Law / United States

FTC Act Section 5, Unfair or Deceptive Acts or Practices (privacy and data-security enforcement)

15 U.S.C. Section 45

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 26 September 1914.

An enforcement supervision rule binding private bodies.

As of 23 August 2026.

What it requires

  • Do not engage in unfair or deceptive practices when collecting, using, or sharing personal data.
  • Assess foreseeable privacy harms before deploying a system that collects or uses biometric identifiers derived from photographs, videos, or voice recordings, and disclose material facts about that collection.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Penalty structure

Section 5(a) declares unfair or deceptive practices unlawful but attaches no civil penalty to a bare first violation; a penalty attaches only once the FTC has issued a trade-regulation rule (15 U.S.C. 45(m)(1)(A)) or a final cease-and-desist order (15 U.S.C. 45(l), 45(m)(1)(B)), and the person then violates it with actual knowledge or knowledge fairly implied. Each of those provisions states a nominal $10,000-per-violation ceiling, adjusted for inflation to $53,088 per violation (2025 figure) by 16 CFR 1.98. Each day of a continuing failure to comply with a rule is a separate violation under 45(m)(1)(C).

Rule
Per violation only
As of
2 September 2026
Currency
USD
Per violation unit
Violation
Per violation amount
53,088

Who enforces it

Enforcement body

Federal Trade Commission

Enforcement record

Counts the case entries listed on the FTC's own Privacy and Security Enforcement page, part of the Protecting Consumer Privacy and Security topic hub, with case dates from September 29, 2025 through September 10, 2026, the latest twelve months the page's own Cases list covers as of the read date: Hims and Hers, CMG Media Corporation, RentGrow, Amazon.com, FTC v. Kochava, Illuminate Education, Twitter, OkCupid and Match, General Motors, NGL, Disney, Illusory Systems and Nomad, Support King (SpyFone.com), Avast, Apitor, and Iconic Hearts Holdings, sixteen matters the page brings under Section 5 as the general federal vehicle for privacy and data-security enforcement. The next-oldest listed case, Pornhub, Mindgeek and Aylo, is dated September 8, 2025 and falls just outside this window.

As of
17 September 2026
Source link
https://www.ftc.gov/news-events/topics/protecting-consumer-privacy-security/privacy-security-enforcement
Actions per year
16

What it reaches

Obligation class

Disclosure, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Prohibits unfair or deceptive acts or practices in or affecting commerce and empowers the FTC, not private plaintiffs, to investigate and enforce against them. This is the primary federal vehicle for privacy and data-security enforcement in the absence of a comprehensive statute, reaching misrepresentations about data collection or protection and unfair data practices that cause substantial, unavoidable consumer injury.

The Commission's 2023 Policy Statement on Biometric Information applies this authority to biometric identifiers, including those derived from photographs, videos, or voice recordings.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics

Read the law

Official U.S. Code text (Office of the Law Revision Counsel), 15 U.S.C. Section 45

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app