Court Rules

Privacy Enforcement Tracker

1,285 enforcement actions from 14 federal and state jurisdictions. Every event traced back to its official government source.

1,285

Total Actions

14

Jurisdictions

$35.3B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
CTSettlement

Frontier Communications(Frontier)

Connecticut Attorney General settled with Frontier Communications over deceptive marketing, hidden fees, and poor service. The $60 million settlement requires Frontier to invest $42.5 million in fiber upgrades for 40,000 households in distressed areas, end a $6.99 monthly surcharge, pay $1 million to the state, and provide $200,000 in consumer refunds. Frontier must also improve customer service, billing disclosures, and service quality guarantees over six years.

MediumNotice FailureConsent Failure

$1.0M

FTCConsent DecreeMultistate

Harris Jewelry

Harris Jewelry defrauded servicemembers with deceptive marketing, inflated prices, and hidden fees. A multistate settlement requires $34.2 million in refunds and debt relief, stops debt collection, and dissolves the business, affecting over 46,000 servicemembers.

MediumNotice FailureConsent Failure

$1.0M

FTCConsent Decree

Residual Pumpkin Entity, LLC and PlanetArt, LLC(CafePress)

The FTC took action against CafePress for failing to secure consumer data and covering up a major data breach. The company stored sensitive information insecurely and delayed notifying customers. As part of the settlement, Residual Pumpkin must pay $500,000 in redress, and both companies must implement comprehensive security programs.

MediumData BreachSecurity FailureNotice Failure

$500K

FTCSettlement

Support King, LLC(Support King)

The FTC finalized an order banning Support King, LLC and its CEO from the surveillance business for selling stalkerware apps that secretly collected and shared users' personal data without consent. The order requires them to delete all illegally collected data and notify affected device owners.

LowNotice FailureConsent FailureUnauthorized Data Sharing
CTEnforcement ActionMultistate

companies that agreed to these Principles(Telecom Companies)

Attorney General William Tong released an update on the implementation of the Anti-Robocall Principles signed in 2019. Telecom companies have identified over 52 billion spam calls and blocked 32.5 billion, but robocalls continue to cause significant financial losses. Enforcement actions have increased with thousands of tracebacks and investigations.

LowConsent Failure
FTCConsent Decree

Support King, LLC(Support King)

The FTC banned Support King, LLC (SpyFone) and its CEO from the surveillance business for secretly harvesting and sharing users' data without consent, and ordered the deletion of all illegally collected data and notification to affected device owners. The company failed to secure the data, leading to a hack that exposed 2,200 consumers.

LowNotice FailureUnauthorized Data SharingConsent Failure
CTSettlement

L.A. Vision

Connecticut Attorney General William Tong announced a $678,901 settlement with L.A. Vision and optician Lisa Azinheira for overbilling the state Medicaid program. The providers billed for non-medically necessary vision services and extra eyeglasses for children. In addition to restitution, they must comply with a federal Integrity Agreement requiring audits, training, and compliance measures.

MediumConsent FailureNotice Failure

$679K

CTSettlement

Town Square Energy

Connecticut Attorney General and agencies settled with Town Square Energy for deceptive marketing, including misrepresenting rates and enrolling customers without consent. Town Square must pay $400,000 to Operation Fuel and cease in-person marketing for 15 months.

MediumConsent Failure

$400K

FTCConsent Decree

Kuuhuub Inc.(Kuuhuub)

The FTC settled with Kuuhuub Inc., operator of the Recolor coloring book app, for violating COPPA by collecting personal information from children under 13 without parental consent. The app's social media features allowed children to register and share data, and third-party ad networks collected persistent identifiers for targeted ads. The settlement requires deletion of children's data, refunds to underage subscribers, a $3 million penalty (suspended upon $100,000 payment), and user notifications about the violations.

HighChildren's DataNotice FailureConsent Failure

$3.0M

FTCSettlement

Vivint Smart Homes, Inc.(Vivint)

The FTC settled with Vivint Smart Homes, Inc. for $20 million over allegations that the company misused consumer credit reports to secure financing for unqualified customers, harming consumers' credit. The FTC is now distributing approximately $500,000 in refunds to affected consumers.

CriticalUnauthorized Data SharingConsent Failure

$20.0M

FTCConsent Decree

Everalbum, Inc.(Everalbum)

Everalbum, Inc. settled FTC allegations that it deceived consumers about its use of facial recognition technology in its photo storage app and failed to delete photos when users deactivated their accounts. The settlement requires Everalbum to obtain express consent before using facial recognition, delete user photos and derived face embeddings, and delete developed models and algorithms. It also prohibits misrepresentations about data practices and requires consent for biometric data use if marketing software to consumers.

LowConsent FailureNotice FailureBiometric Data
FTCSettlement

Zoom Video Communications, Inc.(Zoom)

The FTC settled with Zoom for deceiving users about its encryption security and unfairly installing software that bypassed browser safeguards. Zoom must implement a comprehensive security program, undergo biennial audits, and is banned from making false security claims. No monetary penalty was imposed.

