Skip to main content
Reference · Updated August 26, 2026

Privacy Enforcement Tracker

A curated reference of 26 selected FTC / FCC / multi-state / state-AG data-privacy cases with dedicated detail pages and government-source links, plus 28 California privacy actions and 37 selected GDPR fines. The source type is shown for each table: government detail pages for the federal set, the current California AG index for the California set, and CMS Law’s secondary tracker for the GDPR set. Totals are sums of the displayed rows, not agency-published totals: $5,836,825,000 federal + $1,035,725,000 California + €5,756,200,000 GDPR.

Rahul Kandoriya
Written byRahul Kandoriya·Founder, OfflistMe·Last updated August 26, 2026

FTC / FCC / Multi-state / State AG

26

$5,836,825,000 total

CCPA Enforcement

28

$1,035,725,000 total

Selected GDPR fines

37

€5,756,200,000 total

FTC, FCC, Multi-state, and State AG Data-Privacy Enforcement

Curated federal, multi-state, and state-AG data-privacy enforcement cases. Each row links to a detail page with key facts, injunctive terms, statute citations, and direct links to the primary-source government press release and consent order. Sources include ftc.gov, fcc.gov, and state AG press releases.

RespondentAgencyDateSettlementSummarySource
Avast LimitedFTC2024-02-22$16,500,000Avast, a popular antivirus vendor, sold consumers’ browsing data through its Jumpshot subsidiary without adequate notice or consent despite marketing its products as privacy-protecting.Government detail
X-Mode Social, Inc.FTC2024-01-09InjunctiveFirst-ever FTC order prohibiting a data broker from selling sensitive location data. X-Mode / Outlogic sold precise geolocation that could identify consumers’ visits to medical, reproductive-health, religious, and military locations.Government detail
InMarket Media, LLCFTC2024-01-18InjunctiveInMarket collected precise location data from at least 100 million devices, combined it with sensitive categories (religion, health), and sold it for advertising without adequate consumer consent.Government detail
Kochava, Inc.FTC2022-08-29InjunctiveFirst FTC lawsuit targeting a data broker for selling precise location data. FTC alleges Kochava sold geolocation tracing visits to reproductive-health clinics, addiction recovery centers, and places of worship.Government detail
BetterHelp, Inc.FTC2023-03-02$7,800,000Online counseling platform BetterHelp shared sensitive mental-health information of ~7 million consumers with Facebook, Snapchat, Pinterest, and Criteo for targeted advertising, despite promises it would not.Government detail
GoodRx Holdings, Inc.FTC2023-02-01$1,500,000Prescription drug discount platform GoodRx shared users’ prescription medication lists and personal health information with Facebook, Google, and other advertising companies.Government detail
Rite Aid CorporationFTC2023-12-19InjunctiveRite Aid deployed facial recognition technology in hundreds of stores that falsely identified consumers, disproportionately people of color and women, as shoplifters.Government detail
Facebook, Inc.FTC2019-07-24$5,000,000,000Largest-ever FTC civil penalty. Facebook paid $5 billion and accepted a 20-year consent order after the Cambridge Analytica incident and related privacy failures violated its 2012 FTC order.Government detail
Equifax, Inc.multi-state2019-07-22$575,000,000Equifax, one of the three US consumer credit bureaus, agreed to pay up to $700 million in connection with its 2017 breach that exposed personal information of ~147 million Americans.Government detail
Cerebral, Inc.FTC2024-04-15$7,000,000Online mental-health service Cerebral disclosed sensitive patient information to third parties including LinkedIn, Snapchat, and TikTok and used dark patterns to make canceling subscriptions difficult.Government detail
Easy Healthcare Corporation (Premom)FTC2023-05-17$200,000Fertility-tracking app Premom shared sensitive reproductive-health information, including pregnancy status, with AppsFlyer, Google, and Chinese firms without disclosure.Government detail
