Drizly LLC, an alcohol delivery service, and its chief executive officer agreed to separate consent orders following a data breach that exposed the personal information — including names, email addresses, dates of birth, and hashed passwords — of approximately 2.5 million Drizly customer accounts. The orders were notable for two reasons: the company order required Drizly to destroy data it had collected but did not need, limiting the data retention that had made the breach consequential; and the personal consent order against CEO James Cory Rellas was unprecedented in its reach, binding him individually to data security requirements that would follow him to any company he leads or substantially controls for twenty years.DOCUMENTED
The personal order against Rellas was based on regulators' finding that he had been aware of security vulnerabilities in Drizly's systems — including the lack of a process for identifying security risks and the absence of adequate access controls — and had failed to implement remediation for those vulnerabilities before the breach occurred. The order reflects a policy position that when an executive has personal knowledge of security deficiencies and fails to address them, the resulting breach creates individual accountability that should follow that executive beyond their current employer.DOCUMENTED
- 2.5 million Drizly customer records exposed, including contact information, dates of birth, and hashed passwords
- The breach resulted from inadequate data security practices that Drizly's leadership had been warned about prior to the incident
- The company order requires Drizly to delete unnecessary data and implement specific security measures
- The personal CEO consent order runs twenty years and applies to any company Rellas leads or substantially controls with more than 25,000 consumer records
- The CEO order includes requirements to implement data security programs, conduct risk assessments, and limit unnecessary data collection at future employers
The Security Failures
Regulators found that Drizly lacked several basic data security practices that are standard for companies holding consumer personal information at the scale Drizly had reached. The company had not implemented a process for identifying and addressing security risks — no formal risk assessment program, no systematic vulnerability identification process, and no assigned responsibility for monitoring and remediating security issues. Access controls were inadequate, with more employees having access to sensitive customer data than had any operational need for that access. And despite Rellas having been told by a company employee about specific security vulnerabilities approximately two years before the breach, no systematic remediation of those vulnerabilities was implemented.DOCUMENTED
The gap between knowing about a security vulnerability and fixing it — documented in this case by the prior employee warning — was central to the regulators' decision to pursue individual accountability through the personal consent order. When a company leader knows about a risk and fails to address it, the resulting harm is not simply a corporate governance failure; it reflects a personal decision by the leader with authority to direct resources toward remediation and who chose not to do so. The personal order is designed to ensure that the same failure cannot recur at another company where Rellas may be in a position of security oversight authority.REVIEWED
The Unprecedented Personal Order
Consumer protection enforcement has historically focused on companies rather than on individual executives when data security failures occur. The Drizly CEO order represented a departure from this norm — a signal that regulators were prepared to use personal orders as a tool for individual accountability in data security cases where leadership failures contributed to preventable consumer harm. The twenty-year duration and the provision binding Rellas at future employers of any kind — not just alcohol delivery companies — made the order among the most consequential individual data security accountability measures ever issued.DOCUMENTED
The scope of the personal order means that if Rellas later leads a healthcare company, a financial services company, or any other consumer-facing business with more than 25,000 customer records, he will be personally required to implement the data security program elements specified in the order — including risk assessments, access controls, data minimization, and employee training. Failure to comply with the personal order would expose him to contempt proceedings independent of any corporate liability, creating a personal compliance obligation that cannot be delegated or discharged by leaving a particular employment.REVIEWED
The personal consent order's reach to future employers was deliberate — regulators wanted accountability to follow the executive, not just the company, recognizing that the same failure to prioritize security could recur at any organization he leads.
Data Minimization as a Remedy
The company consent order's requirement that Drizly delete data it had collected but did not need reflects an emerging approach to data security remediation that addresses the underlying cause of large breach impacts rather than just requiring better security for data that is retained. Breaches are consequential in proportion to the data that is exposed; a company that collects only the data it genuinely needs for its operations and deletes data it no longer needs has a smaller breach impact when security fails. Requiring data deletion as a remedy — rather than just enhanced security for all collected data — creates incentives for data minimization that benefit consumers in the event of future incidents.REVIEWED
Drizly customers whose data was exposed in the breach were notified and can take standard protective measures including monitoring their accounts at any service where they used the same email and password combination as their Drizly account, enabling two-factor authentication on important accounts, and monitoring their credit reports for unauthorized activity. The hashed passwords exposed in the breach may be cracked through brute-force techniques if weak passwords were used, making password rotation at other services a prudent step for affected customers.DOCUMENTED
What the Personal CEO Order Means Going Forward
The Drizly CEO order represents an important expansion of how consumer protection enforcement can reach individual executives — not just companies — when their personal decisions contribute to preventable consumer harm. The order demonstrates that executives who have direct knowledge of security vulnerabilities and fail to act on them can face personal legal obligations that follow them through their career. For boards of directors evaluating potential CEO candidates, the existence of a personal consent order is now a material consideration in executive due diligence. For executives themselves, the Drizly case establishes that their personal choices about security investment priorities can carry personal legal consequences independent of the companies they lead. Privacy and cybersecurity professionals who report identified vulnerabilities to leadership and do not see action taken have an independent reporting channel through their regulator, and documenting those reports provides evidence relevant to any future enforcement inquiry about who knew what and when.
Sources behind this report
Have documents relevant to this story? Reach us through our tips channel.