Skip to main content
corporate Support = Good

Consumer Protection

Supporting means...

Strong consumer safety standards; transparent practices; responsive to product issues; prioritizes user safety over profits; proactive recalls when needed

Opposing means...

Deficient safety testing; ignores product defects; resists recalls; prioritizes speed-to-market over consumer wellbeing; downplays safety concerns

Recent Incidents

reactive

NHTSA opened Audit Query AQ26002 and issued a Special Order requiring Tesla to certify under oath, by September 30, 2026, how its Cybercab robotaxi - which has no steering wheel, pedals, or mirrors - complies with Federal Motor Vehicle Safety Standards. The order followed Tesla's September 3, 2026 launch of commercial Cybercab service in Austin, Texas, and carries civil penalties up to $139 million and potential criminal liability for false or withheld information.

negligent

UK consumer group Which? set up a fake listing for the UK Prime Minister's residence at 10 Downing Street on Booking.com in minutes, using the real address and photo. The listing received 14 inquiries in a 20-minute window, had a fabricated 10/10 review published despite promised moderation, and Booking.com processed a payment for a week-long stay that remained unrefunded more than six weeks later. Which? also used Booking.com's internal messaging system to send an external phishing-style payment link requesting card details without triggering interception. The listing stayed live for about six weeks before removal on August 27, 2026; under Booking.com policy, hosts are not required to provide ID or proof of ownership until three months after a listing goes live. Booking.com disputed the test's methodology, and Which? urged UK regulator Ofcom to investigate the platform's compliance with the Online Safety Act.

Singapore-based sellers on Sea Limited's Shopee (and separately TikTok Shop) reported in August 2026 that the platforms auto-generated AI promotional videos and images for their listings without notifying them or obtaining consent, in some cases misrepresenting products (e.g. an independent publisher, Epigram Books, said around 10 of its book listings were affected since March 2026). Sellers said they had no mechanism to remove or replace the AI-generated videos, only an option to disable AI-generated images but not videos, and reported resulting brand-reputation damage. Shopee said it had contacted affected sellers and had safeguards to detect policy-violating content, but did not address whether sellers are informed when AI content is created about their products or given a way to opt out of video generation specifically.

Argentina's Buenos Aires Province government opened an investigation into Mercado Pago and other digital wallets after receiving 2,240 consumer complaints in the first half of 2026 alleging harassment, unclear loan information and abusive practices, with potential fines up to 1,883 million pesos. Separately, Partido Obrero leader Gabriel Solano filed a criminal usury complaint against Mercado Libre CEO Marcos Galperin and the company's board, alleging Mercado Pago's consumer loans carried an effective total annual cost (CET) of up to 1,375.94%, roughly 21 times the rate charged for comparable products in Brazil, and sought suspension of loan collections pending investigation. Mercado Libre had not agreed to a settlement (Conduct Adjustment Agreement) proposed in a related Bahia, Brazil prosecutorial matter as of reporting.

negligent

Former Tesla Autopilot/FSD test operations manager Medrano filed a lawsuit alleging Tesla's Houston test fleet was operated by a chronically overworked and sleep-deprived team, including one instance where a supervisor processed a real-time crash call while asleep due to exhaustion he had formally escalated days earlier. The complaint alleges Medrano raised the safety oversight breakdown to Autopilot Director Pete Scheutzow in February 2025 and was met with a performance-rating ultimatum, had a subordinate promoted into his role in April 2025, and was fired May 1, 2025, with a pending stock award cancelled days before vesting. NHTSA data shows Tesla's Texas robotaxi fleet logged 22 collisions over the prior year, a rate the lawsuit's supporters note is several times Tesla's own human-driver benchmark. Tesla has not responded publicly to the allegations, which remain unproven in an active, self-represented lawsuit.

$44.0M

On July 21, 2026, the São Paulo Public Ministry (MPSP) filed a civil lawsuit against Tools for Humanity Corporation (operator of Sam Altman's World ID/Worldcoin project) and Amazon AWS Servicos Brasil, seeking a minimum R$240 million in collective moral damages. The suit alleges Tools for Humanity scanned the irises of more than 400,000 people in Sao Paulo -- concentrated at metro stations and Poupatempo government-service offices in low-income peripheral areas -- paying R$300-700 per scan while presenting the effort as a humanitarian identity initiative without disclosing its economic purpose tied to Worldcoin cryptocurrency. Prosecutors say the company continued offering compensation through 'internal benefits' in the World App even after Brazil's data protection authority (ANPD) ordered a suspension of paid iris collection in January 2025. AWS Brasil, named as co-defendant for hosting the biometric data, did not deny the hosting contract but said any responsibility would lie with AWS's foreign entity. The case follows a 161-page report from a Sao Paulo City Council inquiry (CPI da Iris) finding the operation posed high legal, social and data-protection risks.

negligent $34K

On July 13, 2026 Justice Asenath Ongeri ruled that Safaricom and Diamond Trust Bank must compensate a customer who lost KES 4.4 million to SIM-swap fraud, apportioning 60% of liability (about KES 2.63 million) to Safaricom and 40% to the bank. The court found that permitting the fraudulent SIM swap was 'a direct and proximate cause of the loss', rejected the argument that a correctly entered PIN absolves the providers, and dismissed Safaricom's cross-appeal against its liability share. The ruling sets a consumer-protection precedent for Kenya's mobile-money ecosystem.

