Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
enforcement-actionprivacy-surveillance-policycybersecurity-regulation

Regulatory Enforcement and Penalty Updates for Privacy Violations

Updated 3mo agoFirst seen Jan 29, 20263 sources

Regulators and courts continued to impose and update financial consequences for privacy violations across major regimes. In the EU, GDPR enforcement remained significant, with cumulative fines since 2018 reaching €7.1B and annual totals around €1.2B, while Ireland’s Data Protection Commission continued to lead enforcement totals due to the EU headquarters of major US tech firms; notable penalties cited include €1.2B against Meta Platforms Ireland Ltd. and €530M against TikTok for alleged transfers of EU user data to China.

In the US, Apple began issuing payments under a $95M settlement tied to allegations that Siri captured private conversations and that data was used for advertising, with per-device payouts reported as variable and capped (up to five devices per claimant). Separately, the US Department of Health and Human Services’ Office for Civil Rights implemented an inflation-based increase to HIPAA civil monetary penalties effective immediately, updating tiered per-violation minimums and maximums and noting the adjustment was applied later than the statutory schedule required under the federal inflation adjustment framework.

Share:
Regulatory Enforcement and Penalty Updates for Privacy Violations
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

9 events from the most recent confirmed update back to the earliest known activity.

9 EVENTS
Jan 28, 20265mo ago

HHS raises HIPAA civil monetary penalties for inflation

HHS' Office for Civil Rights increased HIPAA civil monetary penalties effective January 28, 2026, applying the overdue 2025 inflation adjustment. Updated penalty tiers range from a $145 minimum per violation up to $73,011 per violation, with annual caps reaching $2,190,294 depending on the tier.

Jan 23, 20265mo ago

Apple begins issuing Siri settlement payments to claimants

Payments tied to Apple's $95 million Siri settlement began appearing in claimants' accounts, reportedly labeled 'Lopez v. Apple.' Reports said payouts started appearing on January 23, 2026, with awards capped at $20 per device but sometimes reduced when multiple devices were claimed.

Jul 2, 20251y ago

Deadline passes for Apple Siri settlement claims

The deadline to file claims in the Apple Siri settlement was July 2, 2025. Eligible claimants were owners of Siri-enabled Apple devices used between September 17, 2014 and December 31, 2024, with up to five devices per claimant.

Apr 1, 20251y ago

TikTok fined €530 million over China data transfers

TikTok Technology Ltd. was fined €530 million in April 2025 for transferring personal user data to China. The penalty was cited as one of the major recent GDPR enforcement actions.

Jan 17, 20251y ago

HHS misses statutory deadline for 2025 HIPAA inflation adjustment

The Department of Health and Human Services did not apply the required 2025 inflation adjustment to HIPAA civil monetary penalties by the January 17, 2025 deadline set under the Federal Civil Penalties Inflation Adjustment Act Improvements Act of 2015. The adjustment was later described as more than a year overdue.

May 22, 20233y ago

Meta receives record €1.2 billion GDPR fine

European regulators imposed a €1.2 billion GDPR fine on Meta Platforms Ireland Ltd., identified in the reporting as the largest GDPR penalty to date. The fine contributed significantly to Ireland's leading enforcement total under the GDPR.

Mar 17, 20215y ago

Lawsuit filed against Apple over Siri eavesdropping allegations

A lawsuit was filed in California alleging Siri unlawfully recorded private conversations and that the data was used for advertising purposes. Apple denied wrongdoing but later agreed to settle the case to avoid further litigation.

Jan 1, 20197y ago

The Guardian reports Apple contractors reviewed Siri recordings

Reporting in 2019 revealed that Apple used subcontractors to review Siri recordings and that accidental activations sometimes captured sensitive private conversations. The disclosures became a key basis for later litigation over alleged unlawful recording and use of Siri data.

May 25, 20188y ago

GDPR takes effect across the European Union

The EU General Data Protection Regulation came into force, establishing the enforcement regime under which European data protection authorities have since issued billions of euros in fines. DLA Piper said cumulative GDPR fines have reached €7.1 billion since May 2018.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

15 LINKEDOpen in app
Affected products
5 linked
Apple TvImacIpod TouchIpadIphone
Organizations
10 linked
AppleGoogleDLA PiperTikTokMeta PlatformsMeta Platforms IrelandThe GuardianCBS NewsUSA TodayMacRumors
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Regulatory Enforcement and Penalty Updates for Privacy Violations | Mallory