RegImpact
ftcproposed· Published 8/22/2022

Trade Regulation Rule on Commercial Surveillance and Data Security

The Federal Trade Commission ("FTC") is publishing this advance notice of proposed rulemaking ("ANPR") to request public comment on the prevalence of commercial surveillance and data security practices that harm consumers. Specifically, the Commission invites comment on whether it should implement new trade regulation rules or other regulatory alternatives concerning the ways in which companies collect, aggregate, protect, use, analyze, and retain consumer data, as well as transfer, share, sell, or otherwise monetize that data in ways that are unfair or deceptive.

What this rule actually says

The FTC is considering new rules to stop companies from collecting, using, or selling consumer data in unfair or deceptive ways. Right now this is just a proposal asking for public feedback—nothing is final yet. The rule would likely require companies to be honest about what data they collect, who they share it with, and how they use it; restrict selling or sharing data without clear consent; and require reasonable security to protect that data.

Who it applies to

  • If you collect any personal data from users (names, emails, medical history, hiring info, chat transcripts)—this likely applies to you, regardless of whether you sell that data
  • If you're in the US—the FTC has jurisdiction over US companies and non-US companies serving US users
  • If you're building: medical scribes, hiring tools, support chatbots, or any AI product that processes user information—you're in scope
  • If you share, sell, or monetize user data (even anonymized)—this is a primary concern of the rule
  • If you use third-party vendors or APIs that process user data—you may still be liable for their practices
  • **Data that's *out of scope*: publicly available information you didn't collect, employee-only data (if you're an employer), and data that's truly anonymized** (though the FTC has a high bar for what counts as truly anonymized)

What founders need to do

  1. Document your data practices (2-3 days): Write down what user data you collect, where it goes, who accesses it, how long you keep it, and whether you share or sell it. This isn't optional—regulators will ask for this.
  1. Review your privacy policy (1-2 days): Make sure it's actually honest about what you do. Vague language like "we may share data with partners" is a red flag. Be specific.
  1. Audit security basics (1 week): Ensure you have basic protections—encrypted databases, access controls, secure APIs. Nothing extreme, but legitimate safeguards.
  1. Get explicit consent for data sharing (ongoing): If you share, sell, or use user data in ways beyond the core service, ask permission first. Make it easy to say no.
  1. Monitor FTC updates (ongoing): This rule is still proposed. Subscribe to FTC announcements or check back quarterly. When it finalizes, you'll need to adjust if requirements change significantly.

Bottom line

Monitor this closely but don't panic yet—it's still a proposal, not law. However, the practices it targets (opaque data collection, deceptive sharing, poor security) are already risky under existing FTC authority, so tightening up your data practices now is smart either way.