.

David J. Shannon

Chair, Privacy and Data Security

Chair, Intellectual Property, Technology and Media Litigation

Portrait of David J. Shannon

David chairs both the Privacy and Data Security Practice Group and the Intellectual Property, Technology and Media Litigation Practice Group. He concentrates a substantial portion of his practice on privacy law, data breaches, intellectual property, copyright and trademark infringement, as well as trade secret, trade dress technology and media related litigation. David is experienced defending privacy and intellectual property cases venued throughout the United States and has been litigating cases in federal and state courts since 1994. David is a national and international featured speaker at privacy and data security conferences and seminars. His presentations focus on legal issues and emerging trends in the insurance industry with an emphasis on all areas of privacy, data breach and data security.

David additionally represents design professionals in a variety of construction industry related claims.  He has extensive experience representing architects, engineers, surveyors, land developers, commercial property owners, general contractors, subcontractors and commercial landscapers.  David has defended clients in cases that involved claims for design errors and omissions and other contractual and negligence claims. Over the past 25 years, he has tried a number of bench trials, jury trials, and arbitrations.

    • Widener University Delaware Law School (J.D., 1994)
    • Denison University (B.A., 1990)
    • New Jersey, 1994
    • Pennsylvania, 1994
    • U.S. Court of Appeals 3rd Circuit, 1998
    • U.S. District Court Eastern District of Pennsylvania, 1998
    • U.S. District Court District of New Jersey, 2000
    • U.S. District Court Middle District of Pennsylvania, 2006
    • Legal 500 Philadelphia Legal Elite, Intellectual Property (2025-2026)
    • Pennsylvania Super Lawyers (2005, 2026)
    • Pennsylvania Bar Association, IP Law Section, Past Chair
    • Philadelphia Bar Association
    • Professional Liability Underwriting Society
    • PLUS Podcast: Managing Cybersecurity Threats in 2026, Episode 1, Law Firm Cyber Attacks & the New Financial Sector Regulatory Landscape, June 2026
    • PLUS Podcast: Managing Cybersecurity Threats in 2025Episode 2, Beyond the Breach: Remediation vs. Forensic Investigation, December 2025
    • PLUS Podcast: Managing Cybersecurity Threats in 2025Episode 1, "Ransomware, Business Email Compromise, AI and The Increasing Sophistication of Cyber Threat Actors," July 2025
    • PLUS Podcast: Managing Cybersecurity Threats in 2024, Episode 3, Restoration After The Data Breach, December 2024
    • PLUS Podcast, Managing Cybersecurity Threats in 2024, Episode 2: SEC Amendment's Impact on Compliance and Reporting, July 2024
    • PLUS Podcast: Managing Cybersecurity Threats in 2024, Episode 1:The Persisting Threat of Ransomware, February 27, 2024 
    • PLUS Podcast: Managing Cybersecurity Threats in 2023. Episode 2: The Current State of Ransomware Attacks in 2023. April 2023
    • Critical Infrastructure – A Global View on Cyber Risk and Systemic Threats, ILG 360º London Annual Conference 2023, March 15, 2023
    • PLUS Podcast: Managing Cyber Security Threats in 2023. Episode 1: Cryptojacking - New Risks For Carriers and Their Insureds. March 2023
    • Business Email Compromise & Wire Transfer Fraud - Evolving Trends and Cyber Crime, Marshall Dennehey Client Webinar, Presented to Multiple Clients, 2022
    • Ransomware Attacks: An Ongoing Global Threat, Marshall Dennehey Client Presentation, Presented to Multiple Clients, 2022
    • Ransomware Attacks: An Ongoing Global Threat, ILG Virtual Conference, March 31, 2022
    • Cybersecurity: Crucial for a Law Firm’s Survival, Moderator, Philadelphia Association of Defense Counsel, November 16, 2021
    • Civil Litigation Updates in COVID-19 Litigation – Where Do We Stand One Year Later? Marshall Dennehey Webinar, May, 2021
    • Ransomware Attacks: An Ongoing Global Threat, ILG Virtual Conference, March 25, 2021
    • Cyber Security & Construction, National Association of Women in Construction, November 2020
    • Speaking Up on Silent Cyber, A.M. Best Webinar Panelist, May 2020 
    • Emerging Global Cyber Ransom Threats Require A Strategic Response From The C-Suite, A.M. Best Insurance Law Podcast, July 2018
    • Cyber Claims: What to Do?, National Conference of Insurance Guaranty Funds, November 2017 
    • Data Breaches Come in All Sizes, Beacon Technologies, April 26, 2017 
    • Cyber: Global Perspectives, Insurance Law Global, International Insurance Defence Network Conference, March 2017 
    • Cyber Security for the C Suite, panelist, SIM, February 7, 2017
    • Ethical and Statutory Concerns for Law Firms,  webinar panelist, Bloomberg & CNA Insurance, November 2, 2016
    • Cybersecurity for the C Suite, panelist, Tatum, October 26, 2016
    • Cybersecurity: Emerging Trends and the Current Regulatory Environment for Independent Financial Advisors and Independent Financial Services Firm, Financial Services Institute (FSI) webinar, September 22, 2016
    • The Changing Landscape of Cyber Liability Litigation, ACI’s 13th Advanced Forum on Cyber & Data Risk Insurance, July 29, 2016
