California · verified official-source register

California Privacy Enforcement Cases

3 verified case records from the authoritative 50-state register. The fields below preserve the supplied amount, date, legal basis and explanation of why the action was brought.

3 official case source links · state register dated August 31, 2026

Actual case links

California case register

Each record links directly to the official Attorney General or state-agency source supplied for this register. Shared multistate amounts are reproduced as stated and should not be summed as unique state penalties.

Verified case 1 of 3

General Motors

Date
2026-05-08
Amount
$12,750,000
Legal basis
California Consumer Privacy Act and the Unfair Competition Law

Why the action was brought

GM allegedly unlawfully sold California drivers’ driving and precise location data collected through OnStar to two data brokers for driver-rating products, without disclosing those sales and while misleading consumers about data use. The conduct violated the CCPA’s purpose limitation and data minimization provisions; using driving data to set insurance premiums is illegal in California.

View Official Case Source ↗ (opens in a new tab)

Verified case 2 of 3

Rickenbacher Data LLC, d/b/a Datamasters

Date
2026-01-08
Amount
$45,000
Legal basis
California’s Delete Act

Why the action was brought

Datamasters failed to register as a data broker in 2024, violating California’s Delete Act, while buying and reselling names, addresses, phone numbers, and email addresses of millions of people with Alzheimer’s disease, drug addiction, bladder incontinence, and other health conditions. It also sold lists based on age, perceived race, political views, purchases, and banking activity for targeted advertising.

View Official Case Source ↗ (opens in a new tab)

Verified case 3 of 3

Premera Blue Cross

Date
Thursday, July 11, 2019
Amount
$10 million in civil penalties; California will receive $1,002,814
Legal basis
Each state’s consumer protection and medical information laws; the federal Health Insurance Portability & Accountability Act (HIPAA)

Why the action was brought

Premera’s 2014 breach exposed names, Social Security numbers, bank account information, medical information, and health claims-related data of 10.5 million consumers, including 400,000 Californians. Attackers used targeted emails and malware, while Premera lacked basic security, failed to monitor its network, ignored warnings, and allowed unnecessary employee access.

View Official Case Source ↗ (opens in a new tab)

Source data is based on verified concluded privacy, data-breach and data-security enforcement actions located on official state Attorney General or state-agency sources. Multistate settlement amounts are reproduced as stated by the official source and should not be summed as unique state penalties.