Profile
Devin is the Chair of the Privacy & Data Security group of McNees. He began working on cybersecurity issues in 2005, when he represented banks to recover credit card replacement costs from national retailers who failed to safeguard such information; his clients prevailed in some of the first successful data breach lawsuits in U.S federal courts.
Today, Devin counsels clients on policies and procedures to limit the risk of data exposure events, including developing of data security policies, privacy disclosures, breach response plans, and associated training programs. He regularly advises clients on compliance with federal, state, and international privacy laws, including the EU GDPR. He also helps businesses respond to data breaches, including in rectifying and reporting those events, and in limiting their potential liability for such events.
Devin has earned the Certified Information Privacy Professional designation (CIPP/US) from the International Association of Privacy Professionals, which accredits lawyers and other professionals with knowledge of privacy best practices, information technology issues, and relevant U.S. and international laws.
When he is not working on data security matters, Devin’s practice otherwise is focused on complex commercial litigation, with an emphasis on defending class action lawsuits. He has defended clients from class action claims in areas including civil rights, consumer protection law, and employment practices. He also litigates all manner of other commercial cases on behalf of organizations and individuals.
He maintains an extensive practice in constitutional law, representing municipalities and other government entities, legislators, and media companies with regard to civil rights, First Amendment, and other state and federal constitutional claims.
Since 2010, Devin has been recognized annually as a Pennsylvania “Rising Star” by Super Lawyers, a Thomson Reuters rating service, based on peer recognition and professional achievement. No more than 2.5% of attorneys practicing in the Commonwealth are selected as Rising Stars.
Devin has long been a supporter of free speech causes, and served for six years as the President of the Central Pennsylvania Chapter of the American Civil Liberties Union. He remains a member of the board of that organization. Before joining McNees, he worked in Washington, D.C. for a First Amendment advocacy organization and for a public interest law firm.
Active in the community, Devin has served as a member of the Board of Directors of the Dauphin County Bar Association, and presently serves as Chair of the organization’s Volunteer Lawyers for the Arts program and Vice-Chair of its Equal Professional Opportunity Committee. He also serves on the Board of Directors of the Bridges Society of the United Way of the Capital Region, the East Shore YMCA, and the Harrisburg Parks Foundation. Devin resides in the Midtown neighborhood of Harrisburg.
Devin is admitted to practice in the Commonwealth of Pennsylvania, before the U.S. Courts of Appeals for the Third and Ninth Circuits and in the U.S. District Courts for the Eastern and Middle Districts of Pennsylvania.
EXPERIENCE/REPRESENTATIVE CASES
Some of Mr. Chwastyk’s notable reported cases include:
- Data Security: Represented financial institutions in one of the largest data breach events in history and obtained one of the first appellate court decisions recognizing the right to recover damages resulting from a credit card data security breach. Pa. State Employees Credit Union v. BJ’s Wholesale Club, 533 F.3d 162 (3d Cir. 2008).
- Municipal Litigation: Opposed the City of Harrisburg’s Chapter 9 municipal bankruptcy filing on behalf of its largest municipal creditor; obtained dismissal of the City’s bankruptcy petition and summary disposition of the City’s appeal to the Third Circuit. In re City of Harrisburg, 462 B.R. 510, 2011 Bankr. LEXIS 4920, 2011 WL 6180034 (Bankr. M.D. Pa. 2011).
- Constitutional Litigation: Filed briefs on behalf of county, as amicus curiae, in successful opposition to constitutional challenges to Pennsylvania’s Financially Distressed Municipalities Act (“Act 47”), which imposed state receivership on the City of Harrisburg. Williams v. Corbett, 916 F.Supp.2d 593 (M.D.Pa. 2013); Harris v. Corbett, 2012 U.S. Dist. LEXIS 61354 (M.D.Pa. 2012).
- Constitutional Litigation: Represented Pennsylvania’s legislative leadership, as amicus curiae, in defense of challenges to the constitutionality of Pennsylvania’s Act 13 legislation regarding Marcellus Shale development. Robinson Twp. v. Commonwealth of Pa., 83 A.3d 901 (Pa. 2013).
- Constitutional Litigation: On behalf of the Pennsylvania Senate President Pro Tempore, secured dismissal of constitutional challenges to legislation authorizing taking of property for municipal purposes. Pilchesky v. Rendell, et al., 2011 WL 10844349 (Pa. Commw. 2011).
- Public Interest Litigation: Obtained appellate ruling recognizing rights of a domestic partner to jointly-held property of his decedent partner over objections of the decedent’s family, as administrators of the estate. In re: Estate of DeVoe, 74 A.3d 264 (Pa. Super. 2013).
