Latest privacy fines, EU and US
A running list of notable GDPR, UK, and US privacy enforcement actions, curated from regulator releases, law-firm alerts, and mainstream coverage. Not exhaustive, and not legal advice, see our methodology for how we approach this site generally.
First-ever CCPA data-broker action, and first joint CCPA + Delete Act case: didn't register as a data broker and required an SSN or address just to process an opt-out.
Source: CalPrivacy ↗Inadequate credential and certificate security let attackers breach systems twice via social engineering, exposing 365,000+ customers.
Source: Help Net Security ↗Lacked credential-stuffing safeguards, rate limiting, or intrusion monitoring, enabling the 2023 breach that exposed genetic data of 6.9 million users.
Source: New York Attorney General ↗Third-party ad-tech trackers allegedly collected site-visitor data without consent, in violation of CIPA's pen-register provision.
Source: Top Class Actions ↗Repurposed and consolidated over 12 billion traveler records for profiling without a valid legal basis or adequate transparency.
Source: Norton Rose Fulbright ↗Sold driver geolocation and driving-behavior data to data brokers without adequate consumer consent, the largest CCPA penalty to date and the first centered on data minimization.
Source: California Attorney General ↗First CCPA action centered on students: used tracking technology to sell and share student and family data with ad and analytics partners without an effective opt-out.
Source: WilmerHale ↗Relied on self-declared age only, with no robust age assurance or children's-risk DPIA, letting under-13s onto the platform.
Source: ICO ↗Didn't consistently honor consumer opt-out-of-sale/share requests across devices and streaming services tied to Disney accounts.
Source: California Attorney General ↗Weak VPN authentication and ineffective anomaly detection contributed to a breach exposing 24 million subscriber records, including IBANs.
Source: CNIL ↗A 2021/2022 breach via a former employee's credentials exposed unencrypted student records for millions of students nationwide.
Source: California Attorney General ↗Advertising cookies loaded before any consent choice was made, and clicking "Reject all" did not actually stop tracking cookies.
Source: CNIL ↗Inserted ads into Gmail inboxes without consent, and placed cookies at account creation without a valid consent choice.
Source: GRC Report ↗Resolved claims Google tracked user locations despite privacy settings, misrepresented Incognito-mode privacy, and collected biometric identifiers without consent.
Source: Texas Attorney General ↗Couldn't demonstrate EEA user data accessed by staff in China had protection essentially equivalent to the EU, and didn't disclose that access in its privacy policy.
Source: Irish DPC ↗Collected and sold sensitive location data, including visits to health clinics and places of worship, without informed consent.
Source: FTC ↗Its "Tag Suggestions" facial-recognition feature captured facial geometry from photos without consent, violating Texas's biometric-identifier law.
Source: Texas Attorney General ↗Transferred EU drivers' location, payment, and in some cases medical or criminal data to the US for over two years without SCCs or another valid transfer mechanism.
Source: EDPB ↗Continued transferring Facebook EU/EEA user data to the US via SCCs without adequate supplementary measures after Schrems II, the largest GDPR fine issued to date.
Source: Irish DPC ↗Don't be the next name on this list
Every tool on this list is one we've personally installed and tested. See which one fits your site.
Amounts and dates are sourced from the regulator or outlet linked on each entry. Currency conversions, where shown, are approximate. This list is a curated selection of notable actions, not a complete record of enforcement activity, and isn't legal advice. For your specific situation, consult a privacy attorney.