$6.2B+ IN REAL ENFORCEMENT ACTIONS

The compliance fines that should scare you

18 public-record enforcement actions across GDPR, HIPAA, PCI DSS, GLBA, SOX, and state privacy regimes — with the actual root cause and the specific controls that would have prevented each one. Use them as your board-deck appendix.

Run my free compliance auditGenerate policies
AllGDPRHIPAAPCI DSSCCPA / StateGLBA / FintechSOX / SEC
Meta Platforms
Irish Data Protection Commission (DPC) · 2023
€1.2B
B2C Tech
Largest GDPR fine ever — EU→US data transfers under invalidated Privacy Shield framework
GDPR
Read root cause + lessons →
Didi Global
Cyberspace Administration of China (CAC) · 2022
¥8.026B (~$1.2B)
Mobility
Largest data-protection fine in Asia — 16 violations across PIPL, DSL, CSL
China PIPLData Security LawCybersecurity Law
Read root cause + lessons →
Amazon Europe Core
CNPD (Luxembourg) · 2021
€746M
E-Commerce
Largest GDPR fine at the time — behavioural ad targeting without valid consent
GDPR
Read root cause + lessons →
Equifax
FTC + CFPB + 50 State AGs · 2017
$700M+
Financial Services
Largest consumer-data settlement in US history — Apache Struts patch ignored for 76 days
GLBAFTC ActState AG
Read root cause + lessons →
Meta / Instagram
Irish DPC · 2022
€405M
B2C Tech
Children's business-account email + phone exposed publicly
GDPR
Read root cause + lessons →
TikTok
Irish DPC · 2023
€345M
B2C Tech
Children's accounts defaulted to public — GDPR Articles 5, 12, 24, 25 violations
GDPRAge-Appropriate Design
Read root cause + lessons →
Capital One
OCC + class action · 2020
$80M + $190M class
Banking
Mis-configured AWS WAF → 106M records exfiltrated by a former AWS engineer
GLBABank Service Co Act
Read root cause + lessons →
TJX Companies
FTC + state AGs + card networks · 2007
~$256M
Retail
The breach that wrote PCI DSS — 94M cards stolen via insecure WEP wireless
PCI DSSFTC Act
Read root cause + lessons →
Target
47 State AGs + class action + card networks · 2013
~$202M
Retail
HVAC vendor credentials → 40M payment cards + 70M customer records
PCI DSSState AGClass Action
Read root cause + lessons →
Block / Cash App
CFPB + 48 State AGs · 2025
$175M
Fintech
Failed fraud investigations + inadequate Reg E dispute handling
CFPAGLBAEFTA Reg E
Read root cause + lessons →
Altaba (Yahoo)
US SEC + class action · 2018
$35M SEC + $117.5M class
B2C Tech
First SEC enforcement against a public company for failing to disclose a cyber breach
SEC DisclosureSecurities Act
Read root cause + lessons →
Uber
50 State AGs + DC · 2018
$148M
Mobility
Paid hackers $100K to hide a 57M-record breach for over a year
State Breach Notification
Read root cause + lessons →
H&M
Hamburg DPA (Germany) · 2020
€35.3M
Retail / HR
Secret employee profiling — managers logged personal details after 1:1s
GDPREmployee Monitoring
Read root cause + lessons →
British Airways
UK ICO · 2020
£20M
Travel
Magecart-style skimmer on payment page — 429K records exposed
GDPR
Read root cause + lessons →
Marriott International
UK ICO · 2020
£18.4M
Hospitality
Starwood acquisition inherited a 4-year undetected breach — 339M records
GDPR
Read root cause + lessons →
Anthem Inc.
HHS Office for Civil Rights (OCR) · 2018
$16M
Healthcare
Largest HIPAA settlement in history — 78.8M records breached
HIPAA
Read root cause + lessons →
BetterHelp
US Federal Trade Commission · 2023
$7.8M
Healthcare / Telehealth
Disclosed sensitive mental-health data to Meta / Snap ad pixels
FTC ActHIPAA-adjacentState
Read root cause + lessons →
Premera Blue Cross
HHS OCR · 2020
$6.85M
Healthcare
11M-record breach + risk-analysis + access-controls failures
HIPAA
Read root cause + lessons →

Find your gaps before a regulator does

Run a free 60-second compliance audit on your existing policies. ComplianceIQ scores you against every framework in this database and tells you which control gap would expose you to which enforcement pattern.

Start free audit