7.3 Future Enforcement Priorities: Brokers, IoT, AI, Biometrics
Key Takeaways
- Unregulated data means commercial information outside the major sectoral statutes — typically HIPAA, GLBA, FCRA, and COPPA — for which Section 5 is the federal backstop.
- The FTC Health Breach Notification Rule covers non-HIPAA vendors of personal health records, related entities, and service providers; July 2024 amendments confirm that many health apps and connected devices are in scope.
- GoodRx (2023) was the first HBNR case: a $1.5 million civil penalty for unauthorized disclosures of health information to advertising platforms.
- Verified priority matters include data-broker and precise-location sales (Kochava, resolved in 2026), IoT device security, AI and biometric deployment (Rite Aid's five-year facial-recognition ban), and dark patterns.
- The 2022 commercial-surveillance ANPR is not a final comprehensive privacy rule, and the Commission has not published 2026 enforcement quotas.
7.3 Future Enforcement Priorities: Brokers, IoT, AI, Biometrics
Domain II.A performance indicator 3 asks where the Commission has pointed its Section 5, COPPA, and rulemaking energy: data brokers, the Internet of Things (IoT), artificial intelligence (AI), biometrics, and unregulated data. The exam wants the legal hooks and a few verified matters. It does not want invented 2026 case quotas, unpublished penalty targets, or a pretend comprehensive federal privacy rule.
What "unregulated data" means on this exam
Unregulated data is commercial information that sits outside the major sectoral statutes — typically HIPAA, GLBA, the Fair Credit Reporting Act (FCRA), and COPPA (FERPA and similar statutes appear in later Domain II sections). A fitness app's heart-rate stream, a data broker's movement graph, a doorbell camera's face templates, and a general-audience retailer's browsing graph are the usual examples. They are not "unregulated" in the sense of "legal to do anything." They are regulated, if at all, by Section 5, by the Health Breach Notification Rule (HBNR) when that rule applies, by state comprehensive and biometric laws, and by whatever promises the company made. The federal backstop is Section 5.
Health Breach Notification Rule versus HIPAA
HIPAA is an HHS statute. The HIPAA Privacy, Security, and Breach Notification Rules apply to covered entities (health plans, most health-care providers that conduct standard electronic transactions, and health-care clearinghouses) and their business associates. HHS's Office for Civil Rights (OCR) enforces those rules.
The FTC's Health Breach Notification Rule, 16 C.F.R. Part 318, covers a different population: vendors of personal health records (PHRs), PHR related entities, and their third-party service providers that are not HIPAA covered entities or business associates. If HIPAA already covers you, HBNR does not.
Amendments the Commission finalized in April 2024 and put into effect in mid-2024 — commonly cited as the July 2024 HBNR update — make express that health apps, connected devices, and similar products that draw identifiable health information from multiple sources can be PHR vendors. A "breach of security" is not limited to a hacker on the network. Unauthorized acquisition, including unauthorized disclosure to an advertising platform, can be a breach. Covered entities must notify individuals, the FTC, and, for incidents affecting 500 or more people, the media, without unreasonable delay and in no case later than 60 calendar days after discovery.
GoodRx (2023) is the first HBNR enforcement action. The Commission alleged that the telehealth and prescription-discount company shared consumers' personal health information with advertising platforms, including Facebook and Google, and failed to provide the required breach notices. GoodRx paid a $1.5 million civil penalty and accepted a ban on sharing user health data with third parties for advertising. The case is also a Section 5 broken-notice matter: the company had told users it would not share health information with advertisers.
Worked contrast. A hospital's electronic medical record is HIPAA. A consumer-downloaded fertility or mental-health app that is not offered by a covered entity is usually not HIPAA and is in the HBNR and Section 5 zone. Do not put OCR in charge of the app, and do not put the FTC's HBNR in charge of the hospital.
Data brokers and precise location
A data broker collects and sells information about consumers with whom it often has no direct relationship. Location, inferred health, and household graphs are the high-risk products. Because brokers typically sit outside HIPAA, GLBA, FCRA (unless they actually assemble consumer reports), and COPPA (unless they collect from children), they are the textbook unregulated-data target.
FTC v. Kochava is the lead broker-and-location matter. The Commission sued in 2022, alleging that Kochava sold geolocation data from hundreds of millions of mobile devices that could be used to trace individuals to reproductive-health clinics, places of worship, and other sensitive locations. After an amended complaint survived dismissal, the Commission in 2026 announced a settlement that prohibits Kochava and a subsidiary from selling, sharing, or disclosing sensitive location data without consumer consent, subject to a narrow exception, and requires a supplier-assessment program. Teach it as Section 5 unfairness applied to the sale of precise location, not as a new location statute.
