Court Rules
All enforcement actions
Consent DecreeLow Risk

FTC Orders Drizly to Implement Security After 2.5M Consumer Data Breach

DrizlyJanuary 10, 2023Federal Trade Commission

Consumers Affected

2,500,000

Summary

The FTC finalized an order against Drizly and its CEO for security failures that led to a data breach exposing 2.5 million consumers' personal information. Drizly failed to implement basic security measures despite prior alerts. The order requires Drizly to destroy unnecessary data, implement a security program, and publicly detail data collection practices.

Remedy

Drizly must destroy personal data not necessary for services, refrain from unnecessary data collection, implement an information security program, and publicly disclose data collection practices on its website. CEO James Cory Rellas must implement an information security program at future companies where he has a majority ownership or senior security role if the business collects data from over 25,000 individuals.

Data DeletionCompliance Program

Contract Impact

In-house legal teams should review all vendor, customer, and data processing agreements for clauses related to data security, data retention, and data collection practices. Specifically, examine security standards, data minimization obligations, retention schedules, and audit rights. Contracts may need amendments to mandate specific security controls (e.g., encryption, access controls), require regular security assessments, enforce strict data retention limits aligned with 'necessary for specific purposes,' and include robust breach notification and cooperation provisions. Additionally, agreements should incorporate rights to audit the vendor's security program and require transparency about data collection purposes, mirroring the FTC's order for public disclosure.

Contract Search Terms

data retention schedulesecurity program implementationpersonal data destructiondata collection disclosuresecurity vulnerability remediationpurpose limitation clausesecure storage requirementscontinuous security monitoring

Violation Types

Entity Details

Entity

Drizly

Industry

Retail

Official Sources

Source Evidence

Entity Name
"Drizly"
Violation Types
"failed to implement basic security measures"
Violation Types
"data breach exposing the personal information"

Related Enforcement Actions

FTC

Vanilla Chip LLC

$750K

The FTC finalized an order against Vanilla Chip LLC (doing business as TruHeight) and its principals for deceptively advertising height-enhancing supplements for children and teens without scientific evidence. The company also used fake reviews and incentivized 5-star ratings. The order requires a $750,000 payment and prohibits false health claims and deceptive review practices.

FTC

RentGrow Inc.

$2.3M

The FTC alleged that RentGrow, a tenant screening company, violated the Fair Credit Reporting Act (FCRA) by failing to use reasonable procedures to ensure the accuracy of its reports, including by reporting duplicate records and failing to disclose data sources. RentGrow agreed to pay a $2.25 million penalty and is prohibited from further FCRA violations and from misrepresenting dispute outcomes.

FTC

Handy Technologies

The FTC and New York Attorney General took action against Handy Technologies for deceptive earnings claims and failure to disclose fees and fines that led to millions of dollars being withheld from workers' wages. The FTC is sending over $2.7 million in refunds to 62,893 affected consumers.

FTC

Hopper Inc.

$35.0M

The FTC alleged that Hopper, a travel booking app, charged consumers hidden and pre-selected fees (Tip and VIP Support) without their consent, misrepresented the benefits of VIP Support and Price Freeze services, and failed to clearly disclose total prices. Hopper agreed to pay $35 million for consumer redress and is prohibited from misrepresenting fees under a proposed order.

FTC

Publishing.com LLC

$1.5M

The FTC finalized a settlement with Publishing.com LLC and its principals for misleading consumers about potential earnings from self-publishing products. The company will pay $1.5 million and is prohibited from making unsubstantiated earnings claims, failing to disclose refund terms, and misrepresenting endorsements and reviews.

FTC

Federal Trade Commission

The FTC is seeking public comment on a proposed policy statement addressing concerns that AI companies may be manipulating AI system outputs contrary to consumer expectations for objectivity and accuracy. The statement explains that such conduct could be considered deceptive under Section 5 of the FTC Act. The public comment period runs until July 31, 2026.