Court Rules
All enforcement actions
SettlementLow Risk

FTC Finalizes Order Against Illuminate Education for Student Data Breach

Illuminate Education Inc.June 5, 2026Federal Trade Commission

Consumers Affected

10,100,000

Summary

The FTC finalized a consent order against Illuminate Education Inc. for failing to secure students' personal data, leading to a breach affecting 10.1 million students. The order requires Illuminate to implement a data security program, delete unnecessary data, and limit data collection, but imposes no monetary penalty.

Remedy

Illuminate is prohibited from misrepresenting its data security and privacy practices and breach notification speed. It must delete unnecessary personal data, limit data collection to what is reasonably needed, adopt a data retention schedule, implement a comprehensive information security program, and notify the FTC if it reports a breach to other government entities.

InjunctionConsent DecreeCompliance ProgramData DeletionReporting Requirements

Contract Impact

In-house legal teams should review vendor agreements with education technology providers for data security obligations, breach notification timelines, data retention and deletion clauses, and representations about privacy and security. Specific focus should be on contracts with schools that include student data processing, ensuring they require prompt breach notification, data minimization, and a comprehensive security program. Also, contracts with third-party vendors that have access to student data should include security vulnerability remediation requirements and audit rights.

Contract Search Terms

data security programstudent data breach notificationdata retention schedulethird-party vendor security vulnerabilitiescloud-based database securitypersonal information deletionprivacy and security representationsbreach notification timelinedata minimization requirementhealth-related information

Laws Cited

FTC Act

Violation Types

Entity Details

Entity

Illuminate Education Inc.

Industry

Education

Official Sources

Source Evidence

Entity Name
"Illuminate Education Inc."
Consumers Affected
"10.1 million students"
Violation Types
"data security failures led to a major data breach"
Violation Types
"failed to notify schools about the breach in a timely manner"
Remedy Types
"implement a data security program, limit collection and retention of consumer data, and delete unnecessary data"
Document Urls
"https://www.ftc.gov/system/files/ftc_gov/pdf/2223105c4833illuminatefinalcomplaint.pdf"

Related Enforcement Actions

FTC

CMG Media Corporation

$930K

The FTC finalized orders requiring CMG Media Corporation (doing business as Cox Media Group), MindSift LLC, and 1010 Digital Works LLC to pay a total of $930,000 for falsely claiming they offered an AI-powered service that could target ads based on conversations captured from consumers' smart devices, and that consumers had opted into such targeting. The orders also prohibit the companies from making misrepresentations about their advertising services, voice data collection, and consumer consent.

FTC

Federal Trade Commission

The FTC announced it is seeking public comment on a proposed enforcement policy statement regarding personalized pricing, which is the use of personal data to set prices based on what a company believes an individual consumer is willing to spend. The statement warns that undisclosed collection or use of personal data for personalized pricing could violate the FTC Act's prohibition on unfair or deceptive practices. The Commission voted 2-0 to authorize the Federal Register notice.

FTC

Chase Nissan LLC

$4.0M

The FTC and Connecticut secured a $4 million settlement with Chase Nissan LLC (doing business as Manchester City Nissan) over allegations the dealership charged consumers unauthorized fees, including double-charging for 'certified pre-owned' vehicles and inserting charges like total loss protection into financing agreements without consent. The settlement requires $4 million in consumer redress, prohibits misrepresentations about vehicle certification and warranties, mandates prominent disclosure of the maximum total vehicle price, and requires express informed consent for all charges.

FTC

Credit Glory LLC

The FTC filed a complaint against Credit Glory LLC and related entities for deceptive credit repair practices, including false promises, impersonating debt collectors, charging illegal upfront fees, and using negative option billing without consent. A federal court temporarily halted the operation.

FTC

Federal Trade Commission

The FTC issued a policy statement abandoning disparate-impact liability, stating it will no longer bring claims based on this theory. It also modified compliance obligations for several companies based on past decisions.

FTC

Hims & Hers

The FTC, along with Utah and California, filed a complaint against Hims & Hers alleging the telehealth provider shared consumers' sensitive health information with third-party advertising platforms without consent, and deceived consumers about billing and cancellation practices. The complaint alleges violations of the FTC Act and the Restore Online Shoppers' Confidence Act.