Court Rules

Privacy Enforcement Tracker

1,667 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,667

Total Actions

16

Jurisdictions

$50.5B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
VAAdministrative OrderMultistate

Trump Administration

A federal judge permanently blocked the Trump administration from penalizing states over SNAP administration and struck down guidance restricting food assistance for certain lawful permanent residents. The release does not state the date of the court’s ruling, so the event date uses the publication date as a proxy.

Low
MNSettlement

Plain Green, LLC

Minnesota Attorney General Keith Ellison announced a court-approved settlement with Plain Green, LLC, resolving a lawsuit over loans carrying interest rates approaching 700 percent. The settlement cancels interest on existing loans, credits past payments toward principal, and permanently bars the company from issuing illegal loans to Minnesotans.

Low
ORCoalitionMultistate

U.S. Immigration and Customs Enforcement

Oregon Attorney General Dan Rayfield joined other state attorneys general in court filings arguing that people in ICE detention are entitled to individualized review and that warrantless arrests require an individualized flight-risk determination. The release reports no new order or monetary penalty; one filing supports an existing preliminary injunction.

Low
NYCoalitionMultistate

U.S. Department of the Interior

New York and a coalition of other state attorneys general sued the federal government, challenging agreements that paid Bluepoint Wind and Invenergy to cancel offshore wind leases and redirect funds to other energy projects. The coalition asks the courts to declare the agreements unlawful, void the lease cancellations, and block further action to carry them out; the release does not report a penalty or court ruling.

Low
CTEnforcement ActionMultistate

U.S. Department of the Interior

Connecticut Attorney General William Tong joined other state attorneys general in suing the federal government over deals that canceled offshore wind leases in exchange for payments to Bluepoint Wind and Invenergy. The states allege the deals unlawfully used taxpayer funds and failed to follow required procedures, and ask the courts to invalidate the deals and block their implementation.

Low
CTSettlementMultistate

Glenmark, Lannett, Bausch, Apotex, Heritage, and Emcure

Connecticut and a coalition of 47 other states and territories announced preliminary court approval of a plan to distribute funds from settlements with generic drug manufacturers accused of conspiring to inflate drug prices. The release does not give the date of the court’s preliminary approval, so the event date reflects the press release date.

Low
NYConsent DecreeMultistate

Paramount Skydance Corp. and Warner Bros. Discovery, Inc.

New York Attorney General Letitia James and a coalition of 11 other attorneys general secured enforceable commitments from Paramount Skydance Corp. and Warner Bros. Discovery, Inc. to protect entertainment industry workers during their merger. Paramount must release at least 30 films per year, invest $1.5 billion in domestic film production, and create an independent editorial board for CNN and CBS. The consent decree also requires Paramount to sell Miramax and pay penalties if it fails to meet production requirements.

Low
CTConsent DecreeMultistate

Warner Bros./Paramount

Connecticut Attorney General William Tong issued a statement regarding a consent decree secured with Warner Bros./Paramount to protect editorial independence of CNN and CBS News. The consent decree establishes an editorial board structure, though the AG expressed disappointment that full divestiture was not achieved.

Low
COSettlementMultistate

Paramount Skydance Corporation

Colorado Attorney General Phil Weiser joined a coalition of 12 attorneys general in settling a lawsuit against Paramount Skydance Corporation over its merger with Warner Bros. Discovery, which the states alleged would harm competition by lowering film output and raising prices. The settlement includes a five-year commitment to increase film output, a $1.5 billion investment in domestic production, a $47.5 million worker fund, and an independent monitor. This is an antitrust/competition enforcement action, not a privacy enforcement action, despite the extraction schema's privacy focus.

Low
VACoalitionMultistate

Coalition of 24 Attorneys General

Attorney General Jay Jones joined a coalition of 24 attorneys general in filing a comment letter opposing a proposed CMS rule that the coalition says oversteps federal law, could put Medicaid funding at risk, and interfere with state regulation of health insurance. The coalition urges CMS to withdraw or significantly revise the proposed rule.

