Texas · verified official-source register

Texas Privacy Enforcement Cases

3 verified case records from the authoritative 50-state register. The fields below preserve the supplied amount, date, legal basis and explanation of why the action was brought.

3 official case source links · state register dated August 31, 2026

Actual case links

Texas case register

Each record links directly to the official Attorney General or state-agency source supplied for this register. Shared multistate amounts are reproduced as stated and should not be summed as unique state penalties.

Verified case 1 of 3

Google

Date
not stated in the official release
Amount
$1.375 billion; State of Texas recovery: $1.375 billion
Legal basis
Not stated

Why the action was brought

In 2022, Attorney General Paxton sued Google for unlawfully tracking and collecting users’ private geolocation data, incognito searches, and biometric data, including voiceprints and facial geometry. Google secretly tracked people’s movements and private searches through its products and services, abusing Texans’ trust and privacy rights.

View Official Case Source ↗ (opens in a new tab)

Verified case 2 of 3

Experian Data Corp.; Experian Information Solutions; T-Mobile

Date
not stated in the official release
Amount
More than $16 million total; approximately $1.63 million to the State of Texas
Legal basis
No specific statutes or laws cited

Why the action was brought

In September 2015, Experian reported a data breach affecting more than 15 million people who submitted credit applications with T-Mobile, an Experian client. Nearly two million Texans were exposed, putting consumers’ privacy and personal information at risk. The document does not specify the particular security failure or statutory violation.

View Official Case Source ↗ (opens in a new tab)

Verified case 3 of 3

23andMe

Date
not stated in the official release
Amount
$150 million settlement; recovery limited to $18 million; Texas share: $1,266,860
Legal basis
No statutes or laws cited

Why the action was brought

23andMe’s 2023 data breach compromised genetic data and other customer information belonging to 6.9 million consumers worldwide; some genetic ancestry information was exposed and later offered for sale on the dark web. The investigation found unreasonable data-security practices and inadequate safeguards against hacking, with personal information becoming publicly available.

View Official Case Source ↗ (opens in a new tab)

Source data is based on verified concluded privacy, data-breach and data-security enforcement actions located on official state Attorney General or state-agency sources. Multistate settlement amounts are reproduced as stated by the official source and should not be summed as unique state penalties.