Precise location is also a COPPA personal-information element when it can identify a street name and city or town, and it is a recurring state-law trigger you will meet in Domain V. The federal exam hook in this chapter is Section 5 plus, where children are involved, COPPA. The Commission has also reminded brokers of separate duties under the Protecting Americans' Data from Foreign Adversaries Act (PADFAA); that reminder is an additional broker-facing authority, not a substitute for Section 5.
IoT, AI, and biometrics
Internet of Things devices — cameras, routers, toys, fitness trackers — create always-on collection points. The Commission has used Section 5 against insecure connected products (weak default credentials, unencrypted streams, abandoned firmware) and has published Careful Connections guidance: authentication, access control, secure data management, and honest user communication. An IoT case is usually unreasonable security as unfairness, often paired with a deceptive "secure" or "encrypted" claim.
AI enters through the same two Section 5 doors. Using consumers' personal information, including children's voice recordings, to train a model can be a COPPA retention violation — the Commission charged Amazon with retaining children's Alexa voice recordings indefinitely and using them to improve its speech-recognition algorithm — or a Section 5 deception or unfairness theory if the company hid that use. Deploying an AI system that causes substantial, unavoidable injury, such as a facial-recognition watchlist that repeatedly misidentifies people, is an unfairness theory.
Rite Aid (2023) is the biometric and AI teaching case. The Commission alleged that from 2012 to 2020 the retailer deployed facial-recognition systems in hundreds of stores without reasonable procedures, that the systems falsely flagged consumers — with particular harm to women and people of color — and that employees then confronted those consumers. Rite Aid agreed to a five-year ban on using facial recognition for surveillance, plus a comprehensive program for any future biometric security systems. The case also alleged a violation of a 2010 data-security order. The Commission's 2023 Policy Statement on Biometric Information flags collection, retention, and use of faceprints, voiceprints, and similar data as a Section 5 priority.
The 2025 COPPA amendments put biometric identifiers in the children's personal-information definition, so a child-directed service that captures a faceprint or voiceprint needs verifiable parental consent, a retention limit, and the written children's security program.
Commercial surveillance and dark patterns
In August 2022 the Commission issued an Advance Notice of Proposed Rulemaking (ANPR) on commercial surveillance and lax data security — the business of collecting, analyzing, and profiting from information about people. The ANPR asked whether new trade-regulation rules are needed. As of August 2026 there is no final comprehensive commercial-surveillance rule and still no general federal privacy statute. Do not invent one. Enforcement continues under existing authorities.
Dark patterns are user-interface designs that trick or pressure consumers into a choice they would not otherwise make — hidden opt-outs, confirm-shaming, pre-checked sharing boxes, or making cancellation far harder than signup. The Commission's 2022 staff report Bringing Dark Patterns to Light and later cases treat material dark patterns as deceptive when they distort the net impression and, when they coerce data collection the consumer cannot reasonably avoid, as unfair. COPPA adds a specific ban on conditioning a child's participation on disclosure that is not integral to the activity.
What the exam will not give you
The Commission has not published a 2026 quota of broker, IoT, AI, or biometric cases, and this guide will not invent one. Priorities are inferred from complaints, policy statements, the COPPA and HBNR amendments, and settled matters such as Kochava, Rite Aid, GoodRx, and the children's-voice and connected-device cases. A privacy program treats those categories as high-scrutiny processing: map whether a sectoral statute applies; if not, assume Section 5 plus HBNR for consumer health apps plus state law; tell the truth in the notice; obtain a separate, informed choice before selling precise location or biometric templates; and build security that matches the sensitivity of the data.
Worked scenario. A startup buys mobility feeds from a broker, trains a "likely pregnant" model, and sells scores to advertisers. No HIPAA relationship exists. FCRA does not apply unless the scores are used as consumer reports for credit, insurance, or employment. COPPA applies only if the feed includes children under 13 and the operator has a coverage hook. The live federal theories are Section 5 unfairness for the sensitive inference and sale, Section 5 deception if the consumer-facing apps promised they do not sell data, HBNR if a PHR vendor disclosed identifiable health information without authorization, and — after Kochava — a very specific risk on sensitive location. There is no published FTC "AI enforcement quota" that changes those hooks.
Exam traps
Do not send a consumer health app to OCR solely because it stores health metrics. Do not send a hospital to HBNR. Do not treat the 2022 ANPR as an enacted privacy code. Do not claim precise location is never personal information under COPPA. Do not invent 2026 enforcement quotas.
Which statement correctly distinguishes unregulated data from the Health Breach Notification Rule and HIPAA?
A data broker sells precise mobile-location feeds that can place devices at reproductive-health clinics. Which description matches current FTC enforcement?
Which statement about commercial surveillance, dark patterns, and biometric AI is accurate as of August 2026?