{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,2]],"date-time":"2026-08-02T09:53:14Z","timestamp":1785664394682,"version":"3.56.0"},"reference-count":97,"publisher":"MDPI AG","issue":"4","license":[{"start":{"date-parts":[[2025,11,22]],"date-time":"2025-11-22T00:00:00Z","timestamp":1763769600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JCP"],"abstract":"<jats:p>Privacy harms have expanded alongside rapid technological change, challenging the adequacy of existing regulatory frameworks. This systematic review (1990\u20132025) systematically maps documented privacy harms to specific legal mechanisms and observed enforcement outcomes across jurisdictions, using PRISMA-guided methods and ROBIS risk-of-bias assessment. We synthesize evidence on major regimes (e.g., GDPR, COPPA, CCPA, HIPAA, GLBA) and conduct comparative legal analysis across the U.S., E.U., and underexplored regions in Asia, Latin America, and Africa. Key findings indicate increased recognition of data subject rights, persistent gaps in cross-border data governance, and emerging risks from AI\/ML\/LLMs, IoT, and blockchain, including data breaches, algorithmic discrimination, and surveillance. While regulations have advanced, enforcement variability and fragmented standards limit effectiveness. We propose strategies for harmonization and risk-based, technology-neutral safeguards. While focusing on the U.S. sectoral and E.U. comprehensive models, we include targeted comparisons with Canada (PIPEDA), Australia (Privacy Act\/APPs), Japan (APPI), India (DPDPA), Africa (POPIA\/NDPR\/Kenya DPA), and ASEAN interoperability instruments. This review presents an evidence-based framework for understanding the interplay between evolving harms, emerging technologies, and legal protections, and identifies priorities for strengthening global privacy governance.<\/jats:p>","DOI":"10.3390\/jcp5040103","type":"journal-article","created":{"date-parts":[[2025,11,24]],"date-time":"2025-11-24T09:02:07Z","timestamp":1763974927000},"page":"103","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["Privacy in Flux: A 35-Year Systematic Review of Legal Evolution, Effectiveness, and Global Challenges (U.S.\/E.U. Focus with International Comparisons)"],"prefix":"10.3390","volume":"5","author":[{"ORCID":"https:\/\/orcid.org\/0009-0002-7660-2107","authenticated-orcid":false,"given":"Kong","family":"Phang","sequence":"first","affiliation":[{"name":"Beacom College of Computer and Cyber Sciences, Dakota State University, Madison, SD 57042, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9677-9607","authenticated-orcid":false,"given":"Jihene","family":"Kaabi","sequence":"additional","affiliation":[{"name":"Beacom College of Computer and Cyber Sciences, Dakota State University, Madison, SD 57042, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2025,11,22]]},"reference":[{"key":"ref_1","unstructured":"Abbate, J. (2000). Inventing the Internet, MIT Press."},{"key":"ref_2","first-page":"793","article-title":"Privacy harms","volume":"102","author":"Citron","year":"2022","journal-title":"BUL Rev."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"10","DOI":"10.1177\/1095796018819461","article-title":"Surveillance capitalism and the challenge of collective action","volume":"Volume 28","author":"Zuboff","year":"2019","journal-title":"Proceedings of the New Labor Forum"},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Floridi, L., and Cowls, J. (2022). A unified framework of five principles for AI in society. Machine Learning and the City: Applications in Architecture and Urban Design, Wiley.","DOI":"10.1002\/9781119815075.ch45"},{"key":"ref_5","unstructured":"Schneier, B. (2015). Data and Goliath: The Hidden Battles to Collect Your Data and Control Your World, WW Norton & Company."},{"key":"ref_6","first-page":"215","article-title":"The Equifax data breach and the resulting legal recourse","volume":"13","author":"Kenny","year":"2018","journal-title":"Brook. J. Corp. Fin. Com. L."