Penalty Amount
$5,100,000
Consumers Affected
4,728,610
Connecticut Attorney General William Tong, along with California and New York Attorneys General, settled with Illuminate Education, Inc. for failing to protect student data in a breach that exposed personal information of millions of students. The settlement, the first under Connecticut's Student Data Privacy Law, requires Illuminate to pay $5.1 million and implement enhanced cybersecurity measures.
Illuminate must pay $5.1 million and adopt measures including reviewing contracts, employing data safeguards, access controls, risk assessments, establishing a right to delete data, monitoring vendors, and obtaining third-party security assessments.
In-house legal teams should review all agreements where the company acts as a data processor or service provider to educational institutions, including vendor contracts with school districts and any subcontractor agreements. Key clauses to scrutinize are data security specifications, breach notification timelines and procedures, data retention and deletion terms, representations of compliance with student privacy laws (like FEPRA and state-specific statutes), and requirements for subprocessor oversight. Given the failure to implement basic monitoring and security, contracts may need to be amended to include more prescriptive technical controls (e.g., mandatory encryption, continuous security monitoring), shorter breach notification windows, regular independent security audits, and explicit indemnification for privacy violations.
Entity
Illuminate Education, Inc.
Also known as: Illuminate Education
Industry
TechnologyOfficial Press Release
https://portal.ct.gov/ag/press-releases/2025-press-releases/attorney-general-tong-enters-into-settlement-in-first-action-under-student-data-privacy-law
illuminate education avc ct fully executed 103025.pdf?rev=c1
https://portal.ct.gov/-/media/ag/press_releases/2025/illuminate-education-avc-ct--fully-executed-103025.pdf?rev=c1b494f168ea413886ade5983a62afe0&hash=57D77A8E4F5595FCF16A00239839BC18
Connecticut Attorney General Enforcement Page
https://portal.ct.gov/AG/Privacy/Privacy-Resources
"Illuminate Education, Inc."
"$5.1 million"
"Connecticut’s Student Data Privacy Law"
"failed to implement basic security measures to protect students’ data"
"experienced a data breach"
"personal information of millions of students"
The FTC proposed a consent order against Illuminate Education, Inc. for failing to secure student data, leading to a breach affecting over 10 million students. The company allegedly had security failures and delayed breach notifications. The order requires a data security program, data deletion, and a retention schedule.
$5.1M
New York, California, and Connecticut attorneys general reached a $5.1 million settlement with educational technology company Illuminate Education, Inc. for failing to protect student data, resulting in a 2022 breach exposing millions of students’ personal information. The investigation found Illuminate failed to implement basic security measures including data encryption, suspicious activity monitoring, and proper decommissioning of inactive user accounts, and did not delete student data when required by contracts. Illuminate must pay the penalty and implement enhanced data security measures including a comprehensive information security program, encryption of student data, and annual notice to schools about data collection and deletion options.
$5.1M
California Attorney General Rob Bonta, joined by Connecticut and New York Attorneys General, secured a $5.1 million multistate settlement with edtech company Illuminate Education, Inc. over a 2021 data breach that exposed sensitive personal and medical information of millions of students, including over 434,000 California students. The investigation found Illuminate failed to implement basic security measures, including failing to terminate former employee credentials, lacking suspicious activity monitoring, and unsecured backup databases, as well as making false statements in its privacy policy. Illuminate must pay $3.25 million to California, implement enhanced security practices, and notify the CA DOJ of future student data breaches.
Connecticut Attorney General William Tong announced a civil investigative demand into MediaLab.AI Inc., owner of the Kik Messenger app, over lax age assurance practices, content moderation, and child safety failures that advocates have dubbed a "predator's paradise." The action follows a July 2025 notice of violation under the Connecticut Data Privacy Act for privacy notice deficiencies and processing sensitive data — including health, biometric, and precise geolocation data — without proper consent, which the company has only partially addressed. The new investigation seeks records related to practices that may constitute unfair or deceptive acts or practices under the CTDPA and the Connecticut Unfair Trade Practices Act. No fine has been imposed to date.
Attorney General William Tong issued a consumer alert warning Connecticut residents about unregulated, offshore decentralized finance (DeFi) cryptocurrency exchanges, naming GMX, Gains Network, dYdX, Aevo, Drift Protocol, Vertex Protocol, and Hyperliquid. The alert highlights risks including bypassing U.S. law via VPNs, predatory leverage up to 250x, misleading synthetic asset products, and lack of KYC protections. No enforcement action or penalty was imposed; at least one Connecticut consumer reportedly lost $200,000 deposited with an unregulated DeFi exchange.
$2.0M
Attorney General Tong and a coalition of four other states and the FTC sued Zillow and Redfin after Zillow paid Redfin $100 million to shut down its multifamily rental advertising business and transfer clients to Zillow. The settlement requires the companies to restore competition, with Redfin rebuilding its apartment advertising business, and pay $2 million to the coalition.