Penalty Amount
$1,250,000
Consumers Affected
180,000
Connecticut, co-leading a multistate investigation, secured a $1.25 million settlement with Carnival Cruise Line over a 2019 data breach affecting approximately 180,000 individuals nationwide. The breach exposed sensitive data including passport numbers, driver's licenses, payment card information, and health data, with a 10-month delay in notification. Carnival agreed to implement enhanced email security measures, a breach response plan, and an independent security assessment.
Carnival must implement and maintain a breach response and notification plan, provide email security training with dedicated phishing exercises, enable multi-factor authentication for remote email access, enforce strong password policies, maintain enhanced behavior analytics tools for network monitoring, and undergo an independent information security assessment.
In-house legal teams should review vendor agreements (especially those involving data processing or sharing), customer privacy policies, and employee data handling agreements. Key clauses to scrutinize include data security provisions (particularly email account protections), breach notification timelines (to avoid delays like the 10-month lapse), data retention and disposal policies (for unstructured data like emails), and audit rights for security assessments. Changes may be needed to mandate specific email security measures (e.g., multi-factor authentication, encryption), require prompt breach notification (e.g., within 72 hours), implement regular independent security audits, enhance data inventory practices for unstructured data, and ensure compliance with all applicable state breach notification laws.
Entity
Carnival Cruise Line
Industry
Other$1.3M
New Jersey, as part of a multistate coalition, settled with Carnival Cruise Line over a 2019 data breach that compromised personal information of approximately 180,000 employees and customers nationwide. The breach resulted from deficiencies in Carnival's data security program and delayed breach notification. Carnival will pay $1.25 million and implement enhanced email security and breach response measures.
$2.0M
Attorney General Tong and a coalition of four other states and the FTC sued Zillow and Redfin after Zillow paid Redfin $100 million to shut down its multifamily rental advertising business and transfer clients to Zillow. The settlement requires the companies to restore competition, with Redfin rebuilding its apartment advertising business, and pay $2 million to the coalition.
Attorney General William Tong sent a letter to the Connecticut Insurance Department urging rejection of double-digit rate increases sought by Anthem, ConnectiCare, and UnitedHealthcare for individual and small group health insurance plans covering about 220,000 people. The letter argues the rates exceed inflationary measures and criticizes the carriers for failing to control costs and for poor claims system management, particularly ConnectiCare's transition to Molina Healthcare.
$275K
Connecticut Attorney General William Tong announced a $275,000 settlement with TaxAct, an online tax preparation company, over allegations that between January 2018 and December 2022, TaxAct improperly disclosed detailed customer financial information to Meta and Google through third-party tracking technologies without notifying taxpayers. The settlement requires TaxAct to pay $275,000 and implement new third-party tracking compliance measures, including a review committee, written policies, a tag monitoring system, and two independent third-party audits.
$4.0M
Connecticut Attorney General William Tong and the Federal Trade Commission announced a $4 million settlement with Manchester City Nissan (Chase Nissan LLC) resolving allegations that the dealership double-charged for 'certified pre-owned' vehicles and collected unauthorized junk fees. The settlement requires payment for consumer redress, prohibits misrepresentations, mandates clear disclosure of the maximum total price, and requires express informed consent for all charges.
Attorney General Tong and a coalition of 21 attorneys general and Pennsylvania filed lawsuits against the U.S. Department of Transportation, FMCSA, and DHS to block demands for the personal information of 17 million CDL drivers. The lawsuits allege violations of federal privacy laws and the Administrative Procedure Act, and seek an emergency order to prevent the data transfer.