Court Rules

California Attorney General

Privacy and consumer protection enforcement actions tracked from official California Attorney General sources.

Official enforcement page

54

Total Actions

$573.3M

Total Fines

Enforcement Action

Nexstar Media Group, Inc. and Tegna Inc.

California Attorney General Rob Bonta, joined by attorneys general from seven other states, filed a lawsuit to block the $6.2 billion merger between Nexstar Media Group and Tegna Inc. The lawsuit alleges the merger violates Section 7 of the Clayton Act by reducing competition in local TV markets, leading to higher prices, less local news, and job losses.

Enforcement Action

U.S. Department of Education

California Attorney General Rob Bonta filed a lawsuit against the U.S. Department of Education to block the expansion of IPEDS data collection requiring colleges to submit race-linked student data. The lawsuit argues the demand is arbitrary, capricious, and burdensome, and could enable costly partisan investigations. A multistate coalition co-led the challenge.

Student Data
Enforcement Action

Live Nation

California Attorney General Rob Bonta and a coalition of state attorneys general announced they will continue their antitrust lawsuit against Live Nation/Ticketmaster after the U.S. Department of Justice settled the case. The states aim to hold Live Nation accountable for anticompetitive conduct that harms consumers, artists, and venues in the live music industry.

Settlement

Ford Motor Company

The California Privacy Protection Agency (CalPrivacy) settled with Ford Motor Company requiring the company to pay a $375,703 fine and change its practices. Ford violated the CCPA by requiring consumers to complete an email verification step before they could opt-out of the sale and sharing of their personal information collected through digital properties and connected vehicle services. In addition to the fine, Ford must provide easy methods to submit opt-out requests with minimal steps, audit its tracking technologies, and ensure compliance with opt-out preference signals including Global Privacy Control.

Opt-Out Failure

$376K

Enforcement Action

GoFundMe

California Attorney General Rob Bonta, co-leading a bipartisan coalition of 21 attorneys general and charitable regulators, sent a letter to GoFundMe demanding the platform remove all plagiarized donation web pages for over 1.4 million charities, disclose information about donations, and ensure pages do not outrank official charity sites in search results. The action follows reports that GoFundMe used charities' information without consent and engaged in deceptive solicitations, violating state charitable solicitation and consumer protection laws.

Consent Failure
Guidance

U.S. Department of Health and Human Services

California Attorney General Rob Bonta sent a letter to the U.S. Department of Health and Human Services opposing a proposed rule that would eliminate model card requirements for AI tools in healthcare, warning that such rollbacks could lead to biased and unsafe healthcare decisions by reducing transparency.

AI/Automated DecisionsHealth Data
Enforcement Action

U.S. Department of Agriculture

California Attorney General Rob Bonta secured a second preliminary injunction from the U.S. District Court for the Northern District of California blocking the Trump Administration's demand that states turn over personal data of SNAP applicants and recipients. The court found the USDA's proposed data protocol would allow sharing of state data with entities unrelated to federal benefits administration, violating federal law.

Unauthorized Data Sharing
Settlement

The Walt Disney Company

The California Attorney General settled with The Walt Disney Company for $2.75 million over CCPA violations. Disney's opt-out processes failed to stop the sale or sharing of consumer data across all devices and services associated with accounts, requiring consumers to navigate cumbersome methods. Disney must pay the penalty and implement comprehensive opt-out mechanisms.

Opt-Out Failure

$2.8M

Investigation

businesses with significant online presence in the retail, grocery, and hotel sectors

California Attorney General Rob Bonta announced an investigative sweep targeting businesses that use surveillance pricing, which involves setting individualized prices based on consumer data. The Department of Justice is sending information request letters to companies in the retail, grocery, and hotel sectors to assess compliance with the CCPA's purpose limitation principle. This action seeks to ensure that consumers are not charged different prices without proper disclosure and that businesses adhere to privacy laws.

Surveillance PricingAI/Automated Decisions
Enforcement Action

xAI

California Attorney General Rob Bonta sent a cease and desist letter to xAI, demanding the company immediately stop the creation and distribution of deepfake, nonconsensual intimate images and child

AI/Automated DecisionsChildren's Data
Enforcement Action

U.S. Department of Justice

California Attorney General Rob Bonta joined a multistate coalition in filing an amicus brief opposing the U.S. Department of Justice's subpoena for patient records from University of Pittsburgh Medical Center related to gender-affirming care. The brief argues that the subpoena violates patient privacy, infringes on states' rights to regulate medicine, and exceeds DOJ's statutory authority.

