Court Rules

Privacy Enforcement Tracker

1,285 enforcement actions from 14 federal and state jurisdictions. Every event traced back to its official government source.

1,285

Total Actions

14

Jurisdictions

$35.3B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
FTCSettlement

NTT Global Data Centers Americas, Inc.(NTT Global Data Centers Americas)

The FTC settled with NTT Global Data Centers Americas, Inc. for deceiving consumers about its participation in the EU-U.S. Privacy Shield framework. The company's certification lapsed in 2018, but it continued to claim compliance in its privacy policy and marketing materials. Under the settlement, NTT is prohibited from misrepresenting its participation in any privacy program and must apply Privacy Shield protections to previously collected personal data or delete it.

LowNotice Failure
FTCEnforcement Action

MyLife.com, Inc.(MyLife.com)

The FTC filed a complaint against MyLife.com, Inc. and its CEO for deceiving consumers with 'teaser background reports' that falsely claimed to include criminal and arrest records, and for violating the Fair Credit Reporting Act by failing to ensure accuracy and permissible purpose. The company also engaged in misleading billing practices under the Restore Online Shoppers’ Confidence Act and Telemarketing Sales Rule.

LowUnauthorized Data Sharing
FTCSettlement

Ortho-Clinical Diagnostics, Inc.(Ortho-Clinical Diagnostics)

The FTC settled with Ortho-Clinical Diagnostics, Inc. for misleading consumers about its participation in the EU-U.S. Privacy Shield framework. The company allowed its certification to lapse in 2018 but continued to claim participation. The settlement prohibits such misrepresentations and requires compliance with Privacy Shield obligations for data collected or deletion of such data.

LowNotice Failure
FTCSettlement

Miniclip, S.A.(Miniclip)

The FTC finalized a settlement with Miniclip, S.A. for falsely claiming it was a member of the CARU COPPA safe harbor program. Miniclip is prohibited from misrepresenting its participation in privacy programs and subject to compliance and recordkeeping requirements.

LowChildren's Data
FTCConsent Decree

NTT Global Data Centers, Inc.(NTT Global Data Centers)

NTT Global Data Centers settled FTC allegations that it misled consumers about its participation in the EU-U.S. Privacy Shield framework and failed to comply with its requirements. The settlement requires the company to hire a third-party assessor if it re-certifies, prohibits misrepresentations about privacy programs, and mandates continued application of Privacy Shield protections or deletion of data collected while participating.

LowNotice Failure
NJConsent Decree

Lightyear Dealer Technologies(DealerBuilt)

Lightyear Dealer Technologies (DealerBuilt) settled an investigation into a 2016 data breach where a misconfigured file system exposed personal data, including social security numbers and bank information, of thousands of auto dealership customers nationwide. The settlement includes an $80,784 payment (with $20,000 suspended) and mandatory cybersecurity reforms.

LowData BreachSecurity Failure

$49K

NJConsent Decree

Unixiz, Inc.(Unixiz)

Unixiz, Inc. agreed to shut down its i-Dressup teen social website and pay $98,618 in civil penalties to settle allegations that it violated COPPA by collecting personal information from over 2,500 New Jersey children without parental consent and failed to safeguard user data, leading to a 2016 data breach affecting more than 24,000 New Jersey residents.

LowChildren's DataSecurity Failure

$99K

NJSettlement

DealerApp

The New Jersey Division of Consumer Affairs settled with DealerApp, a mobile app developer for auto dealerships, for allegedly collecting and transmitting consumer personal information without notice or consent. DealerApp agreed to pay a $38,000 civil penalty and implement measures to disclose data practices and obtain consent for third-party sharing.

LowNotice FailureUnauthorized Data Sharing

$38K

NJSettlement

Equiliv Investments and Ryan Ramminger(Equiliv Investments)

The New Jersey Attorney General and FTC settled with app developer Equiliv Investments and Ryan Ramminger for distributing the Prized app that contained malware to mine cryptocurrency without user consent. The settlement prohibits such activities, requires record-keeping for 20 years, and imposes a $5,200 penalty with an additional $44,800 suspended.

LowSecurity FailureConsent Failure

$5K

NJConsent Decree

Jeremy Rubin

The New Jersey Division of Consumer Affairs obtained a consent decree against Jeremy Rubin, developer of Tidbit Bitcoin-mining software, for accessing New Jersey computers without users' knowledge or consent. The settlement includes a suspended $25,000 monetary penalty and prohibits future unauthorized access, requiring clear notification and verifiable consent.

LowNotice FailureConsent Failure

$25K

CAEnforcement Action

Kaiser Foundation Health Plan, Inc.(Kaiser)

The California Attorney General filed a complaint against Kaiser Foundation Health Plan, Inc. for improperly disposing of patient medical records containing protected health information. The records, including diagnoses and lab results, were found discarded at a recycling facility, violating patient privacy. The action alleges breaches of the California Confidentiality of Medical Information Act.

LowHealth DataSecurity Failure
NJSettlement

Dokogeo

The New Jersey Attorney General settled with Dokogeo, the developer of the Dokobots app, for violating COPPA by collecting personal information from children without parental consent. The settlement requires Dokogeo to disclose its data practices, stop collecting children's data, delete existing children's data, and pay a suspended $25,000 penalty.

LowChildren's DataConsent FailureNotice Failure

$25K

CAEnforcement Action

Citibank, N.A.(Citibank)

In 2013, the California Attorney General filed a complaint against Citibank, N.A. alleging that the bank failed to implement adequate security measures and did not properly notify customers about a data breach exposing personal and financial information. The complaint asserts violations of California's data breach notification law.

LowSecurity FailureBreach Notification Delay

Explore Enforcement Data