},{"key":"ref_7","unstructured":"Andrews, E.L. (2025, May 27). The Science Behind Cambridge Analytica: Does Psychological Profiling Work. Geli\u015f Tarihi, Available online: https:\/\/www.gsb.stanford.edu\/insights\/science-behind-cambridge-analytica-does-psychological-profiling-work."},{"key":"ref_8","unstructured":"Solove, D.J. (2004). The Digital Person: Technology and Privacy in the Information age, NyU Press."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"193","DOI":"10.2307\/1321160","article-title":"The right to privacy","volume":"4","author":"Warren","year":"1890","journal-title":"Harv. L. Rev."},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Nissenbaum, H. (2009). Privacy in context: Technology, policy, and the integrity of social life. Privacy in Context, Stanford University Press.","DOI":"10.1515\/9780804772891"},{"key":"ref_11","first-page":"583","article-title":"The FTC and the new common law of privacy","volume":"114","author":"Solove","year":"2014","journal-title":"Colum. L. Rev."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"61","DOI":"10.3354\/esep00076","article-title":"Google Scholar as a new source for citation analysis","volume":"8","author":"Harzing","year":"2008","journal-title":"Ethics Sci. Environ. Politics"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"253","DOI":"10.1007\/s11192-007-1722-z","article-title":"Generalized Hirsch h-index for disclosing latent facts in citation networks","volume":"72","author":"Sidiropoulos","year":"2007","journal-title":"Scientometrics"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"811","DOI":"10.1007\/s11192-013-1208-0","article-title":"hIa: An individual annual h-index to accommodate disciplinary and career length differences","volume":"99","author":"Harzing","year":"2014","journal-title":"Scientometrics"},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3590152","article-title":"Privacy policies across the ages: Content of privacy policies 1996\u20132021","volume":"26","author":"Wagner","year":"2023","journal-title":"ACM Trans. Priv. Secur."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"388","DOI":"10.1080\/0960085X.2021.1927212","article-title":"Algorithmic bias: Review, synthesis, and future research directions","volume":"31","author":"Kordzadeh","year":"2022","journal-title":"Eur. J. Inf. Syst."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"81608","DOI":"10.1109\/ACCESS.2024.3406724","article-title":"Challenges and enablers for GDPR compliance: Systematic literature review and future research directions","volume":"12","author":"Zaguir","year":"2024","journal-title":"IEEE Access"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Chen, S., Gu, C., Wei, J., and Lv, M. (2023). Research on the influence mechanism of privacy invasion experiences with privacy protection intentions in social media contexts: Regulatory focus as the moderator. Front. Psychol., 13.","DOI":"10.3389\/fpsyg.2022.1031592"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"1038","DOI":"10.1016\/j.tele.2017.04.013","article-title":"The privacy paradox\u2013Investigating discrepancies between expressed privacy concerns and actual online behavior\u2013A systematic literature review","volume":"34","author":"Barth","year":"2017","journal-title":"Telemat. Inform."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"695","DOI":"10.1111\/1756-2171.12455","article-title":"The effect of privacy regulation on the data industry: Empirical evidence from GDPR","volume":"54","author":"Aridor","year":"2023","journal-title":"RAND J. Econ."},{"key":"ref_21","first-page":"123","article-title":"Privacy\u2019s Other Path: Recovering the law of confidentiality","volume":"96","author":"Richards","year":"2007","journal-title":"Geo. LJ"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Prosser, W.L. (2014). California Law Review Vol. 48 August 1960 No. 3: Privacy. Pre-Nineteen Sixty Developments in the Bill of Rights Area, Routledge.","DOI":"10.2307\/3478805"},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"477","DOI":"10.2307\/40041279","article-title":"A taxonomy of privacy","volume":"154","author":"Solove","year":"2005","journal-title":"U. Pa. L. Rev."