    • Attorney Client Privilege Issues Arising out of Data Breaches, Breach Responses, and Subsequent Third Party Litigation, ACI Data Breach & Privacy Litigation and Enforcement Conference, March 18, 2016
    • Developments and Emerging Trends in the Legal and Insurance Areas of Cybersecurity, Travelers Insurance, February 2016
    • A Legislative Update From the Front Lines, DRI Data Breach and Privacy Law Conference, November 4, 2015
    • Litigation Roundup Including Recent Supreme Court Developments on Article III Standing, Injury, Damages (Spokeo v. Robins), Class Actions, and Data Breach Litigation, ACI's 17th Advanced Global Legal & Compliance Forum on Cyber Security & Data Privacy and Protection, October 5, 2015
    • Cyber Liability Insurance: New Risks & Emerging Trends, Insurance Brokers' Association of the State of New York (IBANY), September 16, 2015
    • Liability Concerns for Architects, Engineers and Construction Professionals: Pennsylvania Intellectual Property Overview, Marshall Dennehey Client Seminar, July 2015
    • Online Ethics: Blawgs, Directory Listings, Q & A Forums & Social Media Use and Confidentiality and Data Security, National Business Institute, April 2015
    • Cyber Hackers Are Everywhere! Are You Prepared? Philly I-Day, April 9, 2015
    • Current Trends in Data Breach First and Third-Party Claims and Litigation, American Conference Institute's Cyber & Data Risk Insurance conference, March 24, 2015
    • Hot Topics in Employment, Assurex Loss Control & Claims Conference, October 22, 2014
    • Cyber Technology, Data Breaches and Related E&O Trends, Claims and Coverage, moderator and speaker, 8th Annual ExecuSummit E&O Insurance Conference, June 2014
    • Cyber Liability Exposures, Every Business Has Them, Panelist, PLUS Mid-Atlantic Chapter Seminar, May 2014
    • Hot Topics in Employment, Marshall Dennehey / AIG Seminar, Philadelphia, PA, October 10, 2013
    • Employment Liability in the Cyber Age, Marshall Dennehey / AIG Employment Seminar, Pittsburgh, PA, May 2, 2013
    • Cyber Liability Claims, Coverage Issues, panel speaker, 2nd Annual National Cyber Liabilities Insurance ExecuSummit, 2013
    • Data Privacy Risk: Red Flags in Higher Education, ASFAA Annual Conference, 2012
    • Prevailed on a Motion to Dismiss in a data breach class action in the Eastern District of Pennsylvania. Sixteen named plaintiffs brought claims alleging that a hacker had accessed the personal information of over 1,000,000 individuals nationwide. We defended the debt collection company whose computer servers were compromised. Plaintiffs asserted broad and novel legal theories, including negligent failure to protect data, breach of implied contract, invasion of privacy, negligence per se, and violations of various state consumer protection laws. We successfully contested these claims, resulting in the dismissal of eight plaintiffs for lack of standing and 15 of the 17 asserted causes of action being dismissed.
    • Successfully represented and assisted a large commercial payment card processing company in a data breach notice that affected over 2 million customers.
    • Successfully defended and resolved a multimillion dollar trademark and dilution lawsuit in the 9th Circuit that included obtaining dismissal of the dilution claim.
    • Obtained complete denial of a temporary and permanent injunction motion after a weeklong injunction hearing in a trademark dispute over a well known East Coast antique show brand.
    • Successfully resolved several copyright infringement claims by an international music recording association against various entertainment venues.
    • Obtained dismissal of all claims against a website developer on the first day of trial in a matter where plaintiff alleged significant lost profits after a new customer ordering platform was installed for plaintiff's website.
    •  Successfully resolved a significant copyright infringement claim by the heirs of a famous European author against a theater where plaintiff attempted to enjoin national theater production and claim past and future profits.
    • Defeated vicarious liability claims for trademark infringement by luxury handbag manufacturer against the owner of a large retail shopping center.  All claims were dismissed after a summary judgment motion was filed.
    • Obtained voluntary dismissal of trade secret and theft of confidential information matter where the initial demand was over $300,000 by demonstrating that no trade secrets existed in the plaintiff's manufacturing process.
    • Successfully obtained summary judgment in an architectural copyright infringement action by demonstrating that client did not infringe on the plaintiff's drawings for a country club.
    • Successfully defended international chemical company in temporary and permanent injunction hearings regarding stolen trade secrets and hiring of former plant manager. 
    • Longenecker-Wells v. Benecard Services, No. 15-3538, 2016 U.S. App. LEXIS 15696 (3d Cir. Aug, 25, 2016).
    • Gianacopoulos v. Glen Oak Country Club, 2007 U.S. Dist. LEXIS 7710 (M.D. Pa. 2007)
    • Luszczynski v. Bradley, 729 A.2d 83 (Superior 1999)

