Court Rules
All enforcement actions
SettlementHigh Risk

FTC Settles with AppFolio for $4.25M Over FCRA Violations

AppFolio, Inc.December 8, 2020Federal Trade Commission

Penalty Amount

$4,250,000

Summary

AppFolio, Inc., a tenant background report provider, settled with the FTC for $4.25 million over allegations it violated the Fair Credit Reporting Act by failing to implement reasonable procedures to ensure the accuracy of its screening reports and by including eviction and non-conviction criminal records older than seven years. The settlement prohibits including old records and requires maintaining accuracy procedures.

Remedy

AppFolio must pay $4.25 million, is prohibited from including non-conviction criminal or eviction records older than seven years in its reports, and must maintain reasonable procedures to ensure the maximum possible accuracy of its background reports.

Monetary PenaltyInjunctionCompliance Program

Contract Impact

In-house legal teams should review all vendor and customer agreements where the company either provides or consumes tenant/background screening reports. Specifically examine clauses governing data accuracy, FCRA compliance certifications, data sourcing from third parties, and restrictions on the age of reported records (e.g., evictions, non-convictions). Agreements with property management clients (as vendors) may require amendments to mandate adherence to FCRA's 'reasonable procedures' standard and prohibit inclusion of records older than seven years. Contracts with third-party data providers should be scrutinized for warranties of accuracy and compliance. Consider adding audit rights, indemnification for FCRA violations, and explicit requirements for maintaining up-to-date accuracy procedures.

Contract Search Terms

tenant screening accuracy proceduresFair Credit Reporting Act (FCRA) complianceconsumer report user obligationsdata sourcing and verification protocolseviction record reporting limitationsnon-conviction criminal record inclusionseven-year reporting period restrictionthird-party vendor data validationbackground report audit rightsFCRA certification and compliance addendum

Laws Cited

Fair Credit Reporting Act

Violation Types

Entity Details

Entity

AppFolio, Inc.

Also known as: AppFolio

Industry

Data Broker

Official Sources

Source Evidence

Entity Name
"AppFolio, Inc."
Fine Amount
"$4.25 million"
Laws Cited
"Fair Credit Reporting Act (FCRA)"
Violation Types
"failed to implement reasonable procedures to ensure that criminal and eviction records it received from a third party vendor were accurate before including such information in its tenant screening reports."
Violation Types
"including eviction or non-conviction criminal records more than seven years old in its reports."

Related Enforcement Actions

FTC

Federal Trade Commission

The FTC rescinded its 2021 Policy Statement on Breaches by Health Apps and Other Connected Devices, which had purported to apply the Health Breach Notification Rule to health apps and connected devices that collect consumer health information. The rescission follows the Commission's 2024 update to the Health Breach Notification Rule, which already covers health apps and connected devices like fitness trackers, and implements an executive order directing agencies to eliminate obsolete guidance documents. No company was charged or penalized; this is a deregulatory action.

FTC

Humboldt Merchant Services

$12.0M

The FTC alleged that payment processor Humboldt Merchant Services knowingly processed payments for more than 1,000 shell merchant entities serving as fronts for fraudulent companies engaged in unauthorized billing scams, despite red flags including chargeback rates nearly 10 times higher than card-brand thresholds. Under the proposed stipulated order filed in the U.S. District Court for the Eastern District of Michigan, Humboldt will pay $12 million for consumer redress and is permanently banned from processing payments for merchants with a heightened risk of potential fraud.

FTC

Nuvei Corporation

$4.8M

The FTC charged Canada-based payment processor Nuvei Corporation and its subsidiaries with knowingly processing payments for fraudulent merchants, including more than $30 million in payments for the Reimage tech support scam from 2017 to 2023, as well as merchants making false earnings claims and impersonating government tax authorities. Under the stipulated order filed in the U.S. District Court for the District of Arizona, Nuvei will pay $4.85 million for consumer redress, is banned from serving tech support telemarketers, and must implement robust merchant screening and chargeback monitoring practices. Note: this is a payments-fraud facilitation action under the FTC Act and Telemarketing Sales Rule, not a data privacy violation.

FTC

N/A (no entity named - agency policy announcement)

The FTC announced a seven-day extension of the public comment period on its proposed enforcement policy statement regarding personalized pricing, pushing the deadline from Sept. 18, 2026 to Sept. 25, 2026. Personalized pricing refers to using personal data to set prices based on what the company believes an individual consumer is willing to spend. This is a procedural announcement about draft agency guidance, not an enforcement action against any company, and no entity was named, no violation found, and no penalty imposed.

FTC

Amazon.com, Inc.

Colorado Attorney General Phil Weiser joined the FTC and 22 state attorneys general in filing a lawsuit against Amazon for manipulating the auctions used to set advertising prices, replacing actual auction results with higher prices since 2019 and overcharging nearly 1.2 million U.S. advertising customers. The FTC estimates total improper surcharges from 2018 to 2026 exceed $20 billion, with costs ultimately passed to shoppers through higher prices. The states seek a permanent injunction and monetary relief; no penalty has been imposed yet as this is a newly filed complaint.

FTC

CMG Media Corporation

$930K

The FTC finalized orders requiring CMG Media Corporation (doing business as Cox Media Group), MindSift LLC, and 1010 Digital Works LLC to pay a total of $930,000 for falsely claiming they offered an AI-powered service that could target ads based on conversations captured from consumers' smart devices, and that consumers had opted into such targeting. The orders also prohibit the companies from making misrepresentations about their advertising services, voice data collection, and consumer consent.