Court Rules

Privacy Enforcement Tracker

1,634 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,634

Total Actions

16

Jurisdictions

$49.9B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
CASettlement

Kaiser Foundation Health Plan, Inc., and Kaiser Foundation Hospitals

California Attorney General Rob Bonta, alongside six county district attorneys, announced a $49 million settlement with Kaiser Foundation Health Plan, Inc. and Kaiser Foundation Hospitals resolving allegations of unlawful disposal of hazardous waste, medical waste, and protected patient health information. Investigations of 16 Kaiser facilities found hundreds of hazardous and medical waste items and over 10,000 paper records containing data of more than 7,700 patients in unsecured dumpsters. The settlement requires Kaiser to pay up to $49 million in penalties and compliance costs, retain an independent auditor for five years of regular audits, and implement enhanced waste and data disposal procedures.

CriticalHealth DataData Breach

$49.0M

CASettlement

Kaiser Foundation Health Plan, Inc. and Kaiser Foundation Hospitals (collectively Kaiser)

California Attorney General Rob Bonta, alongside six county district attorneys, announced a $49 million settlement with Kaiser Foundation Health Plan, Inc. and Kaiser Foundation Hospitals resolving allegations of unlawful disposal of hazardous waste, medical waste, and protected health information at Kaiser’s California facilities. Undercover inspections of 16 Kaiser facilities found hundreds of hazardous and medical waste items, plus over 10,000 paper records containing personal information of more than 7,700 patients in unsecured, publicly accessible dumpsters. The settlement requires Kaiser to pay $49 million total, implement enhanced compliance measures, and retain an independent auditor for five years to conduct regular waste and programmatic compliance audits.

CriticalHealth DataSecurity FailureData Breach

$49.0M

CTSettlementMultistate

JUUL Labs(JUUL)

Connecticut led a multistate settlement with JUUL Labs for $438.5 million over allegations of marketing vaping products to underage youth. The settlement funds are being directed to Regional Behavioral Health Action Organizations through new legislation to combat youth vaping, with requirements for transparency and evidence-based programs.

CriticalChildren's Data

$438.5M

FTCConsent Decree

Amazon.com, Inc.(Amazon)

The FTC and DOJ charged Amazon with violating COPPA by indefinitely retaining children's Alexa voice recordings and failing to honor parents' deletion requests. Under a proposed consent decree, Amazon must pay $25 million, delete children's data, and implement privacy safeguards.

CriticalChildren's Data

$25.0M

FTCSettlement

Epic Games, Inc.(Epic Games)

Epic Games, maker of Fortnite, violated children's privacy laws by collecting data from under-13 users without parental consent and used deceptive designs to trick users into unintended purchases. The FTC secured a $275 million civil penalty and $245 million in consumer refunds, with requirements to enhance privacy defaults, delete improperly collected data, implement a privacy program, and prohibit dark patterns and account locking for charge disputes.

CriticalChildren's DataDark Patterns

$275.0M

NJSettlementMultistate

Google

Google settled with 40 state attorneys general over allegations that it misled consumers about location tracking practices. Google will pay $391.5 million and must enhance transparency and user controls for location data collection.

CriticalNotice FailureOpt-Out FailureGeolocation Data

$391.5M

CTSettlementMultistate

Google

Connecticut and 39 other states secured a $391.5 million settlement with Google for misleading consumers about location tracking and continuing to collect data after users opted out. The settlement mandates Google to enhance transparency and user controls for location settings, including clear disclosures and user-friendly account controls.

CriticalOpt-Out FailureNotice Failure

$391.5M

CTSettlementMultistate

Experian; T-Mobile

Connecticut, as part of a 40-state coalition, secured multistate settlements totaling over $16 million with Experian and T-Mobile related to data breaches in 2012 and 2015 that exposed consumers' personal information. Experian agreed to pay $12.67 million and implement enhanced data security measures, while T-Mobile agreed to pay $2.43 million and strengthen vendor management. Additionally, Experian Data Corp. paid $1 million to resolve a separate 2012 breach investigation, with all entities required to improve data protection practices.

CriticalData BreachSecurity FailureNotice Failure

$16.0M

NJSettlementMultistate

Experian and T-Mobile

New Jersey Attorney General Matthew J. Platkin announced a multistate settlement with Experian and T-Mobile over a 2015 data breach that compromised personal information of over 15 million consumers. The companies will pay over $16 million to states and agree to improve data security and vendor management practices. New Jersey will receive approximately $500,000 from the settlement.

