Court Rules
All enforcement actions
SettlementHigh RiskMultistate

Multi-State $5.1M Settlement with Illuminate Over Student Data Breach

Illuminate Education, Inc.November 6, 2025Connecticut Attorney General

Penalty Amount

$5,100,000

Consumers Affected

4,728,610

Summary

Connecticut Attorney General William Tong, along with California and New York Attorneys General, settled with Illuminate Education, Inc. for failing to protect student data in a breach that exposed personal information of millions of students. The settlement, the first under Connecticut's Student Data Privacy Law, requires Illuminate to pay $5.1 million and implement enhanced cybersecurity measures.

Remedy

Illuminate must pay $5.1 million and adopt measures including reviewing contracts, employing data safeguards, access controls, risk assessments, establishing a right to delete data, monitoring vendors, and obtaining third-party security assessments.

Monetary PenaltyAudit RequirementCompliance ProgramData Deletion

Contract Impact

In-house legal teams should review all agreements where the company acts as a data processor or service provider to educational institutions, including vendor contracts with school districts and any subcontractor agreements. Key clauses to scrutinize are data security specifications, breach notification timelines and procedures, data retention and deletion terms, representations of compliance with student privacy laws (like FEPRA and state-specific statutes), and requirements for subprocessor oversight. Given the failure to implement basic monitoring and security, contracts may need to be amended to include more prescriptive technical controls (e.g., mandatory encryption, continuous security monitoring), shorter breach notification windows, regular independent security audits, and explicit indemnification for privacy violations.

Contract Search Terms

student data privacy addendumdata processing agreement for educational servicesFERPA compliance clausebreach notification requirementsdata security standards and safeguardsencryption of student recordsaccess controls and monitoringsubprocessor management obligationsdata retention and deletion policyincident response plan

Laws Cited

Connecticut’s Student Data Privacy Law

Violation Types

Entity Details

Entity

Illuminate Education, Inc.

Also known as: Illuminate Education

Industry

Technology

Multistate Coalition

Official Sources

Source Evidence

Entity Name
"Illuminate Education, Inc."
Fine Amount
"$5.1 million"
Laws Cited
"Connecticut’s Student Data Privacy Law"
Violation Types
"failed to implement basic security measures to protect students’ data"
Violation Types
"experienced a data breach"
Violation Types
"personal information of millions of students"

Related Enforcement Actions

FTC

Illuminate Education, Inc.

The FTC proposed a consent order against Illuminate Education, Inc. for failing to secure student data, leading to a breach affecting over 10 million students. The company allegedly had security failures and delayed breach notifications. The order requires a data security program, data deletion, and a retention schedule.

NY

Illuminate Education, Inc.

$5.1M

New York, California, and Connecticut attorneys general reached a $5.1 million settlement with educational technology company Illuminate Education, Inc. for failing to protect student data, resulting in a 2022 breach exposing millions of students’ personal information. The investigation found Illuminate failed to implement basic security measures including data encryption, suspicious activity monitoring, and proper decommissioning of inactive user accounts, and did not delete student data when required by contracts. Illuminate must pay the penalty and implement enhanced data security measures including a comprehensive information security program, encryption of student data, and annual notice to schools about data collection and deletion options.

CA

Illuminate Education, Inc.

$5.1M

California Attorney General Rob Bonta, joined by Connecticut and New York Attorneys General, secured a $5.1 million multistate settlement with edtech company Illuminate Education, Inc. over a 2021 data breach that exposed sensitive personal and medical information of millions of students, including over 434,000 California students. The investigation found Illuminate failed to implement basic security measures, including failing to terminate former employee credentials, lacking suspicious activity monitoring, and unsecured backup databases, as well as making false statements in its privacy policy. Illuminate must pay $3.25 million to California, implement enhanced security practices, and notify the CA DOJ of future student data breaches.

CT

Glenmark

$29.6M

Attorney General Jennifer Davenport joined a coalition of 48 states and territories in a $29.6 million settlement with Glenmark, a generic drug manufacturer, for allegedly conspiring to artificially inflate and manipulate prices, reduce competition, and restrain trade for numerous generic prescription drugs. The settlement includes cooperation in ongoing litigations and internal reforms to ensure fair competition.

CT

Glenmark

$29.6M

Attorney General William Tong led a coalition of 48 states and territories in a $29.6 million settlement with Glenmark, a generic drug manufacturer, to resolve allegations of a widespread conspiracy to artificially inflate prices, reduce competition, and unreasonably restrain trade for numerous generic prescription drugs. The settlement includes cooperation from Glenmark in ongoing multistate litigations and internal reforms to ensure fair competition and compliance with antitrust laws.

CT

23andMe

$18.0M

Attorney General William Tong led a coalition of 42 attorneys general in a settlement with the bankruptcy trustee for 23andMe, resolving allegations from a 2023 data breach that compromised the genetic data of 6.9 million customers. The settlement includes $150 million in allowed claims, with $18 million paid from bankruptcy funds, and requires enhanced data security measures for the new entity holding the data.