FTC Announces Settlement with Lenovo Regarding Preinstalled Laptop Software
Time 2 Minute Read

On September 5, 2017, the FTC announced that Lenovo, Inc. (“Lenovo”) agreed to settle charges that its preloaded software on some laptop computers compromised online security protections in order to deliver advertisements to consumers. The settlement agreement (the “Settlement”) is between Lenovo, the FTC and 32 State Attorneys General. 

In its complaint, the FTC charged that, since August 2014, Lenovo sold consumer laptops in the United States with a preinstalled “man-in-the-middle” software program, known as VisualDiscovery and sold by a third-party software company, that delivered pop-up advertisements from the software company’s retail partners whenever a user placed the laptop’s cursor over a similar product on a website. The FTC charged that the software was able to access consumers’ sensitive personal information transmitted online, including login credentials, Social Security numbers, medical information and financial and payment card information, in order to deliver the targeted advertisements. Further, the FTC charged that, to facilitate the display of pop-up advertisements on encrypted websites, the software “used an insecure method to replace digital certificates for those websites with its own VisualDiscovery-signed certificates,” but failed to authenticate the validity of websites’ digital certificates before replacing them. This prevented consumers’ Internet browsers from warning them when they visited potentially spoofed or malicious websites. According to the FTC, Lenovo sold laptops with the VisualDiscovery software without discovering the security vulnerabilities “because it failed to assess and address security risks created by” VisualDiscovery.

The Settlement prohibits Lenovo from future misrepresentations of preloaded software on its laptops that will inject advertising or transmit sensitive consumer information to third parties. In addition, the Settlement requires Lenovo to obtain consumers’ affirmative consent before preloading this type of software onto laptops. Lenovo also must implement a comprehensive software security program for most preloaded consumer software and be subject to third-party audits for 20 years. The Settlement will be subject to public comment until October 5, 2017, after which the FTC will determine whether to finalize it.

You May Also Be Interested In

Time 3 Minute Read

On March 20, 2026, Oklahoma Governor Kevin Stitt signed SB 546 into law, enacting the Oklahoma Consumer Data Privacy Act, which will take effect on January 1, 2027.

Time 2 Minute Read

On March 23, 2026, the UK Information Commissioner's Office released new guidance clarifying the use of the new recognized legitimate interest lawful basis for processing personal information under UK data protection law.

Time 2 Minute Read

On March 5, 2026, the California Privacy Protection Agency announced that the agency had reached a settlement with Ford Motor Company resolving an enforcement action against the company that alleged noncompliance with the California Consumer Privacy Act’s opt-out of sale/sharing rights.

Time 3 Minute Read

The Federal Trade Commission has issued a new Policy Statement encouraging the adoption of robust age‑verification technologies by pledging not to bring enforcement actions under the COPPA Rule against operators of general‑ or mixed‑audience sites that collect, use or disclose personal information solely to determine users’ ages, so long as long as they follow strict safeguards.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Authors

Archives

Jump to Page