Court Rules

Privacy Enforcement Tracker

1,506 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,506

Total Actions

16

Jurisdictions

$26.6B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
FTCEnforcement Action

Credit Glory LLC

The FTC filed a complaint against Credit Glory LLC and related entities for deceptive credit repair practices, including false promises, impersonating debt collectors, charging illegal upfront fees, and using negative option billing without consent. A federal court temporarily halted the operation.

LowConsent FailureNotice FailureDark Patterns
FTCEnforcement ActionMultistate

Hims & Hers

The FTC, along with Utah and California, filed a complaint against Hims & Hers alleging the telehealth provider shared consumers' sensitive health information with third-party advertising platforms without consent, and deceived consumers about billing and cancellation practices. The complaint alleges violations of the FTC Act and the Restore Online Shoppers' Confidence Act.

LowUnauthorized Data SharingConsent FailureDark Patterns
FTCSettlementMultistate

Handy Technologies

The FTC and New York Attorney General took action against Handy Technologies for deceptive earnings claims and failure to disclose fees and fines that led to millions of dollars being withheld from workers' wages. The FTC is sending over $2.7 million in refunds to 62,893 affected consumers.

LowNotice FailureConsent Failure
FTCWarning Letter

A&F Drum Company LLC

The FTC issued warning letters to seven companies for allegedly misrepresenting products as 'Made in the USA' when they were imported. The letters urge compliance with the FTC's Made in the USA standard. No monetary penalties were imposed.

LowNotice Failure
FTCEnforcement Action

Genesis Tech enterprise

The FTC sued the Genesis Tech enterprise and its owners for operating deceptive internet-based subscription schemes. The defendants allegedly misled consumers about subscription terms, billed without authorization, and made cancellation difficult. The court granted a temporary halt to the operations pending trial.

LowConsent FailureNotice FailureDark Patterns
FTCEnforcement ActionMultistate

World Professional Association for Transgender Health

The FTC, along with Alaska, Iowa, Nebraska, and Texas, filed a lawsuit against WPATH alleging the organization made false and unsubstantiated claims about the necessity, safety, and effectiveness of pediatric medical transition services. The complaint alleges WPATH misled parents and children about medical consensus and failed to disclose serious side effects, in violation of the FTC Act.

LowConsent FailureNotice FailureChildren's Data
FTCSettlement

Illuminate Education Inc.

The FTC finalized a consent order against Illuminate Education Inc. for failing to secure students' personal data, leading to a breach affecting 10.1 million students. The order requires Illuminate to implement a data security program, delete unnecessary data, and limit data collection, but imposes no monetary penalty.

LowSecurity FailureData BreachChildren's Data
FTCEnforcement Action

X Corp.

The Federal Trade Commission is seeking public comment on a petition from X Corp., formerly known as Twitter, to set aside or modify its 2022 settlement order with the agency. The petition argues that the order no longer serves a valid regulatory purpose and that X Corp. has built a world-class privacy program. The Commission will vote after the comment period closes.

LowConsent FailureNotice Failure
FTCEnforcement Action

National Amendment Assistance

The FTC filed a complaint against National Amendment Assistance and related entities for allegedly deceiving homeowners into paying unlawful upfront fees for mortgage relief services falsely associated with the CARES Act. The court granted a temporary restraining order, and the FTC seeks redress for affected consumers.

LowConsent FailureNotice Failure
FTCEnforcement Action

Innovative Partners, LP; American Collective, LP; Papyrus Green Investments LLC; Health Plan Administrators, LLC; Amani Ibrahim Shokry; Ahmed Ibrihim Shokry

The FTC filed a complaint and obtained a temporary restraining order against six defendants operating a deceptive health care scheme that impersonated government and insurance carriers to sell fake comprehensive health plans. The defendants allegedly charged consumers without express informed consent, failed to disclose material terms including cancellation processes, and misled consumers into paying for inadequate coverage that left many with substantial medical debt. The FTC seeks refunds for affected consumers and alleges violations of the FTC Act, Telemarketing Sales Rule, Impersonation Rule, and Gramm-Leach-Bliley Act.

