Court Rules

Privacy Enforcement Tracker

1,506 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,506

Total Actions

16

Jurisdictions

$26.6B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
MNSettlement

Unlock Partnership Solutions, Inc.

Minnesota Attorney General Keith Ellison filed a settlement with Unlock Partnership Solutions, Inc. over allegations that its 'home equity agreements' were actually unlawful mortgage loans that violated Minnesota's predatory interest rate caps and disclosure requirements. Unlock agreed to pay $944,626 in monetary and debt relief, cease lending unless licensed, and comply with Minnesota mortgage laws.

MediumNotice Failure

$945K

COSettlement

Domuso, Inc.

Domuso, Inc., a rent payment processor, settled with the Colorado Attorney General for charging illegal surcharges on credit/debit card rent payments. The settlement requires Domuso to cap fees at 2%, end fee-sharing with properties, provide cost-free payment options, and pay $100,000. The company must also comply with Colorado's surcharge and junk fees laws.

MediumNotice Failure

$100K

NYGuidance

New York State Office of the Attorney General

New York Attorney General Letitia James released final rules implementing the SAFE for Kids Act, which requires social media companies to restrict algorithmically personalized feeds and nighttime notifications for users under 18 unless they obtain parental consent. The rules establish age assurance standards, parental consent procedures, and data minimization requirements, with civil penalties of up to $5,000 per violation for noncompliance.

MediumChildren's DataDark PatternsConsent Failure
FTCSettlement

Elite Events and Tickets LLC

The FTC alleged that Elite Events and Tickets LLC, doing business as Smart Scalpers, violated the Better Online Ticket Sales Act by circumventing security measures to bypass ticket purchase limits for over 2,400 events, reselling tickets at a profit. The proposed order requires payment of $300,000 (with a total penalty of $10.7 million partially suspended) and permanently prohibits the company and its owners from engaging in such circumvention tactics.

MediumSecurity Failure

$300K

NYSettlement

1-800-Flowers.com, Inc.

New York Attorney General Letitia James secured $375,000 from 1-800-Flowers.com, Inc. for misleading consumers and enrolling them in automatically-renewing paid subscriptions without clear disclosure or consent. The settlement requires 1-800-Flowers to pay penalties, change its subscription practices, and provide refunds to eligible subscribers.

MediumNotice FailureConsent FailureOpt-Out Failure

$375K

VASettlementMultistate

23andMe

Attorney General Jay Jones joined 42 attorneys general in a multistate settlement with 23andMe's bankruptcy trustee over a 2023 data breach that compromised genetic data of nearly 7 million customers. The settlement includes $150 million in allowed claims, with immediate recovery of $18 million from bankruptcy funds, of which Virginia receives $662,649. The settlement also requires enhanced data security measures and consumer protections for the new entity, 23andMe Research Institute.

MediumData BreachSecurity FailureHealth Data

$663K

FTCSettlement

Vanilla Chip LLC

The FTC finalized a settlement with Vanilla Chip LLC (doing business as TruHeight) and its principals over allegations that they deceptively advertised height-enhancing supplements for children and teenagers without competent and reliable scientific evidence. The FTC also alleged that TruHeight used fake social media bot profiles and relied on reviews written by employees, vendors, or consumers who received free products or discounts for 5-star reviews. Under the final order, TruHeight must pay $750,000 and is barred from making unsupported health claims or misrepresenting reviews.

MediumNotice Failure

$750K

COSettlementMultistate

Cal-Maine Foods, Inc.

Colorado Attorney General Phil Weiser, along with a bipartisan multistate coalition and the U.S. Department of Justice, settled with Cal-Maine Foods, Versova/Centrum, and Hickman's Egg Ranch for colluding to manipulate egg prices. The companies secretly coordinated bidding activity to influence the Urner Barry price index, artificially inflating egg prices for consumers and retailers nationwide. The settlement requires the companies to pay $3.3 million, donate 53 million eggs to food banks, and implement compliance measures.

