7.2 FTC Privacy and Security Enforcement

Key Takeaways

  • The FTC brings privacy and security cases by administrative complaint or federal-court action; most matters settle as consent orders, typically for a 20-year term, usually without an admission of liability.
  • Civil penalties attach to violations of a final Commission order and to knowing violations of trade-regulation rules such as COPPA; a first-time standalone Section 5 UDAP count does not, by itself, authorize those penalties.
  • Section 5 creates no private right of action. Consumers cannot sue "under the FTC Act."
  • Wyndham (3d Cir. 2015) confirmed that Section 5 reaches unreasonable data security; LabMD (11th Cir. 2018) vacated an FTC order as unenforceably vague without repealing that authority.
  • State attorneys general sue concurrently under mini-UDAP statutes and state privacy laws; an FTC file does not oust them.
Last updated: August 2026

7.2 FTC Privacy and Security Enforcement

Domain II.A performance indicator 2 asks how the Federal Trade Commission (FTC) actually brings a privacy or security case — the path, the remedy, and the limits. The exam is testing the toolkit, not a roster of every respondent.

How a case starts and how it is filed

A typical investigation is non-public. Staff use civil investigative demands (CIDs) to obtain documents, written answers, and testimony. The Commission may proceed only if it has "reason to believe" a violation occurred and a proceeding would be in the public interest.

The Commission then chooses a forum:

PathWhat it isTypical privacy or security product
Administrative complaint (FTC Act § 5(b))In-house adjudication before an administrative law judge, with appeal to the full Commission and then to a federal court of appealsA cease-and-desist order, later usable as the predicate for civil penalties if the respondent violates it
Consent orderA negotiated settlement of an administrative or court case. The respondent usually does not admit liability, consents to a final order, and waives judicial review. The Commission places the proposed order on the public record for 30 days of comment before making it final.A 20-year injunctive order is the typical privacy and security term: a comprehensive privacy or information-security program, periodic assessments, deletion, and conduct bans
Federal-court actionA complaint in U.S. district court seeking a permanent injunction (FTC Act § 13(b)) or, with the Department of Justice (DOJ), civil penaltiesA stipulated federal judgment with the same long-term program terms; used when the Commission wants a court order or a penalty

A consent order binds the named respondent. It is not a statute. A competitor that never signed it cannot be held in contempt of it. The competitor remains subject to Section 5 and to any applicable rule.

After AMG Capital Management, LLC v. FTC (2021), Section 13(b) does not authorize the Commission to obtain equitable monetary relief such as restitution. Money in modern privacy cases therefore comes from (1) civil penalties when a statute allows them, (2) joint settlements with agencies or states that do have penalty or restitution authority, or (3) consumer-redress funds the respondent agrees to pay as part of a deal.

When civil penalties are available

For a first-time, standalone Section 5 UDAP case, the Commission generally cannot extract a civil penalty. The FTC said so expressly in its Equifax business-blog write-up: the Commission did not have legal authority to get civil penalties in a case like that.

Civil penalties are available when:

  • The respondent violates a final Commission order (FTC Act § 5(l)). Each day of a continuing violation can be a separate offense. The 2019 Facebook matter — a $5 billion penalty for violating the 2012 consent order — is the flagship order-violation case.
  • The respondent knowingly violates a trade-regulation rule respecting unfair or deceptive acts or practices (FTC Act § 5(m)), including the COPPA Rule and the Health Breach Notification Rule. The official COPPA FAQ cites up to $53,088 per violation.
  • Another statute the Commission enforces independently authorizes a penalty.

That is why a COPPA count in the same complaint can produce a large check — Epic Games' $275 million COPPA civil penalty in 2022, plus additional dark-pattern redress — while a pure "you broke your privacy policy" first-timer usually produces a 20-year order and injunctive terms, not a Section 5(m) fine.

No private right of action under Section 5

Section 5 does not create a private right of action. Consumers cannot file a federal UDAP suit "under the FTC Act." They may have state mini-UDAP claims, contract claims, common-law privacy torts, or a statutory private right under some other law. COPPA itself does not create a general private right of action. On the exam, "the customers sue under Section 5" is the trap.

