Regulations › US federal

FTC Act Section 5

Federal Trade Commission Act, Section 5

In force privacy security consumer protection
WhenIn effect since 26 September 1914
Who enforces itFederal Trade Commission
Who it applies toMost businesses, except those regulated by other agencies such as banks and common carriers.

The main federal privacy enforcement tool: unfair or deceptive practices, including privacy promises not kept and unreasonable security.

The law in brief

Section 5 of the FTC Act prohibits unfair or deceptive acts or practices. It contains no privacy or security rules of its own, yet it has been the main tool of US federal privacy enforcement for more than twenty years. The FTC uses it against companies that break their privacy promises, collect or share data in ways people would not expect, keep weak security, or make unsupported claims about AI.

The practical rule is simple: do what your privacy notice, security statements and product claims say, and do not use data in ways that cause substantial harm people cannot avoid.

Who it applies to

  • Most businesses and nonprofits engaged in commerce. Banks, common carriers and certain other entities regulated by other agencies are largely excluded, though their non-bank affiliates may not be.
  • Deception covers statements and omissions likely to mislead a reasonable consumer about something material, including privacy notices, cookie banners, security claims and AI capability claims.
  • Unfairness covers practices that cause or are likely to cause substantial injury that consumers cannot reasonably avoid and that is not outweighed by benefits.

What it requires

Keep your promises

Do not make statements in privacy notices, interfaces or marketing about data practices, security or AI that are false or misleading, including by omission.

No unfair practices

Do not engage in data practices that cause or are likely to cause substantial injury to consumers that they cannot reasonably avoid and that is not outweighed by benefits.

Reasonable security

Failing to take reasonable measures to protect consumer data can be an unfair practice, and claiming protection you do not provide is deceptive.

Consent for material changes

Get affirmative express consent before using data collected under one privacy promise in a materially different way.

Enforcement and penalties

The FTC usually resolves cases through consent orders that run for 20 years and can require security programs, independent assessments, deletion of data and of models or algorithms built with it, and bans on certain practices. It generally cannot obtain civil penalties for a first violation of Section 5 alone, but it can for violations of an order or of a trade regulation rule, and each violation of an order can carry a substantial penalty adjusted for inflation.

What to do first

  1. Compare your privacy notice with reality: every data flow, sharing arrangement and retention period.
  2. Check cookie banners and consent flows for design that misleads.
  3. Review security claims and the controls that support them.
  4. Substantiate AI claims before they go into marketing.
  5. Get affirmative consent before using data in materially different ways from what you told people.
  6. Treat sensitive data, such as health and location, with extra care; it features heavily in recent cases.

Checked against the official text on 28 September 2026. Quotations are the operative words of the law, linked to the article they come from; the official text is the authority. This brief is written by the Association for practitioners and is not legal advice.

Recent developments

Sources