Court Rules
All enforcement actions
Consent DecreeLow Risk

FTC Proposes Order Against Global Tel*Link for Data Breach

Global Tel*Link Corp.November 16, 2023Federal Trade Commission

Consumers Affected

650,000

Summary

The FTC proposed a consent order against Global Tel*Link Corp. for failing to secure sensitive user data, leading to a breach affecting nearly 650,000 consumers, and for delaying notification for about nine months. The order requires the company to implement a comprehensive security program, notify affected users with credit monitoring, and report future breaches promptly.

Remedy

Global Tel*Link must implement a data security program with change management and multifactor authentication, notify all affected users from the breach and provide credit monitoring, notify consumers and facilities within 30 days of future breaches, report security incidents to the FTC within 10 days, and is prohibited from misrepresenting its security practices.

Compliance ProgramCorrective NoticeReporting RequirementsInjunction

Contract Impact

In-house legal teams should review all vendor and customer agreements, particularly those with telecommunications or communication service providers (like prison communications services), as well as any data processing agreements. Specific clauses to scrutinize include data security obligations, breach notification requirements (including timelines and scope of affected parties), data retention and disposal policies, and provisions related to cloud or third-party storage. Given the FTC's focus on inadequate safeguards and delayed notification, contracts may need amendments to mandate specific security controls (e.g., encryption, access logs), shorten breach notification windows (e.g., from months to days), require immediate notification to all affected individuals and business partners (like correctional facilities), and include audit rights or certification requirements for security programs.

Contract Search Terms

data encryption standardsbreach notification timelinesecurity audit requirementscloud storage securitysensitive data handlingincident response planthird-party vendor managementuser notification proceduresdata processing safeguardscomprehensive security program

Violation Types

Entity Details

Entity

Global Tel*Link Corp.

Also known as: Global Tel*Link

Industry

Telecommunications

Official Sources

Source Evidence

Entity Name
"Global Tel*Link Corp."
Violation Types
"failed to implement adequate security safeguards"
Violation Types
"waited approximately nine months to notify affected customers"

Related Enforcement Actions

FTC

Vanilla Chip LLC

$750K

The FTC finalized an order against Vanilla Chip LLC (doing business as TruHeight) and its principals for deceptively advertising height-enhancing supplements for children and teens without scientific evidence. The company also used fake reviews and incentivized 5-star ratings. The order requires a $750,000 payment and prohibits false health claims and deceptive review practices.

FTC

RentGrow Inc.

$2.3M

The FTC alleged that RentGrow, a tenant screening company, violated the Fair Credit Reporting Act (FCRA) by failing to use reasonable procedures to ensure the accuracy of its reports, including by reporting duplicate records and failing to disclose data sources. RentGrow agreed to pay a $2.25 million penalty and is prohibited from further FCRA violations and from misrepresenting dispute outcomes.

FTC

Handy Technologies

The FTC and New York Attorney General took action against Handy Technologies for deceptive earnings claims and failure to disclose fees and fines that led to millions of dollars being withheld from workers' wages. The FTC is sending over $2.7 million in refunds to 62,893 affected consumers.

FTC

Hopper Inc.

$35.0M

The FTC alleged that Hopper, a travel booking app, charged consumers hidden and pre-selected fees (Tip and VIP Support) without their consent, misrepresented the benefits of VIP Support and Price Freeze services, and failed to clearly disclose total prices. Hopper agreed to pay $35 million for consumer redress and is prohibited from misrepresenting fees under a proposed order.

FTC

Publishing.com LLC

$1.5M

The FTC finalized a settlement with Publishing.com LLC and its principals for misleading consumers about potential earnings from self-publishing products. The company will pay $1.5 million and is prohibited from making unsubstantiated earnings claims, failing to disclose refund terms, and misrepresenting endorsements and reviews.

FTC

Federal Trade Commission

The FTC is seeking public comment on a proposed policy statement addressing concerns that AI companies may be manipulating AI system outputs contrary to consumer expectations for objectivity and accuracy. The statement explains that such conduct could be considered deceptive under Section 5 of the FTC Act. The public comment period runs until July 31, 2026.