Low
ORCoalitionMultistate

U.S. federal government

A federal court granted Oregon and a coalition of other attorneys general summary judgment in a lawsuit challenging federal restrictions on access to social services. The ruling vacated the rules that threatened programs including Head Start, Title X clinics, food banks, and community health centers; the release describes no monetary penalty or privacy violation.

Low
VAEnforcement ActionMultistate

U.S. Department of Transportation

Attorney General Jay Jones and a coalition of 24 attorneys general obtained a preliminary injunction blocking the Trump administration from demanding a database of state-owned records containing personal information of 17 million CDL drivers from AAMVA and from terminating over $10 million in federal funding. The lawsuits allege DOT, FMCSA, and DHS violated federal privacy laws by secretly creating a database with no guardrails on use or sharing of Social Security numbers and no public notice.

LowUnauthorized Data SharingNotice FailureSecurity Failure
TXGuidance

N/A (consumer alert; no enforcement target)

Texas Attorney General Ken Paxton issued a consumer alert warning Texas businesses and nonprofits about a surge of demand letters alleging California Invasion of Privacy Act (CIPA) violations based on common website technologies such as cookies, pixels, and analytics tools. The AG cautions that some letters may exaggerate or misrepresent violations and may be fraudulent, noting serial CIPA plaintiff Vivek Shah has been declared a vexatious litigant. Recipients are advised not to pay or respond directly, to consult privacy counsel, and to report suspected fraud to the Consumer Protection Division.

LowUnauthorized Data SharingConsent Failure
NYGuidance

Various AI developers (no specific entity named)

New York Attorney General Letitia James issued an industry alert urging workers with knowledge of unsafe or illegal conduct in AI development to file confidential complaints through the OAG's secure whistleblower portal. The alert cites the OAG's monitoring of cybersecurity, economic, and other safety risks from emerging AI, and highlights the RAISE Act (effective January 1, 2027), which will require large AI developers to publicly disclose safety measures and report security incidents, as well as the SHIELD Act's data security requirements. No company was named, charged, or penalized; the alert signals impending OAG enforcement authority over AI developers.

LowAI/Automated DecisionsSecurity Failure
COSettlement

Sares Regis Group

Colorado Attorney General Phil Weiser announced a settlement with Sares Regis Group, a Denver-metro property management company, after an investigation found it told prospective tenants that rental subsidies and housing vouchers were not accepted at its properties, in violation of the Colorado Anti-Discrimination Act and the Colorado Consumer Protection Act. Under the settlement, the company must adopt written source-of-income policies, train leasing employees, submit a compliance report to the AG's office, and refrain from misrepresenting its voucher acceptance, and it pays $30,000 to the Housing Rights Initiative. Note: this is a fair-housing enforcement action, not a privacy matter, so no privacy violation taxonomy categories apply.

Low

$30K

VAGuidance

No respondent entity (consumer advisory announcement)

Virginia Attorney General Jay Jones announced that Governor Spanberger's declaration of a state of emergency due to prolonged, severe drought has triggered Virginia's anti-price gouging statutes, making it unlawful to charge unconscionable prices for necessary goods and services. A price is unconscionable if it grossly exceeds the price charged during the ten days immediately prior to the emergency. No entity was charged or fined; the release is a consumer advisory explaining how to report suspected price gouging to the Attorney General's Consumer Protection Section.

Low
CTNew Law

N/A - General advisory to Connecticut businesses and consumers (no specific entity)

Connecticut Attorney General William Tong issued an advisory that newly enacted privacy laws take effect October 1, 2026, including Public Act 26-64 (SB4), which amends the Connecticut Data Privacy Act, and Public Act 26-15 (SB5), which established the Connecticut Artificial Intelligence Responsibility and Transparency Act (CART Act). The new laws regulate surveillance pricing, facial recognition technology, genetic data collected by direct-to-consumer testing companies, a ban on the sale of precise geolocation data, a data broker registry, AI use in employment decisions, and chatbots offered to children. No enforcement action was taken; this is prospective guidance alerting consumers and businesses to new rights and compliance requirements.