Health DataChildren's Data
Enforcement Action

U.S. Department of Health and Human Services

California Attorney General Rob Bonta, alongside attorneys general from New York, Colorado, Illinois, and Minnesota, filed a motion for preliminary injunction to continue blocking the Trump Administration's unlawful freeze of $10 billion in federal funding for child care and family assistance programs and to prevent broad data requests for personally identifiable information of millions of residents. The funding freeze targets five Democratic-led states without evidence of fraud, and the data requests are part of the challenged unlawful actions. A temporary restraining order was previously granted blocking these measures.

Unauthorized Data Sharing
Investigation

xAI

California Attorney General Rob Bonta announced an investigation into xAI for its Grok AI model generating nonconsensual sexual images of women and children, including child sexual abuse material. The AG expressed deep concern and zero tolerance, urging immediate action to prevent further

Children's DataConsent Failure
Enforcement Action

Trump Administration

California Attorney General Rob Bonta, on behalf of a multistate coalition, filed a motion in U.S. District Court to enforce a preliminary injunction that blocks the Trump Administration from demanding personal and sensitive information about Supplemental Nutrition Assistance Program (SNAP) recipients. The Administration has renewed its demand, threatening to withhold administrative funding from states that do not comply, which the AG argues violates the existing court order and federal law protecting the confidentiality of SNAP applicant data.

Unauthorized Data Sharing
Fine

ROR Partners LLC

The California Privacy Protection Agency fined ROR Partners LLC $56,600 for failing to register as a data broker under the Delete Act. The Nevada-based marketing firm must pay the fine and past-due fees. This action is part of CalPrivacy's enforcement against unregistered data brokers.

Data Broker Non-Compliance

$57K

Guidance

Data Brokers

CalPrivacy issued Enforcement Advisory No. 2025-01 to remind data brokers of their annual registration obligations under California's Delete Act, including disclosing all trade names and websites and registering independently rather than through a parent company. The advisory warns that failures to comply may result in administrative fines of $200 per day, plus fees and recovery costs. It also highlights the upcoming Delete Request and Opt-Out Platform (DROP) launching January 1, 2026.

Data Broker Non-Compliance
Enforcement Action

U.S. Department of Justice

California Attorney General Rob Bonta joined 20 attorneys general in filing an amicus brief to quash a U.S. DOJ administrative subpoena seeking sensitive medical records and personally identifying information of adolescent patients receiving gender-affirming care at Children's Hospital Colorado. The brief argues the subpoena violates states' rights to regulate medicine under the Tenth Amendment and misinterprets the Food, Drug, and Cosmetic Act, which would harm off-label drug use across all medical fields.

Health DataChildren's Data
Investigation

Inteliquent, Bandwidth, Peerless, Lumen

California Attorney General Rob Bonta announced Phase 2 of Operation Robocall Roundup, a multistate investigation targeting four major voice service providers—Inteliquent, Bandwidth, Peerless, and Lumen—for routing suspected illegal robocalls. The Anti-Robocall Multistate Litigation Task Force sent warning letters demanding they stop transmitting such calls, following Phase 1 which already led to some providers being removed from the FCC's database. The AG emphasized that these companies have a heightened responsibility to block call traffic from known bad actors.

Consent Failure
Guidance

U.S. Department of Homeland Security

California Attorney General Rob Bonta co-led a coalition of 18 attorneys general in submitting a comment letter opposing the Department of Homeland Security's expansion of the Systematic Alien Verification for Entitlements (SAVE) program to include U.S.-born citizens. The coalition argues the expansion violates the Privacy Act of 1974, creates a massive surveillance database, increases data breach risks, and will lead to inaccurate verifications and denial of benefits.

Surveillance PricingUnauthorized Data Sharing
Guidance

California Attorney General Rob Bonta

California Attorney General Rob Bonta joined a bipartisan coalition of 36 state attorneys general in sending a letter to Congress opposing a proposed provision in the National Defense Authorization Act that would preempt state laws addressing AI risks. The coalition argues that states must retain authority to mitigate AI harms, particularly to children, and that state-level enforcement is critical for protecting residents from emerging threats like deepfakes and harmful AI interactions.

