Court Rules
All enforcement actions
SettlementHigh RiskMultistate

State AGs Settle Lenovo for $3.5M Over Unauthorized Data Interception

LenovoSeptember 5, 2017California Attorney General

Penalty Amount

$3,500,000

Summary

Lenovo preinstalled 'Visual Discovery' software on its computers that intercepted browsing data and broke encrypted connections without user consent, compromising security and privacy. The multi-state settlement imposes a $3.5 million penalty and requires Lenovo to implement disclosure, consent, opt-out, and security compliance measures.

Remedy

Lenovo must clearly disclose pre-installed advertising software operations, obtain affirmative consumer consent, provide effective opt-out and removal options, implement a software security compliance program, and undergo biennial third-party assessments for 20 years.

Monetary PenaltyConsent DecreeAudit RequirementCompliance Program

Contract Impact

In-house legal teams should review vendor agreements with software suppliers and manufacturing contracts to ensure clauses prohibit unauthorized data interception and encryption compromise. Customer agreements and end-user license agreements (EULAs) must be assessed for adequate disclosure of preinstalled software, explicit user consent for data collection, and clear opt-out mechanisms. Security clauses should mandate compliance with encryption standards and regular audits. Changes needed include adding specific consent requirements for data interception, prohibiting software that breaks encrypted connections, implementing transparent disclosure obligations, and incorporating settlement-mandated security compliance and audit rights.

Contract Search Terms

preinstalled softwarebrowsing data interceptionTLS/SSL interceptionuser consentopt-out mechanismdisclosure requirementssecurity complianceencrypted connection breaking

Violation Types

Entity Details

Entity

Lenovo

Industry

Technology

Multistate Coalition

Official Sources

Related Enforcement Actions

CA

California

Governor Newsom signed the Expanding Privacy Rights Act (SB 923), expanding CCPA deletion rights to cover personal information obtained from third parties and requiring online-only businesses to offer an online method for submitting privacy requests. The law takes effect January 1, 2027, and allows businesses to maintain suppression lists to help keep deleted information from being reacquired.

CA

California State Legislature

The California Privacy Protection Agency announced that the California State Legislature approved the Expanding Privacy Rights Act (SB 923), which expands the CCPA's right to delete to cover all non-exempt personal information a business holds about a consumer, including data originally collected from third parties. The bill also requires online-only businesses with a direct relationship to consumers to provide online methods, such as webforms, for submitting access, deletion, and correction requests, and expressly permits businesses to retain suppression lists so deleted information stays deleted. The bill, authored by Senator Becker and sponsored by CalPrivacy, now goes to the Governor for consideration.

CA

Meta Platforms, Inc.

A bipartisan coalition of 33 state attorneys general, led by Minnesota AG Keith Ellison, began trial against Meta Platforms, Inc., alleging the company knowingly designed and deployed harmful features on Facebook and Instagram that drive children and teens to use the platforms compulsively, while falsely assuring parents and the public that its platforms were safe for young users. The states also allege Meta illegally collected personal information from children under 13 without parental consent, violating COPPA. The trial opened before Judge Yvonne Gonzalez Rogers in the U.S. District Court for the Northern District of California, with the states seeking monetary penalties and injunctive relief.

CA

Paramount Skydance Corporation

A coalition of 12 state attorneys general, led by Colorado AG Phil Weiser, obtained a temporary restraining order from a federal court in California to halt the proposed $110 billion merger of Warner Bros. Discovery, Inc. by Paramount Skydance Corporation. The lawsuit alleges the merger violates Section 7 of the Clayton Act by substantially lessening competition in film distribution, anticipated blockbuster film distribution, and licensing cable TV channels.

CA

California Privacy Protection Agency

The California Privacy Protection Agency (CalPrivacy) joined a coalition of 18 Attorneys General and state agencies in opposing the proposed SECURE Data Act, a federal privacy bill that would preempt stronger state privacy laws like the CCPA. The coalition argues the bill would weaken consumer privacy protections, limit enforcement remedies, and undermine California's Delete Request and Opt-out Platform (DROP).

CA

Meta Platforms, Inc.

A bipartisan coalition of state attorneys general began trial against Meta Platforms, Inc., alleging the company knowingly designed addictive features on Facebook and Instagram that harm children and teens, deceived parents about platform safety, and illegally collected personal information from children under 13 without parental consent in violation of COPPA. The states seek monetary penalties, an injunction to stop unlawful practices, and other relief. The trial is being litigated in the U.S. District Court for the Northern District of California.