Description

Settlement regarding Carnival Cruise data breach

On 22 June 2022, the multistate investigation into the Carnival Cruise data breach concluded in a USD 1.25 million settlement. The investigation by 45 states and the District of Columbia found that Carnival Cruise did not adequately notify consumers and regulators of the data breach and that vulnerabilities in Carnival's data security programme contributed to the initial breach. The data breach concerned approximately 180'000 customers and employees in the United States, whose information including names, addresses, passport numbers, payment card information, health information and national insurance numbers were compromised.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cybersecurity regulation
Regulated Economic Activity
other service provider
Implementation Level
subnational
Government Branch
executive
Government Body
central government

Complete timeline of this policy change

Hide details
2020-03-02
under deliberation

In March 2020, a multistate investigation into a data breach by Carnival Cruise was initiated. The …

2022-06-22
in force

On 22 June 2022, the multistate investigation into the Carnival Cruise data breach concluded in a U…