Robinson Cole LLP
High Contrast Mode
Marquee

Data Privacy + Cybersecurity

Data privacy and cybersecurity increasingly affects all businesses and industries. To handle this complex and rapidly changing area of law, our Data Privacy + Cybersecurity practice group collaborates with lawyers throughout Robinson+Cole’s diverse practice areas.

Each member of our highly experienced team understands the spectrum of challenges businesses may face with evolving digital technologies. We are dedicated to helping you achieve success, providing you with the right resources to match your specific business needs.

Our Services

Our clients include public and private companies in all industries, including:

  • Software companies
  • Companies with websites and mobile apps
  • Health care providers and hospital systems
  • Retail and marketing companies
  • Higher education providers
  • Start-up companies
  • Tax-exempt organizations
  • Utilities, manufacturing, energy, and wireless telecommunications service providers

Our team regularly works with federal and state data privacy and security rules and regulations, including:

  • California Consumer Privacy Act (CCPA) and Privacy Rights Act and implementing regulations and state data privacy laws and emerging privacy regulations
  • Laws and regulations applicable to tracking technology and pixels
  • Children's Online Privacy Protection Act (COPPA)
  • Controlling the Assault of Non-Solicited Pornography and Marketing Act (CAN-SPAM Act)
  • European Union (EU) General Data Protection Regulation (GDPR) and revised Standard Contractual Clauses (SCCs)
  • Fair Credit Reporting Act (FCRA)
  • Family Educational Rights and Privacy Act (FERPA)
  • Federal Aviation Administration’s (FAA) Small Unmanned Aerial Systems (UAS) regulations (Part 107), and state and local laws related to the use of UAS and privacy concerns
  • Federal Trade Commission Act (FTC Act)
  • FTC's Telemarketing Sales Rule (TSR)
  • Gramm-Leach-Bliley Act (GLBA)
  • Health Insurance Portability and Accountability Act (HIPAA)
  • New York Department of Financial Services Cybersecurity Regulations
  • Consumer protection enforcement actions by Attorneys General or federal agencies including the Office for Civil Rights and the Federal Trade Commission
  • SEC cybersecurity regulations
  • State data security laws and regulations, including implementation of statutorily required Written Information Security Programs
  • State and federal data privacy and security laws and regulations related to employee and workplace privacy
  • State specific biometric information privacy laws and regulations
  • Telephone Consumer Protection Act (TCPA)
  • Video Privacy Protection Act (VPPA)

Our lawyers are knowledgeable about data collection technology, including the use of tracking technology like cookies and pixels for targeted advertising and behavioral advertising. We also understand the value and risks of collecting and using data for marketing and strategic purposes.

The team has a significant HIPAA compliance practice and assists covered entities and business associates navigate the intricacies of HIPAA, guidance from the OCR, and OCR enforcement actions. We have vast experience with HIPAA data breach response and statutory requirements.

Our Financial Services Cyber-Compliance team helps protect our banking, insurance, and financial services clients on a wide range of issues, including implementation of enterprise-wide cybersecurity programs, and adoption of required written cybersecurity policies and procedures to comply with state and federal laws.

Our Team

Our team is well-versed in incident and data breach response, mitigation, remediation, coordination, and litigation, including investigations by the U.S. Office for Civil Rights and state Attorneys General (AGs). We coordinate forensic investigations and mitigation tactics in the event of ransomware or other cyber attacks.

Our attorneys advise our clients in data mapping and development of enterprise-wide privacy and security plans, and compliance with privacy requirements and industry-specific regulations. We also advise on sharing and transfer of collected data and assist with strategy to minimize risk associated with the collection, use and disclosure of data. We regularly structure arrangements relating to data transfer, and prepare technology contracts and information security addenda to outline appropriate protection obligations for the sharing and care of customer and patient data.

We promote practices and policies to safeguard data against accidental or deliberate disclosure, including security programs. We provide tailored education programs for employees, executives and boards. We have completed dozens of cybersecurity tabletop exercises, which are designed to experience a live cybersecurity event and response.

Our lawyers also work with clients to develop website and mobile app privacy policies and terms and conditions of use, and social media policies, practices, and procedures.

Our Robinson+Cole team members also author the Data Privacy + Cybersecurity Insider blog, providing clients with timely, thoughtful, and cutting-edge legal news and perspectives about data privacy and cybersecurity issues. The widely-recognized blog has received multiple Readers Choice Awards distinction from JD Supra and featured in FeedSpot's "100 Best Infosec Blogs and Websites in 2025."

