Robinson Cole LLP
High Contrast Mode

Kathryn M. Rattigan advises clients on data privacy and security, cybersecurity, and compliance with related state and federal laws. She assists clients in assessing risks related to technology and software contracts, as well as with compliance-related issues with outsourcing and vendor management. She represents clients across all industries, such as manufacturing, insurance, health care, education, energy, and construction. Kathryn is a member of our Business Litigation group, Data Privacy + Cybersecurity team and Artificial Intelligence team and is co-chair of the firm’s Women’s Committee. Kathryn has presented around the country on data privacy and cybersecurity, and she writes extensively on these topics, including for the firm’s Data Privacy + Cybersecurity Insider blog. The widely recognized Insider blog has received multiple Readers’ Choice Awards distinction from JD Supra.

Data Privacy + Cybersecurity Compliance

As a Certified Information Privacy Professional, Kathryn helps clients comply with all state and federal regulations related to data privacy and cybersecurity. She counsels clients facing government investigations over alleged non-compliance. She advises clients on the development of privacy and security plans, and how to best handle high-risk data to avoid breaches and cyber intrusions. Kathryn helps clients review, revise, and implement necessary policies and procedures under the California Consumer Privacy Act and other state consumer protection laws, the Health Insurance Portability and Accountability Act (HIPAA), Telephone Consumer Protection Act, the Children's Online Privacy Protection Act, Family Educational Rights and Privacy Act, and other federal and state laws and regulations. She assists businesses and organizations with measures to protect the security and confidentiality of personal and sensitive information, as well as proprietary data and intellectual property. Kathryn assists with the development of website and mobile app privacy policies and terms and conditions of use, as well as assessing risk with website tracking and pixel technology. She also assists clients in the negotiation of technology and software contracts to reduce risk and ensure that third-party vendors implement appropriate, and required, privacy and security safeguards and processes. Kathryn also collaborates with clients’ business teams and third-party consultants in negotiating these vendor contracts.

Information Governance + Record Management

Kathryn assists clients in building a strong foundation for their information governance program to drive efficiency and reduce risk related to unnecessary data and information storage. She assists clients with data mapping and classification, retention and destruction policy development and implementation, vendor management, data privacy and security compliance programs, training and ongoing support, and maintenance of information governance initiatives. The team has been recognized as a Verified Organization by ARMA International.

Artificial Intelligence Governance + Compliance

Kathryn advises clients developing AI governance programs, evaluating AI tools, negotiating AI vendor contracts, and implementation of AI platforms (such as Co-Pilot). She assists businesses with mapping of their organization’s AI use, preparation of policies and procedures, including acceptable use, adopting a methodology to comply with applicable laws for AI software and algorithm development, creating a cross-functional governance committee, updating employee handbooks and codes of conduct, training, risk assessments, and state and federal law surveys such that clients stay apprised of this ever-changing space.

Unmanned Aerial Systems + FAA Compliance

Kathryn advises clients on all legal issues surrounding the use of commercial drones, including navigation of Federal Aviation Administration regulations, commercial registration requirements, and Part 107 waivers. She reviews and prepares employee and subcontractor agreements for the piloting and use of drones. She advises commercial businesses on insurance options for adequate coverage for drone use. Kathryn is well-versed on various local and state laws, regulations, and ordinances which apply to a business’ drone use. She assists clients with privacy and cybersecurity policies, procedures and programs to mirror the National Telecommunications and Information Administration’s voluntary best practices, as well as other industry standards. Kathryn also handles drone-related litigation, such as claims involving manufacturing defects, personal injury, or property damage. She has given numerous presentations about implementing UAS into company infrastructure and privacy and cybersecurity issues related to drone use.

HIPAA Compliance

Kathryn counsels clients on HIPAA compliance, including assisting with employee training, and providing guidance on the implementation of required and recommended Privacy Rule and Security Rule policies and procedures.

Security Incident + Data Breach Preparedness + Emergency Response

Kathryn provides clients with the information needed to effectively handle potential and confirmed data breaches and cyber-attacks, including insight into state and federal regulations and requirements. If a client suffers a data breach, she assists with the follow-up response, including notification, remediation, and litigation.

Privacy + Class Action Litigation + Enforcement

If a data breach, cybersecurity issue, or consumer privacy rights complaint results in litigation or an enforcement action, Kathryn represents clients in court and before government regulatory agencies. This includes assisting clients with matters related to unauthorized access, use or disclosure of health, financial, or personal information, consumer privacy rights violations under state laws like the California Consumer Privacy Rights Act and the Connecticut Data Privacy Act, and website tracking claims under state and federal wiretap statutes.

