Gregory T. Parks
For more than 25 years, Gregory T. Parks has helped companies navigate cyber incidents, ransomware attacks, data breaches, privacy crises, compliance needs, and related litigation and regulatory proceedings. Greg brings practical judgment and calm, clear communication to these matters. He advises boards of directors, chief executive officers, chief legal officers, senior in-house legal teams, chief information security officers, and business leaders. During an incident, Greg works with forensic experts, recovery specialists, negotiators, insurers, and communications professionals to manage the matter from the first minutes through regulatory investigations, class action litigation, recovery efforts, and resolution.
Greg has advised on more than 3,000 data security incidents for organizations across the retail, healthcare, financial services, technology, education, insurance, and other industries. His experience includes leading the response to a major healthcare data security incident and a major retail payment card incident. In those and other significant matters, he has directed crisis response and forensic investigations, advised boards and senior management, developed notification and communications strategies, managed regulatory inquiries, defended multiple class actions, pursued and defended substantial cost-recovery claims, and negotiated complex litigation and regulatory resolutions.
Greg is also an active first-chair litigator who regularly defends data breach and privacy class actions, consumer and financial institution claims, and other litigation arising from cybersecurity incidents, privacy practices, and consumer-facing business operations. He handles all phases of these and other types of litigation, including early case assessment, motions to dismiss, class certification, discovery, expert proceedings, summary judgment, trial, settlement, and appeal. His broader litigation practice includes consumer protection, retail, payment card, advertising, loyalty and gift card, and other complex commercial and class action matters.
That litigation experience informs Greg’s advice from the outset of an incident. He helps clients assess how decisions concerning investigation scope, containment, remediation, notification, public communications, and affected individuals are likely to be scrutinized months or years later in litigation and regulatory proceedings. His practice sits at the intersection of cybersecurity, privacy law, crisis management, and litigation, with a focus on helping clients make practical and defensible decisions while remaining calm under intense time pressure.
Clients rely on Greg for clear-eyed risk assessment, calm leadership, and practical advice that accounts for legal obligations, operational realities, enterprise value, and reputation. He regularly handles regulatory investigations and enforcement matters, disputes with vendors and other responsible parties, insurance and contractual recovery issues, and governance questions arising from data security and privacy events.
Greg also advises companies on the design and implementation of privacy and cybersecurity compliance programs. He has assisted more than 1,000 companies with compliance under US state consumer privacy laws, including the California Consumer Privacy Act (CCPA), Virginia Consumer Data Protection Act (VCDPA), Colorado Privacy Act (CPA), and Connecticut Data Privacy Act (CTDPA); the European Union’s General Data Protection Regulation (GDPR); state data breach notification laws; Fair Credit Reporting Act (FCRA); Telephone Consumer Protection Act (TCPA); CAN-SPAM Act; Children’s Online Privacy Protection Act (COPPA); Payment Card Industry Data Security Standard (PCI DSS); and other global, federal, state, and local requirements.
A longtime leader of the Morgan Lewis retail and ecommerce industry team, Greg also counsels retailers and other consumer-facing companies on advertising and marketing, loyalty and gift card programs, payment systems, pricing, loss prevention, consumer protection, and related litigation.
Results may vary depending on your particular facts and legal circumstances.
- Led more than 3,000 data security incident response matters, ranging from isolated compromises involving a single individual to enterprise-wide breaches affecting thousands of systems and more than 100 million individuals, advising clients from the first minutes of an incident through forensic investigation, containment, remediation, notification, regulatory scrutiny, communications, class action and other litigation, cost recovery, and final resolution
- Led the response to a major healthcare data security incident, including coordinating the forensic investigation and crisis response, advising the board of directors and senior management, developing notification and communications strategies, responding to regulatory investigations, defending multiple class actions, and addressing complex cost-recovery, litigation, and settlement issues
- Led the response to a major retail payment card data security incident, including advising the board of directors and senior management, overseeing the forensic investigation and remediation, managing public and regulatory communications, defending consumer and financial institution class actions, pursuing recoveries from responsible parties, and negotiating related litigation and settlements
- Defended more than 100 data breach class actions arising from data security incidents, obtaining wins on motions to dismiss, defeating class certification motions, or resolving matters for less than anticipated future defense costs
- Obtained a defense verdict in a six-week jury trial of a premises liability case at a major retailer’s flagship New York store in which the plaintiff sought $25 million
- Obtained a $6.4 million jury verdict and judgment for a venture capital company that sold its interest in a number of related companies and then faced an indemnity/escrow claim from the purchaser
- Obtained complete indemnity from a supplier for a Top 10 retailer against an $80 million claim for alleged violations of the Fair Credit Reporting Act in the conduct of criminal background checks
- Won motions to dismiss or settled more than three dozen lawsuits under the Fair and Accurate Credit Transactions Act (FACTA) for information printed on credit card receipts provided by retail companies at the point of sale
- Obtained favorable settlements of more than 300 consumer class actions, in which the costs of the settlement were less than 20% of the liability or costs of defense the company faced
- Obtained motion to dismiss a claim under the Fair Credit Reporting Act by arguing that the source of a criminal background check was not a consumer reporting agency
- Obtained complete indemnity for three retailers accused of using illegal technologies on their ecommerce websites to track website visitors
- Obtained motions to dismiss or convinced the plaintiff’s lawyers not to bring more than 20 lawsuits accusing retailers of collecting information at the point of sale in credit card transactions that is prohibited by state law
- Obtained settlement of allegations of systemic pricing inaccuracy by a major retailer across the state of California
- Obtained $3.6 million judgment in favor of a retailer against a shopping center landlord who failed to carry out various development obligations
- Secured motion to dismiss a trademark infringement and license dispute on behalf of the holder of a world-famous trademark
- Won a motion to dismiss after oral argument on an $80 million claim against a trustee in a mortgage securitization
- Obtained a $25 million judgment in a bench trial arising from the acquisition of subprime mortgage assets
Results may vary depending on your particular facts and legal circumstances.
- University of Pennsylvania Law School, 1997, J.D., cum laude
- Bucknell University, 1994, B.A., cum laude
- Pennsylvania
- New Jersey
- US Court of Appeals for the Second Circuit
- US Court of Appeals for the Third Circuit
- US Court of Appeals for the Ninth Circuit
- US District Court for the Eastern District of Pennsylvania
- US District Court for the Middle District of Pennsylvania
- US District Court for the Western District of Pennsylvania
- US District Court for the Northern District of Illinois
- US District Court for the Central District of Illinois
- US District Court for the Eastern District of Wisconsin
- US District Court for the District of Colorado
Incident Response Elite, Cybersecurity Docket (2026)
500 Leading Global Cyber Lawyers, Incident Response and Cybersecurity, Lawdragon (2024–2026)
Recognized, Privacy and Data Security Law, The Best Lawyers in America (2023–2025)
Recommended, Cybersecurity, Incident Response and Privacy, The Legal 500 US (2026)
Recommended, Data Index, Lexology (2026)
Recommended, Media, Technology and Telecoms: Cyber Law (including Data Privacy and Data Protection), The Legal 500 US (2019–2023, 2026)
Recommended, Dispute Resolution: General Commercial Disputes, The Legal 500 US (2018)
Listed, BTI Consulting Group, Client Service All-Star (2020)
Law360, Retail and eCommerce MVP (2014–2015)
Member, American Bar Association
Member, Philadelphia Bar Association
Member, International Association of Privacy Professionals
Fellow, Temple University’s Academy of Advocacy
No aspect of this advertisement has been approved by the Supreme Court of New Jersey. A description of the selection methodology for the above awards can be found here.