← ALL ARTICLES
// REGULATORY ENFORCEMENT

Regulatory Enforcement Intelligence

25 articles. Data protection enforcement actions and regulatory analysis. GDPR, PDPL, CCPA, and HIPAA enforcement across MENA, EU, and US.

🇺🇸 USA HIGH

USPTO GovDelivery Scam: How Fraudsters Weaponize Real .gov Emails to Steal From Trademark Filers

Fraudsters weaponize the USPTO's real GovDelivery email system as a social engineering prop during live phone scams targeting trademark filers. 77,000+ victims.

2026-04-01
🇪🇺 EU GDPR HIGH

Free Mobile Fined EUR 42M After 24.6 Million Customer Records Stolen

CNIL imposed a record EUR 42M fine after an attacker exploited weak VPN authentication to exfiltrate 43.6GB covering 19.2M individuals over 15 days undetected.

2026-01-16
🇺🇸 USA HIGH

Illuminate Education: FTC Action Over 10.1 Million Student Records Breach

FTC and three state AGs imposed a $5.1M settlement after a former employee's dormant credentials were used to access 10.1M student records over 11 days.

2025-12-01
🇪🇺 EU GDPR CRITICAL

Capita Fined £14M After Black Basta Ransomware Exposes 6.6M Records

ICO fined outsourcing giant Capita GBP 14M after Black Basta exfiltrated 974GB of data, exposing 6.6M individuals across 90+ organizations including the NHS.

2025-10-01
🇪🇺 EU GDPR MEDIUM

SHEIN Fined €150M for Cookie Consent Violations

CNIL fined SHEIN EUR 150M after 30+ tracking cookies were deployed on 12 million French visitors before obtaining consent, violating ePrivacy and GDPR rules.

2025-01-23
🇪🇺 EU GDPR HIGH

TikTok Fined €530M for Sending EU Data to China

Irish DPC fined TikTok EUR 530M for illegally transferring EU user data to China without adequate safeguards, the largest GDPR data transfer fine ever imposed.

2025-05-01
🇪🇺 EU GDPR

Meta Fined €251M for 2018 Facebook Breach

Irish DPC fined Meta EUR 251M after a Facebook 'View As' bug let attackers steal access tokens for 29M accounts, exposing names, phone numbers.

2024-12-01
🇪🇺 EU GDPR

OpenAI Fined €15M for ChatGPT Data Processing

Italian DPA fined OpenAI EUR 15M for processing EU personal data to train ChatGPT without valid legal basis and failing to implement adequate age verification.

2024-12-01
🇺🇸 USA

SolarWinds: SEC Fines Four Companies for Disclosure Failures

Russian SVR compromised 18,000 organizations via SolarWinds Orion supply chain attack. SEC fined Unisys, Avaya, Check Point, and Mimecast for misleading.

2024-10-01
🇪🇺 EU GDPR

LinkedIn Fined €310M for Behavioral Ad Targeting

Irish DPC fined LinkedIn EUR 310M for processing hundreds of millions of EEA members' data for behavioral advertising without valid consent under GDPR.

2024-10-01
🇶🇦 Qatar

QFC Issues First-Ever Data Protection Fine: $150,000 Penalty

Qatar Financial Centre issued its first-ever data protection fine, penalizing an unnamed financial services firm $150,000 for security and notification.

2024-09-01
🇪🇺 EU GDPR

Uber Fined €290M for Transferring Driver Data to US

Dutch DPA fined Uber EUR 290M for two years of illegal EU-to-US driver data transfers without Standard Contractual Clauses after the Schrems II ruling.

2024-08-01
🇪🇺 EU GDPR

Orange SA Fined €50M for Email Marketing Violations

CNIL fined Orange SA EUR 50M for ignoring 4.5 million subscribers' marketing opt-out requests, continuing promotional emails for months after users.

2024-01-01
🇸🇦 Saudi PDPL

SDAIA's First Year: 48 PDPL Enforcement Decisions

Aggregate analysis of SDAIA's first 48 enforcement decisions under the Saudi PDPL, examining regulatory patterns, priorities, and compliance expectations.

2024-01-01
🇪🇺 EU GDPR

Apotheka Pharmacy Fined €3M After 750K Patient Records Stolen

Estonia's data protection authority fined Apotheka EUR 3M after a cyberattack exposed 750,000+ patient prescription records from the pharmacy chain's systems.

2024-02-01
🇪🇺 EU GDPR

TikTok Fined €345M for Children's Data Violations

Irish DPC fined TikTok EUR 345M after public-by-default settings for children's accounts exposed minors' personal data to strangers.

2023-09-01
🇯🇴 Jordan

Jordan Cybercrime Law 2023: New Rules, Broader Powers, Unresolved Gaps

Analysis of Jordan's Cybercrime Law No. 17/2023, which replaced the 2015 framework with expanded prosecutorial powers and broader offense definitions but.

2023-09-01
🇪🇺 EU GDPR

Meta Fined €1.2B for Illegal EU-to-US Data Transfers

Irish DPC imposed the largest single GDPR fine ever, EUR 1.2B, for Meta's systematic transfer of EU Facebook user data to US servers after the Schrems II.

2023-05-01
🇪🇺 EU GDPR MEDIUM

Google Fined €325M for Cookie Consent Violations

CNIL fined Google EUR 325M for deploying dark patterns that made refusing cookies harder than accepting them, affecting consent across millions of French users.

2025-09-01
🇪🇺 EU GDPR

Clearview AI Fined €30.5M for Illegal Facial Recognition

Clearview AI scraped 30 billion+ facial images from social media without consent to build a biometric database. Multiple EU authorities imposed fines.

2024-09-01
🇪🇺 EU GDPR

British Airways Fined £20M for Magecart Payment Card Breach

ICO fined British Airways GBP 20M after a Magecart skimming attack stole payment card details and personal data from 429,612 customers over a 75-day window.

2020-10-01
🇺🇸 USA

Meta/Facebook: $5 Billion FTC Fine for Cambridge Analytica

Cambridge Analytica harvested 87M Facebook users' data for political profiling, violating a prior FTC consent decree. The $5B fine was the largest ever.

2019-07-01
🇺🇸 USA

Capital One: 106M Records Stolen via AWS Misconfiguration

A former AWS engineer exploited a misconfigured WAF via SSRF to steal 106M credit card applications spanning 14 years, including 140K SSNs.

2019-07-01
🇺🇸 USA

Equifax: 147M Americans' SSNs Stolen - $700M Settlement

An unpatched Apache Struts vulnerability led to 76 days of undetected data theft affecting 147M Americans. Equifax settled for up to $700M with the FTC.

2017-09-01
🌍 GLOBAL HIGH

INTERPOL Operation Synergia III: 45,000 Malicious IPs Dismantled, 94 Arrested Across 72 Countries

INTERPOL's largest coordinated cyber takedown of 2026 dismantled 45,000+ malicious IPs, arrested 94 suspects, and seized 212 devices across 72 countries.

2026-03-13