},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"662","DOI":"10.1080\/1369118X.2012.678878","article-title":"Critical questions for big data: Provocations for a cultural, technological, and scholarly phenomenon","volume":"15","author":"Boyd","year":"2012","journal-title":"Inf. Commun. Soc."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"2728","DOI":"10.1002\/sec.795","article-title":"Privacy in the Internet of Things: Threats and challenges","volume":"7","author":"Ziegeldorf","year":"2014","journal-title":"Secur. Commun. Netw."},{"key":"ref_26","first-page":"505","article-title":"Artificial intelligence and the \u2018good society\u2019: The US, EU, and UK approach","volume":"24","author":"Cath","year":"2018","journal-title":"Sci. Eng. Ethics"},{"key":"ref_27","unstructured":"Gellman, R. (2025). Fair Information Practices: A Basic History-Version 2.30. SSRN Electron. J., Available online: https:\/\/papers.ssrn.com\/sol3\/papers.cfm?abstract_id=5348107."},{"key":"ref_28","unstructured":"European Parliament and Council of the European Union (2016). Regulation (EU) 2016\/679 of the European Parliament and of the Council. Regulation (EU), 679, 2016."},{"key":"ref_29","unstructured":"Bonta, R. (2025, May 25). California Consumer Privacy Act (CCPA), Available online: https:\/\/oag.ca.gov\/privacy\/ccpa."},{"key":"ref_30","first-page":"1733","article-title":"Catalyzing privacy law","volume":"105","author":"Chander","year":"2020","journal-title":"Minn. L. Rev."},{"key":"ref_31","first-page":"2023","article-title":"How Americans view data privacy","volume":"18","author":"McClain","year":"2023","journal-title":"Pew Res. Cent."},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"307","DOI":"10.1007\/s13347-016-0220-8","article-title":"On human dignity as a foundation for the right to privacy","volume":"29","author":"Floridi","year":"2016","journal-title":"Philos. Technol."},{"key":"ref_33","first-page":"12","article-title":"Privacy by design: The 7 foundational principles","volume":"5","author":"Cavoukian","year":"2009","journal-title":"Inf. Priv. Comm. Ont. Can."},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"DeYoung, H., Garg, D., Jia, L., Kaynar, D., and Datta, A. (2010, January 4\u20138). Experiences in the logical specification of the HIPAA and GLBA privacy laws. Proceedings of the 9th Annual ACM Workshop on Privacy in the Electronic Society, Chicago, IL, USA.","DOI":"10.1145\/1866919.1866930"},{"key":"ref_35","first-page":"53181","article-title":"Standards for privacy of individually identifiable health information. Final rule","volume":"67","year":"2002","journal-title":"Fed. Regist."},{"key":"ref_36","first-page":"6","article-title":"The Guardian of The Digital Era: Assessing the Impact and Challenges of the Children\u2019s Online Privacy Protection Act","volume":"3","author":"Anderson","year":"2024","journal-title":"Law Econ."},{"key":"ref_37","first-page":"121","article-title":"Privacy Purgatory: Why the United States Needs a Comprehensive Federal Data Privacy Law","volume":"50","author":"Taetzsch","year":"2024","journal-title":"J. Legis."},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"252","DOI":"10.1016\/S0267-3649(00)89134-7","article-title":"European Data Protection: Determining Applicable Law Pursuant to European Data Protection Legislation","volume":"16","author":"Bygrave","year":"2000","journal-title":"Comput. Law Secur. Rev."},{"key":"ref_39","unstructured":"Greenleaf, G. (2025). 172 Countries with Data Privacy Laws-Year by Year 1973\u20132025. Priv. Laws Bus. Int. Rep., 16\u201317. Available online: https:\/\/ssrn.com\/abstract=5189972."