Court Rules

Privacy Enforcement Tracker

1,285 enforcement actions from 14 federal and state jurisdictions. Every event traced back to its official government source.

1,285

Total Actions

14

Jurisdictions

$35.3B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
CTEnforcement Action

C F Division Services, LLC(C F Division Services)

Connecticut Attorney General William Tong and Secretary of State Stephanie Thomas warned businesses about a scam by C F Division Services, LLC, which sends solicitations mimicking government notices for free UCC reports while charging $90. The company's disclaimer is not clear and conspicuous, and the AG has demanded information via letter while investigating the deceptive practices.

LowNotice Failure
FTCSettlement

GoodRx Holdings Inc.(GoodRx)

The FTC settled with GoodRx for sharing consumers' sensitive prescription and health information with Facebook, Google, and other third parties for advertising without consent, and for failing to report these unauthorized disclosures as required by the Health Breach Notification Rule. GoodRx will pay a $1.5 million civil penalty and is permanently barred from sharing user health data for advertising.

HighConsent FailureHealth DataNotice Failure

$1.5M

FTCConsent Decree

Chegg Inc.(Chegg)

The FTC finalized an order against Chegg Inc. for failing to secure student data, leading to breaches that exposed personal information of about 40 million users and employees. Chegg must implement a comprehensive security program, limit data collection, offer multifactor authentication, and allow data access and deletion.

LowSecurity FailureStudent DataHealth Data
FTCConsent Decree

Drizly

The FTC finalized an order against Drizly and its CEO for security failures that led to a data breach exposing 2.5 million consumers' personal information. Drizly failed to implement basic security measures despite prior alerts. The order requires Drizly to destroy unnecessary data, implement a security program, and publicly detail data collection practices.

LowSecurity FailureData Breach
FTCSettlement

Epic Games, Inc.(Epic Games)

Epic Games, maker of Fortnite, violated children's privacy laws by collecting data from under-13 users without parental consent and used deceptive designs to trick users into unintended purchases. The FTC secured a $275 million civil penalty and $245 million in consumer refunds, with requirements to enhance privacy defaults, delete improperly collected data, implement a privacy program, and prohibit dark patterns and account locking for charge disputes.

CriticalChildren's DataDark Patterns

$275.0M

CTCoalitionMultistate

Airlines(Airline Industry)

Attorney General William Tong led a bipartisan coalition of 41 attorneys general in urging the U.S. Department of Transportation to strengthen consumer protections for airline passengers, criticizing a proposed rule as insufficient. The coalition called for mandatory refunds for cancellations, compensation for delays, and prohibitions on practices like upselling after cancellations, amid over 260 complaints received by Connecticut AG's office.

Low
CTInvestigation

Altice Optimum

Connecticut Attorney General William Tong announced an investigation into Altice Optimum based on nearly 500 consumer complaints regarding slow internet speeds, hidden fees, and poor customer service. The investigation, launched under the Connecticut Unfair Trade Practices Act, seeks records dating back to January 2017 to determine potential violations. This follows a prior $60 million settlement with Frontier Communications for similar consumer protection issues.

Low
FTCAdministrative Order

Financial institutions covered by the Safeguards Rule(Financial Institutions)

The FTC extended the compliance deadline for certain provisions of the Safeguards Rule by six months to June 9, 2023, due to challenges like shortage of qualified personnel and supply chain issues exacerbated by the COVID-19 pandemic. The rule requires non-banking financial institutions to implement enhanced data security measures, and the extension aims to facilitate compliance, especially for small entities.

Low
NJSettlementMultistate

Google

Google settled with 40 state attorneys general over allegations that it misled consumers about location tracking practices. Google will pay $391.5 million and must enhance transparency and user controls for location data collection.

CriticalNotice FailureOpt-Out FailureGeolocation Data

$391.5M

CTSettlementMultistate

Google

Connecticut and 39 other states secured a $391.5 million settlement with Google for misleading consumers about location tracking and continuing to collect data after users opted out. The settlement mandates Google to enhance transparency and user controls for location settings, including clear disclosures and user-friendly account controls.

