Court Rules
All enforcement actions
SettlementHigh RiskMultistate

CT AG Multistate $1.25M Settlement with Carnival Cruise Line for Data Breach

Carnival Cruise LineJune 22, 2022Connecticut Attorney General

Penalty Amount

$1,250,000

Consumers Affected

180,000

Summary

Connecticut, co-leading a multistate investigation, secured a $1.25 million settlement with Carnival Cruise Line over a 2019 data breach affecting approximately 180,000 individuals nationwide. The breach exposed sensitive data including passport numbers, driver's licenses, payment card information, and health data, with a 10-month delay in notification. Carnival agreed to implement enhanced email security measures, a breach response plan, and an independent security assessment.

Remedy

Carnival must implement and maintain a breach response and notification plan, provide email security training with dedicated phishing exercises, enable multi-factor authentication for remote email access, enforce strong password policies, maintain enhanced behavior analytics tools for network monitoring, and undergo an independent information security assessment.

Monetary PenaltyCompliance ProgramAudit Requirement

Contract Impact

In-house legal teams should review vendor agreements (especially those involving data processing or sharing), customer privacy policies, and employee data handling agreements. Key clauses to scrutinize include data security provisions (particularly email account protections), breach notification timelines (to avoid delays like the 10-month lapse), data retention and disposal policies (for unstructured data like emails), and audit rights for security assessments. Changes may be needed to mandate specific email security measures (e.g., multi-factor authentication, encryption), require prompt breach notification (e.g., within 72 hours), implement regular independent security audits, enhance data inventory practices for unstructured data, and ensure compliance with all applicable state breach notification laws.

Contract Search Terms

breach notification clauseemail security standardsdata retention policyindependent security assessmentsensitive data handlingnotification timelinedata inventory requirementsmultistate compliance

Violation Types

Entity Details

Entity

Carnival Cruise Line

Industry

Other

Multistate Coalition

Official Sources

Related Enforcement Actions

NJ

Carnival Cruise Line

$1.3M

New Jersey, as part of a multistate coalition, settled with Carnival Cruise Line over a 2019 data breach that compromised personal information of approximately 180,000 employees and customers nationwide. The breach resulted from deficiencies in Carnival's data security program and delayed breach notification. Carnival will pay $1.25 million and implement enhanced email security and breach response measures.

CT

Glenmark

$29.6M

Attorney General Jennifer Davenport joined a coalition of 48 states and territories in a $29.6 million settlement with Glenmark, a generic drug manufacturer, for allegedly conspiring to artificially inflate and manipulate prices, reduce competition, and restrain trade for numerous generic prescription drugs. The settlement includes cooperation in ongoing litigations and internal reforms to ensure fair competition.

CT

Glenmark

$29.6M

Attorney General William Tong led a coalition of 48 states and territories in a $29.6 million settlement with Glenmark, a generic drug manufacturer, to resolve allegations of a widespread conspiracy to artificially inflate prices, reduce competition, and unreasonably restrain trade for numerous generic prescription drugs. The settlement includes cooperation from Glenmark in ongoing multistate litigations and internal reforms to ensure fair competition and compliance with antitrust laws.

CT

23andMe

$18.0M

Attorney General William Tong led a coalition of 42 attorneys general in a settlement with the bankruptcy trustee for 23andMe, resolving allegations from a 2023 data breach that compromised the genetic data of 6.9 million customers. The settlement includes $150 million in allowed claims, with $18 million paid from bankruptcy funds, and requires enhanced data security measures for the new entity holding the data.

CT

Paramount Skydance Corporation

Attorney General William Tong joined a coalition of 12 attorneys general in suing to block the $110 billion acquisition of Warner Bros. Discovery, Inc. by Paramount Skydance Corporation. The lawsuit alleges the merger violates Section 7 of the Clayton Act by substantially lessening competition in theatrical film distribution and basic cable television licensing, which would harm consumers through higher prices and reduced quality.

CT

Federal Communications Commission

Attorney General William Tong and 48 other attorneys general submitted comments to the FCC urging stronger rules to prevent scammers from accessing legitimate telephone numbers for illegal robocalls. The coalition is responding to the FCC's proposed rules and asks for measures such as stronger certification, reporting, and prohibitions on number cycling.