Court Rules

Privacy Enforcement Tracker

1,285 enforcement actions from 14 federal and state jurisdictions. Every event traced back to its official government source.

1,285

Total Actions

14

Jurisdictions

$35.3B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
CTNew Law

Bad actor platforms

Connecticut’s legislature passed House Bill 5312, creating new civil enforcement mechanisms for deepfake digital sexual assault, including unauthorized dissemination of synthetically created intimate images and AI-generated child pornography. The bill establishes a private right of action for victims and empowers the Connecticut Attorney General to pursue civil injunctions and penalties against abusers and platforms hosting illegal content. This builds on prior Connecticut laws criminalizing unauthorized intimate image dissemination.

LowConsent FailureChildren's Data
CTNew Law

social media companies

Connecticut Attorney General William Tong issued a statement on May 1, 2026, announcing the final passage of bipartisan legislation targeting youth social media addiction and artificial intelligence harms. The legislation imposes new obligations on social media companies regarding minor account settings, parental consent, and reporting, as well as requirements for AI chatbot operators and employers using automated decision tools. The statement also references ongoing enforcement actions against Meta and TikTok for allegedly designing addictive platform features for youth.

LowChildren's DataAI/Automated DecisionsConsent Failure
CTSettlement

Sephora

Connecticut Attorney General William Tong announced a settlement with beauty retailer Sephora resolving an investigation into the company’s marketing of anti-aging skincare products containing active ingredients like retinol to children under 13. Sephora agreed to adopt enforceable safeguards including requiring suppliers to provide age suitability warnings, disclosing those warnings on product pages, training employees to advise young customers, and maintaining a public resource on age-appropriate products. No monetary penalty was imposed.

LowChildren's Data
FLInvestigation

Discord

Florida Attorney General James Uthmeier opened a civil investigation into Discord and issued a subpoena demanding documents related to its marketing to children, age-verification processes, content moderation, parental controls, and reporting of child exploitative activity. The investigation alleges potential violations of Florida’s Deceptive and Unfair Trade Practices Act, citing the platform’s widespread use by child predators to target minors. Discord must produce records on its child safety practices, minor user data, and complaint handling related to child exploitation.

LowChildren's DataConsent Failure
NJEnforcement Action

Susaida Nazario

A former employee of the New Jersey Department of Children and Families was indicted for allegedly leaking confidential child protection case information in exchange for bribes. The defendant, Susaida Nazario, misused her access to provide case details to an unauthorized individual, compromising sensitive children's data.

LowChildren's Data
CPPASettlement

PlayOn Sports

The California Privacy Protection Agency settled with PlayOn Sports for $1.10 million over CCPA violations, including failing to provide adequate opt-out mechanisms and improperly tracking users, particularly students. The company must implement proper opt-out methods, improve disclosures, and comply with children's data consent requirements.

HighOpt-Out FailureNotice FailureChildren's Data

$1.1M

FTCGuidance

Operators of General Audience and Mixed Audience Sites and Services(Online Service Operators)

The FTC issued a policy statement announcing that it will not enforce the COPPA Rule against website and online service operators that use age verification technologies solely to determine user age, provided they comply with conditions such as limiting data use, ensuring security, and providing clear notice. This policy aims to incentivize age verification tools to protect children online.

LowChildren's Data
FTCGuidance

Website and Online Service Operators(Online Service Operators)

The FTC issued a policy statement announcing it will not enforce COPPA against operators that collect age verification data under specific conditions. The policy aims to encourage the use of age verification technologies to protect children online. Operators must limit data use, ensure security, provide notice, and use accurate verification methods.

LowChildren's DataConsent FailureNotice Failure
NYWarning LetterMultistate

xAI

A bipartisan coalition of 35 state attorneys general led by New York Attorney General Letitia James sent a demand letter to xAI on January 26, 2026, requiring the company to address its Grok chatbot’s creation and sharing of nonconsensual intimate images, including child sexual abuse material. The AGs demand that xAI implement safeguards to prevent Grok from generating such content, delete existing harmful content, suspend offending users, and give X users control over whether their content can be edited by Grok. No monetary penalty has been imposed as this is a pre-enforcement demand for action.

LowConsent FailureChildren's DataUnauthorized Data Sharing
CAEnforcement ActionMultistate

U.S. Department of Justice

California Attorney General Rob Bonta joined a multistate coalition in filing an amicus brief opposing the U.S. Department of Justice's subpoena for patient records from University of Pittsburgh Medical Center related to gender-affirming care. The brief argues that the subpoena violates patient privacy, infringes on states' rights to regulate medicine, and exceeds DOJ's statutory authority.

