Dan Pepper
Partner
Norton Rose Fulbright US LLP
Related services and key industries
Biography
Dan Pepper advises clients on proactive data privacy and security practices, data breach incident response and regulatory compliance, and has represented organizations in large-scale ransomware attacks, and cyber breaches by nation-states. He also supports clients on compliance with domestic and international security laws, regulations and standards, including PCI-DSS, the NIST and ISO. Additionally, Dan facilitates in-depth security incident simulations and performs cybersecurity risk assessments.
Dan also conducts artificial intelligence risk assessments for clients, and helps companies establish AI ethics, governance, and compliance programs, including with respect to transparency, documentation, policies and training.
Drawing upon his previous senior in-house counsel roles at multinational telecommunications and cable providers, Dan regularly advises clients on matters involving emerging technology and connected device product and service rollouts, including regulatory licensing requirements for organizations partnering with OEMs for IoT offerings, FCC licensing requirements, and negotiating content, communications and logistics contracts.
With nearly 30 years of experience in data privacy, cybersecurity and information technology law, including leadership roles at Fortune 50 public companies, Dan is highly knowledgeable in identifying, evaluating and managing risks associated with privacy and information security practices. He frequently counsels clients in regard to compliance with state, federal and international privacy and data security laws, including the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), the New York Department of Financial Services Cybersecurity Regulation and the New York SHIELD Act.
Dan has significant experience handling complex technology transactions, including structuring technology acquisitions, licensing and distribution arrangements, as well as cloud-based/SaaS transactions. With his substantial industry knowledge, Dan has drafted and negotiated thousands of technology and intellectual property-based transactions.
Professional experience
Collapse all- Executive Leadership Program, The Tuck School of Business, Dartmouth College, 2018
- JD, Duquesne University School of Law, 1994
- BA, Political Science, Rutgers University, 1991
- Colorado State Bar
- New Jersey State Bar
- New York State Bar
- Pennsylvania State Bar
Privacy and data security compliance | Information governance
- Advises on compliance with international data transfer restrictions and data localization requirements, including through the implementation of cross-border transfer mechanisms such as the standard contractual clauses, intercompany agreements and binding corporate rules. Counsels both importers and exporters of EU personal data on strategies to address potential compliance gaps resulting from the July 2020 invalidation of the EU-U.S. Privacy Shield Framework
- Reviews products, applications, and business initiatives and practices (including, data use, big data, social media, marketing and advertising campaigns) to identify potential privacy and security issues, recommending solutions for compliance with policy and legal requirements across all business unit operations
- Designs, implements and maintains data governance and compliance programs and drafts supporting materials (including policies, privacy impact assessments, standards, consumer messaging, guidance materials and awareness and training materials) relating to privacy, data use and consumer protection
- Devises privacy and information security awareness programs and training modules for personnel, typically deploying a multi-tiered, risk-based approach to account for varying degrees of employee access to, and responsibility for, sensitive data
- Advises on IP, data privacy and protection and industry-specific issues on M&A, financing and other corporate transactions (e.g., due diligence, issue identification, the drafting of APA/merger agreement provisions and counseling on warranty and indemnity issues)
- Develops and implements CCPA and EU GDPR compliance programs for U.S. and international organizations, which includes advising clients on data mapping, data transfer mechanisms, data subject request response and procedures, data protection impact assessments/privacy impact assessments, recordkeeping, the appointment of privacy officers and representatives and employee training
- Develops and implements third party cyber risk management programs to help clients identify compliance and control gaps with third parties that access sensitive and personal information, and to incorporate comprehensive contractual information security provisions and assessment mechanisms
- Conducts data and risk assessments to help clients establish "reasonable security" and appropriate "technical and organizational measures" pursuant to the CCPA, EU GDPR, FTC regulations and other federal and state regulatory requirements
- Represented a large digital cable television and telecommunications provider with its annual CPNI certification to the Federal Communication Commission
- Represented a multinational broadcasting, telecommunications and cable television provider with developing information security and third party privacy and security risk management programs, as well as CPNI protection policies
- Defended a publicly traded American telecommunications provider against an FCC enforcement action involving CPNI compliance in connection with a data security incident
Security incident response
- Prepares cyber incident response plans for potential breaches, including protocols for managing investor relations, press releases, communications with regulators/law enforcement and public disclosures following a cyber incident
- Manages cross-functional legal and business groups within client organizations to determine privacy and security objectives, and advises on the impact of the clients' data privacy and security legal and operational strategies
- Conducts in-house security training and tabletop exercises to build awareness and help companies prepare to effectively and efficiently manage data security threats and incidents.
Information technology and transactions
- Manages complex technology transactions on both the vendor side and the customer side, drafting and negotiating multiparty contracts and outsourcing agreements from the RFP through follow-up compliance assessments
- Negotiates information privacy and security based commercial transactions and counsel in the areas of business intelligence, advanced advertising, intellectual property and e-commerce for telecommunications and entertainment technologies, as well as businesses and product development
- Represented a telecommunications and cable provider in its multimillion-dollar, multi-party, cloud and software services agreements
- Represented several technology product and service start-ups as sole outside counsel, helping to grow them from inception to over $100 million in annual revenue
- Develops standard services agreements for IT service providers (e.g., cloud, SaaS, platform usage, data analytics, advertising technologies and payment processing, and website, mobile app and video game development) and negotiates such agreements on both vendor and customer sides
- Negotiated over-the-top television channel deals for content and commerce companies on various streaming and smart TV platforms
- Lawdragon 500 Leading Global Cyber Lawyers, Lawdragon, Inc., 2024
- Legal 500 US, Recommended, Cyber law (including data privacy and data protection), The Legal 500 US, 2020 (conferred by Legalease Ltd.)
- Certified Information Privacy Professional/US (CIPP/US) (conferred by International Association of Privacy Professionals)
- US Technical Advisory Group formulating consensus positions for development of the global ISO "Consumer Protection: Privacy by Design for Consumer Goods & Services" standard (ISO/PC 317) (conferred by US Technical Advisory Group: Privacy by Design)
Learn more about the descriptions of the selection methodologies for rankings and recognitions. No aspect of this advertisement has been approved by the Supreme Court of New Jersey.
- International Association of Privacy Professionals: Board Member
- Rutgers University Big Data Advisory Board: Board Member
- Superior Court of New Jersey: New Jersey Rule 1:40 Qualified Mediator
- Association of Technology Procurement Professionals
- CAUCUS: Senior Advisor
- American Corporate Counsel Association
- New Jersey Corporate Counsel Association
Insights
CISA issues proposed rules for cyber incident reporting in critical infrastructure
Blog | April 24, 2024
The New York Department of Financial Services’ cybersecurity regulation
Publication | March 18, 2024
NYDFS issues significant guidance on insurers using AI or external data
Blog | February 02, 2024