MediumSurveillance Pricing

$3.3M

MNSettlementMultistate

GS Labs

Attorney General Ellison announced a $4.87 million multistate settlement with GS Labs for overcharging patients, charging unlawful administrative fees, and failing to deliver timely COVID-19 test results. The settlement includes $3.63 million in restitution to affected consumers and $1.25 million to the multistate group, along with injunctive relief if GS Labs resumes operations.

MediumNotice FailureConsent Failure
FTCSettlementMultistate

Golden Home Services

The FTC is returning nearly $3 million to consumers deceived by the Golden Home Services mortgage relief scheme, which falsely promised to reduce homeowners' mortgage payments and prevent foreclosures. A federal court banned the companies and their operators from telemarketing and debt relief businesses and required them to pay millions. The refunds are being mailed to 1,821 affected homeowners.

MediumConsent Failure

$3.0M

FTCSettlement

Cox Media Group

The FTC alleged that Cox Media Group (CMG), MindSift LLC, and 1010 Digital Works LLC deceived customers by falsely claiming to offer an AI-powered 'Active Listening' service that could target ads based on conversations captured from consumers' smart devices, and that consumers had opted into such targeting. In reality, the service did not use voice data and consumers had not consented. The companies agreed to pay a total of $930,000 and are prohibited from making misrepresentations about their services, voice data collection, and consumer consent.

MediumConsent FailureNotice FailureUnauthorized Data Sharing

$930K

NJConsent Decree

King Distribution LLC and 17 related retail businesses

New Jersey Attorney General Jennifer Davenport and the Division of Consumer Affairs announced a Consent Order with King Distribution LLC and 17 related retail smoke shops, resolving allegations that the companies illegally sold flavored vapor products in violation of New Jersey’s consumer protection laws. The Consent Order imposes a $100,000 civil penalty, requires reimbursement of $22,279 in investigation costs, and prohibits the companies from selling or distributing flavored vapor products in New Jersey. The enforcement action is part of New Jersey’s ongoing efforts to protect youth from flavored vape products, which have been permanently banned in the state since January 2020.

Medium

$100K

CTSettlement

Made-in-China

Connecticut Attorney General William Tong announced a settlement with international trade platform Made-in-China to cease all U.S. sales of unlawful 'research grade' GLP-1 weight loss drugs following an investigation into direct sales to consumers without prescriptions or medical oversight. The settlement prohibits the platform from hosting GLP-1 sales to U.S. customers, requires a monitoring system to remove non-compliant listings, and imposes a $300,000 penalty suspended after an initial $30,000 payment. Additional settlements were announced with Radiance Medspa and Advanced Medical Weight Loss over compounded non-FDA approved GLP-1 drugs.

Medium

$300K

FTCSettlement

TouchTunes Music Company, LLC; Americana Liberty LLC; Three Nations LLC; Oak Street Manufacturing Company, LLC

The FTC announced three separate settlements with companies making false 'Made in USA' claims: TouchTunes (electronic dartboards, $625k consumer redress), Americana Liberty and related parties (flags and flagpoles, $167,743 redress), and Oak Street Bootmakers (footwear, $75k redress). The companies violated the FTC Act, Made in USA Labeling Rule, and for Americana Liberty, the Textile Act and Rules, by making unqualified origin claims for products with significant imported components or wholly imported from China. Each settlement prohibits future misrepresentations of U.S. origin and requires consumer notices.

Medium

$868K

FTCSettlement

Vanilla Chip LLC

The FTC alleged that Vanilla Chip LLC (d/b/a TruHeight) deceptively advertised height-enhancing supplements for children and teens without competent scientific evidence, and used fake employee-written and incentivized 5-star reviews. The proposed settlement requires TruHeight and its principals to pay $750,000, bars false health claims, and prohibits misleading review practices. A $4 million total judgment is partially suspended due to the respondents' inability to pay the full amount.

