On August 19, 2026, Connecticut Attorney General William Tong announced a $275,000 settlement with online tax preparation company TaxAct over allegations that the company improperly disclosed taxpayer information to advertising partners through third-party tracking technologies on its website. The Attorney General alleged that, between January 2018 and December 2022, TaxAct used third-party tracking technologies for analytics and marketing purposes and, in doing so, disclosed detailed taxpayer information without informing consumers.

The settlement is notable because it highlights regulatory scrutiny over the disclosure of financial information, and also because it imposes extensive governance, monitoring, and auditing requirements on TaxAct relating to the use of third-party tracking technologies. In addition, the settlement does not specify what law was allegedly violated.

Alleged Disclosures of Taxpayer Information

According to the Attorney General, TaxAct disclosed various categories of taxpayer information to advertising partners through tracking technologies embedded on its website. The information allegedly disclosed included rounded adjusted gross income, rounded tax refunds and taxes owed, and certain information relating to taxpayers’ income and deductions. The Attorney General also alleged that the disclosures included information concerning taxpayers’ number of dependents and whether they reported charitable contributions, investment income, mortgage interest, or student loan interest.

The Attorney General further alleged that TaxAct’s agreement with its advertising partner did not limit the partner’s ability to use the information for its own purposes or to share the information with additional third parties. According to the settlement announcement, TaxAct did not notify taxpayers of these disclosures despite representing in its privacy notices that it would safeguard consumer privacy and prohibit third parties from sharing TaxAct data.

Settlement Requires Third-Party Tracking Governance Program

In addition to the $275,000 payment, the settlement requires TaxAct to implement a compliance program governing its use of third-party tracking technologies. According to the Attorney General’s announcement, the settlement requires TaxAct to:

  • Establish a review committee responsible for overseeing the use of third-party tracking technologies;
  • Implement written policies and procedures governing the approval of new tracking technologies and modifications to existing technologies;
  • Maintain documentation identifying the data points collected through third-party tracking technologies;
  • Deploy a tag-monitoring system that regularly scans the company’s website to verify that tracking technologies are functioning as approved; and
  • Obtain two independent third-party audits assessing compliance with the company’s third-party tracking governance program.

These requirements focus heavily on ongoing oversight and technical monitoring of tracking technologies, rather than solely on notice and consent obligations.

Print:
Email this postTweet this postLike this postShare this post on LinkedIn
Photo of Lindsey Tonsager Lindsey Tonsager

Lindsey Tonsager is a recognized leader in representing companies before federal and state regulators, and is renowned for advising on minor protection, AI, and state comprehensive privacy laws.

Lindsey chairs the firm’s global Data Privacy and Cybersecurity practice. She advises clients in their…

Lindsey Tonsager is a recognized leader in representing companies before federal and state regulators, and is renowned for advising on minor protection, AI, and state comprehensive privacy laws.

Lindsey chairs the firm’s global Data Privacy and Cybersecurity practice. She advises clients in their strategic and proactive engagement with the Federal Trade Commission, the U.S. Congress, the California Privacy Protection Agency, and State Attorneys General on proposed changes to data protection laws, and regularly represents clients in responding to investigations and enforcement actions involving their privacy and information security practices.

Lindsey’s practice focuses on helping clients launch new products and services that implicate the laws governing the use of artificial intelligence; data processing for robotics, autonomous vehicles, and other connected devices; biometrics; online advertising; the collection of personal information from children, teens, and students online; e-mail marketing; disclosures of video viewing information; and new technologies.

Lindsey also assesses privacy and data security risks in complex corporate transactions where personal data is a critical asset or data processing risks are otherwise material. In light of a dynamic regulatory environment where new state, federal, and international data protection laws are always on the horizon and enforcement priorities are shifting, she focuses on designing risk-based global privacy programs for clients that can keep pace with evolving legal requirements and efficiently leverage the clients’ existing privacy policies and practices. She conducts data protection assessments to benchmark against legal requirements and industry trends and proposes practical risk mitigation measures.

Photo of Jenna Zhang Jenna Zhang

Jenna Zhang advises clients across industries on data privacy, cybersecurity, and emerging technologies. 

Jenna partners with clients to ensure their compliance with the rapidly evolving federal and state privacy and cybersecurity laws. She supports clients in designing new products and services, drafting privacy…

Jenna Zhang advises clients across industries on data privacy, cybersecurity, and emerging technologies. 

Jenna partners with clients to ensure their compliance with the rapidly evolving federal and state privacy and cybersecurity laws. She supports clients in designing new products and services, drafting privacy notices and terms of use, responding to cyber and data security incidents, and evaluating privacy and cybersecurity risks in corporate transactions. In particular, she advises clients on substantive requirements relating to children’s and student privacy, including COPPA, FERPA, age-appropriate design code laws, and social media laws.

As part of her practice, Jenna regularly represents clients in data privacy investigations and enforcement actions brought by the Federal Trade Commission and state attorneys general. She also supports clients in proactive engagement with regulators and policymakers to ensure their perspectives are heard.

Jenna also maintains an active pro bono practice with a focus on supporting families in adoptions, guardianships, and immigration matters.

Photo of Bolatito Adetula Bolatito Adetula

Tito Adetula is an associate in the firm’s Washington, DC office. She is a member of the Data Privacy and Cybersecurity Practice Group. Tito advises clients on a broad range of data privacy matters, with a focus on artificial intelligence, state privacy laws…

Tito Adetula is an associate in the firm’s Washington, DC office. She is a member of the Data Privacy and Cybersecurity Practice Group. Tito advises clients on a broad range of data privacy matters, with a focus on artificial intelligence, state privacy laws, and regulatory compliance matters. She has experience counseling clients on state privacy and advertising technology compliance, as well as counselling clients on related e-discovery data retention issues.

Tito also maintains an active pro bono practice focused on data privacy and cybersecurity matters.