Settlement

Jam City, Inc.

California Attorney General Rob Bonta announced a $1.4 million settlement with Jam City, Inc. for violating the CCPA. The mobile gaming company failed to provide opt-out methods for the sale or sharing of personal information across its 21 apps and sold or shared data of children aged 13-16 without required affirmative consent. Jam City must now implement in-app opt-out mechanisms and obtain affirmative consent for minors' data.

Opt-Out FailureChildren's Data

$1.4M

Enforcement Action

Data Brokers

The California Privacy Protection Agency (CalPrivacy) announced the creation of a Data Broker Enforcement Strike Force to investigate privacy violations by data brokers under the CCPA and Delete Act. The strike force will focus on compliance with registration requirements and other obligations, building on previous enforcement actions to increase accountability.

Data Broker Non-Compliance
Settlement

Greystar Management Services LLC

California Attorney General Rob Bonta announced a $7 million settlement with Greystar Management Services LLC for using RealPage's algorithmic software to illegally align rent prices with competitors by sharing confidential pricing information, violating antitrust laws. Greystar must cease using such anticompetitive algorithms, refrain from data sharing, accept monitoring, and cooperate in the ongoing case against RealPage.

AI/Automated Decisions

$7.0M

Settlement

Illuminate Education, Inc.

Illuminate Education, Inc. suffered a data breach in 2021 due to security failures, exposing sensitive student data including medical conditions across millions of students. The company has agreed to pay $5.1 million in settlements to California, Connecticut, and New York and implement injunctive relief to strengthen data security practices.

Student DataHealth DataSecurity Failure

$5.1M

Guidance

California healthcare providers, service plans, and contractors

California Attorney General Rob Bonta issued an informational bulletin summarizing new responsibilities under SB 81, which expands protections for immigrants' medical information by designating immigration status as protected data under the Confidentiality of Medical Information Act (CMIA) and restricts immigration enforcement access to non-public areas of healthcare facilities.

Health Data
Enforcement Action

U.S. Department of Justice

California Attorney General Rob Bonta joined 15 attorneys general in filing an amicus brief to limit a U.S. DOJ subpoena seeking medical records of transgender youth from Children's Hospital of Philadelphia, arguing it violates patient privacy and could intimidate providers of gender-affirming care.

Health DataChildren's Data
Settlement

Sling TV LLC

California Attorney General Rob Bonta settled with Sling TV for $530,000 over CCPA violations. Sling TV failed to provide an easy-to-use opt-out mechanism for the sale of personal information and lacked adequate privacy protections for children's data. The settlement requires Sling TV to implement changes to ensure CCPA compliance, including improved opt-out processes and children's privacy safeguards.

Opt-Out FailureChildren's Data

$530K

Settlement

Sling TV LLC and Dish Media Sales LLC

California Attorney General Rob Bonta secured a $530,000 settlement with Sling TV for violating the CCPA. The company failed to provide an easy-to-use method for consumers to opt-out of the sale of their personal information and did not provide adequate privacy protections for children. The settlement requires Sling TV to implement specific changes to its opt-out mechanisms and parental controls.

Opt-Out FailureChildren's Data

$530K

Investigation

OpenAI

The California Attorney General conducted an investigation into OpenAI's recapitalization plan and secured a memorandum of understanding ensuring charitable assets are used for their intended purpose, safety is prioritized, and OpenAI remains in California. The AG will not oppose the plan and will monitor ongoing adherence to these commitments.

Guidance

U.S. Department of Education

California Attorney General Rob Bonta led a coalition of 18 attorneys general in submitting a comment letter opposing the U.S. Department of Education's proposal to collect extensive student data on race, admissions, and financial aid. The coalition argues the data collection is burdensome, unlikely to yield quality data, and may be misused to target lawful diversity, equity, and inclusion efforts.

Student Data
Enforcement Action

City of El Cajon and El Cajon Police Department

California Attorney General Rob Bonta filed a lawsuit against the City of El Cajon for unlawfully sharing Automated License Plate Reader (ALPR) data with over 100 out-of-state law enforcement agencies, violating state law that restricts such data to California public agencies. The AG is seeking a court order to halt the sharing and compel compliance with state privacy protections.

