1,634 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.
1,634
Total Actions
16
Jurisdictions
$49.9B+
Total Fines Tracked
Attorney General Jay Jones and a coalition of 24 attorneys general obtained a preliminary injunction blocking the Trump administration from demanding a database of state-owned records containing personal information of 17 million CDL drivers from AAMVA and from terminating over $10 million in federal funding. The lawsuits allege DOT, FMCSA, and DHS violated federal privacy laws by secretly creating a database with no guardrails on use or sharing of Social Security numbers and no public notice.
Texas Attorney General Ken Paxton issued a consumer alert warning Texas businesses and nonprofits about a surge of demand letters alleging California Invasion of Privacy Act (CIPA) violations based on common website technologies such as cookies, pixels, and analytics tools. The AG cautions that some letters may exaggerate or misrepresent violations and may be fraudulent, noting serial CIPA plaintiff Vivek Shah has been declared a vexatious litigant. Recipients are advised not to pay or respond directly, to consult privacy counsel, and to report suspected fraud to the Consumer Protection Division.
Attorney General Jay Jones and a coalition of 21 attorneys general obtained a temporary restraining order blocking the Trump administration from demanding a database of state-owned records containing sensitive personal information of 17 million commercial drivers from AAMVA. The lawsuits allege the federal agencies violated federal privacy laws and the Administrative Procedure Act by seeking to acquire the data without guardrails or public notice.
New York Attorney General Letitia James and a coalition of 22 attorneys general plus Pennsylvania secured a temporary restraining order blocking the Trump administration from seizing the names, dates of birth, and Social Security numbers of 17 million commercial drivers nationwide, including nearly 500,000 New Yorkers. The U.S. District Court for the Eastern District of Virginia granted the TRO, preventing the federal government from accessing the data or cutting off access to the critical database.
New York Attorney General Letitia James and a coalition of 21 other attorneys general and Pennsylvania sued the U.S. Department of Transportation and Department of Homeland Security to block the federal government from seizing the personal data of 17 million commercial drivers from the CDLIS database. The coalition argues the demands violate federal privacy laws and the Constitution, and seeks an injunction to prevent the data transfer.
Attorney General Phil Weiser joined a coalition of 22 attorneys general and Pennsylvania in filing two lawsuits against the Trump administration for demanding a database of state-owned records containing sensitive personal information of 17 million commercial drivers. The lawsuits allege violations of federal privacy laws and the Administrative Procedure Act, and seek an emergency order to prevent the data from being turned over by the August 17 deadline.
A coalition of 21 state attorneys general and Pennsylvania filed lawsuits against the Trump Administration, DOT, FMCSA, DHS, and AAMVA to prevent the unlawful demand for a database containing personal information of 17 million commercial driver's license holders. The lawsuits allege violations of federal privacy laws and the Administrative Procedure Act, and seek an emergency order to block the data transfer.
A coalition of 21 attorneys general and the Governor of Pennsylvania filed lawsuits against the U.S. Department of Transportation, FMCSA, DHS, and AAMVA to prevent the federal government from obtaining a database of personal information of 17 million commercial driver's license holders. The lawsuits allege the federal government violated federal privacy laws and the Administrative Procedure Act by demanding the data without notice or guardrails, and threatening to withhold $10 million in federal funding if AAMVA refused.
Attorney General Tong and a coalition of 21 attorneys general and Pennsylvania filed lawsuits against the U.S. Department of Transportation, FMCSA, and DHS to block demands for the personal information of 17 million CDL drivers. The lawsuits allege violations of federal privacy laws and the Administrative Procedure Act, and seek an emergency order to prevent the data transfer.
Attorney General Dan Rayfield and a coalition of 21 attorneys general and Pennsylvania filed lawsuits against the U.S. Department of Transportation, FMCSA, and AAMVA to block demands for a database containing personal information of 17 million commercial drivers. The federal government threatened to withhold $10 million in funding unless the data was turned over, which the coalition argues violates privacy law.
Attorney General William Tong joined a coalition of 23 states and the District of Columbia in suing the Trump administration over policy changes by the Administration for Children and Families (ACF) that would allow broad sharing of TANF recipients' sensitive personal data across federal agencies and potentially private organizations. The lawsuit alleges violations of the Administrative Procedure Act and the Spending Clause, seeking to block the policy.
Oregon Attorney General Dan Rayfield, joined by a coalition of 23 other states, the District of Columbia, and two governors, sued the Trump administration to block a new policy by the Administration for Children and Families (ACF) that would allow federal officials to access private records of millions of TANF recipients. The coalition argues the policy illegally shares sensitive personal data, including Social Security numbers and immigration status, with other federal agencies and private organizations, violating the Administrative Procedure Act and the Spending Clause. The lawsuit seeks to declare the policy illegal and block it from taking effect.
Attorney General Jennifer Davenport joined a coalition of 23 states and DC in suing the Trump Administration over policy changes by the Administration for Children and Families (ACF) that would allow broad sharing of TANF recipients' sensitive personal data with other federal agencies, including ICE. The lawsuit argues the policy violates the Administrative Procedure Act and the Spending Clause, and seeks to block its implementation.
Attorney General Ellison joined a coalition of 23 other states and DC to sue the Trump administration over a policy that would allow the Administration for Children and Families (ACF) to share sensitive TANF recipient data with other federal agencies. The lawsuit argues the policy violates the Administrative Procedure Act and the Spending Clause, and seeks to block its implementation.