LowSurveillance PricingBiometric DataHealth Data
FTCGuidance

Automobile industry (auto dealers) - no named respondent; industry-wide guidance publication

FTC staff published FAQs on price transparency to help the automobile industry comply with the FTC Act, reiterating that an advertised vehicle price must be the actual price any consumer can pay, excluding only government-required charges. The guidance follows warning letters the FTC sent to 97 auto dealership groups earlier in 2026 and signals continued litigation against dealers that advertise one price but charge more through undisclosed fees. No specific entity was charged and no penalty was imposed.

LowDark Patterns
NYCoalitionMultistate

Not applicable (no company named - coalition letter to U.S. Congress re: Digital Asset Market Clarity Act)

New York Attorney General Letitia James led a bipartisan coalition of 17 other state attorneys general in sending a letter to Congress opposing the Digital Asset Market Clarity Act, warning that the bill would preempt state attorneys general authority to combat cryptocurrency fraud and scams. This is a legislative advocacy action, not an enforcement action against any company, and no penalties or remedies were imposed. The coalition urged Congress to preserve state enforcement power over both tokenized and non-tokenized securities and state crypto registration regimes.

Low
CTCoalitionMultistate

Digital Asset Market Clarity Act (proposed federal legislation — no enforcement target entity)

Connecticut Attorney General William Tong joined a bipartisan coalition of 16 other state attorneys general in sending a letter to the U.S. Senate Banking Committee opposing the Digital Asset Market Clarity Act, warning it would preempt state authority to protect investors from cryptocurrency fraud and scams. The coalition urges Congress to preserve state enforcement, registration, and federal-state cooperation roles over digital assets. This is a legislative advocacy action, not an enforcement action — no entity was charged, no violations were found, and no penalty was imposed.

Low
MNCoalitionMultistate

Bipartisan Coalition of 16 State Attorneys General

Minnesota Attorney General Keith Ellison joined a bipartisan coalition of 16 attorneys general in a letter to U.S. Senate Banking Committee leaders opposing the Digital Asset Market Clarity Act, warning it would strip states of their ability to combat cryptocurrency scams and fraud. The letter cites over $10 million in crypto scam losses by Minnesotans in 18 months and urges Congress to preserve state registration regimes and enforcement authority. No company was charged and no penalty was imposed; this is legislative advocacy rather than an enforcement action.

Low
VACoalitionMultistate

Federal Communications Commission

Virginia Attorney General Jay Jones, joined by a bipartisan coalition of 48 other attorneys general, sent a letter urging the FCC to strengthen its 'Know Your Upstream Provider' (KYUP) rules to keep illegal robocalls off the U.S. phone network. The coalition asks the FCC to mandate baseline vetting measures for upstream providers, add monitoring triggers, strengthen STIR/SHAKEN caller ID authentication, establish base penalties, and require retention of KYUP data. No company was fined in this action; it is regulatory advocacy that builds on the Anti-Robocall Multistate Litigation Task Force's Operation Robocall Roundup, which sent warning letters to 37 voice providers.

Low
MNSettlement

Minnesota Valley Cooperative Light and Power Association

Minnesota Attorney General Ellison reached a settlement with Minnesota Valley Cooperative Light and Power Association resolving allegations of deceptive and unfair practices, including disconnecting a customer's electricity despite the customer's need for life-sustaining medical equipment and failing to properly notify customers of consumer protections or offer appropriate payment plans. Under the consent judgment, the cooperative must provide separate disconnection notices, offer written payment plans, maintain records for AG oversight, and forgive amounts owed by the affected consumer.

LowNotice Failure
FTCGuidance

Federal Trade Commission

The FTC rescinded its 2021 Policy Statement on Breaches by Health Apps and Other Connected Devices, which had purported to apply the Health Breach Notification Rule to health apps and connected devices that collect consumer health information. The rescission follows the Commission's 2024 update to the Health Breach Notification Rule, which already covers health apps and connected devices like fitness trackers, and implements an executive order directing agencies to eliminate obsolete guidance documents. No company was charged or penalized; this is a deregulatory action.