Flo Health, Inc.FTC2021-01-13InjunctiveMenstruation and fertility tracker Flo Health shared app-users’ pregnancy intent and period-cycle data with Facebook, Google, and analytics firms despite assurances of privacy.Government detail
Amazon.com, Inc.FTC2023-05-31$25,000,000Amazon kept children’s Alexa voice recordings indefinitely, used them to train its algorithms, and ignored parents’ deletion requests, violating COPPA.Government detail
Ring LLCFTC2023-05-31$5,800,000Ring let employees and contractors access customer video footage and failed to implement basic security controls, allowing attackers to hijack thousands of customer cameras.Government detail
Vizio, Inc.FTC2017-02-06$2,200,000Vizio installed tracking software on 11 million smart TVs that captured viewing data second-by-second and sold it, including linked demographic profiles, to advertisers without consumer knowledge.Government detail
Drizly, LLCFTC2022-10-24InjunctiveOnline alcohol-delivery platform Drizly exposed the personal data of about 2.5 million consumers in a 2020 breach after ignoring known security flaws. Precedent-setting case imposing personal obligations on the CEO.Government detail
Chegg, Inc.FTC2022-10-31InjunctiveOnline education company Chegg suffered four data breaches affecting ~40 million consumers and employees due to repeatedly inadequate security practices.Government detail
Residual Pumpkin Entity, LLC (formerly CafePress)FTC2022-06-23$500,000CafePress ignored a 2019 data breach, failed to notify 22 million users, and then falsely claimed to reset passwords that it was actually leaving unchanged.Government detail
Twitter, Inc.FTC2022-05-25$150,000,000Twitter used phone numbers and email addresses collected for account security to target advertising, the same practice that was supposed to end under its 2011 FTC order.Government detail
Sephora USA, Inc.state-AG2022-08-24$1,200,000First-ever public CCPA enforcement settlement. Sephora failed to disclose that it was selling personal information and did not honor Global Privacy Control opt-out signals.Government detail
DoorDash, Inc.state-AG2024-02-21$375,000First public enforcement action targeting a company’s participation in a marketing co-operative. DoorDash sold personal information via a marketing exchange without notifying consumers or providing an opt-out.Government detail
Healthline Media LLCstate-AG2025-07-01$1,550,000Health-information publisher Healthline shared article-reading data indicating users’ specific health conditions with advertisers without honoring opt-outs. Largest CCPA settlement at time of resolution.Government detail
The Walt Disney Companystate-AG2026-02-11$2,750,000The California Attorney General announced a $2.75 million civil-penalty settlement resolving allegations that Disney did not fully effectuate CCPA opt-out requests across the Disney+, Hulu, and ESPN+ services and devices associated with a consumer account.Government detail
T-Mobile USA, Inc.FCC2024-09-30$15,750,000T-Mobile entered an FCC consent decree resolving investigations into multiple data-breach incidents in 2021, 2022, and 2023 that affected millions of current, former, or prospective customers and some mobile-virtual-network-operator customers.Government detail
Musical.ly (TikTok)FTC2019-02-27$5,700,000Largest COPPA penalty at the time. Musical.ly (now TikTok) collected personal information from children under 13 without parental consent.Government detail
23andMe, Inc.multi-state2026-07-14$18,000,000A bipartisan coalition of 43 attorneys general secured an $18 million settlement from 23andMe over failures tied to its 2023 genetic-data breach and obtained additional data-protection requirements for the successor custodian of the data.Government detail

California CCPA & Privacy Enforcement

The displayed rows are transcribed from the California Attorney General’s Privacy Enforcement Actions index. The index is the source for the set, but it does not make every row a CCPA-only action; the table preserves broader privacy and consumer-protection matters.