On July 13, 2026, Dutch non-profit Stichting Massaschade & Consument (SMC) filed a class action lawsuit against Klarna in the Netherlands, alleging the company failed to conduct adequate creditworthiness assessments before extending buy-now-pay-later credit, provided credit to minors without valid parental consent using age-verification processes SMC called 'easy to circumvent,' and handled disputed claims, returns, and fraud cases carelessly. SMC is seeking over €500 million in reimbursements covering purchase amounts, late fees, collection costs, and fines. The suit follows an April 2026 ruling by Dutch complaints institute Kifid that Klarna's BNPL services fall under consumer credit regulation; Klarna is appealing that ruling and disputes the class action's allegations.

Colombia's Superintendencia de Industria y Comercio (SIC) confirmed on July 8, 2026 (Resolution 45710) the permanent and immediate closure of all data-processing operations by World Foundation and Tools for Humanity Corporation (the entities behind Sam Altman's World/Worldcoin iris-scanning project) in Colombia, with no further appeal available. The SIC found the companies violated Colombia's data protection law by collecting biometric iris data without valid free consent (conditioning it on cryptocurrency payments), failing to adequately disclose processing purposes, lacking compliant data-handling procedures, and mischaracterizing encrypted iris codes as 'anonymous' data. The ruling upheld and finalized sanctions first imposed in October 2025. This follows earlier bans/restrictions on the project in Brazil, Kenya, Indonesia, the Philippines, Thailand, Spain, Portugal and Hong Kong.

negligent

The US Department of Justice announced that Alibaba Group and AUS Merchant Services agreed to pay a combined $600 million ($125M criminal penalty plus $200M forfeiture from Alibaba; $85M penalty plus $190M forfeiture from AUS) to resolve allegations that merchants used Alibaba's messaging tools to conduct roughly 80,000 illegal sales of pharmaceuticals, controlled substances, and counterfeiting equipment between January 2016 and December 2024, with combined gross merchandise value exceeding $200 million. DOJ said Alibaba employees had internally flagged inadequate compliance controls, and the company continued to profit from transaction fees on the illegal sales; AUS was found to have merely reported flagged bad actors rather than systematically restricting them, allowing at least one merchant to continue illegal sales after being flagged. No independent monitor was imposed; both companies agreed to enhanced compliance, reporting, and cooperation obligations. The European Commission separately imposed an additional €550 million fine on Alibaba for related conduct in the EU market.

On June 17, 2026 Argentina's official lottery regulator publicly stated that Mercado Pago's promoted 'friends tournaments' allowing users to wager on World Cup matches constitute illegal gambling under Argentine law, since the product offered cash prizes funded from user stakes outside the official licensing regime. The regulator warned of criminal exposure for Mercado Pago and demanded the product be discontinued.

A Federal District (Brasilia) court ruled on June 17, 2026 that Garena and twelve other gaming and platform companies failed to protect children from 'loot box' randomized-purchase mechanics, in a civil action brought by Brazil's National Association of Child and Adolescent Defense Centers (ANCED). Garena, Sea Limited's gaming subsidiary, was fined R$15 million (~$2.9M) over Free Fire as part of a R$298M (~$58.7M) collective judgment against the named companies. The court ordered Garena, within 90 days, to display explicit randomness warnings, disclose item-drop probabilities, deploy reliable (non-self-declared) age verification blocking minors from loot-box purchases, and provide refunds for loot-box purchases made by minors without parental authorization. The ruling is subject to appeal.

A Brasília federal district court ruled on June 17, 2026 (case 0701554-83.2021.8.07.0013) that Tencent violated Brazil's Child and Adolescent Statute (ECA) by offering paid randomized loot boxes to minors without adequate warnings, odds disclosure, or age verification. Tencent was ordered to pay R$50 million (~$9.8 million) in collective damages, part of a combined R$298 million judgment against Apple, Google, Microsoft, Sony, EA, Riot Games, Garena, Ubisoft, Valve, Konami, and Nintendo in the same ruling. Companies must implement probability disclosures, reliable age verification, and refund systems for minors' purchases within 90 days of final judgment or face daily fines of R$100,000. The ruling is subject to appeal and also allows individual children to pursue separate compensation claims.

