Court Rules
All enforcement actions
SettlementHigh RiskMultistate

NJ AG Settles with Carnival for $1.25M Over Data Breach

Carnival Cruise LineJune 22, 2022New Jersey Attorney General

Penalty Amount

$1,250,000

Consumers Affected

180,000

Summary

New Jersey, as part of a multistate coalition, settled with Carnival Cruise Line over a 2019 data breach that compromised personal information of approximately 180,000 employees and customers nationwide. The breach resulted from deficiencies in Carnival's data security program and delayed breach notification. Carnival will pay $1.25 million and implement enhanced email security and breach response measures.

Remedy

Carnival must implement and maintain a breach response and notification plan, provide email security training with phishing exercises, enforce strong password policies, maintain enhanced network monitoring tools, and undergo an independent information security assessment.

Compliance ProgramAudit Requirement

Contract Impact

In-house legal teams should review customer agreements, employee agreements, and vendor contracts for clauses related to data security, breach notification, and incident response. Specifically, examine data security obligations, breach notification timelines and methods, email security provisions, and regulatory reporting requirements. Changes may be needed to enhance email security controls, ensure prompt breach notification to consumers and regulators, and implement regular security audits to align with settlement mandates.

Contract Search Terms

data security programbreach notification clauseemail security measuresincident response planpersonal information protectionsecurity audit requirementsnotification timelinesconsumer notificationdata processing standards

Violation Types

Entity Details

Entity

Carnival Cruise Line

Also known as: Carnival

Industry

Other

Multistate Coalition

Official Sources

Source Evidence

Entity Name
"Carnival Cruise Line"
Fine Amount
"total of $1.25 million"
Violation Types
"data breach"
Violation Types
"deficiencies in Carnival’s data security program contributed to the breach"
Violation Types
"Carnival did not provide adequate notice of the breach"
Violation Types
"health information"

Related Enforcement Actions

CT

Carnival Cruise Line

$1.3M

Connecticut, co-leading a multistate investigation, secured a $1.25 million settlement with Carnival Cruise Line over a 2019 data breach affecting approximately 180,000 individuals nationwide. The breach exposed sensitive data including passport numbers, driver's licenses, payment card information, and health data, with a 10-month delay in notification. Carnival agreed to implement enhanced email security measures, a breach response plan, and an independent security assessment.

NJ

Match Group, Inc.

$650K

The New Jersey Attorney General and Division of Consumer Affairs announced that Match Group, Inc. will pay $650,000 and change its business practices to settle allegations that it misrepresented or failed to disclose its criminal background screening policies and practices to New Jersey users, violating the New Jersey Consumer Fraud Act and the Internet Dating Safety Act. Under a Consent Order, Match must accurately represent its screening policies, notify existing New Jersey members of updated disclosures within 150 days, and post clear and conspicuous disclosures and safety notifications about the limitations of criminal background screenings.

NJ

Amazon

On August 31, 2026, New Jersey Attorney General Jennifer Davenport and the Division of Consumer Affairs joined the FTC and a bipartisan coalition of 21 other states in suing Amazon, alleging that for over seven years the company secretly rigged its advertising auctions—converting advertised 'second price' auctions into first-price auctions with hidden 'soft reserve price' surcharges—overcharging more than 500,000 small- and medium-sized businesses and extracting tens of billions of dollars. The complaint alleges Amazon actively concealed the surcharges, gave false and misleading answers to advertisers who asked directly about the auction format, and applied inflated upcharges on high-volume shopping days like Prime Day and Black Friday. The lawsuit was just filed; no penalties or remedies have been imposed yet.

NJ

Meta Platforms, Inc.

A bipartisan coalition of state attorneys general led by New Jersey, California, Colorado, and Kentucky is taking Meta Platforms, Inc. to trial, alleging that Meta designed addictive features on Instagram and Facebook that harm minors' mental health, illegally collected data from children under 13 without the required protections under COPPA, and misled users about platform safety. Opening arguments begin August 18, 2026, in the U.S. District Court for the Northern District of California. No monetary penalty or final remedy has yet been imposed.

NJ

U.S. Department of Transportation

A coalition of 21 state attorneys general and Pennsylvania filed lawsuits against the Trump Administration, DOT, FMCSA, DHS, and AAMVA to prevent the unlawful demand for a database containing personal information of 17 million commercial driver's license holders. The lawsuits allege violations of federal privacy laws and the Administrative Procedure Act, and seek an emergency order to block the data transfer.

NJ

Opportunity Financials, LLC

Attorney General Jennifer Davenport joined a coalition of 17 attorneys general in sending comment letters to the Office of the Comptroller of the Currency and the Federal Reserve Board, urging them to deny OppFi's application to acquire BNC National Bank and obtain a national bank charter. The coalition argues that the charter would allow OppFi to circumvent state usury laws and offer high-cost loans with APRs up to 200%, harming consumers.