Medium

$750K

CTSettlement

Spruce Power 3, LLC(Spruce Power 3)

The Connecticut Attorney General announced a $100,000 settlement with Spruce Power 3, LLC to resolve an investigation into billing, customer service, and warranty issues stemming from consumer complaints. The settlement includes refunds for improper charges and requires reforms to improve billing practices and response times. Separately, an investigation was initiated into SunStrong Management LLC based on approximately 65 consumer complaints regarding warranty failures, unresponsiveness, and fees.

Medium

$100K

CASettlement

Ford Motor Company

The California Privacy Protection Agency (CalPrivacy) settled with Ford Motor Company requiring the company to pay a $375,703 fine and change its practices. Ford violated the CCPA by requiring consumers to complete an email verification step before they could opt-out of the sale and sharing of their personal information collected through digital properties and connected vehicle services. In addition to the fine, Ford must provide easy methods to submit opt-out requests with minimal steps, audit its tracking technologies, and ensure compliance with opt-out preference signals including Global Privacy Control.

MediumOpt-Out Failure

$376K

CPPASettlement

Ford Motor Company(Ford)

The California Privacy Protection Agency settled with Ford Motor Company for $375,703 after finding that Ford violated the CCPA by requiring email verification for opt-out requests, creating unnecessary friction. Ford must implement easier opt-out methods, conduct a website audit, and comply with global privacy controls.

MediumOpt-Out Failure

$376K

HHSEnforcement Action

Manhattan Retirement Foundation d/b/a Meadowlark Hills

Manhattan Retirement Foundation d/b/a Meadowlark Hills (Healthcare Provider, KS) reported a HIPAA breach affecting 14,442 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Couve Healthcare Consulting, LLC DBA Evergreen Healthcare Group

Couve Healthcare Consulting, LLC DBA Evergreen Healthcare Group (Business Associate, WA) reported a HIPAA breach affecting 11,795 individuals. Breach type: Hacking/IT Incident. Location of breached information: Electronic Medical Record.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Emanuel Medical Center

Emanuel Medical Center (Healthcare Provider, GA) reported a HIPAA breach affecting 28,963 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

National Association on Drug Abuse Problems

National Association on Drug Abuse Problems (Healthcare Provider, NY) reported a HIPAA breach affecting 90,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Academic Urology & Urogynecology of Arizona

Academic Urology & Urogynecology of Arizona (Healthcare Provider, AZ) reported a HIPAA breach affecting 73,281 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Communications Workers of America Local 1180 Security Benefits Fund

Communications Workers of America Local 1180 Security Benefits Fund (Health Plan, NY) reported a HIPAA breach affecting 18,550 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record, Other.

MediumData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Cedar Point Health, LLC

Cedar Point Health, LLC (Healthcare Provider, CO) reported a HIPAA breach affecting 23,114 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Wendy Foster OD

Wendy Foster OD (Healthcare Provider, KS) reported a HIPAA breach affecting 20,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Counseling Center of Wayne & Holmes Counties

Counseling Center of Wayne & Holmes Counties (Healthcare Provider, OH) reported a HIPAA breach affecting 83,354 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Triad Radiology Associates

Triad Radiology Associates (Healthcare Provider, NC) reported a HIPAA breach affecting 11,011 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

WIRX Pharmacy

WIRX Pharmacy (Healthcare Provider, PA) reported a HIPAA breach affecting 20,047 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

EyeCare Partners, LLC, including The Ophthalmology Group, Ophthalmology Consultants, and Ophthalmology Associates.

EyeCare Partners, LLC, including The Ophthalmology Group, Ophthalmology Consultants, and Ophthalmology Associates. (Healthcare Provider, MO) reported a HIPAA breach affecting 17,110 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

MediumData BreachHealth DataSecurity Failure

Explore Enforcement Data