Privacy Enforcement Tracker
A curated reference of 26 selected FTC / FCC / multi-state / state-AG data-privacy cases with dedicated detail pages and government-source links, plus 28 California privacy actions and 37 selected GDPR fines. The source type is shown for each table: government detail pages for the federal set, the current California AG index for the California set, and CMS Law’s secondary tracker for the GDPR set. Totals are sums of the displayed rows, not agency-published totals: $5,836,825,000 federal + $1,035,725,000 California + €5,756,200,000 GDPR.
FTC / FCC / Multi-state / State AG
26
$5,836,825,000 total
CCPA Enforcement
28
$1,035,725,000 total
Selected GDPR fines
37
€5,756,200,000 total
FTC, FCC, Multi-state, and State AG Data-Privacy Enforcement
Curated federal, multi-state, and state-AG data-privacy enforcement cases. Each row links to a detail page with key facts, injunctive terms, statute citations, and direct links to the primary-source government press release and consent order. Sources include ftc.gov, fcc.gov, and state AG press releases.
| Respondent | Agency | Date | Settlement | Summary | Source |
|---|---|---|---|---|---|
| Avast Limited | FTC | 2024-02-22 | $16,500,000 | Avast, a popular antivirus vendor, sold consumers’ browsing data through its Jumpshot subsidiary without adequate notice or consent despite marketing its products as privacy-protecting. | Government detail |
| X-Mode Social, Inc. | FTC | 2024-01-09 | Injunctive | First-ever FTC order prohibiting a data broker from selling sensitive location data. X-Mode / Outlogic sold precise geolocation that could identify consumers’ visits to medical, reproductive-health, religious, and military locations. | Government detail |
| InMarket Media, LLC | FTC | 2024-01-18 | Injunctive | InMarket collected precise location data from at least 100 million devices, combined it with sensitive categories (religion, health), and sold it for advertising without adequate consumer consent. | Government detail |
| Kochava, Inc. | FTC | 2022-08-29 | Injunctive | First FTC lawsuit targeting a data broker for selling precise location data. FTC alleges Kochava sold geolocation tracing visits to reproductive-health clinics, addiction recovery centers, and places of worship. | Government detail |
| BetterHelp, Inc. | FTC | 2023-03-02 | $7,800,000 | Online counseling platform BetterHelp shared sensitive mental-health information of ~7 million consumers with Facebook, Snapchat, Pinterest, and Criteo for targeted advertising, despite promises it would not. | Government detail |
| GoodRx Holdings, Inc. | FTC | 2023-02-01 | $1,500,000 | Prescription drug discount platform GoodRx shared users’ prescription medication lists and personal health information with Facebook, Google, and other advertising companies. | Government detail |
| Rite Aid Corporation | FTC | 2023-12-19 | Injunctive | Rite Aid deployed facial recognition technology in hundreds of stores that falsely identified consumers, disproportionately people of color and women, as shoplifters. | Government detail |
| Facebook, Inc. | FTC | 2019-07-24 | $5,000,000,000 | Largest-ever FTC civil penalty. Facebook paid $5 billion and accepted a 20-year consent order after the Cambridge Analytica incident and related privacy failures violated its 2012 FTC order. | Government detail |
| Equifax, Inc. | multi-state | 2019-07-22 | $575,000,000 | Equifax, one of the three US consumer credit bureaus, agreed to pay up to $700 million in connection with its 2017 breach that exposed personal information of ~147 million Americans. | Government detail |
| Cerebral, Inc. | FTC | 2024-04-15 | $7,000,000 | Online mental-health service Cerebral disclosed sensitive patient information to third parties including LinkedIn, Snapchat, and TikTok and used dark patterns to make canceling subscriptions difficult. | Government detail |
| Easy Healthcare Corporation (Premom) | FTC | 2023-05-17 | $200,000 | Fertility-tracking app Premom shared sensitive reproductive-health information, including pregnancy status, with AppsFlyer, Google, and Chinese firms without disclosure. | Government detail |
