Court Rules

Privacy Enforcement Tracker

1,634 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,634

Total Actions

16

Jurisdictions

$49.9B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
CASettlement

Kaiser Foundation Health Plan, Inc. and Kaiser Foundation Hospitals (collectively Kaiser)

California Attorney General Rob Bonta, alongside six county district attorneys, announced a $49 million settlement with Kaiser Foundation Health Plan, Inc. and Kaiser Foundation Hospitals resolving allegations of unlawful disposal of hazardous waste, medical waste, and protected health information at Kaiser’s California facilities. Undercover inspections of 16 Kaiser facilities found hundreds of hazardous and medical waste items, plus over 10,000 paper records containing personal information of more than 7,700 patients in unsecured, publicly accessible dumpsters. The settlement requires Kaiser to pay $49 million total, implement enhanced compliance measures, and retain an independent auditor for five years to conduct regular waste and programmatic compliance audits.

CriticalHealth DataSecurity FailureData Breach

$49.0M

CASettlement

Sephora, Inc.(Sephora)

California Attorney General Rob Bonta announced a settlement with Sephora, Inc. resolving allegations that the company violated the California Consumer Privacy Act (CCPA) by failing to disclose it was selling consumers' personal information and failing to process opt-out requests via user-enabled Global Privacy Controls. Sephora agreed to pay $1.2 million in penalties and implement injunctive measures including updating privacy disclosures, enabling opt-out via GPC, conforming service provider agreements to CCPA, and reporting to the AG. The settlement is part of ongoing CCPA enforcement efforts, with the AG also issuing cure notices to other businesses failing to honor GPC opt-out signals.

HighOpt-Out FailureNotice Failure

$1.2M

CASettlementMultistate

Anthem, Inc.(Anthem)

California Attorney General Xavier Becerra announced an $8.69 million settlement with health insurer Anthem, Inc. resolving allegations that the company violated state and federal privacy laws by failing to protect patient personal data in a 2014 data breach. The breach, announced in 2015, exposed personal information of 78 million consumers nationwide, including 13.5 million Californians, due to Anthem’s inadequate information security practices. The settlement includes injunctive terms requiring Anthem to overhaul its information security program to address vulnerabilities that enabled the breach.

HighData BreachHealth DataSecurity Failure

$8.7M

CASettlement

Glow, Inc.(Glow)

California Attorney General Xavier Becerra announced a settlement with Glow, Inc., operator of a fertility-tracking mobile app, over privacy and security failures that risked exposing millions of users’ sensitive personal and medical information. The settlement includes a $250,000 civil penalty and injunctive terms requiring Glow to implement privacy and security design principles, obtain affirmative user consent for data sharing, and allow users to revoke consent. Glow was alleged to have failed to safeguard health information, allowed unauthorized access to user data, and maintained flawed password reset functions that could enable third-party access without consent.

MediumHealth DataSecurity FailureConsent Failure

$250K

CASettlementMultistate

Equifax

California Attorney General Xavier Becerra, leading a multistate coalition of all 50 states, the District of Columbia, and Puerto Rico, announced a settlement with Equifax over a 2017 data breach that exposed personal information of 147 million consumers, including 15 million Californians. The breach resulted from Equifax’s failure to apply a critical software patch and implement adequate security measures, with disclosure delayed for months after discovery. Equifax will pay $175 million in state penalties, up to $425 million in consumer restitution, and implement enhanced data security measures and ten years of free credit monitoring for affected consumers.

CriticalData BreachSecurity FailureBreach Notification Delay

$175.0M

CASettlementMultistate

Premera Blue Cross(Premera)

Premera Blue Cross suffered a data breach in 2014 that exposed personal and medical information of 10.5 million consumers. As part of a multistate settlement, Premera agreed to pay $10 million in civil penalties and implement security improvements and a compliance program. California will receive over $1 million from the settlement.

HighData BreachHealth DataSecurity Failure

$10.0M

CASettlement

Aetna Inc.(Aetna)

Aetna Inc. settled with the California Attorney General for $935,000 over allegations that it revealed the HIV status of 1,991 Californians through a mailing error where medication information was visible through envelope windows. The settlement requires Aetna to implement improved mailing procedures and conduct annual privacy assessments. This action enforces health privacy laws and protects sensitive medical information.