Overlap with state attorneys general

State attorneys general enforce mini-UDAP statutes and, where they exist, state comprehensive or sectoral privacy laws. Jurisdiction is concurrent. An FTC investigation does not oust the AGs. The same breach can produce an FTC consent order, a multi-state AG consent judgment, a Consumer Financial Protection Bureau (CFPB) penalty if the respondent is a covered person under the Dodd-Frank Act, and private class actions. Equifax is the teaching example of that stack.

Reasonable security cases you must place accurately

FTC v. Wyndham Worldwide Corp., 799 F.3d 236 (3d Cir. 2015). Wyndham's hotel-brand systems were breached three times between 2008 and 2010. The privacy policy claimed reasonable security. The Commission sued in federal court on unfairness and deception. The Third Circuit held that Section 5 reaches unreasonable data-security practices and that Wyndham had fair notice. The 2015 stipulated order required a comprehensive information-security program and annual assessments on a 20-year term. Wyndham is the leading appellate confirmation of the FTC's security-unfairness theory.

LabMD, Inc. v. FTC, 894 F.3d 1221 (11th Cir. 2018). LabMD was a clinical laboratory. A billing file containing personal information of thousands of consumers appeared on a peer-to-peer network. The Commission brought an administrative unfairness case. An administrative law judge first dismissed for failure to prove substantial injury; the full Commission reversed and issued a cease-and-desist order commanding a "reasonably designed" comprehensive security program. The Eleventh Circuit vacated that order as unenforceably vague: it did not enjoin a specific act or practice. Teach LabMD for order specificity and for the reminder that unfairness still requires a proven or likely substantial injury. Do not teach it as "the FTC lost the power to bring security cases." Wyndham is still good law in the Third Circuit, and the Commission has continued to bring security cases.

Equifax (2019). Equifax announced in 2017 that attackers had exploited an unpatched vulnerability and reached data on approximately 147 million people, including names, dates of birth, Social Security numbers, and addresses. The complaint described failures to patch, to segment the network, and to avoid storing Social Security numbers in plaintext. Equifax agreed to a global settlement with the FTC, the CFPB, and 50 U.S. states and territories of at least $575 million and potentially up to $700 million. That package included a large consumer fund, $175 million to states, and a $100 million CFPB civil penalty. The FTC's own write-up is the exam-safe line: the Commission obtained injunctive relief and helped structure consumer redress; it did not have authority to assess a civil penalty on the standalone Section 5 theory. The CFPB and the states supplied the penalty dollars.

Privacy-as-deception (broken notice)

The other classic theory is that the company said one thing and did another. A privacy policy, a just-in-time banner, an app-store listing, or a sales deck is a representation. If the actual collection, sharing, retention, or security practice contradicts a material claim, the Commission pleads deception — often without needing to prove that the underlying sharing would have been unfair if it had been honestly disclosed. Snapchat's 2014 settlement over claims that messages disappeared permanently, while the company retained them and collected geolocation contrary to its promises, is the commonly taught broken-notice illustration. A 20-year order followed.

Worked scenario. A photo app's settings screen says "Location: Off." The app still transmits precise GPS to an analytics SDK. Parents of child users never saw a COPPA notice. Staff can plead (1) Section 5 deception for the broken location claim, (2) Section 5 unfairness if the covert tracking causes substantial, unavoidable injury, and (3) COPPA if the service is child-directed or the operator has actual knowledge it collected personal information from children under 13. Only the COPPA count, or a later order-violation count, is a civil-penalty count on day one.

Exam traps

Do not give Section 5 a private right of action. Do not award civil penalties for a first-time standalone Section 5 count. Do not say LabMD repealed Wyndham. Do not treat a 20-year consent order as a statute that binds the industry. Do not forget that state attorneys general can sue on the same facts.

Loading diagram...
FTC Privacy and Security Enforcement Paths
Test Your Knowledge

When can the FTC obtain civil penalties in a privacy or security matter?

A
B
C
D
Test Your Knowledge

Which statement accurately places the leading FTC data-security appellate decisions?

A
B
C
D
Test Your Knowledge

Customers want to sue a retailer that broke its public privacy promises. Which statement about remedies and parallel enforcers is correct?

A
B
C
D