FTC Act Section 5, Unfair or Deceptive Acts or Practices (privacy and data-security enforcement)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 26 September 1914.
An enforcement supervision rule binding private bodies.
As of 23 August 2026.
What it requires
- Do not engage in unfair or deceptive practices when collecting, using, or sharing personal data.
- Assess foreseeable privacy harms before deploying a system that collects or uses biometric identifiers derived from photographs, videos, or voice recordings, and disclose material facts about that collection.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Penalty structure
Section 5(a) declares unfair or deceptive practices unlawful but attaches no civil penalty to a bare first violation; a penalty attaches only once the FTC has issued a trade-regulation rule (15 U.S.C. 45(m)(1)(A)) or a final cease-and-desist order (15 U.S.C. 45(l), 45(m)(1)(B)), and the person then violates it with actual knowledge or knowledge fairly implied. Each of those provisions states a nominal $10,000-per-violation ceiling, adjusted for inflation to $53,088 per violation (2025 figure) by 16 CFR 1.98. Each day of a continuing failure to comply with a rule is a separate violation under 45(m)(1)(C).
- Rule
- Per violation only
- As of
- 2 September 2026
- Currency
- USD
- Per violation unit
- Violation
- Per violation amount
- 53,088
Who enforces it
Enforcement body
Federal Trade Commission
Enforcement record
Counts the case entries listed on the FTC's own Privacy and Security Enforcement page, part of the Protecting Consumer Privacy and Security topic hub, with case dates from September 29, 2025 through September 10, 2026, the latest twelve months the page's own Cases list covers as of the read date: Hims and Hers, CMG Media Corporation, RentGrow, Amazon.com, FTC v. Kochava, Illuminate Education, Twitter, OkCupid and Match, General Motors, NGL, Disney, Illusory Systems and Nomad, Support King (SpyFone.com), Avast, Apitor, and Iconic Hearts Holdings, sixteen matters the page brings under Section 5 as the general federal vehicle for privacy and data-security enforcement. The next-oldest listed case, Pornhub, Mindgeek and Aylo, is dated September 8, 2025 and falls just outside this window.
- As of
- 17 September 2026
- Source link
- https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement
- Actions per year
- 16
What it reaches
Obligation class
Disclosure, Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Prohibits unfair or deceptive acts or practices in or affecting commerce and empowers the FTC, not private plaintiffs, to investigate and enforce against them. This is the primary federal vehicle for privacy and data-security enforcement in the absence of a comprehensive statute, reaching misrepresentations about data collection or protection and unfair data practices that cause substantial, unavoidable consumer injury.
The Commission's 2023 Policy Statement on Biometric Information applies this authority to biometric identifiers, including those derived from photographs, videos, or voice recordings.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometrics
Read the law
Official U.S. Code text (Office of the Law Revision Counsel), 15 U.S.C. Section 45
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.