The United States never wrote a general data security statute, so the FTC wrote one order at a time. Read twenty years of consent decrees and the same program emerges with the regularity of case law: assess risk, gate access with MFA, encrypt what matters, watch the logs, vet the vendors, plan the incident, and have a named human accountable for all of it. Wyndham settled that the agency can demand this; LabMD forced it to be specific; Drizly showed it will follow executives to their next job. The standard is knowable because the FTC keeps publishing it, the only surprise left is being surprised.
| Theory | Unreasonable security = unfair practice (Section 5) |
|---|---|
| Standard source | Consent order library + FTC guidance |
| Core controls | Risk assessment, MFA, encryption, logging, vendor oversight, IR |
| Accountability | Executive certifications; Drizly-style personal orders |
| Codified cousin | Safeguards Rule (financial institutions, penalty-eligible) |
Meeting the baseline
Build to the order composite. The consent-order control list is the checklist; map it to NIST CSF and keep evidence, Section 5 doctrine explains the liability theories behind it.
Audit security claims separately. ‘Military-grade encryption’ and stale compliance badges are deception counts independent of actual security posture.
Financial institutions: comply with the codified version. The Safeguards Rule makes this program mandatory with penalties and a 30-day breach report; GLBA program design covers the details.
Retain less, delete on schedule. Over-retention is now an unfairness theory of its own; data you no longer hold cannot injure anyone.
Security promises start on your website: verify what your pages actually do with a free scan.