Penalty Amount
$1,250,000
Consumers Affected
180,000
Connecticut, co-leading a multistate investigation, secured a $1.25 million settlement with Carnival Cruise Line over a 2019 data breach affecting approximately 180,000 individuals nationwide. The breach exposed sensitive data including passport numbers, driver's licenses, payment card information, and health data, with a 10-month delay in notification. Carnival agreed to implement enhanced email security measures, a breach response plan, and an independent security assessment.
Carnival must implement and maintain a breach response and notification plan, provide email security training with dedicated phishing exercises, enable multi-factor authentication for remote email access, enforce strong password policies, maintain enhanced behavior analytics tools for network monitoring, and undergo an independent information security assessment.
In-house legal teams should review vendor agreements (especially those involving data processing or sharing), customer privacy policies, and employee data handling agreements. Key clauses to scrutinize include data security provisions (particularly email account protections), breach notification timelines (to avoid delays like the 10-month lapse), data retention and disposal policies (for unstructured data like emails), and audit rights for security assessments. Changes may be needed to mandate specific email security measures (e.g., multi-factor authentication, encryption), require prompt breach notification (e.g., within 72 hours), implement regular independent security audits, enhance data inventory practices for unstructured data, and ensure compliance with all applicable state breach notification laws.
Entity
Carnival Cruise Line
Industry
Other$1.3M
New Jersey, as part of a multistate coalition, settled with Carnival Cruise Line over a 2019 data breach that compromised personal information of approximately 180,000 employees and customers nationwide. The breach resulted from deficiencies in Carnival's data security program and delayed breach notification. Carnival will pay $1.25 million and implement enhanced email security and breach response measures.
Connecticut Attorney General William Tong joined a coalition of states and local governments in filing suit against NHTSA over its rule weakening fuel economy standards for new passenger cars and light trucks. The lawsuit alleges the rule violates the agency’s statutory mandate and the Administrative Procedure Act; no penalty or final remedy is reported.
Connecticut Attorney General William Tong joined a multistate coalition suing the EPA over its repeal of greenhouse gas pollution limits for power plants and separately filed a notice of intent to sue over regulation of existing gas plants. The coalition asks the court to overturn the repeal and restore the protections; the release reports no monetary penalty or final order.
$400.0M
Connecticut Attorney General William Tong announced a $400 million settlement with Sandoz Inc. and Fougera Pharmaceuticals Inc. resolving allegations that the generic drug manufacturers conspired to inflate prices, limit competition, and restrain trade. The settlement includes consumer restitution and injunctive reforms; court approval was being sought.
Connecticut Attorney General William Tong joined a coalition of 21 attorneys general in submitting a comment letter opposing a DHS rule that allows certain affirmative asylum applications to be referred to removal proceedings without an asylum officer interview. The coalition argues the rule violates federal law and harms asylum seekers, including unaccompanied children; this was a policy opposition letter, not a privacy enforcement action.
Connecticut and Massachusetts co-led a coalition protest urging FERC to reject the proposed NextEra Energy-Dominion Energy merger. The coalition argued that the merger could increase market power and threaten energy affordability, reliability, and competition; the release does not report a final enforcement decision or penalty.