1,634 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.
1,634
Total Actions
16
Jurisdictions
$49.9B+
Total Fines Tracked
The FTC rescinded its 2021 Policy Statement on Breaches by Health Apps and Other Connected Devices, which had purported to apply the Health Breach Notification Rule to health apps and connected devices that collect consumer health information. The rescission follows the Commission's 2024 update to the Health Breach Notification Rule, which already covers health apps and connected devices like fitness trackers, and implements an executive order directing agencies to eliminate obsolete guidance documents. No company was charged or penalized; this is a deregulatory action.
Minnesota Attorney General Keith Ellison filed a lawsuit in Hennepin County against C4D, LLC, its owners Travis Benoit and Steven Legatt, and related entity Five Points Properties, LLC, alleging 18 counts of violating the Minnesota Human Rights Act, federal lending laws, and state consumer-fraud and contract-for-deed laws. The complaint alleges the defendants sold homes through predatory contracts for deed with inflated prices, hidden finance charges, and large annual balloon payments that leave buyers immediately underwater and forfeit all equity upon default, while targeting Somali-American Muslims on the basis of religion and national origin — a form of 'reverse redlining.' The AG seeks an injunction, civil penalties, and cancellation or reformation of existing contracts; no penalty amounts have been determined.
Connecticut Attorney General William Tong announced a civil investigative demand into MediaLab.AI Inc., owner of the Kik Messenger app, over lax age assurance practices, content moderation, and child safety failures that advocates have dubbed a "predator's paradise." The action follows a July 2025 notice of violation under the Connecticut Data Privacy Act for privacy notice deficiencies and processing sensitive data — including health, biometric, and precise geolocation data — without proper consent, which the company has only partially addressed. The new investigation seeks records related to practices that may constitute unfair or deceptive acts or practices under the CTDPA and the Connecticut Unfair Trade Practices Act. No fine has been imposed to date.
Oregon Attorney General Dan Rayfield, leading a bipartisan coalition of 48 other state and territorial attorneys general, sent a letter urging the FCC to strengthen its 'Know Your Upstream Provider' (KYUP) rule so phone companies must properly vet, continuously monitor, and cut ties with upstream providers that facilitate illegal robocalls and caller ID spoofing. The coalition asks the FCC to set minimum vetting standards, require periodic re-checks rather than one-time contract reviews, strengthen caller ID authentication across the call chain, impose meaningful penalties, and mandate record-keeping for investigators. No fine or injunction was imposed; the letter notes Americans received more than 29.6 billion scam robocalls and texts last year and lost nearly $2 billion to these scams.
The FTC announced a seven-day extension of the public comment period on its proposed enforcement policy statement regarding personalized pricing, pushing the deadline from Sept. 18, 2026 to Sept. 25, 2026. Personalized pricing refers to using personal data to set prices based on what the company believes an individual consumer is willing to spend. This is a procedural announcement about draft agency guidance, not an enforcement action against any company, and no entity was named, no violation found, and no penalty imposed.
CalPrivacy (the California Privacy Protection Agency) issued Enforcement Advisory 2026-01 warning data brokers that providing incorrect information in their annual registration with California's data broker registry carries liability of a $200 fine per day. The advisory observes that the Enforcement Division has already brought multiple enforcement actions over reporting errors, and emphasizes that accurate registry disclosures are what make the newly launched Delete Request and Opt-Out Platform (DROP) work for Californians. No specific company was named and no penalty was imposed by the advisory itself; it functions as forward-looking guidance.
Attorney General William Tong issued a consumer alert warning Connecticut residents about unregulated, offshore decentralized finance (DeFi) cryptocurrency exchanges, naming GMX, Gains Network, dYdX, Aevo, Drift Protocol, Vertex Protocol, and Hyperliquid. The alert highlights risks including bypassing U.S. law via VPNs, predatory leverage up to 250x, misleading synthetic asset products, and lack of KYC protections. No enforcement action or penalty was imposed; at least one Connecticut consumer reportedly lost $200,000 deposited with an unregulated DeFi exchange.
Minnesota Attorney General Keith Ellison announced the first round of restitution, issuing 8 refund checks totaling $38,634 to consumers harmed by Omega Dental Care, a defunct Eden Prairie dental clinic owned and operated by Anne Soberay. The refunds, paid from the state's Consumer Protection Restitution Account (CPRA), compensate consumers who paid out of pocket for dental services that were never provided. The refunds follow an earlier settlement between the AG's office and Omega Dental Care and Soberay. Note: this is a consumer protection (non-delivery of services) action, not a privacy enforcement action; no privacy violation types from the taxonomy apply.