| Flo Health, Inc. | FTC | 2021-01-13 | Injunctive | Menstruation and fertility tracker Flo Health shared app-users’ pregnancy intent and period-cycle data with Facebook, Google, and analytics firms despite assurances of privacy. | Government detail |
| Amazon.com, Inc. | FTC | 2023-05-31 | $25,000,000 | Amazon kept children’s Alexa voice recordings indefinitely, used them to train its algorithms, and ignored parents’ deletion requests, violating COPPA. | Government detail |
| Ring LLC | FTC | 2023-05-31 | $5,800,000 | Ring let employees and contractors access customer video footage and failed to implement basic security controls, allowing attackers to hijack thousands of customer cameras. | Government detail |
| Vizio, Inc. | FTC | 2017-02-06 | $2,200,000 | Vizio installed tracking software on 11 million smart TVs that captured viewing data second-by-second and sold it, including linked demographic profiles, to advertisers without consumer knowledge. | Government detail |
| Drizly, LLC | FTC | 2022-10-24 | Injunctive | Online alcohol-delivery platform Drizly exposed the personal data of about 2.5 million consumers in a 2020 breach after ignoring known security flaws. Precedent-setting case imposing personal obligations on the CEO. | Government detail |
| Chegg, Inc. | FTC | 2022-10-31 | Injunctive | Online education company Chegg suffered four data breaches affecting ~40 million consumers and employees due to repeatedly inadequate security practices. | Government detail |
| Residual Pumpkin Entity, LLC (formerly CafePress) | FTC | 2022-06-23 | $500,000 | CafePress ignored a 2019 data breach, failed to notify 22 million users, and then falsely claimed to reset passwords that it was actually leaving unchanged. | Government detail |
| Twitter, Inc. | FTC | 2022-05-25 | $150,000,000 | Twitter used phone numbers and email addresses collected for account security to target advertising, the same practice that was supposed to end under its 2011 FTC order. | Government detail |
| Sephora USA, Inc. | state-AG | 2022-08-24 | $1,200,000 | First-ever public CCPA enforcement settlement. Sephora failed to disclose that it was selling personal information and did not honor Global Privacy Control opt-out signals. | Government detail |
| DoorDash, Inc. | state-AG | 2024-02-21 | $375,000 | First public enforcement action targeting a company’s participation in a marketing co-operative. DoorDash sold personal information via a marketing exchange without notifying consumers or providing an opt-out. | Government detail |
| Healthline Media LLC | state-AG | 2025-07-01 | $1,550,000 | Health-information publisher Healthline shared article-reading data indicating users’ specific health conditions with advertisers without honoring opt-outs. Largest CCPA settlement at time of resolution. | Government detail |
| The Walt Disney Company | state-AG | 2026-02-11 | $2,750,000 | The California Attorney General announced a $2.75 million civil-penalty settlement resolving allegations that Disney did not fully effectuate CCPA opt-out requests across the Disney+, Hulu, and ESPN+ services and devices associated with a consumer account. | Government detail |
| T-Mobile USA, Inc. | FCC | 2024-09-30 | $15,750,000 | T-Mobile entered an FCC consent decree resolving investigations into multiple data-breach incidents in 2021, 2022, and 2023 that affected millions of current, former, or prospective customers and some mobile-virtual-network-operator customers. | Government detail |
| Musical.ly (TikTok) | FTC | 2019-02-27 | $5,700,000 | Largest COPPA penalty at the time. Musical.ly (now TikTok) collected personal information from children under 13 without parental consent. | Government detail |
| 23andMe, Inc. | multi-state | 2026-07-14 | $18,000,000 | A bipartisan coalition of 43 attorneys general secured an $18 million settlement from 23andMe over failures tied to its 2023 genetic-data breach and obtained additional data-protection requirements for the successor custodian of the data. | Government detail |
California CCPA & Privacy Enforcement
The displayed rows are transcribed from the California Attorney General’s Privacy Enforcement Actions index. The index is the source for the set, but it does not make every row a CCPA-only action; the table preserves broader privacy and consumer-protection matters.
