Skip to main content

Morning Overview

12 household names the FTC forced to stop collecting, selling or keeping Americans’ personal data

Federal Trade Commission actions have left a trail of orders, bans and penalties at companies that most Americans use or visit regularly. The cases range from retail stores and hotels to video games, social platforms and cars, and each one turned on how personal information was gathered, shared or retained. Here are twelve of them, with what each order or penalty required.

1. Rite Aid: Five-Year Face Scan Ban

Rite Aid — Image Credit: Jo Coscia - CC0/Wiki Commons
Image Credit: Jo Coscia – CC0/Wiki Commons

The FTC announced that Rite Aid would be banned for five years from using facial recognition technology for security purposes. In its facial recognition ban announcement, the agency said the retailer’s technology falsely tagged consumers, particularly women and people of color, as shoplifters. The headline of that release states the length of the ban directly, and the same release carries the allegation about who the system misidentified.

For shoppers, the order is a time-limited restriction on one retailer’s security technology rather than a general rule for stores. The mistaken tags described by the agency fell most heavily on women and people of color.

2. Amazon Alexa: Kids’ Voice Recordings Deleted

Amazon Alexa — Image Credit: Freepik
Image Credit: Freepik

The FTC and the Justice Department charged Amazon over children’s privacy tied to Alexa voice recordings. A proposed $25 million order would require Amazon to pay $25 million and to delete children’s data, geolocation data and other voice recordings. The agency’s release title describes the recordings as having been kept forever, meaning the company had retained them indefinitely.

The practical effect for Alexa households with children is deletion of stored voice and location data under the order. The financial penalty is a separate $25 million obligation.

3. Ring: Videos Ordered Deleted

Ring — Image Credit: Donald Trung Quoc Don (Chữ Hán: 徵國單) - CC BY-SA 4.0/Wiki Commons
Image Credit: Donald Trung Quoc Don (Chữ Hán: 徵國單) – CC BY-SA 4.0/Wiki Commons

Amazon-owned Ring agreed to pay $5.8 million in refunds after the FTC said the doorbell maker let employees and contractors watch customers’ videos and used recordings to train algorithms without consent. The agency said the permission for that use sat in the terms of service and the privacy policy, described as product improvement and development.

The order goes past the money: Ring has to delete customer videos and the face embeddings taken from them collected before 2018, along with any work products built from that footage. Deleting the derived models, not just the files, is what separates this from a simple refund, because it removes the asset the recordings became.

4. Xbox: Signup Data From Children

Xbox — Image Credit: Evan-Amos - Public domain/Wiki Commons
Image Credit: Evan-Amos – Public domain/Wiki Commons

Microsoft agreed to a $20 million settlement to resolve FTC charges that it violated COPPA by collecting personal information from children who signed up for its Xbox gaming system. The FTC said the collection happened at signup without notifying the children’s parents. The case sits in the FTC’s legal library as a United States action against Microsoft Corporation.

For families, the case concerns the account creation step, where a child’s details were gathered before a parent had been told. The $20 million payment is the penalty named in the agency’s description.

5. Marriott: Breaches Across Two Systems

Marriott — Image Credit: Michael Rivera - CC BY-SA 4.0/Wiki Commons
Image Credit: Michael Rivera – CC BY-SA 4.0/Wiki Commons

The FTC’s case against Marriott International and Starwood Hotels & Resorts ended in a data security settlement requiring them to settle charges that they failed to implement reasonable data security. According to the agency’s description, that failure led to data breaches. The breaches spanned both the Marriott and Starwood systems, tying the guest information at risk to the two brands the case names together.

For hotel guests, the case concerns how guest data was protected rather than how it was sold. No dollar figure is given here, so the order’s data security requirements are the substance.

6. Twitter: Security Numbers Used for Ads

Twitter — Image Credit: MatthewKeys - CC BY 3.0/Wiki Commons
Image Credit: MatthewKeys – CC BY 3.0/Wiki Commons

The FTC said Twitter’s collection of phone numbers and email addresses for account security was followed by use of that information for advertising targeting. In the agency’s account, the deceptive use of user email addresses and phone numbers violated the FTC Act and the 2011 Commission order. The case is filed in the legal library as a United States action against Twitter, Inc.