New York Attorney General Letitia James issued a consumer alert (not an enforcement action) warning New Yorkers about scammers exploiting confusion from recent federal changes to student loan repayment programs, including the elimination of the SAVE plan and phase-out of income-driven repayment plans. The alert describes common scam tactics — upfront fees, false guarantees of loan forgiveness, manufactured urgency, demands for powers of attorney, and requests for federal student aid (FSA) credentials — and urges consumers to report scams to the OAG. No company was named, no violation was alleged against a specific entity, and no penalty was imposed.
New York Attorney General Letitia James issued a consumer alert warning borrowers about scammers exploiting recent federal changes to student loan repayment programs, including the elimination of the SAVE plan and phase-out of income-based plans. The alert provides tips for borrowers, including refusing upfront fees, never granting powers of attorney to unknown parties, and never sharing Federal Student Aid login credentials. No specific company was named and no penalties or remedies were imposed; this is an advisory alert, not an enforcement action.
The California Privacy Protection Agency Board issued a Decision and Final Stipulated Order requiring Virginia-based data broker SalesIntel Research, Inc. to pay a $36,400 fine for operating as a data broker without registering by the 2025 deadline under the Delete Act. SalesIntel sells consumer personal information, including more than 200 million professional contacts and de-anonymized website traffic data, for targeted advertising. In addition to the fine, the company must post privacy rights metrics on its website, integrate with CalPrivacy's Delete Request and Opt-out Platform (DROP), and process future deletion requests through that system.
$36K
Texas Attorney General Ken Paxton opened an investigation into TriWest Healthcare Alliance Corp., the U.S. government contractor that administers the VA Community Care Network and the Defense Health Agency's TRICARE West Region, over reports that it wrongfully denied health care claims by falsely treating insureds as having other health insurance (OHI). The OAG has issued Civil Investigative Demands (CIDs) and plans to interview consumers and employees to determine whether TriWest violated the Texas Deceptive Trade Practices Act. No findings or penalties have been imposed yet.
The Minnesota Attorney General entered into a 10-year oversight agreement with Sanford Health and North Memorial Health to allow their merger to proceed, conditioned on commitments to invest $600 million in Minnesota hospitals, maintain core services including the Level 1 trauma center at Robbinsdale Hospital, honor collective-bargaining agreements, and maintain charity care and government program participation. The agreement also requires quarterly meetings and annual reporting to the Attorney General for 10 years.
The California Privacy Protection Agency announced that the California State Legislature approved the Expanding Privacy Rights Act (SB 923), which expands the CCPA's right to delete to cover all non-exempt personal information a business holds about a consumer, including data originally collected from third parties. The bill also requires online-only businesses with a direct relationship to consumers to provide online methods, such as webforms, for submitting access, deletion, and correction requests, and expressly permits businesses to retain suppression lists so deleted information stays deleted. The bill, authored by Senator Becker and sponsored by CalPrivacy, now goes to the Governor for consideration.
Attorney General Weiser joined a coalition of attorneys general in suing to block new unlawful conditions on Title X funding imposed by HHS, which would penalize states and providers that refuse to abandon nondiscrimination initiatives or conform to the administration's ideological vision of family planning. The lawsuit argues the conditions conflict with federal law, violate the Administrative Procedure Act, and are unconstitutionally vague.
The California Privacy Protection Agency announced that more than 500,000 Californians have registered for the Delete Request and Opt-out Platform (DROP) since its January 1, 2026 launch. After the August 1, 2026 deadline for brokers to begin processing requests, 654 data brokers are in the system and approximately 25% have reported processing deletion requests, with tens of millions of records already deleted. No enforcement action has been announced yet; the agency warned that brokers who fail to delete eligible personal information face significant fines.
Attorney General William Tong sent a letter to the Connecticut Insurance Department urging rejection of double-digit rate increases sought by Anthem, ConnectiCare, and UnitedHealthcare for individual and small group health insurance plans covering about 220,000 people. The letter argues the rates exceed inflationary measures and criticizes the carriers for failing to control costs and for poor claims system management, particularly ConnectiCare's transition to Molina Healthcare.
Attorney General Jay Jones and a coalition of 21 attorneys general obtained a temporary restraining order blocking the Trump administration from demanding a database of state-owned records containing sensitive personal information of 17 million commercial drivers from AAMVA. The lawsuits allege the federal agencies violated federal privacy laws and the Administrative Procedure Act by seeking to acquire the data without guardrails or public notice.