- Class Actions: Represented a county prison in the defense of a class action filed on behalf of pretrial detainees alleging the prison’s strip search practices violated the Fourth Amendment. Reynolds, et al. v. County of Dauphin, 2007 WL 4772731 (M.D. Pa. 2007).
- Civil Rights Litigation: Successfully defended Hershey Entertainment & Resorts Company in trial court and on appeal from First Amendment and other civil rights claims by protesters alleging a conspiracy by the company and a municipality to suppress protests in the municipality. Cvetko v. Derry Township Police Dep’t, 2009 U.S. Dist. LEXIS 70576 (M.D. Pa. 2009).
- Civil Rights Litigation: Successfully defended civil rights claims brought by a subcontractor against contractor and university regarding bidding and practices on facility construction project. Gross v. Harrisburg University, et al., 487 Fed. Appx. 711 (3d Cir. 2012).
- Intellectual Property Litigation: Represented the licensor of patents for dental products in obtaining arbitration of claims by the licensee for unpaid royalties. D.W. Industries v. Dentsply Int’l, 171 Fed. Appx. 92 (9th Cir. 2006).
- Contract Disputes: Represented a major electronics manufacturer in multi-million dollar breach of contract action regarding purchases of components. Tyco Elecs. Corp. v. Milwaukee Elec. Tool Corp., 2012 U.S. Dist. LEXIS 50816 (M.D.Pa. 2012).
- Intellectual Property Litigation: Represented a regional entertainment company in a preliminary injunction action to enforce its trademark to the term “Harvest” for use in restaurants and food services. Hershey Entertainment & Resorts Company v. David Magrogan Group, LLC, 2014 WL 4720437 (M.D.Pa. 2014).
- Contract Disputes: Successfully represented a university in district court and on appeal in defense of breach of contract claims brought by a student expelled from a graduate program. Kimberg v. University of Scranton, 411 Fed. Appx. 473 (3d Cir. 2010).
- Intellectual Property Litigation: Represented a pharmaceutical company in the defense of trademark claims. Ameritox, Ltd. v. Medytox Labs, LLC, 2013 U.S. Dist. LEXIS 86729 (M.D.Pa. 2013).
- Contract Disputes: Obtained summary judgment and appellate decision in favor of an insurance company against claims by agents for commission payments. Ryncavage v. Am. Family Life Ins. Co., 293 Fed. Appx. 122 (3d Cir. 2008).
- Defamation Litigation: Defended doctors and hospital employees in a defamation action brought by the hospital’s former CEO.
- Collections Litigation: Secured appellate affirmation of judgment for an equipment manufacturer entitled to insurance proceeds on its collateral in the bankruptcy proceedings of the borrower. Selective Way Ins. Co. v. John Deere Const. & Forestry Co., 2009 WL 3400983 (M.D.Pa. 2009).
- Contract Disputes: Obtained appellate decision affirming dismissal of civil conspiracy claims against an insurance company arising out of the denial of worker’s compensation claims. Waters v. Comp Services, Inc., 898 A.2d 697 (Pa.Cmwlth. 2006).
- Civil Rights Litigation: Successfully defended national automobile lender in defense of Truth-In-Lending Act claims by borrower. Kuenzi v. Capitol One Auto Finance, 2009 WL 1872599 (E.D.Pa. 2009).
EDUCATION
The Pennsylvania State University, B.A., 1999
Georgetown University Law Center, J.D., 2003, cum laude, Georgetown Journal of International Law
Certified Information Privacy Professional, CIPP/US, 2016
HONORS/AWARDS
Dauphin County Bar Association’s Hon. John F. Cherry Award, 2024
Pennsylvania Rising Stars®, 2010-present
MEMBERSHIPS
Dauphin County Bar Association, Board of Directors, 2015-2018
Dauphin County Bar Association, Equal Professional Opportunity Committee, Vice Chair, 210-present
Dauphin County Bar Association, Volunteer Lawyers for the Arts, Chair, 2015-present
Pennsylvania Bar Association, Cybersecurity and Data Privacy Committee, 2018-present
Federal Bar Association, 2018-present
United Way of the Capital Region, Bridges Society – Board member, 2010-present.
American Civil Liberties Union, Central Pennsylvania Chapter – President, 2006-2013; Board member, 2004-present
YMCA, East Shore Board of Managers, 2018-present
Technology Council of Central Pa., Board Member, 2020-present
Harrisburg Park Foundation, Board Member, 2019-present
William W. Lipsitt American Inn of Court, Dauphin County, Pa., Barristoer
Wilkinson-Campbell Inn of Court, Centre County, Pa.
