2023 Data Security Incident Response Report Get the Full Report

FTC Update

Share this chapter

Aggressive FTC Rulemaking Agenda

For the first time in decades, the Federal Trade Commission (FTC) has initiated multiple new rulemakings covering a wide range of industries and issues. These rulemakings (which, if completed, would allow the agency to seek civil penalties for violations) will continue into 2023 and beyond.

The Rulemakings Include:

Commercial Surveillance

A broad rulemaking focused on a wide range of privacy and data collection issues, with an emphasis on the use of data for advertising purposes.


Unfair or Deceptive Fees (Junk Fees)

A rulemaking exploring whether and how to ban a wide range of fees that are charged to consumers in various contexts that “have little or no added value to the consumer, including goods or services that consumers would reasonably assume to be included within the overall advertised price.”


Reviews and Endorsements

A rulemaking focused on deceptive or unfair review and endorsement practices, with an emphasis on potential unlawful practices regarding online reviews. 


FTC Emphasis on Online Dark Patterns

For the past year, the FTC has focused extensively on dark patterns, which are generally described as online interfaces that manipulate consumers into making decisions they would not otherwise make or that lead to consumers sharing more data than they intended. The contours of what constitutes a dark pattern that violates the law are not particularly well-defined and a September 2022 FTC report on the topic did not provide real clarity. Two recent FTC law enforcement actions do shed some light on what practices the FTC finds deceptive or unfair. In one case, the FTC settled for $100 million and alleged that a company made it easy for consumers to sign up for services but difficult to cancel through the use of dark patterns. In a $3 million settlement in a different matter, the agency alleged that, through dark patterns, a company falsely represented to consumers that they had been preapproved for certain credit offerings. The focus on dark patterns continues in 2023. 

FTC Focus on Health and Geo Data

For decades the FTC has focused on the privacy of health data and has also focused a good deal on the privacy of location data. As noted previously, the FTC has focused even more on these issues since the Dobbs decision and will continue to do so. Shortly after the decision was announced, the FTC’s then-acting associate director of the Division of Privacy & Identity Protection announced in a blog post that websites sharing health, location, and highly sensitive data without adequate disclosures to consumers would “hear from” the FTC. A recent case, which for the first time alleged a violation of the agency’s Health Breach Notification Rule, also claimed that the company unlawfully shared health data with third-party advertisers. And in a case currently in litigation, the FTC alleged that the company unlawfully shared consumer geo data with third parties, which could be used to trace individuals to sensitive locations.