LowConsent FailureNotice Failure
FTCEnforcement Action

Innovative Partners

The FTC filed a complaint against Innovative Partners in April 2026, alleging the operators impersonate the government and large insurance carriers to deceive consumers seeking health insurance into buying supposedly comprehensive PPO plans that do not offer the coverage they seek.

LowNotice Failure
FTCSettlement

Humor Rainbow, Inc. and Match Group Americas

The FTC settled with Humor Rainbow, Inc. (operator of OkCupid) and Match Group Americas over allegations that OkCupid deceived users by sharing personal data including photos and location information with an unauthorized third party, contrary to its privacy policy promises to inform users and provide opt-out opportunities. The settlement permanently prohibits the companies from misrepresenting their data collection, use, disclosure, and privacy control practices. No monetary penalty was imposed.

LowOpt-Out FailureNotice FailureUnauthorized Data Sharing
FTCGuidance

Website and Online Service Operators(Online Service Operators)

The FTC issued a policy statement announcing it will not enforce COPPA against operators that collect age verification data under specific conditions. The policy aims to encourage the use of age verification technologies to protect children online. Operators must limit data use, ensure security, provide notice, and use accurate verification methods.

LowChildren's DataConsent FailureNotice Failure
FTCEnforcement Action

JustAnswer LLC(JustAnswer)

Consumer fraud case where the FTC sued JustAnswer LLC for deceiving consumers into enrolling in a costly recurring monthly subscription by falsely claiming low one-time fees. The company did not obtain affirmative consent or clearly disclose subscription terms, violating ROSCA and the FTC Act. The FTC seeks an injunction, consumer refunds, and civil penalties.

LowConsent FailureNotice Failure
FTCInvestigation

Sports agents(Sports Agents)

Consumer fraud investigation where the FTC is seeking information from 20 universities about whether sports agents are complying with the Sports Agent Responsibility and Trust Act (SPARTA), which requires disclosures to student athletes and notification to schools. The inquiry aims to ensure student athletes are protected from deceptive practices by agents.

LowNotice Failure
FTCInvestigation

Alphabet, Inc.; Character Technologies, Inc.; Instagram, LLC; Meta Platforms, Inc.; OpenAI OpCo, LLC; Snap, Inc.; X.AI Corp.(Alphabet, Character Technologies, Instagram, Meta, OpenAI, Snap, X.AI)

The FTC issued 6(b) orders to seven technology companies to investigate the safety and privacy practices of their AI chatbots, particularly regarding impacts on children and teens. The inquiry focuses on compliance with children's privacy laws, data handling, and disclosures, requiring companies to provide information on these aspects.

LowChildren's DataNotice FailureConsent Failure
FTCConsent Decree

GoDaddy Inc., et al.(GoDaddy)

The FTC settled charges against GoDaddy Inc. and GoDaddy.com, LLC for misleading customers about their data security protections and failing to adequately secure their website hosting services. The company's security failures left customers' and website visitors' data vulnerable to attacks. The final order requires GoDaddy to implement comprehensive data security measures.

LowSecurity FailureNotice Failure
FTCConsent Decree

GoDaddy Inc. and GoDaddy.com, LLC(GoDaddy)

The FTC settled charges against GoDaddy Inc. and GoDaddy.com, LLC for misleading customers about their data security protections and failing to adequately secure their website hosting services. The company allegedly did not implement reasonable security measures, leaving customer websites vulnerable to attacks that could harm both the customers and visitors to those sites. The case resulted in a consent order requiring GoDaddy to improve its security practices.

LowNotice FailureSecurity Failure
FTCGuidance

Major Social Media and Video Streaming Companies (Amazon, Meta, YouTube, X, Snap, TikTok, Discord, Reddit, WhatsApp)(Major Social Media and Video Streaming Companies)

The FTC staff report examined data practices of nine major social media and video streaming companies and found they engaged in vast surveillance of users with lax privacy controls and inadequate safeguards for children and teens. The report recommends limiting data collection, restricting targeted advertising, and strengthening protections for young users, and calls for comprehensive federal privacy legislation.

LowChildren's DataOpt-Out FailureUnauthorized Data Sharing
FTCEnforcement Action

TikTok and ByteDance(TikTok)

The FTC and DOJ sued TikTok and ByteDance for violating COPPA by collecting personal information from children under 13 without parental consent. The complaint alleges that TikTok knowingly allowed millions of children on its platform and failed to comply with a 2019 consent order. The lawsuit seeks civil penalties and a permanent injunction.