COURT ADMISSIONS
PA Supreme Court
U.S. Court of Appeals for the Ninth Circuit
U.S. Court of Appeals for the Third Circuit
U.S. District Court – Eastern District of Pennsylvania
U.S. District Court – Middle District of Pennsylvania
Bar Admissions
Pennsylvania
PUBLICATIONS
February 21, 2023 - Amendments to Pennsylvania’s Data Breach Notification Law Expand Notification Obligations, Bring New Scrutiny for Municipalities and Government Contractors
The Legal Intelligencer
November 18, 2022 - Imminent and Substantial: The Third Circuit Holds That the Leak of Personal Information onto the Dark Web is Sufficient to Establish an “Injury-In-Fact”
McNees Labor & Employment Law Blog
September 7, 2022 - Lessons Learned on Privacy Compliance from the Enforcement Action Against Sephora
McNees Privacy & Data Security Alert
September 6, 2022 - First CCPA Enforcement Action Provides Lessons on Privacy Compliance
The Legal Intelligencer
February 25, 2022 - Key Privacy and Cybersecurity Issues for Sellers in M&A Transactions
The Legal Intelligencer
November 16, 2021 - Another Day, Another Jurisdiction: China Is Most Recent to Enact Sweeping Privacy Regulation
The Legal Intelligencer
September 6, 2021 - Becoming a Cybersecurity or Privacy Lawyer: Tips for Young Attorneys
The Legal Intelligencer
June 9, 2021 - U.S. Supreme Court Emphasizes Need to Couple IT Safeguards with Written Policies to Safeguard Confidential Data
McNees Labor & Employment Law Blog
April 26, 2021 - Following Calif.'s Lead, Data Privacy Laws Reach East Coast
The Legal Intelligencer
September 3, 2020 - Charges From Botched Data Breach Responses Put the Heat on Corporate Execs
The Legal Intelligencer
April 24, 2020 - New State Laws Set National Standards for Privacy and Data Security
The Legal Intelligencer
February 24, 2022 - Defining Reasonable Care for the Protection of Personal Data
The Legal Intelligencer
October 8, 2019 - New Nevada Privacy Law Requires Attention of Businesses and Websites Nationwide
McNees Privacy & Data Security Alert
October 1, 2019 - Ransomware Attacks Targeting Municipalities
Borough News
June 24, 2019 - Ransomware Attacks Targeting Cities and Municipalities
McNees Privacy & Data Security Alert
April 18, 2019 - McNees Litigation News
Copyrighting Your Body, Revenge Pornography, and Safeguarding Employees' Information
November 8, 2018 - A Data Security Plan Will Protect Your Company from Liability: New Ohio Cybersecurity Law Creates “Safe Harbor” from Data Breach Claims
Privacy & Data Security Alert
August 3, 2018 - State agencies becoming cyber targets
Central Penn Business Journal
June 29, 2018 - Sweeping Privacy Legislation Hits the United States
McNees Privacy & Data Security Alert
June 14, 2018 - IT'S NOT TOO LATE: We can help your business comply with the EU General Data Protection Regulation (GDPR)
McNees Privacy & Data Security Alert
June 1, 2018 - No Excuses: GDPR Ups Ante on Accountability and Risk
Corporate Counsel Business Journal
May 29, 2018 - Law firm cybersecurity 'an imperative' as clients make demands clear
Pittsburgh Post-Gazette
May 21, 2018 - Law firm cybersecurity 'an imperative' as clients make demands clear
The Legal Intelligencer
April 4, 2018 - Atlanta Cyberattack Shows Importance of Cybersecurity for Municipalities
McNees Privacy & Data Security Alert
March 14, 2018 - GDPR Primer For Universities
McNees Education Law Update
March 13, 2018 - GDPR IS HERE: HOW EU PRIVACY REGULATIONS IMPACT U.S. BUSINESSES
October 27, 2017 - What’s Worse Than Getting Phished? Getting Whaled: Five ways company execs can avoid the harpoon
Metropolitan Corporate Counsel
August 16, 2017 - DOE Imposes Data Security Requirements on Colleges and Universities
McNees Privacy & Data Security Alert
July 11, 2017 - McNees Advocate Alert
McNees Advocate Alert Newsletter
May 19, 2017 - Avoiding Consumer Class Actions after Spokeo
March 15, 2017 - Three Lessons All Companies Can Learn from the Data Breaches that Cost Yahoo $350 Million
McNees Privacy & Data Security Alert
March 8, 2017 - Cybersecurity Threats Facing the Trucking Industry, Penntrux
PA Motor Truck Association
February 2, 2017 - Data Privacy Day brings reminder that businesses should require encryption on laptops and mobile devices
January 31, 2017 - Post-'Spokeo' Standing for Consumer Class Actions a Struggle
The Legal Intelligencer
December 13, 2016 - What to Know About Cyber Crime and Pennsylvania Law
Central Penn Business Journal
October 28, 2016 - October is National Cybersecurity Awareness Month!
