Skip to main content
Mallory
Mallory

Regulatory Enforcement and Penalty Updates for Privacy Violations

regulatory enforcementprivacy violationscivil monetary penaltiesdata protection commissiongdproffice for civil rightshipaauser data
Updated January 29, 2026 at 11:02 AM3 sources
Regulatory Enforcement and Penalty Updates for Privacy Violations

Get Ahead of Threats Like This

Know if you're exposed — before adversaries strike.

Regulators and courts continued to impose and update financial consequences for privacy violations across major regimes. In the EU, GDPR enforcement remained significant, with cumulative fines since 2018 reaching €7.1B and annual totals around €1.2B, while Ireland’s Data Protection Commission continued to lead enforcement totals due to the EU headquarters of major US tech firms; notable penalties cited include €1.2B against Meta Platforms Ireland Ltd. and €530M against TikTok for alleged transfers of EU user data to China.

In the US, Apple began issuing payments under a $95M settlement tied to allegations that Siri captured private conversations and that data was used for advertising, with per-device payouts reported as variable and capped (up to five devices per claimant). Separately, the US Department of Health and Human Services’ Office for Civil Rights implemented an inflation-based increase to HIPAA civil monetary penalties effective immediately, updating tiered per-violation minimums and maximums and noting the adjustment was applied later than the statutory schedule required under the federal inflation adjustment framework.

Sources

January 28, 2026 at 07:42 PM

Related Stories

Rising Regulatory and Governance Pressure on Data Protection and Cybersecurity

Rising Regulatory and Governance Pressure on Data Protection and Cybersecurity

European regulators issued roughly **€1.2B** in **GDPR** fines in 2025 and received an average of **443 personal data breach notifications per day**, signaling increased enforcement and reporting volume alongside overlapping disclosure regimes such as **NIS2** and **DORA**. Ireland remained a leading enforcement authority, including a **€530M** fine against **TikTok**, while large technology firms continued to account for most of the largest penalties; cumulative GDPR penalties since 2018 were reported at **€7.1B**. In the U.S., an **HHS Office of Inspector General** management challenges report highlighted persistent federal healthcare cybersecurity gaps, including inconsistent governance and controls across HHS divisions and heavy dependence on contractors and grantees to implement security measures—conditions that complicate prevention and response as ransomware and other attacks continue to target healthcare. Separately, an academic study on insider risk reported that **58%** of surveyed college students in technology-related programs said they would violate **HIPAA** and disclose patient data for sufficient payment, underscoring the human/insider threat dimension that can drive breach risk and downstream regulatory exposure.

1 months ago
Regulatory Reporting Highlights Rising GDPR Enforcement and U.S. Healthcare Breach Disclosures

Regulatory Reporting Highlights Rising GDPR Enforcement and U.S. Healthcare Breach Disclosures

European privacy regulators issued roughly **€1.2B in GDPR fines in 2025** and received an average of **443 personal data breach notifications per day** (a reported 22% increase year over year), according to DLA Piper’s GDPR Fines and Data Breach Survey as cited by DataBreaches.net. The reporting indicates sustained enforcement since GDPR’s introduction, with cumulative penalties reaching **€7.1B** since 2018, alongside a continued high volume of breach notifications to data protection authorities. In the U.S. healthcare sector, HIPAA Journal reported that **November 2025** showed unusually low counts of large breaches listed on the HHS OCR breach portal (**32 incidents affecting 500+ individuals**), but attributed the apparent decline to reporting delays during the **U.S. government shutdown (Oct 1–Nov 12, 2025)** and a resulting backlog. Separately, Central Maine Healthcare disclosed a breach affecting **~145,000 individuals**, with unauthorized network access occurring between **Mar 19 and Jun 1, 2025** and exposure of data including **names and Social Security numbers** plus clinical/insurance details; notifications began in late December 2025 and credit monitoring was offered.

1 months ago
Healthcare and consumer privacy litigation over alleged improper data access and collection

Healthcare and consumer privacy litigation over alleged improper data access and collection

Multiple legal actions highlighted ongoing **privacy and data-protection risk** across healthcare and consumer platforms. Epic Systems sued health information exchange implementer **Health Gorilla** and several provider organizations, alleging improper access to roughly **300,000 patients’ records** and claiming some participants abused interoperability frameworks (including **Carequality** and **TEFCA**) to obtain and monetize sensitive health data without appropriate consent or authorization. Separately, pharmacy services provider **PharMerica** agreed to a **$5.2 million** class-action settlement tied to a **2023** hacking incident attributed to the **Money Message** ransomware group, which claimed exfiltration of **4.7 TB** and later leaked data affecting **5.8 million** people (including SSNs and medication/insurance details), alongside commitments to invest further in security. Outside healthcare, California’s Attorney General opened a probe into **xAI** after **Grok** was used to generate and post non-consensual sexualized deepfakes, while Google agreed to pay **$8.25 million** to settle claims that its **AdMob SDK** collected data from children’s devices in “Designed for Families” apps in alleged violation of **COPPA**; a separate YouTube children’s-data settlement was also noted. A HIPAA Privacy Rule update was also reported as moving closer to finalization following an HHS OCR tribal consultation notice, but it is a regulatory development rather than a specific incident.

1 months ago

Get Ahead of Threats Like This

Mallory continuously monitors global threat intelligence and correlates it with your attack surface. Know if you're exposed — before adversaries strike.