US Federal Law United States

FTC Data Security Expectations: What Orders Actually Require

The FTC's data security baseline distilled from consent orders and guidance: risk assessment, MFA, encryption, vendor oversight, incident response, and the unfairness theory behind it.

Regulation

FTC Act Section 5 (unfairness); FTC Safeguards Rule for financial institutions; consent order requirements as de facto standards

Max Penalty

First-time Section 5 security cases yield ~20-year consent orders; order violations and Safeguards Rule cases carry per-violation civil penalties over $50,000 (inflation-adjusted)

Enforcing Authority

Federal Trade Commission (FTC)

Official Source

www.ftc.gov

Executive Summary

  • The FTC treats unreasonable data security as an unfair practice under Section 5, no statute defines 'reasonable security', so the standard lives in two decades of consent orders and the agency's business guidance.
  • The recurring order requirements form a de facto national baseline: documented risk assessment, access controls with MFA, encryption of sensitive data, secure development, vendor oversight, logging and monitoring, incident response, and a named accountable executive.
  • Post-LabMD, orders specify concrete controls rather than vague 'reasonableness', and modern orders add executive certifications and board reporting.
  • The Safeguards Rule imposes a codified version of the same program on non-bank financial institutions, with civil penalties available immediately and a 30-day breach reporting requirement since May 2024.
  • Security claims are policed as deception too: overstating encryption, 'bank-level security', or compliance certifications invites a parallel count.

The United States never wrote a general data security statute, so the FTC wrote one order at a time. Read twenty years of consent decrees and the same program emerges with the regularity of case law: assess risk, gate access with MFA, encrypt what matters, watch the logs, vet the vendors, plan the incident, and have a named human accountable for all of it. Wyndham settled that the agency can demand this; LabMD forced it to be specific; Drizly showed it will follow executives to their next job. The standard is knowable because the FTC keeps publishing it, the only surprise left is being surprised.

TheoryUnreasonable security = unfair practice (Section 5)
Standard sourceConsent order library + FTC guidance
Core controlsRisk assessment, MFA, encryption, logging, vendor oversight, IR
AccountabilityExecutive certifications; Drizly-style personal orders
Codified cousinSafeguards Rule (financial institutions, penalty-eligible)

Meeting the baseline

Build to the order composite. The consent-order control list is the checklist; map it to NIST CSF and keep evidence, Section 5 doctrine explains the liability theories behind it.

Audit security claims separately. ‘Military-grade encryption’ and stale compliance badges are deception counts independent of actual security posture.

Financial institutions: comply with the codified version. The Safeguards Rule makes this program mandatory with penalties and a 30-day breach report; GLBA program design covers the details.

Retain less, delete on schedule. Over-retention is now an unfairness theory of its own; data you no longer hold cannot injure anyone.

Security promises start on your website: verify what your pages actually do with a free scan.

Frequently Asked Questions

Where does the FTC get authority to police security at all?

From Section 5 unfairness: inadequate security causes or is likely to cause substantial consumer injury (fraud, identity theft, exposure of sensitive data) that consumers cannot avoid, they cannot inspect your network, and that is not outweighed by the cost of fixing basic flaws. The Third Circuit blessed the theory in FTC v. Wyndham (2015), rejecting the argument that companies lacked notice of what security Section 5 requires. Deception supplies the second hook where security claims are overstated. Sectoral rules add penalty-eligible codified versions: the GLBA Safeguards Rule for financial institutions, HBNR for health apps, COPPA's security requirements for children's data. The result is jurisdiction over essentially every US for-profit holding consumer data, with the standard defined by the order library.

What controls do FTC orders consistently require?

The composite program appearing across orders: a written information security program with a designated qualified individual; periodic risk assessment feeding control selection; access controls including least privilege and multi-factor authentication for accounts touching consumer data; encryption of sensitive information in transit and at rest; secure software development with code review and testing; retention limits and secure disposal; service provider selection and contractual security requirements with ongoing oversight; network monitoring, logging, and intrusion detection; a tested incident response plan; workforce training; and annual program evaluation. Add order-specific machinery: biennial independent assessments filed with the FTC, incident reporting to the Commission, and annual executive certifications. Companies not under order should read this list as the FTC's definition of reasonable, because it is.

What fact patterns keep producing security cases?

The complaints recite the same sins across two decades: default or shared credentials (TRENDnet, Drizly); no MFA on remote access and admin accounts; sensitive data stored in plaintext (Uber's GitHub-exposed keys, CafePress's unhashed answers); unpatched known vulnerabilities (Equifax's Apache Struts flaw); no segmentation between corporate and payment networks (BJ's, Wyndham); ignored alerts and absent logging (LabMD); over-retention of data with no business need (Drizly's order mandated deletion schedules); and unvetted vendors with broad access. None are exotic, that is the doctrinal point. Unfairness weighs injury against the burden of prevention, and the FTC picks cases where the fix was cheap, known, and skipped, making the cost-benefit math unarguable.

How do executive accountability provisions work now?

Recent orders convert security from a corporate abstraction into named-person exposure. Drizly's order followed its CEO personally, binding him to implement security programs at future companies he leads, a first the FTC signaled it would repeat. Standard modern orders require a senior officer's annual certification of compliance, filed with the Commission, false certification risks individual liability. Safeguards Rule programs require a Qualified Individual reporting in writing at least annually to the board or governing body. CISOs and general counsel should read these provisions together: the FTC is constructing a paper trail regime where 'the company knew' is provable through what named executives signed. Internal candor in those reports matters more than polish.

How should a company benchmark itself against FTC expectations?

Three artifacts, tested honestly. First, a current risk assessment that inventories consumer data, maps flows, and rates threats, the root document every order mandates and every investigation requests. Second, a controls matrix mapping the consent-order composite (MFA, encryption, logging, vendor oversight, IR plan, training, disposal) to your actual implementation with evidence, not policy citations; NIST CSF or CIS Controls work as the scaffold. Third, a claims audit reconciling every public security statement, website, contracts, marketing, against reality, since deception counts are the cheapest for the FTC to prove. Then exercise the incident response plan, because the post-breach investigation examines pre-breach paper: companies with dated assessments, tracked remediation, and tested response plans settle on dramatically better terms, or not at all.

Regulatory Crosswalk

NIST CSFCIS ControlsGLBA Safeguards RuleState security statutes

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.