Unauthorized Data SharingSurveillance Pricing
Settlement

Healthline Media LLC

California Attorney General Rob Bonta announced a $1.55 million settlement with Healthline Media LLC for CCPA violations. Healthline failed to honor opt-out requests, shared consumer data including health-related article titles with third parties, and used deceptive privacy practices. The settlement includes injunctive relief and a compliance program.

Opt-Out FailureUnauthorized Data SharingHealth Data

$1.6M

Settlement

Tilting Point Media LLC

Tilting Point Media LLC illegally collected and shared children's personal data in its mobile app game 'SpongeBob: Krusty Cook-Off' without parental consent, violating COPPA and CCPA. The settlement imposes a $500,000 civil penalty and injunctive terms to ensure compliance with children's data privacy laws.

Children's DataConsent FailureUnauthorized Data Sharing

$500K

Settlement

Blackbaud

Blackbaud, a software company, suffered a data breach in 2020 due to inadequate security measures and made misleading statements about the breach and its security practices. California Attorney General Rob Bonta secured a $6.75 million settlement requiring Blackbaud to pay penalties and implement enhanced data security and breach notification protocols.

Data BreachSecurity FailureBreach Notification Delay

$6.8M

Settlement

DoorDash

DoorDash sold California consumers' personal information to a marketing cooperative without providing required notice or an opt-out option, violating the CCPA and CalOPPA. The settlement requires DoorDash to pay a $375,000 civil penalty and comply with injunctive terms, including reviewing vendor contracts and providing annual reports to the Attorney General. This enforcement action clarifies that participation in marketing cooperatives constitutes a sale under the CCPA.

Opt-Out FailureNotice Failure

$375K

Settlement

Google

California Attorney General Rob Bonta announced a $93 million settlement with Google for deceiving users about location tracking. Google continued to collect location data even after users opted out, violating California consumer protection laws. The settlement includes injunctive terms to enhance transparency and user controls over location settings.

Opt-Out FailureNotice FailureGeolocation Data

$93.0M

Settlement

Kaiser Foundation Health Plan, Inc. and Kaiser Foundation Hospitals

California Attorney General Rob Bonta announced a $49 million settlement with Kaiser for illegally disposing of hazardous waste, medical waste, and protected patient information at facilities statewide. The settlement resolves allegations of violations under health privacy and environmental laws, requiring Kaiser to pay penalties, implement compliance measures, and undergo independent audits.

Health Data

$49.0M

Settlement

Sephora, Inc.

California Attorney General Rob Bonta announced a settlement with Sephora, Inc. for $1.2 million over violations of the California Consumer Privacy Act. Sephora failed to disclose that it sold consumer personal information and did not process opt-out requests via Global Privacy Control. The settlement requires Sephora to pay penalties and implement compliance measures including policy changes and reporting.

Opt-Out FailureNotice Failure

$1.2M

Settlement

Anthem, Inc.

Anthem, Inc. settled with California for $8.69 million over a 2014 data breach that exposed personal information of 78 million consumers, including 13.5 million Californians. The breach resulted from security deficiencies, and the settlement includes injunctive relief to improve information security practices. This action was part of a parallel multistate settlement.

Data BreachSecurity FailureHealth Data

$8.7M

Settlement

Glow, Inc.

California Attorney General settled with Glow, Inc. for $250,000 due to privacy and security failures in its fertility app that risked exposing users' sensitive health information. The settlement requires Glow to implement privacy and security measures, obtain affirmative consent for data sharing, and consider unique impacts on women.

Health DataSecurity FailureConsent Failure

$250K

Settlement

Equifax

California Attorney General led a multistate settlement with Equifax for a 2017 data breach that exposed personal information of 147 million consumers due to security failures and delayed disclosure. Equifax must pay $175 million in state penalties, $425 million for consumer restitution, and implement data security enhancements including a comprehensive Information Security Program and credit monitoring for up to ten years.

Data BreachSecurity FailureBreach Notification Delay

$175.0M

Settlement

Premera Blue Cross

Premera Blue Cross suffered a data breach in 2014 that exposed personal and medical information of 10.5 million consumers. As part of a multistate settlement, Premera agreed to pay $10 million in civil penalties and implement security improvements and a compliance program. California will receive over $1 million from the settlement.

Data BreachHealth DataSecurity Failure

$10.0M

Settlement

Aetna Inc.