Thought Leadership

Legal Updates for Privacy and Data Security

Vendor Cyber Attack Compromises PII of More Than 3 Million Hunting and Fishing License Holders in Texas

June 30, 2026

The Texas Parks & Wildlife Department (TPWD) announced earlier this month that one of its vendors which handles the sale of state hunting and fishing licenses was the victim of a cybersecurity attack. The threat actor appears to have exfiltrated personal driver’s license information, passport numbers, email addresses, phone numbers and addresses of over 3 million hunting and fishing license holders.  The State Parks Department advised that the attack did not compromise social security numbers, dates of birth or financial information. Texas Cyber Command, the state’s new cybersecurity authority formed to protect critical infrastructure and coordinate threat responses across state and local government, reportedly assisted in detecting and containing the attack. TPWD has already set up free credit monitoring for those impacted through Kroll.  According to press reports, no specific group has yet been identified as the perpetrator of the theft. TPWD also advised that business has not been interrupted and license sales were continuing. This incident once again demonstrates that cybersecurity is only as strong as the weakest link in the supply chain. Businesses must prioritize security across their own environments and those of their vendors and contractors as well.

Legal Updates for Privacy and Data Security

Identity Theft Resource Center Report Reveals Rising Data Breaches Despite Drop in Mega Breaches

February 19, 2026

The Identity Theft Resource Center (ITRC), a well-known, non-profit identity theft and fraud prevention organization, recently released its 2025 annual data breach report with significant findings for the data breach field. The ITRC tracked 3,322 data breaches in 2025 – an increase of more than 5% compared to 2024. The numbers set a new record for U.S. data breaches tracked by the ITRC over the past 20 years. These numbers also show a 79% jump in data breaches over the last five years.  Just as importantly, the number of victim notices that were sent out decreased. In 2024, the ITRC found that over 1.3 million notices had been sent out, while in 2025 less than 300,000 notices were distributed. The ITRC noted that the significant decrease in victim notices was likely due to the lack of “mega-breaches” in 2025 compared to 2024.  The ITRC also found that the financial services industry was the most breached industry in 2025 followed by health care, professional services, manufacturing, and education.  The ITRC’s president was quoted that they had found “more attacks that are more precise, more automated and more difficult to detect. Consumers can take all of the right steps, businesses can have the best cyber security and still fall victim to criminals.”   These findings are significant for the cyber security insurance field. While mega breaches may be decreasing, the overall number of breaches demonstrates that all businesses should be obtaining proper cyber security insurance, and insurance carriers should be aware that while less notices will go out, more claims will be made that can affect both underwriting and the claims procedures.  Legal Updates for Privacy & Data Security - February 19, 2026, has been prepared for our readers by Marshall Dennehey. It is solely intended to provide information on recent legal developments and is not intended to provide legal advice for a specific situation or to create an attorney-client relationship. We welcome the opportunity to provide such legal assistance as you require on this and other subjects. If you receive the alerts in error, please contact MeDeSatnick@MDWCG.com. ATTORNEY ADVERTISING pursuant to New York RPC 7.1. © 2026 Marshall Dennehey, P.C. All Rights Reserved.

