The FTC settled charges against GoDaddy Inc. and GoDaddy.com, LLC for misleading customers about their data security protections and failing to adequately secure their website hosting services. The company allegedly did not implement reasonable security measures, leaving customer websites vulnerable to attacks that could harm both the customers and visitors to those sites. The case resulted in a consent order requiring GoDaddy to improve its security practices.
In-house legal teams should review all vendor and customer agreements where GoDaddy provides website hosting or related services. Specifically examine clauses covering security representations, warranties, and standards; audit and inspection rights; breach notification procedures; indemnification terms related to security incidents; and limitations of liability for data breaches or service vulnerabilities. Given the FTC's findings, contracts must accurately reflect the actual security practices and avoid overpromising protections. Consider adding or strengthening requirements for vulnerability testing, patch management, and customer-specific security controls, and ensure breach notification timelines align with regulatory expectations. Updates may be needed to align with the consent order's mandated security program improvements.
Entity
GoDaddy Inc. and GoDaddy.com, LLC
Also known as: GoDaddy
Industry
TechnologyOfficial Press Release
https://www.ftc.gov/legal-library/browse/cases-proceedings/2023133-godaddy-inc-et-al-matter
GoDaddy Complaint
https://www.ftc.gov/system/files/ftc_gov/pdf/GoDaddy-Complaint.pdf
GoDaddy D&O
https://www.ftc.gov/system/files/ftc_gov/pdf/GoDaddy-D&O.pdf
2023133 godaddy consent
https://www.ftc.gov/system/files/ftc_gov/pdf/2023133_godaddy_consent.pdf
2023133 godaddy decisionandorder
https://www.ftc.gov/system/files/ftc_gov/pdf/2023133_godaddy_decisionandorder.pdf
2023133 godaddy complaint
https://www.ftc.gov/system/files/ftc_gov/pdf/2023133_godaddy_complaint.pdf
2023133 godaddy analysisofproposedconsent
https://www.ftc.gov/system/files/ftc_gov/pdf/2023133_godaddy_analysisofproposedconsent.pdf
2023133 godaddy exhibits
https://www.ftc.gov/system/files/ftc_gov/pdf/2023133_godaddy_exhibits.pdf
ftc finalizes order godaddy over data security failures
https://www.ftc.gov/news-events/news/press-releases/2025/05/ftc-finalizes-order-godaddy-over-data-security-failures
ftc takes action against godaddy alleged lax data security i
https://www.ftc.gov/news-events/news/press-releases/2025/01/ftc-takes-action-against-godaddy-alleged-lax-data-security-its-website-hosting-services
Federal Trade Commission Enforcement Page
https://www.ftc.gov/enforcement
"In the Matter of GoDaddy Inc., a corporation, and GoDaddy.com, LLC, a limited liability company."
"Case settles charges that GoDaddy misled customers about the extent of its data security protections and failed to secure its website hosting services against attacks that could harm its customers and visitors to the customers' websites."
"Agreement Containing Consent Order"
$930K
The FTC finalized orders requiring CMG Media Corporation (doing business as Cox Media Group), MindSift LLC, and 1010 Digital Works LLC to pay a total of $930,000 for falsely claiming they offered an AI-powered service that could target ads based on conversations captured from consumers' smart devices, and that consumers had opted into such targeting. The orders also prohibit the companies from making misrepresentations about their advertising services, voice data collection, and consumer consent.
The FTC announced it is seeking public comment on a proposed enforcement policy statement regarding personalized pricing, which is the use of personal data to set prices based on what a company believes an individual consumer is willing to spend. The statement warns that undisclosed collection or use of personal data for personalized pricing could violate the FTC Act's prohibition on unfair or deceptive practices. The Commission voted 2-0 to authorize the Federal Register notice.
$4.0M
The FTC and Connecticut secured a $4 million settlement with Chase Nissan LLC (doing business as Manchester City Nissan) over allegations the dealership charged consumers unauthorized fees, including double-charging for 'certified pre-owned' vehicles and inserting charges like total loss protection into financing agreements without consent. The settlement requires $4 million in consumer redress, prohibits misrepresentations about vehicle certification and warranties, mandates prominent disclosure of the maximum total vehicle price, and requires express informed consent for all charges.
The FTC filed a complaint against Credit Glory LLC and related entities for deceptive credit repair practices, including false promises, impersonating debt collectors, charging illegal upfront fees, and using negative option billing without consent. A federal court temporarily halted the operation.
The FTC issued a policy statement abandoning disparate-impact liability, stating it will no longer bring claims based on this theory. It also modified compliance obligations for several companies based on past decisions.
The FTC, along with Utah and California, filed a complaint against Hims & Hers alleging the telehealth provider shared consumers' sensitive health information with third-party advertising platforms without consent, and deceived consumers about billing and cancellation practices. The complaint alleges violations of the FTC Act and the Restore Online Shoppers' Confidence Act.