Court Rules
All enforcement actions
SettlementCritical RiskMultistate

Experian, T-Mobile to Pay $16M Over 2012, 2015 Data Breaches

Experian; T-MobileNovember 7, 2022Connecticut Attorney General

Penalty Amount

$16,000,000

Summary

Connecticut, as part of a 40-state coalition, secured multistate settlements totaling over $16 million with Experian and T-Mobile related to data breaches in 2012 and 2015 that exposed consumers' personal information. Experian agreed to pay $12.67 million and implement enhanced data security measures, while T-Mobile agreed to pay $2.43 million and strengthen vendor management. Additionally, Experian Data Corp. paid $1 million to resolve a separate 2012 breach investigation, with all entities required to improve data protection practices.

Remedy

Experian agreed to pay $12.67 million and implement a comprehensive information security program with zero-trust principles, due diligence, data minimization, and specific security requirements. T-Mobile agreed to pay $2.43 million and implement a vendor risk management program with contractual security requirements for vendors. Experian Data Corp. agreed to pay $1 million to improve vetting of third parties and maintain a Red Flags program. Experian also must offer 5 years of free credit monitoring to affected consumers.

Monetary PenaltyConsent DecreeCompliance Program

Contract Impact

In-house legal teams should review vendor agreements (particularly those involving data brokers or credit reporting agencies like Experian), customer agreements (such as telecom service contracts with T-Mobile), and any data processing addendums. Focus on clauses governing data security obligations, breach notification timelines and procedures, audit and inspection rights, indemnification for data breaches, data encryption and access control standards, incident response plans, data retention and disposal policies, and vendor oversight requirements. Changes may include strengthening security specifications (e.g., mandatory encryption, regular penetration testing), clarifying breach notification within 72 hours, requiring third-party security audits, enhancing vendor due diligence and monitoring provisions, and updating indemnification terms to cover regulatory fines and consumer redress.

Contract Search Terms

data security standardsbreach notification clausevendor management provisionsdata protection practicesencryption requirementssecurity audit rightsincident response plandata retention policyaccess controlspenetration testing

Violation Types

Entity Details

Entity

Experian; T-Mobile

Industry

Data Broker

Multistate Coalition

40-state coalition

Official Sources

Related Enforcement Actions

CT

National Highway Traffic Safety Administration

Connecticut Attorney General William Tong joined a coalition of states and local governments in filing suit against NHTSA over its rule weakening fuel economy standards for new passenger cars and light trucks. The lawsuit alleges the rule violates the agency’s statutory mandate and the Administrative Procedure Act; no penalty or final remedy is reported.

CT

U.S. Environmental Protection Agency

Connecticut Attorney General William Tong joined a multistate coalition suing the EPA over its repeal of greenhouse gas pollution limits for power plants and separately filed a notice of intent to sue over regulation of existing gas plants. The coalition asks the court to overturn the repeal and restore the protections; the release reports no monetary penalty or final order.

CT

Sandoz Inc. and Fougera Pharmaceuticals Inc.

$400.0M

Connecticut Attorney General William Tong announced a $400 million settlement with Sandoz Inc. and Fougera Pharmaceuticals Inc. resolving allegations that the generic drug manufacturers conspired to inflate prices, limit competition, and restrain trade. The settlement includes consumer restitution and injunctive reforms; court approval was being sought.

CT

U.S. Department of Homeland Security

Connecticut Attorney General William Tong joined a coalition of 21 attorneys general in submitting a comment letter opposing a DHS rule that allows certain affirmative asylum applications to be referred to removal proceedings without an asylum officer interview. The coalition argues the rule violates federal law and harms asylum seekers, including unaccompanied children; this was a policy opposition letter, not a privacy enforcement action.

CT

NextEra Energy and Dominion Energy

Connecticut and Massachusetts co-led a coalition protest urging FERC to reject the proposed NextEra Energy-Dominion Energy merger. The coalition argued that the merger could increase market power and threaten energy affordability, reliability, and competition; the release does not report a final enforcement decision or penalty.

CT

Unspecified home improvement contractors

Connecticut officials warned residents about potential home improvement scams before an approaching nor’easter, including unlicensed contractors, high-pressure sales tactics, and demands for full payment upfront. The release provides consumer guidance on checking contractors and contract requirements; it does not announce an enforcement action or penalty against a named entity.