Data Breaches and Privacy Violations: A Summary

Date: August 13, 2026

Read the full PDF here: Data Breaches and Privacy Violations: A Summary

INTRODUCTION

Over the last decade, multiple high profile cases have revealed the invasive nature of data collection in the technological industry and adjacent markets. Systems of data collection, often used to strengthen algorithms, create targeted consumer advertising campaigns, and train artificial intelligence (AI) models, violate the most essential conceptions of human privacy.

Privacy is not a luxury, but a right. It is also a foundational tenet of democracy. UNESCO, in their own research on privacy, declared:

“The exercise of the right to privacy is important for the realization of the right to freedom of expression and to hold opinions without interference and the right to freedom of peaceful assembly and association, and is one of the foundations of a democratic society.”

The following compilation of the most impactful data privacy breaches, court cases, and lawsuits that have occurred in the past decade reveals the state of data collection and privacy around the world. The human right to privacy is left sorely unprotected, and even in societies with privacy regulations, the enforcement of such legislation falls short in actively preventing violations of privacy.

These cases have shaped the landscape of data privacy today, not only setting legal precedents but also solidifying relational norms between technology companies, large corporations, and consumers. High-profile data breaches have called attention to the imbalance of power, information, and control in the highly dynamic relationship between service providers and consumers.

While some of these cases have resulted in landmark legislation that protects user privacy, there is still much to be done to standardize, and most importantly, enforce, data protection practices. CDAI calls upon lawmakers, technology developers, and business executives to build and enforce a comprehensive, effective system of privacy protections in the technological industry.

THE CASES

Csupo v. Alphabet Inc., No. 19CV352557 (Cal. Super. Ct. Santa Clara County., jury verdict July 1, 2025).

A California jury ordered Google to pay a $314.6 million fine after finding it secretly transmitted data from idle Android phones over users' cellular plans without consent.

Clearview AI, Inc., Consumer Privacy Litigation, No. 1:21-cv-00135, MDL No. 2967 (N.D. Ill., final approval Mar. 20, 2025).

A nationwide settlement resolved claims that Clearview's facial-recognition database, built by scraping billions of online photos, violated BIPA and other privacy laws.

Facebook Biometric Information Privacy Litigation, No. 3:15-cv-03747 (N.D. Cal., final approval Feb. 26, 2021).

Facebook agreed to pay $650 million to settle claims that its photo-tagging facial-recognition feature scanned and stored Illinois users' biometric data without the consent BIPA requires.

United States v. Amazon.com, Inc., No. 2:23-cv-00811 (W.D. Wash., filed May 31, 2023).

The FTC and DOJ secured a $25 million penalty and data-deletion mandates after alleging Amazon kept children's Alexa voice recordings indefinitely and ignored parents' deletion requests, violating COPPA.

United States v. Facebook, Inc., No. 19-cv-2184 (D.D.C., filed July 24, 2019).

The FTC sued Facebook over the Cambridge Analytica scandal, in which the political consultancy improperly harvested data on up to 87 million users. Facebook settled for $5 billion — the largest privacy penalty the FTC had ever imposed — and agreed to sweeping new data-governance oversight.

Google LLC v. CNIL, Conseil d'État, No. 430810 (Fr., June 19, 2020).

France's data regulator fined Google €50 million for failing to clearly disclose and obtain valid consent for ad-personalization data use, and separately ordered global delisting of "right to be forgotten" requests. France's highest administrative court upheld the fine but ruled the delisting obligation only applies within the EU, not worldwide.

State of Texas v. Google LLC (Harrison County Dist. Ct., Tex., settlement announced May 9, 2025; finalized Oct. 31, 2025).

Texas sued Google alleging it unlawfully tracked users' geolocation and incognito browsing and collected biometric identifiers (voiceprints, facial geometry) without consent. Google agreed to pay $1.375 billion, the largest privacy settlement any single US state has won against a tech company.

State of Oregon et al. v. Google LLC (multistate settlement, announced Nov. 14, 2022).

Forty states accused Google of misleading users into believing they had disabled location tracking when the company kept collecting their location data anyway. Google settled for $391.5 million, at the time the largest attorney-general-led consumer privacy settlement in US history.

United States v. Epic Games, Inc., No. 5:22-cv-00518 (E.D.N.C., settled Dec. 19, 2022).

The FTC accused the Fortnite maker of collecting children's data without parental consent and using manipulative "dark pattern" designs to trick players into unwanted purchases. Epic paid a combined $520 million across two settlements — a record COPPA penalty plus a separate deceptive-practices fine.

In re TikTok, Inc., Consumer Privacy Litigation, MDL No. 2948, No. 1:20-cv-04699 (N.D. Ill., final approval 2022).

Dozens of consolidated lawsuits alleged TikTok collected biometric and other personal data from roughly 89 million US users without proper consent, largely under Illinois' BIPA. TikTok resolved the multidistrict litigation for $92 million.

United States v. Twitter, Inc., No. 3:22-cv-03070 (N.D. Cal., filed May 25, 2022).

The FTC and DOJ alleged Twitter used phone numbers and email addresses that users had provided for account security to instead power targeted advertising, without adequate disclosure. Twitter paid a $150 million civil penalty and agreed to compliance reforms affecting the 140+ million users involved.

Meta Platforms Ireland Ltd., Irish Data Protection Commission Inquiry Decision (May 22, 2023).

Ireland's Data Protection Commission found Meta's continued transfer of European Facebook users' data to US servers, via standard contractual clauses, failed to adequately protect that data from US surveillance in light of Schrems II. Meta was fined €1.2 billion — the largest GDPR penalty ever issued — and ordered to bring its transfers into compliance.

People v. Sephora USA, Inc. (Cal. Super. Ct., San Francisco County., settled Aug. 24, 2022).

California's Attorney General alleged Sephora told customers it didn't "sell" their data while actually sharing it with ad-tech and analytics partners via tracking pixels, without honoring opt-out signals like Global Privacy Control. Sephora paid $1.2 million in the first-ever public CCPA enforcement action, setting an early precedent for what counts as a data "sale" under the law.

CONCLUSION

The risk of privacy violations is not limited to one industry. In fact, as technology and digital systems become increasingly integrated with non-technological markets, systems of data collection expand into new industries. Opportunities for privacy violations increase accordingly. It is more important now than ever that the human right to privacy is protected, both in the law and in the embedded practices of developing digital systems.

Previous
Previous

Policy Commentary: Bernie Sanders’ Proposed AI Sovereign Wealth Fund Act

Next
Next

Privacy and Data Agency AI Benchmarking Scale