},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"tyac011","DOI":"10.1093\/cybsec\/tyac011","article-title":"China\u2019s emerging data protection framework","volume":"8","author":"Creemers","year":"2022","journal-title":"J. Cybersecur."},{"key":"ref_41","first-page":"460","article-title":"The Court of Justice of the European Union ruling in Data Protection Commissioner v Facebook Ireland and Maximillian Schrems. Judgment in Case C-311\/18","volume":"3","author":"Baskett","year":"2020","journal-title":"J. Data Prot. Priv."},{"key":"ref_42","unstructured":"Parliament of Canada (2025, May 28). Personal Information Protection and Electronic Documents Act (S.C. 2000, c. 5). Available online: https:\/\/laws-lois.justice.gc.ca\/eng\/acts\/P-8.6\/FullText.html."},{"key":"ref_43","unstructured":"Australian Government (2025, May 28). Privacy Act 1988 (Cth), Available online: https:\/\/www.oaic.gov.au\/privacy\/privacy-legislation\/the-privacy-act."},{"key":"ref_44","unstructured":"Personal Information Protection Commission (PPC), Japan (2022). Act on the Protection of Personal Information (APPI), Amendments Effective 2022."},{"key":"ref_45","unstructured":"Ministry of Electronics and Information Technology (2023). The Digital Personal Data Protection Act, 2023, Act No. 22 of 2023."},{"key":"ref_46","unstructured":"Republic of South Africa (2013). Protection of Personal Information Act (POPIA), Commenced 1 July 2020."},{"key":"ref_47","unstructured":"Nigeria Data Protection Bureau (NDPB) (2019). Nigeria Data Protection Regulation (NDPR), Issued January 2019."},{"key":"ref_48","unstructured":"Republic of Kenya (2019). Data Protection Act, Kenya Gazette Supplement. Act No. 24 of 2019."},{"key":"ref_49","doi-asserted-by":"crossref","unstructured":"Chin, Y.C., and Zhao, J. (2022). Governing cross-border data flows: International trade agreements and their limits. Laws, 11.","DOI":"10.3390\/laws11040063"},{"key":"ref_50","doi-asserted-by":"crossref","first-page":"6","DOI":"10.1093\/idpl\/ipq002","article-title":"The history, achievement and future of the 1980 OECD guidelines on privacy","volume":"1","author":"Kirby","year":"2011","journal-title":"Int. Data Priv. Law"},{"key":"ref_51","doi-asserted-by":"crossref","unstructured":"Voigt, P., and Von dem Bussche, A. (2017). The EU General Data Protection Regulation (GDPR): A Practical Guide, Springer International Publishing. [1st ed.].","DOI":"10.1007\/978-3-319-57959-7"},{"key":"ref_52","doi-asserted-by":"crossref","unstructured":"Boeckl, K.R., and Lefkovitz, N.B. (2025, May 27). NIST Privacy Framework: A Tool for Improving Privacy Through Enterprise Risk Management, Version 1.0, Available online: https:\/\/www.nist.gov\/publications\/nist-privacy-framework-tool-improving-privacy-through-enterprise-risk-management.","DOI":"10.6028\/NIST.CSWP.10.may"},{"key":"ref_53","unstructured":"(2019). Information Technology\u2014Security Techniques\u2014Extension to ISO\/IEC 27001 and ISO\/IEC 27002 for Privacy Information Management\u2014Requirements and Guidelines (Standard No. ISO\/IEC 27701:2019). Technical Report."},{"key":"ref_54","doi-asserted-by":"crossref","first-page":"194","DOI":"10.21552\/edpl\/2020\/2\/7","article-title":"ISO\/IEC 27701 standard: Threats and opportunities for GDPR certification","volume":"6","author":"Lachaud","year":"2020","journal-title":"Eur. Data Prot. L. Rev."},{"key":"ref_55","unstructured":"(2022). Information Technology\u2014Security Techniques\u2014Information Security Management Systems\u2014Requirements (Standard No. ISO\/IEC 27001:2022). Technical Report."},{"key":"ref_56","first-page":"671","article-title":"Big data\u2019s disparate impact","volume":"104","author":"Barocas","year":"2016","journal-title":"Calif. L. Rev."},{"key":"ref_57","doi-asserted-by":"crossref","first-page":"17","DOI":"10.21552\/edpl\/2018\/1\/6","article-title":"Blockchains and data protection in the European Union","volume":"4","author":"Finck","year":"2018","journal-title":"Eur. Data Prot. L. Rev."