FTC Reaches Consent Order With Sole Proprietor Over Failure To Protect Personal Information

Fox Rothschild LLP
Contact

Fox Rothschild LLPThe FTC has entered into a consent order with a sole proprietor for a failure to implement reasonable protections to personal information.

At issue were the following statements, which the FTC held to be deceptive/misleading:

  • “[We] utilize the latest security and encryption techniques to ensure the security of your account information.”
  • “We understand clearly that you and your information are one of our most important assets.”

In actuality – the website did not implement:

  • penetration testing
  • IDPS or other techniques to detect anomalous activity
  • TLS encryption
  •  valid SSL certificate
  • effective access controls

The FTC also found a number of unfair practices including:

  • maintaining information in cleartext
  • allowing employees to store credentials in cleartext

Consent order requirements include:

  • implement a comprehensive written information security plan
  • appoint a person in charge of personal information
  • undergo an biennial, external, third party audit
  • supervise third party providers
  • conduct regular risk assessments

Read the full decision.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Fox Rothschild LLP | Attorney Advertising

Written by:

Fox Rothschild LLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Fox Rothschild LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide