.

David J. Shannon

Chair, Privacy and Data Security

Chair, Intellectual Property, Technology and Media Litigation

Portrait of David J. Shannon

David chairs both the Privacy and Data Security Practice Group and the Intellectual Property, Technology and Media Litigation Practice Group. He concentrates a substantial portion of his practice on privacy law, data breaches, intellectual property, copyright and trademark infringement, as well as trade secret, trade dress technology and media related litigation. David is experienced defending privacy and intellectual property cases venued throughout the United States and has been litigating cases in federal and state courts since 1994. David is a national and international featured speaker at privacy and data security conferences and seminars. His presentations focus on legal issues and emerging trends in the insurance industry with an emphasis on all areas of privacy, data breach and data security.

David additionally represents design professionals in a variety of construction industry related claims.  He has extensive experience representing architects, engineers, surveyors, land developers, commercial property owners, general contractors, subcontractors and commercial landscapers.  David has defended clients in cases that involved claims for design errors and omissions and other contractual and negligence claims. Over the past 25 years, he has tried a number of bench trials, jury trials, and arbitrations.

    • Widener University Delaware Law School (J.D., 1994)
    • Denison University (B.A., 1990)
    • New Jersey, 1994
    • Pennsylvania, 1994
    • U.S. Court of Appeals 3rd Circuit, 1998
    • U.S. District Court Eastern District of Pennsylvania, 1998
    • U.S. District Court District of New Jersey, 2000
    • U.S. District Court Middle District of Pennsylvania, 2006
    • Legal 500 Philadelphia Legal Elite, Intellectual Property (2025-2026)
    • Pennsylvania Super Lawyers (2005, 2026)
    • Pennsylvania Bar Association, IP Law Section, Past Chair
    • Philadelphia Bar Association
    • Professional Liability Underwriting Society
    • PLUS Podcast: Managing Cybersecurity Threats in 2026, Episode 1, Law Firm Cyber Attacks & the New Financial Sector Regulatory Landscape, June 2026
    • PLUS Podcast: Managing Cybersecurity Threats in 2025Episode 2, Beyond the Breach: Remediation vs. Forensic Investigation, December 2025
    • PLUS Podcast: Managing Cybersecurity Threats in 2025Episode 1, "Ransomware, Business Email Compromise, AI and The Increasing Sophistication of Cyber Threat Actors," July 2025
    • PLUS Podcast: Managing Cybersecurity Threats in 2024, Episode 3, Restoration After The Data Breach, December 2024
    • PLUS Podcast, Managing Cybersecurity Threats in 2024, Episode 2: SEC Amendment's Impact on Compliance and Reporting, July 2024
    • PLUS Podcast: Managing Cybersecurity Threats in 2024, Episode 1:The Persisting Threat of Ransomware, February 27, 2024 
    • PLUS Podcast: Managing Cybersecurity Threats in 2023. Episode 2: The Current State of Ransomware Attacks in 2023. April 2023
    • Critical Infrastructure – A Global View on Cyber Risk and Systemic Threats, ILG 360º London Annual Conference 2023, March 15, 2023
    • PLUS Podcast: Managing Cyber Security Threats in 2023. Episode 1: Cryptojacking - New Risks For Carriers and Their Insureds. March 2023
    • Business Email Compromise & Wire Transfer Fraud - Evolving Trends and Cyber Crime, Marshall Dennehey Client Webinar, Presented to Multiple Clients, 2022
    • Ransomware Attacks: An Ongoing Global Threat, Marshall Dennehey Client Presentation, Presented to Multiple Clients, 2022
    • Ransomware Attacks: An Ongoing Global Threat, ILG Virtual Conference, March 31, 2022
    • Cybersecurity: Crucial for a Law Firm’s Survival, Moderator, Philadelphia Association of Defense Counsel, November 16, 2021
    • Civil Litigation Updates in COVID-19 Litigation – Where Do We Stand One Year Later? Marshall Dennehey Webinar, May, 2021
    • Ransomware Attacks: An Ongoing Global Threat, ILG Virtual Conference, March 25, 2021
    • Cyber Security & Construction, National Association of Women in Construction, November 2020
    • Speaking Up on Silent Cyber, A.M. Best Webinar Panelist, May 2020 
    • Emerging Global Cyber Ransom Threats Require A Strategic Response From The C-Suite, A.M. Best Insurance Law Podcast, July 2018
    • Cyber Claims: What to Do?, National Conference of Insurance Guaranty Funds, November 2017 
    • Data Breaches Come in All Sizes, Beacon Technologies, April 26, 2017 
    • Cyber: Global Perspectives, Insurance Law Global, International Insurance Defence Network Conference, March 2017 
    • Cyber Security for the C Suite, panelist, SIM, February 7, 2017
    • Ethical and Statutory Concerns for Law Firms,  webinar panelist, Bloomberg & CNA Insurance, November 2, 2016
    • Cybersecurity for the C Suite, panelist, Tatum, October 26, 2016
    • Cybersecurity: Emerging Trends and the Current Regulatory Environment for Independent Financial Advisors and Independent Financial Services Firm, Financial Services Institute (FSI) webinar, September 22, 2016
    • The Changing Landscape of Cyber Liability Litigation, ACI’s 13th Advanced Forum on Cyber & Data Risk Insurance, July 29, 2016
    • Attorney Client Privilege Issues Arising out of Data Breaches, Breach Responses, and Subsequent Third Party Litigation, ACI Data Breach & Privacy Litigation and Enforcement Conference, March 18, 2016
    • Developments and Emerging Trends in the Legal and Insurance Areas of Cybersecurity, Travelers Insurance, February 2016
    • A Legislative Update From the Front Lines, DRI Data Breach and Privacy Law Conference, November 4, 2015
    • Litigation Roundup Including Recent Supreme Court Developments on Article III Standing, Injury, Damages (Spokeo v. Robins), Class Actions, and Data Breach Litigation, ACI's 17th Advanced Global Legal & Compliance Forum on Cyber Security & Data Privacy and Protection, October 5, 2015
    • Cyber Liability Insurance: New Risks & Emerging Trends, Insurance Brokers' Association of the State of New York (IBANY), September 16, 2015
    • Liability Concerns for Architects, Engineers and Construction Professionals: Pennsylvania Intellectual Property Overview, Marshall Dennehey Client Seminar, July 2015
    • Online Ethics: Blawgs, Directory Listings, Q & A Forums & Social Media Use and Confidentiality and Data Security, National Business Institute, April 2015
    • Cyber Hackers Are Everywhere! Are You Prepared? Philly I-Day, April 9, 2015
    • Current Trends in Data Breach First and Third-Party Claims and Litigation, American Conference Institute's Cyber & Data Risk Insurance conference, March 24, 2015
    • Hot Topics in Employment, Assurex Loss Control & Claims Conference, October 22, 2014
    • Cyber Technology, Data Breaches and Related E&O Trends, Claims and Coverage, moderator and speaker, 8th Annual ExecuSummit E&O Insurance Conference, June 2014
    • Cyber Liability Exposures, Every Business Has Them, Panelist, PLUS Mid-Atlantic Chapter Seminar, May 2014
    • Hot Topics in Employment, Marshall Dennehey / AIG Seminar, Philadelphia, PA, October 10, 2013
    • Employment Liability in the Cyber Age, Marshall Dennehey / AIG Employment Seminar, Pittsburgh, PA, May 2, 2013
    • Cyber Liability Claims, Coverage Issues, panel speaker, 2nd Annual National Cyber Liabilities Insurance ExecuSummit, 2013
    • Data Privacy Risk: Red Flags in Higher Education, ASFAA Annual Conference, 2012
    • Prevailed on a Motion to Dismiss in a data breach class action in the Eastern District of Pennsylvania. Sixteen named plaintiffs brought claims alleging that a hacker had accessed the personal information of over 1,000,000 individuals nationwide. We defended the debt collection company whose computer servers were compromised. Plaintiffs asserted broad and novel legal theories, including negligent failure to protect data, breach of implied contract, invasion of privacy, negligence per se, and violations of various state consumer protection laws. We successfully contested these claims, resulting in the dismissal of eight plaintiffs for lack of standing and 15 of the 17 asserted causes of action being dismissed.
    • Successfully represented and assisted a large commercial payment card processing company in a data breach notice that affected over 2 million customers.
    • Successfully defended and resolved a multimillion dollar trademark and dilution lawsuit in the 9th Circuit that included obtaining dismissal of the dilution claim.
    • Obtained complete denial of a temporary and permanent injunction motion after a weeklong injunction hearing in a trademark dispute over a well known East Coast antique show brand.
    • Successfully resolved several copyright infringement claims by an international music recording association against various entertainment venues.
    • Obtained dismissal of all claims against a website developer on the first day of trial in a matter where plaintiff alleged significant lost profits after a new customer ordering platform was installed for plaintiff's website.
    •  Successfully resolved a significant copyright infringement claim by the heirs of a famous European author against a theater where plaintiff attempted to enjoin national theater production and claim past and future profits.
    • Defeated vicarious liability claims for trademark infringement by luxury handbag manufacturer against the owner of a large retail shopping center.  All claims were dismissed after a summary judgment motion was filed.
    • Obtained voluntary dismissal of trade secret and theft of confidential information matter where the initial demand was over $300,000 by demonstrating that no trade secrets existed in the plaintiff's manufacturing process.
    • Successfully obtained summary judgment in an architectural copyright infringement action by demonstrating that client did not infringe on the plaintiff's drawings for a country club.
    • Successfully defended international chemical company in temporary and permanent injunction hearings regarding stolen trade secrets and hiring of former plant manager. 
    • Longenecker-Wells v. Benecard Services, No. 15-3538, 2016 U.S. App. LEXIS 15696 (3d Cir. Aug, 25, 2016).
    • Gianacopoulos v. Glen Oak Country Club, 2007 U.S. Dist. LEXIS 7710 (M.D. Pa. 2007)
    • Luszczynski v. Bradley, 729 A.2d 83 (Superior 1999)

