A PII violation is any unauthorized collection, use, sharing, or exposure of personally identifiable information—and an organization that fails to protect PII faces consequences in four broad categories: regulatory fines, private lawsuits, criminal liability, and reputational damage. Personally identifiable information is any piece of sensitive information that can be used to uniquely identify an individual, either directly or indirectly. In the US, PII protection isn't regulated by one federal law; a patchwork of federal and state laws, industry standards, and common-law claims all apply at once—which is exactly why the consequences are so hard to predict, and so easy to underestimate.
The short version: mishandled PII exposes you to FTC and state AG enforcement, statutory damages of $100–$7,500 per consumer under state laws, class actions, PCI penalties, and—in willful cases—criminal charges. IBM's 2025 Cost of a Data Breach report puts the average US breach at $10.22 million (global average: $4.44 million).
For example, consumer protection laws such as the Federal Trade Commission Act↗ (FTC Act) make it illegal to collect, use, process, or share PII in an unfair or deceptive way. In addition, as of 2026, nineteen states enforce comprehensive privacy laws of their own—up from five just three years ago. The scope and duties of these laws vary, but the enforcement trend does not: it's accelerating.
What Consequences Can an Organization That Fails to Protect PII Face?
When an organization mishandles, exposes, or fails to safeguard PII, the fallout typically arrives in some combination of the following forms:
- Regulatory fines and civil penalties imposed by the FTC, a state Attorney General, or California's dedicated privacy regulator (the CPPA).
- Private lawsuits and class actions brought by affected individuals, often after a data breach.
- Criminal liability for individuals who knowingly misuse or improperly disclose PII.
- Mandatory remediation, such as third-party audits, security overhauls, and years of regulatory monitoring.
- Reputational damage and lost revenue as customers lose trust and take their business elsewhere.
Here's how the major penalty regimes compare:
| Law / regime | Who enforces it | Penalty exposure |
|---|---|---|
| FTC Act §5 | FTC | Consent decrees, monetary relief, up to 20 years of monitoring |
| CCPA / CPRA (California) | CA Attorney General + CPPA | $2,500 per violation; $7,500 if intentional or involving minors' data |
| CCPA private right of action | Consumers directly | $100–$750 statutory damages per consumer per breach incident |
| Other state privacy laws (18 more states) | State AGs | Typically $2,500–$7,500 per violation |
| BIPA (Illinois biometrics) | Consumers directly | $1,000 per negligent / $5,000 per intentional violation |
| GDPR (EU customers) | EU data protection authorities | Up to €20M or 4% of global revenue |
| PCI DSS (card data) | Card networks / acquirers | $5,000–$100,000 per month until compliant |
The sections below break down each of these consequences, how they're triggered, and what an organization can do to avoid them. For a deeper look at the dollar figures involved, see our breakdown of what privacy fines really do to mid-market brands.
Fines and Civil Penalties for PII Violations
Breaching PII often leads to fraud like identity theft. Violations involving confidential and sensitive information also happen when:
- PII is accessed, used, or shared without permission, whether physical or electronic.
- There is a failure to report a PII breach.
- An employee or agency deliberately distributes personal information to any person or agency not authorized to receive it.
- Anyone requests or obtains an individual's record from an agency under false pretenses.
Organizations that mishandle PII can face civil penalties — payment of damages, legal fees, and regulatory enforcement — and, in serious cases involving willful or fraudulent misuse, criminal liability for the individuals responsible.
And these aren't theoretical. In 2025, California regulators landed three consent-related enforcement actions in a single year: a $1.55 million settlement with Healthline (the largest CCPA penalty to date, announced July 2025), a $632,500 fine against American Honda, and a $345,178 fine against retailer Todd Snyder. All three shared the same root cause—personal data flowing to third parties without properly honored consent or opt-outs.
To avoid violations, every organization that handles PII should adhere to the best security practices for protecting PII. This includes installing firewall and antivirus software and enforcing an eCommerce privacy policy. If you're not sure where your exposure lies, start by understanding what counts as PII in the first place.
How to Report a PII Violation
Visit the FTC website and navigate to their identity theft page↗. If you want to report a scam or fraud incident, head on to the FTC fraud page↗.
Data Breaches: The Costliest Consequence of a PII Violation
A data breach is where the abstract risk of failing to protect PII turns into a concrete, expensive event. When exposed records contain customer names, emails, addresses, or payment details, an organization can face consequences on several fronts at once: mandatory breach notifications, regulatory investigations, class-action lawsuits, and the operational cost of remediation. IBM's 2025 report put the average cost of a US breach at $10.22 million—driven in part by regulatory penalties—even as the global average fell to $4.44 million.
If you want a case study in how far the consequences can cascade, look at 23andMe. A 2023 credential-stuffing breach exposed data tied to roughly 6.9 million people. What followed: a wave of class actions, a £2.31 million fine from the UK's ICO in June 2025, a Chapter 11 bankruptcy filing in March 2025 under the weight of legal costs and collapsed consumer trust, and a $46.75 million breach settlement approved by the bankruptcy court in July 2026. A single failure to protect PII ultimately consumed the company.
