Enforcement tracker

Latest privacy fines, EU and US

A running list of notable GDPR, UK, and US privacy enforcement actions, curated from regulator releases, law-firm alerts, and mainstream coverage. Not exhaustive, and not legal advice, see our methodology for how we approach this site generally.

USCaliforniaCalifornia Privacy Protection AgencyAug 11, 2026
LocateSmarter LLC$116,490

First-ever CCPA data-broker action, and first joint CCPA + Delete Act case: didn't register as a data broker and required an SSN or address just to process an opt-out.

Source: CalPrivacy ↗
EUItalyGarante (Italy)Jul 16, 2026
WindTre€1.72M

Inadequate credential and certificate security let attackers breach systems twice via social engineering, exposing 365,000+ customers.

Source: Help Net Security ↗
USMultistateMultistate AG coalition (40+ states)Jul 2026
23andMe$18M

Lacked credential-stuffing safeguards, rate limiting, or intrusion monitoring, enabling the 2023 breach that exposed genetic data of 6.9 million users.

Source: New York Attorney General ↗
USCaliforniaCIPA class action (California courts)Jun 26, 2026
Los Angeles Times$3.85M

Third-party ad-tech trackers allegedly collected site-visitor data without consent, in violation of CIPA's pen-register provision.

Source: Top Class Actions ↗
EUSpainAEPD (Spain)May 26, 2026
Amadeus IT Group€14.4M

Repurposed and consolidated over 12 billion traveler records for profiling without a valid legal basis or adequate transparency.

Source: Norton Rose Fulbright ↗
USCaliforniaCalifornia Attorney GeneralMay 8, 2026
General Motors / OnStar$12.75M

Sold driver geolocation and driving-behavior data to data brokers without adequate consumer consent, the largest CCPA penalty to date and the first centered on data minimization.

Source: California Attorney General ↗
USCaliforniaCalifornia Privacy Protection AgencyMar 3, 2026
PlayOn Sports (GoFan)$1.1M

First CCPA action centered on students: used tracking technology to sell and share student and family data with ad and analytics partners without an effective opt-out.

Source: WilmerHale ↗
EUUnited KingdomICO (UK)Feb 24, 2026
Reddit£14.47M

Relied on self-declared age only, with no robust age assurance or children's-risk DPIA, letting under-13s onto the platform.

Source: ICO ↗
USCaliforniaCalifornia Attorney GeneralFeb 11, 2026
Disney / ABC$2.75M

Didn't consistently honor consumer opt-out-of-sale/share requests across devices and streaming services tied to Disney accounts.

Source: California Attorney General ↗
EUFranceCNIL (France)Jan 13, 2026
Free Mobile & Free€42M

Weak VPN authentication and ineffective anomaly detection contributed to a breach exposing 24 million subscriber records, including IBANs.

Source: CNIL ↗
USMultistateCalifornia, Connecticut & New York AGsNov 6, 2025
Illuminate Education$5.1M

A 2021/2022 breach via a former employee's credentials exposed unencrypted student records for millions of students nationwide.

Source: California Attorney General ↗
EUFranceCNIL (France)Sep 3, 2025
SHEIN€150M

Advertising cookies loaded before any consent choice was made, and clicking "Reject all" did not actually stop tracking cookies.

Source: CNIL ↗
EUFranceCNIL (France)Sep 3, 2025
Google€325M

Inserted ads into Gmail inboxes without consent, and placed cookies at account creation without a valid consent choice.

Source: GRC Report ↗
USTexasTexas Attorney GeneralMay 9, 2025
Google$1.375B

Resolved claims Google tracked user locations despite privacy settings, misrepresented Incognito-mode privacy, and collected biometric identifiers without consent.

Source: Texas Attorney General ↗
EUIrelandIrish DPCMay 2, 2025
TikTok€530M

Couldn't demonstrate EEA user data accessed by staff in China had protection essentially equivalent to the EU, and didn't disclose that access in its privacy policy.

Source: Irish DPC ↗
USFederalFTCJan 14, 2025
Gravy Analytics & VenntelNo monetary penalty (behavioral order)

Collected and sold sensitive location data, including visits to health clinics and places of worship, without informed consent.

Source: FTC ↗
USTexasTexas Attorney GeneralJul 30, 2024
Meta$1.4B

Its "Tag Suggestions" facial-recognition feature captured facial geometry from photos without consent, violating Texas's biometric-identifier law.

Source: Texas Attorney General ↗
EUNetherlandsDutch AP2024
Uber€290M

Transferred EU drivers' location, payment, and in some cases medical or criminal data to the US for over two years without SCCs or another valid transfer mechanism.

Source: EDPB ↗
EUIrelandIrish DPCMay 22, 2023
Meta€1.2B

Continued transferring Facebook EU/EEA user data to the US via SCCs without adequate supplementary measures after Schrems II, the largest GDPR fine issued to date.

Source: Irish DPC ↗
Our recommendation

Don't be the next name on this list

Every tool on this list is one we've personally installed and tested. See which one fits your site.

Become Compliant

Amounts and dates are sourced from the regulator or outlet linked on each entry. Currency conversions, where shown, are approximate. This list is a curated selection of notable actions, not a complete record of enforcement activity, and isn't legal advice. For your specific situation, consult a privacy attorney.