Court Rules

Privacy Enforcement Tracker

1,634 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,634

Total Actions

16

Jurisdictions

$49.9B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
FTCConsent Decree

X-Mode Social and Outlogic, LLC(X-Mode Social)

The FTC settled with data brokers X-Mode Social and Outlogic for selling precise location data without informed consent and failing to protect sensitive information. The proposed order bans the sale of sensitive location data, requires deletion of collected data, and mandates a comprehensive privacy program. This is the FTC's first action against a data broker for sensitive location data practices.

LowConsent FailureGeolocation DataOpt-Out Failure
FTCGuidance

Website and Online Service Operators Covered by COPPA(COPPA-Covered Operators)

The FTC has proposed amendments to the COPPA Rule to enhance children's privacy protections. Key changes include requiring separate parental consent for targeted advertising, prohibiting conditioning access on data collection, limiting push notifications, strengthening data security and retention requirements, and restricting commercial use in educational technology. The proposal shifts responsibility from parents to companies to safeguard children's data.

LowChildren's DataConsent FailureUnauthorized Data Sharing
FTCConsent Decree

Global Tel*Link Corp.(Global Tel*Link)

The FTC proposed a consent order against Global Tel*Link Corp. for failing to secure sensitive user data, leading to a breach affecting nearly 650,000 consumers, and for delaying notification for about nine months. The order requires the company to implement a comprehensive security program, notify affected users with credit monitoring, and report future breaches promptly.

LowSecurity FailureBreach Notification Delay
NYConsent Decree

Marymount Manhattan College

Marymount Manhattan College suffered a data breach in 2021 affecting 99,097 New Yorkers. The New York Attorney General found that MMC failed to secure its network infrastructure and update security policies. As part of the agreement, MMC must invest $3.5 million over six years to improve data encryption, enable multi-factor authentication, and implement other security measures.

LowSecurity FailureData BreachStudent Data
FTCConsent Decree

1Health.io(1Health)

The FTC finalized an order against 1Health.io for failing to secure genetic data and unfairly changing its privacy policy. The company must pay $75,000 for consumer refunds, destroy DNA samples, and implement security measures. It deceived consumers about data deletion and shared data without proper consent.

LowSecurity FailureOpt-Out FailureNotice Failure

$75K

CTInvestigationMultistate

Hyundai and Kia(Hyundai, Kia)

Connecticut Attorney General William Tong launched a consumer protection investigation into Hyundai and Kia for failing to equip vehicles with standard anti-theft immobilizers between 2011 and 2022, leading to high theft rates and public safety concerns. The investigation seeks records on the companies' decision-making and potential fixes, following a coalition of attorneys general calling for a federal recall.

LowSecurity Failure
FTCSettlement

1Health.io

The FTC settled with genetic testing company 1Health.io for failing to secure sensitive genetic and health data, deceiving consumers about data deletion, and unfairly changing its privacy policy without notice or consent. The settlement includes refunds totaling over $49,500 to 2,432 affected consumers.

LowSecurity FailureOpt-Out FailureNotice Failure

$50K

FTCAdministrative Order

Meta

The FTC proposed modifications to its 2020 privacy order with Meta, alleging violations including non-compliance with the order, misleading parents about Messenger Kids, and unauthorized data sharing. The proposed changes include banning monetization of youth data, pausing new product launches, and strengthening privacy requirements.

LowChildren's DataConsent FailureNotice Failure
FTCSettlement

Ring

The FTC settled with Ring for failing to secure consumer videos, allowing unauthorized access by employees and hackers. Ring agreed to provide $5.6 million in refunds to affected customers and implement security measures.

LowData BreachUnauthorized Data SharingConsent Failure

$5.6M

FTCConsent Decree

Chegg Inc.(Chegg)

The FTC finalized an order against Chegg Inc. for failing to secure student data, leading to breaches that exposed personal information of about 40 million users and employees. Chegg must implement a comprehensive security program, limit data collection, offer multifactor authentication, and allow data access and deletion.

LowSecurity FailureStudent DataHealth Data
FTCConsent Decree

Drizly

The FTC finalized an order against Drizly and its CEO for security failures that led to a data breach exposing 2.5 million consumers' personal information. Drizly failed to implement basic security measures despite prior alerts. The order requires Drizly to destroy unnecessary data, implement a security program, and publicly detail data collection practices.

LowSecurity FailureData Breach
CTInvestigationMultistate

T-Mobile

In March 2022, Connecticut Attorney General William Tong announced that Connecticut is co-leading a multistate investigation into T-Mobile's 2021 data breach, which affected over 53 million individuals. The breach compromised sensitive data including names, dates of birth, Social Security Numbers, and driver's license information. Tong urged affected consumers to take protective steps such as credit monitoring and freezes.

LowData BreachSecurity Failure
FTCSettlement

CafePress

The FTC settled with CafePress for failing to implement reasonable data security measures, leading to multiple breaches that exposed Social Security numbers and other sensitive data. As part of the settlement, over $370,000 in refunds are being distributed to 20,044 consumers who filed valid claims.