EntityDateSettlementViolationSummarySource
General Motors2026-05-08$12,750,000CCPA / UCLSold California drivers’ location and driving data to data brokers; the settlement includes data-minimization, deletion, and five-year consumer-reporting-agency sales restrictions.CA AG index
Disney2026-02-11$2,750,000CCPAFailed to effectuate opt-out of sale requests across Disney+, Hulu, and ESPN+ devices.CA AG index
Jam City, Inc.2025-11-21$1,400,000CCPANo opt-out methods in apps; shared children’s data without parental consent.CA AG index
Illuminate Education2025-11-06$3,250,000KOPIPA / CA Privacy2021 data breach; failed security for student records.CA AG index
Sling TV LLC2025-10-30$530,000CCPAConfusing opt-out process; inadequate child privacy protections.CA AG index
Healthline Media LLC2025-07-01$1,550,000CCPATracked health information and shared sensitive data without safeguards.CA AG index
Tilting Point Media LLC2024-06-19$500,000CCPA / COPPACollected children’s data in mobile game without parental consent.CA AG index
Blackbaud2024-06-13$6,750,000Consumer Protection2020 data breach; inadequate security measures.CA AG index
DoorDash2024-02-21$375,000CCPA / CalOPPASold customer data via marketing co-operative without notice or opt-out opportunity. First public CCPA enforcement targeting marketing co-op data sales.CA AG index
Google2023-09-14$93,000,000Consumer ProtectionLocation tracking without consumer consent for ad profiling. Multi-state settlement; CA portion.CA AG index
Kaiser Foundation Health Plan2023-09-08$49,000,000Privacy / WasteImproperly disposed of medical waste and health records.CA AG index
Sephora2022-08-24$1,200,000CCPAFirst-ever public CCPA enforcement. Failed to disclose sales of personal information; ignored Global Privacy Control signals.CA AG index
Glow, Inc.2020-09-17$250,000CMIA / Data SecurityReproductive-health app lacked basic security protections for sensitive user data.CA AG index
Anthem Blue Cross Life and Health Insurance2020-09-30$8,690,000Consumer Protection2014 breach exposed data of 13.5 million Californians.CA AG index
Equifax2019-07-22$600,000,000Consumer Protection2017 breach exposed 15 million Californians. Multi-state settlement; includes CA portion.CA AG index
Premera Blue Cross2019-07-11$10,000,000Privacy Laws2014 phishing breach exposed 10.5 million consumers.CA AG index
Aetna2019-01-30$935,000Medical PrivacyMailing envelope revealed recipients’ HIV medication status.CA AG index
Uber Technologies2018-09-26$148,000,000Data Breach / Security2016 data breach covered up for over one year.CA AG index
Cottage Health System2017-11-22$2,000,000State / Federal PrivacyFailed safeguards for patient medical information.CA AG index
Lenovo2017-09-05$3,500,000Consumer ProtectionPre-installed ad-injecting software compromised security.CA AG index
Target2017-05-23$18,500,000Consumer Protection2013 POS breach compromised 40M+ payment cards.CA AG index
Wells Fargo Bank2016-03-28$8,500,000CA Penal Code PrivacyRecorded customer calls without timely disclosure.CA AG index
Houzz2015-10-02$175,000Privacy LawsRecorded calls without notifying all parties.CA AG index
Comcast2015-09-17$33,000,000Privacy LawPosted unlisted phone numbers online.CA AG index
Aaron’s, Inc.2014-10-13$28,400,000Consumer ProtectionInstalled spyware on rental computers.CA AG index
Kaiser Foundation Hospitals (USB incident)2014-01-23$150,000Data Breach NotificationDelayed notifying employees of lost USB drive.CA AG index
Citibank2013-08-28$420,000Data SecurityUnencrypted website vulnerability exposed customer accounts.CA AG index
Anthem Blue Cross2012-10-01$150,000Privacy LawSocial security numbers visible on mailing envelopes.CA AG index

Selected GDPR fines

Selected GDPR fines issued by EU and UK data protection authorities, transcribed from CMS Law’s GDPR Enforcement Tracker. This is a secondary, non-exhaustive snapshot; confirm any individual fine against the issuing authority before relying on it. The total below is only the sum of the displayed rows.

