Court Rules
All enforcement actions
SettlementCritical Risk

FTC Settles with Avast for $16.5M Over Deceptive Data Sales

AvastFebruary 1, 2024Federal Trade Commission

Penalty Amount

$16,500,000

Consumers Affected

3,690,813

Summary

The FTC settled with Avast for deceiving customers by claiming its antivirus software blocked tracking while secretly collecting and selling browsing data. Avast must pay $16.5 million in refunds and is banned from such practices. The FTC is now processing claims for affected consumers.

Remedy

Avast is required to pay $16.5 million to a refund fund, is permanently banned from selling or licensing browsing data for advertising purposes and from misrepresenting data practices, and must comply with other requirements.

Monetary PenaltyBan

Contract Impact

In-house legal teams should review all customer-facing agreements for antivirus/security software (end-user license agreements, terms of service) and vendor contracts where data is shared with third parties (e.g., analytics, advertising partners). Key clauses to scrutinize include: (1) data collection and use descriptions, ensuring they explicitly disclose if browsing data will be sold/licensed for advertising; (2) consent mechanisms, verifying they obtain affirmative, informed consent for such sales; (3) privacy policy representations, cross-checking marketing claims against permitted data practices; (4) data sharing permissions with subsidiaries or affiliates; and (5) data retention and deletion schedules. Changes may be needed to add clear, conspicuous disclosures about data sales, implement granular opt-out/opt-in consent, prohibit re-identification of data, and restrict advertising use of data from security products.

Contract Search Terms

browsing data sale clausethird-party data sharing agreementprivacy policy disclosure requirementsconsumer consent for data collectiondata processing addendumopt-out mechanism for data salesadvertising data licensingsoftware privacy noticere-identifiable data handlingsubsidiary data sharing

Violation Types

Entity Details

Entity

Avast

Industry

Technology

Official Sources

Source Evidence

Entity Name
"Avast"
Fine Amount
"pay $16.5 million"
Violation Types
"deceived users by claiming that its software would protect consumers’ privacy by blocking third party tracking, but it failed to adequately inform consumers that it would collect and sell their detailed, re-identifiable browsing data."
Event Date
"February 2024"

Related Enforcement Actions

FTC

CMG Media Corporation

$930K

The FTC finalized orders requiring CMG Media Corporation (doing business as Cox Media Group), MindSift LLC, and 1010 Digital Works LLC to pay a total of $930,000 for falsely claiming they offered an AI-powered service that could target ads based on conversations captured from consumers' smart devices, and that consumers had opted into such targeting. The orders also prohibit the companies from making misrepresentations about their advertising services, voice data collection, and consumer consent.

FTC

Federal Trade Commission

The FTC announced it is seeking public comment on a proposed enforcement policy statement regarding personalized pricing, which is the use of personal data to set prices based on what a company believes an individual consumer is willing to spend. The statement warns that undisclosed collection or use of personal data for personalized pricing could violate the FTC Act's prohibition on unfair or deceptive practices. The Commission voted 2-0 to authorize the Federal Register notice.

FTC

Chase Nissan LLC

$4.0M

The FTC and Connecticut secured a $4 million settlement with Chase Nissan LLC (doing business as Manchester City Nissan) over allegations the dealership charged consumers unauthorized fees, including double-charging for 'certified pre-owned' vehicles and inserting charges like total loss protection into financing agreements without consent. The settlement requires $4 million in consumer redress, prohibits misrepresentations about vehicle certification and warranties, mandates prominent disclosure of the maximum total vehicle price, and requires express informed consent for all charges.

FTC

Credit Glory LLC

The FTC filed a complaint against Credit Glory LLC and related entities for deceptive credit repair practices, including false promises, impersonating debt collectors, charging illegal upfront fees, and using negative option billing without consent. A federal court temporarily halted the operation.

FTC

Federal Trade Commission

The FTC issued a policy statement abandoning disparate-impact liability, stating it will no longer bring claims based on this theory. It also modified compliance obligations for several companies based on past decisions.

FTC

Hims & Hers

The FTC, along with Utah and California, filed a complaint against Hims & Hers alleging the telehealth provider shared consumers' sensitive health information with third-party advertising platforms without consent, and deceived consumers about billing and cancellation practices. The complaint alleges violations of the FTC Act and the Restore Online Shoppers' Confidence Act.