Penalty Amount
$175,000,000
Consumers Affected
147,000,000
California Attorney General Xavier Becerra, leading a multistate coalition of all 50 states, the District of Columbia, and Puerto Rico, announced a settlement with Equifax over a 2017 data breach that exposed personal information of 147 million consumers, including 15 million Californians. The breach resulted from Equifax’s failure to apply a critical software patch and implement adequate security measures, with disclosure delayed for months after discovery. Equifax will pay $175 million in state penalties, up to $425 million in consumer restitution, and implement enhanced data security measures and ten years of free credit monitoring for affected consumers.
Equifax must pay $175 million in penalties to states, including over $18.7 million to California, and up to $425 million into a restitution fund for affected consumers, who may receive cash reimbursement for breach-related losses or free credit monitoring for up to 10 years. Injunctive terms require Equifax to implement a comprehensive Information Security Program, hire a Chief Information Security Officer, reduce unnecessary storage of Social Security numbers, establish a consumer assistance process for identity theft claims, and comply with data protection requirements. Equifax is banned from profiting off data collected in connection with the breach or settlement remedies.
In-house legal teams should review vendor agreements with data brokers, credit reporting agencies, and third-party service providers to ensure robust data security clauses mandating timely software patching, encryption of sensitive personal information (including Social Security numbers), and comprehensive Information Security Programs. Breach notification clauses must be updated to require immediate disclosure of security incidents, aligning with state and federal notification timelines, and include obligations to provide consumer remediation such as credit monitoring. Data retention clauses should limit unnecessary storage of sensitive consumer data like Social Security numbers, and all contracts involving consumer personal information should require vendors to comply with applicable data protection laws and injunctive terms from enforcement actions.
Entity
Equifax
Industry
Data BrokerOfficial Press Release
https://oag.ca.gov/news/press-releases/attorney-general-becerra-announces-settlement-against-equifax-providing-600
Equifax Complaint
https://oag.ca.gov/system/files/attachments/press-docs/Equifax%20Complaint.pdf
Equifax Final approved judgment
https://oag.ca.gov/system/files/attachments/press-docs/Equifax%20-%20Final%20approved%20%20judgment.pdf
California Attorney General Enforcement Page
https://oag.ca.gov/privacy/privacy-enforcement-actions
"Equifax"
"pay another $175 million to states in penalties"
"Monday, July 22, 2019"
"California Attorney General Xavier Becerra today announced a nationwide settlement against Equifax"
"improperly exposed the personal information of 147 million consumers"
"failed to apply a critical software fix and implement security measures that would have protected and encrypted consumers’ data"
New Jersey Attorney General Christopher Porrino announced that New Jersey has joined a multi-state investigation into Equifax following a data breach affecting 143 million consumers. The multi-state group sent a letter demanding Equifax disable fee-based credit monitoring services and reimburse consumers for credit freeze fees with other bureaus, citing unfair practices and a months-long delay in breach disclosure.
A coalition of 12 state attorneys general, led by Colorado AG Phil Weiser, obtained a temporary restraining order from a federal court in California to halt the proposed $110 billion merger of Warner Bros. Discovery, Inc. by Paramount Skydance Corporation. The lawsuit alleges the merger violates Section 7 of the Clayton Act by substantially lessening competition in film distribution, anticipated blockbuster film distribution, and licensing cable TV channels.
The California Privacy Protection Agency (CalPrivacy) joined a coalition of 18 Attorneys General and state agencies in opposing the proposed SECURE Data Act, a federal privacy bill that would preempt stronger state privacy laws like the CCPA. The coalition argues the bill would weaken consumer privacy protections, limit enforcement remedies, and undermine California's Delete Request and Opt-out Platform (DROP).
$12.8M
California Attorney General Rob Bonta, along with multiple district attorneys and the California Privacy Protection Agency, announced a $12.75 million settlement with General Motors for illegally selling hundreds of thousands of Californians' location and driving data to data brokers Verisk and LexisNexis without notice or consent. The settlement includes the largest CCPA penalty to date, a five-year ban on selling driving data to consumer reporting agencies, and requirements to delete retained data and implement a robust privacy program.
The California Privacy Protection Agency Board voted to support two bills (AB 1542 and SB 1106) and took a 'support if amended' position on a third bill (AB 883). These bills aim to strengthen privacy protections by expanding sensitive data protections, improving deletion rights under the Delete Act, and providing expedited deletion for elected officials and judges.
The California Privacy Protection Agency sent a letter to Congress opposing the SECURE Data Act, a federal bill that would preempt state privacy laws like the CCPA and Delete Act. The letter argues the bill would eliminate rights for 40 million Californians, including the DROP platform and opt-out preference signal requirements, and urges Congress to set a floor rather than a ceiling on privacy protections.