Penalty Amount
$1,250,000
Consumers Affected
180,000
New Jersey, as part of a multistate coalition, settled with Carnival Cruise Line over a 2019 data breach that compromised personal information of approximately 180,000 employees and customers nationwide. The breach resulted from deficiencies in Carnival's data security program and delayed breach notification. Carnival will pay $1.25 million and implement enhanced email security and breach response measures.
Carnival must implement and maintain a breach response and notification plan, provide email security training with phishing exercises, enforce strong password policies, maintain enhanced network monitoring tools, and undergo an independent information security assessment.
In-house legal teams should review customer agreements, employee agreements, and vendor contracts for clauses related to data security, breach notification, and incident response. Specifically, examine data security obligations, breach notification timelines and methods, email security provisions, and regulatory reporting requirements. Changes may be needed to enhance email security controls, ensure prompt breach notification to consumers and regulators, and implement regular security audits to align with settlement mandates.
Entity
Carnival Cruise Line
Also known as: Carnival
Industry
OtherOfficial Press Release
https://www.njoag.gov/acting-ag-platkin-announces-settlement-with-carnival-cruise-line-over-2019-data-breach-that-compromised-personal-information-from-its-employees-and-customers/
2022 0622 Carnival Corporation AVC
https://www.nj.gov/oag/newsreleases22/2022-0622-Carnival-Corporation AVC.pdf
New Jersey Attorney General Enforcement Page
https://www.njoag.gov/about/divisions-and-offices/division-of-consumer-affairs/
"Carnival Cruise Line"
"total of $1.25 million"
"data breach"
"deficiencies in Carnival’s data security program contributed to the breach"
"Carnival did not provide adequate notice of the breach"
"health information"
$1.3M
Connecticut, co-leading a multistate investigation, secured a $1.25 million settlement with Carnival Cruise Line over a 2019 data breach affecting approximately 180,000 individuals nationwide. The breach exposed sensitive data including passport numbers, driver's licenses, payment card information, and health data, with a 10-month delay in notification. Carnival agreed to implement enhanced email security measures, a breach response plan, and an independent security assessment.
$650K
The New Jersey Attorney General and Division of Consumer Affairs announced that Match Group, Inc. will pay $650,000 and change its business practices to settle allegations that it misrepresented or failed to disclose its criminal background screening policies and practices to New Jersey users, violating the New Jersey Consumer Fraud Act and the Internet Dating Safety Act. Under a Consent Order, Match must accurately represent its screening policies, notify existing New Jersey members of updated disclosures within 150 days, and post clear and conspicuous disclosures and safety notifications about the limitations of criminal background screenings.
On August 31, 2026, New Jersey Attorney General Jennifer Davenport and the Division of Consumer Affairs joined the FTC and a bipartisan coalition of 21 other states in suing Amazon, alleging that for over seven years the company secretly rigged its advertising auctions—converting advertised 'second price' auctions into first-price auctions with hidden 'soft reserve price' surcharges—overcharging more than 500,000 small- and medium-sized businesses and extracting tens of billions of dollars. The complaint alleges Amazon actively concealed the surcharges, gave false and misleading answers to advertisers who asked directly about the auction format, and applied inflated upcharges on high-volume shopping days like Prime Day and Black Friday. The lawsuit was just filed; no penalties or remedies have been imposed yet.
A bipartisan coalition of state attorneys general led by New Jersey, California, Colorado, and Kentucky is taking Meta Platforms, Inc. to trial, alleging that Meta designed addictive features on Instagram and Facebook that harm minors' mental health, illegally collected data from children under 13 without the required protections under COPPA, and misled users about platform safety. Opening arguments begin August 18, 2026, in the U.S. District Court for the Northern District of California. No monetary penalty or final remedy has yet been imposed.
A coalition of 21 state attorneys general and Pennsylvania filed lawsuits against the Trump Administration, DOT, FMCSA, DHS, and AAMVA to prevent the unlawful demand for a database containing personal information of 17 million commercial driver's license holders. The lawsuits allege violations of federal privacy laws and the Administrative Procedure Act, and seek an emergency order to block the data transfer.
Attorney General Jennifer Davenport joined a coalition of 17 attorneys general in sending comment letters to the Office of the Comptroller of the Currency and the Federal Reserve Board, urging them to deny OppFi's application to acquire BNC National Bank and obtain a national bank charter. The coalition argues that the charter would allow OppFi to circumvent state usury laws and offer high-cost loans with APRs up to 200%, harming consumers.