Court Rules

Privacy Enforcement Tracker

1,634 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,634

Total Actions

16

Jurisdictions

$49.9B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
CTSettlementMultistate

Intuit Inc.(Intuit)

Connecticut Attorney General William Tong secured $1.2 million in restitution for 40,841 state consumers as part of a multistate $141 million settlement with Intuit Inc., the owner of TurboTax. The settlement resolves allegations that Intuit deceived low-income consumers into paying for tax preparation services that were offered for free through the IRS Free File program by using deceptive marketing tactics and confusing product names. Intuit must pay restitution, suspend its 'free, free, free' ad campaign, and implement business practice reforms.

CriticalNotice FailureDark Patterns

$141.0M

CTCoalitionMultistate

Buy-Now-Pay-Later Lenders(BNPL Lenders)

Connecticut Attorney General William Tong joined a coalition of 19 attorneys general to submit comments to the CFPB, urging robust consumer protections for buy-now-pay-later (BNPL) lenders. The coalition expressed concerns that BNPL loans may trap consumers in debt through hidden fees, inadequate disclosures, and improper data monetization practices.

LowNotice FailureUnauthorized Data Sharing
FTCConsent Decree

Residual Pumpkin Entity, LLC and PlanetArt, LLC(CafePress)

The FTC took action against CafePress for failing to secure consumer data and covering up a major data breach. The company stored sensitive information insecurely and delayed notifying customers. As part of the settlement, Residual Pumpkin must pay $500,000 in redress, and both companies must implement comprehensive security programs.

MediumData BreachSecurity FailureNotice Failure

$500K

CTSettlement

Lively Hearing Corporation, Widex USA, Inc., Hark Wellness, Inc., Wonder Ear, Inc.(Lively Hearing, Widex USA, Hark Wellness, Wonder Ear)

Connecticut Attorney General William Tong announced settlements with four hearing aid companies for marketing their products as 'FDA-approved' when no such approval exists. The companies will collectively pay $40,000 and cease such marketing practices. The investigation underscores that over-the-counter hearing aids are not FDA-approved and consumers should be wary of such claims.

LowNotice Failure

$40K

CTSettlement

Safe Home Security Inc.(Safe Home Security)

Connecticut Attorney General filed a $5 million stipulation judgment against Safe Home Security for repeated non-compliance with court-ordered consumer protection measures, including blocking contract terminations and misrepresenting terms. The judgment requires immediate payment of $1 million and suspends $4 million pending compliance, with an independent monitor for five years.

HighOpt-Out FailureNotice Failure

$5.0M

CTSettlementMultistate

Navient

Connecticut Attorney General William Tong announced a $1.85 billion multistate settlement with student loan servicer Navient for unfair and deceptive servicing practices. Navient steered borrowers into costly forbearances and originated predatory loans, resulting in debt relief for over 66,000 borrowers and restitution for 350,000 federal loan borrowers. The settlement includes a $142.5 million payment to attorneys general and conduct reforms to improve servicing practices.

CriticalNotice Failure

$142.5M

CTEnforcement Action

Associated Community Services

The Connecticut Attorney General announced an enforcement action against Associated Community Services for operating a massive telefunding scheme that bombarded 67 million consumers with 1.3 billion deceptive fundraising calls, fraudulently collecting over $110 million. The action resulted in hundreds of millions of dollars in fines and a permanent prohibition from fundraising, forcing the sale of assets purchased with illegal proceeds.

HighNotice Failure
FTCSettlement

Support King, LLC(Support King)

The FTC finalized an order banning Support King, LLC and its CEO from the surveillance business for selling stalkerware apps that secretly collected and shared users' personal data without consent. The order requires them to delete all illegally collected data and notify affected device owners.

LowNotice FailureConsent FailureUnauthorized Data Sharing
FTCSettlementMultistate

MyLife.com, Inc.(MyLife.com)

The FTC and DOJ settled with MyLife.com, Inc. and its CEO for deceiving consumers with misleading background reports that falsely implied criminal records and for engaging in difficult-to-cancel subscription practices. MyLife violated the Fair Credit Reporting Act, Restore Online Shoppers’ Confidence Act, and Telemarketing Sales Rule. The settlement includes a permanent ban on negative option marketing, $33.9 million in judgments for consumer refunds, and a monitoring program.

