Court Rules

Privacy Enforcement Tracker

1,285 enforcement actions from 14 federal and state jurisdictions. Every event traced back to its official government source.

1,285

Total Actions

14

Jurisdictions

$35.3B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
NJEnforcement Action

Susaida Nazario

A former employee of the New Jersey Department of Children and Families was indicted for allegedly leaking confidential child protection case information in exchange for bribes. The defendant, Susaida Nazario, misused her access to provide case details to an unauthorized individual, compromising sensitive children's data.

LowChildren's Data
NJEnforcement ActionMultistate

Uber Technologies, LLC, and Uber USA, LLC(Uber)

New Jersey Attorney General Matthew Platkin announced that New Jersey is joining a coalition of 22 states in suing Uber for deceptive practices related to its Uber One subscription service. The lawsuit alleges that Uber enrolled consumers without their knowledge and made cancellation extremely difficult, seeking restitution, penalties, and an injunction under New Jersey's Consumer Fraud Act and the Restore Online Shoppers' Confidence Act.

LowConsent FailureOpt-Out Failure
NJWarning LetterMultistate

Anthropic, Apple, Chai AI, Character Technologies, Google, Luka, Meta, Microsoft, Nomi AI, OpenAI, Perplexity AI, Replika, and xAI(Anthropic, Apple, Chai AI, Character.AI, Google, Luka, Meta, Microsoft, Nomi AI, OpenAI, Perplexity AI, Replika, xAI)

New Jersey Attorney General Matthew Platkin is leading a bipartisan coalition of 42 attorneys general in sending a letter to 13 tech companies, demanding that they implement safeguards for their AI chatbots to prevent harmful interactions such as sexually explicit conversations with children, encouraging self-harm, and spurring violence, following reports of serious incidents including deaths and self-harm.

LowAI/Automated Decisions
NJWarning Letter

auto dealerships(Auto Dealerships)

The New Jersey Division of Consumer Affairs sent warning letters to over 3,000 auto dealerships reminding them of the state's data deletion law, which requires dealerships to offer to delete personal data from vehicles when accepting them for resale or lease. Failure to comply can result in fines of $500 for first offenses and $1,000 for subsequent offenses, aimed at preventing unauthorized access to sensitive consumer information stored in vehicle infotainment systems.

LowSecurity Failure
NJEnforcement ActionMultistate

U.S. Department of Agriculture(USDA)

New Jersey Attorney General Matthew J. Platkin joined a coalition of 20 attorneys general in filing a lawsuit against the U.S. Department of Agriculture (USDA) for demanding that states turn over sensitive personal information of SNAP recipients, including Social Security numbers and addresses. The lawsuit argues that this demand violates federal privacy laws and the Constitution, as the data is protected and should only be used for program administration. The coalition seeks to block USDA from conditioning SNAP funding on compliance with this demand.

HighUnauthorized Data SharingConsent Failure
NJEnforcement Action

Discord, Inc.(Discord)

The New Jersey Attorney General filed a lawsuit against Discord, Inc. for deceptive business practices under the Consumer Fraud Act. Discord misrepresented its Safe Direct Messaging and age verification features, failing to protect children from

LowChildren's DataSecurity Failure
NJEnforcement ActionMultistate

U.S. Department of Treasury(U.S. Treasury)

New Jersey Attorney General Matthew J. Platkin joined a coalition of 19 attorneys general in filing a lawsuit against the Trump administration for illegally granting Elon Musk and DOGE unauthorized access to the U.S. Treasury Department's central payment system, which contains sensitive personal information such as Social Security numbers and bank details. The lawsuit seeks an injunction to halt this policy and a declaration that it is unlawful and unconstitutional.

HighSecurity Failure
NJSettlementMultistate

Marriott International, Inc.(Marriott)

A multistate coalition of 50 attorneys general, including New Jersey, reached a $52 million settlement with Marriott International, Inc. for two data breaches that exposed personal information of over 131 million consumers. The breaches resulted from inadequate cybersecurity practices at Starwood and Marriott networks. The settlement mandates comprehensive security improvements and monetary penalties.

CriticalData BreachSecurity Failure

$52.0M

NJConsent DecreeMultistate

Enzo Biochem, Inc.(Enzo Biochem)

Enzo Biochem, Inc. agreed to pay $4.5 million and strengthen its cybersecurity practices to settle allegations that deficient data security led to a ransomware attack exposing the health data of 2.4 million patients. The multistate enforcement action was led by New Jersey with New York and Connecticut.

HighData BreachHealth DataSecurity Failure

$4.5M

NJSettlement

Bumble, Inc.(Bumble)

Bumble Inc. agreed to pay $315,000 and update its disclosures to settle allegations that it misrepresented its criminal background screening policies to New Jersey users, violating the New Jersey Consumer Fraud Act and Internet Dating Safety Act. The settlement requires Bumble to clearly disclose its screening practices and safety limitations on its dating platforms.

