Court Rules

Privacy Enforcement Tracker

1,509 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,509

Total Actions

16

Jurisdictions

$26.6B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
CAEnforcement ActionMultistate

GoFundMe

California Attorney General Rob Bonta, co-leading a bipartisan coalition of 21 attorneys general and charitable regulators, sent a letter to GoFundMe demanding the platform remove all plagiarized donation web pages for over 1.4 million charities, disclose information about donations, and ensure pages do not outrank official charity sites in search results. The action follows reports that GoFundMe used charities' information without consent and engaged in deceptive solicitations, violating state charitable solicitation and consumer protection laws.

LowConsent Failure
CANew Law

California Privacy Protection Agency (CalPrivacy)

CalPrivacy sponsored AB 2021, the Whistleblower Protection and Privacy Act, introduced by Assemblymember Pilar Schiavo. The bill establishes whistleblower protections under the CCPA, including an award program and anti-retaliation provisions, to encourage insiders to report privacy violations.

LowNotice FailureUnauthorized Data SharingConsent Failure
CAInvestigation

xAI

California Attorney General Rob Bonta announced an investigation into xAI for its Grok AI model generating nonconsensual sexual images of women and children, including child sexual abuse material. The AG expressed deep concern and zero tolerance, urging immediate action to prevent further

LowChildren's DataConsent Failure
CAInvestigationMultistate

Inteliquent, Bandwidth, Peerless, Lumen

California Attorney General Rob Bonta announced Phase 2 of Operation Robocall Roundup, a multistate investigation targeting four major voice service providers—Inteliquent, Bandwidth, Peerless, and Lumen—for routing suspected illegal robocalls. The Anti-Robocall Multistate Litigation Task Force sent warning letters demanding they stop transmitting such calls, following Phase 1 which already led to some providers being removed from the FCC's database. The AG emphasized that these companies have a heightened responsibility to block call traffic from known bad actors.

LowConsent Failure

Explore Enforcement Data