
FTC Act section 5: privacy and security claims
At a glance
US-07High15 U.S.C. §45(a); FTC Policy Statement on Deception (1983)
Peeky reads claims like 'we never share your data' or 'bank-level encryption' and checks the ones a browser can test against what the site actually did.
Last checked against the source:
The rule
In the United States there is no single federal privacy statute that covers every website. For the claims a company makes about privacy and security, the main federal tool is section 5 of the Federal Trade Commission Act.
Section 5(a)(1) provides that “unfair or deceptive acts or practices in or affecting commerce, are hereby declared unlawful”, and section 5(a)(2) empowers and directs the Commission to prevent persons, partnerships and corporations from using them. The Act has a separate test for unfairness in section 5(n): conduct that “causes or is likely to cause substantial injury to consumers which is not reasonably avoidable by consumers themselves and not outweighed by countervailing benefits to consumers or to competition.”
The statute does not define deception. The FTC’s 1983 Policy Statement on Deception does, and the FTC has applied it to privacy and security claims since.
The statement says three elements “undergird all deception cases”. First, “there must be a representation, omission or practice that is likely to mislead the consumer”. Second, the practice is examined from the perspective of “a consumer acting reasonably in the circumstances”. Third, it “must be a ‘material’ one”, meaning likely to affect the consumer’s conduct or decision about a product or service. The issue is whether the practice “is likely to mislead, rather than whether it causes actual deception”. For express claims, “the representation itself establishes the meaning”, and the Commission “presumes that express claims are material”.
Apply that to a website. A sentence such as “we never share your data with third parties” or “your information is 100% confidential” is an express claim, so its meaning is what it says. If the site sends visitor data to an advertising platform, the claim is open to being tested against that fact.
Penalties work differently from the GDPR, and the text should be read carefully. Section 5(l) provides that a party that disobeys a final Commission order “shall forfeit and pay to the United States a civil penalty of not more than $10,000 for each violation”. Each day of a continuing failure counts separately. The figure is the statute’s base amount and is adjusted over time, so the current number should be checked. For a first false claim the usual result is an order that binds the company for years, which can then carry penalties if it is not followed. Money can also arise through a settlement or a referral to the Department of Justice, as in the Monument matter below, where the penalty rests on a different statute.
What PeekWell checks and how
US-07 asks, for each privacy or security claim on a public page, whether something the browser did contradicts it. It looks only for literal contradiction with evidence attached. Claims that a browser cannot test are read but not flagged.
The scan reads the pages it visits, including the privacy policy, and a language model extracts affirmative claims such as “we never share”, “bank-level encryption” or “HIPAA-compliant”. For the claims that map to something observable, code runs a test. The spec’s examples are “encrypted” against the TLS actually in use, and “no third-party sharing” against the trackers the browser recorded in a clean visit. The method is the same one EU-05 uses against the GDPR’s transparency rule, applied here to the claims themselves.
The decision is made by code from the evidence. The model reads the claim and helps write the explanation. It never asserts that a claim is false. Severity starts at high and is strongest when a specific claim is contradicted.
The scan has limits, and the report says so. It sees the public pages it visited and nothing behind a sign-in. It does not submit forms, test passwords or open addresses nobody linked to. It is not a security test and cannot confirm what encryption a company uses on a server, who has access to a database or whether a standard was met. A claim like “HIPAA-compliant” can be read and quoted in a report, but no browser visit can confirm or refute it. A Passed means the expected behaviour was observed on the pages scanned. It does not say the site’s claims are accurate.
Why it matters for a company
The FTC’s recent privacy and security cases lean on a company’s own words. In each of the three below, the FTC alleged that the company’s statements did not match what it was doing.
Zoom is the cleanest example of a security claim. The FTC alleged in 2020 that Zoom had advertised “end-to-end, 256-bit encryption” while holding the keys that let it reach meeting content, and that it had said recorded meetings were encrypted right after they ended when some stayed unencrypted for up to 60 days. The settlement announced on 9 November 2020 would require a security program and bar misrepresentation of privacy and security practices. It was subject to public comment, and the press release states no money. The Commission voted 3-2, with two commissioners dissenting.
GoDaddy followed in 2025. The FTC alleged the company claimed “award-winning security” while failing to use multi-factor authentication, to monitor for security threats and to secure connections to consumer data. It also alleged deception about compliance with the Privacy Shield frameworks. The order, finalized on 21 May 2025 by a 3-0 vote, bars misrepresentation of security and of compliance with any government, self-regulatory or standard-setting program. It requires a security program and an independent assessor.
Monument, in 2024, is a promise about confidentiality. The FTC’s complaint says that from 2020 to 2022 Monument told users their personal information would be “100% confidential” and not disclosed to third parties without consent, and said it complied with HIPAA, when an outside assessor had found it had not fully complied. The complaint alleges that it shared health details with advertising platforms, for as many as 84,000 users. The proposed order, as announced on 11 April 2024 and filed by the Department of Justice, would carry a $2.5 million civil penalty under a separate statute, the Opioid Addiction Recovery Fraud Prevention Act, suspended because of Monument’s inability to pay.
Three things follow for a company. Marketing copy counts: the claims in these cases were on a website or in consumer communications, not in a contract. A statement of a standard or a program, such as Privacy Shield, is a claim in its own right. And an order outlasts the case, since a company that has agreed to one is then measured against it.
Smaller companies and larger companies
Section 5 has no size threshold, and the Monument case shows it reaches a small firm. What differs is how the gap forms.
