Court Rules

Privacy Enforcement Tracker

1,506 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,506

Total Actions

16

Jurisdictions

$26.6B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
VASettlementMultistate

23andMe, Inc.

Virginia Attorney General Jay Jones joined a coalition of 42 state attorneys general in a multistate settlement with 23andMe over a 2023 data breach that exposed the genetic data of approximately 6.9 million customers. The settlement requires 23andMe to pay $18 million to the states and $46.75 million to affected consumers, resolving allegations of inadequate security practices and delayed breach notification.

CriticalData BreachSecurity FailureHealth Data

$18.0M

VASettlementMultistate

23andMe

Attorney General Jay Jones joined 42 attorneys general in a multistate settlement with 23andMe's bankruptcy trustee over a 2023 data breach that compromised genetic data of nearly 7 million customers. The settlement includes $150 million in allowed claims, with immediate recovery of $18 million from bankruptcy funds, of which Virginia receives $662,649. The settlement also requires enhanced data security measures and consumer protections for the new entity, 23andMe Research Institute.

MediumData BreachSecurity FailureHealth Data

$663K

TXSettlementMultistate

23andMe

Texas Attorney General Ken Paxton secured a $150 million multistate settlement against 23andMe following a 2023 data breach that exposed genetic and personal data of 6.9 million consumers. The settlement resolves bankruptcy claims and requires enhanced data security, risk assessments, and an independent advisory board, with immediate recovery of $18 million from bankruptcy funds.

CriticalData BreachSecurity FailureBreach Notification Delay

$150.0M

CTSettlementMultistate

23andMe

Attorney General William Tong led a coalition of 42 attorneys general in a settlement with the bankruptcy trustee for 23andMe, resolving allegations from a 2023 data breach that compromised the genetic data of 6.9 million customers. The settlement includes $150 million in allowed claims, with $18 million paid from bankruptcy funds, and requires enhanced data security measures for the new entity holding the data.

HighData BreachSecurity FailureHealth Data

$18.0M

ORSettlementMultistate

23andMe

A coalition of 42 state attorneys general settled bankruptcy claims against 23andMe following a 2023 data breach that compromised genetic data of 6.9 million customers. The settlement includes $150 million in allowed claims, with $18 million paid from bankruptcy funds, and requires enhanced data security measures for the successor entity, 23andMe Research Institute.

HighData BreachSecurity FailureHealth Data

$18.0M

MNSettlementMultistate

23andMe, Inc.

A coalition of 42 state attorneys general reached a settlement with the bankruptcy trustee for 23andMe over a 2023 data breach that compromised the genetic data of 6.9 million customers. The settlement provides $18 million from bankruptcy funds, with Minnesota receiving $514,871, and imposes data security requirements on the successor entity, 23andMe Research Institute.

HighData BreachSecurity FailureBreach Notification Delay

$18.0M

TXInvestigation

Conduent Business Services LLC(Conduent)

Texas Attorney General Ken Paxton issued Civil Investigative Demands to Blue Cross Blue Shield of Texas and Conduent Business Services LLC as part of an investigation into a data breach that exposed the protected health information of approximately four million Texans. The breach, which occurred between October 21, 2024 and January 13, 2025, is believed to be the largest in U.S. history. The investigation focuses on Conduent's security measures and BCBS's compliance with state data protection laws.

LowData BreachHealth DataSecurity Failure
TXEnforcement Action

Epic Systems Corporation(Epic Systems)

Texas Attorney General Ken Paxton filed a lawsuit against Epic Systems Corporation, a major electronic health records vendor, alleging unlawful monopolization of the EHR industry and deceptive practices that restrict parental access to minor children’s medical records. The privacy-related claim asserts Epic automatically hides children’s medication lists, treatment notes, and provider messages from parents when a child turns 12, violating Texas law guaranteeing parents unrestricted access to their children’s medical records. The action is part of broader efforts to ensure EHR vendors comply with Texas parental access requirements and promote market competition.

LowChildren's DataHealth Data
CASettlementMultistate

Illuminate Education, Inc.(Illuminate Education)

California Attorney General Rob Bonta, joined by Connecticut and New York Attorneys General, secured a $5.1 million multistate settlement with edtech company Illuminate Education, Inc. over a 2021 data breach that exposed sensitive personal and medical information of millions of students, including over 434,000 California students. The investigation found Illuminate failed to implement basic security measures, including failing to terminate former employee credentials, lacking suspicious activity monitoring, and unsecured backup databases, as well as making false statements in its privacy policy. Illuminate must pay $3.25 million to California, implement enhanced security practices, and notify the CA DOJ of future student data breaches.

HighData BreachStudent DataHealth Data

$5.1M

TXEnforcement Action

PowerSchool

Texas Attorney General Ken Paxton filed a lawsuit against PowerSchool, a provider of cloud-based services for K-12 schools, following a data breach that exposed the personal and health information of over 880,000 Texas school-aged children and teachers. The breach occurred in December 2024 when a hacker gained administrative access through a subcontractor's account and stole unencrypted data including Social Security numbers, medical details, and disability records. The lawsuit alleges PowerSchool violated Texas law by failing to implement basic security measures and by misleading customers about its security practices.

LowData BreachStudent DataChildren's Data
FTCConsent Decree

Verkada

Verkada, a security camera company, failed to secure customer data, leading to a hacker accessing over 150,000 cameras and sensitive health information. The company also violated the CAN-SPAM Act by sending spam emails without proper opt-out mechanisms. To settle, Verkada will pay $2.95 million and implement a comprehensive security program with audits.

HighSecurity FailureOpt-Out FailureNotice Failure

$3.0M

NJSettlementMultistate

Blackbaud

Blackbaud, a software company, experienced a ransomware attack in 2020 that exposed sensitive personal information, including protected health data, due to inadequate security practices and delayed breach notification. A multistate investigation resulted in a $49.5 million settlement, requiring Blackbaud to enhance data security, implement breach response plans, and undergo third-party assessments.

CriticalData BreachSecurity FailureBreach Notification Delay

$49.5M

CASettlement

Glow, Inc.(Glow)

California Attorney General Xavier Becerra announced a settlement with Glow, Inc., operator of a fertility-tracking mobile app, over privacy and security failures that risked exposing millions of users’ sensitive personal and medical information. The settlement includes a $250,000 civil penalty and injunctive terms requiring Glow to implement privacy and security design principles, obtain affirmative user consent for data sharing, and allow users to revoke consent. Glow was alleged to have failed to safeguard health information, allowed unauthorized access to user data, and maintained flawed password reset functions that could enable third-party access without consent.

MediumHealth DataSecurity FailureConsent Failure

$250K

Explore Enforcement Data