Court Rules

Privacy Enforcement Tracker

1,634 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,634

Total Actions

16

Jurisdictions

$49.9B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
NYSettlement

DARCARS of Railroad Avenue, Inc. (DARCARS Lexus) and MT Kisco Automotive, LLC (DARCARS BMW)

New York Attorney General Letitia James secured a settlement with two Mt. Kisco car dealerships, DARCARS Lexus and DARCARS BMW, that deceptively charged a two percent 'sales commission' fee that was optional, provided no consumer benefit, and was never paid to the salesperson, and that misleadingly bundled a low-value aftermarket product ('DARCARS Assurance') into sales and lease agreements as if it were mandatory. The dealerships will pay more than $1.17 million in consumer refunds (with potentially millions more through a claims process) plus $700,000 in penalties. They must clearly disclose all future fees and add-ons, are banned from selling DARCARS Assurance or similar junk bundles at any New York dealership, and must conduct annual fair-business-practices training for all employees.

MediumDark PatternsNotice Failure

$700K

COSettlement

Corporate Certificates, LLC and FL UCC Statement Service, LLC

Colorado Attorney General Phil Weiser announced a settlement with Corporate Certificates, LLC and FL UCC Statement Service, LLC resolving allegations that the companies mailed marketing materials to Colorado businesses designed to look like official government invoices, without the statutorily required disclaimers and with purported deadlines implying a legal duty. Under the stipulated consent judgment, the companies will pay $150,000 in refunds and fees and permanently cease all operations in Colorado. The companies had ignored prior warning notices and stopped operating in Colorado in August 2025 after the AG obtained a preliminary injunction.

MediumDark PatternsNotice Failure

$150K

COSettlement

Sahansila Karki and Gokul Tiwari

Colorado Attorney General Phil Weiser announced a $152,000 settlement with smoke shop owners Sahansila Karki and Gokul Tiwari for selling kratom products that exceeded the legal potency limit and failed to meet labeling and packaging requirements. The settlement requires compliance with the Colorado Consumer Protection Act and the Daniel Bregger Act, product testing, documentation of purchases, and payment of $152,000, with an additional $500,000 due if the terms are violated.

MediumNotice Failure

$152K

NYSettlement

425 Marcy, LLC

New York Attorney General Letitia James secured a settlement with 425 Marcy, LLC and its principal Ezra Unger over the unlawful pre-sale of condominium units at 427 Marcy Avenue in Williamsburg before the required Martin Act offering plan was accepted for filing, and the misuse of $6.715 million in buyer down payments that were never placed in escrow. Unger agreed to repay residential buyers their down payments with interest or provide purchase credits, pay up to $824,000 in penalties, and is barred from selling securities in New York for six years. Note: this is a real estate offering-plan/escrow enforcement action rather than a data privacy matter; 'notice_failure' is the closest available taxonomy mapping (selling without the required offering plan disclosures).

MediumNotice Failure

$824K

COSettlement

Avail Property Management Inc. and PK Management, LLC

Colorado Attorney General Phil Weiser announced a settlement with Avail Property Management Inc. and PK Management, LLC resolving allegations that the companies denied prospective tenants housing based on criminal history information prohibited under Colorado's Rental Application Fairness Act, including arrests, deferred judgments, and convictions older than five years (some more than 20 years old). The companies, which managed nearly 4,000 rental units across Colorado, relied on a third-party background screening service despite legal prohibitions. Under the settlement, they must change screening practices, review vendor recommendations rather than relying on them automatically, submit to two years of compliance reporting, and pay $300,000.

MediumNotice FailureUnauthorized Data Sharing

$300K

NJConsent Decree

Match Group, Inc.

The New Jersey Attorney General and Division of Consumer Affairs announced that Match Group, Inc. will pay $650,000 and change its business practices to settle allegations that it misrepresented or failed to disclose its criminal background screening policies and practices to New Jersey users, violating the New Jersey Consumer Fraud Act and the Internet Dating Safety Act. Under a Consent Order, Match must accurately represent its screening policies, notify existing New Jersey members of updated disclosures within 150 days, and post clear and conspicuous disclosures and safety notifications about the limitations of criminal background screenings.