LowSecurity FailureConsent Failure
CASettlement

Glow, Inc.(Glow)

California Attorney General settled with Glow, Inc. for $250,000 due to privacy and security failures in its fertility app that risked exposing users' sensitive health information. The settlement requires Glow to implement privacy and security measures, obtain affirmative consent for data sharing, and consider unique impacts on women.

MediumHealth DataSecurity FailureConsent Failure

$250K

FTCConsent Decree

Facebook, Inc.(Meta)

The FTC charged Facebook with deceiving consumers about its privacy practices and violating a 2012 consent order. In July 2019, Facebook agreed to pay a $5 billion civil penalty and accept comprehensive new privacy restrictions.

CriticalNotice FailureConsent Failure

$5.0B

NJSettlement

Meitu, Inc.(Meitu)

Meitu, Inc. allegedly violated COPPA and the New Jersey Consumer Fraud Act by collecting personal information from children under 13 without parental consent. The settlement requires Meitu to pay a $100,000 civil penalty, update its privacy policies, and modify its apps to block data collection from children.

MediumChildren's DataNotice FailureConsent Failure

$100K

CASettlementMultistate

Lenovo

Lenovo preinstalled 'Visual Discovery' software on its computers that intercepted browsing data and broke encrypted connections without user consent, compromising security and privacy. The multi-state settlement imposes a $3.5 million penalty and requires Lenovo to implement disclosure, consent, opt-out, and security compliance measures.

HighNotice FailureConsent FailureOpt-Out Failure

$3.5M

NJSettlementMultistate

VIZIO

VIZIO and Inscape settled allegations that they collected viewing data from Smart TVs without adequate disclosure and consent, selling it to third parties. They agreed to pay $1 million to New Jersey, destroy collected data, and implement privacy measures including obtaining consumer consent and establishing a privacy program.

MediumNotice FailureConsent FailureUnauthorized Data Sharing

$1.0M

CASettlement

Houzz Inc.(Houzz)

The California Attorney General settled with Houzz Inc. for secretly recording incoming and outgoing telephone calls from March to September 2013 without notifying or obtaining consent from all parties, violating state wiretapping and eavesdropping laws. The settlement requires Houzz to pay $175,000, appoint a Chief Privacy Officer, conduct a privacy risk assessment, secure and destroy the recordings, and implement compliance measures.

MediumNotice FailureConsent Failure

$175K

NJSettlement

Equiliv Investments and Ryan Ramminger(Equiliv Investments)

The New Jersey Attorney General and FTC settled with app developer Equiliv Investments and Ryan Ramminger for distributing the Prized app that contained malware to mine cryptocurrency without user consent. The settlement prohibits such activities, requires record-keeping for 20 years, and imposes a $5,200 penalty with an additional $44,800 suspended.

LowSecurity FailureConsent Failure

$5K

NJConsent Decree

Jeremy Rubin

The New Jersey Division of Consumer Affairs obtained a consent decree against Jeremy Rubin, developer of Tidbit Bitcoin-mining software, for accessing New Jersey computers without users' knowledge or consent. The settlement includes a suspended $25,000 monetary penalty and prohibits future unauthorized access, requiring clear notification and verifiable consent.

LowNotice FailureConsent Failure

$25K

CASettlement

Aaron's, Inc.(Aaron's)

The California Attorney General reached a $28.4 million settlement with Aaron's, Inc. for installing spyware on rented computers without customer consent and for violating the Karnette Rental-Purchase Act. The spyware, called 'Detective Mode', allowed remote monitoring of keystrokes, screenshots, location, and webcam activation. Aaron's must refund $25 million to approximately 100,000 customers and pay $3.4 million in penalties, and is prohibited from using spyware.

HighConsent FailureGeolocation Data

$3.4M

NJSettlement

Dokogeo

The New Jersey Attorney General settled with Dokogeo, the developer of the Dokobots app, for violating COPPA by collecting personal information from children without parental consent. The settlement requires Dokogeo to disclose its data practices, stop collecting children's data, delete existing children's data, and pay a suspended $25,000 penalty.

LowChildren's DataConsent FailureNotice Failure

$25K

NJSettlement

Dataium

Dataium settled allegations that it used history sniffing to track consumers' online browsing without consent and sold personal data of 400,000 consumers to a data broker without notice. The settlement imposes a $400,000 monetary penalty, requires a privacy program, and mandates transparency and opt-out mechanisms.

MediumNotice FailureConsent FailureUnauthorized Data Sharing

$400K

NJSettlementMultistate

Google

New Jersey joined a multi-state settlement with Google alleging that Google circumvented Safari browser's default privacy settings to plant third-party cookies without user consent. Google agreed to pay $17 million and implement injunctive relief to prevent such conduct and improve transparency.

CriticalConsent FailureNotice Failure

$17.0M

NJSettlementMultistate

Google

Google settled multi-state allegations that it collected personal data from unsecured wireless networks during Street View operations without user consent. The settlement requires Google to destroy the collected data, refrain from future non-consensual collection, implement a 10-year employee privacy training program, and run a public advertising campaign. New Jersey's share of the settlement is approximately $147,000.

HighConsent Failure

Explore Enforcement Data