A proposed class action accusing Kenneth Cole Productions, Inc., of unlawfully sharing website visitor data with Meta, Google, and other third parties was voluntarily dismissed in the Northern District of California. The plaintiffs alleged that Kenneth Cole used third-party tracking tools on its website that allowed those companies to collect data about consumers’ interactions with the
Kathryn Rattigan
Kathryn Rattigan is a member of the Business Litigation Group and the Data Privacy+ Cybersecurity Team. She concentrates her practice on privacy and security compliance under both state and federal regulations and advising clients on website and mobile app privacy and security compliance. Kathryn helps clients review, revise and implement necessary policies and procedures under the Health Insurance Portability and Accountability Act (HIPAA). She also provides clients with the information needed to effectively and efficiently handle potential and confirmed data breaches while providing insight into federal regulations and requirements for notification and an assessment under state breach notification laws. Prior to joining the firm, Kathryn was an associate at Nixon Peabody. She earned her J.D., cum laude, from Roger Williams University School of Law and her B.A., magna cum laude, from Stonehill College. She is admitted to practice law in Massachusetts and Rhode Island. Read her full rc.com bio here.
FTC Frames AI Output Steering as a Potential Section 5 Risk
The Federal Trade Commission’s (FTC) proposed policy statement puts a new consumer-protection frame around AI model behavior: if an AI company represents that its system is designed to deliver accurate, objective, or user-directed outputs, the company may create a reasonable consumer expectation that the system is trying to provide the best answer it can within…
Another CIPA Warning Shot: DraftKings Sued Over Website Tracking Tools
DraftKings is the latest target in California’s wave of California Invasion of Privacy Act (CIPA) website-tracking litigation. In Hughes v. DraftKings Inc., filed in the Central District of California, plaintiff Dana Hughes alleges that DraftKings operated its website with data broker software from NextRoll, The Trade Desk, and Comscore that secretly collected data about website visitors, their…
AI in Insurance: The Real Test Is Readiness, Not Technology
After several years of experimenting with generative AI, machine learning, and AI agents, many insurers are no longer asking whether AI belongs in the business. The harder question is whether a pilot is ready to scale. The answer usually is not found in the model architecture or the novelty of the tool. It is found…
FCC Narrows Foreign Drone Restrictions with Toy Exception
The Federal Communications Commission (FCC) has narrowed its foreign-produced drone restrictions by removing a specific category of “Toy Drones” and “Toy Drones that contain foreign-produced components” from the FCC Covered List. The June 15, 2026, Public Notice follows a June 12, 2026, National Security Determination from the Department of War, which found that this defined…
Why AI Is Changing Anonymized Data Rules
For years, companies have treated anonymization as a legal comfort zone. Remove names, emails, phone numbers, and other identifiers, and the remaining dataset was often viewed as safer to share, analyze, monetize, and retain. That assumption is getting harder to defend. Artificial intelligence (AI) has changed the practical re-identification analysis by making it easier to…
Kaiser Tracking Tech Case Moves Toward Class Certification
A member of Kaiser Permanente, an integrated managed care consortium headquartered in Oakland, California, has asked a federal judge in Seattle to certify nationwide classes and California subclasses in a privacy lawsuit against Microsoft and Qualtrics over tracking technologies allegedly embedded in Kaiser’s website and patient portal. The plaintiff, identified as Jane Doe, claims that…
AI Governance Is Not Just a Policy Problem – Your Contracts Matter
AI governance is often discussed through the lens of policies, frameworks, and responsible AI principles. Those tools matter, but they are not where many of the most important AI decisions are actually being made. In practice, AI governance is increasingly happening in contracts. Vendor agreements now decide who can use data, whether customer inputs may…
Big Win for Companies Facing CIPA Website Tracking Lawsuits
A California court just gave companies facing website tracking claims under the California Invasion of Privacy Act (CIPA) a very helpful ruling. In Blaker v. NetScout Systems, Inc., Case No. 25STCV31283 (May 27, 2026), the plaintiff claimed that NetScout violated California’s trap-and-trace law by using a software development kit (SDK) on its website that…
A Strong Defense Ruling for Companies Facing CIPA Website Tracking Claims
A recent Third Circuit decision gives companies another strong defense point in the wave of website tracking and session replay litigation, including claims brought under the California Invasion of Privacy Act (CIPA). In Smidga v. Spirit Airlines, the plaintiffs alleged that Spirit used session replay code to record website visitors’ interactions, including text entries…