Firm Highlights

Thought Leadership

Mitigating Long-Tail Liability: Delaware Court Reaffirms Five-Year Workers’ Compensation Deadline

Williamson v. Donald F. Deaven, Inc., No. N25A-07-004 FWW, 2026 LX 252526 (Del. Super. Ct. June 2, 2026) Claimant was involved in a compensable industrial work accident on May 12, 1995, for a low back injury.  Following this, he received compensation for temporary total disability benefits from July 1996 to September 1996 and for sustaining a permanent impairment in 1997 and 1998. For the next 23 years, the claimant continued treatment and paid his own medical bills without submitting them to the employer’s insurer. In November 2021, the claimant filed a petition seeking payment for medical expenses, including prospective surgery and a resulting period of total disability. The employer moved to dismiss the petition, arguing it was barred by Delaware’s five-year statute of limitations (19 Del. C. § 2361(b)). Pursuant to 18 Del. C. § 3914, insurers must provide prompt written notice of the applicable statute of limitations to invoke the five-year deadline. Due to the age of the case, neither party had a comprehensive file of the claim and the Board had archived its file of the matter. The carrier’s computer system retained only bare information indicating that payments occurred and agreements and receipts were filed with the Board in 1997. While the claimant argued that the employer could not prove it provided the mandatory statutory notice, the Hearing Officer recovered the archived file, which contained two “Receipts for Compensation Paid” signed by the claimant. The receipts explicitly contained the required five-year limitation language, which the claimant testified to signing at the hearing. The claimant also attempted to introduce evidence of payments he claimed the employer made, which would have extended the statute of limitations. As a preliminary matter, the hearing officer excluded the testimony about the payments because the claimant did not produce them to the employer. The Board found in favor of the employer and dismissed the claimant’s petition as time-barred. The claimant appealed the Board’s decision, arguing that he never received adequate notice of the statute of limitations and that the hearing officer’s evidentiary ruling was an abuse of discretion. The Court held that the archived, signed receipts constituted substantial evidence that the insurer fulfilled its statutory notice requirements. Therefore, the claimant’s petition was time-barred under the statute of limitations provisions of 19 Del. C. § 2361(b). Furthermore, the Court reinforced strict procedural compliance: it rejected the claimant’s attempts to introduce evidence of payment on appeal, ruling the argument was waived for failure to preserve it while the matter was still before the Board. This recent ruling by the Court underscores the importance and necessity of robust data preservation and precise compliance with notice requirements. For risk managers, employers, and insurers, the decision highlights how tight administrative execution protects against catastrophic long-tail liability.

Thought Leadership

Congress Passes Financial Exploitation Prevention Act

On June 25, 2026, the House passed the Financial Exploitation Prevention Act of 2025 (“the Act”) by a vote of 414 to 2. The Act allows financial advisors and firms to delay suspicious transactions regarding the accounts of clients who are 65 or older, if they believe financial exploitation has occurred or is about to take place. With the advancement of technology and AI, the House’s overwhelming bipartisan passage of the Financial Exploitation Prevention Act represents an important step in strengthening the financial industry’s ability to combat the growing threat of elder financial exploitation. The Act recognizes what advisors have long known that financial professionals are often the first to detect suspicious behavior but have historically lacked clear legal authority to intervene before irreversible financial harm occurs. From the industry’s perspective, the bill accomplishes several important objectives, including the following: (1) Provides a practical “pause button” by allowing financial professionals to temporarily delay certain transaction requests when there is a reasonable belief that a senior or vulnerable adult is being financially exploited; (2) Empowers financial professionals to act by providing greater certainty that firms can act in good faith to protect clients without unnecessary legal risk; and (3) Strengthens investor protection without sacrificing client rights by allowing temporary delays based on a reasonable suspicion of exploitation, which is intended only to allow additional review and not to deny clients access to their money indefinitely. In sum, the Financial Exploitation Prevention Act will equip financial professionals with practical, carefully tailored tools to stop suspected financial exploitation before client assets are lost. By allowing firms to temporarily delay suspicious transactions under defined circumstances, Congress is recognizing the critical role advisors play as the first line of defense against increasingly sophisticated fraud schemes. The Act strikes an appropriate balance between protecting vulnerable investors and preserving individual financial autonomy, while reinforcing collaboration among advisors, families, and law enforcement to combat financial exploitation. The bill now awaits Senate action.