DefendantDPACountryFineYearViolationSource
Meta Platforms IrelandDPCIreland€1,200,000,0002023Unlawful data transfers of Facebook EU user data to the United States.CMS tracker
Amazon Europe CoreCNPDLuxembourg€746,000,0002021Tracking user data without appropriate consent for targeted advertising.CMS tracker
TikTokDPCIreland€530,000,0002024Transfers of EEA user data to China; inadequate transparency.CMS tracker
Instagram (Meta)DPCIreland€405,000,0002022Processing children’s data without legal basis; minors’ contact info public by default.CMS tracker
Meta Platforms IrelandDPCIreland€390,000,0002023Unclear legal basis for data processing; contract reliance instead of consent.CMS tracker
TikTok LimitedDPCIreland€345,000,0002023Collecting personal data of children under 13; automatically public profiles.CMS tracker
LinkedIn IrelandDPCIreland€310,000,0002024Behavioural advertising based on personal data without valid legal basis.CMS tracker
Uber TechnologiesAPNetherlands€290,000,0002024Unlawful personal-data transfers of EU drivers to US servers.CMS tracker
Meta (Facebook)DPCIreland€265,000,0002022Personal information dataset scraped and made publicly available.CMS tracker
WhatsApp IrelandDPCIreland€225,000,0002021Unclear privacy policies; transparency failures on data usage.CMS tracker
Google LLCCNILFrance€90,000,0002021Failing to provide easy cookie-refusal methods.CMS tracker
Google IrelandCNILFrance€60,000,0002021Difficult cookie-refusal mechanisms on YouTube.CMS tracker
Facebook Ireland Ltd.CNILFrance€60,000,0002021No simple methods to refuse cookies.CMS tracker
CRITEOCNILFrance€40,000,0002023Failing to ensure opt-in consent; inadequate user-rights information.CMS tracker
H&MHmbBfDIGermany€35,300,0002020Excessive employee records; family, religion, and health information tracked.CMS tracker
TIM (Telecom Italia)GaranteItaly€27,800,0002020Unlawful telemarketing calls; inadequate privacy policies.CMS tracker
Enel EnergiaGaranteItaly€26,500,0002022Unlawful customer data use for telemarketing without consent.CMS tracker
Clearview AIGaranteItaly€20,000,0002022Processing biometric and geolocation data without legal basis.CMS tracker
Clearview AICNILFrance€20,000,0002022Processing millions of personal data records; non-compliance with deletion orders.CMS tracker
Clearview AIHDPAGreece€20,000,0002022Collecting photos and selfies without consent.CMS tracker
Wind TreGaranteItaly€16,700,0002020Telemarketing calls and texts without consent; public data disclosure.CMS tracker
Meta Platforms IrelandDPCIreland€17,000,0002022Inadequate technical measures for 2018 data breaches.CMS tracker
TikTokICOUnited Kingdom€14,500,0002023Collecting data from children under 13 without parental consent.CMS tracker
Vodafone ItaliaGaranteItaly€12,250,0002020Marketing calls without consent; continued contact after opt-out.CMS tracker
Eni Gas e LuceGaranteItaly€11,500,0002019Customer data storage without legal basis; unsolicited telemarketing.CMS tracker
Google LLCAEPDSpain€10,000,0002022Unlawful EU citizen data transfers; complicated right-to-be-forgotten process.CMS tracker
Clearview AI Inc.ICOUnited Kingdom€8,750,0002022Collecting facial recognition images without lawful basis.CMS tracker
REWE InternationalDSBAustria€8,000,0002022Loyalty program data collection without user consent.CMS tracker
GrindrDatatilsynetNorway€6,300,0002021Sharing sensitive personal data (sexual orientation) to advertisers without consent.CMS tracker
Cosmote Mobile TelecommunicationsHDPAGreece€6,000,0002022Data breach exposure; inadequate pseudonymization.CMS tracker
CaixaBankAEPDSpain€6,000,0002021Invalid consent methods; unlawful data transfers to third parties.CMS tracker
Meta Platforms Ireland (2018 breach)DPCIreland€251,000,00020242018 data breach re-finalisation; improper breach notification and poor system design.CMS tracker
Meta (plaintext passwords)DPCIreland€91,000,0002024Storing hundreds of millions of Facebook and Instagram user passwords in plaintext.CMS tracker
Enel Energia SpAGaranteItaly€79,100,0002024Unlawful customer data acquisition by sales partners; inadequate security controls.CMS tracker
Google LLCCNILFrance€50,000,0002019Lack of transparency and invalid consent for ad personalisation, first major GDPR fine against Big Tech.CMS tracker
Amazon France LogistiqueCNILFrance€32,000,0002024Excessive worker monitoring system; unlawful retention of warehouse-worker productivity data.CMS tracker
Clearview AIAPNetherlands€30,500,0002024Illegal facial image scraping of Dutch residents without consent.CMS tracker