LowHealth DataChildren's Data
CAEnforcement Action

xAI

California Attorney General Rob Bonta sent a cease and desist letter to xAI, demanding the company immediately stop the creation and distribution of deepfake, nonconsensual intimate images and child

CriticalAI/Automated DecisionsChildren's Data
CAInvestigation

xAI

California Attorney General Rob Bonta announced an investigation into xAI for its Grok AI model generating nonconsensual sexual images of women and children, including child sexual abuse material. The AG expressed deep concern and zero tolerance, urging immediate action to prevent further

LowChildren's DataConsent Failure
MAEnforcement ActionMultistate

Trump Administration

Massachusetts Attorney General Andrea Campbell filed a motion to enforce a preliminary injunction against the Trump Administration's demands for personal data of SNAP recipients. The court previously blocked such demands, but the administration renewed its request, threatening to withhold funding. The AG seeks to ensure compliance with federal privacy laws and protect SNAP recipients' sensitive information.

LowUnauthorized Data SharingChildren's Data
VAEnforcement Action

Social Media Platforms

Virginia Attorney General Jay Jones announced intent to enforce new provisions of the Virginia Consumer Data Protection Act that limit minors' social media usage to one hour per day without parental consent. The law, effective January 1, 2026, requires age verification and verifiable parental consent to change time limits, with potential penalties up to $7,500 per violation and injunctive relief. This follows a motion to dismiss a lawsuit by NetChoice challenging the law.

LowChildren's Data
FTCSettlement

Disney Worldwide Services, Inc. and Disney Entertainment Operations LLC(Disney)

The FTC settled with Disney for violating the COPPA Rule by mislabeling videos on YouTube, which allowed the collection of children's personal data without parental consent. Disney must pay a $10 million civil penalty and implement measures to ensure proper video labeling and compliance with COPPA.

HighChildren's DataConsent FailureNotice Failure

$10.0M

CTEnforcement ActionMultistate

Anthropic, Apple, Chai AI, Character Technologies, Google, Luka, Meta, Microsoft, Nomi AI, OpenAI, Perplexity AI, Replika, xAI(Anthropic)

A bipartisan coalition of 42 attorneys general sent a letter to major AI software companies demanding safeguards to protect users from harmful chatbot interactions. The letter cites multiple incidents of mental health struggles, self-harm, and deaths, particularly affecting children and vulnerable populations. Companies are asked to implement safety testing, recall procedures, and clear warnings by January 16, 2026.

LowAI/Automated DecisionsChildren's Data
TXEnforcement Action

Epic Systems Corporation(Epic Systems)

Texas Attorney General Ken Paxton filed a lawsuit against Epic Systems Corporation, a major electronic health records vendor, alleging unlawful monopolization of the EHR industry and deceptive practices that restrict parental access to minor children’s medical records. The privacy-related claim asserts Epic automatically hides children’s medication lists, treatment notes, and provider messages from parents when a child turns 12, violating Texas law guaranteeing parents unrestricted access to their children’s medical records. The action is part of broader efforts to ensure EHR vendors comply with Texas parental access requirements and promote market competition.

LowChildren's DataHealth Data
FLEnforcement Action

Roblox

Florida Attorney General James Uthmeier filed a lawsuit against Roblox, alleging that the company misrepresented the safety of its platform to parents and failed to protect children from accessing adult content and being contacted by predators. The lawsuit seeks injunctive relief and other remedies to ensure child safety on the platform.

LowChildren's DataSecurity Failure
CAEnforcement ActionMultistate

U.S. Department of Justice(Children's Hospital Colorado)

California Attorney General Rob Bonta joined 20 attorneys general in filing an amicus brief to quash a U.S. DOJ administrative subpoena seeking sensitive medical records and personally identifying information of adolescent patients receiving gender-affirming care at Children's Hospital Colorado. The brief argues the subpoena violates states' rights to regulate medicine under the Tenth Amendment and misinterprets the Food, Drug, and Cosmetic Act, which would harm off-label drug use across all medical fields.

LowHealth DataChildren's Data
FTCConsent Decree

Illuminate Education, Inc.(Illuminate Education)

The FTC proposed a consent order against Illuminate Education, Inc. for failing to secure student data, leading to a breach affecting over 10 million students. The company allegedly had security failures and delayed breach notifications. The order requires a data security program, data deletion, and a retention schedule.

LowSecurity FailureBreach Notification DelayStudent Data
CASettlement

Jam City, Inc.(Jam City)

California Attorney General Rob Bonta announced a $1.4 million settlement with Jam City, Inc. for violating the CCPA. The mobile gaming company failed to provide opt-out methods for the sale or sharing of personal information across its 21 apps and sold or shared data of children aged 13-16 without required affirmative consent. Jam City must now implement in-app opt-out mechanisms and obtain affirmative consent for minors' data.