CriticalData BreachSecurity Failure

$16.0M

CTSettlementMultistate

JUUL Labs(JUUL)

Connecticut Attorney General William Tong led 34 states and territories in a $438.5 million settlement with JUUL Labs over its youth-targeted marketing and misleading practices. The settlement includes strict injunctive terms prohibiting youth marketing, certain flavors, and requiring age verification. Funds will support tobacco cessation programs.

CriticalDark PatternsChildren's DataNotice Failure

$438.5M

CTSettlementMultistate

Endo International plc(Endo)

State attorneys general reached a $450 million settlement with opioid manufacturer Endo International plc as part of its bankruptcy. The settlement resolves allegations of deceptive marketing that downplayed addiction risks and overstated benefits, particularly for Opana ER. Endo must pay $450 million over 10 years, ban opioid marketing forever, and disclose millions of documents.

Critical

$450.0M

CTSettlementMultistate

Harris Jewelry

Connecticut Attorney General announced a $34 million multistate settlement with Harris Jewelry for deceptive marketing and false promises to servicemembers, tricking them into high-interest loans for overpriced jewelry, with refunds and debt relief for affected consumers.

CriticalDark Patterns

$34.0M

CTSettlementMultistate

Ford Motor Company(Ford)

Ford Motor Company agreed to a $19.2 million multistate settlement for falsely advertising the fuel economy of 2013–2014 C-Max hybrids and the payload capacity of 2011–2014 Super Duty pickup trucks. The settlement requires Ford to cease deceptive advertising practices and pay penalties to participating states.

Critical

$19.2M

CTSettlementMultistate

Intuit Inc.(Intuit)

Connecticut Attorney General William Tong secured $1.2 million in restitution for 40,841 state consumers as part of a multistate $141 million settlement with Intuit Inc., the owner of TurboTax. The settlement resolves allegations that Intuit deceived low-income consumers into paying for tax preparation services that were offered for free through the IRS Free File program by using deceptive marketing tactics and confusing product names. Intuit must pay restitution, suspend its 'free, free, free' ad campaign, and implement business practice reforms.

CriticalNotice FailureDark Patterns

$141.0M

CTSettlementMultistate

Navient

Connecticut Attorney General William Tong announced a $1.85 billion multistate settlement with student loan servicer Navient for unfair and deceptive servicing practices. Navient steered borrowers into costly forbearances and originated predatory loans, resulting in debt relief for over 66,000 borrowers and restitution for 350,000 federal loan borrowers. The settlement includes a $142.5 million payment to attorneys general and conduct reforms to improve servicing practices.

CriticalNotice Failure

$142.5M

FTCSettlementMultistate

MyLife.com, Inc.(MyLife.com)

The FTC and DOJ settled with MyLife.com, Inc. and its CEO for deceiving consumers with misleading background reports that falsely implied criminal records and for engaging in difficult-to-cancel subscription practices. MyLife violated the Fair Credit Reporting Act, Restore Online Shoppers’ Confidence Act, and Telemarketing Sales Rule. The settlement includes a permanent ban on negative option marketing, $33.9 million in judgments for consumer refunds, and a monitoring program.

CriticalNotice FailureData Broker Non-Compliance

$33.9M

FTCSettlement

Vivint Smart Homes, Inc.(Vivint)

The FTC settled with Vivint Smart Homes, Inc. for $20 million over allegations that the company misused consumer credit reports to secure financing for unqualified customers, harming consumers' credit. The FTC is now distributing approximately $500,000 in refunds to affected consumers.

CriticalUnauthorized Data SharingConsent Failure

$20.0M

FTCSettlement

Vivint Smart Home, Inc.(Vivint)

The FTC settled with Vivint Smart Home, Inc. for misusing consumer credit reports to qualify customers for financing without permission, harming innocent third parties' credit. Vivint agreed to pay $20 million, with over $4.7 million for consumer compensation, and established a Customer Service Task Force.

CriticalUnauthorized Data Sharing

$20.0M

NJSettlementMultistate

Retrieval-Masters Creditors Bureau d/b/a American Medical Collection Agency(American Medical Collection Agency)

AMCA suffered an eight-month data breach from August 2018 to March 2019, exposing personal information including Social Security numbers, payment card data, and medical test details of over 7 million individuals nationwide, including 246,000 New Jersey residents. The multistate settlement requires AMCA to implement enhanced data security measures and pay $21 million, though payment is suspended due to the company's financial situation.

