Verified case 1 of 3
Experian Data Corp.
- Date
- November 7, 2022
- Amount
- $1,000,000 total payable to the ATTORNEYS GENERAL; $20,000.00 payable to the Commonwealth of Kentucky for the Attorney General’s reasonable costs of investigation and litigation
- Legal basis
- KRS 367.230; Kentucky Consumer Protection Act, KRS §§ 367.110-.300, 367.990; KRS 365.732; STATE CONSUMER PROTECTION ACTS, STATE PERSONAL INFORMATION PROTECTION ACTS, and STATE DATA BREACH NOTIFICATION ACTS listed in Appendices A and B, including: Alaska Unfair Trade Practices Act, AS 45.50.471 et seq.; Personal Information Protection Act, AS §§ 45.48.010 et seq.; Arizona Consumer Fraud Act, A.R.S. §§ 44-1521 et seq.; Ariz. Rev. Stat. § 18-552; Arkansas Deceptive Trade Practices Act, Ark. Code Ann. §§ 4-88-101 et seq.; Personal Information Protection Act, Ark. Code Ann. §§ 4-110-101 et seq.; Colorado Consumer Protection Act, C.R.S. §§ 6-1-101 et seq.; Personal Information Protection, C.R.S. § 6-1-713.5; Security Breach Notification, C.R.S. § 6-1-716; Connecticut Unfair Trade Practices Act, Conn. Gen. Stat. §§ 42-110b et seq.; Safeguarding of Personal Information, Conn. Gen. Stat. § 42-471; Breach of Security, Conn. Gen. Stat. § 36a-701b; Consumer Fraud Act, 6 Del. C. §§ 2511 et seq.; Delaware Data Breach Notification Law, 6 Del. C. § 12B-100 et seq.; Consumer Protection Procedures Act, D.C. Code §§ 28-3901 et seq.; District of Columbia Consumer Security Breach Notification Act, D.C. Code §§ 28-3851 et seq.; Florida Deceptive and Unfair Trade Practices Act, Chapter 501, Part II, Florida Statutes; Florida Information Protection Act, Section 501.171, Florida Statutes; Uniform Deceptive Trade Practice Act, Haw. Rev. Stat. Chpt. 481A and Haw. Rev. Stat. Sect. 480-2; Personal Information Protection, Haw. Rev. Stat. Chpt. 487J; Security Breach of Personal Information, Haw. Rev. Stat. Chpt. 487N; Idaho Consumer Protection Act, Idaho Code §§ 48-601 et seq.; Identity Theft, Idaho Code §§ 28-51-104 et seq.; Illinois Consumer Fraud and Deceptive Business Practices Act, 815 ILCS 505/1 et seq.; Illinois Personal Information Protection Act, 815 ILCS 530/1 et seq.; Deceptive Consumer Sales Act, Ind. Code §§ 24-5-0.5 et seq.; Disclosure of Security Breach Act, Indiana Code §§ 24-4.9 et seq.; Iowa Consumer Fraud Act, Iowa Code § 714.16; Personal Information Security Breach Protection Act, Iowa Code § 715C; Kansas Consumer Protection Act, K.S.A §§ 50-623 et seq.; The Wayne Owen Act, K.S.A. § 50-6,139b; Security Breach Notification Act, K.S.A. §§ 50-7a01 et seq.; Maine Unfair Trade Practices Act, 5 M.R.S.A. §§ 205-A et seq.; Maine Notice of Risk to Personal Data Act, 10 M.R.S.A. §§ 1346 et seq.; Maryland Consumer Protection Act, Md. Code Ann., Com. Law §§ 13-101 et seq.; Maryland Personal Information Protection Act, Md. Code Ann., Com. Law § 14-3501 et seq.; Mass. Gen. Laws ch. 93A; Mass. Gen. Laws ch. 93H; 201 Code Mass. Regs. 17.00 et seq.; Michigan Consumer Protection Act, MCL §§ 445.901 et seq.; Identity Theft Protection Act, MCL §§ 445.61 et seq.; The Uniform Deceptive Trade Practices Act, Minn. Stat. §§ 325D.43–.48; Consumer Fraud Act, Minn. Stat. §§ 325F.68-.694; Minnesota Data Breach Notification Statute, Minn. Stat. § 325E.61; Missouri Merchandising Practices Act, Mo. Rev. Stat. §§ 407.010 et