|
CNIL (France) fines undisclosed company €3.5 million for selling member data
On December 30, 2025 (announced January 22, 2026), the French Data Authority CNIL fined an undisclosed company €5 million for transferring loyalty program member data of more than 10 million individuals to a social network for ad targeting without valid user consent.
CCPA settles claims with two companies for violation of Data Broker Law
On January 8, 2026, the California Privacy Protection Agency (CCPA) reached settlements with Rickenbacher Data LLC (Datamasters) for $45,000 and S&P Global, Inc. for $62,000 for failing to register as a data broker. Datamasters is barred from selling any personal data of California residents.
Kentucky Attorney General files lawsuit against Character.AI over interactions with minors
On January 8, 2026, the Kentucky Attorney General’s office announced a lawsuit against Character.AI, a popular online chatbot, for violations of various Kentucky laws, including the Consumer Data Protection Act, for prioritizing profits by allowing children to engage with chatbots with a history of psychological manipulation and encouraging suicide, self-injury, and isolation.
France's CNIL fines Free Mobile €42 million connected to data breach
On January 13, 2026, the French Data Authority CNIL fined Free Mobile and Free a total of €42 million for inadequate measures taken to protect their subscriber’s personal data after data was stolen in a cyber attack.
England's ICO issues fine of £120,000 for unauthorized SMS marketing messages
On January 20, the England Information Commissioner’s Office (ICO) announced two fines, one £120,000 fine against Allay Claims, Ltd. and one £105,000 fine against ZMLUK Limited, for sending millions of direct marketing emails and text messages to individuals without obtaining proper consent.
France's CNIL fines France Travail €5 million connected to data breach
On January 29, 2026, the French Data Authority CNIL fined France Travail €5 million for failing to protect sensitive and high-volume public service datasets containing job seeker data that was stolen in a cyberattack.
|