Mark Paulding

 

Partner, DC Office

(202) 288-9549

mpaulding@infolawgroup.com

LINKEDIN

SCan or CLICK FOR MY VCARD:

 
 
 
 
 

About Mark

Mark Paulding advises clients on data security, privacy, and consumer protection matters. His practice includes conducting privacy and security risk and compliance assessments; development of security programs, policies, and procedures; development of privacy policies and procedures; security incident investigation, response, and reporting; health information privacy compliance under HIPAA and state consumer health data laws; the privacy and security risks raised by AI; and development and implementation of web content accessibility policies and procedures. In addition, Mark assists clients with responses to regulatory inquiries into compliance with federal and state data protection laws, including the FTC Act and CCPA/CPRA.

A significant part of Mark’s practice involves the wave of claims targeting website tracking technologies. These claims rest on federal and state wiretapping statutes, including the California Invasion of Privacy Act, along with pen register and trap and trace theories and the Video Privacy Protection Act. Mark advises clients on their exposure, analyzing how courts are treating allegations that pixels, tracking technologies, and embedded video amount to unlawful interception. He responds to demand letters and arbitration claims, develops litigation strategy, and negotiates the settlement agreements. Mark also advises on the consent management and AdTech decisions that reduce exposure going forward.

Mark builds and reviews information security programs, drafting and assessing security policies, standards, and process documentation. He also advises on gaps, including cyber risk insurance coverage, and reviews the security terms in vendor agreements. He prepares and delivers compliance training for client teams, including AdTech and HIPAA training, and participates in incident response tabletop exercises. When incidents occur, Mark leads the investigation, response, and reporting. He coordinates forensic investigation, analyzes notification obligations under state breach laws, and drafts communications to affected individuals and regulators, whether the incident arose at the client or at one of its service providers.

Mark has counseled clients on health information privacy for many years, across HIPAA and the range of state laws that have developed alongside it. He advises healthcare providers and insurers on HIPAA compliance, building compliance programs, drafting business associate agreements, preparing health data security policies, and developing HIPAA training materials. He also advises the growing number of companies that handle health information without falling under HIPAA, and that are instead subject to state consumer health data laws such as Washington’s My Health My Data Act, and to state medical information statutes including the California Confidentiality of Medical Information Act. That work includes consent mechanisms for collecting health data, state requirements for disclosing medical records to patients, and identifying the sensitive personal information that triggers heightened obligations under state privacy laws.

Mark also advises on the risks and opportunities that AI raises for data security and privacy. He evaluates the security commitments and contractual safeguards in AI vendor agreements, reviews the terms and acceptable use policies attached to enterprise AI tools, drafts template AI contract addenda, and maintains AI risk analyses for clients tracking a changing legal landscape. Mark also counsels clients on biometric privacy, including company policies and template consent forms, and on deployments of facial recognition and facial analysis technology. Those areas increasingly converge, as clients apply AI tools to biometric identifiers and to regulated data such as protected health information.

 
Mark is extremely knowledgeable about privacy matters. He monitors developments and trends in the privacy space closely and is able to bring clarity to novel issues even in the face of ambiguous and, at time, conflicting laws and regulations. His advice is always prompt, thorough and, perhaps most importantly, practical.
— Happy Client

REPRESENTATIVE Experience

  • Preparing privacy policies and terms of use for websites and mobile applications published by a wide variety of organizations.

  • Advising on claims arising from website tracking technologies under federal and state wiretapping statutes, planning litigation strategy, and negotiating the settlement agreements.

  • Advising healthcare providers and insurers on HIPAA compliance, including compliance programs, business associate agreements, and training materials.

  • Counseling companies not covered by HIPAA on state consumer health data laws, including Washington’s My Health My Data Act, and on state medical information statutes including the California Confidentiality of Medical Information Act.

  • Evaluating security commitments in AI vendor agreements and drafting template AI contract addenda.

  • Advising on biometric privacy and deployments of facial recognition and facial analysis technology.

  • Conducting privacy assessments for online and offline businesses, including performing data mapping analyses.

  • Drafting and counseling on data security policies, procedures, and guidelines.

  • Conducting cybersecurity risk assessments and compliance audits.

  • Drafting and negotiating agreements affecting privacy and security of sensitive personal information of consumers and/or employees.

  • Preparing responses to regulatory inquiries under the CCPA and CPRA, including requests concerning the technical implementation of opt-out preference signals.

  • Assisting clients with investigation of data breaches and, when appropriate, notification to government regulators and affected consumers.

  • Counseling clients regarding website accessibility and compliance with the Americans with Disabilities Act and Web Content Accessibility Guidelines.

  • Advising clients that process payment card transactions regarding compliance with PCI-DSS.

  • Counseling clients regarding compliance with the Fair Credit Reporting Act concerning collection and use of consumer information for fraud prevention, identity verification, and assessing creditworthiness.

  • Representing clients in data privacy and consumer protection investigations and enforcement actions by federal and state regulators.

  • Counseling clients regarding compliance with the Computer Fraud and Abuse Act and Wiretap Act, and similar state laws, concerning interception and analysis of information transmitted over private and public networks.

REPRESENTATIVE SPEAKING ENGAGEMENTS and publications

Bad Actors Use AI Too- Security Measures Your Company Should Keep in Mind,” Lexology, July 2023

BAR ADMISSIONS

District of Columbia, 1999
Maryland, 1998 (inactive)

PROFESSIONAL ASSOCIATIONS

International Association of Privacy Professionals (IAPP)

Association of National Advertisers (ANA)

Education

Princeton University, A.B. 1994

Harvard Law School, J.D. 1998