US Federal Law United States

FTC Section 5 Privacy: Unfair and Deceptive Data Practices

How the FTC polices privacy under Section 5: deception and unfairness doctrine, landmark data cases, consent decree mechanics, and the current enforcement agenda.

Regulation

FTC Act Section 5, 15 USC 45 (unfair or deceptive acts or practices)

Max Penalty

No civil penalties for first-time Section 5 violations, but consent order breaches carry penalties per violation (inflation-adjusted, over $50,000 each), and rule-based cases (COPPA, HBNR, Safeguards) are penalty-eligible from the start

Enforcing Authority

Federal Trade Commission (FTC)

Official Source

www.ftc.gov

Executive Summary

  • Section 5 of the FTC Act prohibits unfair or deceptive acts or practices, and for decades it has served as the United States' de facto general privacy law.
  • Deception covers broken promises: privacy policies, security claims, and consent representations that do not match practice; unfairness covers practices causing substantial, unavoidable consumer injury not outweighed by benefits, including inadequate security itself.
  • First-time violations bring injunctive consent orders (typically 20 years) rather than fines, but order violations and rule-based cases carry per-violation civil penalties.
  • Modern FTC privacy remedies go beyond money: algorithmic disgorgement (deleting models trained on ill-gotten data), data deletion, banned practices, and executive-level compliance certifications.
  • The current agenda targets health data sharing, dark patterns, data brokers and sensitive location data, AI claims, and children's privacy.

Section 5 is a 1914 statute doing a 2026 job. Congress never passed a comprehensive federal privacy law, so two phrases, unfair, deceptive, grew a common law of data through two decades of consent orders: keep your privacy promises, secure what you hold, and avoid practices whose harm outweighs their point. The enforcement economics are distinctive: the first violation buys you a 20-year order rather than a fine, and the order is where liability lives, ask Facebook, whose $5 billion penalty was for breaking one. Watch the orders, not just the statute; each one is a memo about what the FTC will require of you.

StatuteFTC Act Section 5, 15 USC 45
DeceptionMaterial misleading claims (privacy policies, security promises)
UnfairnessSubstantial, unavoidable, unjustified injury (incl. bad security)
First offense~20-year consent order, no penalty
Order violation$50K+ per violation (Facebook: $5B)
Modern remediesAlgorithm deletion, data bans, executive certifications

Staying off the docket

Audit promises against practice. Every privacy policy claim, ‘never sold’, ‘anonymized’, ‘encrypted’, is a deception count if untrue; reconcile them against actual data flows quarterly.

Treat security as unfairness exposure. The FTC’s data security expectations catalog what orders require; the Safeguards Rule makes it penalty-eligible for financial companies.

Design consent flows straight. Dark patterns convert UX choices into counts; health data sharing has its own breach notification rule.

Mind the sensitive categories. Health, location, and children’s data anchor the current agenda; COPPA runs penalty-eligible from day one.

Your privacy policy makes promises your trackers must keep: check the gap with a free scan.

Frequently Asked Questions

How do deception and unfairness differ in privacy cases?

Deception is the promise-keeping theory: a representation or omission likely to mislead reasonable consumers on a material point. Privacy policies claiming data is never shared while pixels fire to ad platforms, 'anonymized' claims for re-identifiable data, fake encryption assurances, all classic deception. Unfairness needs no broken promise: a practice is unfair if it causes or is likely to cause substantial injury consumers cannot reasonably avoid, not outweighed by countervailing benefits, the theory behind pure data-security cases (unpatched systems, default passwords) and behind actions targeting harmful data practices consumers never see, like selling precise location traces revealing visits to clinics and shelters. Most complaints plead both, and the practical lesson is symmetrical: say what you do, and do not do what a reasonable person would find indefensible even if you never said otherwise.

What are the landmark cases to know?

The doctrine's spine: Eli Lilly (2002, first privacy-promise case, Prozac patient email exposure); BJ's Wholesale and Wyndham (unfairness for weak security, with the Third Circuit's 2015 Wyndham decision confirming FTC authority); LabMD (11th Circuit trimming vague injunctions, orders now specify controls); Facebook (2012 order, then the record $5 billion penalty in 2019 for violating it); Equifax ($575M+ with CFPB and states). The modern wave: GoodRx and BetterHelp (2023, health data to advertisers, HBNR's first use plus Section 5); Epic Games ($520M combining COPPA and dark patterns); Kochava and the location-data actions; Rite Aid (2023, unfair AI, facial recognition misidentifying customers, with algorithmic remedies); Amazon Alexa and Ring (children's recordings, employee access). Each order writes rules the next company inherits.

What does an FTC consent order actually require?

The standard privacy/security order runs about 20 years and includes: prohibited misrepresentations (the conduct clause); a mandated comprehensive privacy or security program with documented risk assessment and controls; biennial third-party assessments filed with the FTC; incident reporting to the Commission; recordkeeping and compliance monitoring; and increasingly, executive certifications, named officers annually attest to compliance, converting corporate promises into personal exposure. Recent orders add specific remedies: data and algorithm deletion, bans on sharing health data for advertising (GoodRx, BetterHelp), multi-year facial-recognition bans (Rite Aid). Violating any term triggers per-violation civil penalties, Facebook's $5 billion was an order-violation case, which is why the first order is the expensive thing to acquire.

Does the FTC have jurisdiction over us?

Almost certainly, if you are a for-profit company in or affecting US commerce. Section 5 reaches corporations regardless of sector, with carve-outs for banks and credit unions (prudential regulators), common carriers in that capacity, insurers to the McCarran-Ferguson extent, and true nonprofits (though the FTC has pursued nominally nonprofit shells). It applies alongside sectoral laws: a HIPAA-covered entity can face OCR and FTC theories on the same facts, and the FTC's Health Breach Notification Rule deliberately covers the health-app world HIPAA misses. Foreign companies serving US consumers are reachable. The practical point: there is no 'we are unregulated' zone in US consumer data, Section 5 is the floor under everyone.

What is the FTC's current privacy agenda?

Five visible fronts. Health data: HBNR enforcement plus Section 5 against apps and telehealth platforms sharing with advertisers. Sensitive location data: actions and settlements against brokers (Kochava litigation, X-Mode/InMarket orders) over precise traces to sensitive places. Dark patterns: manipulative consent and cancellation flows, from Epic's $245M dark-pattern component to click-to-cancel rulemaking. AI: deceptive AI claims, model-training data practices, and algorithmic disgorgement as a remedy. Children and teens: COPPA enforcement at scale and scrutiny of engagement-optimized design. Commission priorities shift with administrations, but these dockets are grounded in litigated orders and rules, which do not evaporate with leadership changes.

Regulatory Crosswalk

State UDAP statutesGDPR fairness principleCCPA/state privacy laws

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.