In a smaller company a founder or a marketer writes the reassuring lines: “bank-level security”, “we never sell your data”, “fully HIPAA-compliant”. They are written to win trust, often copied from another company’s page or a template. Then the site gets the usual tools, an analytics script, an ad pixel, a session recorder, and nobody checks the new tool against the old promise. The Monument complaint describes how that can go in a small health service, where the claim was “100% confidential” and the pixels sent health details to ad platforms.
In a larger company the claim often comes from brand or product marketing (“award-winning security”), while the practice sits with security, engineering and vendors. Nobody owns the question of whether the two agree. GoDaddy is the example in the sources: the claim was about the company as a whole, and the allegations concerned specific practices that did not match it.
Enforcement cases
Published decisions about other companies, listed for context. Each links to the authority's own page. They say nothing about any particular website.

Larger companies
Zoom Video Communications, Inc.
The FTC alleged that Zoom marketed 'end-to-end, 256-bit encryption' while keeping cryptographic keys that allowed it to access meeting content and using a lower level of encryption than advertised. It also alleged that recorded meetings stored on Zoom's servers were described as encrypted right after the meeting ended, when some stayed unencrypted for up to 60 days. The proposed settlement requires a security program and bars misrepresenting privacy and security practices.
Read the FTC (United States) publication about Zoom Video Communications, Inc.GoDaddy Inc.
The FTC alleged that GoDaddy claimed to provide award-winning security while not using multi-factor authentication, not monitoring for security threats and not securing connections to consumer data. It also alleged that the company deceived users about its compliance with the EU-U.S. and Swiss-U.S. Privacy Shield Frameworks. The finalized order bars misrepresenting security and requires a comprehensive security program and independent assessments.
Read the FTC (United States) publication about GoDaddy Inc.
Smaller companies
Monument, Inc.
The FTC alleged that Monument, a New York-based alcohol addiction treatment service that told users their information was 100% confidential, disclosed health details to Meta, Google and other ad platforms through tracking pixels. According to the complaint, as many as 84,000 users were affected.
Read the FTC (United States) publication about Monument, Inc.
How to fix it
Treat every privacy or security sentence on the site as something you can be asked to prove, and keep the proof close to the sentence.
- Collect the claims. Search the site, the privacy policy, the checkout and the app store text for “secure”, “encrypted”, “never”, “confidential”, “private” and “compliant”. Put each sentence in a list with the page it sits on.
- Test the ones you can. For “encrypted”, confirm every page and form posts over HTTPS and note what covers data at rest. For “we never share”, open the site in a private window with the network tab open and list every third-party request. Do it again after accepting the banner.
- Reword to what is true and specific. Replace “bank-level” or “military-grade” with what you do, for example “data is encrypted in transit with TLS and at rest with AES-256”, if that is the case. Replace “we never share” with who receives what, and why.
- Remove or gate what you cannot back up. If an ad pixel contradicts “we do not share”, either remove the pixel, or load it only after consent and change the claim to describe it. Drop a standard or program badge you cannot support.
- Give each claim an owner. Name who should re-check the list when a tool is added, a vendor changes or the policy is edited. Put the check in the release checklist.
- Re-scan. Run a scan again after the changes. The finding should disappear once no stated claim is contradicted by what the browser did.
Whether a reworded claim holds up with the FTC or a state authority is a question for your legal adviser. Peeky reports only what it sees.
Questions
What does section 5 of the FTC Act say about deception?
Section 5(a)(1) declares unlawful "unfair or deceptive acts or practices in or affecting commerce", and the FTC is directed to prevent them. The statute does not define deception. The FTC's 1983 policy statement sets out three elements: a representation, omission or practice likely to mislead, judged from a reasonable consumer's view, and material.
What is a deceptive practice according to the FTC?
A statement, omission or practice that is likely to mislead a consumer acting reasonably, on something that matters to the consumer's choice. The FTC's policy statement says the question is whether it is likely to mislead, not whether anyone was actually misled. For express claims, it says the claim itself establishes the meaning.
Does the FTC enforce privacy policies?
Yes, when a policy or other statement makes a promise the company does not keep. The cases listed here, Zoom, GoDaddy and Monument, were all brought over statements about security or confidentiality that the FTC alleged did not match practice. Most ended in orders, and the Monument settlement was announced in April 2024 as a proposed order needing court approval.
Is it deceptive to say data is encrypted if it is not?
The FTC has treated it that way. In the Zoom matter it alleged that the company claimed end-to-end encryption while keeping the keys needed to read meeting content. Zoom settled and agreed to an order that bars misrepresenting its privacy and security practices.
Can the FTC fine a company for a first false privacy claim?
Section 5(l) sets a civil penalty of up to $10,000 for each violation of a final order, adjusted over time. Section 5(m) adds penalties for knowing violations of FTC rules and of orders against others. A first false claim usually ends in an order, and money can follow through a settlement or a referral to the Department of Justice. In Monument the suspended $2.5 million came under a different statute, the Opioid Addiction Recovery Fraud Prevention Act. The other cases here show orders with no payment stated.
Filed with
The rule
Federal Trade Commission Act, section 5, 15 U.S.C. §45(a), (l) and (n)
Read the rule (Federal Trade Commission Act, section 5, 15 U.S.C. §45(a), (l) and (n))Sources
- 15 U.S.C. §45, Unfair methods of competition unlawful; prevention by Commission (Legal Information Institute copy)
- FTC Policy Statement on Deception (14 October 1983)
- FTC, FTC Requires Zoom to Enhance its Security Practices as Part of Settlement (9 November 2020)
- FTC, FTC Finalizes Order with GoDaddy over Data Security Failures (21 May 2025)
- FTC, Alcohol Addiction Treatment Firm will be Banned from Disclosing Health Data for Advertising to Settle FTC Charges that It Shared Data Without Consent (11 April 2024)
Last checked against the source:
For information only. Not legal advice.


