Photo of Bolatito Adetula

Bolatito Adetula

Tito Adetula is an associate in the firm’s Washington, DC office. She is a member of the Data Privacy and Cybersecurity Practice Group. Tito advises clients on a broad range of data privacy matters, with a focus on artificial intelligence, state privacy laws, and regulatory compliance matters. She has experience counseling clients on state privacy and advertising technology compliance, as well as counselling clients on related e-discovery data retention issues.

Tito also maintains an active pro bono practice focused on data privacy and cybersecurity matters.

On August 19, 2026, Connecticut Attorney General William Tong announced a $275,000 settlement with online tax preparation company TaxAct over allegations that the company improperly disclosed taxpayer information to advertising partners through third-party tracking technologies on its website. The Attorney General alleged that, between January 2018 and December 2022, TaxAct used third-party tracking technologies for analytics and marketing purposes and, in doing so, disclosed detailed taxpayer information without informing consumers.

The settlement is notable because it highlights regulatory scrutiny over the disclosure of financial information, and also because it imposes extensive governance, monitoring, and auditing requirements on TaxAct relating to the use of third-party tracking technologies. In addition, the settlement does not specify what law was allegedly violated.

Continue Reading Connecticut Attorney General Settles with TaxAct Over Sharing Taxpayer Data

A number of previously enacted laws related to privacy and minors’ use of social media platforms will enter into force in July 2025.  These laws include comprehensive privacy frameworks in Tennessee and Minnesota, as well as laws governing the use of social media platforms by minors in Georgia and Louisiana.  An overview of some key laws is below.

Continue Reading New State Privacy and Minor Social Media Laws to Become Effective in July

On May 22, 2025, the Cybersecurity and Infrastructure Security Agency (“CISA”), which sits within the Department of Homeland Security (“DHS”) released guidance for AI system operators regarding managing data security risks.  The associated press release explains that the guidance provides “best practices for system operators to mitigate cyber risks through the artificial intelligence lifecycle, including consideration on securing the data supply chain and protecting data against unauthorized modification by threat actors.”  CISA published the guidance in conjunction with the National Security Agency, the Federal Bureau of Investigation, and cyber agencies from Australia, the United Kingdom, and New Zealand.  This guidance is intended for organizations using AI systems in their operations, including Defense Industrial Bases, National Security Systems owners, federal agencies, and Critical Infrastructure owners and operators. This guidance builds on the Joint Guidance on Deploying AI Systems Security released by CISA and several other U.S. and foreign agencies in April 2024.

Continue Reading CISA Releases AI Data Security Guidance