Court Rules

Privacy Enforcement Tracker

1,506 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,506

Total Actions

16

Jurisdictions

$26.6B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
MNEnforcement Action

X.AI

The Minnesota court denied X.AI's request for a temporary restraining order that would have halted enforcement of Minnesota's first-in-the-nation AI nudification ban (HF 1606). The law bans technology that generates fake nude images of real people, and Attorney General Ellison argued that X.AI's delay in filing the motion showed no immediate harm. The court agreed, allowing the law to take effect as planned.

LowAI/Automated DecisionsConsent FailureChildren's Data
VASettlementMultistate

23andMe, Inc.

Virginia Attorney General Jay Jones joined a coalition of 42 state attorneys general in a multistate settlement with 23andMe over a 2023 data breach that exposed the genetic data of approximately 6.9 million customers. The settlement requires 23andMe to pay $18 million to the states and $46.75 million to affected consumers, resolving allegations of inadequate security practices and delayed breach notification.

CriticalData BreachSecurity FailureHealth Data

$18.0M

VASettlementMultistate

23andMe

Attorney General Jay Jones joined 42 attorneys general in a multistate settlement with 23andMe's bankruptcy trustee over a 2023 data breach that compromised genetic data of nearly 7 million customers. The settlement includes $150 million in allowed claims, with immediate recovery of $18 million from bankruptcy funds, of which Virginia receives $662,649. The settlement also requires enhanced data security measures and consumer protections for the new entity, 23andMe Research Institute.

MediumData BreachSecurity FailureHealth Data

$663K

TXSettlementMultistate

23andMe

Texas Attorney General Ken Paxton secured a $150 million multistate settlement against 23andMe following a 2023 data breach that exposed genetic and personal data of 6.9 million consumers. The settlement resolves bankruptcy claims and requires enhanced data security, risk assessments, and an independent advisory board, with immediate recovery of $18 million from bankruptcy funds.

CriticalData BreachSecurity FailureBreach Notification Delay

$150.0M

TXInvestigation

LinkedIn Corporation

Texas Attorney General Ken Paxton opened an investigation into LinkedIn Corporation over allegations that the company advertised and profited from fake or misleading job opportunities ("ghost jobs") on its platform. The investigation focuses on whether LinkedIn misled consumers who paid for Premium subscriptions by failing to disclose that a significant percentage of job postings may be inactive or not genuine hiring opportunities.

LowNotice FailureConsent Failure
NYSettlementMultistate

23andMe

New York Attorney General Letitia James and a bipartisan coalition of 42 other attorneys general secured an $18 million settlement from genetic testing company 23andMe for failing to protect customers' private genetic data. The October 2023 data breach exposed sensitive genetic information of 6.9 million consumers, including 305,245 in New York, with some data published for sale on the dark web. The settlement includes monetary penalties and new data protection requirements for the company and its successor, 23andMe Research Institute.

CriticalData BreachSecurity FailureBreach Notification Delay

$18.0M

CTSettlementMultistate

23andMe

Attorney General William Tong led a coalition of 42 attorneys general in a settlement with the bankruptcy trustee for 23andMe, resolving allegations from a 2023 data breach that compromised the genetic data of 6.9 million customers. The settlement includes $150 million in allowed claims, with $18 million paid from bankruptcy funds, and requires enhanced data security measures for the new entity holding the data.

HighData BreachSecurity FailureHealth Data

$18.0M

ORSettlementMultistate

23andMe

A coalition of 42 state attorneys general settled bankruptcy claims against 23andMe following a 2023 data breach that compromised genetic data of 6.9 million customers. The settlement includes $150 million in allowed claims, with $18 million paid from bankruptcy funds, and requires enhanced data security measures for the successor entity, 23andMe Research Institute.

HighData BreachSecurity FailureHealth Data

$18.0M

NJSettlementMultistate

23andMe, Inc.

Attorney General Jennifer Davenport joined a bipartisan coalition of 42 attorneys general in announcing a settlement with the bankruptcy trustee for 23andMe, resolving allegations from a 2023 data breach that compromised genetic data of 6.9 million people worldwide, including nearly 150,000 in New Jersey. The settlement provides $18 million to states from available bankruptcy funds, plus enhanced data security and consumer deletion rights for the successor entity, 23andMe Research Institute.

CriticalData BreachSecurity FailureBreach Notification Delay

$18.0M

COSettlementMultistate

23andMe, Inc.

A coalition of 42 state attorneys general settled with the bankruptcy trustee for 23andMe over a 2023 data breach that exposed genetic data of 6.9 million customers. The states will receive $18 million from bankruptcy funds, and 23andMe agreed to enhanced data security requirements and consumer deletion rights as part of the asset sale to TTAM Research Institute.

