Court Rules
All enforcement actions
SettlementLow Risk

FTC Finalizes Zoom Settlement Over Deceptive Security Practices

Zoom Video Communications, Inc.January 19, 2021Federal Trade Commission

Summary

The FTC finalized a settlement with Zoom Video Communications, Inc. for misleading consumers about its data security practices and compromising user security. The settlement requires Zoom to implement a comprehensive security program, review software updates for security flaws, and undergo biennial third-party assessments.

Remedy

Zoom must implement and maintain a comprehensive security program, review software updates for security flaws before release to ensure they don't hamper third-party security features, obtain biennial independent third-party assessments of its security program, and notify the FTC of any data breaches.

Compliance ProgramAudit RequirementReporting RequirementsConsent Decree

Contract Impact

In-house legal teams should review all vendor and customer agreements, particularly those involving software-as-a-service (SaaS) or platform provisions where data security is a material term. Specific clauses to audit include representations and warranties regarding data security measures, obligations to review and test software updates for vulnerabilities, requirements to maintain a documented security program, and breach notification procedures. Agreements may need amendments to explicitly require compliance with a comprehensive, FTC-approved security program, mandate pre-release security testing for updates to prevent degradation of third-party security features, and incorporate obligations for independent biennial security audits. Teams should also ensure contracts with sub-processors or downstream vendors reflect these heightened security obligations.

Contract Search Terms

data security practicessoftware update reviewsecurity flawsthird-party security assessmentbiennial assessmentcomprehensive security programdata breach notificationmisleading security claims

Violation Types

Entity Details

Entity

Zoom Video Communications, Inc.

Also known as: Zoom

Industry

Technology

Official Sources

Source Evidence

Entity Name
"Zoom Video Communications, Inc."
Violation Types
"allegations it misled consumers about the level of security it provided for its Zoom meetings and compromised the security of some Mac users."

Related Enforcement Actions

FTC

Zoom Video Communications, Inc.

The FTC settled with Zoom for deceiving users about its encryption security and unfairly installing software that bypassed browser safeguards. Zoom must implement a comprehensive security program, undergo biennial audits, and is banned from making false security claims. No monetary penalty was imposed.

FTC

CMG Media Corporation

$930K

The FTC finalized orders requiring CMG Media Corporation (doing business as Cox Media Group), MindSift LLC, and 1010 Digital Works LLC to pay a total of $930,000 for falsely claiming they offered an AI-powered service that could target ads based on conversations captured from consumers' smart devices, and that consumers had opted into such targeting. The orders also prohibit the companies from making misrepresentations about their advertising services, voice data collection, and consumer consent.

FTC

Federal Trade Commission

The FTC announced it is seeking public comment on a proposed enforcement policy statement regarding personalized pricing, which is the use of personal data to set prices based on what a company believes an individual consumer is willing to spend. The statement warns that undisclosed collection or use of personal data for personalized pricing could violate the FTC Act's prohibition on unfair or deceptive practices. The Commission voted 2-0 to authorize the Federal Register notice.

FTC

Chase Nissan LLC

$4.0M

The FTC and Connecticut secured a $4 million settlement with Chase Nissan LLC (doing business as Manchester City Nissan) over allegations the dealership charged consumers unauthorized fees, including double-charging for 'certified pre-owned' vehicles and inserting charges like total loss protection into financing agreements without consent. The settlement requires $4 million in consumer redress, prohibits misrepresentations about vehicle certification and warranties, mandates prominent disclosure of the maximum total vehicle price, and requires express informed consent for all charges.

FTC

Credit Glory LLC

The FTC filed a complaint against Credit Glory LLC and related entities for deceptive credit repair practices, including false promises, impersonating debt collectors, charging illegal upfront fees, and using negative option billing without consent. A federal court temporarily halted the operation.

FTC

Federal Trade Commission

The FTC issued a policy statement abandoning disparate-impact liability, stating it will no longer bring claims based on this theory. It also modified compliance obligations for several companies based on past decisions.