},{"key":"ref_58","doi-asserted-by":"crossref","unstructured":"Zyskind, G., and Nathan, O. (2015, January 21\u201322). Decentralizing privacy: Using blockchain to protect personal data. Proceedings of the 2015 IEEE Security and Privacy Workshops, San Jose, CA, USA.","DOI":"10.1109\/SPW.2015.27"},{"key":"ref_59","unstructured":"Dwork, C. (2008, January 25\u201329). Differential privacy: A survey of results. Proceedings of the International Conference on Theory and Applications of Models of Computation, Xi\u2019an, China."},{"key":"ref_60","doi-asserted-by":"crossref","unstructured":"Dwork, C., and Roth, A. (2014). The Algorithmic Foundations of Differential Privacy, Foundations and Trends in Theoretical Computer Science, Now Publishers.","DOI":"10.1561\/9781601988195"},{"key":"ref_61","doi-asserted-by":"crossref","unstructured":"Erlingsson, \u00da., Pihur, V., and Korolova, A. (2014, January 3\u20137). RAPPOR: Randomized Aggregatable Privacy-Preserving Ordinal Response. Proceedings of the ACM CCS 2014, Scottsdale, AZ, USA.","DOI":"10.1145\/2660267.2660348"},{"key":"ref_62","doi-asserted-by":"crossref","unstructured":"Gentry, C. (June, January 31). Fully Homomorphic Encryption Using Ideal Lattices. Proceedings of the STOC 2009, Washington, DC, USA.","DOI":"10.1145\/1536414.1536440"},{"key":"ref_63","doi-asserted-by":"crossref","unstructured":"Halevi, S., and Shoup, V. (2014, January 17\u201321). Algorithms in HElib. Proceedings of the CRYPTO 2014, Santa Barbara, CA, USA.","DOI":"10.1007\/978-3-662-44371-2_31"},{"key":"ref_64","doi-asserted-by":"crossref","first-page":"409","DOI":"10.1007\/978-3-319-70694-8_15","article-title":"Homomorphic Encryption for Arithmetic of Approximate Numbers","volume":"Volume 10624","author":"Cheon","year":"2017","journal-title":"Proceedings of the ASIACRYPT 2017"},{"key":"ref_65","first-page":"86","article-title":"Intel SGX Explained","volume":"2016","author":"Costan","year":"2016","journal-title":"IACR Cryptol. EPrint Arch."},{"key":"ref_66","unstructured":"Van Bulck, J., Minkin, M., Weisse, O., Genkin, D., Kasikci, B., Piessens, F., Silberstein, M., Fogh, A., Yarom, Y., and Strackx, R. (2018, January 15\u201317). Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order Execution. Proceedings of the USENIX Security Symposium, Baltimore, MD, USA."},{"key":"ref_67","doi-asserted-by":"crossref","unstructured":"Schwarz, M., Weiser, S., Gruss, D., Giner, L., Maurice, C., and Mangard, S. (2017, January 6\u20137). Malware Guard Extension: Using SGX to Conceal Cache Attacks. Proceedings of the DIMVA 2017, Bonn, Germany.","DOI":"10.1007\/978-3-319-60876-1_1"},{"key":"ref_68","unstructured":"McMahan, H.B., Moore, E., Ramage, D., Hampson, S., and Aguera y Arcas, B. (2017, January 20\u201322). Communication-Efficient Learning of Deep Networks from Decentralized Data. Proceedings of the AISTATS 2017, Ft. Lauderdale, FL, USA."},{"key":"ref_69","doi-asserted-by":"crossref","unstructured":"Nasr, M., Shokri, R., and Houmansadr, A. (2019, January 20\u201322). Comprehensive Privacy Analysis of Deep Learning: Passive and Active White-box Inference Attacks Against Centralized and Federated Learning. Proceedings of the IEEE Symposium on Security and Privacy (S&P), San Francisco, CA, USA.","DOI":"10.1109\/SP.2019.00065"},{"key":"ref_70","first-page":"046","article-title":"Scalable, Transparent, and Post-Quantum Secure Computational Integrity","volume":"2018","author":"Bentov","year":"2018","journal-title":"IACR Cryptol. EPrint Arch."},{"key":"ref_71","doi-asserted-by":"crossref","unstructured":"B\u00fcnz, B., Bootle, J., Boneh, D., Poelstra, A., Wuille, P., and Maxwell, G. (2018, January 21\u201323). Bulletproofs: Short Proofs for Confidential Transactions and More. Proceedings of the IEEE Symposium on Security and Privacy (S&P), San Francisco, CA, USA.","DOI":"10.1109\/SP.2018.00020"},{"key":"ref_72","doi-asserted-by":"crossref","unstructured":"Narayanan, A., and Shmatikov, V. (2008, January 18\u201321). Robust De-anonymization of Large Sparse Datasets. Proceedings of the IEEE Symposium on Security and Privacy (S&P), Oakland, CA, USA.","DOI":"10.1109\/SP.2008.33"},{"key":"ref_73","unstructured":"(2018). Privacy Enhancing Data De-Identification Terminology and Classification of Techniques (Standard No. ISO\/IEC 20889:2018)."