New Mexico · verified official-source register

New Mexico Privacy Enforcement Cases

3 verified case records from the authoritative 50-state register. The fields below preserve the supplied amount, date, legal basis and explanation of why the action was brought.

3 official case source links · state register dated August 31, 2026

Actual case links

New Mexico case register

Each record links directly to the official Attorney General or state-agency source supplied for this register. Shared multistate amounts are reproduced as stated and should not be summed as unique state penalties.

Verified case 1 of 3

Google LLC

Date
2021-12-13
Amount
millions of dollars; no state share stated
Legal basis
federal Children’s Online Privacy Protection Act (COPPA) and state consumer protection laws

Why the action was brought

New Mexico alleged that Google improperly collected and disclosed minor students’ personal data through Workspace for Education products. The allegations also concerned Google Play app developers mislabeling child-directed apps to obtain targeted advertising and user-profiling revenue, and apps collecting information from children under 13 without adequate age screening or parental visibility.

View Official Case Source ↗ (opens in a new tab)

Verified case 2 of 3

Equifax

Date
2019-07-22
Amount
Up to $425 million in consumer restitution, $175 million to the states, including nearly $2.3 million for New Mexico; $600 million total stated
Legal basis
No statutes or laws cited

Why the action was brought

Equifax’s 2017 data breach exposed information of more than 147 million consumers, including more than 860,000 New Mexicans: Social Security numbers, names, birth dates, addresses, credit card numbers, and some driver’s-license numbers. Equifax failed to maintain reasonable security, patch a known critical vulnerability, or replace monitoring software, allowing attackers to steal data undetected for more than two months.

View Official Case Source ↗ (opens in a new tab)

Verified case 3 of 3

Blackbaud

Date
not stated in the official release
Amount
$49.5 million payment to states; New Mexico: $476,196.00
Legal basis
state consumer protection laws, breach notification laws, and HIPAA

Why the action was brought

Blackbaud’s software stored highly sensitive constituent information, including Social Security and driver’s-license numbers, financial and health information. Attorneys general alleged Blackbaud failed to implement reasonable security, remediate known gaps, and timely, completely, or accurately notify customers after a 2020 ransomware breach exposed information involving more than 13,000 customers and millions of consumers.

View Official Case Source ↗ (opens in a new tab)

Source data is based on verified concluded privacy, data-breach and data-security enforcement actions located on official state Attorney General or state-agency sources. Multistate settlement amounts are reproduced as stated by the official source and should not be summed as unique state penalties.