CriticalOpt-Out FailureNotice Failure

$391.5M

NJSettlementMultistate

Experian and T-Mobile

New Jersey Attorney General Matthew J. Platkin announced a multistate settlement with Experian and T-Mobile over a 2015 data breach that compromised personal information of over 15 million consumers. The companies will pay over $16 million to states and agree to improve data security and vendor management practices. New Jersey will receive approximately $500,000 from the settlement.

CriticalData BreachSecurity Failure

$16.0M

CTSettlementMultistate

Experian; T-Mobile

Connecticut, as part of a 40-state coalition, secured multistate settlements totaling over $16 million with Experian and T-Mobile related to data breaches in 2012 and 2015 that exposed consumers' personal information. Experian agreed to pay $12.67 million and implement enhanced data security measures, while T-Mobile agreed to pay $2.43 million and strengthen vendor management. Additionally, Experian Data Corp. paid $1 million to resolve a separate 2012 breach investigation, with all entities required to improve data protection practices.

CriticalData BreachSecurity FailureNotice Failure

$16.0M

CTEnforcement ActionMultistate

Avid Telecom and One Eye LLC(Avid Telecom and One Eye)

The Connecticut Attorney General, on behalf of the national Anti-Robocall Litigation Task Force, filed petitions in Indiana state court to compel Avid Telecom and One Eye LLC to comply with civil investigative demands regarding their alleged involvement in routing illegal robocalls. The task force alleges these providers accepted and routed fraudulent calls, including government imposter scams, and seeks court orders for them to produce documents and call data records.

Low
CTCoalitionMultistate

FCC

Attorney General William Tong of Connecticut led a coalition of 51 attorneys general to urge the FCC to expand anti-robocall protections by requiring all telephone providers to implement STIR/SHAKEN caller ID authentication and other measures to prevent illegal and fraudulent robocalls.

Low
CTCoalitionMultistate

American Airlines

Connecticut Attorney General William Tong joined a multi-state coalition urging Congress to allow state attorneys general to enforce airline consumer protections, citing thousands of complaints about refunds, cancellations, and poor customer service, with airlines often citing federal preemption to avoid state intervention. Examples include American Airlines refusing refunds during the pandemic, highlighting the need for stronger penalties and enforcement.

Low
CTEnforcement Action

Solar Wolf Energy, Inc.(Solar Wolf Energy)

Connecticut Attorney General William Tong and the Department of Consumer Protection announced an enforcement action against Solar Wolf Energy, Inc. for unfair and deceptive sales practices. The company took high-priced deposits from consumers for residential solar projects but failed to complete or even begin the work and did not return deposits. A Superior Court order now blocks Solar Wolf from selling or advertising in Connecticut until it responds to the investigation.

LowConsent Failure
CTCoalitionMultistate

Motor Vehicle Dealers

Attorney General William Tong joined a coalition of 18 attorneys general to urge the FTC to strengthen the Motor Vehicle Dealers Trade Regulation Rule. The coalition supports proposed updates that prohibit misrepresentations, require accurate pricing disclosures, and obtain informed consent for add-ons, while suggesting enhancements like written disclosures and record retention to prevent consumer harm in car sales.

LowNotice FailureConsent Failure
FTCEnforcement Action

Experian

The FTC and CFPB filed an amicus brief with the Third Circuit Court of Appeals to overturn a lower court ruling that exempted furnishers from investigating indirect disputes under the FCRA. The brief argues that all disputes must be investigated to ensure consumers can correct inaccurate credit information and be notified of outcomes, upholding key FCRA protections.

LowNotice Failure
CTSettlementMultistate

JUUL Labs(JUUL)

Connecticut Attorney General William Tong led 34 states and territories in a $438.5 million settlement with JUUL Labs over its youth-targeted marketing and misleading practices. The settlement includes strict injunctive terms prohibiting youth marketing, certain flavors, and requiring age verification. Funds will support tobacco cessation programs.

CriticalDark PatternsChildren's DataNotice Failure

$438.5M

CTSettlement

Frontier Communications(Frontier)

Connecticut Attorney General settled with Frontier Communications over deceptive marketing, hidden fees, and poor service. The $60 million settlement requires Frontier to invest $42.5 million in fiber upgrades for 40,000 households in distressed areas, end a $6.99 monthly surcharge, pay $1 million to the state, and provide $200,000 in consumer refunds. Frontier must also improve customer service, billing disclosures, and service quality guarantees over six years.