October 20, 2016 - Vehicle Dealerships Must Take Steps To Avoid Data Breaches
Pennsylvania Automotive Association
October 5, 2016 - New York’s Proposed Cybersecurity Regulations Impose New Compliance Requirements on Financial Institutions and Insurance Companies
September 1, 2016 - Dropbox.com: Change Passwords Immediately
McNees Privacy & Data Security Alert
August 1, 2016 - If Your Company Receives EU Citizens’ Personal Data, Privacy Shield Self-Certification Is Now Open – And the Clock is Ticking on Compliance Grace Period
July 11, 2016 - Reasonable Accommodation in Cyberspace
Metropolitan Corporate Counsel
June 30, 2016 - A Wealth of Information: Data Security and Local Governments
Municipal Lawyer: The Journal of Local Government Law
April 12, 2016 - Cybersecurity Threats Pose Big Risks for Local Governments
The Legal Intellegencer
April 1, 2016 - Law firms among businesses testing the cybersecurity waters
Central Penn Business Journal
March 23, 2016 - Using app to secretly record conversation a violation of wiretapping law, state SC rules
PennRecord
February 9, 2016 - Courts Send Mixed Messages on Standing for Plaintiffs in Data Breach Litigation
Metropolitan Corporate Counsel
December 19, 2015 - McNees Insights - Estate Planning
In this issue: Year End Tax Planning l Safeguard Your Finances From Online Threats
September 19, 2015 - All Businesses Have to Protect Against Data Breaches
Times Leader
September 10, 2015 - Ashley Madison Breach Another Warning To Companies
August 27, 2015 - 3rd Circuit Says: FTC Can Take Action Against Companies That Suffer Data Security Breaches
June 4, 2015 - Even Small Businesses Need To Pay Attention To Data Security
SPEAKING ENGAGEMENTS
November 8, 2024 - Navigating the AI Hype Cycle
April 25, 2024 - Digital Advertising – Using adtech while avoiding liability through effective website privacy notices
October 27, 2023 - Cyber Risk is a Business Risk
September 14, 2023 - Big University 2023
May 16, 2023 - Cyber Insurance and Data Breach Response 101
May 26, 2022 - Pennsylvania Legislative Update
March 24, 2022 - Developments in U.S. State Privacy & Breach Notification Laws
October 26, 2021 - McNees Privacy and Data Security Chair to Guide Young Attorneys, Practicing Lawyers
September 9, 2021 - Cyber Threat Awareness and Mitigation
October 19, 2020 - Central Keystone Valley HR Professionals’ 2020 Labor & Employment Law Conference
October 15, 2020 - Cybersecurity Terms for Contracts
September 24, 2020 - Cyber Security Strategies for Onsite and Remote Workers
August 12, 2020 - Cybersecurity Risks Associated with Telework
June 10, 2020 - Cyber Security, Ransomware and Digital Ethics
May 1, 2020 - Cybersecurity Risks of Remote Work During COVID-19
April 30, 2020 - Coronavirus: Managing the Privacy & Cybersecurity Risks
April 14, 2020 - Cybersecurity Roundtable Webinar
February 20, 2020 - Assessing Your Cyber Security Risk
March 5, 2020 - Cybersecurity and Privacy in 2020: Risks, Trends, and Preparing for Disaster
October 7, 2019 - 2019 Cybersecurity Summit
October 30, 2019 - Corporate Leadership Symposium: Navigating Challenges and Seizing Opportunities
September 9, 2019 - Data Breaches: Emerging Legal Issues
August 22, 2019 - Cyber Security Panel Workshop
July 25, 2019 - Is the Internet of Things (IOT) the End of Privacy as We Know It?
