Court Rules

Privacy Enforcement Tracker

1,506 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,506

Total Actions

16

Jurisdictions

$26.6B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
FTCEnforcement Action

Credit Glory LLC

The FTC filed a complaint against Credit Glory LLC and related entities for deceptive credit repair practices, including false promises, impersonating debt collectors, charging illegal upfront fees, and using negative option billing without consent. A federal court temporarily halted the operation.

LowConsent FailureNotice FailureDark Patterns
FTCEnforcement ActionMultistate

Hims & Hers

The FTC, along with Utah and California, filed a complaint against Hims & Hers alleging the telehealth provider shared consumers' sensitive health information with third-party advertising platforms without consent, and deceived consumers about billing and cancellation practices. The complaint alleges violations of the FTC Act and the Restore Online Shoppers' Confidence Act.

LowUnauthorized Data SharingConsent FailureDark Patterns
FTCSettlementMultistate

Handy Technologies

The FTC and New York Attorney General took action against Handy Technologies for deceptive earnings claims and failure to disclose fees and fines that led to millions of dollars being withheld from workers' wages. The FTC is sending over $2.7 million in refunds to 62,893 affected consumers.

LowNotice FailureConsent Failure
FTCEnforcement Action

Genesis Tech enterprise

The FTC sued the Genesis Tech enterprise and its owners for operating deceptive internet-based subscription schemes. The defendants allegedly misled consumers about subscription terms, billed without authorization, and made cancellation difficult. The court granted a temporary halt to the operations pending trial.

LowConsent FailureNotice FailureDark Patterns
FTCEnforcement ActionMultistate

World Professional Association for Transgender Health

The FTC, along with Alaska, Iowa, Nebraska, and Texas, filed a lawsuit against WPATH alleging the organization made false and unsubstantiated claims about the necessity, safety, and effectiveness of pediatric medical transition services. The complaint alleges WPATH misled parents and children about medical consensus and failed to disclose serious side effects, in violation of the FTC Act.

LowConsent FailureNotice FailureChildren's Data
FTCEnforcement Action

Amare Global Holdings

The FTC filed a contempt motion against Amare Global Holdings, Shawn Talbott, Patrick Hintze, and Hiep Tran for allegedly violating a 2005 FTC order that prohibited Talbott from making unsubstantiated health claims. The motion alleges that the defendants marketed dietary supplements for children and adults with false claims about treating depression, anxiety, and ADHD, and misrepresented scientific evidence. The FTC seeks compensatory damages for consumers.

LowConsent FailureHealth Data
FTCEnforcement Action

National Amendment Assistance

The FTC filed a complaint against National Amendment Assistance and related entities for allegedly deceiving homeowners into paying unlawful upfront fees for mortgage relief services falsely associated with the CARES Act. The court granted a temporary restraining order, and the FTC seeks redress for affected consumers.

LowConsent FailureNotice Failure
FTCEnforcement Action

X Corp.

The Federal Trade Commission is seeking public comment on a petition from X Corp., formerly known as Twitter, to set aside or modify its 2022 settlement order with the agency. The petition argues that the order no longer serves a valid regulatory purpose and that X Corp. has built a world-class privacy program. The Commission will vote after the comment period closes.

LowConsent FailureNotice Failure
FTCEnforcement Action

Amare Global Holdings Inc.

The FTC sued Amare Global Holdings Inc. and its principals for falsely claiming that dietary supplements like Kids Happy Juice and Kids Mood+ could treat or cure depression, anxiety, and ADHD in children and adults. The FTC also alleged the company misled recruits about their potential earnings as 'brand partners' in its multilevel marketing scheme.

LowConsent FailureHealth DataChildren's Data
FTCWarning Letter

12 Unnamed Nudify Tool Providers

The FTC sent warning letters to 12 companies offering 'nudify' tools that generate nonconsensual intimate images, for failing to comply with the TAKE IT DOWN Act (TIDA) by not providing a mechanism for victims to request removal of such content. The letters urge immediate compliance with TIDA, which requires platforms to remove nonconsensual intimate images within 48 hours of a valid request. Noncompliant companies may face future legal action and civil penalties of up to $53,088 per violation.

LowConsent Failure
FTCEnforcement Action

Covered Platforms

The FTC began enforcing the TAKE IT DOWN Act on May 19, 2026, a law requiring covered platforms to establish a process for victims to request removal of nonconsensual intimate images and delete such content within 48 hours of a valid request. The agency launched a consumer complaint portal, issued compliance guidance for businesses and consumers, and sent reminder letters to major platforms including Meta, TikTok, and X about their obligations under the law. No specific penalties or enforcement actions against individual companies were announced in this release.