MediumNotice FailureConsent Failure

$1.0M

CASettlement

Sephora, Inc.(Sephora)

California Attorney General Rob Bonta announced a settlement with Sephora, Inc. for $1.2 million over violations of the California Consumer Privacy Act. Sephora failed to disclose that it sold consumer personal information and did not process opt-out requests via Global Privacy Control. The settlement requires Sephora to pay penalties and implement compliance measures including policy changes and reporting.

HighOpt-Out FailureNotice Failure

$1.2M

CTSettlementMultistate

Endo International plc(Endo)

State attorneys general reached a $450 million settlement with opioid manufacturer Endo International plc as part of its bankruptcy. The settlement resolves allegations of deceptive marketing that downplayed addiction risks and overstated benefits, particularly for Opana ER. Endo must pay $450 million over 10 years, ban opioid marketing forever, and disclose millions of documents.

Critical

$450.0M

CTInvestigationMultistate

Gateway Providers

Connecticut Attorney General William Tong announced the formation of a nationwide Anti-Robocall Litigation Task Force with 50 states to investigate and take legal action against gateway providers responsible for foreign robocall traffic. The task force issued 20 civil investigative demands to these providers as its first action to reduce illegal robocalls and scams.

Low
NJSettlementMultistate

Wawa Inc.(Wawa)

Wawa Inc. agreed to pay $8 million to resolve a multistate investigation into a data breach that compromised approximately 34 million payment cards between April 2019 and December 2019. The breach involved malware that harvested card data from point-of-sale terminals. New Jersey will receive $2.5 million, and Wawa must implement enhanced cybersecurity measures including a comprehensive security program and third-party audits.

HighData BreachSecurity Failure

$8.0M

FTCConsent DecreeMultistate

Harris Jewelry

Harris Jewelry defrauded servicemembers with deceptive marketing, inflated prices, and hidden fees. A multistate settlement requires $34.2 million in refunds and debt relief, stops debt collection, and dissolves the business, affecting over 46,000 servicemembers.

MediumNotice FailureConsent Failure

$1.0M

CTSettlement

Public Power

Connecticut Attorney General and Consumer Counsel announced a $3 million settlement with electric supplier Public Power for failing to publish required 'next cycle rate' information, which denied consumers the opportunity to switch suppliers to avoid rate increases. As part of the settlement, Public Power and its sister companies must permanently exit the Connecticut market, and the funds will be used to pay down unpaid electric bills for hardship customers.

HighNotice Failure

$3.0M

NJConsent Decree

AllCare Pharmacy(AllCare)

The New Jersey Board of Pharmacy temporarily suspended the license of Christina Bekhit, owner of AllCare Pharmacy, after her arrest for selling falsified COVID-19 vaccination cards and entering false information into the state's immunization database. Under a consent order filed on July 5, 2022, Bekhit agreed to cease pharmacy operations and surrender her permit, addressing grave public health risks from fraudulent vaccination records.

LowHealth Data
CTSettlementMultistate

Harris Jewelry

Connecticut Attorney General announced a $34 million multistate settlement with Harris Jewelry for deceptive marketing and false promises to servicemembers, tricking them into high-interest loans for overpriced jewelry, with refunds and debt relief for affected consumers.

CriticalDark Patterns

$34.0M

CTCoalitionMultistate

Malicious actors marketing illicit copycat THC edibles(Illicit THC Edible Sellers)

Attorney General William Tong joined a bipartisan coalition of attorneys general to urge Congress to enact legislation allowing trademark holders to hold accountable sellers of unregulated cannabis copycat products that resemble popular snacks and cause accidental THC ingestion in children. The coalition highlighted the public health risk and called for federal action to stop the spread of these dangerous products.

Low
FTCConsent Decree

CafePress

The FTC finalized an order against CafePress for failing to secure consumer data and covering up a data breach. The company must implement comprehensive security measures, and its former owner must pay $500,000 in redress to victims.

MediumSecurity FailureData BreachBreach Notification Delay

$500K

Explore Enforcement Data