Thought Leadership

Legal Updates for Privacy and Data Security

Vendor Cyber Attack Compromises PII of More Than 3 Million Hunting and Fishing License Holders in Texas

June 30, 2026

The Texas Parks & Wildlife Department (TPWD) announced earlier this month that one of its vendors which handles the sale of state hunting and fishing licenses was the victim of a cybersecurity attack. The threat actor appears to have exfiltrated personal driver’s license information, passport numbers, email addresses, phone numbers and addresses of over 3 million hunting and fishing license holders.  The State Parks Department advised that the attack did not compromise social security numbers, dates of birth or financial information. Texas Cyber Command, the state’s new cybersecurity authority formed to protect critical infrastructure and coordinate threat responses across state and local government, reportedly assisted in detecting and containing the attack. TPWD has already set up free credit monitoring for those impacted through Kroll.  According to press reports, no specific group has yet been identified as the perpetrator of the theft. TPWD also advised that business has not been interrupted and license sales were continuing. This incident once again demonstrates that cybersecurity is only as strong as the weakest link in the supply chain. Businesses must prioritize security across their own environments and those of their vendors and contractors as well.

Legal Updates for Privacy and Data Security

Identity Theft Resource Center Report Reveals Rising Data Breaches Despite Drop in Mega Breaches

February 19, 2026

The Identity Theft Resource Center (ITRC), a well-known, non-profit identity theft and fraud prevention organization, recently released its 2025 annual data breach report with significant findings for the data breach field. The ITRC tracked 3,322 data breaches in 2025 – an increase of more than 5% compared to 2024. The numbers set a new record for U.S. data breaches tracked by the ITRC over the past 20 years. These numbers also show a 79% jump in data breaches over the last five years.  Just as importantly, the number of victim notices that were sent out decreased. In 2024, the ITRC found that over 1.3 million notices had been sent out, while in 2025 less than 300,000 notices were distributed. The ITRC noted that the significant decrease in victim notices was likely due to the lack of “mega-breaches” in 2025 compared to 2024.  The ITRC also found that the financial services industry was the most breached industry in 2025 followed by health care, professional services, manufacturing, and education.  The ITRC’s president was quoted that they had found “more attacks that are more precise, more automated and more difficult to detect. Consumers can take all of the right steps, businesses can have the best cyber security and still fall victim to criminals.”   These findings are significant for the cyber security insurance field. While mega breaches may be decreasing, the overall number of breaches demonstrates that all businesses should be obtaining proper cyber security insurance, and insurance carriers should be aware that while less notices will go out, more claims will be made that can affect both underwriting and the claims procedures.  Legal Updates for Privacy & Data Security - February 19, 2026, has been prepared for our readers by Marshall Dennehey. It is solely intended to provide information on recent legal developments and is not intended to provide legal advice for a specific situation or to create an attorney-client relationship. We welcome the opportunity to provide such legal assistance as you require on this and other subjects. If you receive the alerts in error, please contact MeDeSatnick@MDWCG.com. ATTORNEY ADVERTISING pursuant to New York RPC 7.1. © 2026 Marshall Dennehey, P.C. All Rights Reserved.