Low
MNEnforcement Action

C4D, LLC

Minnesota Attorney General Keith Ellison filed a lawsuit in Hennepin County against C4D, LLC, its owners Travis Benoit and Steven Legatt, and related entity Five Points Properties, LLC, alleging 18 counts of violating the Minnesota Human Rights Act, federal lending laws, and state consumer-fraud and contract-for-deed laws. The complaint alleges the defendants sold homes through predatory contracts for deed with inflated prices, hidden finance charges, and large annual balloon payments that leave buyers immediately underwater and forfeit all equity upon default, while targeting Somali-American Muslims on the basis of religion and national origin — a form of 'reverse redlining.' The AG seeks an injunction, civil penalties, and cancellation or reformation of existing contracts; no penalty amounts have been determined.

Low
CTInvestigation

MediaLab.AI Inc.

Connecticut Attorney General William Tong announced a civil investigative demand into MediaLab.AI Inc., owner of the Kik Messenger app, over lax age assurance practices, content moderation, and child safety failures that advocates have dubbed a "predator's paradise." The action follows a July 2025 notice of violation under the Connecticut Data Privacy Act for privacy notice deficiencies and processing sensitive data — including health, biometric, and precise geolocation data — without proper consent, which the company has only partially addressed. The new investigation seeks records related to practices that may constitute unfair or deceptive acts or practices under the CTDPA and the Connecticut Unfair Trade Practices Act. No fine has been imposed to date.

LowChildren's DataConsent FailureNotice Failure
ORCoalitionMultistate

Federal Communications Commission

Oregon Attorney General Dan Rayfield, leading a bipartisan coalition of 48 other state and territorial attorneys general, sent a letter urging the FCC to strengthen its 'Know Your Upstream Provider' (KYUP) rule so phone companies must properly vet, continuously monitor, and cut ties with upstream providers that facilitate illegal robocalls and caller ID spoofing. The coalition asks the FCC to set minimum vetting standards, require periodic re-checks rather than one-time contract reviews, strengthen caller ID authentication across the call chain, impose meaningful penalties, and mandate record-keeping for investigators. No fine or injunction was imposed; the letter notes Americans received more than 29.6 billion scam robocalls and texts last year and lost nearly $2 billion to these scams.

Low
FTCGuidance

N/A (no entity named - agency policy announcement)

The FTC announced a seven-day extension of the public comment period on its proposed enforcement policy statement regarding personalized pricing, pushing the deadline from Sept. 18, 2026 to Sept. 25, 2026. Personalized pricing refers to using personal data to set prices based on what the company believes an individual consumer is willing to spend. This is a procedural announcement about draft agency guidance, not an enforcement action against any company, and no entity was named, no violation found, and no penalty imposed.

LowSurveillance Pricing
CPPAGuidance

Data brokers (unspecified - advisory applies to all businesses registered with California's data broker registry)

CalPrivacy (the California Privacy Protection Agency) issued Enforcement Advisory 2026-01 warning data brokers that providing incorrect information in their annual registration with California's data broker registry carries liability of a $200 fine per day. The advisory observes that the Enforcement Division has already brought multiple enforcement actions over reporting errors, and emphasizes that accurate registry disclosures are what make the newly launched Delete Request and Opt-Out Platform (DROP) work for Californians. No specific company was named and no penalty was imposed by the advisory itself; it functions as forward-looking guidance.

LowData Broker Non-ComplianceNotice Failure
CTGuidance

Hyperliquid

Attorney General William Tong issued a consumer alert warning Connecticut residents about unregulated, offshore decentralized finance (DeFi) cryptocurrency exchanges, naming GMX, Gains Network, dYdX, Aevo, Drift Protocol, Vertex Protocol, and Hyperliquid. The alert highlights risks including bypassing U.S. law via VPNs, predatory leverage up to 250x, misleading synthetic asset products, and lack of KYC protections. No enforcement action or penalty was imposed; at least one Connecticut consumer reportedly lost $200,000 deposited with an unregulated DeFi exchange.

LowDark PatternsSecurity Failure

Explore Enforcement Data