CriticalNotice FailureData Broker Non-Compliance

$33.9M

FTCInvestigation

AT&T Mobility LLC, Cellco Partnership (Verizon Wireless), Charter Communications Operating LLC, Comcast Cable Communications (Xfinity), T-Mobile US Inc., Google Fiber Inc.(AT&T, Verizon, Charter, Comcast, T-Mobile, Google Fiber)

The FTC released a staff report based on Section 6(b) orders to six major ISPs, finding they collect extensive personal data, including internet traffic and location data, and share it with third parties. The ISPs often obscure data use disclosures in fine print and make it difficult for consumers to opt out, while combining data to profile sensitive characteristics. The report highlights the need for stricter privacy restrictions.

LowOpt-Out FailureNotice FailureUnauthorized Data Sharing
CTInvestigationMultistate

Facebook(Meta)

Connecticut Attorney General William Tong led a coalition of 14 attorneys general in demanding that Facebook disclose whether members of the 'Disinformation Dozen' were granted XCheck protections, which allow users to bypass enforcement rules. The coalition seeks information on the extent of anti-vaccine content from whitelisted users and complaint outcomes.

LowNotice Failure
FTCConsent Decree

Support King, LLC(Support King)

The FTC banned Support King, LLC (SpyFone) and its CEO from the surveillance business for secretly harvesting and sharing users' data without consent, and ordered the deletion of all illegally collected data and notification to affected device owners. The company failed to secure the data, leading to a hack that exposed 2,200 consumers.

LowNotice FailureUnauthorized Data SharingConsent Failure
CTSettlement

L.A. Vision

Connecticut Attorney General William Tong announced a $678,901 settlement with L.A. Vision and optician Lisa Azinheira for overbilling the state Medicaid program. The providers billed for non-medically necessary vision services and extra eyeglasses for children. In addition to restitution, they must comply with a federal Integrity Agreement requiring audits, training, and compliance measures.

MediumConsent FailureNotice Failure

$679K

FTCConsent Decree

Kuuhuub Inc.(Kuuhuub)

The FTC settled with Kuuhuub Inc., operator of the Recolor coloring book app, for violating COPPA by collecting personal information from children under 13 without parental consent. The app's social media features allowed children to register and share data, and third-party ad networks collected persistent identifiers for targeted ads. The settlement requires deletion of children's data, refunds to underage subscribers, a $3 million penalty (suspended upon $100,000 payment), and user notifications about the violations.

HighChildren's DataNotice FailureConsent Failure

$3.0M

FTCSettlement

SkyMed International, Inc.(SkyMed)

The FTC finalized a settlement with SkyMed International, Inc., an emergency travel services provider, for failing to secure sensitive consumer data and deceiving consumers about HIPAA compliance. The company left a cloud database with 130,000 membership records unsecured, containing personal and health information. Under the settlement, SkyMed must notify affected consumers, implement a security program, undergo biennial assessments, and is prohibited from misrepresenting its data practices.

LowSecurity FailureNotice Failure
FTCConsent Decree

Flo Health, Inc.(Flo Health)

The FTC settled with Flo Health, Inc., developer of a popular fertility-tracking app, alleging it misled users by sharing sensitive health data with third-party analytics providers like Facebook and Google after promising to keep such data private. The proposed consent order requires Flo to obtain user consent before sharing health data, notify affected users, and destroy previously shared data, among other requirements.

LowHealth DataUnauthorized Data SharingNotice Failure
FTCConsent Decree

Everalbum, Inc.(Everalbum)

Everalbum, Inc. settled FTC allegations that it deceived consumers about its use of facial recognition technology in its photo storage app and failed to delete photos when users deactivated their accounts. The settlement requires Everalbum to obtain express consent before using facial recognition, delete user photos and derived face embeddings, and delete developed models and algorithms. It also prohibits misrepresentations about data practices and requires consent for biometric data use if marketing software to consumers.

LowConsent FailureNotice FailureBiometric Data
FTCSettlement

NTT Global Data Centers Americas, Inc.(NTT Global Data Centers Americas)

The FTC settled with NTT Global Data Centers Americas, Inc. for deceiving consumers about its participation in the EU-U.S. Privacy Shield framework. The company's certification lapsed in 2018, but it continued to claim compliance in its privacy policy and marketing materials. Under the settlement, NTT is prohibited from misrepresenting its participation in any privacy program and must apply Privacy Shield protections to previously collected personal data or delete it.

LowNotice Failure
FTCSettlement

Ortho-Clinical Diagnostics, Inc.(Ortho-Clinical Diagnostics)

The FTC settled with Ortho-Clinical Diagnostics, Inc. for misleading consumers about its participation in the EU-U.S. Privacy Shield framework. The company allowed its certification to lapse in 2018 but continued to claim participation. The settlement prohibits such misrepresentations and requires compliance with Privacy Shield obligations for data collected or deletion of such data.