We actively speak at industry-sponsored programs on data privacy and cybersecurity developments, cases, trends, and agendas. We proactively track updates to federal and state privacy and security laws and proposals.

Our Data Privacy + Cybersecurity team is here to help you navigate the ever-evolving complexities of nationwide laws and regulations, providing skilled legal services for businesses in the digital sphere.

Data Privacy + Cybersecurity Insider


Verizon’s 2026 Data Breach Investigations Report Highlights

I am a big fan of Verizon’s yearly Data Breach Investigations Report. I follow it closely, as it confirms what we are seeing in the field, and provides validation for defense strategies employed to protect against attacks. The 2026 Report was recently published, and as I have mentioned before, it is well worth reading. At... Continue Reading

Visit Blog

Verification Texts Are Not Automatically TCPA Ads, New Jersey Court Holds

On May 20, 2026, in Zelma v. Wonder Group Inc. (D.N.J. May 20, 2026), a federal court in New Jersey largely dismissed Telephone Consumer Protection Act (TCPA) claims against food-tech company Wonder Group Inc. (Wonder), holding that two bare verification-code text messages were not “telephone solicitations” or “unsolicited advertisements.” The TCPA regulates certain calls and... Continue Reading

Visit Blog

A Strong Defense Ruling for Companies Facing CIPA Website Tracking Claims

A recent Third Circuit decision gives companies another strong defense point in the wave of website tracking and session replay litigation, including claims brought under the California Invasion of Privacy Act (CIPA). In Smidga v. Spirit Airlines, the plaintiffs alleged that Spirit used session replay code to record website visitors’ interactions, including text entries, clicks, and... Continue Reading

Visit Blog

Shadow AI Continues to Expose Company IP

Verizon recently published its 2026 Data Breach Investigations Report, which is full of helpful information for cybersecurity professionals to implement strategies for protection of systems. For a summary, click here. The Report notes that a whopping “67% of users are using non-corporate accounts on their corporate devices to access AI services” and “45% of employees... Continue Reading

Visit Blog

Colorado Rewrites Its AI Law Before It Takes Effect

Colorado has now significantly revised its AI governance framework before the law ever takes effect. SB 26-189, approved by Governor Jared Polis on May 14, 2026, repeals and reenacts key portions of the Colorado Artificial Intelligence Act (CAIA) and reframes the law around “automated decision-making technology” (ADMT) used to materially influence consequential decisions in areas such... Continue Reading

Visit Blog

Privacy Tip #493 – Stop Using Shadow AI!

As you can tell, I am obsessed with Verizon’s Data Breach Investigations Report. It is worthy of full immersion, and I am picking it apart with precision (here and here). I always spend a lot of time delving into it as it informs and confirms strategies to assist others with prevention and resilience. One of... Continue Reading

Visit Blog

CISA Passwords Used to Access DHS Systems Exposed

The Cybersecurity and Infrastructure Security Agency (CISA), which is part of the Department of Homeland Security, is responsible for cybersecurity and infrastructure security throughout the federal government, to improve cybersecurity protection against private and nation-state hackers. CISA has been without a director since the beginning of President Trump’s second term, when the then-director resigned. In... Continue Reading

Visit Blog

No Easy Walkaway: Skechers Must Face Email Marketing Claims

The latest ruling in Liss v. Skechers USA Inc., No. 3:25-CV-05861-DGE, 2026 WL 1392327 (W.D. Wash. May 19, 2026), keeps alive a proposed Washington class action challenging promotional email subject lines that allegedly used deadline-driven language to create artificial urgency around discounts. The plaintiffs alleged that Skechers sent commercial emails to Washington consumers with subject... Continue Reading

Visit Blog

Texas Sues Netflix Over Alleged Data Privacy and Children’s Safety Practices

The Texas Attorney General has filed a new consumer-protection lawsuit against Netflix, alleging that the company misled Texans by marketing itself as an ad-free, kid-friendly alternative to Big Tech while allegedly building a large-scale system for collecting and monetizing user data. The complaint claims that Netflix repeatedly assured consumers that its paid subscription model separated it... Continue Reading

Visit Blog

Why AI Risk Needs Its Own Insurance Conversation

Many insurers, and the businesses they cover, are still treating artificial intelligence (AI) risk as if it were cyber risk cloaked in a costume. That instinct is understandable since AI systems process data, rely on vendors, create operational dependencies, and sit inside digital infrastructures. However, early litigation is showing why that framing is likely incomplete.... Continue Reading

