Photo of Lindsey Tonsager

Lindsey Tonsager

Lindsey Tonsager is a recognized leader in representing companies before federal and state regulators, and is renowned for advising on minor protection, AI, and state comprehensive privacy laws.

Lindsey chairs the firm’s global Data Privacy and Cybersecurity practice. She advises clients in their strategic and proactive engagement with the Federal Trade Commission, the U.S. Congress, the California Privacy Protection Agency, and State Attorneys General on proposed changes to data protection laws, and regularly represents clients in responding to investigations and enforcement actions involving their privacy and information security practices.

Lindsey’s practice focuses on helping clients launch new products and services that implicate the laws governing the use of artificial intelligence; data processing for robotics, autonomous vehicles, and other connected devices; biometrics; online advertising; the collection of personal information from children, teens, and students online; e-mail marketing; disclosures of video viewing information; and new technologies.

Lindsey also assesses privacy and data security risks in complex corporate transactions where personal data is a critical asset or data processing risks are otherwise material. In light of a dynamic regulatory environment where new state, federal, and international data protection laws are always on the horizon and enforcement priorities are shifting, she focuses on designing risk-based global privacy programs for clients that can keep pace with evolving legal requirements and efficiently leverage the clients’ existing privacy policies and practices. She conducts data protection assessments to benchmark against legal requirements and industry trends and proposes practical risk mitigation measures.

On August 19, 2026, Connecticut Attorney General William Tong announced a $275,000 settlement with online tax preparation company TaxAct over allegations that the company improperly disclosed taxpayer information to advertising partners through third-party tracking technologies on its website. The Attorney General alleged that, between January 2018 and December 2022, TaxAct used third-party tracking technologies for analytics and marketing purposes and, in doing so, disclosed detailed taxpayer information without informing consumers.

The settlement is notable because it highlights regulatory scrutiny over the disclosure of financial information, and also because it imposes extensive governance, monitoring, and auditing requirements on TaxAct relating to the use of third-party tracking technologies. In addition, the settlement does not specify what law was allegedly violated.

Continue Reading Connecticut Attorney General Settles with TaxAct Over Sharing Taxpayer Data

Employers increasingly rely on automated tools to help make decisions concerning hiring, promotion, discipline, and termination. In response, state legislatures and agencies have begun to regulate uses of these technologies, often referred to as automated decision-making technology (“ADMT”). These laws generally require entities that deploy ADMT in the employment context

Continue Reading ADMT Law Round-Up: What Employers Need to Know About Recent ADMT Laws

On July 28, 2026, the New York Office of the Attorney General released final rules (the “Rules”) implementing the Stop Addictive Feeds Exploitation (SAFE) for Kids Act, which goes into effect on January 25, 2027.

The SAFE for Kids Act requires online “addictive social media platforms,” which are defined as

Continue Reading New York Publishes Final SAFE For Kids Act Rules

On July 23, 2026, New Jersey Governor Mikie Sherrill signed A4085 (the Fair Price Protection Act) into law, which prohibits companies from charging consumers different prices for groceries based on their personal data. New Jersey will join New York, Connecticut, and Maryland in imposing prohibitions and requirements on the use

Continue Reading New Jersey Enacts Ban on Surveillance Pricing

On June 2, 2026, Colorado Governor Jared Polis vetoed HB 26-1210, a bill that would have imposed requirements for use of “surveillance data” to set individualized prices for consumers or individualized wage setting for workers. The veto is yet another action in a trend of bills focused on regulating “surveillance” or “dynamic” pricing.

Continue Reading Colorado Governor Vetoes Overly Broad Algorithmic Pricing and Wage Setting Bill

Last month, the Illinois Department of Human Rights (“IDHR”) released draft regulations addressing employers’ use of AI in employment decisions and invited public comment. The IDHR will hold a hearing on the draft regulations on June 10, and the public comment period will close on June 29.

Background

HB

Continue Reading Illinois Department of Human Rights Seeks Public Comment on Draft AI Employment Regulations

On May 27, the Connecticut governor signed SB 4, an omnibus privacy law, followed a week later by two clean-up bills, HB 2222 and HB 5563 (collectively “SB 4”). SB 4, among other things, amends the Connecticut Data Privacy Act (“CTDPA”), establishes a data broker registry and accessible deletion mechanism, imposes restrictions on surveillance pricing, and creates requirements for direct-to-consumer genetic testing companies.

Continue Reading Connecticut Enacts Omnibus Privacy Law

On April 28, 2026, Maryland Governor Moore signed HB 895 (the Protection From Predatory Pricing Act) into law, which will impose limitations on the use of personalized pricing in the food retail and grocery delivery context.  The law will go into effect on October 1, 2026.  As we have detailed in prior blog posts, there has been a wave of personalized pricing proposals at the state level, and the FTC is focusing attention on pricing in the grocery sector.

Continue Reading Maryland Enacts Law on Personalized Food Pricing