Georgia · verified official-source register

Georgia Privacy Enforcement Cases

3 verified case records from the authoritative 50-state register. The fields below preserve the supplied amount, date, legal basis and explanation of why the action was brought.

3 official case source links · state register dated August 31, 2026

Actual case links

Georgia case register

Each record links directly to the official Attorney General or state-agency source supplied for this register. Shared multistate amounts are reproduced as stated and should not be summed as unique state penalties.

Verified case 1 of 3

23andMe

Date
2026-07-14
Amount
$150 million in allowed claims for states; recovery is limited to $18 million, of which Georgia will receive $452,232.00; $46.75 million class-action settlement
Legal basis
No statutes or laws cited in the document

Why the action was brought

The 2023 credential-stuffing breach compromised genetic ancestry and other data of 6.9 million customers worldwide, including 171,125 Georgians, with subsets sold on the dark web. Investigators found unreasonable security practices: inadequate safeguards, rate limiting, monitoring, investigation of unusual login activity, vulnerability remediation, and design-feature testing.

View Official Case Source ↗ (opens in a new tab)

Verified case 2 of 3

Anthem

Date
2020-09-30
Amount
$39.5 million; Georgia’s share: $1,387,257.61
Legal basis
None stated

Why the action was brought

Attackers infiltrated Anthem’s systems beginning in February 2014 through malware installed via a phishing email, then accessed its data warehouse and harvested names, birth dates, Social Security numbers, healthcare identification numbers, addresses, email addresses, phone numbers, and employment information. The breach affected 78.8 million Americans, including 3,726,249 Georgia residents.

View Official Case Source ↗ (opens in a new tab)

Verified case 3 of 3

The Home Depot

Date
2020-11-24
Amount
$17.5 million-dollar settlement; Georgia's share: $356,366.24
Legal basis
No statutes or laws cited.

Why the action was brought

The multistate investigation concerned a 2014 data breach in which hackers gained access to The Home Depot’s network and deployed malware on self-checkout point-of-sale systems. The malware obtained payment-card information from customers using self-checkout lanes at U.S. stores between April 10 and September 13, 2014, affecting approximately 40 million consumers nationwide.

View Official Case Source ↗ (opens in a new tab)

Source data is based on verified concluded privacy, data-breach and data-security enforcement actions located on official state Attorney General or state-agency sources. Multistate settlement amounts are reproduced as stated by the official source and should not be summed as unique state penalties.