LowSecurity FailureData BreachBreach Notification Delay

$370K

CTEnforcement ActionMultistate

The Office of the Attorney General William Tong

Connecticut Attorney General William Tong joined a bipartisan coalition of 51 attorneys general in urging the FCC to require gateway providers to implement STIR/SHAKEN caller ID authentication and take additional measures to block foreign-based illegal robocalls that scam Americans.

LowSecurity Failure
FTCSettlement

Ascension Data & Analytics, LLC(Ascension Data & Analytics)

The FTC settled with Ascension Data & Analytics, LLC for violating the Gramm-Leach-Bliley Act's Safeguards Rule by failing to ensure its vendor properly protected consumer data. The company must strengthen its security safeguards and increase oversight of vendors. No monetary penalty was imposed.

LowSecurity Failure
FTCConsent Decree

Support King, LLC(Support King)

The FTC banned Support King, LLC (SpyFone) and its CEO from the surveillance business for secretly harvesting and sharing users' data without consent, and ordered the deletion of all illegally collected data and notification to affected device owners. The company failed to secure the data, leading to a hack that exposed 2,200 consumers.

LowNotice FailureUnauthorized Data SharingConsent Failure
FTCSettlement

SkyMed International, Inc.(SkyMed)

The FTC finalized a settlement with SkyMed International, Inc., an emergency travel services provider, for failing to secure sensitive consumer data and deceiving consumers about HIPAA compliance. The company left a cloud database with 130,000 membership records unsecured, containing personal and health information. Under the settlement, SkyMed must notify affected consumers, implement a security program, undergo biennial assessments, and is prohibited from misrepresenting its data practices.

LowSecurity FailureNotice Failure
FTCSettlement

Zoom Video Communications, Inc.(Zoom)

The FTC finalized a settlement with Zoom Video Communications, Inc. for misleading consumers about its data security practices and compromising user security. The settlement requires Zoom to implement a comprehensive security program, review software updates for security flaws, and undergo biennial third-party assessments.

LowSecurity Failure
FTCConsent Decree

SkyMed International, Inc.(SkyMed International)

SkyMed International, Inc. settled FTC allegations that it failed to secure sensitive consumer data, including health information, leaving a cloud database with 130,000 records exposed to the public. The FTC also alleged that SkyMed misrepresented HIPAA compliance on its website. As part of the settlement, SkyMed must implement a comprehensive security program, undergo biennial third-party assessments, and send notices to affected consumers.

LowSecurity Failure
FTCSettlement

Ascension Data & Analytics, LLC(Ascension Data & Analytics)

Ascension Data & Analytics, LLC, a mortgage analytics company, settled FTC allegations that it violated the Gramm-Leach-Bliley Act's Safeguards Rule by failing to ensure its vendor adequately protected consumer data. The vendor stored sensitive mortgage information in plain text on a cloud server, leading to unauthorized access. Ascension must implement a data security program, undergo biennial assessments, and report future breaches.

LowSecurity Failure
FTCSettlement

Zoom Video Communications, Inc.(Zoom)

The FTC settled with Zoom for deceiving users about its encryption security and unfairly installing software that bypassed browser safeguards. Zoom must implement a comprehensive security program, undergo biennial audits, and is banned from making false security claims. No monetary penalty was imposed.

LowSecurity FailureConsent Failure
NJConsent Decree

Lightyear Dealer Technologies(DealerBuilt)

Lightyear Dealer Technologies (DealerBuilt) settled an investigation into a 2016 data breach where a misconfigured file system exposed personal data, including social security numbers and bank information, of thousands of auto dealership customers nationwide. The settlement includes an $80,784 payment (with $20,000 suspended) and mandatory cybersecurity reforms.

LowData BreachSecurity Failure

$49K

NJConsent Decree

Unixiz, Inc.(Unixiz)

Unixiz, Inc. agreed to shut down its i-Dressup teen social website and pay $98,618 in civil penalties to settle allegations that it violated COPPA by collecting personal information from over 2,500 New Jersey children without parental consent and failed to safeguard user data, leading to a 2016 data breach affecting more than 24,000 New Jersey residents.

LowChildren's DataSecurity Failure

$99K

NJSettlement

Equiliv Investments and Ryan Ramminger(Equiliv Investments)

The New Jersey Attorney General and FTC settled with app developer Equiliv Investments and Ryan Ramminger for distributing the Prized app that contained malware to mine cryptocurrency without user consent. The settlement prohibits such activities, requires record-keeping for 20 years, and imposes a $5,200 penalty with an additional $44,800 suspended.

LowSecurity FailureConsent Failure

$5K

CAEnforcement Action

Kaiser Foundation Health Plan, Inc.(Kaiser)

The California Attorney General filed a complaint against Kaiser Foundation Health Plan, Inc. for improperly disposing of patient medical records containing protected health information. The records, including diagnoses and lab results, were found discarded at a recycling facility, violating patient privacy. The action alleges breaches of the California Confidentiality of Medical Information Act.

LowHealth DataSecurity Failure
CAEnforcement Action

Citibank, N.A.(Citibank)

In 2013, the California Attorney General filed a complaint against Citibank, N.A. alleging that the bank failed to implement adequate security measures and did not properly notify customers about a data breach exposing personal and financial information. The complaint asserts violations of California's data breach notification law.

LowSecurity FailureBreach Notification Delay

Explore Enforcement Data