Court Rules

Privacy Enforcement Tracker

1,285 enforcement actions from 14 federal and state jurisdictions. Every event traced back to its official government source.

1,285

Total Actions

14

Jurisdictions

$35.3B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
FTCConsent Decree

General Motors LLC, General Motors Holdings LLC, and OnStar LLC(General Motors)

The FTC alleged that General Motors and its OnStar subsidiary collected and sold drivers' precise geolocation and driving behavior data (e.g., hard braking, speeding) to consumer reporting agencies without adequately notifying consumers or obtaining their affirmative consent. A proposed consent order bans the companies from disclosing this sensitive data to consumer reporting agencies for five years and requires them to implement clearer consent mechanisms, data access/deletion processes, and opt-out options.

HighGeolocation DataConsent FailureUnauthorized Data Sharing
TXEnforcement Action

Allstate and Arity(Allstate)

Texas Attorney General Ken Paxton filed a lawsuit against Allstate and its subsidiary Arity for unlawfully collecting, using, and selling driving data from over 45 million consumers without consent. The data, which includes precise geolocation information, was used to justify insurance premium increases. This action alleges violations of the Texas Data Privacy and Security Act (TDPSA).

LowNotice FailureConsent FailureUnauthorized Data Sharing
HHSEnforcement Action

Eastern Idaho Public Health

Eastern Idaho Public Health (Healthcare Provider, ID) reported a HIPAA breach affecting 759 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record.

LowData BreachHealth DataUnauthorized Data Sharing
CTEnforcement ActionMultistate

Greystar Real Estate Partners LLC, Blackstone's LivCor LLC, Camden Property Trust, Cushman & Wakefield Inc, Pinnacle Property Management Services LLC, Willow Bridge Property Company LLC, Cortland Management LLC(Greystar, LivCor, Camden, Cushman & Wakefield, Pinnacle Property Management, Willow Bridge, Cortland)

The U.S. Department of Justice and ten states filed an amended complaint against six major landlords for using algorithmic pricing and sharing competitively sensitive information to suppress competition and raise rents. Cortland Management LLC agreed to a consent decree requiring it to cease these practices, cooperate with the investigation, and submit to court-monitored oversight. The landlords collectively manage over 1.3 million rental units across the United States.

LowSurveillance PricingUnauthorized Data Sharing
HHSEnforcement Action

DentaQuest

DentaQuest (Health Plan, WI) reported a HIPAA breach affecting 868 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Khalil Foundation (DBA Khalil Center)

Khalil Foundation (DBA Khalil Center) (Healthcare Provider, IL) reported a HIPAA breach affecting 1,153 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Network Server.

LowData BreachHealth DataUnauthorized Data Sharing
TXInvestigation

Character.AI, Reddit, Instagram, Discord, and 11 other companies(Character.AI)

Texas Attorney General Ken Paxton announced investigations into 15 companies, including Character.AI, Reddit, Instagram, and Discord, for potential violations of the SCOPE Act and TDPSA concerning children's privacy. The investigations target practices such as unauthorized sharing of minors' personal data and failure to provide parental controls. This action is part of Texas's broader initiative to enforce data privacy laws.

LowChildren's DataConsent FailureNotice Failure
TXInvestigation

Character.AI, Reddit, Instagram, Discord, and 14 other companies

Texas Attorney General Ken Paxton launched investigations into Character.AI and 14 other companies, including Reddit, Instagram, and Discord, over potential violations of children’s privacy and safety laws. The investigations focus on compliance with the SCOPE Act and Texas Data Privacy and Security Act (TDPSA), which require parental consent for sharing minors’ data and mandate notice and consent requirements for children’s personal information. No fines or remedies have been imposed as the investigations are ongoing.

LowChildren's DataConsent FailureNotice Failure
HHSEnforcement Action

El Paso Healthcare System, Ltd. d/b/a Las Palmas Del Sol Healthcare

El Paso Healthcare System, Ltd. d/b/a Las Palmas Del Sol Healthcare (Healthcare Provider, TX) reported a HIPAA breach affecting 1,854 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record.