Visit Blog

Privacy Tip #492 – FTC Enforcing the Take It Down Act

On May 19, 2026, the Federal Trade Commission (FTC) announced that it will begin enforcing the Take It Down Act (TIDA) immediately. TIDA was made law in May 2025 and requires platforms to remove non-consensual intimate imagery within 48 hours of being notified. It provides criminal penalties for the publication of non-consensual intimate imagery and... Continue Reading

Visit Blog

ShinyHunters Hit Instructure + Downs Canvas Learning Management System

Another recent victim of ShinyHunters is Instructure, the supplier of the Canvas learning management system, which disrupted the login portals of 330 colleges and universities during the critical college exam schedule. According to Dataminr, ShinyHunters “claimed to have stolen 3.654TB of data affecting about 275 million individuals and 9,000 institutions worldwide.” The stolen data included... Continue Reading

Visit Blog

FTC’s TAKE IT DOWN Act Stakeholder Letter Signals Heightened Compliance Priority

The spread of AI generated intimate imagery has turned what was already a serious online safety issue into a fast- moving platform governance problem. The Federal Trade Commission’s (FTC) latest stakeholder letter makes clear that covered platforms will be expected to have systems in place before enforcement begins. This week, the FTC sent a stakeholder... Continue Reading

Visit Blog

California’s GM Settlement Reveals a New Era for Connected Car Privacy

California regulators have announced a major privacy settlement with General Motors (GM) over allegations that the company unlawfully sold the location and driving data of hundreds of thousands of Californians to two data brokers: Verisk Analytics and LexisNexis Risk Solutions. The settlement, subject to court approval, requires GM to pay $12.75 million in civil penalties... Continue Reading

Visit Blog

When an AI Chatbot Calls Itself a Doctor

Pennsylvania’s lawsuit against Character Technologies, Inc., is a notable early test of how professional licensing laws may apply to consumer-facing AI chatbots. The Commonwealth, acting through the Department of State and State Board of Medicine, filed a Petition for Review in the Commonwealth Court of Pennsylvania seeking to restrain what it alleges is the unlawful... Continue Reading

Visit Blog

Experience


Software + Technology Contract Negotiations

Represented multiple companies in the negotiation of software and technology contracts with third-party vendors.

Start-Up Policy Development

Worked with multiple start-up organizations in developing privacy policies and terms of use for websites and mobile applications, as well as privacy and security plans and compliance programs.

Data Breach Assistance

Assisted dozens of organizations with reportable data breaches, including notification, mitigation, and regulatory enforcement, as well as class action defense.



News


April 17, 2026

Kathryn Rattigan Joins the Beta Gamma Sigma Society as Honorary Inductee

Data Privacy + Cybersecurity team partner Kathryn Rattigan was invited to join the Beta Gamma Sigma (BGS) Society as an honorary inductee at the Leo J. Meehan School of Business at Stonehill College. Her honorary membership reflects her exceptional leadership skills, service to the legal profession, and impact to the business community. BGS is the international business honor society for AACSB-accredited schools, which are the top 5% of business schools in the world and is comprised of individuals serving in critical leadership roles in corporate, entrepreneurial, government, non-profit, and academic sectors. In a ceremony on April 16, 2026, in Easton, Massachusetts, Kathryn provided brief remarks while accepting her invitation.

Beta Gamma Sigma Society
Kathryn Rattigan Joins the Beta Gamma Sigma Society as Honorary Inductee teaser
April 15, 2026

Robinson+Cole Presented with 2026 Law Firm Excellence in Innovation Award

Massachusetts Lawyers Weekly
Robinson+Cole Presented with 2026 Law Firm Excellence in Innovation Award teaser
March 19, 2026

Roma Patel Authors Article on Secondary Liability and AI

The Licensing Journal
April 17, 2026

Kathryn Rattigan Joins the Beta Gamma Sigma Society as Honorary Inductee

Data Privacy + Cybersecurity team partner Kathryn Rattigan was invited to join the Beta Gamma Sigma (BGS) Society as an honorary inductee at the Leo J. Meehan School of Business at Stonehill College. Her honorary membership reflects her exceptional leadership skills, service to the legal profession, and impact to the business community. BGS is the international business honor society for AACSB-accredited schools, which are the top 5% of business schools in the world and is comprised of individuals serving in critical leadership roles in corporate, entrepreneurial, government, non-profit, and academic sectors. In a ceremony on April 16, 2026, in Easton, Massachusetts, Kathryn provided brief remarks while accepting her invitation.

