Court Rules

Privacy Enforcement Tracker

1,634 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,634

Total Actions

16

Jurisdictions

$49.9B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
WAEnforcement ActionMultistate

U.S. Department of Education

Attorney General Nick Brown of Washington led a coalition of 17 state attorneys general in filing a lawsuit against the U.S. Department of Education on March 11, 2026, challenging new requirements for the IPEDS survey that demand race- and sex-disaggregated student data retroactive seven years. The coalition alleges the rushed rule violates the law, jeopardizes student privacy by collecting in-depth student information, and imposes undue burdens on institutions with unclear data definitions and risk of severe penalties for errors. The lawsuit seeks to invalidate the rule, arguing it was arbitrarily implemented without proper procedure and poses widespread privacy risks to students.

CriticalStudent Data
ILEnforcement ActionMultistate

U.S. Department of Education(Department of Education)

Illinois Attorney General Kwame Raoul, joined by 16 other attorneys general, filed a lawsuit against the U.S. Department of Education to stop new data collection requirements under IPEDS that threaten student privacy by requesting sensitive personal information including income, test scores, and GPA.

LowStudent Data
MAEnforcement ActionMultistate

U.S. Department of Education(Department of Education)

Massachusetts Attorney General Andrea Campbell co-led a coalition of 17 attorneys general in filing a lawsuit against the Trump Administration to stop new data reporting requirements for colleges and universities through IPEDS. The requirements demand detailed student data disaggregated by race and sex, retroactive for seven years, which the coalition argues jeopardizes student privacy and could lead to baseless investigations.

LowStudent Data
CTEnforcement ActionMultistate

U.S. Department of Education(Department of Education)

Connecticut Attorney General William Tong joined a coalition of 17 attorneys general in filing a lawsuit against the U.S. Department of Education to stop new data reporting requirements under IPEDS that demand detailed student information. The coalition argues the requirements are unlawful, arbitrary, and jeopardize student privacy by requesting in-depth data that could lead to inadvertent errors and baseless investigations. The lawsuit seeks an injunction to block the implementation of these requirements.

LowStudent Data
NYEnforcement ActionMultistate

U.S. Department of Education

New York Attorney General Letitia James, joined by 16 other states, sued the U.S. Department of Education over a new survey requiring colleges to submit extensive student data, arguing it violates the Administrative Procedure Act and threatens student privacy. The lawsuit seeks to block the mandate and prevent penalties for non-compliance.

LowStudent Data
CAEnforcement ActionMultistate

Live Nation

California Attorney General Rob Bonta and a coalition of state attorneys general announced they will continue their antitrust lawsuit against Live Nation/Ticketmaster after the U.S. Department of Justice settled the case. The states aim to hold Live Nation accountable for anticompetitive conduct that harms consumers, artists, and venues in the live music industry.

Low
NJEnforcement Action

Susaida Nazario

A former employee of the New Jersey Department of Children and Families was indicted for allegedly leaking confidential child protection case information in exchange for bribes. The defendant, Susaida Nazario, misused her access to provide case details to an unauthorized individual, compromising sensitive children's data.

LowChildren's Data
CTAdministrative Order

Aquarion Company(Aquarion)

PURA preliminarily approved the sale of Aquarion Water Company to a new nonprofit Aquarion Water Authority, expected to double water rates. Attorney General Tong opposes the decision, citing loss of public oversight and high costs to consumers. The conversion removes PURA regulation, placing rate approvals under a board with no history of rejecting hikes.

Low
OREnforcement ActionMultistate

Trump Administration

Consumer protection lawsuit led by Oregon Attorney General Dan Rayfield, on behalf of a coalition of 24 states and two governors, challenging the Trump Administration's imposition of worldwide tariffs under Section 122 of the Trade Act of 1974. The suit alleges the administration is acting without legal authority, violating the Administrative Procedure Act and constitutional separation of powers, and causing immediate financial harm to American consumers and businesses through increased prices.

