WSGR logoWSGR logo
WSGR logo
  • Experience
  • People
  • Insights
  • About Us
  • Careers

  • Practice Areas
  • Industries

  • Corporate
  • Intellectual Property
  • Litigation
  • Patents and Innovations
  • Regulatory
  • Technology Transactions

  • Capital Markets
  • Corporate Governance
  • Corporate Life Sciences
  • Derivatives
  • Emerging Companies and Venture Capital
  • Employee Benefits and Compensation
  • Energy and Climate Solutions
  • Executive Advisory Program
  • Finance and Structured Finance
  • Fund Formation
  • Greater China
  • Mergers & Acquisitions
  • Private Equity
  • Public Company Representation
  • Real Estate
  • Restructuring
  • Shareholder Engagement and Activism
  • Tax
  • U.S. Expansion
  • Wealthtech

  • Special Purpose Acquisition Companies (SPACs)

  • Environmental, Social, and Governance

  • AI and Data Center Infrastructure
  • Energy Regulation and Competition
  • Project Development and M&A
  • Project Finance and Tax Credit Transactions
  • Sustainability and Decarbonization
  • Transportation Electrification

  • U.S. Expansion Library and Resources

  • Post-Grant Review
  • Trademark and Advertising

  • Antitrust Litigation
  • Arbitration
  • Board and Internal Investigations
  • Class Action Litigation
  • Commercial Litigation
  • Consumer Litigation
  • Corporate Governance Litigation
  • Employment Litigation
  • Executive Branch Updates
  • Government Investigations
  • Internet Strategy and Litigation
  • Patent Litigation
  • Securities Litigation
  • State Attorneys General
  • Supreme Court and Appellate Practice
  • Trade Secret Litigation
  • Trademark and Copyright Litigation
  • Trial
  • White Collar Crime

  • Advertising, Promotions, and Marketing
  • Antitrust and Competition
  • Committee on Foreign Investment in the U.S. (CFIUS)
  • Communications
  • Data, Privacy, and Cybersecurity
  • Export Control and Sanctions
  • FCPA and Anti-Corruption
  • FDA Regulatory, Healthcare, and Consumer Products
  • Federal Trade Commission
  • Fintech and Financial Services
  • Government Contracts
  • National Security and Trade
  • Payments
  • State Attorneys General
  • Strategic Risk and Crisis Management
  • Tariffs, Customs, and Import Compliance

  • Antitrust and Intellectual Property
  • Antitrust Civil Enforcement
  • Antitrust Compliance and Business Strategy
  • Antitrust Criminal Enforcement
  • Antitrust Litigation
  • Antitrust Merger Clearance
  • European Competition Law
  • Third-Party Merger and Non-Merger Antitrust Representation

  • Anti-Money Laundering
  • Foreign Ownership, Control, or Influence (FOCI)
  • Team Telecom

  • AI in Healthcare
  • Animal Health
  • Artificial Intelligence and Machine Learning
  • Aviation
  • Biotech
  • Blockchain and Cryptocurrency
  • Clean Energy
  • Climate and Clean Technologies
  • Communications and Networking
  • Consumer Products and Services
  • Data Storage and Cloud
  • Defense Tech
  • Diagnostics, Life Science Tools, and Deep Tech
  • Digital Health
  • Digital Media and Entertainment
  • Electronic Gaming
  • Fintech and Financial Services
  • FoodTech and AgTech
  • Global Generics
  • Internet
  • Life Sciences
  • Medical Devices
  • Mobile Devices
  • Mobility
  • NewSpace
  • Quantum Computing
  • Semiconductors
  • Software

  • Offices
  • Country Desks
  • Events
  • Community
  • Our Diversity
  • Sustainability
  • Our Values
  • Board of Directors
  • Management Team

  • Austin
  • Boston
  • Boulder
  • Brussels
  • Century City
  • Hong Kong
  • London
  • Los Angeles
  • New York
  • Palo Alto
  • Salt Lake City
  • San Diego
  • San Francisco
  • Seattle
  • Shanghai
  • Washington, D.C.
  • Wilmington, DE

  • Law Students
  • Judicial Clerks
  • Experienced Attorneys
  • Patent Agents
  • Business Professionals
  • Alternative Legal Careers
  • Contact Recruiting
FTC Outlines Potential Changes to Enhance Privacy and Security Enforcement Efforts If Given More Resources
Alerts
July 1, 2020

On June 19, 2020, the Federal Trade Commission (FTC) submitted to Congress two reports that Congress requested in connection with the spending bill that funds the FTC. One of these reports (the "Resources Report") describes the resources used and needed by the FTC to protect consumer privacy and security, and the second (the "Authorities Report") describes the FTC's use of its existing authorities to protect consumer privacy and security.

