The FTC finalized an order with GoDaddy for failing to implement adequate data security measures and misleading consumers about its security and Privacy Shield compliance. The order prohibits misrepresentations, requires a comprehensive security program, and mandates independent assessments.
GoDaddy must stop making false security claims, establish and implement a comprehensive information-security program, and hire an independent third-party assessor to review the program.
In-house legal teams should review all vendor, customer, and data processing agreements where GoDaddy acts as a service provider. Focus on clauses related to data security obligations, representations/warranties about security measures and compliance certifications (especially Privacy Shield), audit and assessment rights, and breach notification requirements. Contracts may need amendments to: (1) remove or qualify any broad security claims or references to specific certifications like Privacy Shield; (2) incorporate specific, actionable security requirements aligned with the order's mandate for a comprehensive program (e.g., MFA, threat monitoring); (3) grant the company rights to conduct or require independent security assessments; and (4) ensure breach notification terms are robust and consistent with the order's expectations.
Entity
GoDaddy
Industry
TechnologyOfficial Press Release
https://www.ftc.gov/news-events/news/press-releases/2025/05/ftc-finalizes-order-godaddy-over-data-security-failures
ftc takes action against godaddy alleged lax data security i
https://www.ftc.gov/news-events/news/press-releases/2025/01/ftc-takes-action-against-godaddy-alleged-lax-data-security-its-website-hosting-services
Federal Trade Commission Enforcement Page
https://www.ftc.gov/enforcement
"GoDaddy"
"misled consumers by failing to implement data security protections, which led to several data breaches."
$750K
The FTC finalized an order against Vanilla Chip LLC (doing business as TruHeight) and its principals for deceptively advertising height-enhancing supplements for children and teens without scientific evidence. The company also used fake reviews and incentivized 5-star ratings. The order requires a $750,000 payment and prohibits false health claims and deceptive review practices.
$2.3M
The FTC alleged that RentGrow, a tenant screening company, violated the Fair Credit Reporting Act (FCRA) by failing to use reasonable procedures to ensure the accuracy of its reports, including by reporting duplicate records and failing to disclose data sources. RentGrow agreed to pay a $2.25 million penalty and is prohibited from further FCRA violations and from misrepresenting dispute outcomes.
The FTC and New York Attorney General took action against Handy Technologies for deceptive earnings claims and failure to disclose fees and fines that led to millions of dollars being withheld from workers' wages. The FTC is sending over $2.7 million in refunds to 62,893 affected consumers.
$35.0M
The FTC alleged that Hopper, a travel booking app, charged consumers hidden and pre-selected fees (Tip and VIP Support) without their consent, misrepresented the benefits of VIP Support and Price Freeze services, and failed to clearly disclose total prices. Hopper agreed to pay $35 million for consumer redress and is prohibited from misrepresenting fees under a proposed order.
$1.5M
The FTC finalized a settlement with Publishing.com LLC and its principals for misleading consumers about potential earnings from self-publishing products. The company will pay $1.5 million and is prohibited from making unsubstantiated earnings claims, failing to disclose refund terms, and misrepresenting endorsements and reviews.
The FTC is seeking public comment on a proposed policy statement addressing concerns that AI companies may be manipulating AI system outputs contrary to consumer expectations for objectivity and accuracy. The statement explains that such conduct could be considered deceptive under Section 5 of the FTC Act. The public comment period runs until July 31, 2026.