| Entity | Date | Settlement | Violation | Summary | Source |
|---|---|---|---|---|---|
| General Motors | 2026-05-08 | $12,750,000 | CCPA / UCL | Sold California drivers’ location and driving data to data brokers; the settlement includes data-minimization, deletion, and five-year consumer-reporting-agency sales restrictions. | CA AG index |
| Disney | 2026-02-11 | $2,750,000 | CCPA | Failed to effectuate opt-out of sale requests across Disney+, Hulu, and ESPN+ devices. | CA AG index |
| Jam City, Inc. | 2025-11-21 | $1,400,000 | CCPA | No opt-out methods in apps; shared children’s data without parental consent. | CA AG index |
| Illuminate Education | 2025-11-06 | $3,250,000 | KOPIPA / CA Privacy | 2021 data breach; failed security for student records. | CA AG index |
| Sling TV LLC | 2025-10-30 | $530,000 | CCPA | Confusing opt-out process; inadequate child privacy protections. | CA AG index |
| Healthline Media LLC | 2025-07-01 | $1,550,000 | CCPA | Tracked health information and shared sensitive data without safeguards. | CA AG index |
| Tilting Point Media LLC | 2024-06-19 | $500,000 | CCPA / COPPA | Collected children’s data in mobile game without parental consent. | CA AG index |
| Blackbaud | 2024-06-13 | $6,750,000 | Consumer Protection | 2020 data breach; inadequate security measures. | CA AG index |
| DoorDash | 2024-02-21 | $375,000 | CCPA / CalOPPA | Sold customer data via marketing co-operative without notice or opt-out opportunity. First public CCPA enforcement targeting marketing co-op data sales. | CA AG index |
| 2023-09-14 | $93,000,000 | Consumer Protection | Location tracking without consumer consent for ad profiling. Multi-state settlement; CA portion. | CA AG index | |
| Kaiser Foundation Health Plan | 2023-09-08 | $49,000,000 | Privacy / Waste | Improperly disposed of medical waste and health records. | CA AG index |
| Sephora | 2022-08-24 | $1,200,000 | CCPA | First-ever public CCPA enforcement. Failed to disclose sales of personal information; ignored Global Privacy Control signals. | CA AG index |
| Glow, Inc. | 2020-09-17 | $250,000 | CMIA / Data Security | Reproductive-health app lacked basic security protections for sensitive user data. | CA AG index |
| Anthem Blue Cross Life and Health Insurance | 2020-09-30 | $8,690,000 | Consumer Protection | 2014 breach exposed data of 13.5 million Californians. | CA AG index |
| Equifax | 2019-07-22 | $600,000,000 | Consumer Protection | 2017 breach exposed 15 million Californians. Multi-state settlement; includes CA portion. | CA AG index |
| Premera Blue Cross | 2019-07-11 | $10,000,000 | Privacy Laws | 2014 phishing breach exposed 10.5 million consumers. | CA AG index |
| Aetna | 2019-01-30 | $935,000 | Medical Privacy | Mailing envelope revealed recipients’ HIV medication status. | CA AG index |
| Uber Technologies | 2018-09-26 | $148,000,000 | Data Breach / Security | 2016 data breach covered up for over one year. | CA AG index |
| Cottage Health System | 2017-11-22 | $2,000,000 | State / Federal Privacy | Failed safeguards for patient medical information. | CA AG index |
| Lenovo | 2017-09-05 | $3,500,000 | Consumer Protection | Pre-installed ad-injecting software compromised security. | CA AG index |
| Target | 2017-05-23 | $18,500,000 | Consumer Protection | 2013 POS breach compromised 40M+ payment cards. | CA AG index |
| Wells Fargo Bank | 2016-03-28 | $8,500,000 | CA Penal Code Privacy | Recorded customer calls without timely disclosure. | CA AG index |
| Houzz | 2015-10-02 | $175,000 | Privacy Laws | Recorded calls without notifying all parties. | CA AG index |
| Comcast | 2015-09-17 | $33,000,000 | Privacy Law | Posted unlisted phone numbers online. | CA AG index |
| Aaron’s, Inc. | 2014-10-13 | $28,400,000 | Consumer Protection | Installed spyware on rental computers. | CA AG index |
| Kaiser Foundation Hospitals (USB incident) | 2014-01-23 | $150,000 | Data Breach Notification | Delayed notifying employees of lost USB drive. | CA AG index |
| Citibank | 2013-08-28 | $420,000 | Data Security | Unencrypted website vulnerability exposed customer accounts. | CA AG index |
| Anthem Blue Cross | 2012-10-01 | $150,000 | Privacy Law | Social security numbers visible on mailing envelopes. | CA AG index |
Selected GDPR fines
Selected GDPR fines issued by EU and UK data protection authorities, transcribed from CMS Law’s GDPR Enforcement Tracker. This is a secondary, non-exhaustive snapshot; confirm any individual fine against the issuing authority before relying on it. The total below is only the sum of the displayed rows.
