Consumers Affected
10,100,000
The FTC finalized a consent order against Illuminate Education Inc. for failing to secure students' personal data, leading to a breach affecting 10.1 million students. The order requires Illuminate to implement a data security program, delete unnecessary data, and limit data collection, but imposes no monetary penalty.
Illuminate is prohibited from misrepresenting its data security and privacy practices and breach notification speed. It must delete unnecessary personal data, limit data collection to what is reasonably needed, adopt a data retention schedule, implement a comprehensive information security program, and notify the FTC if it reports a breach to other government entities.
In-house legal teams should review vendor agreements with education technology providers for data security obligations, breach notification timelines, data retention and deletion clauses, and representations about privacy and security. Specific focus should be on contracts with schools that include student data processing, ensuring they require prompt breach notification, data minimization, and a comprehensive security program. Also, contracts with third-party vendors that have access to student data should include security vulnerability remediation requirements and audit rights.
Entity
Illuminate Education Inc.
Industry
EducationOfficial Press Release
https://www.ftc.gov/news-events/news/press-releases/2026/06/ftc-gives-final-approval-order-against-illuminate-settling-allegations-it-failed-secure-students
2223105c4833illuminatefinalcomplaint
https://www.ftc.gov/system/files/ftc_gov/pdf/2223105c4833illuminatefinalcomplaint.pdf
2223105c4833illuminatefinalorder
https://www.ftc.gov/system/files/ftc_gov/pdf/2223105c4833illuminatefinalorder.pdf
Federal Trade Commission Enforcement Page
https://www.ftc.gov/enforcement
"Illuminate Education Inc."
"10.1 million students"
"data security failures led to a major data breach"
"failed to notify schools about the breach in a timely manner"
"implement a data security program, limit collection and retention of consumer data, and delete unnecessary data"
"https://www.ftc.gov/system/files/ftc_gov/pdf/2223105c4833illuminatefinalcomplaint.pdf"
$930K
The FTC finalized orders requiring CMG Media Corporation (doing business as Cox Media Group), MindSift LLC, and 1010 Digital Works LLC to pay a total of $930,000 for falsely claiming they offered an AI-powered service that could target ads based on conversations captured from consumers' smart devices, and that consumers had opted into such targeting. The orders also prohibit the companies from making misrepresentations about their advertising services, voice data collection, and consumer consent.
The FTC announced it is seeking public comment on a proposed enforcement policy statement regarding personalized pricing, which is the use of personal data to set prices based on what a company believes an individual consumer is willing to spend. The statement warns that undisclosed collection or use of personal data for personalized pricing could violate the FTC Act's prohibition on unfair or deceptive practices. The Commission voted 2-0 to authorize the Federal Register notice.
$4.0M
The FTC and Connecticut secured a $4 million settlement with Chase Nissan LLC (doing business as Manchester City Nissan) over allegations the dealership charged consumers unauthorized fees, including double-charging for 'certified pre-owned' vehicles and inserting charges like total loss protection into financing agreements without consent. The settlement requires $4 million in consumer redress, prohibits misrepresentations about vehicle certification and warranties, mandates prominent disclosure of the maximum total vehicle price, and requires express informed consent for all charges.
The FTC filed a complaint against Credit Glory LLC and related entities for deceptive credit repair practices, including false promises, impersonating debt collectors, charging illegal upfront fees, and using negative option billing without consent. A federal court temporarily halted the operation.
The FTC issued a policy statement abandoning disparate-impact liability, stating it will no longer bring claims based on this theory. It also modified compliance obligations for several companies based on past decisions.
The FTC, along with Utah and California, filed a complaint against Hims & Hers alleging the telehealth provider shared consumers' sensitive health information with third-party advertising platforms without consent, and deceived consumers about billing and cancellation practices. The complaint alleges violations of the FTC Act and the Restore Online Shoppers' Confidence Act.