Court Rules

Privacy Enforcement Tracker

1,506 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,506

Total Actions

16

Jurisdictions

$26.6B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
NJSettlementMultistate

23andMe, Inc.

Attorney General Jennifer Davenport joined a bipartisan coalition of 42 attorneys general in announcing a settlement with the bankruptcy trustee for 23andMe, resolving allegations from a 2023 data breach that compromised genetic data of 6.9 million people worldwide, including nearly 150,000 in New Jersey. The settlement provides $18 million to states from available bankruptcy funds, plus enhanced data security and consumer deletion rights for the successor entity, 23andMe Research Institute.

CriticalData BreachSecurity FailureBreach Notification Delay

$18.0M

NJSettlementMultistate

Blackbaud

Blackbaud, a software company, experienced a ransomware attack in 2020 that exposed sensitive personal information, including protected health data, due to inadequate security practices and delayed breach notification. A multistate investigation resulted in a $49.5 million settlement, requiring Blackbaud to enhance data security, implement breach response plans, and undergo third-party assessments.

CriticalData BreachSecurity FailureBreach Notification Delay

$49.5M

NJSettlementMultistate

Sabre Corp.(Sabre)

New Jersey participated in a multi-state settlement resolving an investigation into a 2017 data breach at Sabre Hospitality Solutions. Intruders accessed the company's hotel booking system from August 2016 to March 2017, compromising data from over 1.3 million consumer credit cards, including CVV numbers and expiration dates. Sabre failed to promptly notify affected consumers. The $2.4 million settlement requires Sabre to implement enhanced data security measures, develop a breach notification plan, clarify contractual responsibilities with client hotels, and undergo third-party security assessments.

HighData BreachBreach Notification Delay

$2.4M

NJSettlementMultistate

Uber Technologies, Inc.(Uber)

Uber Technologies, Inc. agreed to pay $148 million to settle a multi-state investigation into a data breach that compromised personal information of riders and drivers. The breach occurred in November 2016 but was not disclosed until November 2017. Uber must adopt new policies to safeguard consumer data.

CriticalData BreachSecurity FailureBreach Notification Delay

$148.0M

NJConsent Decree

Lightyear Dealer Technologies(DealerBuilt)

Lightyear Dealer Technologies (DealerBuilt) settled an investigation into a 2016 data breach where a misconfigured file system exposed personal data, including social security numbers and bank information, of thousands of auto dealership customers nationwide. The settlement includes an $80,784 payment (with $20,000 suspended) and mandatory cybersecurity reforms.

LowData BreachSecurity Failure

$49K

NJInvestigation

Facebook(Meta)

The New Jersey Attorney General announced an investigation into how the personal information of millions of Facebook users was harvested and obtained by Cambridge Analytica, a UK-based data analytics company. The AG expressed concern that Facebook may have allowed the harvesting and monetization of user data despite promises to keep it secure.

HighData BreachUnauthorized Data Sharing

Explore Enforcement Data