The significance for account holders is that a number supplied to protect a login was, per the FTC, put to a second purpose. The earlier order is what made the allegation a violation of a standing commitment.

7. Disney: Kid Videos on YouTube

Disney — Image Credit: Coolcaesar - CC BY-SA 4.0/Wiki Commons
Image Credit: Coolcaesar – CC BY-SA 4.0/Wiki Commons

Disney agreed to a $10 million payment to settle FTC allegations that it allowed personal data to be collected from children who viewed kid-directed videos on YouTube. A judge approved the order in December 2025. The agency’s case page for Disney sets out both the allegation and the amount, and it describes the data collection as occurring on videos aimed at children.

The case shows that the obligation attached to how the videos were labeled and delivered, not only to a company’s own apps. Families should read it as an enforcement outcome of a settlement approved by a court.

8. TikTok: Musical.ly Became TikTok

TikTok — Image Credit: Coolcaesar - CC BY 4.0/Wiki Commons
Image Credit: Coolcaesar – CC BY 4.0/Wiki Commons

The company now known as TikTok agreed to a $5.7 million settlement with the FTC over allegations that it illegally collected personal information from children. The case was brought under the app’s earlier name, Musical.ly, which is why the FTC’s case page carries that name. The agency’s description uses the phrase now known as TikTok to connect the two, and the payment came under the earlier name.

A reader looking for the case under TikTok will find it filed as Musical.ly. The $5.7 million figure belongs to that earlier company.

9. YouTube: Kids’ Channels Penalty

YouTube — Image Credit: Coolcaesar - CC BY-SA 4.0/Wiki Commons
Image Credit: Coolcaesar – CC BY-SA 4.0/Wiki Commons

Google and YouTube agreed to pay a $170 million civil penalty to the Federal Trade Commission and the New York Attorney General. The settlement resolved allegations that the YouTube video sharing service illegally collected personal information from children without their parents’ consent. The children were watching kids’ channels, which places the conduct in child-directed content rather than the platform’s general audience.

The split of the payment between the FTC and the New York Attorney General shows a joint action. For parents, the key term in the allegation is consent, which the agency said was missing.

10. General Motors: Drivers’ Location Data

General Motors — Image Credit: Randall Ferry - CC BY-SA 4.0/Wiki Commons
Image Credit: Randall Ferry – CC BY-SA 4.0/Wiki Commons

General Motors and its OnStar service were handed a five-year ban on disclosing consumers’ sensitive geolocation and driver behavior data to consumer reporting agencies. The agency’s January 2025 release describes the data as drivers’ precise location and driving behavior. Both GM and OnStar are bound by the restriction, so it covers the connected-car service as well as the manufacturer.

For owners of connected cars, the order limits one specific flow, which is sharing with consumer reporting agencies. It is time-limited to five years.

11. Uber: The Undisclosed Breach

Uber — Image Credit: Dllu - CC BY-SA 4.0/Wiki Commons
Image Credit: Dllu – CC BY-SA 4.0/Wiki Commons

Uber accepted an expanded settlement with the FTC over privacy and security claims after failing to disclose a 2016 breach during the agency’s investigation. The agency’s release states that, due to Uber’s misconduct related to the 2016 breach, the company would be subject to additional requirements. Possible civil penalties were part of the expanded arrangement.

The case turns on the disclosure failure during the investigation itself. The release describes additional requirements and possible penalties, with no dollar amount attached.

12. Facebook: Largest Privacy Penalty

Facebook — Image Credit: Austin McKinley - CC BY 3.0/Wiki Commons
Image Credit: Austin McKinley – CC BY 3.0/Wiki Commons

The FTC imposed a $5 billion penalty on Facebook that it described as the largest ever imposed on any company for violating consumers’ privacy. The company also had to rebuild how it oversees privacy decisions, which the release’s title describes as sweeping new privacy restrictions. The figure and the characterization both come from the agency’s July 2019 announcement.

For users, the lasting piece is the oversight structure the order required, not only the amount. The $5 billion total remains the benchmark the FTC itself cites for privacy penalties.


More from Morning Overview