LowChildren's DataConsent FailureNotice Failure
FTCConsent Decree

Blackbaud Inc.(Blackbaud)

The FTC finalized a consent order against Blackbaud Inc. for alleged security failures that led to a data breach exposing personal data of millions of consumers. Blackbaud must delete unnecessary data, implement a security program, and not misrepresent its policies. No monetary penalty was imposed.

LowSecurity FailureData BreachNotice Failure
FTCSettlement

InMarket Media(InMarket)

The FTC settled with InMarket Media for unlawfully collecting and using consumers' precise location data without adequate notice and consent. The order prohibits InMarket from selling or sharing precise location data, requires deletion of collected data, and mandates consumer consent mechanisms and privacy programs.

LowNotice FailureConsent FailureGeolocation Data
FTCConsent Decree

X-Mode Social and Outlogic, LLC(X-Mode Social)

The FTC settled with data brokers X-Mode Social and Outlogic for selling precise location data without informed consent and failing to protect sensitive information. The proposed order bans the sale of sensitive location data, requires deletion of collected data, and mandates a comprehensive privacy program. This is the FTC's first action against a data broker for sensitive location data practices.

LowConsent FailureGeolocation DataOpt-Out Failure
FTCConsent Decree

1Health.io(1Health)

The FTC finalized an order against 1Health.io for failing to secure genetic data and unfairly changing its privacy policy. The company must pay $75,000 for consumer refunds, destroy DNA samples, and implement security measures. It deceived consumers about data deletion and shared data without proper consent.

LowSecurity FailureOpt-Out FailureNotice Failure

$75K

FTCSettlement

1Health.io

The FTC settled with genetic testing company 1Health.io for failing to secure sensitive genetic and health data, deceiving consumers about data deletion, and unfairly changing its privacy policy without notice or consent. The settlement includes refunds totaling over $49,500 to 2,432 affected consumers.

LowSecurity FailureOpt-Out FailureNotice Failure

$50K

FTCAdministrative Order

Meta

The FTC proposed modifications to its 2020 privacy order with Meta, alleging violations including non-compliance with the order, misleading parents about Messenger Kids, and unauthorized data sharing. The proposed changes include banning monetization of youth data, pausing new product launches, and strengthening privacy requirements.

LowChildren's DataConsent FailureNotice Failure
FTCEnforcement Action

Experian

The FTC and CFPB filed an amicus brief with the Third Circuit Court of Appeals to overturn a lower court ruling that exempted furnishers from investigating indirect disputes under the FCRA. The brief argues that all disputes must be investigated to ensure consumers can correct inaccurate credit information and be notified of outcomes, upholding key FCRA protections.

LowNotice Failure
FTCSettlement

Support King, LLC(Support King)

The FTC finalized an order banning Support King, LLC and its CEO from the surveillance business for selling stalkerware apps that secretly collected and shared users' personal data without consent. The order requires them to delete all illegally collected data and notify affected device owners.

LowNotice FailureConsent FailureUnauthorized Data Sharing
FTCInvestigation

AT&T Mobility LLC, Cellco Partnership (Verizon Wireless), Charter Communications Operating LLC, Comcast Cable Communications (Xfinity), T-Mobile US Inc., Google Fiber Inc.(AT&T, Verizon, Charter, Comcast, T-Mobile, Google Fiber)

The FTC released a staff report based on Section 6(b) orders to six major ISPs, finding they collect extensive personal data, including internet traffic and location data, and share it with third parties. The ISPs often obscure data use disclosures in fine print and make it difficult for consumers to opt out, while combining data to profile sensitive characteristics. The report highlights the need for stricter privacy restrictions.

LowOpt-Out FailureNotice FailureUnauthorized Data Sharing
FTCConsent Decree

Support King, LLC(Support King)

The FTC banned Support King, LLC (SpyFone) and its CEO from the surveillance business for secretly harvesting and sharing users' data without consent, and ordered the deletion of all illegally collected data and notification to affected device owners. The company failed to secure the data, leading to a hack that exposed 2,200 consumers.

LowNotice FailureUnauthorized Data SharingConsent Failure

Explore Enforcement Data