A Brasília federal district court ruled on June 17, 2026 (case 0701554-83.2021.8.07.0013) that Sony violated Brazil's Child and Adolescent Statute (ECA) by offering paid randomized loot boxes to minors without adequate warnings, odds disclosure, or age verification. Sony was ordered to pay R$40 million (~$7.8 million) in collective damages, part of a combined R$298 million judgment against Apple, Google, Microsoft, Tencent, EA, Riot Games, Garena, Ubisoft, Valve, Konami, and Nintendo in the same ruling. Companies must implement probability disclosures, reliable age verification, and refund systems for minors' purchases within 90 days of final judgment or face daily fines of R$100,000. The ruling is subject to appeal and also allows individual children to pursue separate compensation claims.

A Brasília federal district court ruled on June 17, 2026 (case 0701554-83.2021.8.07.0013) that Nintendo violated Brazil's Child and Adolescent Statute (ECA) by offering paid randomized loot boxes to minors without adequate warnings, odds disclosure, or age verification. Nintendo was ordered to pay R$5 million (~$1.0 million) in collective damages, part of a combined R$298 million judgment against Apple, Google, Microsoft, Tencent, Sony, EA, Riot Games, Garena, Ubisoft, Valve, and Konami in the same ruling. Companies must implement probability disclosures, reliable age verification, and refund systems for minors' purchases within 90 days of final judgment or face daily fines of R$100,000. The ruling is subject to appeal and also allows individual children to pursue separate compensation claims.

negligent

A Federal District (Brasilia) court ruled on June 17, 2026 that Valve and twelve other gaming and platform companies failed to protect children from randomized 'loot box' purchase mechanics, in a civil action brought by Brazil's National Association of Child and Adolescent Defense Centers (ANCED). Valve was fined R$10 million (~$1.96M) over loot-box style item drops in Counter-Strike 2 and Dota 2, as part of a R$298M (~$58.4M) collective judgment against the named companies. The court ordered Valve, within 90 days, to display explicit randomness warnings, disclose item-drop probabilities, deploy reliable (non-self-declared) age verification blocking minors from loot-box purchases, and provide refunds for purchases made by minors without parental authorization. The ruling is subject to appeal.

negligent

A Federal District (Brasilia) court ruled on June 17, 2026 that Electronic Arts and twelve other gaming and platform companies failed to protect children from randomized 'loot box' purchase mechanics, in a civil action brought by Brazil's National Association of Child and Adolescent Defense Centers (ANCED). EA was fined R$20 million (~$3.92M) over loot-box mechanics in Apex Legends and EA FC, as part of a R$298M (~$58.4M) collective judgment against the named companies. The court ordered EA, within 90 days, to display explicit randomness warnings, disclose item-drop probabilities, deploy reliable (non-self-declared) age verification blocking minors from loot-box purchases, and provide refunds for purchases made by minors without parental authorization. The ruling is subject to appeal.

negligent

A Federal District (Brasilia) court ruled on June 17, 2026 that Riot Games and twelve other gaming and platform companies failed to protect children from randomized 'loot box' purchase mechanics, in a civil action brought by Brazil's National Association of Child and Adolescent Defense Centers (ANCED). Riot was fined R$15 million (~$2.94M) over loot-box mechanics in League of Legends, as part of a R$298M (~$58.4M) collective judgment against the named companies. The court ordered Riot, within 90 days, to display explicit randomness warnings, disclose item-drop probabilities, deploy reliable (non-self-declared) age verification blocking minors from loot-box purchases, and provide a free refund system for purchases made by minors without parental authorization; noncompliance carries a daily fine of R$100,000. The ruling is subject to appeal.

A proposed class action filed in the U.S. District Court for the Northern District of California on June 14, 2026 by D.C. resident Karl Kahn alleged that Anthropic's $200/month Claude Max 20x plan delivers only 6-8x Pro tier usage rather than the advertised 20x, and that the $100/month Max 5x plan delivers only 3.5x. The suit also challenges Anthropic's claim that Max 20x offers '50% savings'. Two days after the complaint, on June 16, 2026, Anthropic implemented metered credit caps for agent SDK, headless CLI, GitHub Actions, and third-party app usage, separating them from interactive subscription limits.

negligent

On June 12, 2026, Kenya's High Court (Milimani Constitutional and Human Rights Division), ruling on a petition by the Kenya Association of Radiologists, ordered the immediate suspension of Rology's Kenyan operations. The court found Rology had operated in over 40 public health facilities serving more than 60,000 patients without registering as a data controller/processor under Kenya's Data Protection Act, without Digital Health Act compliance, and without verifying that all reviewing radiologists held Kenyan licenses. Patient medical imaging (X-rays, CT scans, MRIs) with identifying metadata was transferred to Rology's Cairo-based cloud infrastructure without explicit patient consent. The court found violations of the constitutional rights to privacy, consumer protection, fair labor practices, and health, and ordered regulators to cancel any licenses issued to Rology for handling patient data.