Court Rules
All enforcement actions
SettlementMedium Risk

CA AG Settles with Glow for $250K Over Fertility App Privacy Failures

Glow, Inc.September 17, 2020California Attorney General

Penalty Amount

$250,000

Summary

California Attorney General Xavier Becerra announced a settlement with Glow, Inc., operator of a fertility-tracking mobile app, over privacy and security failures that risked exposing millions of users’ sensitive personal and medical information. The settlement includes a $250,000 civil penalty and injunctive terms requiring Glow to implement privacy and security design principles, obtain affirmative user consent for data sharing, and allow users to revoke consent. Glow was alleged to have failed to safeguard health information, allowed unauthorized access to user data, and maintained flawed password reset functions that could enable third-party access without consent.

Remedy

Glow must pay a $250,000 civil penalty. It is required to incorporate privacy and security design principles into its mobile apps, obtain affirmative user consent before sharing or disclosing personal, medical, or sensitive information, allow users to revoke previously granted consent, and consider how privacy or security lapses uniquely impact women. Glow must also comply with all applicable state consumer protection and privacy laws.

Monetary PenaltyInjunctionCompliance Program

Contract Impact

In-house legal teams should review privacy, data processing, and security clauses in user agreements, vendor contracts for third-party service providers handling user data, and public privacy policies. Specifically, teams must ensure clauses require affirmative user consent prior to sharing or disclosing sensitive or health data, include clear mechanisms for users to revoke consent, mandate implementation of privacy-by-design and security principles (including secure password reset functions), and require robust safeguards for medical and personal information. Additionally, contracts with app developers or technology vendors should include specific security requirements for access controls and password functions to prevent unauthorized data access.

Contract Search Terms

affirmative consenthealth data sharingdata security safeguardspassword reset securitymedical information consentconsent revocationsensitive data access controlsprivacy by design

Violation Types

Entity Details

Entity

Glow, Inc.

Also known as: Glow

Industry

Technology

Official Sources

Source Evidence

Entity Name
"Glow, Inc. (Glow), a technology company that operates a fertility-tracking mobile app that stores personal and medical information"
Event Date
"Thursday, September 17, 2020"
Fine Amount
"$250,000 civil penalty"
Violation Types
"Failed to adequately safeguard health information;"
Violation Types
"Allowed access to user’s information without the user’s consent;"
Violation Types
"Additional security problems with the app's password change function could have allowed third parties to reset user account passwords and access information in those accounts without user consent."

Related Enforcement Actions

CA

California State Legislature

The California Privacy Protection Agency announced that the California State Legislature approved the Expanding Privacy Rights Act (SB 923), which expands the CCPA's right to delete to cover all non-exempt personal information a business holds about a consumer, including data originally collected from third parties. The bill also requires online-only businesses with a direct relationship to consumers to provide online methods, such as webforms, for submitting access, deletion, and correction requests, and expressly permits businesses to retain suppression lists so deleted information stays deleted. The bill, authored by Senator Becker and sponsored by CalPrivacy, now goes to the Governor for consideration.

CA

Meta Platforms, Inc.

A bipartisan coalition of 33 state attorneys general, led by Minnesota AG Keith Ellison, began trial against Meta Platforms, Inc., alleging the company knowingly designed and deployed harmful features on Facebook and Instagram that drive children and teens to use the platforms compulsively, while falsely assuring parents and the public that its platforms were safe for young users. The states also allege Meta illegally collected personal information from children under 13 without parental consent, violating COPPA. The trial opened before Judge Yvonne Gonzalez Rogers in the U.S. District Court for the Northern District of California, with the states seeking monetary penalties and injunctive relief.

CA

Paramount Skydance Corporation

A coalition of 12 state attorneys general, led by Colorado AG Phil Weiser, obtained a temporary restraining order from a federal court in California to halt the proposed $110 billion merger of Warner Bros. Discovery, Inc. by Paramount Skydance Corporation. The lawsuit alleges the merger violates Section 7 of the Clayton Act by substantially lessening competition in film distribution, anticipated blockbuster film distribution, and licensing cable TV channels.

CA

California Privacy Protection Agency

The California Privacy Protection Agency (CalPrivacy) joined a coalition of 18 Attorneys General and state agencies in opposing the proposed SECURE Data Act, a federal privacy bill that would preempt stronger state privacy laws like the CCPA. The coalition argues the bill would weaken consumer privacy protections, limit enforcement remedies, and undermine California's Delete Request and Opt-out Platform (DROP).

CA

Meta Platforms, Inc.

A bipartisan coalition of state attorneys general began trial against Meta Platforms, Inc., alleging the company knowingly designed addictive features on Facebook and Instagram that harm children and teens, deceived parents about platform safety, and illegally collected personal information from children under 13 without parental consent in violation of COPPA. The states seek monetary penalties, an injunction to stop unlawful practices, and other relief. The trial is being litigated in the U.S. District Court for the Northern District of California.

CA

General Motors

$12.8M

California Attorney General Rob Bonta, along with multiple district attorneys and the California Privacy Protection Agency, announced a $12.75 million settlement with General Motors for illegally selling hundreds of thousands of Californians' location and driving data to data brokers Verisk and LexisNexis without notice or consent. The settlement includes the largest CCPA penalty to date, a five-year ban on selling driving data to consumer reporting agencies, and requirements to delete retained data and implement a robust privacy program.