MediumNotice Failure

$315K

NJSettlementMultistate

Morgan Stanley Smith Barney, LLC(Morgan Stanley)

New Jersey Attorney General Matthew Platkin announced a multistate settlement where Morgan Stanley will pay $1.27 million to NJ over data security incidents that compromised personal information of over 755,000 NJ residents and millions nationwide. The incidents involved improper decommissioning of devices and a software flaw, leading to unauthorized access. The settlement requires Morgan Stanley to strengthen its data security and disposal procedures.

HighSecurity FailureData Breach

$1.3M

NJEnforcement ActionMultistate

Meta Platforms, Inc.(Meta)

New Jersey, leading a coalition of 41 other attorneys general, sued Meta for knowingly designing addictive Instagram and Facebook features targeting children and teens while falsely claiming the platforms were safe. The lawsuit alleges Meta collected personal data from users under 13 without parental consent, violating the federal Children's Online Privacy Protection Act (COPPA) and state consumer protection laws like the New Jersey Consumer Fraud Act.

HighChildren's DataConsent Failure
NJSettlementMultistate

Blackbaud

Blackbaud, a software company, experienced a ransomware attack in 2020 that exposed sensitive personal information, including protected health data, due to inadequate security practices and delayed breach notification. A multistate investigation resulted in a $49.5 million settlement, requiring Blackbaud to enhance data security, implement breach response plans, and undergo third-party assessments.

CriticalData BreachSecurity FailureBreach Notification Delay

$49.5M

NJEnforcement ActionMultistate

Michael D. Lansky, LLC(Avid Telecom)

New Jersey Attorney General Matthew Platkin joined a multistate lawsuit against Avid Telecom for allegedly initiating and facilitating billions of illegal robocalls, including to numbers on the National Do Not Call Registry, in violation of the Telephone Consumer Protection Act and Telemarketing Sales Rule. The company is accused of transmitting scam calls and ignoring warnings from the Industry Traceback Group.

LowOpt-Out FailureConsent Failure
NJSettlementMultistate

EyeMed Vision Care

EyeMed Vision Care suffered a data breach in June 2020 due to poor security practices, including shared passwords, exposing personal and medical information of approximately 2.1 million individuals. The multistate settlement imposes a $2.5 million penalty and requires EyeMed to implement enhanced security measures and comply with privacy laws.

HighData BreachSecurity FailureHealth Data

$2.5M

NJAdministrative OrderMultistate

Horatiu Charlie Caragaceanu, The Shark of Wall Street, and Hedge4.ai(Hedge4.ai)

The New Jersey Bureau of Securities issued a Cease and Desist Order against Horatiu Charlie Caragaceanu and his organizations for promoting TruthGPT Coin, a cryptocurrency scam that falsely claimed AI capabilities and endorsements from figures like Elon Musk. The respondents misrepresented the AI model's ability to predict cryptocurrency prices and manipulated images to show false endorsements, targeting investors with unrealistic profit promises.

LowAI/Automated Decisions
NJSettlementMultistate

Google

Google settled with 40 state attorneys general over allegations that it misled consumers about location tracking practices. Google will pay $391.5 million and must enhance transparency and user controls for location data collection.

CriticalNotice FailureOpt-Out FailureGeolocation Data

$391.5M

NJSettlementMultistate

Experian and T-Mobile

New Jersey Attorney General Matthew J. Platkin announced a multistate settlement with Experian and T-Mobile over a 2015 data breach that compromised personal information of over 15 million consumers. The companies will pay over $16 million to states and agree to improve data security and vendor management practices. New Jersey will receive approximately $500,000 from the settlement.

CriticalData BreachSecurity Failure

$16.0M

NJSettlementMultistate

Wawa Inc.(Wawa)

Wawa Inc. agreed to pay $8 million to resolve a multistate investigation into a data breach that compromised approximately 34 million payment cards between April 2019 and December 2019. The breach involved malware that harvested card data from point-of-sale terminals. New Jersey will receive $2.5 million, and Wawa must implement enhanced cybersecurity measures including a comprehensive security program and third-party audits.

HighData BreachSecurity Failure

$8.0M

NJConsent Decree

AllCare Pharmacy(AllCare)

The New Jersey Board of Pharmacy temporarily suspended the license of Christina Bekhit, owner of AllCare Pharmacy, after her arrest for selling falsified COVID-19 vaccination cards and entering false information into the state's immunization database. Under a consent order filed on July 5, 2022, Bekhit agreed to cease pharmacy operations and surrender her permit, addressing grave public health risks from fraudulent vaccination records.

