 - Pennsylvania Amends Data Breach Reporting Law; Requires Credit Monitoring for Victims,
Privacy & Cybersecurity Update
, July 2, 2024 - Colorado Adds Protections for Minors to Privacy Law,
Privacy & Cybersecurity Update
, June 13, 2024 - Colorado Adds Biometric Data Requirements to Privacy Law,
Privacy & Cybersecurity Update
, June 4, 2024 - Minnesota Legislature Passes Consumer Privacy Law,
Privacy & Cybersecurity Update
, May 30, 2024 - Tennessee Enacts Data Breach Class Action Safe Harbor,
Privacy & Cybersecurity Update
, May 29, 2024 - SEC Amends Regulation S-P to Address Information Security and Data Breach Response,
Privacy & Cybersecurity Update
, May 28, 2024 - SEC Issues Update on Cybersecurity Incident Report,
Privacy & Cybersecurity Update
, May 23, 2024 - Illinois Legislature Amends BIPA to Limit Damages and Expand Consent Options,
Privacy & Cybersecurity Update
, May 20, 2024