Skip to main content
Research asset · Official-source subset · Reviewed August 26, 2026

Privacy Enforcement Evidence Explorer

Search a curated subset of privacy, data-broker, and breach-related enforcement cases with government-source links for every row. The records are useful for understanding enforcement patterns; they are not a complete count of breaches, investigations, or regulatory actions.

Rahul Kandoriya
Written byRahul Kandoriya·Founder, OfflistMe·Last updated August 26, 2026
Scope and source boundary: The explorer uses the existing OfflistMe case registry, whose entries link to FTC, CFPB, FCC, or state-AG primary materials. A case can involve a breach without representing every breach reported to an agency. For health-sector breaches affecting 500 or more individuals, consult the separate HHS OCR Breach Portal.

Curated cases

26

All case categories

Breach-tagged cases

7

Derived from registry tags

Tagged category

7

breach across breach-tagged cases

Tagged category

2

financial-data across breach-tagged cases

Search official-source cases

Showing 26 of 26 curated cases in the current source set.

Government-source privacy and data-broker enforcement cases
RespondentAgency / dateCategoriesReliefSource
Avast LimitedFederal Trade Commission
2024-02-22
data-broker, deceptive-ad$16,500,000Government source
X-Mode Social, Inc.Federal Trade Commission
2024-01-09
location-data, data-brokerInjunctive onlyGovernment source
InMarket Media, LLCFederal Trade Commission
2024-01-18
location-data, data-broker, adtechInjunctive onlyGovernment source
Kochava, Inc.Federal Trade Commission (stipulated order entered June 2026)
2022-08-29
location-data, data-brokerInjunctive onlyGovernment source
BetterHelp, Inc.Federal Trade Commission
2023-03-02
health-data, mental-health, deceptive-ad$7,800,000Government source
GoodRx Holdings, Inc.Federal Trade Commission
2023-02-01
health-data$1,500,000Government source
Rite Aid CorporationFederal Trade Commission
2023-12-19
biometric, deceptive-adInjunctive onlyGovernment source
Facebook, Inc.Federal Trade Commission
2019-07-24
deceptive-ad, adtech$5,000,000,000Government source
Equifax, Inc.FTC, CFPB, 50 States, and DC
2019-07-22
breach, financial-data, data-brokerAt least $575,000,000; potentially up to $700,000,000Government source
Cerebral, Inc.Federal Trade Commission
2024-04-15
health-data, mental-health, dark-pattern$7,000,000Government source
Easy Healthcare Corporation (Premom)Federal Trade Commission
2023-05-17
health-data, childrens-data$200,000Government source
Flo Health, Inc.Federal Trade Commission
2021-01-13
health-dataInjunctive onlyGovernment source
Amazon.com, Inc.Federal Trade Commission
2023-05-31
childrens-data$25,000,000Government source
Ring LLCFederal Trade Commission
2023-05-31
deceptive-ad, breach$5,800,000Government source
Vizio, Inc.FTC and New Jersey Attorney General
2017-02-06
smart-tv, deceptive-ad$2,200,000Government source
Drizly, LLCFederal Trade Commission
2022-10-24
breachInjunctive onlyGovernment source
Chegg, Inc.Federal Trade Commission
2022-10-31
breachInjunctive onlyGovernment source
Residual Pumpkin Entity, LLC (formerly CafePress)Federal Trade Commission
2022-06-23
breach$500,000Government source
Twitter, Inc.Federal Trade Commission
2022-05-25
deceptive-ad, adtech$150,000,000Government source
Sephora USA, Inc.California Attorney General
2022-08-24
data-broker, adtech$1,200,000Government source
DoorDash, Inc.California Attorney General
2024-02-21
data-broker$375,000Government source
Healthline Media LLCCalifornia Attorney General
2025-07-01
health-data, adtech$1,550,000Government source
The Walt Disney CompanyCalifornia Attorney General
2026-02-11
adtech$2,750,000Government source
T-Mobile USA, Inc.Federal Communications Commission
2024-09-30
breach, financial-data$15,750,000Government source
Musical.ly (TikTok)Federal Trade Commission
2019-02-27
childrens-data$5,700,000Government source
23andMe, Inc.New York AG and 42 other state attorneys general
2026-07-14
genetic, breach, health-data$18,000,000Government source

Interpretation tools

These controls are explanatory simulations. They do not calculate liability, predict enforcement, or replace the official case documents linked in the registry.

How to interpret this asset

  • “Breach-tagged” is an OfflistMe editorial classification based on the case record; it is not an agency-wide breach count.
  • Monetary relief is the publicly announced amount represented in the source case record; injunctive-only cases are not assigned a zero-dollar “fine.”
  • Settlement or consent-order records are not automatically findings of liability. Read the linked government document for procedural posture and allegations.