Penalty Amount
$1,250,000
Consumers Affected
180,000
New Jersey, as part of a multistate coalition, settled with Carnival Cruise Line over a 2019 data breach that compromised personal information of approximately 180,000 employees and customers nationwide. The breach resulted from deficiencies in Carnival's data security program and delayed breach notification. Carnival will pay $1.25 million and implement enhanced email security and breach response measures.
Carnival must implement and maintain a breach response and notification plan, provide email security training with phishing exercises, enforce strong password policies, maintain enhanced network monitoring tools, and undergo an independent information security assessment.
In-house legal teams should review customer agreements, employee agreements, and vendor contracts for clauses related to data security, breach notification, and incident response. Specifically, examine data security obligations, breach notification timelines and methods, email security provisions, and regulatory reporting requirements. Changes may be needed to enhance email security controls, ensure prompt breach notification to consumers and regulators, and implement regular security audits to align with settlement mandates.
Entity
Carnival Cruise Line
Also known as: Carnival
Industry
OtherOfficial Press Release
https://www.njoag.gov/acting-ag-platkin-announces-settlement-with-carnival-cruise-line-over-2019-data-breach-that-compromised-personal-information-from-its-employees-and-customers/
2022 0622 Carnival Corporation AVC
https://www.nj.gov/oag/newsreleases22/2022-0622-Carnival-Corporation AVC.pdf
New Jersey Attorney General Enforcement Page
https://www.njoag.gov/about/divisions-and-offices/division-of-consumer-affairs/
"Carnival Cruise Line"
"total of $1.25 million"
"data breach"
"deficiencies in Carnival’s data security program contributed to the breach"
"Carnival did not provide adequate notice of the breach"
"health information"
$1.3M
Connecticut, co-leading a multistate investigation, secured a $1.25 million settlement with Carnival Cruise Line over a 2019 data breach affecting approximately 180,000 individuals nationwide. The breach exposed sensitive data including passport numbers, driver's licenses, payment card information, and health data, with a 10-month delay in notification. Carnival agreed to implement enhanced email security measures, a breach response plan, and an independent security assessment.
A multistate coalition co-led by New Jersey won a federal court order rejecting the Trump Administration’s decision not to request funding for the CFPB. The order struck down that decision and directed the Administration to follow the law and fund the agency; no monetary penalty or privacy violation is described.
New Jersey’s Attorney General and Division of Consumer Affairs alerted the public that three synthetic kratom-related compounds became illegal to possess or sell in the state under a temporary federal scheduling order. The release describes a controlled-substance alert, not a privacy enforcement action, and identifies no company, privacy violation, or monetary penalty.
$2.3M
Laboratory Corporation of America Holdings agreed to pay $2,287,455 to participating states and strengthen its security and vendor-management practices following an investigation into the 2019 breach at its debt-collection vendor, AMCA. The breach potentially exposed information of more than 27.5 million people nationwide, including sensitive information belonging to approximately 10.2 million LabCorp patients.
$694.0M
New Jersey's Attorney General and Division of Consumer Affairs, along with 41 Attorneys General, reached a $694 million settlement with subprime auto lender Credit Acceptance Corporation over allegations it originated unaffordable loans its own systems predicted borrowers could not repay, employed aggressive debt-collection tactics, and failed to prevent deceptive vehicle-service contract and GAP product 'packing' by dealers. The multistate settlement stepped in after the CFPB permanently dropped its 2023 enforcement action against CAC in 2025. CAC will provide $60 million in cash restitution, $634 million in debt relief, an additional $15 million to the states, and implement injunctive lending reforms including loan off ramps, pre-loan disclosures, add-on packing safeguards, and a seven-year vehicle price cap. Note: this is a consumer-protection lending enforcement action, not a privacy matter; violation categories are best-fit mappings from the available taxonomy.
$650K
The New Jersey Attorney General and Division of Consumer Affairs announced that Match Group, Inc. will pay $650,000 and change its business practices to settle allegations that it misrepresented or failed to disclose its criminal background screening policies and practices to New Jersey users, violating the New Jersey Consumer Fraud Act and the Internet Dating Safety Act. Under a Consent Order, Match must accurately represent its screening policies, notify existing New Jersey members of updated disclosures within 150 days, and post clear and conspicuous disclosures and safety notifications about the limitations of criminal background screenings.