Nearly 1,900 data privacy class actions were filed in the United States during 2025, representing over 25% annual growth and an increase of more than 200% since 2022.
It Moves Faster Than Every Other Mechanism Here
The regulatory files at 25-1113 record a UK bill amending a regime made in 2018 — seven years. DORA at 25-0117 was years in preparation. Enforcement at 25-1222 produced seven arrests and one conviction against a record year of attacks.
Litigation requires no legislature, no agency budget and no international cooperation. A complaint follows a notification by weeks. Whatever else it is, it is the only accountability mechanism in this database that operates on the same timescale as the incidents.
And It Is Triggered By Disclosure, Not By Harm
That speed comes from the trigger. A breach notification is a public admission with a defined affected class, filed by the defendant. It is close to a pre-assembled case.
Which means litigation volume tracks notification volume rather than harm — and every category this corpus records as unnotifiable produces no litigation at all. No workforce data claims at 25-0704. Nothing for corporate information at 25-1204. Nothing for the availability failures at 25-0606 and 25-0902, where thousands of downstream parties suffered and none were data subjects.
The Perverse Consequence
An organisation that discloses carefully and early creates its own liability. One whose incident never crosses a notification threshold faces none, regardless of what actually happened.
This desk is not suggesting organisations suppress notifications, and has no evidence that they do. It is recording that the incentive exists and that the mechanism rewards silence — which is a strange property for the system that has become the primary consequence of a breach in the United States.
Built on published litigation analysis, listed below. Filing counts come from legal-sector reporting with varying definitions of what constitutes a data privacy class action. Corrections: corrections@forensicpost.com.