MediumNotice Failure

$650K

MNSettlement

Midwest Car Search

Minnesota Attorney General Keith Ellison announced that used car dealer Midwest Car Search and its owner Scott Spiczka agreed to reform their business practices and pay $100,000 to resolve allegations that they violated Minnesota's Used Car Law and other consumer-protection laws through five deceptive practices, including fake 'certified' claims, illegally added vehicle service contracts, denied warranties, missing Buyer's Guide disclosures, and operating under an unregistered trade name that exploited Spanish speakers. The settlement resolves the AG's April 23, 2024 lawsuit and makes permanent a prior court order requiring the dealer to cease the deceptive conduct. Note: this is a consumer-protection enforcement action, not a privacy matter, so violation-type mapping to the privacy taxonomy is approximate.

MediumNotice FailureDark Patterns

$100K

NYSettlement

Thirty Madison, Inc.

New York Attorney General Letitia James secured $400,000 from Thirty Madison, Inc., an online medication provider, for misleading consumers about auto-renewing subscriptions and making cancellation difficult. The company failed to clearly disclose subscription terms and non-refundable fees, and required multiple steps to cancel. The settlement requires payment, refunds to eligible subscribers, and changes to subscription practices.

MediumNotice FailureConsent FailureDark Patterns

$400K

CTSettlement

TaxAct

Connecticut Attorney General William Tong announced a $275,000 settlement with TaxAct, an online tax preparation company, over allegations that between January 2018 and December 2022, TaxAct improperly disclosed detailed customer financial information to Meta and Google through third-party tracking technologies without notifying taxpayers. The settlement requires TaxAct to pay $275,000 and implement new third-party tracking compliance measures, including a review committee, written policies, a tag monitoring system, and two independent third-party audits.

MediumUnauthorized Data SharingNotice Failure

$275K

CPPAAdministrative Order

LocateSmarter LLC

The California Privacy Protection Agency Board issued a decision and stipulated order requiring Iowa data broker LocateSmarter LLC to pay $116,490 and change its practices. The company failed to timely register as a data broker and unlawfully required Californians to provide the last four digits of their Social Security numbers before exercising opt-out rights, violating the CCPA's data minimization requirements. This is the first action against a data broker under both the CCPA and the Delete Act.

MediumData Broker Non-ComplianceOpt-Out FailureNotice Failure

$116K

MNSettlement

Unlock Partnership Solutions, Inc.

Minnesota Attorney General Keith Ellison filed a settlement with Unlock Partnership Solutions, Inc. over allegations that its 'home equity agreements' were actually unlawful mortgage loans that violated Minnesota's predatory interest rate caps and disclosure requirements. Unlock agreed to pay $944,626 in monetary and debt relief, cease lending unless licensed, and comply with Minnesota mortgage laws.

MediumNotice Failure

$945K

COSettlement

Domuso, Inc.

Domuso, Inc., a rent payment processor, settled with the Colorado Attorney General for charging illegal surcharges on credit/debit card rent payments. The settlement requires Domuso to cap fees at 2%, end fee-sharing with properties, provide cost-free payment options, and pay $100,000. The company must also comply with Colorado's surcharge and junk fees laws.

MediumNotice Failure

$100K

NYSettlement

1-800-Flowers.com, Inc.

New York Attorney General Letitia James secured $375,000 from 1-800-Flowers.com, Inc. for misleading consumers and enrolling them in automatically-renewing paid subscriptions without clear disclosure or consent. The settlement requires 1-800-Flowers to pay penalties, change its subscription practices, and provide refunds to eligible subscribers.