Texas Attorney General Ken Paxton launched an industry-wide investigation into companies marketing avocado oil products that may contain undisclosed seed oils. Civil Investigative Demands were issued to Primal Kitchen, Siete Foods, and Chosen Foods, with more companies expected to be investigated for potential violations of the Texas Deceptive Trade Practices Act.
New York Attorney General Letitia James and a coalition of 22 attorneys general plus Pennsylvania secured a temporary restraining order blocking the Trump administration from seizing the names, dates of birth, and Social Security numbers of 17 million commercial drivers nationwide, including nearly 500,000 New Yorkers. The U.S. District Court for the Eastern District of Virginia granted the TRO, preventing the federal government from accessing the data or cutting off access to the critical database.
The FTC announced it is seeking public comment on a proposed enforcement policy statement regarding personalized pricing, which is the use of personal data to set prices based on what a company believes an individual consumer is willing to spend. The statement warns that undisclosed collection or use of personal data for personalized pricing could violate the FTC Act's prohibition on unfair or deceptive practices. The Commission voted 2-0 to authorize the Federal Register notice.
Attorney General Ken Paxton secured settlements with WK Kellogg Co. and General Mills Inc. requiring the removal of synthetic dyes from cereals served in schools. The companies have already removed these dyes from K-12 cereals, with full removal from all products by the end of 2027.
A bipartisan coalition of 33 state attorneys general, led by Minnesota AG Keith Ellison, began trial against Meta Platforms, Inc., alleging the company knowingly designed and deployed harmful features on Facebook and Instagram that drive children and teens to use the platforms compulsively, while falsely assuring parents and the public that its platforms were safe for young users. The states also allege Meta illegally collected personal information from children under 13 without parental consent, violating COPPA. The trial opened before Judge Yvonne Gonzalez Rogers in the U.S. District Court for the Northern District of California, with the states seeking monetary penalties and injunctive relief.
A bipartisan coalition of state attorneys general led by New Jersey, California, Colorado, and Kentucky is taking Meta Platforms, Inc. to trial, alleging that Meta designed addictive features on Instagram and Facebook that harm minors' mental health, illegally collected data from children under 13 without the required protections under COPPA, and misled users about platform safety. Opening arguments begin August 18, 2026, in the U.S. District Court for the Northern District of California. No monetary penalty or final remedy has yet been imposed.
Minnesota Attorney General Keith Ellison filed an opposition to X.AI's motion for a preliminary injunction seeking to block enforcement of Minnesota's anti-nudification law, which bans commercial platforms from allowing users to generate synthetic intimate images of real people. The court previously denied X.AI's motion for a temporary restraining order, and the law took effect August 1, 2026. The AG argues X.AI cannot show irreparable harm and is unlikely to prevail on the merits of its First Amendment claims.
New York Attorney General Letitia James issued a statement marking the first day of trial in a multistate lawsuit against Meta, alleging the company knowingly designed addictive features on Facebook and Instagram that harm children's mental health. The coalition alleges Meta illegally collected personal information from children under 13 without parental consent, violating COPPA, and seeks monetary penalties, restitution, and an injunction against deceptive practices.
The New York Attorney General issued a consumer advisory warning New Yorkers about fraudulent charities and scams related to earthquake relief efforts in Colombia. The advisory provides tips for verifying charities, avoiding phishing, and reporting suspicious organizations.
New York Attorney General Letitia James and a coalition of 21 other attorneys general and Pennsylvania sued the U.S. Department of Transportation and Department of Homeland Security to block the federal government from seizing the personal data of 17 million commercial drivers from the CDLIS database. The coalition argues the demands violate federal privacy laws and the Constitution, and seeks an injunction to prevent the data transfer.
New York Attorney General Letitia James and the NY Department of Financial Services secured commitments from Western Union to maintain its physical locations and cap fee increases for three years after acquiring Intermex, ensuring continued access to remittance services for New Yorkers. The agreement requires Western Union to maintain at least the same physical presence in ZIP codes where Intermex locations operate, offer retail remittance services to six countries, and limit price increases to inflation, with reporting and audit requirements.
Attorney General Phil Weiser joined a coalition of 22 attorneys general and Pennsylvania in filing two lawsuits against the Trump administration for demanding a database of state-owned records containing sensitive personal information of 17 million commercial drivers. The lawsuits allege violations of federal privacy laws and the Administrative Procedure Act, and seek an emergency order to prevent the data from being turned over by the August 17 deadline.
All data sourced from official government enforcement pages.