LowData BreachHealth DataUnauthorized Data Sharing
FTCConsent Decree

Gravy Analytics Inc. and Venntel Inc.(Gravy Analytics)

The FTC took action against Gravy Analytics Inc. and Venntel Inc. for unlawfully tracking and selling sensitive consumer location data without consent. The proposed consent order prohibits the sale or use of sensitive location data, requires deletion of historic data, and mandates compliance programs. This is part of the FTC's series of actions against data brokers selling sensitive location data.

LowConsent FailureUnauthorized Data SharingGeolocation Data
HHSEnforcement Action

Atrium Health

Atrium Health (Healthcare Provider, NC) reported a HIPAA breach affecting 585,959 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Network Server.

HighData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

AuthoraCare Collective

AuthoraCare Collective (Healthcare Provider, NC) reported a HIPAA breach affecting 57,944 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Network Server.

MediumData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Mid-Minnesota Management Services d/b/a Central Resources

Mid-Minnesota Management Services d/b/a Central Resources (Business Associate, IL) reported a HIPAA breach affecting 1,232 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Other.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Huron Inc. Health Plan

Huron Inc. Health Plan (Health Plan, MI) reported a HIPAA breach affecting 750 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Network Server.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Mohawk Valley Cardiology, P.C.

Mohawk Valley Cardiology, P.C. (Healthcare Provider, NY) reported a HIPAA breach affecting 4,973 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Other.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Jacksonville Children's Multispecialty Clinics/Atlantic Medical Management

Jacksonville Children's Multispecialty Clinics/Atlantic Medical Management (Healthcare Provider, NC) reported a HIPAA breach affecting 2,224 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Email.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Ad Valorem Records, Inc.

Ad Valorem Records, Inc. (Business Associate, TN) reported a HIPAA breach affecting 590 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.

LowData BreachHealth DataUnauthorized Data Sharing
TXEnforcement Action

TikTok

Texas Attorney General Ken Paxton filed a lawsuit against TikTok for violating the Securing Children Online through Parental Empowerment (SCOPE) Act by sharing minors’ personal identifying information without parental consent and failing to provide parents with tools to manage their children’s account privacy settings. The lawsuit seeks civil penalties of up to $10,000 per violation and injunctive relief to prevent future violations. TikTok is accused of prioritizing profit over the online safety and privacy of Texas children.

LowChildren's DataConsent FailureUnauthorized Data Sharing
FTCGuidance

Major Social Media and Video Streaming Companies (Amazon, Meta, YouTube, X, Snap, TikTok, Discord, Reddit, WhatsApp)(Major Social Media and Video Streaming Companies)

The FTC staff report examined data practices of nine major social media and video streaming companies and found they engaged in vast surveillance of users with lax privacy controls and inadequate safeguards for children and teens. The report recommends limiting data collection, restricting targeted advertising, and strengthening protections for young users, and calls for comprehensive federal privacy legislation.

LowChildren's DataOpt-Out FailureUnauthorized Data Sharing
CTEnforcement ActionMultistate

RealPage Inc.(RealPage)

Attorney General William Tong, along with the U.S. Department of Justice and eight other state attorneys general, filed a civil antitrust lawsuit against RealPage Inc. for allegedly using its algorithmic pricing software to facilitate price fixing among landlords and monopolize the market for revenue management software. The complaint alleges that RealPage collects competitively sensitive rental data from landlords to train its algorithm, which then recommends prices, harming renters by reducing competition. The lawsuit seeks an injunction to end these practices and restore competition.

LowUnauthorized Data SharingAI/Automated Decisions
HHSEnforcement Action

Contents Trader, Inc.

Contents Trader, Inc. (Healthcare Provider, TX) reported a HIPAA breach affecting 27,329 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Network Server.