},{"key":"ref_74","doi-asserted-by":"crossref","first-page":"103670","DOI":"10.1016\/j.cose.2023.103670","article-title":"Deception in double extortion ransomware attacks: An analysis of profitability and credibility","volume":"138","author":"Meurs","year":"2024","journal-title":"Comput. Secur."},{"key":"ref_75","doi-asserted-by":"crossref","first-page":"e2510180","DOI":"10.1001\/jamanetworkopen.2025.10180","article-title":"Ransomware Attacks and Data Breaches in US Health Care Systems","volume":"8","author":"Jiang","year":"2025","journal-title":"JAMA Netw. Open"},{"key":"ref_76","first-page":"100013","article-title":"Information security breaches due to ransomware attacks\u2014A systematic literature review","volume":"1","author":"Reshmi","year":"2021","journal-title":"Int. J. Inf. Manag. Data Insights"},{"key":"ref_77","unstructured":"McKean, R., Magee, J., and de Souza, R. (2025, October 05). GDPR Fines and Data Breach Survey: January 2025. Available online: https:\/\/www.dlapiper.com\/en\/insights\/publications\/2025\/01\/dla-piper-gdpr-fines-and-data-breach-survey-january-2025."},{"key":"ref_78","first-page":"1131","article-title":"The boundaries of privacy harm","volume":"86","author":"Calo","year":"2011","journal-title":"Ind. LJ"},{"key":"ref_79","first-page":"1409","article-title":"Regulating privacy by design","volume":"26","author":"Rubinstein","year":"2011","journal-title":"Berkeley Tech. LJ"},{"key":"ref_80","first-page":"247","article-title":"Privacy on the Books and on the Ground","volume":"63","author":"Bamberger","year":"2010","journal-title":"Stan. L. Rev."},{"key":"ref_81","doi-asserted-by":"crossref","first-page":"32","DOI":"10.1109\/MITP.2015.34","article-title":"Big data privacy in the internet of things era","volume":"17","author":"Perera","year":"2015","journal-title":"IT Prof."},{"key":"ref_82","unstructured":"Goldwasser, S., Micali, S., and Rackoff, C. (2019). The knowledge complexity of interactive proof-systems. Providing Sound Foundations for Cryptography: On the Work of Shafi Goldwasser and Silvio Micali, ACM Digital Library."},{"key":"ref_83","unstructured":"California Privacy Protection Agency (CPPA) (2025, October 05). CPRA Enforcement Update: 2020\u20132025 Metrics and Cases. Expands CCPA Data to Include CPRA Actions, with 25+ New Investigations and $50 Million in Additional Penalties, Totaling $150 Million, Available online: https:\/\/cppa.ca.gov\/enforcement\/reports\/2025-update.html."},{"key":"ref_84","unstructured":"California Department of Justice, Office of the Attorney General (OAG) (2025, October 05). California Privacy Protection: Privacy Enforcement Actions. 2024. Lists CPRA\/CCPA Actions, Including over 100 Investigations Since 2020, with Fines Exceeding $10 Million (e.g., $1.2 Million Against Sephora in 2022). Highlights Under-Enforcement, with Only a Handful of Public Settlements Amid Thousands of Potential Violations, Available online: https:\/\/oag.ca.gov\/privacy\/privacy-enforcement-actions."},{"key":"ref_85","unstructured":"Federal Trade Commission (FTC) (2025, May 26). Protecting Consumer Privacy and Security: Privacy and Security Enforcement Actions, Available online: https:\/\/www.ftc.gov\/news-events\/topics\/protecting-consumer-privacy-security\/privacy-security-enforcement."},{"key":"ref_86","unstructured":"Enforcement Tracker (2024, October 06). Enforcement Tracker Insights. Available online: https:\/\/www.enforcementtracker.com\/?insights."