HighOpt-Out FailureChildren's Data

$1.4M

CASettlement

Sling TV LLC and Dish Media Sales LLC(Sling TV)

California Attorney General Rob Bonta secured a $530,000 settlement with Sling TV for violating the CCPA. The company failed to provide an easy-to-use method for consumers to opt-out of the sale of their personal information and did not provide adequate privacy protections for children. The settlement requires Sling TV to implement specific changes to its opt-out mechanisms and parental controls.

MediumOpt-Out FailureChildren's Data

$530K

CASettlement

Sling TV LLC(Sling TV)

California Attorney General Rob Bonta settled with Sling TV for $530,000 over CCPA violations. Sling TV failed to provide an easy-to-use opt-out mechanism for the sale of personal information and lacked adequate privacy protections for children's data. The settlement requires Sling TV to implement changes to ensure CCPA compliance, including improved opt-out processes and children's privacy safeguards.

MediumOpt-Out FailureChildren's Data

$530K

CAEnforcement ActionMultistate

U.S. Department of Justice(Department of Justice)

California Attorney General Rob Bonta joined 15 attorneys general in filing an amicus brief to limit a U.S. DOJ subpoena seeking medical records of transgender youth from Children's Hospital of Philadelphia, arguing it violates patient privacy and could intimidate providers of gender-affirming care.

LowHealth DataChildren's Data
FLEnforcement Action

Roku, Inc.(Roku)

Florida Attorney General James Uthmeier filed a civil enforcement action against Roku, Inc. for violating the Florida Digital Bill of Rights (FDBOR) and Florida Deceptive and Unfair Trade Practices Act (FDUTPA). The complaint alleges Roku collected, sold, and enabled reidentification of children’s sensitive personal data, including viewing habits and voice recordings, without parental consent or meaningful notice to consumers. The state seeks civil penalties, injunctive relief, and requirements for Roku to implement transparent disclosures, lawful parental controls, and cease unauthorized processing of children’s data.

LowChildren's DataConsent FailureUnauthorized Data Sharing
TXSettlement

Austin Diagnostic Clinic

Texas Attorney General Ken Paxton secured a settlement agreement with Austin Diagnostic Clinic to end its policy of restricting parental access to children’s electronic health records. The agreement requires the clinic to provide parents with full, real-time access to their children’s medical information except where restricted by state or federal law, and the AG will monitor compliance.

LowChildren's DataHealth Data
FTCEnforcement Action

Iconic Hearts Holdings, Inc.(Iconic Hearts Holdings)

The FTC filed a complaint against Iconic Hearts Holdings, Inc., operator of the Sendit anonymous messaging app, for unlawfully collecting personal data from children in violation of COPPA, misleading users by sending messages from fake personas, and tricking consumers into paid subscriptions by falsely promising to reveal anonymous senders.

LowChildren's Data
NYEnforcement ActionMultistate

United States Department of Agriculture (USDA)

A coalition of 21 state attorneys general led by New York Attorney General Letitia James obtained a temporary restraining order from the District Court for the Northern District of California blocking the USDA from demanding personally identifiable information of all SNAP recipients, including Social Security numbers, home addresses, and immigration statuses. The lawsuit argued that the USDA’s demand violated federal and state laws prohibiting disclosure of SNAP data except in narrow circumstances, and that the data would be used for immigration enforcement against recipients. The order also prohibits the USDA from withholding SNAP funding from plaintiff states that refuse to comply with the data demand.

LowUnauthorized Data SharingChildren's Data
FLEnforcement Action

Gethins Limited, Toccata, Inc., Segpay Gateway LLC, Segregated Payments, Inc., D/B/A Segpay, Aylo Holdings USA Corp., Aylo Billings US Corp., Aylo Group Ltd, Nutaku Entertainment Ltd.(Gethins, Toccata, Segpay, Aylo, Nutaku)

Florida Attorney General James Uthmeier filed complaints against multiple pornography websites for violating Florida's age-verification law by not verifying users' ages, allowing children access to harmful material. The law requires such sites to implement age verification, and violations can result in fines up to $50,000 per violation. The complaints seek injunctions, civil penalties, and compliance with the law.

LowChildren's Data
FTCInvestigation

Alphabet, Inc.; Character Technologies, Inc.; Instagram, LLC; Meta Platforms, Inc.; OpenAI OpCo, LLC; Snap, Inc.; X.AI Corp.(Alphabet, Character Technologies, Instagram, Meta, OpenAI, Snap, X.AI)

The FTC issued 6(b) orders to seven technology companies to investigate the safety and privacy practices of their AI chatbots, particularly regarding impacts on children and teens. The inquiry focuses on compliance with children's privacy laws, data handling, and disclosures, requiring companies to provide information on these aspects.

LowChildren's DataNotice FailureConsent Failure

Explore Enforcement Data