MediumNotice FailureConsent FailureOpt-Out Failure

$375K

FTCSettlement

Vanilla Chip LLC

The FTC finalized a settlement with Vanilla Chip LLC (doing business as TruHeight) and its principals over allegations that they deceptively advertised height-enhancing supplements for children and teenagers without competent and reliable scientific evidence. The FTC also alleged that TruHeight used fake social media bot profiles and relied on reviews written by employees, vendors, or consumers who received free products or discounts for 5-star reviews. Under the final order, TruHeight must pay $750,000 and is barred from making unsupported health claims or misrepresenting reviews.

MediumNotice Failure

$750K

MNSettlementMultistate

GS Labs

Attorney General Ellison announced a $4.87 million multistate settlement with GS Labs for overcharging patients, charging unlawful administrative fees, and failing to deliver timely COVID-19 test results. The settlement includes $3.63 million in restitution to affected consumers and $1.25 million to the multistate group, along with injunctive relief if GS Labs resumes operations.

MediumNotice FailureConsent Failure
FTCSettlement

Cox Media Group

The FTC alleged that Cox Media Group (CMG), MindSift LLC, and 1010 Digital Works LLC deceived customers by falsely claiming to offer an AI-powered 'Active Listening' service that could target ads based on conversations captured from consumers' smart devices, and that consumers had opted into such targeting. In reality, the service did not use voice data and consumers had not consented. The companies agreed to pay a total of $930,000 and are prohibited from making misrepresentations about their services, voice data collection, and consumer consent.

MediumConsent FailureNotice FailureUnauthorized Data Sharing

$930K

CTInvestigationMultistate

Affirm, Afterpay, Klarna, PayPal, Sezzle, Zip(Affirm)

Connecticut Attorney General William Tong led a multistate coalition in sending inquiry letters to six major BNPL providers—Affirm, Afterpay, Klarna, PayPal, Sezzle, and Zip—seeking detailed information on their pricing, fees, disclosures, and consumer assessment practices to evaluate compliance with consumer protection laws, following the rescission of federal Truth in Lending Act rules for BNPL.

MediumNotice Failure
ORSettlement

Grocery Delivery E-Service USA, Inc., doing business as HelloFresh(HelloFresh)

Consumer protection and advertising enforcement action. Oregon Attorney General secured a settlement with meal-kit company HelloFresh for misleading consumers with deceptive 'free meal,' 'free shipping,' and 'free gift' offers that required hundreds of dollars in purchases to obtain. The company must pay $106,000 and implement comprehensive advertising reforms.

MediumDark PatternsNotice Failure

$106K

FTCConsent Decree

Apitor Technology

The FTC settled allegations against Apitor Technology for violating COPPA by allowing a third party to collect geolocation data from children without parental consent. Apitor must pay a $500,000 suspended fine, delete improperly collected data, and implement measures to comply with COPPA, including obtaining parental consent and notifying parents.

MediumChildren's DataGeolocation DataNotice Failure

$500K

FTCSettlement

Frank Romero

The FTC is returning over $672,000 to consumers who were deceived by Frank Romero, operator of Trend Deploy, for violating the Mail Order Rule. The court order required Romero to pay the FTC, and the FTC is now distributing refunds to 9,419 affected consumers.

MediumConsent FailureNotice Failure

$672K

NYSettlement

Saturn Technologies(Saturn)

New York Attorney General Letitia James settled with Saturn Technologies, developer of the Saturn social networking app for high school students, over failures to protect young users’ privacy. The Office of the Attorney General found the company disabled required email verification for thousands of schools, used inadequate age and identity checks, retained user contact data after access was revoked, and failed to maintain proper privacy records. Saturn will pay $650,000 in penalties and implement enhanced privacy protections for minor users, including mandatory bi-annual privacy setting reviews and data deletion requirements.

MediumChildren's DataConsent FailureNotice Failure

$650K

CASettlement

Tilting Point Media LLC

California Attorney General Rob Bonta and Los Angeles City Attorney Hydee Feldstein Soto announced a $500,000 settlement with Tilting Point Media LLC over allegations that the company violated COPPA and the CCPA by illegally collecting and sharing children’s personal data without parental consent via its 'SpongeBob: Krusty Cook-Off' mobile game. The settlement requires Tilting Point to pay $500,000 in civil penalties and comply with injunctive terms including implementing neutral age screens, obtaining parental consent for children’s data collection/sharing, and maintaining an SDK governance framework. Tilting Point must also submit annual compliance reports to the California DOJ and LA City Attorney’s Office.