Result

No-Cause Jury Verdict Secured in Wrongful Death Trial

We successfully obtained a no-cause jury verdict in a 13-day wrongful death trial. The decedent, a 59-year-old man, was admitted to the emergency room on February 15, 2019, with complaints of abdominal pain, decreased appetite, and constipation, despite the use of laxatives. The patient did not complain of any nausea, vomiting, or diarrhea. He had a significant medical history including diabetes, hypertension, prior coronary artery stenting, morbid obesity (with past gastric bypass surgery), longstanding ventral hernia, and back pain. A CT scan revealed multiple hernias and a potential closed-loop bowel obstruction, leading to a surgery consultation. Our client, an emergency general surgeon, interpreted that the patient did not have a closed loop or any significant obstruction and recommended non-surgical management. The patient was approved to have clear liquids, and had a vomiting incident shortly after, but our client was not notified. The patient was returned to NPO status, and after improving overnight, he was returned to “clears” and additional medical and renal consults were ordered. Our client did not receive any communications from the residents/nurses of any changes in the patient’s condition. On February 18, 2019, two rapid responses were called due to increased heart rate and vomiting. It is believed that the vomiting resulted in aspiration, causing sepsis, ultimately leading to the patient’s death. During the trial, the plaintiff’s sole medical expert highlighted imaging on the wrong hernia, which called into question all of his opinions in the case. We made key objections related to the expert testimony, limiting what the allegations were, and preventing new allegations from being made. After approximately two and a half hours of deliberating, the jury returned a no-cause verdict. 

Thought Leadership

New Jersey Expands Family Leave Protections Effective July 17, 2026

On January 17, 2026, Governor Murphy signed into law legislation expanding the New Jersey Family Leave Act (NJFLA). Beginning July 17, 2026, significant amendments to the NJFLA will expand job-protected family leave to smaller businesses and more employees across the state. The new law broadens coverage by lowering the threshold for private employers from 30 employees to 15 employees, meaning many smaller businesses will now be subject to the NJFLA. Employees of state and local government agencies will continue to be covered regardless of the size of the employer. The amendments also make it easier for employees to qualify for leave. Under the revised law, an employee will be eligible after three months of employment and at least 250 hours worked during the preceding 12 months, replacing the previous requirement of 12 months of employment and 1,000 hours worked. Currently, New Jersey's Temporary Disability Insurance (TDI) and Family Leave Insurance (FLI) programs provide eligible employees with wage replacement while they are on leave but do not independently guarantee job protection. The recent amendments to the New Jersey Family Leave Act (NJFLA) expand these protections by extending job-protected leave to additional employees. Under the amended law, employees receiving TDI or FLI benefits may be entitled to return to the same position they held before taking leave, or to an equivalent position with the same seniority, status, pay, and benefits. Although the legislation also states that it does not expand or modify an employee's reinstatement rights under the NJFLA, the amendments appear to provide job protection to eligible employees receiving TDI or FLI benefits without requiring them to separately satisfy the eligibility requirements of the NJFLA or the federal Family and Medical Leave Act (FMLA). As a result, some employees may be entitled to longer periods of job-protected leave than were previously available under existing law. With these amendments, New Jersey continues to strengthen workplace protections by expanding access to job-protected family leave for eligible employees. These changes significantly expand access to job-protected family leave and may require employers to update their leave policies, employee handbooks, and HR practices. Notably, employers who were previously not required to administer NJFLA may need to amend their policies and/or create new protocols to come into compliance with the NJFLA. Failure to do so would prove costly, as the penalties for non-compliance are significant.