Court Rules

Privacy Enforcement Tracker

1,634 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,634

Total Actions

16

Jurisdictions

$49.9B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
CTEnforcement Action

Stone Academy

Connecticut Attorney General William Tong expanded the complaint against Stone Academy, alleging its owners siphoned millions for personal luxury while students were denied promised education and clinical training. Revenues surged during the pandemic, but exam pass rates fell and students lacked textbooks and qualified teachers. The AG seeks civil penalties, restitution, and a receiver to protect assets for student relief.

HighNotice Failure
FTCSettlement

TruthFinder; Instant Checkmate

The FTC settled with background report providers TruthFinder and Instant Checkmate, charging they deceived consumers about the accuracy of their reports (often mischaracterizing traffic tickets as criminal records) and violated the Fair Credit Reporting Act (FCRA) by operating as consumer reporting agencies without following its requirements, including ensuring accuracy and limiting permissible purposes. The companies will pay a $5.8 million penalty and implement a comprehensive FCRA compliance monitoring program.

HighNotice FailureConsent FailureData Broker Non-Compliance

$5.8M

FTCConsent Decree

Ring LLC(Ring)

The FTC charged Ring LLC with allowing employees to access private customer videos without consent and failing to secure user accounts, leading to hackers controlling cameras. Under a proposed consent order, Ring must pay $5.8 million in refunds, delete unlawfully accessed data, and implement a privacy and security program.

HighConsent FailureNotice FailureSecurity Failure

$5.8M

FTCSettlement

GoodRx Holdings Inc.(GoodRx)

The FTC settled with GoodRx for sharing consumers' sensitive prescription and health information with Facebook, Google, and other third parties for advertising without consent, and for failing to report these unauthorized disclosures as required by the Health Breach Notification Rule. GoodRx will pay a $1.5 million civil penalty and is permanently barred from sharing user health data for advertising.

HighConsent FailureHealth DataNotice Failure

$1.5M

CASettlement

Sephora, Inc.(Sephora)

California Attorney General Rob Bonta announced a settlement with Sephora, Inc. resolving allegations that the company violated the California Consumer Privacy Act (CCPA) by failing to disclose it was selling consumers' personal information and failing to process opt-out requests via user-enabled Global Privacy Controls. Sephora agreed to pay $1.2 million in penalties and implement injunctive measures including updating privacy disclosures, enabling opt-out via GPC, conforming service provider agreements to CCPA, and reporting to the AG. The settlement is part of ongoing CCPA enforcement efforts, with the AG also issuing cure notices to other businesses failing to honor GPC opt-out signals.

HighOpt-Out FailureNotice Failure

$1.2M

CTSettlement

Public Power

Connecticut Attorney General and Consumer Counsel announced a $3 million settlement with electric supplier Public Power for failing to publish required 'next cycle rate' information, which denied consumers the opportunity to switch suppliers to avoid rate increases. As part of the settlement, Public Power and its sister companies must permanently exit the Connecticut market, and the funds will be used to pay down unpaid electric bills for hardship customers.

HighNotice Failure

$3.0M

CTSettlement

Safe Home Security Inc.(Safe Home Security)

Connecticut Attorney General filed a $5 million stipulation judgment against Safe Home Security for repeated non-compliance with court-ordered consumer protection measures, including blocking contract terminations and misrepresenting terms. The judgment requires immediate payment of $1 million and suspends $4 million pending compliance, with an independent monitor for five years.

HighOpt-Out FailureNotice Failure

$5.0M

CTEnforcement Action

Associated Community Services

The Connecticut Attorney General announced an enforcement action against Associated Community Services for operating a massive telefunding scheme that bombarded 67 million consumers with 1.3 billion deceptive fundraising calls, fraudulently collecting over $110 million. The action resulted in hundreds of millions of dollars in fines and a permanent prohibition from fundraising, forcing the sale of assets purchased with illegal proceeds.

HighNotice Failure
FTCConsent Decree

Kuuhuub Inc.(Kuuhuub)

The FTC settled with Kuuhuub Inc., operator of the Recolor coloring book app, for violating COPPA by collecting personal information from children under 13 without parental consent. The app's social media features allowed children to register and share data, and third-party ad networks collected persistent identifiers for targeted ads. The settlement requires deletion of children's data, refunds to underage subscribers, a $3 million penalty (suspended upon $100,000 payment), and user notifications about the violations.

HighChildren's DataNotice FailureConsent Failure

$3.0M

CASettlementMultistate

Lenovo

Lenovo preinstalled 'Visual Discovery' software on its computers that intercepted browsing data and broke encrypted connections without user consent, compromising security and privacy. The multi-state settlement imposes a $3.5 million penalty and requires Lenovo to implement disclosure, consent, opt-out, and security compliance measures.

HighNotice FailureConsent FailureOpt-Out Failure

$3.5M

NJSettlementMultistate

Lenovo Inc.(Lenovo)

New Jersey joined 31 other states and the FTC in a $3.5 million settlement with Lenovo for pre-installing VisualDiscovery ad software on laptops that created a 'man-in-the-middle' security vulnerability, intercepting users' encrypted data without adequate disclosure or opt-out mechanisms. The settlement requires Lenovo to improve transparency, obtain affirmative consent, provide effective opt-out tools, and implement a long-term security compliance program with independent audits.

HighSecurity FailureUnauthorized Data SharingNotice Failure

$3.5M

CASettlement

Wells Fargo Bank(Wells Fargo)

Wells Fargo Bank recorded consumer phone calls without providing timely notice as required by California law, violating privacy statutes. The settlement imposes a $7.616 million civil penalty, requires compliance with disclosure standards, and mandates an internal compliance program to protect consumer privacy.

HighNotice Failure

$7.6M

Explore Enforcement Data