US Companies on Pace to Pay $1.4 Billion in Privacy Settlements

A law passed in 1968 is apparently driving a new surge in privacy violation settlements.

    Get the Full Story

    Complete the form to unlock this article and enjoy unlimited free access to all PYMNTS content — no additional logins required.

    Subscribe to our daily newsletter, PYMNTS Today.

    By completing this form, you agree to receive marketing communications from PYMNTS and to the sharing of your information with our sponsor, if applicable, in accordance with our Privacy Policy and Terms and Conditions.

    That’s according to new research published Monday (Oct. 5) by privacy platform Privado AI, showing that American companies are on track this year to pay upwards of $1.4 billion to settle claims that their websites and mobile apps shared personal data without permission. That’s a 36% increase over last year’s amount, the company said.

    “Privacy claims are rising fast. Most of the companies facing litigation had a consent management platform in place, and they are not as covered as they thought,” Vaibhav Antil, CEO of Privado AI, said in a news release.

    “The 116 public settlements we have analyzed in our report are the tip of the iceberg. It’s estimated there were as many as 100,000 privacy claims against companies between 2022 and 2025. Many will have settled privately, so the real cost to companies is likely far higher than the $1.4 billion paid out in public class action settlements.”

    We’d love to be your preferred source for news.

    Please add us to your preferred sources list so our news, data and interviews show up in your feed. Thanks!

    The release adds that it is “pre-internet” wiretapping laws driving settlements, rather that new privacy laws. The Federal Wiretap Act, adopted in 1968, showed up in 53% of this year’s settlements. And the California Invasion of Privacy Act (CIPA), passed in 1967 appears in 43%, a 20% increase compared to 2025.

    “Wiretapping laws let any individual sue and set fixed damages per violation; the state privacy laws written for the internet, including California’s CCPA, can be enforced only by regulators,” the news release added.

    Meanwhile, PYMNTS wrote in August that federal and state regulators “are expanding their scrutiny of digital business practices by treating privacy violations and deceptive consumer practices as part of the same enforcement framework.”

    This shift can be seen in a recent enforcement action brought by the Federal Trade Commission (FTC), and states California and Utah against telehealth provider Hims & Hers.

    Per a client alert from Lowenstein Sandler, the complaint covers allegations involving deceptive recurring billing practices as well as allegations that the company improperly shared sensitive customer health information with ad platforms.

    “The lawsuit reflects an evolving enforcement strategy in which regulators evaluate a company’s entire customer experience, from advertising and consent mechanisms to subscription billing, cancellation procedures and downstream data sharing, rather than treating privacy and consumer protection issues as separate compliance matters,” PYMNTS wrote.

    “For businesses, particularly those deploying artificial intelligence (AI) and data-driven personalization tools, the case serves as another reminder that compliance programs can no longer address privacy, marketing and subscription practices in isolation,” the report added.