LowConsumer Fraud
CASettlement

Ford Motor Company

The California Privacy Protection Agency (CalPrivacy) settled with Ford Motor Company requiring the company to pay a $375,703 fine and change its practices. Ford violated the CCPA by requiring consumers to complete an email verification step before they could opt-out of the sale and sharing of their personal information collected through digital properties and connected vehicle services. In addition to the fine, Ford must provide easy methods to submit opt-out requests with minimal steps, audit its tracking technologies, and ensure compliance with opt-out preference signals including Global Privacy Control.

MediumOpt-Out Failure

$376K

CPPASettlement

Ford Motor Company(Ford)

The California Privacy Protection Agency settled with Ford Motor Company for $375,703 after finding that Ford violated the CCPA by requiring email verification for opt-out requests, creating unnecessary friction. Ford must implement easier opt-out methods, conduct a website audit, and comply with global privacy controls.

MediumOpt-Out Failure

$376K

CPPASettlement

PlayOn Sports

The California Privacy Protection Agency settled with PlayOn Sports for $1.10 million over CCPA violations, including failing to provide adequate opt-out mechanisms and improperly tracking users, particularly students. The company must implement proper opt-out methods, improve disclosures, and comply with children's data consent requirements.

HighOpt-Out FailureNotice FailureChildren's Data

$1.1M

CAEnforcement ActionMultistate

GoFundMe

California Attorney General Rob Bonta, co-leading a bipartisan coalition of 21 attorneys general and charitable regulators, sent a letter to GoFundMe demanding the platform remove all plagiarized donation web pages for over 1.4 million charities, disclose information about donations, and ensure pages do not outrank official charity sites in search results. The action follows reports that GoFundMe used charities' information without consent and engaged in deceptive solicitations, violating state charitable solicitation and consumer protection laws.

LowConsent Failure
CAGuidance

U.S. Department of Health and Human Services(Department of Health and Human Services)

California Attorney General Rob Bonta sent a letter to the U.S. Department of Health and Human Services opposing a proposed rule that would eliminate model card requirements for AI tools in healthcare, warning that such rollbacks could lead to biased and unsafe healthcare decisions by reducing transparency.

LowAI/Automated DecisionsHealth Data
ILEnforcement ActionMultistate

U.S. Department of Agriculture(USDA)

Attorney General Raoul secured a court order preventing the U.S. Department of Agriculture from collecting SNAP applicants' and recipients' personal data without an agreed-upon protocol that restricts sharing with unrelated entities like the Department of Homeland Security. The court found that the USDA's proposed protocol would violate federal law by allowing data use for immigration enforcement, contrary to the intended purpose of SNAP.

LowUnauthorized Data Sharing
MAEnforcement ActionMultistate

U.S. Department of Agriculture(USDA)

Massachusetts Attorney General Andrea Campbell secured a preliminary injunction from the U.S. District Court blocking the Trump Administration's USDA from cutting off SNAP funding to states that refuse to turn over personal data of SNAP applicants and recipients. The court found USDA's proposed data protocol unlawful because it allowed sharing data with entities unrelated to federal benefits administration.

LowUnauthorized Data Sharing
CAEnforcement Action

U.S. Department of Agriculture(USDA)

California Attorney General Rob Bonta secured a second preliminary injunction from the U.S. District Court for the Northern District of California blocking the Trump Administration's demand that states turn over personal data of SNAP applicants and recipients. The court found the USDA's proposed data protocol would allow sharing of state data with entities unrelated to federal benefits administration, violating federal law.

HighUnauthorized Data Sharing
CTEnforcement Action

JRK Property Holdings

Connecticut Attorney General William Tong secured a $5.1 million financial relief package for tenants of the Concierge Apartments in Rocky Hill following an investigation into unsafe living conditions and landlord mismanagement. The agreement provides cash payments, free rent, and utility waivers to displaced and affected tenants, with a second agreement pending to address long-term accountability and communications.