Firm Highlights

Result

No-Cause Jury Verdict Secured in Wrongful Death Trial

We successfully obtained a no-cause jury verdict in a 13-day wrongful death trial. The decedent, a 59-year-old man, was admitted to the emergency room on February 15, 2019, with complaints of abdominal pain, decreased appetite, and constipation, despite the use of laxatives. The patient did not complain of any nausea, vomiting, or diarrhea. He had a significant medical history including diabetes, hypertension, prior coronary artery stenting, morbid obesity (with past gastric bypass surgery), longstanding ventral hernia, and back pain. A CT scan revealed multiple hernias and a potential closed-loop bowel obstruction, leading to a surgery consultation. Our client, an emergency general surgeon, interpreted that the patient did not have a closed loop or any significant obstruction and recommended non-surgical management. The patient was approved to have clear liquids, and had a vomiting incident shortly after, but our client was not notified. The patient was returned to NPO status, and after improving overnight, he was returned to “clears” and additional medical and renal consults were ordered. Our client did not receive any communications from the residents/nurses of any changes in the patient’s condition. On February 18, 2019, two rapid responses were called due to increased heart rate and vomiting. It is believed that the vomiting resulted in aspiration, causing sepsis, ultimately leading to the patient’s death. During the trial, the plaintiff’s sole medical expert highlighted imaging on the wrong hernia, which called into question all of his opinions in the case. We made key objections related to the expert testimony, limiting what the allegations were, and preventing new allegations from being made. After approximately two and a half hours of deliberating, the jury returned a no-cause verdict. 

Thought Leadership

SIU Gets a Boost: NJ Supreme Court Affirms Insurers' Right to Litigate, Not Arbitrate, Fraud Claims

In a significant win for insurers' Special Investigation Units, the New Jersey Supreme Court clarified that statutory insurance fraud and racketeering claims may proceed in court rather than through PIP arbitration. At issue was whether insurance fraud claims brought under New Jersey's Insurance Fraud Prevention Act (IFPA) and the state's Anti-Racketeering Act (NJ RICO) are subject to mandatory arbitration under the Automobile Insurance Cost Reduction Act’s (AICRA) PIP dispute-resolution framework. Allstate had sued a network of medical practices, physicians, and related corporate entities, alleging a scheme to extract more than $1.7 million in PIP benefits through fraudulent and misleading billing. The trial court dismissed Allstate's complaint and compelled arbitration, reading AICRA's arbitration clause — which covers "any dispute regarding the recovery of... benefits" under PIP coverage, N.J.S.A. 39:6A-5.1(a) — as sweeping in fraud and racketeering claims along with routine benefit disputes. The Supreme Court affirmed the Appellate Division's reversal, adopting Judge Gilson's opinion below (480 N.J. Super. 566 (App. Div. 2025)) as its own reasoning. The Court held that IFPA and RICO claims fall outside the scope of AICRA's PIP arbitration mechanism because that "streamlined and specialized" process cannot grant the relief those statutes contemplate — treble damages, injunctive relief, broad discovery, and joinder of third parties — and because arbitrators lack authority to award compensatory or treble damages to an insurer. The Court also rejected the argument that Allstate's own Decision Point Review Plans independently compel arbitration, finding those plan provisions no broader than AICRA's own arbitration clause. Notably, the Court expressly disagreed with the Third Circuit's contrary holding in GEICO v. Mt. Prospect Chiropractic Center, 98 F.4th 463 (3d Cir. 2024), concluding it is not bound by that federal interpretation of New Jersey law. Insurers retain the right to pursue IFPA and RICO claims in the Law Division, with a jury trial. For SIU units and NJ insurance carriers, this decision is a significant win: it forecloses defense clinics' primary procedural tool for shunting fraud investigations into limited-scope PIP arbitration, where treble damages, RICO relief, and meaningful discovery were never realistically available. Carriers building cases against fraudulently structured clinics, straw-owned practices, or coordinated billing networks can now proceed with confidence that a well-pleaded IFPA/RICO complaint stays in the Law Division rather than being diverted to arbitration on a motion to compel. Practically, this strengthens SIU's leverage in settlement negotiations, preserves civil discovery tools (subpoenas, depositions, joinder of related corporate entities) critical to unwinding complex ownership and referral schemes, and resolves the split with the Third Circuit in favor of NJ insurers — at least as a matter of state law. Expect increased reliance on IFPA civil actions, rather than PIP arbitration demands, as SIU's primary enforcement vehicle going forward.