MediumData BreachHealth DataUnauthorized Data Sharing
FLInvestigationMultistate

Temu

Florida Attorney General Ashley Moody, joined by 20 other state attorneys general, sent a letter to online retailer Temu and its parent company PDD Holdings demanding answers about data collection, sharing, and retention practices, including potential unauthorized sharing of U.S. consumer data with the Chinese Communist Party. The coalition also raised concerns about possible violations of the Uyghur Forced Labor Prevention Act and inadequate cybersecurity measures. Temu has 30 days to respond to 11 detailed requests for information and documentation.

LowUnauthorized Data SharingNotice FailureSecurity Failure
TXEnforcement Action

General Motors

Texas Attorney General Ken Paxton filed a lawsuit against General Motors for unlawfully collecting private driving data from over 1.5 million Texas drivers without consent and selling the data to third parties including insurance companies. GM allegedly deceived customers into enrolling in products like OnStar Smart Driver by falsely claiming enrollment was required to retain vehicle safety features, while concealing that enrollment authorized systematic collection and sale of detailed driving data. The action follows an investigation launched in June 2024 as part of the Texas AG’s data privacy initiative, and seeks to hold GM accountable for violating state privacy laws.

LowConsent FailureNotice FailureUnauthorized Data Sharing
HHSEnforcement Action

Pemiscot Memorial Health System

Pemiscot Memorial Health System (Healthcare Provider, MO) reported a HIPAA breach affecting 33,279 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record.

MediumData BreachHealth DataUnauthorized Data Sharing
FTCEnforcement Action

TikTok and ByteDance(TikTok)

The FTC and DOJ sued TikTok and ByteDance for violating COPPA by collecting personal information from children under 13 without parental consent. The complaint alleges that TikTok knowingly allowed millions of children on its platform and failed to comply with a 2019 consent order. The lawsuit seeks civil penalties and a permanent injunction.

LowChildren's DataConsent FailureNotice Failure
HHSEnforcement Action

Geisinger

Geisinger (Healthcare Provider, PA) reported a HIPAA breach affecting 1,276,026 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Network Server.

CriticalData BreachHealth DataUnauthorized Data Sharing
CASettlement

Tilting Point Media LLC(Tilting Point Media)

Tilting Point Media LLC illegally collected and shared children's personal data in its mobile app game 'SpongeBob: Krusty Cook-Off' without parental consent, violating COPPA and CCPA. The settlement imposes a $500,000 civil penalty and injunctive terms to ensure compliance with children's data privacy laws.

MediumChildren's DataConsent FailureUnauthorized Data Sharing

$500K

TXInvestigation

Multiple car manufacturers(Car Manufacturers)

Texas Attorney General Ken Paxton opened an investigation into multiple car manufacturers for collecting and selling driver data to third parties, including insurance companies, without consumers' knowledge or consent. The investigation, conducted under the Texas Deceptive Trade Practices – Consumer Protection Act, seeks documents about data collection practices and disclosures made to customers. The AG's office is concerned about invasive data collection and potential deceptive practices.

LowUnauthorized Data SharingGeolocation DataNotice Failure
TXInvestigation

Several Car Manufacturers

Texas Attorney General Ken Paxton initiated an investigation into multiple car manufacturers for allegedly collecting drivers' data without consent and selling it to third parties, including insurance providers. The investigation, authorized under the Texas Deceptive Trade Practices – Consumer Protection Act, requires manufacturers and data purchasers to produce documents related to their data practices and customer disclosures. The AG highlighted concerns about invasive, non-consensual data collection and sale occurring without consumer knowledge.

LowConsent FailureUnauthorized Data SharingNotice Failure
HHSEnforcement Action

Insurance ACE/Humana Inc.

Insurance ACE/Humana Inc. (Health Plan, KY) reported a HIPAA breach affecting 15,003 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.

MediumData BreachHealth DataUnauthorized Data Sharing

Explore Enforcement Data