The FTC, along with Utah and California, filed a complaint against Hims & Hers alleging the telehealth provider shared consumers' sensitive health information with third-party advertising platforms without consent, and deceived consumers about billing and cancellation practices. The complaint alleges violations of the FTC Act and the Restore Online Shoppers' Confidence Act.
Attorney General Jay Jones joined a coalition of 26 states to sue the Trump administration over unlawful conditions attached to counterterrorism and emergency funding. The conditions would require states to share voter data with DHS and assist in immigration enforcement, which the coalition argues violates the Administrative Procedure Act and the Spending Clause.
Minnesota Attorney General Keith Ellison, along with the FTC and attorneys general of Arizona, Illinois, Michigan, and Wisconsin, settled an antitrust lawsuit against John Deere. The settlement requires Deere to provide farmers and independent repair providers with the same repair resources previously only available to authorized dealers for 10 years, and to pay $1 million in legal costs.
$1.0M
Texas Attorney General Ken Paxton launched an investigation into Meta's Meta AI Glasses over allegations of unlawful facial biometric data collection, deceptive privacy practices, and unauthorized sharing of user data with subcontractors. The investigation follows concerns that the glasses' always-on recording mode lacks proper user notice, planned facial recognition features would collect data without consent, and private user videos are accessed by third-party annotators in Kenya. The AG issued a Civil Investigative Demand to Meta to determine violations of Texas privacy laws.
Texas Attorney General Ken Paxton launched an investigation into Meta regarding its Meta AI Glasses, alleging unlawful collection of facial biometric data, deceptive privacy representations, and unauthorized sharing of user data with subcontractors. The investigation follows concerns that the glasses’ always-on recording mode lacks proper notice, subcontractors access private user content including intimate moments, and Meta plans to deploy facial recognition technology to collect unsuspecting individuals’ facial geometry. The AG issued a Civil Investigative Demand to determine if Meta violated Texas law by deceptively misrepresenting its data use practices.
Texas Attorney General Ken Paxton initiated an investigation into Drone Nerds, LLC over its partnership with CCP-affiliated Anzu Robotics, which markets drones with concealed surveillance capabilities and unauthorized data collection risks. Drone Nerds is accused of deceiving Texas consumers by misrepresenting Anzu’s ties to China and falsely claiming the drones are U.S.-based with secure privacy practices. The investigation is being conducted under the Texas Deceptive Trade Practices Act, with a Civil Investigative Demand issued to gather evidence of consumer deception and privacy violations.
The FTC settled charges with data broker Kochava, Inc. and its subsidiary Collective Data Solutions (CDS) over allegations that they sold precise location data from hundreds of millions of mobile devices without consumer consent, enabling tracking of visits to sensitive locations like reproductive health clinics and places of worship. The settlement prohibits the companies from selling or sharing sensitive location data without affirmative express consumer consent, and imposes compliance requirements including a sensitive location data program, supplier consent assessments, incident reporting, and data retention schedules. No monetary penalty was imposed.
The FTC settled with Humor Rainbow, Inc. (operator of OkCupid) and Match Group Americas over allegations that OkCupid deceived users by sharing personal data including photos and location information with an unauthorized third party, contrary to its privacy policy promises to inform users and provide opt-out opportunities. The settlement permanently prohibits the companies from misrepresenting their data collection, use, disclosure, and privacy control practices. No monetary penalty was imposed.
Privacy enforcement action where Oregon AG and a coalition of 16 other states sue the Trump Administration to stop the Department of Education's new IPEDS data reporting requirements, arguing they jeopardize student privacy, lack proper definitions, and risk data errors and identification.
Attorney General Raoul secured a court order preventing the U.S. Department of Agriculture from collecting SNAP applicants' and recipients' personal data without an agreed-upon protocol that restricts sharing with unrelated entities like the Department of Homeland Security. The court found that the USDA's proposed protocol would violate federal law by allowing data use for immigration enforcement, contrary to the intended purpose of SNAP.
Massachusetts Attorney General Andrea Campbell secured a preliminary injunction from the U.S. District Court blocking the Trump Administration's USDA from cutting off SNAP funding to states that refuse to turn over personal data of SNAP applicants and recipients. The court found USDA's proposed data protocol unlawful because it allowed sharing data with entities unrelated to federal benefits administration.
Commonwealth Care Alliance (Health Plan, MA) reported a HIPAA breach affecting 634 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.
CalPrivacy sponsored AB 2021, the Whistleblower Protection and Privacy Act, introduced by Assemblymember Pilar Schiavo. The bill establishes whistleblower protections under the CCPA, including an award program and anti-retaliation provisions, to encourage insiders to report privacy violations.
Weill Cornell Medicine (Healthcare Provider, NY) reported a HIPAA breach affecting 516 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record.
Texas Attorney General Ken Paxton filed a lawsuit against Shein US Services LLC for selling toxic products and exposing consumers' personal data to the Chinese Communist Party. The lawsuit seeks monetary penalties under the Texas Deceptive Trade Practices Act. This action is part of a broader effort to protect Texans from health risks and CCP influence.
Texas Attorney General Ken Paxton filed a lawsuit against PDD Holdings, Inc. and WhaleCo Inc., doing business as Temu, for deceptive marketing and unlawful covert harvesting of Texans’ personal data that was exposed to the Chinese Communist Party. The suit alleges Temu functions as a 'trojan horse' e-commerce app that bypasses security protocols to create a backdoor into users’ private data, which is stored on servers in China. The lawsuit seeks monetary relief under the Texas Deceptive Trade Practices Act, including up to $10,000 per violation and up to $250,000 per violation targeting consumers aged 65 or older.
All data sourced from official government enforcement pages.