MediumHealth Data

$935K

CASettlementMultistate

Uber Technologies, Inc.(Uber)

Uber Technologies, Inc. settled for $148 million over a 2016 data breach that exposed 57 million users' personal information. The company was accused of covering up the breach by paying hackers and failing to notify authorities or affected drivers as required by law. The settlement includes a large penalty and mandates robust data security practices, privacy-by-design integration, and regular reporting to prevent future incidents.

CriticalData BreachNotice FailureSecurity Failure

$148.0M

CASettlement

Cottage Health System

Cottage Health System experienced two data breaches exposing medical information of over 50,000 patients due to inadequate security measures. The settlement requires a $2 million penalty and upgrades to security practices, including designating a Chief Privacy Officer.

HighHealth DataSecurity Failure

$2.0M

CASettlementMultistate

Lenovo

Lenovo preinstalled 'Visual Discovery' software on its computers that intercepted browsing data and broke encrypted connections without user consent, compromising security and privacy. The multi-state settlement imposes a $3.5 million penalty and requires Lenovo to implement disclosure, consent, opt-out, and security compliance measures.

HighNotice FailureConsent FailureOpt-Out Failure

$3.5M

CASettlementMultistate

Target

Target settled a multi-state enforcement action for a 2013 data breach that exposed payment card information of over 40 million customers due to inadequate security. The $18.5 million settlement requires Target to implement advanced security measures, and California receives over $1.4 million.

CriticalData BreachSecurity Failure

$18.5M

CASettlement

Wells Fargo Bank(Wells Fargo)

Wells Fargo Bank recorded consumer phone calls without providing timely notice as required by California law, violating privacy statutes. The settlement imposes a $7.616 million civil penalty, requires compliance with disclosure standards, and mandates an internal compliance program to protect consumer privacy.

HighNotice Failure

$7.6M

CASettlement

Houzz Inc.(Houzz)

The California Attorney General settled with Houzz Inc. for secretly recording incoming and outgoing telephone calls from March to September 2013 without notifying or obtaining consent from all parties, violating state wiretapping and eavesdropping laws. The settlement requires Houzz to pay $175,000, appoint a Chief Privacy Officer, conduct a privacy risk assessment, secure and destroy the recordings, and implement compliance measures.

MediumNotice FailureConsent Failure

$175K

CASettlement

Comcast

Comcast disclosed personal information of approximately 75,000 customers who had paid for unlisted VOIP phone service. The settlement includes a $25 million penalty and $8 million in restitution, along with a permanent injunction requiring improved privacy practices and customer disclosures.

CriticalUnauthorized Data Sharing

$25.0M

CASettlement

Aaron's, Inc.(Aaron's)

The California Attorney General reached a $28.4 million settlement with Aaron's, Inc. for installing spyware on rented computers without customer consent and for violating the Karnette Rental-Purchase Act. The spyware, called 'Detective Mode', allowed remote monitoring of keystrokes, screenshots, location, and webcam activation. Aaron's must refund $25 million to approximately 100,000 customers and pay $3.4 million in penalties, and is prohibited from using spyware.

HighConsent FailureGeolocation Data

$3.4M

CAEnforcement Action

Kaiser Foundation Health Plan, Inc.(Kaiser)

The California Attorney General filed a complaint against Kaiser Foundation Health Plan, Inc. for improperly disposing of patient medical records containing protected health information. The records, including diagnoses and lab results, were found discarded at a recycling facility, violating patient privacy. The action alleges breaches of the California Confidentiality of Medical Information Act.

LowHealth DataSecurity Failure
CAEnforcement Action

Citibank, N.A.(Citibank)

In 2013, the California Attorney General filed a complaint against Citibank, N.A. alleging that the bank failed to implement adequate security measures and did not properly notify customers about a data breach exposing personal and financial information. The complaint asserts violations of California's data breach notification law.

LowSecurity FailureBreach Notification Delay
CASettlement

Blue Cross of California(Anthem)

Anthem Blue Cross printed Social Security numbers on mailed letters, exposing the personal information of over 33,000 Medicare subscribers. The settlement requires the company to improve data security measures, provide employee training, and pay $150,000. This action aims to prevent future privacy violations.

MediumData Breach

$150K

Explore Enforcement Data