FTC Settles with Two Online Operators for Failing to Secure Customers' Data
Time 2 Minute Read

On April 24, 2019, the Federal Trade Commission announced two data security cases involving online operators—one, an online rewards website, and the second, a dress-up games website—that were alleged to have failed to take reasonable steps to secure consumers’ data, which allowed hackers to breach both websites.

ClixSense Case
The FTC’s case against ClixSense and the company’s owner involved deceptive statements that the site, which collected personal information from users (including, in some instances, Social Security numbers), “utilizes the latest security and encryption techniques to ensure the security of your account information.” According to the FTC, ClixSense’s failures to implement reasonable security measures permitted hackers to gain access to the company’s network, through a browser extension that ClixSense downloaded. The hackers then published and offered the ClixSense user data for sale.

Unixiz Case
The FTC’s case against Unixiz, Inc. (doing business as i-Dressup.com) involved alleged violations of the Children’s Online Privacy Protection Act (“COPPA”). According to the FTC, i-Dressup.com failed to obtain parental consent prior to collecting personal information from the child users of the site, and also failed to comply with COPPA’s requirement to keep the data it collected secure. These failures led to a hacker accessing the information of approximately 2.1 million i-Dressup.com users—including approximately 245,000 users who indicated they were under 13.

Both settlements require the operators to implement comprehensive information security programs and obtain independent biennial assessments of this program. In addition, they also are prohibited from making misrepresentations to the third party performing the biennial assessments of any information security program, and must provide an annual certification of compliance to the FTC.

The five-member Commission issued a separate statement in connection with these two settlements, indicating that the Commission was “particularly committed to strengthening the order provisions regarding data security assessments of companies by third parties” and that “future orders will better ensure that third-party assessors know they are accountable for providing meaningful, independent analysis of the data practices under examination.”

You May Also Be Interested In

Time 3 Minute Read

The Connecticut Attorney General recently issued a legal memorandum regarding the application of existing Connecticut laws, such as the Connecticut Data Privacy Act, to the use of artificial intelligence.

Time 3 Minute Read

On March 20, 2026, Oklahoma Governor Kevin Stitt signed SB 546 into law, enacting the Oklahoma Consumer Data Privacy Act, which will take effect on January 1, 2027.

Time 2 Minute Read

On February 5, 2026, Alabama Governor Kay Ivey signed Alabama House Bill 161, the App Store Accountability Act, establishing age categorization, age verification and parental consent requirements for mobile application marketplace providers operating in Alabama, effective January 2027.

Time 2 Minute Read

On March 5, 2026, the California Privacy Protection Agency announced that the agency had reached a settlement with Ford Motor Company resolving an enforcement action against the company that alleged noncompliance with the California Consumer Privacy Act’s opt-out of sale/sharing rights.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page