Pro Bono + Community Involvement

Kathryn is committed to doing pro bono work and being involved in the community. Her recent efforts include assisting Wellbeing Action for Youth, a non-profit which works to help students focus and succeed through mindfulness practice in the classroom, and College Visions, which helps low-income students pursue a college education.

She writes for two of our firm’s blogs, Data Privacy + Cybersecurity Insider and Health Law Diagnosis.

  • Roger Williams University School of Law (Juris Doctor)
  • Stonehill College (Bachelors, magna cum laude)
    • B.A.

  • Commonwealth of Massachusetts
  • State of Rhode Island
  • U.S. Supreme Court
  • U.S. District Court, District of Massachusetts
  • U.S. District Court, District of Rhode Island

Recognized as part of Rhode Island Lawyers Weekly's 2025 Excellence in the Law awards

Recognized as a Woman to watch as part of the Providence Business News 2025 Business Women Awards

Recognized as a 2021 Up and Coming Lawyer by Rhode Island Lawyers Weekly

Recognized as a 2020 "40 Under Forty" winner by Providence Business News

Recognized as a 2020 National Law Review Go-To Thought Leader in the area of Cybersecurity Law

JD Supra Readers' Choice Top Author in the area of Cybersecurity from 2022 to 2026

2021 JD Supra Readers' Choice Top Author in the areas of Cybersecurity and Transportation

2020 JD Supra Readers' Choice Top Author in the areas of Airlines / Aviation and Cybersecurity

2018 and 2019 JD Supra Readers' Choice Top Author and the #1 author in Airlines/Aviation

2017 JD Supra Readers' Choice Awards Top Author with readers in the Aviation industry, on the subject of Class Actions, as well as the #1 author on the topic of Drones

2016 JD Supra Reader’s Choice Award Top Author in Airline and Aviation Industry

Selected as a Rising Star in the Rhode Island Super Lawyers list from 2018 to 2025

Certified Information Privacy Professional/US (CIPP/US) by the International Association of Privacy Professionals (IAPP)

Selected by her peers for inclusion in the Best Lawyers: Ones to Watch in America in the area of Privacy and Data Security since 2023

Recognized as a New Leader in the Law as part of Law.com and Connecticut Law Tribune's 2023 New England Legal Awards

Robinson+Cole Wellbeing Award Recipient, 2023

Stonehill College
President's Advisory Council
Board of Fellows

International Association of Privacy Professionals
Certified Information Privacy Professional, U.S.

Massachusetts Bar Association
Member
Chair of Health Law Section Council (2018 - 2020)
Vice Chair of Health Law Section Council (2016 - 2018)

Association for Unmanned Vehicle Systems International

Rhode Island Bar Association

Rhode Island Women's Bar Association

Journal on Emerging Issues in Litigation
Editorial Board of Advisors, Drone Technology

American Heart Association
Southern New England Board of Directors, Leadership Development Chair
Go Red for Women, 2025 Luncheon Co-Chair

Wellbeing Action for Youth
Advisory Board

Women's Fund of Rhode Island

Rhode Island Hospital Foundation
Board of Governors

Roger Williams University School of Law
Pro Bono Collaborative Advisory Board

Experience


Represented Acentus in Acquisition by Henry Schein, Inc.

Served as legal counsel for Acentus, a national medical supplier specializing in the delivery of continuous glucose monitors for Medicare patients, in its acquisition by Henry Schein, Inc., a solutions company for health care professionals advising over 1 million customers globally to help improve operational success and clinical outcomes. The acquisition, which was announced on November 20, 2024, will see Henry Schein acquire substantially all of Acentus’ assets, and will expand its national homecare solutions platform to address the evolving needs of clients.

Read More
Represented Acentus in Acquisition by Henry Schein, Inc.

Software + Technology Contract Negotiations

Represented multiple companies in the negotiation of software and technology contracts with third-party vendors.

Start-Up Policy Development

Worked with multiple start-up organizations in developing privacy policies and terms of use for websites and mobile applications, as well as privacy and security plans and compliance programs.



