Court Rules

Privacy Enforcement Tracker

1,506 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,506

Total Actions

16

Jurisdictions

$26.6B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
NYSettlementMultistate

Cal-Maine Foods, Versova/Centrum, and Hickman's Egg Ranch

New York Attorney General James announced a multistate settlement with three major egg producers for illegally coordinating to influence a daily egg price index, artificially inflating prices for consumers. The companies will deliver 53 million eggs to food banks and pay $3.3 million, along with adopting compliance measures.

HighSurveillance PricingUnauthorized Data Sharing

$3.3M

CTEnforcement ActionMultistate

Administration for Children and Families

Attorney General William Tong joined a coalition of 23 states and the District of Columbia in suing the Trump administration over policy changes by the Administration for Children and Families (ACF) that would allow broad sharing of TANF recipients' sensitive personal data across federal agencies and potentially private organizations. The lawsuit alleges violations of the Administrative Procedure Act and the Spending Clause, seeking to block the policy.

LowUnauthorized Data Sharing
COSettlementMultistate

Sandoz Inc.

Attorney General Phil Weiser joined a coalition of 43 states and territories announcing a $400 million settlement in principle with Sandoz Inc. to resolve allegations that the generic drug manufacturer engaged in conspiracies to artificially inflate and manipulate prices, reduce competition, and unreasonably restrain trade. Sandoz will pay approximately $469 million including previous settlements and agreed to meaningful reforms to ensure fair competition and compliance with antitrust laws.

CriticalUnauthorized Data Sharing

$400.0M

OREnforcement ActionMultistate

Administration for Children and Families (ACF)

Oregon Attorney General Dan Rayfield, joined by a coalition of 23 other states, the District of Columbia, and two governors, sued the Trump administration to block a new policy by the Administration for Children and Families (ACF) that would allow federal officials to access private records of millions of TANF recipients. The coalition argues the policy illegally shares sensitive personal data, including Social Security numbers and immigration status, with other federal agencies and private organizations, violating the Administrative Procedure Act and the Spending Clause. The lawsuit seeks to declare the policy illegal and block it from taking effect.

LowUnauthorized Data Sharing
NYEnforcement ActionMultistate

Administration for Children and Families

Attorney General Jennifer Davenport joined a coalition of 23 states and DC in suing the Trump Administration over policy changes by the Administration for Children and Families (ACF) that would allow broad sharing of TANF recipients' sensitive personal data with other federal agencies, including ICE. The lawsuit argues the policy violates the Administrative Procedure Act and the Spending Clause, and seeks to block its implementation.

LowUnauthorized Data Sharing
MNCoalitionMultistate

Administration for Children and Families (ACF)

Attorney General Ellison joined a coalition of 23 other states and DC to sue the Trump administration over a policy that would allow the Administration for Children and Families (ACF) to share sensitive TANF recipient data with other federal agencies. The lawsuit argues the policy violates the Administrative Procedure Act and the Spending Clause, and seeks to block its implementation.

LowUnauthorized Data Sharing
FTCEnforcement ActionMultistate

Hims & Hers

The FTC, along with Utah and California, filed a complaint against Hims & Hers alleging the telehealth provider shared consumers' sensitive health information with third-party advertising platforms without consent, and deceived consumers about billing and cancellation practices. The complaint alleges violations of the FTC Act and the Restore Online Shoppers' Confidence Act.

LowUnauthorized Data SharingConsent FailureDark Patterns
VACoalitionMultistate

U.S. Department of Homeland Security

Attorney General Jay Jones joined a coalition of 26 states to sue the Trump administration over unlawful conditions attached to counterterrorism and emergency funding. The conditions would require states to share voter data with DHS and assist in immigration enforcement, which the coalition argues violates the Administrative Procedure Act and the Spending Clause.

LowUnauthorized Data Sharing
COSettlementMultistate

Glenmark Pharmaceuticals

Attorney General Phil Weiser joined a bipartisan coalition of 48 states and territories in announcing a $29.6 million settlement with Glenmark Pharmaceuticals. The settlement resolves allegations that Glenmark participated in a widespread conspiracy to inflate prices, reduce competition, and restrain trade for numerous generic prescription drugs. Glenmark also agreed to cooperate in ongoing multistate litigation and implement internal reforms.

HighUnauthorized Data Sharing

$29.6M

MNSettlementMultistate

Deere & Company

Minnesota Attorney General Keith Ellison, along with the FTC and attorneys general of Arizona, Illinois, Michigan, and Wisconsin, settled an antitrust lawsuit against John Deere. The settlement requires Deere to provide farmers and independent repair providers with the same repair resources previously only available to authorized dealers for 10 years, and to pay $1 million in legal costs.

