FTC Act § 5

15 U.S.C. § 45

Federal Trade Commission Act, Section 5 — unfair or deceptive acts or practices

In force since September 26, 1914

Who it applies to

  • Persons, partnerships and corporations engaged in commerce
  • In practice the general-purpose privacy and data-security authority in the United States

Consumer rights

  • Access / know — not granted
  • Correction — not granted
  • Deletion / erasure — not granted
  • Portability — not granted
  • Opt out of sale / sharing — not granted
  • Opt out of targeted advertising — not granted
  • Opt out of profiling — not granted
  • Limit sensitive data use — not granted
  • Human review of automated decisions — not granted
  • Non-discrimination — not granted
  • Appeal a refusal — not granted
  • Private right of action — not granted

Obligations

Consent model
Mixed
Universal opt-out signal
Not required
Risk assessments
Not required
Data protection officer
Not required
Records of processing
Not required
Processor contract
Not required
Right to cure
None — enforcement may follow immediately
Data broker registration
Not required

Breach notification

To individuals
Not addressed by this section
To the regulator
Not required by this law
What triggers it
Not addressed by this section

Penalties

Headline
Injunctive relief and consent orders; civil penalties for violating an existing order
Private right of action
No — enforcement is by the regulator only
Notes
Section 5 creates no rights a consumer can assert directly. It matters because a privacy policy that misstates a practice becomes a deceptive act, which is how most US privacy enforcement actually happens.

Exemptions

Entities

  • Banks, savings and loan institutions and federal credit unions
  • Common carriers subject to the Communications Act
  • Non-profit organisations not operating for their members' profit

Sources