Andrew Lewis, CIPP/US, is an attorney in the firm's privacy and security group. He has broad litigation and counseling experience, drawing on years of representing some of the largest technology, retail, and media companies in the country to provide exceptional counsel to clients on all matters regarding cybersecurity, privacy, incident response, and related investigations.
Andrew specializes in advising cloud service providers and technology companies on strategies to identify and mitigate their most complex information security challenges, including drafting written information security policies, incident response plans and policies, data classification policies, and cybersecurity standards, as well as advising clients on incident response handling, including pre-breach tabletop exercises and post-breach investigations and notification requirements.
An effective solutions-oriented attorney, Andrew has broad knowledge of data security laws and regulations and provides practical, actionable advice on compliance requirements related to information security and data privacy laws and frameworks in the United States and abroad, including the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) and implementing regulations issued by the Cybersecurity & Infrastructure Security Agency (CISA); the California Consumer Privacy Act (CCPA) and its cybersecurity audit regulations; the Gramm-Leach-Bliley Act (GLBA), including the Consumer Financial Protection Bureau's (CFPB) Regulation P and the Federal Trade Commission's (FTC) Safeguards Rule; the Communications Act and regulations issued by the FCC; the Health Insurance Portability and Accountability Act (HIPAA) and its implementing rules; Executive Order 14028 (Improving the Nation's Cybersecurity); the NYDFS Cybersecurity Regulation; the Payment Card Industry Data Security Standard (PCI DSS); the European Union's NIS2 Directive; Digital Operational Resilience Act (DORA) and Cyber Resilience Act (CRA); and state privacy, data breach, and data security laws.
Andrew also works closely with federal and state contractors on information security and privacy requirements for procurement programs, including requirements of the Federal Risk and Authorization Management Program (FedRAMP), StateRAMP, the Cybersecurity Maturity Model (CMMC), the Federal Acquisition Regulation (FAR), the Defense Federal Acquisition Regulation Supplement (DFARS), and special publications by the National Institute of Standards and Technology (NIST).
Andrew regularly advises companies on information security and privacy risks related to mergers and acquisitions, including companies looking to acquire FedRAMP authorized services.
Also trained in economics, political science, and public policy, Andrew was an intern on Capitol Hill in Washington, D.C., and worked in legal and judicial consulting before practicing law.
Admitted to Practice
-
California, 2014
-
U.S. District Court, Northern District of California
-
U.S. District Court, Eastern District of California
-
U.S. District Court, Western District of Texas
Education
-
J.D., University of Pennsylvania Law School, 2014
-
B.A., Economics and Political Science, University of California, Los Angeles, 2009
-
Certificate in Management, University of Pennsylvania, Wharton School
Memberships & Affiliations
-
- International Association of Privacy Professionals
- UCLA Center for American Politics and Public Policy, Washington, D.C.
Professional Recognition
-
- Named "One to Watch" by Best Lawyers in Commercial Litigation, 2021-2026
Background
-
- Associate, Fenwick & West LLP, San Francisco, 2020-2023
- Associate, Morgan, Lewis & Bockius LLCP, San Francisco, 2014-2020
- Research Assistant, Trial-Partners Inc., Los Angeles, 2009-2011
- Intern, Sen. Dianne Feinstein, Washington, D.C., 2007-2008