Publications


Data Privacy + Cybersecurity Insider teaser
April 23, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
April 16, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
April 9, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
April 23, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
April 16, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
April 9, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
March 26, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
March 19, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
March 5, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
February 26, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
February 19, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
February 12, 2026

Data Privacy + Cybersecurity Insider



Data Privacy + Cybersecurity Insider teaser
March 26, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
March 19, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
March 5, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
February 26, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
February 19, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
February 12, 2026

Data Privacy + Cybersecurity Insider


News


April 17, 2026

Kathryn Rattigan Joins the Beta Gamma Sigma Society as Honorary Inductee

Data Privacy + Cybersecurity team partner Kathryn Rattigan was invited to join the Beta Gamma Sigma (BGS) Society as an honorary inductee at the Leo J. Meehan School of Business at Stonehill College. Her honorary membership reflects her exceptional leadership skills, service to the legal profession, and impact to the business community. BGS is the international business honor society for AACSB-accredited schools, which are the top 5% of business schools in the world and is comprised of individuals serving in critical leadership roles in corporate, entrepreneurial, government, non-profit, and academic sectors. In a ceremony on April 16, 2026, in Easton, Massachusetts, Kathryn provided brief remarks while accepting her invitation.

Beta Gamma Sigma Society
March 16, 2026

Kathryn Rattigan Quoted on Disney CCPA Opt-Out Settlement

Cybersecurity Law Report
February 25, 2026

Data Privacy + Cybersecurity Team Receives 2026 Readers' Choice Awards

JD Supra
Data Privacy + Cybersecurity Team Receives 2026 Readers' Choice Awards teaser
April 17, 2026

Kathryn Rattigan Joins the Beta Gamma Sigma Society as Honorary Inductee

Data Privacy + Cybersecurity team partner Kathryn Rattigan was invited to join the Beta Gamma Sigma (BGS) Society as an honorary inductee at the Leo J. Meehan School of Business at Stonehill College. Her honorary membership reflects her exceptional leadership skills, service to the legal profession, and impact to the business community. BGS is the international business honor society for AACSB-accredited schools, which are the top 5% of business schools in the world and is comprised of individuals serving in critical leadership roles in corporate, entrepreneurial, government, non-profit, and academic sectors. In a ceremony on April 16, 2026, in Easton, Massachusetts, Kathryn provided brief remarks while accepting her invitation.

Beta Gamma Sigma Society
March 16, 2026

Kathryn Rattigan Quoted on Disney CCPA Opt-Out Settlement

Cybersecurity Law Report
February 25, 2026

Data Privacy + Cybersecurity Team Receives 2026 Readers' Choice Awards

JD Supra
Data Privacy + Cybersecurity Team Receives 2026 Readers' Choice Awards teaser
December 18, 2025

Business Transactions in Health Care Team Wins “Pharma & Devices Deal of the Year” at Global M&A Network’s 7th Annual USA Middle Markets M&A Atlas Awards Gala

Global M&A Network
Business Transactions in Health Care Team Wins “Pharma & Devices Deal of the Year” at Global M&A Network’s 7th Annual USA Middle Markets M&A Atlas Awards Gala teaser
November 25, 2025

Kathleen Dion and Kathryn Rattigan Spotlight Three AI-related Legal Issues Facing Higher Education Administrators

University Business
November 6, 2025

Robinson+Cole Commends 62 Attorneys Recognized in 2025 Super Lawyers®

Recognition spans key regions and highlights the firm’s seasoned practitioners and emerging leaders in many business transactions and litigation practices
Robinson+Cole Commends 62 Attorneys Recognized in 2025 <i>Super Lawyers</i>® teaser
October 27, 2025

Kathryn Rattigan and Bill Egan Discuss CIPA Trap and Trace Litigation on SCG Global Spin

SCG Legal
October 8, 2025

Robinson+Cole Healthcare Transactions Team Represents The Pennant Group in One of 2025’s Largest Homecare and Hospice Transactions

August 14, 2025

Kathryn Rattigan Quoted on CPPA Retroactivity Enforcement Authority

Daily Journal

December 18, 2025

Business Transactions in Health Care Team Wins “Pharma & Devices Deal of the Year” at Global M&A Network’s 7th Annual USA Middle Markets M&A Atlas Awards Gala

Global M&A Network
Business Transactions in Health Care Team Wins “Pharma & Devices Deal of the Year” at Global M&A Network’s 7th Annual USA Middle Markets M&A Atlas Awards Gala teaser
November 25, 2025

Kathleen Dion and Kathryn Rattigan Spotlight Three AI-related Legal Issues Facing Higher Education Administrators