Most US states require you to notify affected individuals—and often a state Attorney General—within a defined window after discovering a breach. Missing that deadline is itself a violation that compounds the original failure. For a step-by-step view of what to do in the hours and days after an incident, see our data breach response checklist for eCommerce sellers, and review the broader legal implications of an eCommerce data breach before one happens.
The pattern is consistent: the organizations that weather a breach with the least damage are the ones that already had documented consent, a data inventory, and a response plan in place. The ones that improvise after the fact face the full stack of consequences.
PII Violations in eCommerce: Where Most Brands Get It Wrong
Your eCommerce platform collects PII every single day—email addresses, shipping addresses, payment information, phone numbers. But many mid-market brands don't realize they're violating privacy laws simply by collecting or storing this data without proper consent.
The most common mistake? Assuming that because a customer buys from you, you can use their data however you want. That's not how it works. You need explicit consent before you:
- Add them to your email marketing list (CASL and CAN-SPAM require this)
- Track their behavior with pixels (Meta Pixel, Google Analytics) after they leave your site
- Share their data with third-party apps (Klaviyo, Gorgias, inventory tools)
- Retain their information longer than necessary
If you're running Shopify or BigCommerce, your platform collects PII on your behalf—which means you're liable if that data is mishandled. Many brands assume Shopify's security is enough. It's not. You still need to manage consent, document data flows, and honor customer rights to deletion.
Regulators are not just targeting massive retailers—the 2025 California actions hit a mid-market clothing brand (Todd Snyder) alongside household names, and the CPPA has said publicly it looks for consent tools that don't actually work. A single complaint from a customer who didn't consent to email marketing, or who submitted a data subject access request (DSAR) you ignored, can trigger an investigation. Fines start at thousands of dollars and climb quickly once legal fees enter the picture.
The safest approach: assume every piece of PII requires consent, document that consent, and make it easy for customers to opt out or request deletion. This isn't just compliance—it's good business.
State Privacy Laws: Your Compliance Checklist
The US doesn't have a single federal privacy law like GDPR. Instead, you're juggling multiple state regimes, and the rules change depending on where your customers live.
California's CCPA (and its stricter successor, CPRA) applies to any brand with California customers if you meet the threshold: $25 million in revenue, buy/sell personal info of 100,000+ people, or derive 50%+ of revenue from selling customer data. Most eCommerce brands hit one of these triggers.
And California is no longer the outlier—it's the template. As of 2026, nineteen states have comprehensive privacy laws in effect. The recent wave alone: Tennessee (July 2025), Minnesota (July 2025), Maryland (October 2025), and Indiana, Kentucky, and Rhode Island (January 2026). Maryland's law is notably stricter than the pack—it imposes a hard data-minimization duty and bans selling sensitive data outright. Rhode Island's thresholds are notably low, reaching businesses that process data of just 35,000 consumers in some cases. Each of these laws gives customers the right to:
- Know what PII you collect and why
- Delete their data
- Opt out of data sales or targeted advertising
- Correct inaccurate information
For your Shopify or BigCommerce store, this means:
- Your privacy policy must list every data processor (payment gateway, email provider, analytics tool)
- You need a process to handle deletion requests within the state's deadline (usually 45 days)
- You must honor opt-out requests for marketing and behavioral tracking—including the browser-level Global Privacy Control signal, which California and a growing set of states treat as a binding opt-out
- You need to track consent—not just assume it
The penalty structure varies by state, but violations can cost $100–$7,500 per customer per incident. If you have 10,000 customers in California and you mishandled 500 DSARs, you're looking at six-figure exposure. For the full state-by-state picture, see our 2026 data privacy legislation guide.
Start by mapping where your customers live. Then audit which state laws apply to your business. A free CCPA compliance scan of your site is a fast way to see whether your trackers and consent flows would survive a regulator's first look. Don't wait until you're audited.
Payment Card Industry (PCI) Compliance: Beyond PII
If your store processes credit cards directly (or stores card data), you're also subject to PCI DSS—a separate compliance standard that overlaps with PII protection but has its own teeth.
PCI DSS requires you to:
- Encrypt card data in transit and at rest
- Never store full card numbers after a transaction
- Use tokenization or a PCI-compliant payment processor
- Audit access logs and monitor for suspicious activity
Most Shopify and BigCommerce stores are not PCI-compliant themselves because they use hosted payment forms or third-party gateways (Stripe, Square, PayPal). Those processors handle compliance for you. But if you're capturing card data in any other way—custom integrations, spreadsheets, email—you're opening yourself to both PCI fines and PII liability.
A PCI violation can result in penalties of $5,000–$100,000 per month until you're compliant. Your payment processor can also terminate your account.
The practical takeaway: never store raw payment data. Always use a PCI-compliant processor or tokenization service. Document this decision in your privacy policy so customers know their card data is protected.
What Happens After You're Caught: Investigation and Remediation
If a customer files a complaint with their state's Attorney General or the FTC, you'll likely receive a civil investigative demand (CID)—a formal request for all documents related to your data practices.