Thought Leadership

Supreme Court of Pennsylvania Holds That Public Policy Does Not Prevent Insurance Coverage for Sex Trafficking Claims

On July 21, 2026, the Supreme Court of Pennsylvania issued an opinion emphasizing the limited circumstances in which courts may invoke public policy to bar insurance coverage, holding in Samsung Fire & Marine Insurance Co., Ltd. (U.S. Branch) v. RI Settlement Trust that Pennsylvania public policy does not preclude coverage for claims alleging that insureds enabled or profited from human sex trafficking. The decision rejects a line of federal district court decisions predicting otherwise and reinforces that Pennsylvania courts will invoke the public policy doctrine only in the clearest of circumstances. RI Settlement is particularly significant because it arose on certified questions from the United States Court of Appeals for the Third Circuit, giving the Supreme Court the opportunity to resolve an issue on which federal courts had predicted Pennsylvania law differently. RI Settlement arose out of four separate civil complaints in which the underlying plaintiffs alleged that, as minors, they were the victims of human sex trafficking at various hotels in Philadelphia. The plaintiffs claimed that the hotel owners were negligent in failing to stop the sex trafficking from happening at their hotels. After the filing of the lawsuits, the hotel owners sought coverage under their Commercial General Liability policies. The insurers initially defended the hotels under Reservation of Rights letters, though the carriers later filed Declaratory Judgment actions seeking declarations that they did not owe a duty to defend or indemnify. In short, the insurers argued in the alternative that they did not owe any obligation to provide coverage based upon Pennsylvania public policy (because the claims violated the Human Trafficking Law – 18 Pa.C.S. § 3011) and the terms and conditions of the policy. On motions for judgment on the pleadings, the District Court found for the insurers on the basis of public policy: There is no duty to defend or indemnify against actions arising out of an insured's criminal conduct related to the sex trafficking of minors. The Court appreciates that it may make public policy the basis of a judicial decision only in “the clearest of cases.” See Minnesota Fire & Cas. Co. v. Greenfield, 589 A.2d 854, 868 (Pa. 2004) (quoting Hall v. Amica Mut. Ins. Co., 648 A.2d 755, 760 (Pa. 1994)). Yet, the Court strains to imagine a clearer case than the one presented here in which the facts alleged indicate that Policyholders engaged in criminal conduct in violation of Pennsylvania's Human Trafficking Law. The hotel owners appealed the matter to the Third Circuit, which petitioned the Supreme Court of Pennsylvania to grant review of two certified questions of law: (1) whether Pennsylvania law had an “overriding public policy” against sex trafficking, such that an insurer’s duty to defend and/or indemnify is abrogated when an insured is alleged to have enabled or profited from such trafficking; and (2) if yes, is that duty abrogated whenever the insured’s alleged conduct would constitute a violation of the Pennsylvania Human Trafficking statute. Importantly, the certified questions did not ask the Supreme Court to determine whether the policies afforded coverage under their terms. Rather, the court was asked only whether Pennsylvania public policy independently barred coverage. As a result, the court assumed for purposes of answering the certified questions that the insurers otherwise owed a duty to defend and addressed only the public policy issue, leaving all policy-based coverage defenses for further proceedings. Because the court concluded that the answer to the first certified question was “no”, it did not reach the second issue. In reaching its determination that Pennsylvania public policy does not prohibit insurance coverage for sex trafficking claims, the court limited the impact of its decision in Minnesota Fire & Cas. Co. v. Greenfield, 855 A. 2d 854, 855 (Pa. 2004), which the RI Settlement opinion emphasized as having been an “Opinion Announcing Judgment of the Court” – or a plurality opinion. In Greenfield, the insured homeowner was sued by the estate of his houseguest who overdosed from heroin that he sold to her. The matter wound its way to the Supreme Court, which determined that the insurer did not owe a duty to defend or indemnify based upon Pennsylvania public policy, which criminalized the sale and use of heroin as a Schedule I narcotic. In RI Settlement, the court “decline[d] the invitation” to extend the rationale of the three-justice plurality in Greenfield beyond cases involving Schedule I controlled substances. In so holding, the justices in RI Settlement refused to “divine an overriding public policy pronouncement by the General Assembly by virtue of its enactment of the Human Trafficking Law.” The opinion further states that it is not “within the purview of this Court to rank the magnitude of the public policy underlying the various crimes defined in the Crimes Code. It is sufficient for the work of the courts to know that the General Assembly has identified conduct it deems harmful and dangerous to the maintenance of an orderly society and criminalized it.” While the court declined to declare that Pennsylvania public policy prohibits coverage for sex trafficking claims, the opinion in RI Settlement expressly states that insurers are free to include appropriate exclusionary language for such causes of actions in their policies if they desire to do so. It will certainly be interesting to see whether the insurance industry accepts the court’s invitation, or perhaps whether the Pennsylvania legislature steps in to clarify that sex trafficking claims are indeed of the type or magnitude that they should not be covered by insurance. In any event, we will, of course, continue to monitor this and other insurance coverage issues that arise before courts in Pennsylvania, New Jersey and throughout our firm’s geographic footprint and around the country.