},{"key":"ref_87","unstructured":"California Department of Justice, Office of the Attorney General (2025, May 29). Attorney General Bonta Announces Settlement with Sephora as Part of Ongoing Enforcement of California Consumer Privacy Act. Press Release, Available online: https:\/\/oag.ca.gov\/news\/press-releases\/attorney-general-bonta-announces-settlement-sephora-part-ongoing-enforcement."},{"key":"ref_88","unstructured":"California Department of Justice, Office of the Attorney General (2025, May 29). Attorney General Bonta Announces Largest CCPA Settlement to Date, Secures $1.55 Million from Healthline.com. Press Release, Available online: https:\/\/oag.ca.gov\/news\/press-releases\/attorney-general-bonta-announces-largest-ccpa-settlement-date-secures-155."},{"key":"ref_89","unstructured":"U.S. Department of Health and Human Services (2025, October 06). Enforcement Highlights, Available online: https:\/\/www.hhs.gov\/hipaa\/for-professionals\/compliance-enforcement\/data\/enforcement-highlights\/2023-november\/index.html."},{"key":"ref_90","unstructured":"Statista (2025, October 07). Largest Fines Issued for GDPR Violations (as of Feb 2025). Available online: https:\/\/www.statista.com\/statistics\/1133337\/largest-fines-issued-gdpr\/."},{"key":"ref_91","unstructured":"Data Privacy Manager (2025, October 07). 20 Biggest GDPR Fines so Far [2025]. Includes Case Write-ups for Meta \u20ac1.2B, Amazon \u20ac746M, TikTok \u20ac345M, H&M \u20ac35.3M, LinkedIn \u20ac310M, Uber \u20ac290M. Available online: https:\/\/dataprivacymanager.net\/5-biggest-gdpr-fines-so-far-2020\/."},{"key":"ref_92","unstructured":"Capgemini Research Institute (2025, October 07). Championing Data Protection and Privacy report: Firms Failed to Meet Their Own Expectations on GDPR Compliance. Reports 28% of Organizations Achieved GDPR Compliance. Available online: https:\/\/www.capgemini.com\/news\/press-releases\/championing-data-protection-and-privacy-report\/."},{"key":"ref_93","unstructured":"Business Wire (2025, October 07). 90% of Companies Unprepared for CCPA Compliance, 95% Unprepared for GDPR, Says New Research by CYTRIO. Summarizes CYTRIO Study; Finds Only 11% Fully Meet CCPA Requirements. Available online: https:\/\/www.businesswire.com\/news\/home\/20220426005252\/en\/90-of-Companies-Unprepared-for-CCPA-Compliance-95-Unprepared-for-GDPR-Says-New-Research-by-CYTRIO."},{"key":"ref_94","unstructured":"von Hoffman, C. (2025, October 07). Only 11% of US Businesses Fully Comply with CCPA Privacy Law. Reports CYTRIO Findings on CCPA Compliance Rates. Available online: https:\/\/martech.org\/only-11-of-us-businesses-fully-comply-with-ccpa-privacy-law\/."},{"key":"ref_95","unstructured":"CMS Law (2025, October 07). GDPR Enforcement Tracker Report 2024\/2025: Numbers and Figures. Available online: https:\/\/cms.law\/en\/int\/publication\/gdpr-enforcement-tracker-report\/numbers-and-figures."},{"key":"ref_96","unstructured":"U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) (2025, October 08). Enforcement Highlights\u2014Current. HHS.gov, Available online: https:\/\/www.hhs.gov\/hipaa\/for-professionals\/compliance-enforcement\/data\/enforcement-highlights\/index.html."},{"key":"ref_97","unstructured":"HIPAA Journal (2025, October 07). HIPAA Violation Cases\u2014Updated 2024. HIPAA Journal Website. Available online: https:\/\/www.hipaajournal.com\/hipaa-violation-cases\/."}],"container-title":["Journal of Cybersecurity and Privacy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/4\/103\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,24]],"date-time":"2025-11-24T11:21:27Z","timestamp":1763983287000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/4\/103"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,22]]},"references-count":97,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2025,12]]}},"alternative-id":["jcp5040103"],"URL":"https:\/\/doi.org\/10.3390\/jcp5040103","relation":{},"ISSN":["2624-800X"],"issn-type":[{"value":"2624-800X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,11,22]]}}}