Aleksandr Kogan and Alexander Nix; Analysis To Aid Public Comment
The consent agreements in these matters settle alleged violations of federal law prohibiting unfair or deceptive acts or practices. The attached Analysis to Aid Public Comment describes both the allegations in the complaint and the terms of the consent orders-- embodied in the consent agreements--that would settle these allegations.
What this rule actually says
The FTC settled cases against Aleksandr Kogan and Alexander Nix (Cambridge Analytica) for collecting and misusing personal data without clear consent. The core violation: they gathered detailed information about millions of people—often through deceptive means or without explicit permission—and sold or used it for purposes users didn't agree to. If users thought their data was going one place but it went elsewhere, that's the problem.
Who it applies to
- If you collect user data (names, emails, behavioral patterns, health info, etc.) and use it for anything other than the stated primary service—this applies.
- If you're in the US—the FTC has jurisdiction. This rule doesn't create new law; it reinforces existing FTC authority under the Federal Trade Commission Act.
- If you use AI for: medical scribes (collecting patient data), hiring tools (analyzing candidate info), support chatbots (storing conversation history)—all trigger data-handling obligations.
- What's in scope: personal identifiers, behavioral data, inferred characteristics, location data, health information. Basically anything that could identify or profile a person.
- What's less of a concern: fully anonymized, aggregated data where individuals can't be identified. But anonymization is harder than most founders think.
What founders need to do
- Audit your data practices (2-3 days): Map what personal data you collect, where it goes, and what you do with it. Write it down. Be honest—this is for you, not regulators yet.
- Fix your privacy policy (1-2 days): Make it specific and accurate. Don't say you'll "use data to improve our service" if you're actually training third-party models or selling insights. Match policy to practice.
- Get explicit consent (1-2 days): Before collecting sensitive data (especially health, hiring, or financial info), tell users exactly what you're collecting and why. Make consent affirmative—checkboxes, not sneaky defaults. Keep proof you got consent.
- Limit secondary uses (ongoing): Don't repurpose data without fresh permission. If a user consents to a medical scribe using their notes, that doesn't mean you can train a general LLM on those notes or sell anonymized datasets to researchers without asking again.
- Document everything (ongoing, light): Keep records of consent, data flows, and policy changes. If the FTC ever asks, you'll want a clear paper trail showing you tried to do things right.
Bottom line
Monitor your data practices now—if you're collecting personal information without crystal-clear user consent and honest disclosures, tighten up before regulators notice.