MediumChildren's DataConsent FailureNotice Failure

$500K

CASettlement

DoorDash

California Attorney General Rob Bonta announced a settlement with DoorDash resolving allegations that the company violated the CCPA and CalOPPA by selling California consumers' personal information to a marketing cooperative without required notice or an opt-out mechanism. DoorDash disclosed consumers' names, addresses, and transaction histories to the cooperative, failing to disclose this practice in its privacy policy as required by CalOPPA. The settlement requires DoorDash to pay a $375,000 civil penalty and comply with injunctive terms including vendor contract reviews and annual reporting to the AG.

MediumOpt-Out FailureNotice Failure

$375K

NJSettlement

Bumble, Inc.(Bumble)

Bumble Inc. agreed to pay $315,000 and update its disclosures to settle allegations that it misrepresented its criminal background screening policies to New Jersey users, violating the New Jersey Consumer Fraud Act and Internet Dating Safety Act. The settlement requires Bumble to clearly disclose its screening practices and safety limitations on its dating platforms.

MediumNotice Failure

$315K

FTCSettlement

Experian Consumer Services(Experian)

The FTC settled charges against Experian Consumer Services for violating the CAN-SPAM Act by sending marketing emails to consumers who signed up for credit management accounts without providing an opt-out mechanism. The emails promoted products like Experian Boost and Dark Web scans but lacked unsubscribe links. Experian must pay $650,000 and is prohibited from future violations.

MediumOpt-Out FailureNotice Failure

$650K

FTCConsent DecreeMultistate

Easy Healthcare Corporation(Easy Healthcare)

The FTC charged Easy Healthcare Corporation, operator of the Premom fertility app, with deceiving users by sharing their sensitive health data with third parties for advertising without consent and failing to notify breaches as required by the Health Breach Notification Rule. Under a proposed consent decree, the company will pay a $100,000 civil penalty, be barred from sharing health data for advertising, and must implement privacy and security measures.

MediumUnauthorized Data SharingConsent FailureNotice Failure

$100K

CTSettlementMultistate

Easy Healthcare Corporation(Easy Healthcare)

Connecticut, Oregon, and the District of Columbia reached a $100,000 settlement with Easy Healthcare Corporation, the operator of the Premom ovulation tracking app, for sharing sensitive user health and location data with third parties without appropriate disclosures or user consent. The settlement requires the company to implement comprehensive privacy and security programs, obtain consent before sharing health or location data, and provide users with a method to delete their personal information.

MediumUnauthorized Data SharingNotice FailureHealth Data

$100K

CTSettlement

Frontier Communications(Frontier)

Connecticut Attorney General settled with Frontier Communications over deceptive marketing, hidden fees, and poor service. The $60 million settlement requires Frontier to invest $42.5 million in fiber upgrades for 40,000 households in distressed areas, end a $6.99 monthly surcharge, pay $1 million to the state, and provide $200,000 in consumer refunds. Frontier must also improve customer service, billing disclosures, and service quality guarantees over six years.

MediumNotice FailureConsent Failure

$1.0M

FTCConsent DecreeMultistate

Harris Jewelry

Harris Jewelry defrauded servicemembers with deceptive marketing, inflated prices, and hidden fees. A multistate settlement requires $34.2 million in refunds and debt relief, stops debt collection, and dissolves the business, affecting over 46,000 servicemembers.

MediumNotice FailureConsent Failure

$1.0M

FTCConsent Decree

CafePress

The FTC finalized an order against CafePress for failing to secure consumer data and covering up a data breach. The company must implement comprehensive security measures, and its former owner must pay $500,000 in redress to victims.

MediumSecurity FailureData BreachBreach Notification Delay

$500K

Explore Enforcement Data