Florida · verified official-source register

Florida Privacy Enforcement Cases

3 verified case records from the authoritative 50-state register. The fields below preserve the supplied amount, date, legal basis and explanation of why the action was brought.

3 official case source links · state register dated August 31, 2026

Actual case links

Florida case register

Each record links directly to the official Attorney General or state-agency source supplied for this register. Shared multistate amounts are reproduced as stated and should not be summed as unique state penalties.

Verified case 1 of 3

Wawa

Date
Jul 26, 2022
Amount
$8 million total; Florida will receive more than $1.1 million
Legal basis
state consumer protection and personal information protection laws

Why the action was brought

Hackers accessed Wawa’s computer network and deployed malware on point-of-sale terminals, extracting customers’ sensitive payment card information from April 18, 2019, through Dec. 12, 2019. The breach potentially compromised up to 34 million payment cards. The attorneys general alleged Wawa failed to employ reasonable information-security measures, violating state consumer protection and personal information protection laws.

View Official Case Source ↗ (opens in a new tab)

Verified case 2 of 3

Morgan Stanley Smith Barney LLC

Date
Nov 16, 2023
Amount
$6.5 million to the states; no state-specific share stated
Legal basis
No statutes or laws cited.

Why the action was brought

This action followed findings that Morgan Stanley failed to properly dispose of thousands of hard drives and servers containing customers’ sensitive personal information, hired an inexperienced moving company, failed to monitor equipment sold through internet auctions, and later discovered 42 missing servers potentially containing unencrypted information, exposing millions of consumers.

View Official Case Source ↗ (opens in a new tab)

Verified case 3 of 3

Retrieval-Masters Creditors Bureau d/b/a American Medical Collection Agency

Date
Mar 11, 2021
Amount
$21 million total payment to the states; no state's share stated; payment suspended unless the company violates certain settlement terms
Legal basis
No statutes or laws cited in the document

Why the action was brought

AMCA’s internal system was accessed by an unauthorized user from Aug. 1, 2018, through March 30, 2019, exposing Social Security numbers, payment-card information, and sometimes medical-test names and diagnostic codes. The company failed to detect the intrusion despite bank warnings, potentially jeopardizing identities, finances, and online security of millions.

View Official Case Source ↗ (opens in a new tab)

Source data is based on verified concluded privacy, data-breach and data-security enforcement actions located on official state Attorney General or state-agency sources. Multistate settlement amounts are reproduced as stated by the official source and should not be summed as unique state penalties.