CriticalSecurity FailureData BreachHealth Data

$21.0M

FTCConsent Decree

Midwest Recovery Systems(Midwest Recovery)

The FTC settled with Midwest Recovery Systems for engaging in 'debt parking,' where it placed inaccurate debts on consumers' credit reports to force payment. The company collected over $24 million from such debts. The settlement requires it to delete all reported debts, stop the practice, and pay a $24.3 million monetary judgment.

CriticalUnauthorized Data SharingHealth Data

$24.3M

NJSettlementMultistate

Home Depot

Home Depot settled for $17.5 million over a 2014 data breach that compromised personal information of over 40 million consumers due to inadequate security at self-checkout kiosks. The settlement requires extensive cybersecurity reforms including an information security program, employee training, and encryption. New Jersey receives $579,623 from the multi-state settlement.

CriticalData BreachSecurity Failure

$17.5M

NJSettlementMultistate

Anthem, Inc.(Anthem)

New Jersey Attorney General announced a multi-state settlement with Anthem, Inc. over a 2015 data breach that exposed personal information of over 78 million Americans, including 1.15 million New Jersey residents. Anthem will pay $39.5 million to participating states and implement enhanced cybersecurity measures.

CriticalData BreachSecurity Failure

$39.5M

FTCConsent Decree

Facebook, Inc.(Meta)

The FTC charged Facebook with deceiving consumers about its privacy practices and violating a 2012 consent order. In July 2019, Facebook agreed to pay a $5 billion civil penalty and accept comprehensive new privacy restrictions.

CriticalNotice FailureConsent Failure

$5.0B

CASettlementMultistate

Equifax

California Attorney General Xavier Becerra, leading a multistate coalition of all 50 states, the District of Columbia, and Puerto Rico, announced a settlement with Equifax over a 2017 data breach that exposed personal information of 147 million consumers, including 15 million Californians. The breach resulted from Equifax’s failure to apply a critical software patch and implement adequate security measures, with disclosure delayed for months after discovery. Equifax will pay $175 million in state penalties, up to $425 million in consumer restitution, and implement enhanced data security measures and ten years of free credit monitoring for affected consumers.

CriticalData BreachSecurity FailureBreach Notification Delay

$175.0M

NJSettlementMultistate

Uber Technologies, Inc.(Uber)

Uber Technologies, Inc. agreed to pay $148 million to settle a multi-state investigation into a data breach that compromised personal information of riders and drivers. The breach occurred in November 2016 but was not disclosed until November 2017. Uber must adopt new policies to safeguard consumer data.

CriticalData BreachSecurity FailureBreach Notification Delay

$148.0M

CASettlementMultistate

Uber Technologies, Inc.(Uber)

Uber Technologies, Inc. settled for $148 million over a 2016 data breach that exposed 57 million users' personal information. The company was accused of covering up the breach by paying hackers and failing to notify authorities or affected drivers as required by law. The settlement includes a large penalty and mandates robust data security practices, privacy-by-design integration, and regular reporting to prevent future incidents.

CriticalData BreachNotice FailureSecurity Failure

$148.0M

NJInvestigationMultistate

Equifax

New Jersey Attorney General Christopher Porrino announced that New Jersey has joined a multi-state investigation into Equifax following a data breach affecting 143 million consumers. The multi-state group sent a letter demanding Equifax disable fee-based credit monitoring services and reimburse consumers for credit freeze fees with other bureaus, citing unfair practices and a months-long delay in breach disclosure.

CriticalData BreachNotice Failure
CASettlementMultistate

Target

Target settled a multi-state enforcement action for a 2013 data breach that exposed payment card information of over 40 million customers due to inadequate security. The $18.5 million settlement requires Target to implement advanced security measures, and California receives over $1.4 million.

CriticalData BreachSecurity Failure

$18.5M

NJSettlementMultistate

Target Corp.(Target)

Target Corp. agreed to pay $18.5 million to resolve a multi-state investigation into the November 2013 data breach that compromised payment card information of over 41 million shoppers. The settlement requires Target to implement comprehensive cybersecurity reforms, including a dedicated Information Security Program, encryption, network segmentation, and third-party assessments.

CriticalData BreachSecurity Failure

$18.5M

CASettlement

Comcast

Comcast disclosed personal information of approximately 75,000 customers who had paid for unlisted VOIP phone service. The settlement includes a $25 million penalty and $8 million in restitution, along with a permanent injunction requiring improved privacy practices and customer disclosures.

CriticalUnauthorized Data Sharing

$25.0M

Explore Enforcement Data