Generate requests in under 60 seconds

Generate requests proactively for $9

Enforcement examples do not guarantee a private claim or removal outcome. Review the current privacy route that applies to your situation; OfflistMe prepares request drafts, and you send from your own inbox.

FAQ

What is the largest CCPA settlement to date?+

As of August 26, 2026, the current California Attorney General index lists General Motors’ $12.75 million May 2026 settlement as its largest CCPA penalty to date. The index also lists Disney’s $2.75 million February 2026 CCPA settlement; the earlier Disney release’s “largest” wording was superseded by the later GM action. The index includes broader privacy, consumer-protection, and multi-state matters, so this is not a ranking of every privacy settlement in every jurisdiction. Source: California AG enforcement index

What is the largest GDPR fine ever?+

The selected CMS tracker data used on this page lists Meta Platforms Ireland’s €1.2 billion DPC decision (2023) above Amazon Europe’s €746 million decision (2021). “Largest ever” depends on the tracker’s scope and later decisions; this page is not a complete ranking, so confirm the current tracker and issuing authority before relying on it. Source: CMS Law GDPR Enforcement Tracker

Can individuals receive money from CCPA enforcement?+

Individuals generally do not receive CCPA enforcement penalties directly. The CCPA private right of action is narrow and concerns certain data-breach claims; other enforcement and administrative remedies are pursued by government authorities under the applicable law and judgment. Other state laws differ, so do not generalize from the CCPA. Source: California Privacy Protection Agency CCPA FAQ

Which countries issue the most GDPR fines?+

There is no stable answer without a defined time window and dataset. The selected rows on this page include many Irish DPC decisions because major technology-company cases appear there, but the page does not calculate country-wide totals or counts and is not a global ranking. Use the current tracker and issuing-authority decisions for a comparable answer. Source: CMS Law GDPR Enforcement Tracker

Source and status boundary

Reviewed August 26, 2026. The California table follows the current Attorney General index and includes CCPA, consumer-protection, privacy, and multi-state matters; displayed amounts are the amounts recorded by that index, not necessarily California’s share. The federal table links selected detail pages and government materials; its row-level source dates are maintained on those detail pages and are not all reverified on this page’s review date. The GDPR table is a selected secondary snapshot, not a complete or permanently current ranking. Entries describe allegations, settlements, judgments, consent decrees, or fines according to the cited source; inclusion is not an independent finding of liability. Totals sum displayed rows and should not be compared as agency-wide totals.

Primary references: California AG Privacy Enforcement Actions, General Motors settlement, FTC press releases, FCC enforcement, and the CMS GDPR tracker.

Sources: California Attorney General Privacy Enforcement Actions · CMS Law GDPR Enforcement Tracker. Settlement amounts reflect publicly reported figures; multi-state settlements may include California’s share. Reviewed August 26, 2026.