LowHealth Data
NJSettlementMultistate

Carnival Cruise Line(Carnival)

New Jersey, as part of a multistate coalition, settled with Carnival Cruise Line over a 2019 data breach that compromised personal information of approximately 180,000 employees and customers nationwide. The breach resulted from deficiencies in Carnival's data security program and delayed breach notification. Carnival will pay $1.25 million and implement enhanced email security and breach response measures.

HighData BreachSecurity FailureBreach Notification Delay

$1.3M

NJEnforcement Action

AllCare Pharmacy

The New Jersey Attorney General announced the arrest of Christina Bekhit, a pharmacist operating AllCare Pharmacy, for selling fake COVID-19 vaccination record cards and entering false information into the state's immunization database. She faces criminal charges for computer criminal activity, tampering with public information, and falsification of medical records.

LowHealth Data
NJInvestigationMultistate

TikTok

New Jersey is co-leading a multistate investigation into TikTok to determine if the platform violates consumer protection laws by using techniques that increase engagement among young users, potentially causing mental and physical harm. The investigation will examine what TikTok knows about these harms to children, teenagers, and young adults.

LowChildren's Data
NJInvestigationMultistate

Meta Platforms, Inc.(Meta)

New Jersey is co-leading a nationwide investigation into whether Instagram and its parent company Meta Platforms, Inc. are violating state consumer protection laws by employing techniques that induce children, teenagers, and young adults to use the platform in potentially harmful ways. The bipartisan coalition of attorneys general is examining the potential mental and physical health harms resulting from extended engagement, including depression, anxiety, and body image issues.

LowChildren's Data
NJConsent Decree

Command Marketing Innovations, LLC and Strategic Content Imaging, LLC(Command Marketing Innovations and Strategic Content Imaging)

Command Marketing Innovations, LLC and Strategic Content Imaging, LLC settled allegations that they violated the New Jersey Consumer Fraud Act and HIPAA by failing to safeguard protected health information, exposing the data of 55,715 New Jersey residents. The companies agreed to pay $130,000 in penalties and implement comprehensive security measures, including appointing security officers and providing employee training.

MediumData BreachHealth DataSecurity Failure

$130K

NJSettlement

Diamond Institute for Infertility and Menopause, LLC(Diamond Institute for Infertility and Menopause)

The New Jersey Attorney General settled with Diamond Institute for Infertility and Menopause, LLC, following a data breach that exposed the electronic protected health information (ePHI) of 14,663 patients. The investigation found the clinic failed to implement required HIPAA Security Rule safeguards, including risk assessments, encryption, and access controls. The $495,000 settlement includes civil penalties and requires the clinic to implement a comprehensive information security program and corrective actions.

MediumSecurity FailureHealth Data

$495K

NJEnforcement Action

Kristan T. Bell(New Jersey Department of Children and Families)

A caseworker with the New Jersey Division of Child Protection and Permanency was charged with criminal offenses for allegedly accessing and disclosing confidential DCF database records without authorization. The charges include Computer Theft and Unlawful Access and Disclosure. The investigation was conducted by the New Jersey State Police.

LowChildren's DataUnauthorized Data Sharing
NJSettlementMultistate

Retrieval-Masters Creditors Bureau d/b/a American Medical Collection Agency(American Medical Collection Agency)

AMCA suffered an eight-month data breach from August 2018 to March 2019, exposing personal information including Social Security numbers, payment card data, and medical test details of over 7 million individuals nationwide, including 246,000 New Jersey residents. The multistate settlement requires AMCA to implement enhanced data security measures and pay $21 million, though payment is suspended due to the company's financial situation.

CriticalSecurity FailureData BreachHealth Data

$21.0M

NJSettlementMultistate

Sabre Corp.(Sabre)

New Jersey participated in a multi-state settlement resolving an investigation into a 2017 data breach at Sabre Hospitality Solutions. Intruders accessed the company's hotel booking system from August 2016 to March 2017, compromising data from over 1.3 million consumer credit cards, including CVV numbers and expiration dates. Sabre failed to promptly notify affected consumers. The $2.4 million settlement requires Sabre to implement enhanced data security measures, develop a breach notification plan, clarify contractual responsibilities with client hotels, and undergo third-party security assessments.

HighData BreachBreach Notification Delay

$2.4M

NJSettlementMultistate

CafePress

New Jersey joined a multistate $2 million settlement with online retailer CafePress over a 2019 data breach that exposed personal information of approximately 22 million consumers nationwide, including over 540,000 in New Jersey. The settlement requires CafePress to implement a comprehensive cybersecurity program, incident response plan, and third-party assessments for five years, with payment suspended pending compliance.

HighData BreachSecurity Failure

$2.0M

Explore Enforcement Data