This is where many brands panic. You'll need to produce:
- Your privacy policy and all versions you've published
- Consent records (if you kept them)
- Data processing agreements with vendors
- Security audit reports
- Customer communication about data retention
- Any breach notification emails you've sent
If you don't have these documents, regulators interpret that as evidence of negligence. Your lack of documentation is a violation.
Once the agency investigates, you may face a settlement agreement that requires you to:
- Overhaul your privacy policy
- Implement third-party security audits
- Create a data governance program
- Pay civil penalties and customer restitution
- Submit to monitoring for 10+ years
The total cost—legal fees, remediation, settlements, monitoring—routinely runs into the six figures for mid-market brands. The 2025 California settlements all included binding injunctive terms on top of the fines: contract overhauls with every downstream data recipient, working opt-out mechanisms, and ongoing compliance reporting. That's why prevention is far cheaper than defense.
The best defense is a system. You need clear consent flows, documented data inventories, audit trails, and a process to honor customer requests when they come in. Without automation, you'll lose track of who consented to what, and enforcement agencies will notice.
How Privacy Lawsuits and Settlements Actually Unfold
Beyond regulators, two private routes can hit a brand after a PII failure: individual lawsuits and class actions.
Individual lawsuits typically allege negligence (you didn't take reasonable steps to protect the data), breach of contract (you broke a privacy promise), or violation of a specific statute. Depending on the claim, a plaintiff can recover out-of-pocket losses (fraud charges, credit monitoring), identity-theft recovery costs, statutory damages set by law, and — for especially reckless conduct — punitive damages.
Class actions bundle hundreds or thousands of affected people into one case, and they tend to follow a predictable arc:
- Certification — a judge decides whether the group's claims are similar enough to proceed together.
- Discovery — both sides exchange evidence; expect forensic review of your security and internal emails about any known weaknesses.
- Resolution — most settle, with payouts to affected individuals plus binding commitments to improve security. A few go to trial.
Settlements and consent decrees rarely stop at a check. Whether you're resolving a class action or a regulator's action, expect non-monetary terms too: rewriting your privacy policy, third-party security audits, a formal data-governance program, and sometimes years of outside monitoring. That's why the documentation you keep before anything goes wrong — consent records, data maps, DPAs, audit trails — is what tilts these outcomes in your favor.
How to Make Sure Your Organization Doesn't Face These Consequences
The consequences an organization that fails to protect PII can face are largely avoidable—not by buying more software, but by building a repeatable system around three things: collecting only the PII you need, documenting consent for everything you collect, and being able to prove both on demand.
In practice, that means:
- Map your data. Know exactly what PII you collect, where it lives, and which vendors touch it. You can't protect or delete data you haven't inventoried.
- Capture and store consent. Treat every piece of PII as requiring consent, and keep records that show when and how it was given.
- Honor customer rights on time. Build a process to handle deletion and access requests within each applicable state deadline, rather than scrambling per request.
- Keep your documentation current. A privacy policy, data processing agreements, and audit trails are your evidence of good faith if a regulator ever asks.
(If any of these terms are new, our privacy glossary covers DSARs, data mapping, consent records, and the rest.)
This is the work PieEye is built to automate for Shopify and BigCommerce brands—consent capture, data mapping, and DSAR handling in one place. If you'd like to see how it fits your store, book a walkthrough.
Frequently Asked Questions
How do the FTC and state attorneys general enforce privacy violations?
The FTC acts under Section 5 of the FTC Act against unfair or deceptive data practices — including failing to maintain reasonable security — even without intent to harm. State AGs investigate under their own laws, often after a breach or complaint, and can impose penalties and binding remediation. California added a dedicated regulator, the CPPA, which issued its largest fine to date in 2025.
What is the CCPA private right of action?
It lets California consumers sue directly if their non-encrypted personal information is exposed in a breach caused by inadequate security — with statutory damages of $100–$750 per consumer per incident, no proof of harm required. Across thousands of records, that adds up fast.
What are recent examples of PII violation penalties?
In 2025, California regulators fined Healthline $1.55 million (the largest CCPA settlement to date), Honda $632,500, and Todd Snyder $345,178 — all for consent and opt-out failures. The 23andMe breach led to a £2.31 million UK fine, a Chapter 11 bankruptcy, and a $46.75 million class settlement approved in July 2026. IBM puts the average US breach cost at $10.22 million.
What is BIPA and why is it so risky?
Illinois's Biometric Information Privacy Act requires informed written consent before collecting biometric data (fingerprints, facial scans, voiceprints). Violations carry statutory damages of $1,000 per negligent and $5,000 per intentional violation — which is why biometric class actions have produced enormous settlements.
What are the maximum GDPR fines for a privacy violation?
Up to the greater of €20 million or 4% of worldwide annual revenue — and regulators use that ceiling: TikTok was fined €530 million in May 2025 over transfers of EU user data to China. Separately, under Article 82, any individual who suffers harm from unlawful processing can claim compensation directly from the company.