LowConsent FailureChildren's Data
FTCSettlement

Kochava, Inc. and Collective Data Solutions (CDS)

The FTC settled charges with data broker Kochava, Inc. and its subsidiary Collective Data Solutions (CDS) over allegations that they sold precise location data from hundreds of millions of mobile devices without consumer consent, enabling tracking of visits to sensitive locations like reproductive health clinics and places of worship. The settlement prohibits the companies from selling or sharing sensitive location data without affirmative express consumer consent, and imposes compliance requirements including a sensitive location data program, supplier consent assessments, incident reporting, and data retention schedules. No monetary penalty was imposed.

LowConsent FailureGeolocation DataUnauthorized Data Sharing
FTCEnforcement Action

Innovative Partners, LP; American Collective, LP; Papyrus Green Investments LLC; Health Plan Administrators, LLC; Amani Ibrahim Shokry; Ahmed Ibrihim Shokry

The FTC filed a complaint and obtained a temporary restraining order against six defendants operating a deceptive health care scheme that impersonated government and insurance carriers to sell fake comprehensive health plans. The defendants allegedly charged consumers without express informed consent, failed to disclose material terms including cancellation processes, and misled consumers into paying for inadequate coverage that left many with substantial medical debt. The FTC seeks refunds for affected consumers and alleges violations of the FTC Act, Telemarketing Sales Rule, Impersonation Rule, and Gramm-Leach-Bliley Act.

LowConsent FailureNotice Failure
FTCSettlement

Humor Rainbow, Inc. and Match Group Americas

The FTC settled with Humor Rainbow, Inc. (operator of OkCupid) and Match Group Americas over allegations that OkCupid deceived users by sharing personal data including photos and location information with an unauthorized third party, contrary to its privacy policy promises to inform users and provide opt-out opportunities. The settlement permanently prohibits the companies from misrepresenting their data collection, use, disclosure, and privacy control practices. No monetary penalty was imposed.

LowOpt-Out FailureNotice FailureUnauthorized Data Sharing
FTCGuidance

Website and Online Service Operators(Online Service Operators)

The FTC issued a policy statement announcing it will not enforce COPPA against operators that collect age verification data under specific conditions. The policy aims to encourage the use of age verification technologies to protect children online. Operators must limit data use, ensure security, provide notice, and use accurate verification methods.

LowChildren's DataConsent FailureNotice Failure
FTCConsent Decree

General Motors LLC, General Motors Holdings LLC, and OnStar, LLC(General Motors)

Privacy enforcement action where the FTC settled with General Motors and OnStar for collecting and selling consumers' geolocation and driving behavior data without adequate notice or consent. The order prohibits sharing data with consumer reporting agencies and requires transparency and consumer choice measures.

LowGeolocation DataConsent FailureUnauthorized Data Sharing
FTCEnforcement Action

JustAnswer LLC(JustAnswer)

Consumer fraud case where the FTC sued JustAnswer LLC for deceiving consumers into enrolling in a costly recurring monthly subscription by falsely claiming low one-time fees. The company did not obtain affirmative consent or clearly disclose subscription terms, violating ROSCA and the FTC Act. The FTC seeks an injunction, consumer refunds, and civil penalties.

LowConsent FailureNotice Failure
FTCInvestigation

Alphabet, Inc.; Character Technologies, Inc.; Instagram, LLC; Meta Platforms, Inc.; OpenAI OpCo, LLC; Snap, Inc.; X.AI Corp.(Alphabet, Character Technologies, Instagram, Meta, OpenAI, Snap, X.AI)

The FTC issued 6(b) orders to seven technology companies to investigate the safety and privacy practices of their AI chatbots, particularly regarding impacts on children and teens. The inquiry focuses on compliance with children's privacy laws, data handling, and disclosures, requiring companies to provide information on these aspects.

LowChildren's DataNotice FailureConsent Failure
FTCSettlement

Mobilewalla Inc.(Mobilewalla)

The FTC finalized an order banning Mobilewalla Inc. from selling sensitive location data after alleging the company sold such data without verifying consumer consent. The order prohibits Mobilewalla from collecting data from ad exchanges for non-auction purposes, misrepresenting data practices, and using location data from sensitive locations like health clinics and places of worship.

