Court Rules
All enforcement actions
SettlementMedium Risk

FTC Settles CafePress Data Security Case for $500K Penalty

Residual Pumpkin Entity, LLC and PlanetArt, LLCMarch 1, 2022Federal Trade Commission

Penalty Amount

$500,000

Consumers Affected

184,491

Summary

The FTC settled with CafePress's former owner Residual Pumpkin Entity, LLC and buyer PlanetArt, LLC over data security failures that led to a breach exposing Social Security numbers and other sensitive data. Residual Pumpkin paid $500,000 for victim compensation, and both companies must implement comprehensive security programs. A claims process is open for affected consumers until March 10, 2024.

Remedy

Residual Pumpkin must pay $500,000 to compensate victims, and both Residual Pumpkin and PlanetArt must implement comprehensive information security programs. Eligible consumers can file claims for payments through the FTC's online portal.

Monetary PenaltyCompliance ProgramConsumer Refunds

Contract Impact

In-house legal teams should review all vendor, customer, and data processing agreements where personal information (especially Social Security numbers) is handled or stored. Focus on clauses detailing data security obligations, encryption requirements for sensitive data at rest and in transit, breach notification timelines and procedures, and audit/inspection rights. Given the failure to implement 'reasonable security measures,' agreements should be updated to mandate specific security frameworks (e.g., NIST, ISO 27001), require regular security audits and penetration testing, and clearly allocate liability and remediation costs in the event of a breach involving unencrypted SSNs or other sensitive data.

Contract Search Terms

data security programencryption standardsSSN storagepassword reset securitybreach notificationreasonable security measuresaudit rightsdata processing addendumvendor security clausesconsumer data protection

Violation Types

Entity Details

Entity

Residual Pumpkin Entity, LLC and PlanetArt, LLC

Also known as: CafePress

Industry

Retail

Official Sources

Source Evidence

Entity Name
"Residual Pumpkin Entity, LLC, the former owner of CafePress, and PlanetArt, LLC, which bought CafePress in 2020"
Fine Amount
"Residual Pumpkin also agreed to pay $500,000"
Violation Types
"failed to implement reasonable security measures to protect sensitive information stored on its network, including plain text Social Security numbers, inadequately encrypted passwords, and answers to password reset questions. The company’s data security failures led to a data breach that exposed this sensitive data including Social Security numbers."

Related Enforcement Actions

FTC

Residual Pumpkin Entity, LLC and PlanetArt, LLC

$500K

The FTC took action against CafePress for failing to secure consumer data and covering up a major data breach. The company stored sensitive information insecurely and delayed notifying customers. As part of the settlement, Residual Pumpkin must pay $500,000 in redress, and both companies must implement comprehensive security programs.

FTC

Vanilla Chip LLC

$750K

The FTC finalized an order against Vanilla Chip LLC (doing business as TruHeight) and its principals for deceptively advertising height-enhancing supplements for children and teens without scientific evidence. The company also used fake reviews and incentivized 5-star ratings. The order requires a $750,000 payment and prohibits false health claims and deceptive review practices.

FTC

RentGrow Inc.

$2.3M

The FTC alleged that RentGrow, a tenant screening company, violated the Fair Credit Reporting Act (FCRA) by failing to use reasonable procedures to ensure the accuracy of its reports, including by reporting duplicate records and failing to disclose data sources. RentGrow agreed to pay a $2.25 million penalty and is prohibited from further FCRA violations and from misrepresenting dispute outcomes.

FTC

Handy Technologies

The FTC and New York Attorney General took action against Handy Technologies for deceptive earnings claims and failure to disclose fees and fines that led to millions of dollars being withheld from workers' wages. The FTC is sending over $2.7 million in refunds to 62,893 affected consumers.

FTC

Hopper Inc.

$35.0M

The FTC alleged that Hopper, a travel booking app, charged consumers hidden and pre-selected fees (Tip and VIP Support) without their consent, misrepresented the benefits of VIP Support and Price Freeze services, and failed to clearly disclose total prices. Hopper agreed to pay $35 million for consumer redress and is prohibited from misrepresenting fees under a proposed order.

FTC

Publishing.com LLC

$1.5M

The FTC finalized a settlement with Publishing.com LLC and its principals for misleading consumers about potential earnings from self-publishing products. The company will pay $1.5 million and is prohibited from making unsubstantiated earnings claims, failing to disclose refund terms, and misrepresenting endorsements and reviews.