The Resources Report states that while the FTC has used its "existing resources effectively, and [has] brought more cases, and obtained larger fines, than any other privacy enforcement agency in the world," with additional resources, the FTC "could better ensure that American consumers' privacy is adequately protected." The Resources Report describes specific structural changes the FTC would consider if given such resources. If enacted, these changes would significantly increase the agency's enforcement activity in the privacy and data security areas.

According to the Resources Report, the FTC's data privacy and security efforts are largely handled by 40-45 employees in its Division of Privacy and Identity Protection. In comparison, the U.K. Information Commissioner's Office has 700 employees, and the Irish Data Protection Commissioner has about 180 employees. The FTC states in the Resources Report that it should have "a more comparable number of employees [to these agencies]" given it is the federal entity primarily responsible for protecting consumers' privacy and data security.

The Resources Report notes that, even with its comparatively low number of employees, the FTC has utilized its current resources effectively. The FTC has brought over 633 privacy and security related cases, with billions of dollars ordered in monetary relief and civil penalties. However, the FTC states that its efforts could be enhanced by the creation of at least three separate additional units with the following responsibilities:

First, the FTC would create one or more units to expand its ability to launch new investigations. These units would: (1) investigate more online services for Children's Online Privacy Protection Rule (COPPA) violations; (2) investigate new technologies that have the potential to result in substantial consumer harm, such as biometrics and artificial intelligence; (3) devote additional staff to enforcement involving the collection, use, and disclosure of sensitive data; and (4) continue to take on larger, more complex investigations that may lead to litigation.

Second, one or more units would devote additional resources to order enforcement. The FTC would expand the staff that can conduct compliance reviews of existing privacy and data security orders, building upon resources from the existing Enforcement Division.

Third, one or more units would focus on policy, case generation, and targeting. Among other things, this unit would monitor markets for new risks to consumers, review referrals from privacy and security researchers, and serve as a hub for technical and market expertise as needed on cases. With additional resources, the FTC could also conduct extensive industry studies pursuant to its authority under Section 6(b) of the FTC Act, similar to its past studies regarding mobile device manufacturers and the data broker industry.

Commissioner Chopra issued a separate statement accompanying the reports suggesting, among other things, that the FTC use its existing authority and resources more effectively, that the FTC apply the same hard line standards to large firms that it applies to small firms, cooperate more with state attorneys general, and conduct more industry-wide studies. Chairman Simons and Commissioners Phillips and Wilson issued a separate statement countering Commissioner Chopra's arguments but agreeing that "with more authority and more resources, [the FTC] could do more." The dueling separate statements reflect ongoing division among the Commissioners regarding appropriate relief and penalties in privacy and security cases.

The separate Authorities Report outlines the FTC's authority under the FTC Act (specifically focusing on Section 5), discusses the FTC's other work to deter unfair and deceptive conduct in privacy and data security matters, and concludes by discussing challenges to and limitations on its authority, such as F.T.C. v. Credit Bureau Center, LLC, 937 F.3d 764 (7th Cir. 2019) (holding section 13(b) does not authorize restitution).

Wilson Sonsini Goodrich & Rosati routinely advises clients on investigatory, compliance, and novel privacy issues and will closely monitor any changes to the FTC's structure or priorities, and any rulemaking actions it conducts. For more information, please contact Lydia Parnes, Chris Olsen, or another member of the firm's privacy and cybersecurity practice.

 

Contributors

  • Christopher N. Olsen
  • people
  • insights
  • about us
  • careers
  • Binder
  • Alumni
  • Mailing List Signup
  • Client FTP Portal
  • Privacy Policy
  • Terms of Use
  • Accessibility
WSGR logo
Twitter
LinkedIn
Facebook
Instagram
Youtube
Copyright © 2026 Wilson Sonsini Goodrich & Rosati. All Rights Reserved.