| Defendant | DPA | Country | Fine | Year | Violation | Source |
|---|---|---|---|---|---|---|
| Meta Platforms Ireland | DPC | Ireland | €1,200,000,000 | 2023 | Unlawful data transfers of Facebook EU user data to the United States. | CMS tracker |
| Amazon Europe Core | CNPD | Luxembourg | €746,000,000 | 2021 | Tracking user data without appropriate consent for targeted advertising. | CMS tracker |
| TikTok | DPC | Ireland | €530,000,000 | 2024 | Transfers of EEA user data to China; inadequate transparency. | CMS tracker |
| Instagram (Meta) | DPC | Ireland | €405,000,000 | 2022 | Processing children’s data without legal basis; minors’ contact info public by default. | CMS tracker |
| Meta Platforms Ireland | DPC | Ireland | €390,000,000 | 2023 | Unclear legal basis for data processing; contract reliance instead of consent. | CMS tracker |
| TikTok Limited | DPC | Ireland | €345,000,000 | 2023 | Collecting personal data of children under 13; automatically public profiles. | CMS tracker |
| LinkedIn Ireland | DPC | Ireland | €310,000,000 | 2024 | Behavioural advertising based on personal data without valid legal basis. | CMS tracker |
| Uber Technologies | AP | Netherlands | €290,000,000 | 2024 | Unlawful personal-data transfers of EU drivers to US servers. | CMS tracker |
| Meta (Facebook) | DPC | Ireland | €265,000,000 | 2022 | Personal information dataset scraped and made publicly available. | CMS tracker |
| WhatsApp Ireland | DPC | Ireland | €225,000,000 | 2021 | Unclear privacy policies; transparency failures on data usage. | CMS tracker |
| Google LLC | CNIL | France | €90,000,000 | 2021 | Failing to provide easy cookie-refusal methods. | CMS tracker |
| Google Ireland | CNIL | France | €60,000,000 | 2021 | Difficult cookie-refusal mechanisms on YouTube. | CMS tracker |
| Facebook Ireland Ltd. | CNIL | France | €60,000,000 | 2021 | No simple methods to refuse cookies. | CMS tracker |
| CRITEO | CNIL | France | €40,000,000 | 2023 | Failing to ensure opt-in consent; inadequate user-rights information. | CMS tracker |
| H&M | HmbBfDI | Germany | €35,300,000 | 2020 | Excessive employee records; family, religion, and health information tracked. | CMS tracker |
| TIM (Telecom Italia) | Garante | Italy | €27,800,000 | 2020 | Unlawful telemarketing calls; inadequate privacy policies. | CMS tracker |
| Enel Energia | Garante | Italy | €26,500,000 | 2022 | Unlawful customer data use for telemarketing without consent. | CMS tracker |
| Clearview AI | Garante | Italy | €20,000,000 | 2022 | Processing biometric and geolocation data without legal basis. | CMS tracker |
| Clearview AI | CNIL | France | €20,000,000 | 2022 | Processing millions of personal data records; non-compliance with deletion orders. | CMS tracker |
| Clearview AI | HDPA | Greece | €20,000,000 | 2022 | Collecting photos and selfies without consent. | CMS tracker |
| Wind Tre | Garante | Italy | €16,700,000 | 2020 | Telemarketing calls and texts without consent; public data disclosure. | CMS tracker |
| Meta Platforms Ireland | DPC | Ireland | €17,000,000 | 2022 | Inadequate technical measures for 2018 data breaches. | CMS tracker |
| TikTok | ICO | United Kingdom | €14,500,000 | 2023 | Collecting data from children under 13 without parental consent. | CMS tracker |
| Vodafone Italia | Garante | Italy | €12,250,000 | 2020 | Marketing calls without consent; continued contact after opt-out. | CMS tracker |
| Eni Gas e Luce | Garante | Italy | €11,500,000 | 2019 | Customer data storage without legal basis; unsolicited telemarketing. | CMS tracker |
| Google LLC | AEPD | Spain | €10,000,000 | 2022 | Unlawful EU citizen data transfers; complicated right-to-be-forgotten process. | CMS tracker |
| Clearview AI Inc. | ICO | United Kingdom | €8,750,000 | 2022 | Collecting facial recognition images without lawful basis. | CMS tracker |
| REWE International | DSB | Austria | €8,000,000 | 2022 | Loyalty program data collection without user consent. | CMS tracker |
| Grindr | Datatilsynet | Norway | €6,300,000 | 2021 | Sharing sensitive personal data (sexual orientation) to advertisers without consent. | CMS tracker |
| Cosmote Mobile Telecommunications | HDPA | Greece | €6,000,000 | 2022 | Data breach exposure; inadequate pseudonymization. | CMS tracker |
