Section 5 is a 1914 statute doing a 2026 job. Congress never passed a comprehensive federal privacy law, so two phrases, unfair, deceptive, grew a common law of data through two decades of consent orders: keep your privacy promises, secure what you hold, and avoid practices whose harm outweighs their point. The enforcement economics are distinctive: the first violation buys you a 20-year order rather than a fine, and the order is where liability lives, ask Facebook, whose $5 billion penalty was for breaking one. Watch the orders, not just the statute; each one is a memo about what the FTC will require of you.
| Statute | FTC Act Section 5, 15 USC 45 |
|---|---|
| Deception | Material misleading claims (privacy policies, security promises) |
| Unfairness | Substantial, unavoidable, unjustified injury (incl. bad security) |
| First offense | ~20-year consent order, no penalty |
| Order violation | $50K+ per violation (Facebook: $5B) |
| Modern remedies | Algorithm deletion, data bans, executive certifications |
Staying off the docket
Audit promises against practice. Every privacy policy claim, ‘never sold’, ‘anonymized’, ‘encrypted’, is a deception count if untrue; reconcile them against actual data flows quarterly.
Treat security as unfairness exposure. The FTC’s data security expectations catalog what orders require; the Safeguards Rule makes it penalty-eligible for financial companies.
Design consent flows straight. Dark patterns convert UX choices into counts; health data sharing has its own breach notification rule.
Mind the sensitive categories. Health, location, and children’s data anchor the current agenda; COPPA runs penalty-eligible from day one.
Your privacy policy makes promises your trackers must keep: check the gap with a free scan.