April 25, 2019 - Pennsylvania Supreme Court data breach case Dittman v. UPMC
February 27, 2019 - McNees Attorneys to Moderate Roundtable Discussion on Recent PA Supreme Court Data Breach Case
May 31, 2018 - Contracts and Technology Considerations
May 24, 2018 - Ethics Panel: Ethics and Technology
May 17, 2018 - Ransomware Mitigation: Going Through It Step-by-Step
May 10, 2018 - Cybersecurity: Emerging Legal Issues
May 4, 2018 - Cybersecurity Risks to County Governments: Case Studies and Lessons Learned
April 20, 2018 - McNees Attorney to Present the Impact of Employment Laws on Credit Union Data Security
October 14, 2017 - IMLA 82nd Annual Conference
September 15, 2017 - Complying with HIPAA Privacy Rules and HITECH Security Audits
August 9, 2017 - Navigating the Interrelationship Between Employment Law and Data Security
July 12, 2017 - Cyber Security: Protecting Yourself and Client Transcript Files
May 12, 2017 - PennAg Cybersecurity Symposium
April 26, 2017 - York Business Breakfast
April 25, 2017 - Cyber Wargames
May 4, 2017 - The Interrelationship Between Data Security and HR Policies
January 13, 2017 - McNees Attorneys to present a Cyberattack Simulation at the Cyber Security for Small and Mid-Size Businesses Seminar
October 27, 2016 - Cyber Security Symposium
December 13, 2016 - Cybersecurity for Lawyers and Law Firms
November 22, 2016 - Data Security for Small Businesses
October 25, 2016 - A Strategic Approach to Safeguarding Your Company’s Data
October 25, 2016 - Cybersecurity for Townships
October 20, 2016 - A Strategic Approach to Safeguarding Your Company’s Data
October 19, 2016 - Central Pennsylvania Business Leaders Summit
October 17, 2016 - Cybersecurity: Legal Risks and Solutions for County Governments
July 19, 2016 - 20Cyber Security in the Healthcare Sector
April 16, 2016 - Cybersecurity Issues for Municipal Governments
March 30, 2016 - Safe Harbor, Privacy Shield, and the Future of European Data Privacy Laws
May 7, 2015 - 2015 Annual Information Technology Security Conference: Knowing Your Adversary and Defeating the Threat
March 8, 2015 - McNees Attorney Devin Chwastyk presented "The Legal Landscape for IT: E-Discovery, Data Security, and Privacy Issues" at the Pennsylvania Chamber of Business & Industry IT Security Conference
May 7, 2015 - E-Discovery: Best Practices and Breaking Trends
January 25, 2012 - E-Discovery: Best Practices and Breaking Trends
WEBINARS
November 17, 2022 - Cyber Risk is a Business Risk
October 27, 2022 - Cyber Liability Has Changed: Impacts to Your Strategy & Budget
February 24, 2021 - Cybersecurity and Privacy Compliance for PA School Solicitors
January 7, 2021 - Cybersecurity Essentials
October 30, 2020 - Cybersecurity Leadership and Innovation Forum
October 22, 2020 - Small Businesses Are Big Targets For Ransomware Attacks
June 17, 2020 - Chamber LIVE: Road to Reopening
June 18, 2020 - Understanding The Cybersecurity Impacts And Risks Of COVID-19 On Your Business And Remote Workers
April 16, 2020 - How to Stay Safe From Cybercriminals Capitalizing on the COVID-19 Uncertainty - Webinar
April 14, 2020 - Cybersecurity Roundtable Webinar
March 26, 2020 - Cybersecurity for Remote Work during the Covid-19 Crisis
May 8, 2019 - Dittman v. UPMC - PA Supreme Court Requires Employers to Safeguard Personal Information - Webinar
September 26, 2018 - PCI Compliance with Small Business Update
May 16, 2018 - The EU General Data Protection Regulation (GDPR): What It Means for US Businesses - Webinar
May 18, 2017 - Cyberattack! Are You Ready?
March 22, 2017 - Cybersecurity for Auto Dealerships
SEMINARS
April 21, 2023 - PA Changed Its Laws and Local and State Agencies are in the Crosshairs Are You Ready?
March 5, 2020 - Cybersecurity and Privacy in 2020: Risks, Trends, and Preparing for Disaster
October 8, 2019 - McNees, Murphy McCormack Capital Advisors and Brown Schultz Sheridan & Fritz to Host Joint Seminar
September 7, 2018 - Esports Seminar
November 7, 2017 - Business Leaders Summit
January 24, 2017 - Cyber Security for Small & Mid-Size Businesses
November 22, 2016 - Labor Law Seminar
October 27, 2016 - Cyber Security for Small & Mid-Size Businesses
June 15, 2016 - Lawyer, Heal Thyself! How Should Law Firms Address Cybersecurity Risks?