LowUnauthorized Data SharingNotice Failure

$1.0M

COSettlementMultistate

LivCor, LLC

Colorado Attorney General Phil Weiser, as part of a bipartisan coalition of nine attorneys general, announced a $7 million settlement with LivCor, LLC for its role in an algorithmic rent-fixing scheme. LivCor allegedly used RealPage's revenue management software to share and gather confidential pricing information with competing landlords, artificially inflating rental prices. The settlement requires LivCor to cease using such software, pay $7 million in penalties, and cooperate in ongoing litigation against RealPage.

HighSurveillance PricingUnauthorized Data Sharing

$7.0M

MNSettlementMultistate

LivCor, LLC

Attorney General Ellison, as part of a bipartisan coalition of nine attorneys general, announced a $7 million settlement with property management company LivCor, LLC. The settlement resolves allegations that LivCor used RealPage's revenue management system to illegally share and gather confidential pricing information with competing landlords, enabling them to keep rental prices artificially high. LivCor must cease using such software, refrain from sharing competitively sensitive information, establish an antitrust compliance program, and cooperate in ongoing litigation against RealPage.

HighSurveillance PricingUnauthorized Data Sharing

$7.0M

FTCSettlement

Cox Media Group

The FTC alleged that Cox Media Group (CMG), MindSift LLC, and 1010 Digital Works LLC deceived customers by falsely claiming to offer an AI-powered 'Active Listening' service that could target ads based on conversations captured from consumers' smart devices, and that consumers had opted into such targeting. In reality, the service did not use voice data and consumers had not consented. The companies agreed to pay a total of $930,000 and are prohibited from making misrepresentations about their services, voice data collection, and consumer consent.

MediumConsent FailureNotice FailureUnauthorized Data Sharing

$930K

TXInvestigation

Meta (formerly known as Facebook)

Texas Attorney General Ken Paxton launched an investigation into Meta's Meta AI Glasses over allegations of unlawful facial biometric data collection, deceptive privacy practices, and unauthorized sharing of user data with subcontractors. The investigation follows concerns that the glasses' always-on recording mode lacks proper user notice, planned facial recognition features would collect data without consent, and private user videos are accessed by third-party annotators in Kenya. The AG issued a Civil Investigative Demand to Meta to determine violations of Texas privacy laws.

LowBiometric DataConsent FailureUnauthorized Data Sharing
TXInvestigation

Meta

Texas Attorney General Ken Paxton launched an investigation into Meta regarding its Meta AI Glasses, alleging unlawful collection of facial biometric data, deceptive privacy representations, and unauthorized sharing of user data with subcontractors. The investigation follows concerns that the glasses’ always-on recording mode lacks proper notice, subcontractors access private user content including intimate moments, and Meta plans to deploy facial recognition technology to collect unsuspecting individuals’ facial geometry. The AG issued a Civil Investigative Demand to determine if Meta violated Texas law by deceptively misrepresenting its data use practices.

LowBiometric DataNotice FailureConsent Failure
CASettlementMultistate

General Motors

California Attorney General Rob Bonta, along with multiple district attorneys and the California Privacy Protection Agency, announced a $12.75 million settlement with General Motors for illegally selling hundreds of thousands of Californians' location and driving data to data brokers Verisk and LexisNexis without notice or consent. The settlement includes the largest CCPA penalty to date, a five-year ban on selling driving data to consumer reporting agencies, and requirements to delete retained data and implement a robust privacy program.

CriticalGeolocation DataUnauthorized Data SharingNotice Failure

$12.8M

TXInvestigation

Drone Nerds, LLC

Texas Attorney General Ken Paxton initiated an investigation into Drone Nerds, LLC over its partnership with CCP-affiliated Anzu Robotics, which markets drones with concealed surveillance capabilities and unauthorized data collection risks. Drone Nerds is accused of deceiving Texas consumers by misrepresenting Anzu’s ties to China and falsely claiming the drones are U.S.-based with secure privacy practices. The investigation is being conducted under the Texas Deceptive Trade Practices Act, with a Civil Investigative Demand issued to gather evidence of consumer deception and privacy violations.

LowSecurity FailureUnauthorized Data Sharing
FTCSettlement

Kochava, Inc. and Collective Data Solutions (CDS)

The FTC settled charges with data broker Kochava, Inc. and its subsidiary Collective Data Solutions (CDS) over allegations that they sold precise location data from hundreds of millions of mobile devices without consumer consent, enabling tracking of visits to sensitive locations like reproductive health clinics and places of worship. The settlement prohibits the companies from selling or sharing sensitive location data without affirmative express consumer consent, and imposes compliance requirements including a sensitive location data program, supplier consent assessments, incident reporting, and data retention schedules. No monetary penalty was imposed.

LowConsent FailureGeolocation DataUnauthorized Data Sharing
CPPASettlement

General Motors

CalPrivacy and the California Attorney General secured a $12.75 million settlement from General Motors for data sharing practices from connected vehicles. The settlement includes injunctive terms to change business practices.