LowNotice Failure
FTCSettlement

Kohl's Department Stores, Inc.(Kohl's)

The FTC settled with Kohl's Department Stores for violating the Fair Credit Reporting Act by failing to provide identity theft victims with access to their business transaction records within 30 days. Kohl's agreed to pay a $220,000 civil penalty and must implement measures to comply with FCRA requirements, including providing records promptly and posting a notice on its website.

MediumNotice Failure

$220K

FTCConsent Decree

NTT Global Data Centers, Inc.(NTT Global Data Centers)

NTT Global Data Centers settled FTC allegations that it misled consumers about its participation in the EU-U.S. Privacy Shield framework and failed to comply with its requirements. The settlement requires the company to hire a third-party assessor if it re-certifies, prohibits misrepresentations about privacy programs, and mandates continued application of Privacy Shield protections or deletion of data collected while participating.

LowNotice Failure
FTCConsent Decree

Facebook, Inc.(Meta)

The FTC charged Facebook with deceiving consumers about its privacy practices and violating a 2012 consent order. In July 2019, Facebook agreed to pay a $5 billion civil penalty and accept comprehensive new privacy restrictions.

CriticalNotice FailureConsent Failure

$5.0B

CASettlementMultistate

Uber Technologies, Inc.(Uber)

Uber Technologies, Inc. settled for $148 million over a 2016 data breach that exposed 57 million users' personal information. The company was accused of covering up the breach by paying hackers and failing to notify authorities or affected drivers as required by law. The settlement includes a large penalty and mandates robust data security practices, privacy-by-design integration, and regular reporting to prevent future incidents.

CriticalData BreachNotice FailureSecurity Failure

$148.0M

NJSettlement

Meitu, Inc.(Meitu)

Meitu, Inc. allegedly violated COPPA and the New Jersey Consumer Fraud Act by collecting personal information from children under 13 without parental consent. The settlement requires Meitu to pay a $100,000 civil penalty, update its privacy policies, and modify its apps to block data collection from children.

MediumChildren's DataNotice FailureConsent Failure

$100K

NJInvestigationMultistate

Equifax

New Jersey Attorney General Christopher Porrino announced that New Jersey has joined a multi-state investigation into Equifax following a data breach affecting 143 million consumers. The multi-state group sent a letter demanding Equifax disable fee-based credit monitoring services and reimburse consumers for credit freeze fees with other bureaus, citing unfair practices and a months-long delay in breach disclosure.

CriticalData BreachNotice Failure
NJSettlementMultistate

Lenovo Inc.(Lenovo)

New Jersey joined 31 other states and the FTC in a $3.5 million settlement with Lenovo for pre-installing VisualDiscovery ad software on laptops that created a 'man-in-the-middle' security vulnerability, intercepting users' encrypted data without adequate disclosure or opt-out mechanisms. The settlement requires Lenovo to improve transparency, obtain affirmative consent, provide effective opt-out tools, and implement a long-term security compliance program with independent audits.

HighSecurity FailureUnauthorized Data SharingNotice Failure

$3.5M

CASettlementMultistate

Lenovo

Lenovo preinstalled 'Visual Discovery' software on its computers that intercepted browsing data and broke encrypted connections without user consent, compromising security and privacy. The multi-state settlement imposes a $3.5 million penalty and requires Lenovo to implement disclosure, consent, opt-out, and security compliance measures.

HighNotice FailureConsent FailureOpt-Out Failure

$3.5M

NJSettlementMultistate

VIZIO

VIZIO and Inscape settled allegations that they collected viewing data from Smart TVs without adequate disclosure and consent, selling it to third parties. They agreed to pay $1 million to New Jersey, destroy collected data, and implement privacy measures including obtaining consumer consent and establishing a privacy program.

MediumNotice FailureConsent FailureUnauthorized Data Sharing

$1.0M

CASettlement

Wells Fargo Bank(Wells Fargo)

Wells Fargo Bank recorded consumer phone calls without providing timely notice as required by California law, violating privacy statutes. The settlement imposes a $7.616 million civil penalty, requires compliance with disclosure standards, and mandates an internal compliance program to protect consumer privacy.

HighNotice Failure

$7.6M

CASettlement

Houzz Inc.(Houzz)

The California Attorney General settled with Houzz Inc. for secretly recording incoming and outgoing telephone calls from March to September 2013 without notifying or obtaining consent from all parties, violating state wiretapping and eavesdropping laws. The settlement requires Houzz to pay $175,000, appoint a Chief Privacy Officer, conduct a privacy risk assessment, secure and destroy the recordings, and implement compliance measures.

MediumNotice FailureConsent Failure

$175K

Explore Enforcement Data