HighData BreachSecurity FailureBiometric Data

$18.0M

MNSettlementMultistate

23andMe, Inc.

A coalition of 42 state attorneys general reached a settlement with the bankruptcy trustee for 23andMe over a 2023 data breach that compromised the genetic data of 6.9 million customers. The settlement provides $18 million from bankruptcy funds, with Minnesota receiving $514,871, and imposes data security requirements on the successor entity, 23andMe Research Institute.

HighData BreachSecurity FailureBreach Notification Delay

$18.0M

TXSettlementMultistate

Block, Inc.

Attorney General Ken Paxton secured a $45 million multistate settlement with Block, Inc. (Cash App) for misleading consumers about the safety of its platform and failing to protect users from fraud. The settlement requires Cash App to maintain 24-hour customer support, cease deceptive safety claims, and fulfill its legal duty to investigate and reimburse unauthorized transactions.

CriticalSecurity FailureNotice Failure

$45.0M

NYSettlementMultistate

Block, Inc.

New York Attorney General Letitia James and a bipartisan coalition of 45 other attorneys general secured $45 million from Block, Inc., the company behind Cash App, for misleading users about the platform's security and failing to protect them from fraud. The settlement requires Block to implement changes including maintaining live customer support, stopping misleading marketing, and fulfilling legal obligations to investigate fraud claims and reimburse users for unauthorized transactions.

CriticalSecurity FailureNotice FailureConsent Failure

$45.0M

CTSettlementMultistate

Block, Inc.

Attorney General Tong announced a $45 million multistate settlement with Block, Inc., the company behind Cash App, for misleading consumers about the safety of the platform, failing to protect users from fraud, and not providing promised fraud protection and resolution services. The settlement requires Block to implement major reforms including real customer support, transparent communications, and security commitments, and reaffirms Block's commitment to distribute between $75 million and $120 million to compensate consumers as part of a separate CFPB settlement.

HighSecurity FailureNotice FailureConsent Failure

$45.0M

NJSettlementMultistate

Block, Inc.

Block, Inc. agreed to a $45 million multistate settlement with 46 states for allegedly misleading consumers about the safety of Cash App, failing to protect users from fraud, and not providing promised fraud protection. The settlement requires Block to improve customer support, stop misleading claims, and educate consumers about fraud.

CriticalSecurity FailureNotice Failure

$45.0M

VASettlementMultistate

Block, Inc.

Block, Inc., the parent company of Cash App, agreed to a $45 million multistate settlement with 46 states for misleading consumers about the safety of Cash App and failing to protect users from fraud. The settlement requires Block to improve customer support, stop deceptive marketing, and fulfill legal obligations to investigate fraud and reimburse unauthorized transactions.

CriticalNotice FailureSecurity Failure

$45.0M

FTCSettlementMultistate

Handy Technologies

The FTC and New York Attorney General took action against Handy Technologies for deceptive earnings claims and failure to disclose fees and fines that led to millions of dollars being withheld from workers' wages. The FTC is sending over $2.7 million in refunds to 62,893 affected consumers.

LowNotice FailureConsent Failure
TXInvestigation

StubHub

Texas Attorney General Ken Paxton announced an investigation into StubHub for failing to deliver FIFA World Cup tickets that fans purchased. The investigation focuses on reports of 'ghost ticketing,' where sellers list tickets they do not possess, collect payment, and cancel when unable to deliver.

LowNotice FailureConsent Failure
FTCSettlement

Hopper Inc.

The FTC alleged that Hopper, a travel booking app, charged consumers hidden and pre-selected fees (Tip and VIP Support) without their consent, and misrepresented the benefits of its VIP Support and Price Freeze services. Hopper agreed to pay $35 million for consumer redress and is prohibited from misrepresenting fees, with requirements to clearly disclose fees and total prices.

CriticalConsent FailureNotice FailureDark Patterns

$35.0M

FTCEnforcement Action

Genesis Tech enterprise

The FTC sued the Genesis Tech enterprise and its owners for operating deceptive internet-based subscription schemes. The defendants allegedly misled consumers about subscription terms, billed without authorization, and made cancellation difficult. The court granted a temporary halt to the operations pending trial.

LowConsent FailureNotice FailureDark Patterns
NJEnforcement Action

Xiao Hu

The New Jersey Bureau of Securities filed a lawsuit against Xiao Hu (aka Mark Hu) and his companies Skyline Technology USA LLC and Thunderbirds.ME, Inc. for allegedly defrauding at least 15 investors out of $2.5 million through unregistered securities offerings. Hu allegedly misappropriated at least $280,000 for personal expenses including a home purchase and vacation, and falsely claimed to have a Ph.D. from Columbia University.