CriticalUnauthorized Data Sharing

$12.8M

FTCSettlement

Humor Rainbow, Inc. and Match Group Americas

The FTC settled with Humor Rainbow, Inc. (operator of OkCupid) and Match Group Americas over allegations that OkCupid deceived users by sharing personal data including photos and location information with an unauthorized third party, contrary to its privacy policy promises to inform users and provide opt-out opportunities. The settlement permanently prohibits the companies from misrepresenting their data collection, use, disclosure, and privacy control practices. No monetary penalty was imposed.

LowOpt-Out FailureNotice FailureUnauthorized Data Sharing
OREnforcement ActionMultistate

Department of Education

Privacy enforcement action where Oregon AG and a coalition of 16 other states sue the Trump Administration to stop the Department of Education's new IPEDS data reporting requirements, arguing they jeopardize student privacy, lack proper definitions, and risk data errors and identification.

LowUnauthorized Data SharingNotice FailureSecurity Failure
CPPASettlement

PlayOn Sports

The California Privacy Protection Agency settled with PlayOn Sports for $1.10 million over CCPA violations, including failing to provide adequate opt-out mechanisms and improperly tracking users, particularly students. The company must implement proper opt-out methods, improve disclosures, and comply with children's data consent requirements.

HighOpt-Out FailureNotice FailureChildren's Data

$1.1M

ILEnforcement ActionMultistate

U.S. Department of Agriculture(USDA)

Attorney General Raoul secured a court order preventing the U.S. Department of Agriculture from collecting SNAP applicants' and recipients' personal data without an agreed-upon protocol that restricts sharing with unrelated entities like the Department of Homeland Security. The court found that the USDA's proposed protocol would violate federal law by allowing data use for immigration enforcement, contrary to the intended purpose of SNAP.

LowUnauthorized Data Sharing
MAEnforcement ActionMultistate

U.S. Department of Agriculture(USDA)

Massachusetts Attorney General Andrea Campbell secured a preliminary injunction from the U.S. District Court blocking the Trump Administration's USDA from cutting off SNAP funding to states that refuse to turn over personal data of SNAP applicants and recipients. The court found USDA's proposed data protocol unlawful because it allowed sharing data with entities unrelated to federal benefits administration.

LowUnauthorized Data Sharing
CAEnforcement Action

U.S. Department of Agriculture(USDA)

California Attorney General Rob Bonta secured a second preliminary injunction from the U.S. District Court for the Northern District of California blocking the Trump Administration's demand that states turn over personal data of SNAP applicants and recipients. The court found the USDA's proposed data protocol would allow sharing of state data with entities unrelated to federal benefits administration, violating federal law.

HighUnauthorized Data Sharing
HHSEnforcement Action

Commonwealth Care Alliance

Commonwealth Care Alliance (Health Plan, MA) reported a HIPAA breach affecting 634 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Paper/Films.

LowData BreachHealth DataUnauthorized Data Sharing
CANew Law

California Privacy Protection Agency (CalPrivacy)

CalPrivacy sponsored AB 2021, the Whistleblower Protection and Privacy Act, introduced by Assemblymember Pilar Schiavo. The bill establishes whistleblower protections under the CCPA, including an award program and anti-retaliation provisions, to encourage insiders to report privacy violations.

LowNotice FailureUnauthorized Data SharingConsent Failure
HHSEnforcement Action

Weill Cornell Medicine

Weill Cornell Medicine (Healthcare Provider, NY) reported a HIPAA breach affecting 516 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Electronic Medical Record.

LowData BreachHealth DataUnauthorized Data Sharing
TXEnforcement Action

Shein US Services LLC(Shein)

Texas Attorney General Ken Paxton filed a lawsuit against Shein US Services LLC for selling toxic products and exposing consumers' personal data to the Chinese Communist Party. The lawsuit seeks monetary penalties under the Texas Deceptive Trade Practices Act. This action is part of a broader effort to protect Texans from health risks and CCP influence.

LowUnauthorized Data Sharing
TXEnforcement Action

PDD Holdings, Inc. and WhaleCo Inc. d/b/a Temu

Texas Attorney General Ken Paxton filed a lawsuit against PDD Holdings, Inc. and WhaleCo Inc., doing business as Temu, for deceptive marketing and unlawful covert harvesting of Texans’ personal data that was exposed to the Chinese Communist Party. The suit alleges Temu functions as a 'trojan horse' e-commerce app that bypasses security protocols to create a backdoor into users’ private data, which is stored on servers in China. The lawsuit seeks monetary relief under the Texas Deceptive Trade Practices Act, including up to $10,000 per violation and up to $250,000 per violation targeting consumers aged 65 or older.

LowConsent FailureUnauthorized Data SharingSecurity Failure

Explore Enforcement Data