Court Rules
All enforcement actions
SettlementHigh RiskMultistate

Multistate AGs Secure $5.1M from Illuminate Education for Student Data Breach

Illuminate Education, Inc.November 6, 2025New York Attorney General

Penalty Amount

$5,100,000

Summary

New York, California, and Connecticut attorneys general reached a $5.1 million settlement with educational technology company Illuminate Education, Inc. for failing to protect student data, resulting in a 2022 breach exposing millions of students’ personal information. The investigation found Illuminate failed to implement basic security measures including data encryption, suspicious activity monitoring, and proper decommissioning of inactive user accounts, and did not delete student data when required by contracts. Illuminate must pay the penalty and implement enhanced data security measures including a comprehensive information security program, encryption of student data, and annual notice to schools about data collection and deletion options.

Remedy

Illuminate must pay $5.1 million in penalties and costs, with New York receiving $1.7 million. The company is required to implement a comprehensive information security program including data encryption, access limitations, network monitoring for suspicious activity, and a vulnerability management program. Illuminate must also provide annual notices to schools identifying collected student data categories and allow schools to request deletion of dated or inactive student records.

Monetary PenaltyCompliance ProgramData Deletion

Contract Impact

In-house legal teams should review all edtech and student data vendor agreements to ensure they include mandatory data encryption requirements, provisions for decommissioning inactive user accounts, and obligations to monitor for suspicious network activity. Contracts should also specify student data retention and deletion timelines, require vendors to maintain comprehensive information security programs, and mandate vulnerability management processes. Additionally, agreements should require vendors to provide annual notices detailing collected student data categories and allow the institution to request deletion of inactive or outdated student records. Teams should also verify that vendors do not misrepresent their data security practices and are compliant with applicable state student data privacy laws.

Contract Search Terms

student data security requirementsdata encryption obligationsinactive user account decommissioningstudent data deletion clausevulnerability management programsuspicious activity monitoringstudent data retention policyedtech vendor compliance

Laws Cited

Connecticut Student Data Privacy LawCalifornia student data privacy lawsNew York student data privacy laws

Violation Types

Entity Details

Entity

Illuminate Education, Inc.

Also known as: Illuminate Education

Industry

Technology

Multistate Coalition

Official Sources

Source Evidence

Entity Name
"educational technology company Illuminate Education, Inc. (Illuminate)"
Fine Amount
"secured $5.1 million from educational technology company Illuminate Education, Inc. (Illuminate)"
Event Date
"November 6, 2025"
Laws Cited
"Connecticut’s Student Data Privacy Law requires strict security to protect children’s information"
Laws Cited
"California law imposes heightened obligations for companies to secure children’s’ information"
Violation Types
"In 2022, Illuminate experienced a data breach that exposed the personal information of millions of students"

Related Enforcement Actions

FTC

Illuminate Education, Inc.

The FTC proposed a consent order against Illuminate Education, Inc. for failing to secure student data, leading to a breach affecting over 10 million students. The company allegedly had security failures and delayed breach notifications. The order requires a data security program, data deletion, and a retention schedule.

CT

Illuminate Education, Inc.

$5.1M

Connecticut Attorney General William Tong, along with California and New York Attorneys General, settled with Illuminate Education, Inc. for failing to protect student data in a breach that exposed personal information of millions of students. The settlement, the first under Connecticut's Student Data Privacy Law, requires Illuminate to pay $5.1 million and implement enhanced cybersecurity measures.

CA

Illuminate Education, Inc.

$5.1M

California Attorney General Rob Bonta, joined by Connecticut and New York Attorneys General, secured a $5.1 million multistate settlement with edtech company Illuminate Education, Inc. over a 2021 data breach that exposed sensitive personal and medical information of millions of students, including over 434,000 California students. The investigation found Illuminate failed to implement basic security measures, including failing to terminate former employee credentials, lacking suspicious activity monitoring, and unsecured backup databases, as well as making false statements in its privacy policy. Illuminate must pay $3.25 million to California, implement enhanced security practices, and notify the CA DOJ of future student data breaches.

NY

National Highway Traffic Safety Administration (NHTSA)

New York Attorney General Letitia James joined a coalition lawsuit challenging NHTSA’s rollback of federal fuel economy standards. The coalition alleges that the final rule violates federal law and asks the court to strike it down; the press release describes no privacy violations or monetary penalty.

NY

Sandoz Inc. and Fougera Pharmaceuticals Inc.

$400.0M

New York Attorney General Letitia James and a coalition of 47 other attorneys general secured a $400 million settlement with Sandoz Inc. and Fougera Pharmaceuticals Inc. over an alleged scheme to coordinate generic drug prices and reduce competition. The settlement provides for consumer compensation and requires Sandoz to implement antitrust compliance reforms, including annual staff training and a Chief Compliance Officer.

NY

New York Attorney General's Office

New York Attorney General Letitia James joined eight other attorneys general in issuing a statement criticizing a DOJ judicial misconduct complaint against nearly all federal district court judges in Minnesota. The release concerns judicial independence, not a privacy enforcement action; it announces no penalty or privacy-related remedy.