On August 17, 2026, the Federal Trade Commission (FTC) announced a $2.1 million settlement with online bill-payment company Doxo over allegations that the company, and its two co-founders, deceived consumers through search ads, fees, and subscription practices. The case shows that consumer protection risk can begin at the first click, especially when ads or landing
settlement
Data Brokers Beware: California Settlement Highlights Risks in High-Friction Opt-Out Processes
California’s privacy regulator just sent a clear message to the data broker ecosystem: compliance failures will be viewed across both the California Consumer Privacy Act (CCPA) and the Delete Act. The California Privacy Protection Agency (CPPA) announced a $116,490 settlement with LocateSmarter LLC, an Iowa-based company that allegedly operated as a data broker without registering…
California’s GM Settlement Reveals a New Era for Connected Car Privacy
California regulators have announced a major privacy settlement with General Motors (GM) over allegations that the company unlawfully sold the location and driving data of hundreds of thousands of Californians to two data brokers: Verisk Analytics and LexisNexis Risk Solutions. The settlement, subject to court approval, requires GM to pay $12.75 million in civil penalties…
Ford Settlement Highlights Simple Practice: Opt-Outs Must be Easy
The California Privacy Protection Agency (CPPA) issued a decision requiring Ford Motor Company to pay a fine of $375,703 and update its privacy practices following a settlement for its alleged violations of the California Consumer Privacy Act (CCPA). Under the CCPA, California residents have the right to direct a business to stop selling or sharing…
Lessons from the Sling TV CCPA Settlement: Why a Compliance Overhaul May Be Needed
The California Attorney General (CA AG) has again made waves in the privacy world, this time with a settlement requiring Sling TV to pay a $530,000 fine and make significant operational changes due to alleged violations of the California Consumer Privacy Act (CCPA) and Unfair Competition Law (UCL). This case signals an increase in CCPA…
California Hits Employer with $1.35M Fine in First-Ever Job Applicant Enforcement Action
- Provide a
PIH Health Settles HIPAA Violations for $600,000
PIH Health, a health care entity located in California, suffered a data breach in June 2019 when 45 employee email accounts were compromised in a targeted phishing campaign. The accounts contained the protected health information (PHI) of 189,763 individuals, including their names, social security numbers, driver’s license numbers, diagnoses, lab tests, medications, treatment, claims, and…
Video Game Maker to Pay $20 Million to Settle FTC COPPA Enforcement Action
Singapore-based Chinese video game developer Cognosphere, dba HoYoverse, known for “Genshin Impact,” a role-playing game involving collectible characters with unique fighting skills, has agreed to pay $20 million to settle Federal Trade Commission (FTC) allegations that it violated the Children’s Online Privacy Protection Act (COPPA) and deceived players about the cost of winning certain prizes.…
FTC Settles Case with GM over Allegations of Collection + Use of Drivers’ Precise Geolocation
In its continued concentration on the collection and use of consumers’ precise geolocation, on January 16, 2024, the Federal Trade Commission (FTC) settled with General Motors (GM) over allegations that it collected, used, and sold drivers’ precise geolocation and driving behavior data from millions of vehicles—data that can be used to set insurance rates—without adequately…
FTC Takes Action Against GoDaddy for Alleged Lax Data Security
The Federal Trade Commission (FTC) issued a proposed settlement order against GoDaddy alleging that it “has failed to implement reasonable and appropriate security measures to protect and monitor its website-hosting environments for security threats, and misled customers about the extent of its data security protections on its website hosting services.”
The proposed settlement order requires…