Aetna Inc. settled with the California Attorney General for $935,000 over allegations that it revealed the HIV status of 1,991 Californians through a mailing error where medication information was visible through envelope windows. The settlement requires Aetna to implement improved mailing procedures and conduct annual privacy assessments. This action enforces health privacy laws and protects sensitive medical information.

Health Data

$935K

Settlement

Uber Technologies, Inc.

Uber Technologies, Inc. settled for $148 million over a 2016 data breach that exposed 57 million users' personal information. The company was accused of covering up the breach by paying hackers and failing to notify authorities or affected drivers as required by law. The settlement includes a large penalty and mandates robust data security practices, privacy-by-design integration, and regular reporting to prevent future incidents.

Data BreachNotice FailureSecurity Failure

$148.0M

Settlement

Cottage Health System

Cottage Health System experienced two data breaches exposing medical information of over 50,000 patients due to inadequate security measures. The settlement requires a $2 million penalty and upgrades to security practices, including designating a Chief Privacy Officer.

Health DataSecurity Failure

$2.0M

Settlement

Lenovo

Lenovo preinstalled 'Visual Discovery' software on its computers that intercepted browsing data and broke encrypted connections without user consent, compromising security and privacy. The multi-state settlement imposes a $3.5 million penalty and requires Lenovo to implement disclosure, consent, opt-out, and security compliance measures.

Notice FailureConsent FailureOpt-Out Failure

$3.5M

Settlement

Target

Target settled a multi-state enforcement action for a 2013 data breach that exposed payment card information of over 40 million customers due to inadequate security. The $18.5 million settlement requires Target to implement advanced security measures, and California receives over $1.4 million.

Data BreachSecurity Failure

$18.5M

Settlement

Wells Fargo Bank

Wells Fargo Bank recorded consumer phone calls without providing timely notice as required by California law, violating privacy statutes. The settlement imposes a $7.616 million civil penalty, requires compliance with disclosure standards, and mandates an internal compliance program to protect consumer privacy.

Notice Failure

$7.6M

Settlement

Houzz Inc.

The California Attorney General settled with Houzz Inc. for secretly recording incoming and outgoing telephone calls from March to September 2013 without notifying or obtaining consent from all parties, violating state wiretapping and eavesdropping laws. The settlement requires Houzz to pay $175,000, appoint a Chief Privacy Officer, conduct a privacy risk assessment, secure and destroy the recordings, and implement compliance measures.

Notice FailureConsent Failure

$175K

Settlement

Comcast

Comcast disclosed personal information of approximately 75,000 customers who had paid for unlisted VOIP phone service. The settlement includes a $25 million penalty and $8 million in restitution, along with a permanent injunction requiring improved privacy practices and customer disclosures.

Unauthorized Data Sharing

$25.0M

Settlement

Aaron's, Inc.

The California Attorney General reached a $28.4 million settlement with Aaron's, Inc. for installing spyware on rented computers without customer consent and for violating the Karnette Rental-Purchase Act. The spyware, called 'Detective Mode', allowed remote monitoring of keystrokes, screenshots, location, and webcam activation. Aaron's must refund $25 million to approximately 100,000 customers and pay $3.4 million in penalties, and is prohibited from using spyware.

Consent FailureGeolocation Data

$3.4M

Enforcement Action

Kaiser Foundation Health Plan, Inc.

The California Attorney General filed a complaint against Kaiser Foundation Health Plan, Inc. for improperly disposing of patient medical records containing protected health information. The records, including diagnoses and lab results, were found discarded at a recycling facility, violating patient privacy. The action alleges breaches of the California Confidentiality of Medical Information Act.

Health DataSecurity Failure
Enforcement Action

Citibank, N.A.

In 2013, the California Attorney General filed a complaint against Citibank, N.A. alleging that the bank failed to implement adequate security measures and did not properly notify customers about a data breach exposing personal and financial information. The complaint asserts violations of California's data breach notification law.

Security FailureBreach Notification Delay
Settlement

Blue Cross of California

Anthem Blue Cross printed Social Security numbers on mailed letters, exposing the personal information of over 33,000 Medicare subscribers. The settlement requires the company to improve data security measures, provide employee training, and pay $150,000. This action aims to prevent future privacy violations.

Data Breach

$150K