| CaixaBank | AEPD | Spain | €6,000,000 | 2021 | Invalid consent methods; unlawful data transfers to third parties. | CMS tracker |
| Meta Platforms Ireland (2018 breach) | DPC | Ireland | €251,000,000 | 2024 | 2018 data breach re-finalisation; improper breach notification and poor system design. | CMS tracker |
| Meta (plaintext passwords) | DPC | Ireland | €91,000,000 | 2024 | Storing hundreds of millions of Facebook and Instagram user passwords in plaintext. | CMS tracker |
| Enel Energia SpA | Garante | Italy | €79,100,000 | 2024 | Unlawful customer data acquisition by sales partners; inadequate security controls. | CMS tracker |
| Google LLC | CNIL | France | €50,000,000 | 2019 | Lack of transparency and invalid consent for ad personalisation, first major GDPR fine against Big Tech. | CMS tracker |
| Amazon France Logistique | CNIL | France | €32,000,000 | 2024 | Excessive worker monitoring system; unlawful retention of warehouse-worker productivity data. | CMS tracker |
| Clearview AI | AP | Netherlands | €30,500,000 | 2024 | Illegal facial image scraping of Dutch residents without consent. | CMS tracker |
Generate requests in under 60 seconds
Generate requests proactively for $9
FAQ
What is the largest CCPA settlement to date?+
As of August 26, 2026, the current California Attorney General index lists General Motors’ $12.75 million May 2026 settlement as its largest CCPA penalty to date. The index also lists Disney’s $2.75 million February 2026 CCPA settlement; the earlier Disney release’s “largest” wording was superseded by the later GM action. The index includes broader privacy, consumer-protection, and multi-state matters, so this is not a ranking of every privacy settlement in every jurisdiction. Source: California AG enforcement index
What is the largest GDPR fine ever?+
The selected CMS tracker data used on this page lists Meta Platforms Ireland’s €1.2 billion DPC decision (2023) above Amazon Europe’s €746 million decision (2021). “Largest ever” depends on the tracker’s scope and later decisions; this page is not a complete ranking, so confirm the current tracker and issuing authority before relying on it. Source: CMS Law GDPR Enforcement Tracker
Can individuals receive money from CCPA enforcement?+
Individuals generally do not receive CCPA enforcement penalties directly. The CCPA private right of action is narrow and concerns certain data-breach claims; other enforcement and administrative remedies are pursued by government authorities under the applicable law and judgment. Other state laws differ, so do not generalize from the CCPA. Source: California Privacy Protection Agency CCPA FAQ
Which countries issue the most GDPR fines?+
There is no stable answer without a defined time window and dataset. The selected rows on this page include many Irish DPC decisions because major technology-company cases appear there, but the page does not calculate country-wide totals or counts and is not a global ranking. Use the current tracker and issuing-authority decisions for a comparable answer. Source: CMS Law GDPR Enforcement Tracker
Source and status boundary
Reviewed August 26, 2026. The California table follows the current Attorney General index and includes CCPA, consumer-protection, privacy, and multi-state matters; displayed amounts are the amounts recorded by that index, not necessarily California’s share. The federal table links selected detail pages and government materials; its row-level source dates are maintained on those detail pages and are not all reverified on this page’s review date. The GDPR table is a selected secondary snapshot, not a complete or permanently current ranking. Entries describe allegations, settlements, judgments, consent decrees, or fines according to the cited source; inclusion is not an independent finding of liability. Totals sum displayed rows and should not be compared as agency-wide totals.
Primary references: California AG Privacy Enforcement Actions, General Motors settlement, FTC press releases, FCC enforcement, and the CMS GDPR tracker.
Sources: California Attorney General Privacy Enforcement Actions · CMS Law GDPR Enforcement Tracker. Settlement amounts reflect publicly reported figures; multi-state settlements may include California’s share. Reviewed August 26, 2026.
