Court Rules
All enforcement actions
Consent DecreeLow Risk

FTC Settles with GoDaddy Over Data Security Failures

GoDaddy Inc. and GoDaddy.com, LLCMay 21, 2025Federal Trade Commission

Summary

The FTC settled charges against GoDaddy Inc. and GoDaddy.com, LLC for misleading customers about their data security protections and failing to adequately secure their website hosting services. The company allegedly did not implement reasonable security measures, leaving customer websites vulnerable to attacks that could harm both the customers and visitors to those sites. The case resulted in a consent order requiring GoDaddy to improve its security practices.

Contract Impact

In-house legal teams should review all vendor and customer agreements where GoDaddy provides website hosting or related services. Specifically examine clauses covering security representations, warranties, and standards; audit and inspection rights; breach notification procedures; indemnification terms related to security incidents; and limitations of liability for data breaches or service vulnerabilities. Given the FTC's findings, contracts must accurately reflect the actual security practices and avoid overpromising protections. Consider adding or strengthening requirements for vulnerability testing, patch management, and customer-specific security controls, and ensure breach notification timelines align with regulatory expectations. Updates may be needed to align with the consent order's mandated security program improvements.

Contract Search Terms

security representations and warrantiessecurity measures clauseaudit rightsbreach notification clauseindemnification for security failuresservice level agreement securitydata protection addendumvulnerability management programincident response planlimitation of liability security

Violation Types

Entity Details

Entity

GoDaddy Inc. and GoDaddy.com, LLC

Also known as: GoDaddy

Industry

Technology

Official Sources

Source Evidence

Entity Name
"In the Matter of GoDaddy Inc., a corporation, and GoDaddy.com, LLC, a limited liability company."
Violation Types
"Case settles charges that GoDaddy misled customers about the extent of its data security protections and failed to secure its website hosting services against attacks that could harm its customers and visitors to the customers' websites."
Remedy Types
"Agreement Containing Consent Order"

Related Enforcement Actions

FTC

CMG Media Corporation

$930K

The FTC finalized orders requiring CMG Media Corporation (doing business as Cox Media Group), MindSift LLC, and 1010 Digital Works LLC to pay a total of $930,000 for falsely claiming they offered an AI-powered service that could target ads based on conversations captured from consumers' smart devices, and that consumers had opted into such targeting. The orders also prohibit the companies from making misrepresentations about their advertising services, voice data collection, and consumer consent.

FTC

Federal Trade Commission

The FTC announced it is seeking public comment on a proposed enforcement policy statement regarding personalized pricing, which is the use of personal data to set prices based on what a company believes an individual consumer is willing to spend. The statement warns that undisclosed collection or use of personal data for personalized pricing could violate the FTC Act's prohibition on unfair or deceptive practices. The Commission voted 2-0 to authorize the Federal Register notice.

FTC

Chase Nissan LLC

$4.0M

The FTC and Connecticut secured a $4 million settlement with Chase Nissan LLC (doing business as Manchester City Nissan) over allegations the dealership charged consumers unauthorized fees, including double-charging for 'certified pre-owned' vehicles and inserting charges like total loss protection into financing agreements without consent. The settlement requires $4 million in consumer redress, prohibits misrepresentations about vehicle certification and warranties, mandates prominent disclosure of the maximum total vehicle price, and requires express informed consent for all charges.

FTC

Credit Glory LLC

The FTC filed a complaint against Credit Glory LLC and related entities for deceptive credit repair practices, including false promises, impersonating debt collectors, charging illegal upfront fees, and using negative option billing without consent. A federal court temporarily halted the operation.

FTC

Federal Trade Commission

The FTC issued a policy statement abandoning disparate-impact liability, stating it will no longer bring claims based on this theory. It also modified compliance obligations for several companies based on past decisions.

FTC

Hims & Hers

The FTC, along with Utah and California, filed a complaint against Hims & Hers alleging the telehealth provider shared consumers' sensitive health information with third-party advertising platforms without consent, and deceived consumers about billing and cancellation practices. The complaint alleges violations of the FTC Act and the Restore Online Shoppers' Confidence Act.