Mark H. Francis
Partner

Overview
Mark H. Francis is a leading cybersecurity, data privacy and intellectual property attorney who leverages extensive technical skill and experience to provide clients with pragmatic legal guidance across a wide array of counseling, transactional and litigation matters.
Mr. Francis has received significant recognition for his practice, and has been appointed to the U.S. Department of Homeland Security (DHS) Data Privacy and Integrity Advisory Committee (DPIAC), which provides advice at the request of the Secretary of Homeland Security and the DHS Chief Privacy Officer on programmatic, policy, operational, administrative and technological issues within the DHS that relate to personally identifiable information, as well as data integrity and other privacy-related matters. He is also an active member of the International Association of Privacy Professionals (IAPP), and currently serves on the IAPP Certification Advisory Board.
With a subject matter focus on "tech and data" issues, Mr. Francis provides risk-oriented advice and representation to clients across the following areas:
Counseling. Mr. Francis focuses on data strategy, cybersecurity, risk assessments, policy development, technical controls, cross-border data transfers, data privacy laws, cookie tools, advertising technology (AdTech), data analytics, quantum computing and information governance (including records retention and defensible disposition). In that capacity, Mr. Francis advises clients on:
- Federal laws, including Federal Trade Commission (FTC) Section 5 requirements (unfair and deceptive practices), Gramm-Leach-Bliley Act (GLBA), Health Insurance Portability and Accountability Act (HIPAA), Fair Credit Reporting Act (FCRA), Children's Online Privacy Protection Act (COPPA), Video Privacy Protection Act (VPPA), the Controlling the Assault of Non-Solicited Pornography And Marketing (CAN-SPAM) Act of 2003, and the Telephone Consumer Protection Act (TCPA)
- State privacy and security laws, including the California Consumer Privacy Act (CCPA), Virginia Consumer Data Protection Act (VCDPA), Colorado Privacy Act (CPA), Washington My Health My Data Act (MHMD), New York SHIELD Act, Massachusetts 201 CMR 17.00 and a variety of educational technology (EdTech), student privacy and data breach notification laws
- International laws, including the EU General Data Protection Regulation (GDPR), Canada Personal Information Protection and Electronic Documents Act (PIPEDA), and Brazil Lei Geral de Proteção de Dados (LGPD)
- Industry standards and frameworks, including the Payment Card Industry Data Security Standard (PCI DSS), card brand operating regulations, AdTech industry practices, National Institute of Standards and Technology (NIST), International Organization for Standardization (ISO) standards, and other related legal and regulatory requirements
Mr. Francis regularly advises clients on the adoption of emerging technologies such as artificial intelligence and machine learning (AI/ML) with pragmatic approaches to ethical AI principles, legal and reputational risk mitigation practices, due diligence and contracting.
Artificial Intelligence (AI) Risk Management. Mr. Francis regularly advises clients on the adoption of emerging technologies such as AI and machine learning (ML) with pragmatic approaches to legal and reputational risk mitigation practices, including: 1) AI governance programs addressing the adoption of ethical principles, product policies, diligence in acquisitions and procurement, and incident response, 2) supplier and customer contracting with AI technology, 3) addressing evolving AI laws, regulatory guidance and industry standards and 4) managing employee use of AI tools such as ChatGPT and Microsoft Copilot.
Tech Agreements and Corporate Transactions. Mr. Francis routinely advises clients on complex data and intellectual property agreements and technology transactions, including large-scale master service agreements (MSAs), statements of work (SOWs), data processing agreements (DPAs), open source and proprietary software licenses, AI/ML licensing, IP/data transfers and licenses, e-commerce platforms, software as a service (SaaS) and other cloud services agreements. He also works with deal teams on data and technology due diligence, risk assessments and representations in mergers and acquisitions (M&A) transactions.
Crisis Management and Incident Response. Mr. Francis has counseled clients in responding to a wide spectrum of cyberattacks and other security incidents such as data breaches, cloud/vendor incidents, ransomware, insider threats and wire fraud across a number of industries, including healthcare, financial services, retail, technology, consulting, industrial and telecommunications. He advises clients on internal and forensic investigations, regulatory and individual notifications and interactions with law enforcement and other third parties.
Cybersecurity and Data Privacy Litigation and Regulatory Actions. Mr. Francis represents clients in regulatory and state attorney general investigations, PCI assessments, and arbitrations, class actions or other civil disputes relating to alleged data breaches, data misuse incidents or other allegations involving the privacy or security of personal information.
Intellectual Property Counseling and Litigation. Mr. Francis represents clients in a wide range of intellectual property (IP) disputes and litigation. Many of his IP matters have involved complex technologies such as wired and wireless communications, cloud computing, mobile operating systems, virtual machines, web browsers, encryption, image processing and semiconductor devices. He is a registered patent attorney with the U.S. Patent and Trademark Office and assists clients with patent prosecution, as well as copyright and trademark procurement.
Mr. Francis is an International Information System Security Certification Consortium (ISC)2 Certified Information Systems Security Professional (CISSP) and EC-Council Certified Ethical Hacker (CEH). He is also an IAPP Certified Information Privacy Professional/United States (CIPP/US), IAPP Privacy Law Specialist (PLS), IAPP Fellow of Information Privacy (FIP) and IAPP Artificial Intelligence Governance Professional (AIGP). He has also received a number of cloud services and artificial intelligence certifications.
In addition, Mr. Francis is an accredited attorney for the preparation, presentation and prosecution of claims for veterans' benefits before the U.S. Department of Veterans Affairs (VA).
Representative Experience
Credentials
- Fordham University School of Law, J.D.
- Fordham University, MBA
- City University of New York, B.S.
- New Jersey
- New York
- U.S. Court of Appeals for the Federal Circuit
- U.S. Court of Appeals for the Third Circuit
- U.S. District Court for the Southern District of New York
- U.S. District Court for the Eastern District of New York
- U.S. District Court for the Northern District of New York
- U.S. District Court for the District of New Jersey
- U.S. District Court for the District of Colorado
- U.S. District Court for the Eastern District of Texas
- U.S. Patent and Trademark Office
- International Association of Privacy Professionals (IAPP), Training Advisory Board, 2017-2018; CIPP/US Exam Development Board, 2020-2022; Certification Advisory Board, 2023-2025
- InfraGard, New York Metro InfraGard Members Alliance, Board of Directors, 2018-2021; Governance Committee Chair, 2020-Present
- International Information System Security Certification Consortium (ISC)²
- EC-Council
- The Legal 500 USA, Media, Technology and Telecoms – Cyber Law (Including Data Privacy and Data Protection), 2024
- Meeting the Challenge Award, InfraGard National Members Alliance, 2022
- Holland & Knight Pro Bono All-Star, 2020
- Rising Stars, New York Super Lawyers magazine, 2015-2017
- Nathan Burkan Memorial Award, Fordham University School of Law, 2006