Court Rules

Privacy Enforcement Tracker

1,447 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,447

Total Actions

16

Jurisdictions

$26.1B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
MNSettlementMultistate

23andMe, Inc.

A coalition of 42 state attorneys general reached a settlement with the bankruptcy trustee for 23andMe over a 2023 data breach that compromised the genetic data of 6.9 million customers. The settlement provides $18 million from bankruptcy funds, with Minnesota receiving $514,871, and imposes data security requirements on the successor entity, 23andMe Research Institute.

HighData BreachSecurity FailureBreach Notification Delay

$18.0M

COSettlementMultistate

23andMe, Inc.

A coalition of 42 state attorneys general settled with the bankruptcy trustee for 23andMe over a 2023 data breach that exposed genetic data of 6.9 million customers. The states will receive $18 million from bankruptcy funds, and 23andMe agreed to enhanced data security requirements and consumer deletion rights as part of the asset sale to TTAM Research Institute.

HighData BreachSecurity FailureBiometric Data

$18.0M

CASettlement

Blackbaud

California Attorney General Rob Bonta announced a $6.75 million settlement with software company Blackbaud over a 2020 data breach that exposed consumers' personal information including Social Security numbers, bank account details, and medical data. Blackbaud was found to have inadequate data security practices, failed to timely and accurately notify impacted individuals of the breach, and made misleading public disclosures about the breach and its pre-breach security measures. The settlement requires Blackbaud to pay penalties and implement enhanced data security and breach notification protocols.

HighData BreachSecurity FailureBreach Notification Delay

$6.8M

NJSettlementMultistate

Carnival Cruise Line(Carnival)

New Jersey, as part of a multistate coalition, settled with Carnival Cruise Line over a 2019 data breach that compromised personal information of approximately 180,000 employees and customers nationwide. The breach resulted from deficiencies in Carnival's data security program and delayed breach notification. Carnival will pay $1.25 million and implement enhanced email security and breach response measures.

HighData BreachSecurity FailureBreach Notification Delay

$1.3M

CTSettlementMultistate

Carnival Cruise Line

Connecticut, co-leading a multistate investigation, secured a $1.25 million settlement with Carnival Cruise Line over a 2019 data breach affecting approximately 180,000 individuals nationwide. The breach exposed sensitive data including passport numbers, driver's licenses, payment card information, and health data, with a 10-month delay in notification. Carnival agreed to implement enhanced email security measures, a breach response plan, and an independent security assessment.

HighData BreachSecurity FailureBreach Notification Delay

$1.3M

NJSettlementMultistate

Sabre Corp.(Sabre)

New Jersey participated in a multi-state settlement resolving an investigation into a 2017 data breach at Sabre Hospitality Solutions. Intruders accessed the company's hotel booking system from August 2016 to March 2017, compromising data from over 1.3 million consumer credit cards, including CVV numbers and expiration dates. Sabre failed to promptly notify affected consumers. The $2.4 million settlement requires Sabre to implement enhanced data security measures, develop a breach notification plan, clarify contractual responsibilities with client hotels, and undergo third-party security assessments.

HighData BreachBreach Notification Delay

$2.4M

NJSettlement

Virtua Medical Group, P.A.(Virtua Medical Group)

Virtua Medical Group agreed to pay $417,816 and implement a corrective action plan to settle allegations that it failed to properly secure electronic protected health information (ePHI). A vendor's server misconfiguration publicly exposed the medical records of over 1,650 patients via Google searches. The New Jersey Division of Consumer Affairs found VMG violated HIPAA's Security and Privacy Rules by not adequately vetting the vendor's security and failing to conduct proper risk analysis.

HighHealth DataSecurity FailureBreach Notification Delay

$418K

Explore Enforcement Data