FTC Settles with Fertility-Tracking App Developer Regarding Health Data Disclosures
Time 2 Minute Read

On January 13, 2021, the FTC announced that fertility-app developer Flo Health, Inc. (“Flo”) agreed to a settlement over allegations that the company shared app users’ health information with third-party data analytics providers despite representations that Flo would keep such information private.

The FTC alleged that Flo, a developer of a popular mobile application used by more than 100 million consumers to track menstruation and ovulation cycles, had promised to keep users’ health data private and use it only to provide services to app users, but in fact disclosed the data (such as the fact of a user’s pregnancy) to third-party marketing and analytics services. The complaint also alleged that Flo did not place restrictions on how third-parties could use this health data, and that Flo’s disclosures of sensitive health data continued unhindered until a February 2019 news article revealed them. Additionally, the FTC alleged that Flo, which is certified to the EU-U.S. and Swiss-U.S. Privacy Shield frameworks, violated the Privacy Shield’s Notice, Choice, Accountability for Onward Transfer and Data Integrity and Purpose Limitation Principles.

The proposed settlement would bar Flo from misrepresenting: (1) the purposes for which it collects, uses and discloses data; (2) the extent to which consumers can control the purposes for which their data is used; (3) Flo’s compliance with any privacy, security or compliance program; and (4) how Flo collects, maintains, uses, discloses, deletes or protects app users’ personal information. The proposed settlement also requires Flo to notify affected users about the disclosure of their personal information to third-parties, and instruct any third-party recipient to destroy Flo users’ health information.

You May Also Be Interested In

Time 3 Minute Read

The Connecticut Attorney General recently issued a legal memorandum regarding the application of existing Connecticut laws, such as the Connecticut Data Privacy Act, to the use of artificial intelligence.

Time 3 Minute Read

On March 20, 2026, Oklahoma Governor Kevin Stitt signed SB 546 into law, enacting the Oklahoma Consumer Data Privacy Act, which will take effect on January 1, 2027.

Time 4 Minute Read

Recent changes to 42 CFR Part 2 mean many covered entities must update their HIPAA Notices of Privacy Practices by February 16, 2026.

Time 2 Minute Read

On February 5, 2026, Alabama Governor Kay Ivey signed Alabama House Bill 161, the App Store Accountability Act, establishing age categorization, age verification and parental consent requirements for mobile application marketplace providers operating in Alabama, effective January 2027.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page