LowConsent FailureGeolocation Data
FTCConsent Decree

Gravy Analytics Inc. and Venntel Inc.(Gravy Analytics)

The FTC took action against Gravy Analytics Inc. and Venntel Inc. for unlawfully tracking and selling sensitive consumer location data without consent. The proposed consent order prohibits the sale or use of sensitive location data, requires deletion of historic data, and mandates compliance programs. This is part of the FTC's series of actions against data brokers selling sensitive location data.

LowConsent FailureUnauthorized Data SharingGeolocation Data
FTCGuidance

Major Social Media and Video Streaming Companies (Amazon, Meta, YouTube, X, Snap, TikTok, Discord, Reddit, WhatsApp)(Major Social Media and Video Streaming Companies)

The FTC staff report examined data practices of nine major social media and video streaming companies and found they engaged in vast surveillance of users with lax privacy controls and inadequate safeguards for children and teens. The report recommends limiting data collection, restricting targeted advertising, and strengthening protections for young users, and calls for comprehensive federal privacy legislation.

LowChildren's DataOpt-Out FailureUnauthorized Data Sharing
FTCEnforcement Action

TikTok and ByteDance(TikTok)

The FTC and DOJ sued TikTok and ByteDance for violating COPPA by collecting personal information from children under 13 without parental consent. The complaint alleges that TikTok knowingly allowed millions of children on its platform and failed to comply with a 2019 consent order. The lawsuit seeks civil penalties and a permanent injunction.

LowChildren's DataConsent FailureNotice Failure
FTCSettlement

InMarket Media(InMarket)

The FTC settled with InMarket Media for unlawfully collecting and using consumers' precise location data without adequate notice and consent. The order prohibits InMarket from selling or sharing precise location data, requires deletion of collected data, and mandates consumer consent mechanisms and privacy programs.

LowNotice FailureConsent FailureGeolocation Data
FTCConsent Decree

X-Mode Social and Outlogic, LLC(X-Mode Social)

The FTC settled with data brokers X-Mode Social and Outlogic for selling precise location data without informed consent and failing to protect sensitive information. The proposed order bans the sale of sensitive location data, requires deletion of collected data, and mandates a comprehensive privacy program. This is the FTC's first action against a data broker for sensitive location data practices.

LowConsent FailureGeolocation DataOpt-Out Failure
FTCGuidance

Website and Online Service Operators Covered by COPPA(COPPA-Covered Operators)

The FTC has proposed amendments to the COPPA Rule to enhance children's privacy protections. Key changes include requiring separate parental consent for targeted advertising, prohibiting conditioning access on data collection, limiting push notifications, strengthening data security and retention requirements, and restricting commercial use in educational technology. The proposal shifts responsibility from parents to companies to safeguard children's data.

LowChildren's DataConsent FailureUnauthorized Data Sharing
FTCWarning Letter

Five tax preparation companies(Tax Preparation Companies)

The FTC issued warnings to five tax preparation companies against using or disclosing consumer tax data for unrelated purposes like advertising without explicit consent. The agency cites its penalty offense authority, referencing a previous case against Beneficial Corp, and warns that such practices violate the FTC Act and could incur penalties up to $50,120 per violation. The notices highlight that using tracking technologies for data collection without consent is also prohibited.

LowConsent Failure
FTCConsent Decree

1Health.io(1Health)

The FTC finalized an order against 1Health.io for failing to secure genetic data and unfairly changing its privacy policy. The company must pay $75,000 for consumer refunds, destroy DNA samples, and implement security measures. It deceived consumers about data deletion and shared data without proper consent.

LowSecurity FailureOpt-Out FailureNotice Failure

$75K

FTCSettlement

1Health.io

The FTC settled with genetic testing company 1Health.io for failing to secure sensitive genetic and health data, deceiving consumers about data deletion, and unfairly changing its privacy policy without notice or consent. The settlement includes refunds totaling over $49,500 to 2,432 affected consumers.

LowSecurity FailureOpt-Out FailureNotice Failure

$50K

FTCAdministrative Order

Meta

The FTC proposed modifications to its 2020 privacy order with Meta, alleging violations including non-compliance with the order, misleading parents about Messenger Kids, and unauthorized data sharing. The proposed changes include banning monetization of youth data, pausing new product launches, and strengthening privacy requirements.

LowChildren's DataConsent FailureNotice Failure
FTCSettlement

Ring

The FTC settled with Ring for failing to secure consumer videos, allowing unauthorized access by employees and hackers. Ring agreed to provide $5.6 million in refunds to affected customers and implement security measures.

LowData BreachUnauthorized Data SharingConsent Failure

$5.6M

Explore Enforcement Data