Thought Leadership

New Jersey Expands Family Leave Protections Effective July 17, 2026

On January 17, 2026, Governor Murphy signed into law legislation expanding the New Jersey Family Leave Act (NJFLA). Beginning July 17, 2026, significant amendments to the NJFLA will expand job-protected family leave to smaller businesses and more employees across the state. The new law broadens coverage by lowering the threshold for private employers from 30 employees to 15 employees, meaning many smaller businesses will now be subject to the NJFLA. Employees of state and local government agencies will continue to be covered regardless of the size of the employer. The amendments also make it easier for employees to qualify for leave. Under the revised law, an employee will be eligible after three months of employment and at least 250 hours worked during the preceding 12 months, replacing the previous requirement of 12 months of employment and 1,000 hours worked. Currently, New Jersey's Temporary Disability Insurance (TDI) and Family Leave Insurance (FLI) programs provide eligible employees with wage replacement while they are on leave but do not independently guarantee job protection. The recent amendments to the New Jersey Family Leave Act (NJFLA) expand these protections by extending job-protected leave to additional employees. Under the amended law, employees receiving TDI or FLI benefits may be entitled to return to the same position they held before taking leave, or to an equivalent position with the same seniority, status, pay, and benefits. Although the legislation also states that it does not expand or modify an employee's reinstatement rights under the NJFLA, the amendments appear to provide job protection to eligible employees receiving TDI or FLI benefits without requiring them to separately satisfy the eligibility requirements of the NJFLA or the federal Family and Medical Leave Act (FMLA). As a result, some employees may be entitled to longer periods of job-protected leave than were previously available under existing law. With these amendments, New Jersey continues to strengthen workplace protections by expanding access to job-protected family leave for eligible employees. These changes significantly expand access to job-protected family leave and may require employers to update their leave policies, employee handbooks, and HR practices. Notably, employers who were previously not required to administer NJFLA may need to amend their policies and/or create new protocols to come into compliance with the NJFLA. Failure to do so would prove costly, as the penalties for non-compliance are significant.