Hawaii · verified official-source register

Hawaii Privacy Enforcement Cases

3 verified case records from the authoritative 50-state register. The fields below preserve the supplied amount, date, legal basis and explanation of why the action was brought.

3 official case source links · state register dated August 31, 2026

Actual case links

Hawaii case register

Each record links directly to the official Attorney General or state-agency source supplied for this register. Shared multistate amounts are reproduced as stated and should not be summed as unique state penalties.

Verified case 1 of 3

Marriott International, Inc.

Date
2024-10-09
Amount
$52 million payment to states; Hawai‘i will receive $438,045.00
Legal basis
state consumer protection laws, personal information protection laws, and, where applicable, breach-notification laws

Why the action was brought

Marriott’s Starwood reservation database was breached from July 2014 through September 2018, exposing 131.5 million U.S. guest records, including contact, birth-date, reservation, preference, limited unencrypted passport, and unexpired payment-card information. The attorneys general alleged Marriott failed to implement reasonable data-security measures and remediate deficiencies while using and integrating Starwood, violating state laws and risking consumer harm.

View Official Case Source ↗ (opens in a new tab)

Verified case 2 of 3

Blackbaud

Date
2023-10-18
Amount
$49.5 million payment to states; Hawaiʻi will receive $420,086
Legal basis
state consumer protection laws, breach notification laws, and HIPAA

Why the action was brought

Blackbaud’s deficient data security and failure to remediate known security gaps allowed unauthorized access during a 2020 ransomware event, exposing contact and demographic information, Social Security numbers, driver’s license numbers, financial and health information affecting more than 13,000 customers. Blackbaud then delayed, incomplete, or failed breach notifications and downplayed the incident.

View Official Case Source ↗ (opens in a new tab)

Verified case 3 of 3

Google

Date
November 14, 2022
Amount
$391.5 million; Hawaii’s share: $4,705,227
Legal basis
state consumer protection laws

Why the action was brought

Google’s Location History and Web & App Activity settings collected location information. Since at least 2014, the states found Google misled consumers about the scope of Location History, the existence of Web & App Activity and its location collection, and how users could limit tracking through account and device settings, creating confusion and potentially exposing sensitive personal information.

View Official Case Source ↗ (opens in a new tab)

Source data is based on verified concluded privacy, data-breach and data-security enforcement actions located on official state Attorney General or state-agency sources. Multistate settlement amounts are reproduced as stated by the official source and should not be summed as unique state penalties.