惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

MongoDB | Blog
MongoDB | Blog
B
Blog RSS Feed
MyScale Blog
MyScale Blog
M
MIT News - Artificial intelligence
H
Hackread – Cybersecurity News, Data Breaches, AI and More
J
Java Code Geeks
U
Unit 42
Blog — PlanetScale
Blog — PlanetScale
L
LangChain Blog
C
Check Point Blog
WordPress大学
WordPress大学
Last Week in AI
Last Week in AI
人人都是产品经理
人人都是产品经理
T
Tailwind CSS Blog
Vercel News
Vercel News
腾讯CDC
GbyAI
GbyAI
有赞技术团队
有赞技术团队
S
SegmentFault 最新的问题
H
Help Net Security
博客园 - 三生石上(FineUI控件)
D
DataBreaches.Net
Microsoft Security Blog
Microsoft Security Blog
小众软件
小众软件

Help Net Security

FIDO Alliance wants to keep AI agents from going rogue on online payments Police arrest 10 suspected members of Black Axe cybercrime gang ShinyHunters claims it stole 1.4 million records from Udemy Sevii unveils Cyber Swarm Defense Mode to stop AI-driven attacks at scale Alleged Chinese hacker extradited to US over cyberattacks targeting COVID-19 research Cequence Agent Personas bring granular control and governance to enterprise AI agents NowSecure MARI gives enterprises evidence-based visibility into third-party mobile app risk The metrics killing your SOC, and what to use instead Canada’s first SMS blaster case leads to three arrests Linux storage management tool Stratis 3.9.0 adds online encryption and cache-less pool startup TLS Connect gives SMBs a right-sized automated tool to manage TLS certificates Aptori expands its platform with autonomous offensive testing to reduce security bottlenecks Your IAM was built for humans, AI agents don’t care The AI criminal mastermind is already hiring on gig platforms 25 open-source cybersecurity tools that don’t care about your budget Product showcase: LuLu reveals unauthorized outbound connections from Mac apps Week in review: Claude Mythos finds 271 Firefox flaws, Vercel breach Users advised to drop passwords and make room for passkeys - Help Net Security Indirect prompt injection is taking hold in the wild - Help Net Security Compromised everyday devices power Chinese cyber espionage operations - Help Net Security New Cisco firewall malware can only be killed by pulling the plug - Help Net Security Meta is overhauling how you sign in, manage settings, and protect your accounts - Help Net Security Ubuntu 26.04 LTS delivers memory-safe system tools and live patching for Arm servers - Help Net Security OpenAI’s GPT-5.5 is out with expanded cybersecurity safeguards - Help Net Security AI is speeding up nation-state cyber programs - Help Net Security A study of 1,000 Android apps finds a privacy policy logging gap - Help Net Security IT spending to hit $6.31 trillion record, thanks to AI - Help Net Security Where AI in CI/CD is working for engineering teams - Help Net Security With AI's help, North Korean hackers stumbled into a near-undetectable attack - Help Net Security Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security
US state privacy fines reached $3.425 billion in 2025
Mirko Zorz · 2026-04-28 · via Help Net Security

State privacy regulators across the United States collected $3.425 billion in privacy-related fines from companies in 2025. Gartner said the upward trend is expected to accelerate through 2028. Annual cumulative fines stood at $1.827 billion in 2024, putting the 2025 result at nearly double the previous year’s level.

Gartner derived the estimate by compiling and aggregating enforcement actions and statutory private rights of action tied to state and federal privacy laws.

US state privacy fines

A turning point for state-level enforcement

Privacy regulators are moving from awareness-building into direct penalty activity. “Privacy laws across the U.S. have been in place long enough for Gartner to start seeing a trend of new amendments introducing fresh obligations. These new obligations are primarily focused on automated decision-making technologies,” said Nader Henein, VP Analyst at Gartner. “Regulators are also shifting their efforts away from spreading awareness to full-scale enforcement. This is increasingly becoming the standard in 2026 and beyond.”

The shift coincides with continued growth in the number of US states with consumer privacy statutes. Twenty-two states have passed privacy laws aimed primarily at consumer privacy rights, covering more than half of the US population. Another 24 states have proposed similar legislation and are expected to pass it over the next five years. Kansas, Idaho, South Dakota, and Wyoming sit outside this trend, focusing on narrower measures covering areas such as children’s data and genetic information.

Henein said the state-by-state pattern resembles the earlier rollout of breach disclosure laws, which spread from California in July 2003 to Alabama as the 50th state in March 2018.

AI and automated decisions are driving new amendments

Personal data has moved to the center of AI model training and inference, and state regulators are revising privacy frameworks to address automated decision-making technologies alongside a parallel patchwork of state AI governance laws. Because much of the world’s data sits with US-registered companies, US privacy laws affect data protection levels well beyond US residents.

Enforcement intensity tracks with regulator activity

Independent research published this month reinforces a pattern that helps explain why state-level totals are climbing. A measurement study of web tracking across ten jurisdictions found that privacy laws produce results where regulators bring cases, and produce far less where they do not. EU regulators have issued 833 fines totaling €3.01 billion for processing data without a valid legal basis. Germany and Spain were categorized as high-enforcement jurisdictions, with California, Canada, Australia, and South Korea grouped at a medium level of activity that depends heavily on individual high-profile cases.

The same research documented recent California enforcement actions. The California Attorney General settled with Disney for $2.75 million over failures to honor opt-out signals, and the California Privacy Protection Agency has brought actions against PlayOn Sports and Ford. These cases align with Gartner’s view that state enforcement has moved into a sustained penalty phase.

The analysis also found that advertising trackers account for roughly two-thirds of recorded tracking connections on the web, with consent management consolidating around a small number of platforms. Recent California cases have centered on operational failures in this layer, particularly failures to honor consumer opt-out signals.

Recommendations for CISOs and privacy leaders

Gartner recommends two priorities for CISOs and leaders responsible for privacy programs. The first is a critical review of existing programs. Many organizations operating only in the United States built their privacy programs in 2020 and have allowed them to atrophy in the years since, leaving them poorly positioned for the current enforcement environment. Programs need to be reassessed to confirm they continue to provide adequate and defensible compliance.

The second priority is privacy user experience. Most fines and violations tie back to shortcomings in how organizations handle subject rights, consent, and privacy notices. Improvements in these areas address the operational gaps that regulators are most likely to find and penalize.

Webinar: The IT Leader’s Guide to AI Governance