LowConsent FailureNotice Failure
FTCEnforcement Action

X Corp.

The Federal Trade Commission is seeking public comment on a petition from X Corp., formerly known as Twitter, to set aside or modify its 2022 settlement order with the agency. The petition argues that the order no longer serves a valid regulatory purpose and that X Corp. has built a world-class privacy program. The Commission will vote after the comment period closes.

LowConsent FailureNotice Failure
COEnforcement Action

Xinbi Co., Ltd.

The Colorado Attorney General announced a major enforcement sweep targeting thousands of fraudulently filed businesses that used false information in Colorado registrations to facilitate scams including cryptocurrency fraud, investment fraud, and romance scams. The lawsuits seek court orders to dissolve these entities and the AG's office worked to take down associated websites.

LowNotice FailureConsent Failure
FTCWarning Letter

12 Unnamed Nudify Tool Providers

The FTC sent warning letters to 12 companies offering 'nudify' tools that generate nonconsensual intimate images, for failing to comply with the TAKE IT DOWN Act (TIDA) by not providing a mechanism for victims to request removal of such content. The letters urge immediate compliance with TIDA, which requires platforms to remove nonconsensual intimate images within 48 hours of a valid request. Noncompliant companies may face future legal action and civil penalties of up to $53,088 per violation.

LowConsent Failure
TXInvestigation

Meta (formerly known as Facebook)

Texas Attorney General Ken Paxton launched an investigation into Meta's Meta AI Glasses over allegations of unlawful facial biometric data collection, deceptive privacy practices, and unauthorized sharing of user data with subcontractors. The investigation follows concerns that the glasses' always-on recording mode lacks proper user notice, planned facial recognition features would collect data without consent, and private user videos are accessed by third-party annotators in Kenya. The AG issued a Civil Investigative Demand to Meta to determine violations of Texas privacy laws.

LowBiometric DataConsent FailureUnauthorized Data Sharing
TXInvestigation

Meta

Texas Attorney General Ken Paxton launched an investigation into Meta regarding its Meta AI Glasses, alleging unlawful collection of facial biometric data, deceptive privacy representations, and unauthorized sharing of user data with subcontractors. The investigation follows concerns that the glasses’ always-on recording mode lacks proper notice, subcontractors access private user content including intimate moments, and Meta plans to deploy facial recognition technology to collect unsuspecting individuals’ facial geometry. The AG issued a Civil Investigative Demand to determine if Meta violated Texas law by deceptively misrepresenting its data use practices.

LowBiometric DataNotice FailureConsent Failure
FTCSettlement

Shutterstock Inc.

Shutterstock Inc. agreed to pay $35 million to settle FTC allegations that it charged consumers without their informed consent, failed to disclose auto-renewal and cancellation terms, and made cancellation difficult. The FTC alleged Shutterstock's subscription and on-demand pack offerings violated consumer protection laws through hidden fees and complicated cancellation processes.

CriticalConsent FailureNotice FailureDark Patterns

$35.0M

FTCWarning Letter

Amazon, Alphabet, Apple, Automattic, Bumble, Discord, Match Group, Meta, Microsoft, Pinterest, Reddit, SmugMug, Snapchat, TikTok, X

Federal Trade Commission Chairman Andrew N. Ferguson sent letters to over a dozen major technology companies reminding them of their obligation to comply with the Take It Down Act (TIDA) by May 19, 2026. TIDA requires covered platforms to establish a process for victims, including children, to request removal of nonconsensual intimate images, with takedown of content and all identical copies required within 48 hours of a valid request. The FTC also issued supplemental guidance to help companies prepare for compliance and warned that it will monitor and enforce violations of the law.

Low
TXInvestigation

Drone Nerds, LLC

Texas Attorney General Ken Paxton initiated an investigation into Drone Nerds, LLC over its partnership with CCP-affiliated Anzu Robotics, which markets drones with concealed surveillance capabilities and unauthorized data collection risks. Drone Nerds is accused of deceiving Texas consumers by misrepresenting Anzu’s ties to China and falsely claiming the drones are U.S.-based with secure privacy practices. The investigation is being conducted under the Texas Deceptive Trade Practices Act, with a Civil Investigative Demand issued to gather evidence of consumer deception and privacy violations.

LowSecurity FailureUnauthorized Data Sharing
FTCConsent Decree

Air AI

Consumer fraud enforcement action where the FTC settled with Air AI for misleading entrepreneurs with false earnings and refund guarantees. The company will be banned from marketing business opportunities and pay a suspended $18 million judgment with $50,000 for consumer relief. Violations included failure to provide required disclosures and false claims under the Telemarketing Sales Rule and Business Opportunity Rule.

CriticalNotice Failure

$18.0M

Explore Enforcement Data