High

$5.1M

FTCSettlementMultistate

Walmart, Inc.(Walmart)

The FTC and 11 states settled with Walmart for $100 million over deceptive earnings claims in its Spark Driver gig worker app, where drivers were misled about base pay, tips, and incentives. The settlement also addressed GLBA violations for failing to provide proper notice regarding the handling of drivers' financial information. Walmart must implement an earnings verification program and is banned from misrepresenting driver earnings.

CriticalDark PatternsNotice Failure

$100.0M

TXSettlement

Samsung Electronics America, Inc.(Samsung)

Texas Attorney General Ken Paxton reached an agreement with Samsung Electronics America, Inc. to stop collecting Automated Content Recognition (ACR) data from smart TVs without consumers' express consent. Samsung must update its smart TVs to provide clear and conspicuous disclosures and obtain consent before any data collection, ensuring Texans are informed and in control of their viewing data.

LowConsent FailureNotice Failure
OREnforcement Action

Devon T. Horace(Alberta Main Street)

Consumer protection case involving theft of charitable funds. Former Alberta Main Street president Devon T. Horace pleaded no contest to theft and falsifying business records, paid $85,080.95 in restitution, and was sentenced to probation and community service.

LowSecurity Failure
HHSEnforcement Action

BMG of Kansas, Inc.

BMG of Kansas, Inc. (Health Plan, KS) reported a HIPAA breach affecting 1,327 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Manhattan Retirement Foundation d/b/a Meadowlark Hills

Manhattan Retirement Foundation d/b/a Meadowlark Hills (Healthcare Provider, KS) reported a HIPAA breach affecting 14,442 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

AltaMed Health Services Corporation

AltaMed Health Services Corporation (Healthcare Provider, CA) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
NJAdministrative Order

Arya International Inc. (Mystical Stars, LLC)

The New Jersey Bureau of Securities issued a Summary Cease and Desist Order against Arya International Inc. (operating as Mystical Stars, LLC) and owner Rupal K. Patel for operating a nationwide investment fraud scheme involving unregistered securities. The scheme targeted friends and family of dance students, raising over $5.4 million from 74 investors, including 48 New Jersey residents, through false promises of guaranteed 10-20% returns. The order requires the entities to immediately halt sales of unregistered securities and cease misleading investors.

Low
FTCGuidance

Website and Online Service Operators(Online Service Operators)

The FTC issued a policy statement announcing it will not enforce COPPA against operators that collect age verification data under specific conditions. The policy aims to encourage the use of age verification technologies to protect children online. Operators must limit data use, ensure security, provide notice, and use accurate verification methods.

LowChildren's DataConsent FailureNotice Failure
FTCGuidance

Operators of General Audience and Mixed Audience Sites and Services(Online Service Operators)

The FTC issued a policy statement announcing that it will not enforce the COPPA Rule against website and online service operators that use age verification technologies solely to determine user age, provided they comply with conditions such as limiting data use, ensuring security, and providing clear notice. This policy aims to incentivize age verification tools to protect children online.

LowChildren's Data
HHSEnforcement Action

Commonwealth Care Alliance

Commonwealth Care Alliance (Health Plan, MA) reported a HIPAA breach affecting 634 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.

LowData BreachHealth DataUnauthorized Data Sharing
CANew Law

California Privacy Protection Agency (CalPrivacy)

CalPrivacy sponsored AB 2021, the Whistleblower Protection and Privacy Act, introduced by Assemblymember Pilar Schiavo. The bill establishes whistleblower protections under the CCPA, including an award program and anti-retaliation provisions, to encourage insiders to report privacy violations.

LowNotice FailureUnauthorized Data SharingConsent Failure
MNSettlement

Fleet Farm

Minnesota Attorney General Keith Ellison settled a lawsuit against Fleet Farm for negligently selling at least 37 firearms to two straw purchasers over 16 months, one of which was used in a fatal shooting. The $1 million settlement requires Fleet Farm to implement significant policy changes, pay the penalty, and publicly disclose 694 internal documents now housed in UCSF's Industry Documents Library.

MediumSecurity Failure

$1.0M

Explore Enforcement Data