Photo of Kathryn Rattigan

Kathryn Rattigan is a member of the Business Litigation Group and the Data Privacy+ Cybersecurity Team. She concentrates her practice on privacy and security compliance under both state and federal regulations and advising clients on website and mobile app privacy and security compliance. Kathryn helps clients review, revise and implement necessary policies and procedures under the Health Insurance Portability and Accountability Act (HIPAA). She also provides clients with the information needed to effectively and efficiently handle potential and confirmed data breaches while providing insight into federal regulations and requirements for notification and an assessment under state breach notification laws. Prior to joining the firm, Kathryn was an associate at Nixon Peabody. She earned her J.D., cum laude, from Roger Williams University School of Law and her B.A., magna cum laude, from Stonehill College. She is admitted to practice law in Massachusetts and Rhode Island. Read her full rc.com bio here.

AI governance is often treated as a policy problem: define approved uses, create an oversight framework, publish acceptable use rules, and document compliance. These steps matter, especially as increasingly more regulations are introduced that raise expectations for accountability, transparency, data governance, and lifecycle risk management. However, the harder question for many organizations is no longer

California’s privacy regulator just sent a clear message to the data broker ecosystem: compliance failures will be viewed across both the California Consumer Privacy Act (CCPA) and the Delete Act. The California Privacy Protection Agency (CPPA) announced a $116,490 settlement with LocateSmarter LLC, an Iowa-based company that allegedly operated as a data broker without registering

The California Consumer Privacy Act’s (CCPA) cybersecurity audit requirement marks a significant shift in privacy and security accountability. Beginning January 1, 2027, covered businesses will need to complete annual, independent, evidence-backed cybersecurity audits showing that their privacy and security controls are not only designed appropriately, but operating effectively over time. For many companies, this will

Recent privacy litigation against Shopify and the NBA highlights a shared theme: companies may face risk not only for what their websites say about privacy choices, but for how embedded technologies actually collect data behind the scenes.

In the Shopify case, a California federal court refused to dismiss claims alleging that Shopify collected California consumers’

AI-enabled mental health tools are moving quickly from novelty to mainstream use, and regulators are starting to draw sharper lines around what those tools can and cannot claim to do. Recent lawsuits against Character Technologies Inc.,  the company behind Character.ai, allege that the platform hosted bots that mimicked licensed therapists, including one persona that allegedly

A new California federal lawsuit against AI notetaking provider Granola highlights a growing privacy risk for companies using meeting transcription tools: consent cannot be an afterthought. According to the complaint, Granola’s software allegedly recorded a virtual meeting participant without giving notice that an AI notetaker was present or seeking permission to record. The plaintiff claims

Sony smart TV owners have voluntarily dropped their proposed class action against Samba TV, an analytics company accused of collecting and selling television-viewing information to third-party advertisers in violation of state and federal privacy laws. DellaSalla v. Samba TV, Inc., No. 3:25-cv-03470 (N.D. Cal. 7/23/26).The dismissal came after the federal court had already allowed several

The White House is moving closer to a voluntary framework under which AI companies would submit their most advanced models to the federal government before public release. The White House’s Office of the National Cyber Director reportedly circulated the draft framework by to OpenAI, Anthropic, and Google, and those companies jointly submitted edits. Although the review

California’s privacy regulator has launched its first-ever audit, signaling a new phase of active oversight under the California Consumer Privacy Act (CCPA) and its amendments. The California Privacy Protection Agency (CPPA) is focusing on delivery and transportation apps in the gig economy, examining how platforms collect and use personal information from both consumers and workers

California’s SB 361 expands California’s Delete Act and will soon require registered data brokers to regularly check California’s data deletion database, known as DROP, to determine whether a California consumer has requested deletion of their personal information. Beginning August 1, 2026, data brokers must access DROP at least every 45 days and, when a request