Beta Gamma Sigma Society
Kathryn Rattigan Joins the Beta Gamma Sigma Society as Honorary Inductee teaser
April 15, 2026

Robinson+Cole Presented with 2026 Law Firm Excellence in Innovation Award

Massachusetts Lawyers Weekly
Robinson+Cole Presented with 2026 Law Firm Excellence in Innovation Award teaser
March 19, 2026

Roma Patel Authors Article on Secondary Liability and AI

The Licensing Journal
March 18, 2026

Linn Freedman Sounds the Alarm About the Growth of Deepfake Content

Corporate Counsel
March 16, 2026

Kathryn Rattigan Quoted on Disney CCPA Opt-Out Settlement

Cybersecurity Law Report
February 25, 2026

Data Privacy + Cybersecurity Team Receives 2026 Readers' Choice Awards

JD Supra
Data Privacy + Cybersecurity Team Receives 2026 Readers' Choice Awards teaser
February 19, 2026

Linn Freedman Receives Global Ranking in Chambers Global Guide 2026

Chambers & Partners
February 5, 2026

Linn Freedman Quoted in Cybersecurity Law Report on FTC Settlement

Cybersecurity Law Report
November 26, 2025

Linn Freedman Discusses AI in Education

Law 401 Podcast

March 18, 2026

Linn Freedman Sounds the Alarm About the Growth of Deepfake Content

Corporate Counsel
March 16, 2026

Kathryn Rattigan Quoted on Disney CCPA Opt-Out Settlement

Cybersecurity Law Report
February 25, 2026

Data Privacy + Cybersecurity Team Receives 2026 Readers' Choice Awards

JD Supra
Data Privacy + Cybersecurity Team Receives 2026 Readers' Choice Awards teaser
February 19, 2026

Linn Freedman Receives Global Ranking in Chambers Global Guide 2026

Chambers & Partners
February 5, 2026

Linn Freedman Quoted in Cybersecurity Law Report on FTC Settlement

Cybersecurity Law Report
November 26, 2025

Linn Freedman Discusses AI in Education

Law 401 Podcast

Events


Upcoming

2026 Pennsylvania Legal Awards

Jun 11 2026
Hilton Philadelphia at Penn’s Landing
Past

Managing Matter Mobility - Setting Defensible Rules for Data Leaving or Entering the Firm

Mar 9 2026
Law.com Legalweek 2026
Upcoming

2026 Pennsylvania Legal Awards

Jun 11 2026
Hilton Philadelphia at Penn’s Landing
Past

Managing Matter Mobility - Setting Defensible Rules for Data Leaving or Entering the Firm

Mar 9 2026
Law.com Legalweek 2026
Past

Mastery of IG: Legal and Regulatory

Feb 19 2026
ARMA IG Mastery Session 4
Past

State AI Laws and the Federal EO: Effective Dates, Scope, Enforcement, Compliance Planning

Jan 27 2026
Barbri Webinar
Past

Deepfakes: A Demonstration of How They are Made and Used by Threat Actors

Nov 19 2025
Boston Bar Association 2025 Privacy, Cybersecurity & Digital Law Conference
Past

Fireside Chat | The Cyber Brief: Law, Liability & Response

Sep 19 2025
SCG Legal 2025 Annual Meeting
Past

Mastery of IG: Legal and Regulatory

Feb 19 2026
ARMA IG Mastery Session 4
Past

State AI Laws and the Federal EO: Effective Dates, Scope, Enforcement, Compliance Planning

Jan 27 2026
Barbri Webinar
Past

Deepfakes: A Demonstration of How They are Made and Used by Threat Actors

Nov 19 2025
Boston Bar Association 2025 Privacy, Cybersecurity & Digital Law Conference
Past

Fireside Chat | The Cyber Brief: Law, Liability & Response

Sep 19 2025
SCG Legal 2025 Annual Meeting

Publications


Data Privacy + Cybersecurity Insider teaser
May 28, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
May 21, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
May 14, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
May 28, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
May 21, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
May 14, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
May 7, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
April 30, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
April 23, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
April 16, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
April 9, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
March 26, 2026

Data Privacy + Cybersecurity Insider



Data Privacy + Cybersecurity Insider teaser
May 7, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
April 30, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
April 23, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
April 16, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
April 9, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
March 26, 2026

Data Privacy + Cybersecurity Insider