seq.; Mo. Rev. Stat. § 407.1500; Montana Unfair Trade Practices and Consumer Protection Act, Mont. Code Ann. §§ 30-14-101 et seq.; Montana Impediment of Identity Theft Act, Mont. Code Ann. §§ 30-14-1701 et seq.; Nebraska Consumer Protection Act, Neb. Rev. Stat. §§ 59-1601 et seq.; Nebraska Uniform Deceptive Trade Practices Act, Neb. Rev. Stat. § 87-301 et seq.; Financial Data Protection and Consumer Notification of Data Security Breach Act of 2006, Neb. Rev. Stat. § 87-801 et seq.; Nevada Deceptive Trade Practices Act; Nev. Rev. Stat. §§ 598.0903 et seq.; Nevada Security and Privacy of Personal Information Act; Nev. Rev. Stat. §§ 603A.010 et seq.; New Jersey Consumer Fraud Act, N.J.S.A. 56:8-1 et seq.; New Jersey Identity Theft Prevention Act, N.J.S.A. 56:8-161 to -166; The New Mexico Unfair Practices Act, NMSA 1978, §§ 57-12-1 to -26; The New Mexico Data Breach Notification Act, NMSA 1978, §§ 57-12C-1 to -12; North Carolina Unfair and Deceptive Trade Practices Act, N.C.G.S. §§ 75-1.1 et seq.; North Carolina Identity Theft Protection Act, N.C.G.S. §§ 75-60 et seq.; Unlawful Sales or Advertising Practices, N.D.C.C. §§ 51-15-01 et seq.; Notice of Security Breach for Personal Information, N.D.C.C. §§ 51-30-01 et seq.; Ohio Consumer Sales Practices Act, R.C. §§ 1345.01 et seq.; Security Breach Notification Act, R.C. §§ 1349.19 et seq.; Oregon Unlawful Trade Practices Act, ORS 646.605 et seq.; Oregon Consumer Information Protection Act, ORS 646A.600 et seq.; Pennsylvania Unfair Trade Practices and Consumer Protection Law, 73 P.S. §§ 201-1 et seq.; Breach of Personal Information Notification Act, 73 P.S. §§ 2301 et seq.; Rhode Island Deceptive Trade Practices Act, R.I. Gen. Laws §§ 6-13.1-1 et seq.; Rhode Island Identity Theft Protection Act, R.I. Gen. Laws §§ 11-49.3-1 et seq.; South Carolina Unfair Trade Practices Act, S.C. Code Ann. §§ 39-5-10 et seq.; Data Breach Notification, S.C. Code Ann., § 39-1-90; SDCL 37-24; Data Breach Notification SDCL 22-40-19 through 22-40-26; Tennessee Consumer Protection Act of 1977, Tenn. Code Ann. §§ 47-18-101 to -134; Tennessee Identity Theft Deterrence Act of 1999, Tenn. Code Ann. §§ 47-18-2101 to -2111; Texas Deceptive Trade Practices – Consumer Protection Act, Tex. Bus. & Com. Code Ann. §§ 17.41–17.63; Identity Theft Enforcement and Protection Act, Tex. Bus. & Com. Code Ann. § 521.001–152; Utah Consumer Sales Practices Act, Utah Code §§ 13-11-1 et seq.; Utah Protection of Personal Information Act, Utah Code §§ 13-44-101 et seq.; Vermont Consumer Protection Act, 9 V.S.A. §§ 2451 et seq.; Vermont Security Breach Notice Act, 9 V.S.A. § 2435; Washington Consumer Protection Act, RCW 19.86.020; Washington Data Breach Notification Law, RCW 19.255.010; Fraudulent Representations, Wis. Stat. § 100.18(1); Notice of Unauthorized Acquisition of Personal Information, Wis. Stat. § 134.98
Why the action was brought
Experian continued providing portal access to a database containing consumers’ personal information, including social security numbers, after acquiring Court Ventures. An identity thief used credentials obtained through false representations and enabled more than 3 million queries. After discovering the unauthorized access, Experian notified the database provider but did not notify affected consumers or the Attorneys General.