RegImpact
ftcenforcement· Published 2/29/2024

Avast Limited et al.; Analysis of Proposed Consent Order To Aid Public Comment

The consent agreement in this matter settles alleged violations of federal law prohibiting unfair or deceptive acts or practices. The attached Analysis of Proposed Consent Order to Aid Public Comment describes both the allegations in the complaint and the terms of the consent order--embodied in the consent agreement--that would settle these allegations.

What this rule actually says

The FTC charged Avast (a security software company) with deceiving users about data collection and selling practices. The consent order requires companies to be honest about what user data they collect, how they use it, and who they share it with. If a product claims to protect privacy or security, it actually has to do that.

Who it applies to

  • If you collect user data (even just email addresses, IP logs, or usage patterns), this applies to you
  • If you make privacy or security claims about your AI product, this applies to you—even vague ones like "we protect your data" or "secure by default"
  • If you're in the US, this applies to you (FTC jurisdiction)
  • If you sell, license, or share user data with third parties, this applies to you
  • If you use user data for different purposes than stated (e.g., collecting "for product improvement" but using it for ad targeting), this applies to you
  • Out of scope: purely synthetic/fake data you generate for testing; aggregated/truly anonymized data (though FTC is skeptical of anonymization claims)

What founders need to do

  1. Audit your privacy practices (2-3 days): Document exactly what user data you collect, store, and share. Be honest about it. Check if your actual practices match your Privacy Policy word-for-word.
  1. Update your Privacy Policy (1-2 days): Write clearly in plain English what data you collect and why. Don't make vague claims like "we may use your data to improve services." Be specific. Remove any claims you can't actually back up.
  1. Fix any gaps between what you claim and what you do (1-2 weeks): If your product page says "encrypted end-to-end" but it isn't, fix it now. If you collect usage data but your policy doesn't mention it, update the policy and/or stop collecting it.
  1. Document your security measures (ongoing): If you claim your AI model or data storage is secure, have actual documentation of encryption, access controls, and incident response plans. The FTC will ask for this if they investigate.
  1. Watch for FTC inquiries (ongoing): The FTC occasionally sends Civil Investigative Demands to AI companies. Respond promptly and honestly.

Bottom line

Monitor this now—don't act in panic, but do audit whether your Privacy Policy actually describes what your product does. Most indie founders are compliant here; the risk is making claims you can't back up.