University Business
November 6, 2025

Robinson+Cole Commends 62 Attorneys Recognized in 2025 Super Lawyers®

Recognition spans key regions and highlights the firm’s seasoned practitioners and emerging leaders in many business transactions and litigation practices
Robinson+Cole Commends 62 Attorneys Recognized in 2025 <i>Super Lawyers</i>® teaser
October 27, 2025

Kathryn Rattigan and Bill Egan Discuss CIPA Trap and Trace Litigation on SCG Global Spin

SCG Legal
October 8, 2025

Robinson+Cole Healthcare Transactions Team Represents The Pennant Group in One of 2025’s Largest Homecare and Hospice Transactions

August 14, 2025

Kathryn Rattigan Quoted on CPPA Retroactivity Enforcement Authority

Daily Journal

Events


Past

AI as a Friend, Not Foe: Welcoming AI to Master Information Governance

Apr 21 2026
ARMA InfoNEXT 2026
Past

Managing Matter Mobility – Setting Defensible Rules for Data Leaving or Entering the Firm

Mar 9 2026
Law.com Legalweek 2026
Past

AI as a Friend, Not Foe: Welcoming AI to Master Information Governance

Apr 21 2026
ARMA InfoNEXT 2026
Past

Managing Matter Mobility – Setting Defensible Rules for Data Leaving or Entering the Firm

Mar 9 2026
Law.com Legalweek 2026
Past

Unlocking the Power of Information Governance: Essentials for Legal Professionals

Mar 9 2026
Law.com Legalweek 2026
Past

Mastery of IG: Legal and Regulatory

Feb 19 2026
ARMA IG Mastery Session 4
Past

Deal or No Deal? Winning with Information Governance in M&A by FiT

Oct 21 2025
ARMA International INFOCON 2025
Past

Small Firms, Big Risks – How Can Small Firms Provide Responsible Oversight for AI Model Governance

Oct 21 2025
ARMA International INFOCON 2025
Past

Unlocking the Power of Information Governance: Essentials for Legal Professionals

Mar 9 2026
Law.com Legalweek 2026
Past

Mastery of IG: Legal and Regulatory

Feb 19 2026
ARMA IG Mastery Session 4
Past

Deal or No Deal? Winning with Information Governance in M&A by FiT

Oct 21 2025
ARMA International INFOCON 2025
Past

Small Firms, Big Risks – How Can Small Firms Provide Responsible Oversight for AI Model Governance

Oct 21 2025
ARMA International INFOCON 2025

Data Privacy + Cybersecurity Insider


Below is an excerpt of Data Privacy + Cybersecurity Insider blog posts authored by Kathryn.

California’s DROP Regime will Change the Data Broker Risk Equation

California’s new Delete Request and Opt-Out Platform (DROP) goes live on August 1, 2026, and the compliance stakes are enormous. State officials have warned that a single missed deletion cycle could create theoretical penalty exposure of $1.5 billion for one data broker. That number reflects how aggressively the Delete Act is designed to work. One consumer request can... Continue Reading

Visit Blog

Legal AI Delivers More Value When It Is Tied to Business Outcomes

As corporate legal departments continue adopting AI, the conversation is shifting from experimentation to strategy. According to the Thomson Reuters Institute’s 2026 State of the Corporate Law Department Report, nearly half of legal departments now report department-wide AI adoption, and technology has become a top strategic priority for many general counsel. That momentum matters, but adoption... Continue Reading

Visit Blog

CNN Must Defend Privacy Suit Alleging Data Sharing with Microsoft and Adtech Firms 

A federal judge has ruled that CNN must face a proposed class action alleging that its website shared consumers’ personal information with Microsoft and adtech firms without consent, in alleged violation of the California Invasion of Privacy Act (CIPA). The lawsuit challenges CNN’s alleged use of online tracking tools and the downstream sharing of data in the digital advertising ecosystem.  According... Continue Reading

Visit Blog

Vetting AI for Government: California’s Executive Order Sets New Expectations

California Governor Gavin Newsom issued a new executive order aimed at tightening California’s procurement rules for artificial intelligence (AI) vendors and “raising the bar” for companies that want to sell AI tools to the state. The administration says the goal is to ensure contractors meet strong standards and can demonstrate responsible policies that prevent misuse,... Continue Reading

Visit Blog

Consent Banners Versus Browser Reality: What the Ace Hardware Complaint Alleges

A new class action in the U.S. District Court for the Northern District of California alleges that Ace Hardware tracked users’ online activity through third-party tools before users could make meaningful choices through cookie consent tools, and that it continued even after users took steps to opt out. The plaintiffs claim that the Ace Hardware website... Continue Reading

