Canadian Maker of Smart Locks Settles with FTC Over Deceptive Security Claims
Time 2 Minute Read

A Canadian maker of Internet-connected padlocks, Tapplock, Inc. (“Tapplock”), settled Federal Trade Commission (“FTC”) allegations that the company violated Section 5 of the FTC Act by falsely claiming that its “smart locks” were secure. The FTC alleged that Tapplock “did not take reasonable measures to secure its locks, or take reasonable precautions or follow industry best practices for protecting consumers’ personal information.” The FTC further alleged that Tapplock did not have a security program in place prior to security researchers discovering vulnerabilities in the design and function of the smart locks.

According to the FTC complaint, the smart locks interact with a companion mobile app that enables a user to lock and unlock the smart lock via a Bluetooth connection. The mobile app collects personal information, including usernames, email addresses, profile photos, location history, and the precise location of users’ smart locks. Tapplock advertised the smart locks as “Bold. Sturdy. Secure.” and touted a number of features designed to make the smart locks “unbreakable.” In its privacy policy, Tapplock stated that it takes reasonable precautions and follows industry best practices to make sure users’ personal information is not inappropriately lost, misused, accessed, disclosed, altered or destroyed. Security researchers identified both physical and electronic vulnerabilities that allowed them to unlock and lock the smart locks and gain access to users’ personal information.

Under the terms of the settlement, Tapplock agrees to implement a comprehensive security program and undertake a number of security measures, including obtaining independent assessments of its security program every two years. In a blog post, the FTC reiterated that Internet of Things (“IoT”) companies wanting to avoid similar mistakes should implement “security by design,” encourage a culture of security, design products with authentication in mind, follow industry best practices (such as encryption techniques), and protect interfaces between their IoT products and other devices and services.

The settlement also prohibits Tapplock from misrepresenting its privacy and security practices. According to Andrew Smith, Director of the FTC’s Bureau of Consumer Protection, “[t]ech companies should remember the basics—when you promise security, you need to deliver security.”

You May Also Be Interested In

Time 3 Minute Read

On March 20, 2026, Oklahoma Governor Kevin Stitt signed SB 546 into law, enacting the Oklahoma Consumer Data Privacy Act, which will take effect on January 1, 2027.

Time 2 Minute Read

On March 23, 2026, the UK Information Commissioner's Office released new guidance clarifying the use of the new recognized legitimate interest lawful basis for processing personal information under UK data protection law.

Time 2 Minute Read

On March 5, 2026, the California Privacy Protection Agency announced that the agency had reached a settlement with Ford Motor Company resolving an enforcement action against the company that alleged noncompliance with the California Consumer Privacy Act’s opt-out of sale/sharing rights.

Time 3 Minute Read

The Federal Trade Commission has issued a new Policy Statement encouraging the adoption of robust age‑verification technologies by pledging not to bring enforcement actions under the COPPA Rule against operators of general‑ or mixed‑audience sites that collect, use or disclose personal information solely to determine users’ ages, so long as long as they follow strict safeguards.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page