Court Rules
All enforcement actions
Consent DecreeLow Risk

FTC Settles Privacy Shield Case with NTT Global Data Centers

NTT Global Data Centers, Inc.April 16, 2020Federal Trade Commission

Summary

NTT Global Data Centers settled FTC allegations that it misled consumers about its participation in the EU-U.S. Privacy Shield framework and failed to comply with its requirements. The settlement requires the company to hire a third-party assessor if it re-certifies, prohibits misrepresentations about privacy programs, and mandates continued application of Privacy Shield protections or deletion of data collected while participating.

Remedy

The company must hire a third-party assessor to verify adherence to Privacy Shield promises if it re-certifies, is prohibited from misrepresenting its participation in privacy programs, and must continue to apply Privacy Shield protections to personal information collected while participating or return or delete such information.

Audit RequirementInjunctionData Deletion

Contract Impact

In-house legal teams should review all vendor, customer, and data processing agreements that involve the transfer of personal data from the European Union to the United States. Specifically, scrutinize clauses referencing data transfer mechanisms (like Privacy Shield or its successors), representations regarding participation in or compliance with international privacy frameworks, and obligations that survive the termination or lapse of a certification. Agreements may need amendments to: (1) ensure accurate and non-misleading descriptions of any privacy program participation; (2) incorporate requirements for third-party verification/assessment if the company intends to recertify under a framework like Privacy Shield; and (3) explicitly address the handling or deletion of data collected during a period of prior participation, in line with continuing obligations.

Contract Search Terms

Privacy Shield certificationdata transfer clausethird-party assessor requirementEU-U.S. data transferscertification lapse provisionscontinuing obligationsprivacy policy representationsmarketing materials compliancedata deletion protocolsrecertification conditions

Violation Types

Entity Details

Entity

NTT Global Data Centers, Inc.

Also known as: NTT Global Data Centers

Industry

Technology

Official Sources

Source Evidence

Entity Name
"NTT Global Data Centers, Inc., formerly known as RagingWire Data Centers, Inc. (RagingWire)"
Violation Types
"misled consumers about its participation in the EU-U.S. Privacy Shield framework and failed to adhere to the program’s requirements"

Related Enforcement Actions

FTC

CMG Media Corporation

$930K

The FTC finalized orders requiring CMG Media Corporation (doing business as Cox Media Group), MindSift LLC, and 1010 Digital Works LLC to pay a total of $930,000 for falsely claiming they offered an AI-powered service that could target ads based on conversations captured from consumers' smart devices, and that consumers had opted into such targeting. The orders also prohibit the companies from making misrepresentations about their advertising services, voice data collection, and consumer consent.

FTC

Federal Trade Commission

The FTC announced it is seeking public comment on a proposed enforcement policy statement regarding personalized pricing, which is the use of personal data to set prices based on what a company believes an individual consumer is willing to spend. The statement warns that undisclosed collection or use of personal data for personalized pricing could violate the FTC Act's prohibition on unfair or deceptive practices. The Commission voted 2-0 to authorize the Federal Register notice.

FTC

Chase Nissan LLC

$4.0M

The FTC and Connecticut secured a $4 million settlement with Chase Nissan LLC (doing business as Manchester City Nissan) over allegations the dealership charged consumers unauthorized fees, including double-charging for 'certified pre-owned' vehicles and inserting charges like total loss protection into financing agreements without consent. The settlement requires $4 million in consumer redress, prohibits misrepresentations about vehicle certification and warranties, mandates prominent disclosure of the maximum total vehicle price, and requires express informed consent for all charges.

FTC

Credit Glory LLC

The FTC filed a complaint against Credit Glory LLC and related entities for deceptive credit repair practices, including false promises, impersonating debt collectors, charging illegal upfront fees, and using negative option billing without consent. A federal court temporarily halted the operation.

FTC

Federal Trade Commission

The FTC issued a policy statement abandoning disparate-impact liability, stating it will no longer bring claims based on this theory. It also modified compliance obligations for several companies based on past decisions.

FTC

Hims & Hers

The FTC, along with Utah and California, filed a complaint against Hims & Hers alleging the telehealth provider shared consumers' sensitive health information with third-party advertising platforms without consent, and deceived consumers about billing and cancellation practices. The complaint alleges violations of the FTC Act and the Restore Online Shoppers' Confidence Act.