Visit Blog

Carfax Motion to Dismiss Denied in DPPA Crash-Report Data Sales Case

Carfax, Inc. faced an early loss in a closely-watched privacy case under the federal Driver’s Privacy Protection Act (DPPA), after a judge in Maryland refused to throw out a proposed class action alleging the company sold drivers’ personal information sourced from crash and vehicle records. The plaintiff alleges that Carfax obtained his DPPA-protected personal information... Continue Reading

Visit Blog

Ford Settlement Highlights Simple Practice: Opt-Outs Must be Easy

The California Privacy Protection Agency (CPPA) issued a decision requiring Ford Motor Company to pay a fine of $375,703 and update its privacy practices following a settlement for its alleged violations of the California Consumer Privacy Act (CCPA). Under the CCPA, California residents have the right to direct a business to stop selling or sharing... Continue Reading

Visit Blog

Skullcandy Can’t Transfer its CIPA Case Out of California

A federal court in the Southern District of California declined to dismiss wiretapping and eavesdropping claims tied to Skullcandy Inc.’s alleged use of online trackers on its retail website, allowing the lawsuit to move forward. Plaintiff alleges that Skullcandy used tracking tools from Meta Platforms and Google to collect browser and purchase data. Jones v.... Continue Reading

Visit Blog

A Compliance Wave Is Coming: Data Brokers Brace for DROP Deletion Requests Under the Delete Act

Data brokers are lining up to comply with California’s one-stop deletion tool requirement under the Delete Act, and the numbers signal a major shift in how privacy rights may be exercised and enforced in California starting this summer. At its most recent meeting, the California Privacy Protection Agency (CPPA) reported that more than 575 data brokers... Continue Reading

Visit Blog

Swiped Right, Hacked Hard: Bumble Faces Class Action Over Data Breach

A newly filed putative class action in the Western District of Texas targets Bumble, Inc., over an alleged “massive and preventable” cyberattack in or around January 2026, in which attackers allegedly accessed highly sensitive user data stored in Bumble’s systems. The complaint alleges the compromised information included names, dates of birth, addresses, telephone numbers, Social Security numbers,... Continue Reading

Visit Blog

DJI vs. the FCC: What the “Covered List” Could Mean for Drone Operators and Manufacturers

DJI, the world’s leading manufacturer of civilian drones, has escalated its dispute with the Federal Communications Commission (FCC) by filing an appeal in the Ninth Circuit after the FCC placed many DJI products on its “covered list,” which the FCC uses for telecommunications equipment it deems an unacceptable national security risk. DJI says the decision... Continue Reading

Visit Blog

Appellate Whiplash in Website Tracking Litigation: VPPA Speeds Ahead While CIPA Still Waits

Website tracking litigation continues to generate high stakes compliance risk, but not all privacy statutes are moving through the courts at the same pace. A notable divergence is emerging between the Video Privacy Protection Act (VPPA) and the California Invasion of Privacy Act (CIPA). Where the first is rapidly heading toward definitive interpretation by the... Continue Reading

Visit Blog

CCPA Enforcement Goes Cross Device: What Disney’s Settlement Signals for Compliance

The Office of California Attorney General Rob Bonta announced the largest settlement for violations of the California Consumer Privacy Act (CCPA) to date, imposing a $2.75 million civil penalty and injunctive relief focused on how Disney implements consumer opt-outs across its streaming ecosystem. Disney must pay the penalty within 30 days of the judgment’s effective... Continue Reading

Visit Blog

Tracking After Rejection? ATP Tour Complaint Highlights Risks of Misaligned Cookie Controls

California resident Nathaniel Bee filed a lawsuit this week alleging that the ATP Tour’s website used third-party tracking technology that captured details on how visitors interacted with the site, including what content they viewed; how they navigated the website; and what type of device they used, without user consent in violation of the California Invasion... Continue Reading

Visit Blog

CIPA Demand Letters Are Here to Stay; Reducing Risk from Chat, Session Replay, and Analytics

Until California’s legislature provides clearer guardrails, companies should expect continued class action activity under the California Invasion of Privacy Act (CIPA), targeting common website tracking technologies. Plaintiffs’ firms are actively testing how far this decades-old statute extends in the modern web environment, and courts have not reached a consensus. That uncertainty creates real litigation risk... Continue Reading

Visit Blog