FTC Releases Staff Perspective on Informational Injuries
Time 2 Minute Read
Categories: Cybersecurity

On October 19, 2018, the Federal Trade Commission announced that it released a paper on the Staff Perspective on the Informational Injury Workshop (the “Paper”), which summarized the outcomes of a workshop it hosted on December 12, 2017 to discuss and better understand “informational injuries” (i.e., harm suffered by consumers as a result of privacy and security incidents, such as data breaches or unauthorized disclosures of data) in an effort to guide (1) future policy determinations related to consumer injury and (2) future application of the “substantial injury” prong in cases involving informational injury.

The Paper listed several examples of informational injuries, including medical identity theft, doxing, disclosure of private information and erosion of trust, and emphasized that the risks of such injuries should be balanced against the value of the information collection. In light of these risks, the workshop participants agreed on three factors that governments should consider in determining whether and when to intervene and address these injuries:

  • the sensitivity of the data at issue;
  • how the data at issue will be used; and
  • whether the data at issue is anonymized or identifiable.

Workshop participants further discussed (1) whether the definition of “injury” should include the risk of injury; (2) potential explanations of “the privacy paradox,” in which survey evidence indicates that consumers state their care and concern for privacy, but behave in a contrary way; and (3) the need for more research on a broad range of privacy and data security issues.

Regarding the last topic, workshop participants agreed that such research would inform government policymakers and law enforcers regarding how to prevent and remedy informational injuries without cramping innovation. The FTC hopes to encourage academic research in this area through its annual PrivacyCon conference, to take place in May 2019, and through its series of Hearings on Competition and Consumer Protection in the 21st century, which explore the intersection between privacy, big data, competition and the FTC’s remedial authority to deter unfair and deceptive conduct in privacy and data security matters.

You May Also Be Interested In

Time 3 Minute Read

The Connecticut Attorney General recently issued a legal memorandum regarding the application of existing Connecticut laws, such as the Connecticut Data Privacy Act, to the use of artificial intelligence.

Time 3 Minute Read

On March 20, 2026, Oklahoma Governor Kevin Stitt signed SB 546 into law, enacting the Oklahoma Consumer Data Privacy Act, which will take effect on January 1, 2027.

Time 2 Minute Read

On March 23, 2026, the UK Information Commissioner's Office released new guidance clarifying the use of the new recognized legitimate interest lawful basis for processing personal information under UK data protection law.

Time 2 Minute Read

On February 5, 2026, Alabama Governor Kay Ivey signed Alabama House Bill 161, the App Store Accountability Act, establishing age categorization, age verification and parental consent requirements for mobile application marketplace providers operating in Alabama, effective January 2027.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page