FTC Section 5 Unfair and Deceptive Practices Guide for SaaS (2025): Dark Patterns, Click-to-Cancel Rule, Data Security Enforcement, COPPA, and Multi-Regulator Coordination
FTC Section 5 is the most broad-reaching US consumer protection law — covering subscription dark patterns, data security failures, and children's privacy violations. The 2024 click-to-cancel Negative Option Rule and COPPA enforcement have produced penalties exceeding $500M in the last two years. SaaS and fintech companies face parallel FTC/CFPB/state AG jurisdiction that requires a coordinated compliance strategy.
Click-to-Cancel Rule Effective January 15, 2025: The FTC's updated Negative Option Marketing Rule requires online cancellation to be available for any subscription enrolled online — with no more burdensome steps than enrollment. Companies that require phone calls, emails, or multi-step retention flows to cancel online subscriptions are in violation as of January 2025.
FTC Enforcement Actions: Selected Penalties and Findings
| Company | Year | Penalty | Type | Key Finding |
|---|---|---|---|---|
| Epic Games (Fortnite) | 2023 | $520M total | COPPA ($275M) + Dark Patterns ($245M) | Default voice chat for child users; dark pattern subscription enrollment; difficult cancellation |
| YouTube / Google | 2019 | $170M | COPPA | Persistent identifier (cookie) tracking on child-directed channels used for ad targeting without parental consent |
| Amazon Prime | 2023 | $25M + injunction | Dark Patterns / Deception | "Iliad Flow" cancellation dark pattern; nag screens; misleading enrollment design |
| Vonage | 2022 | $100M | Dark Patterns / Unfair | Cancellation required call to specific number; lengthy retention holds; cancellation obstruction |
| TikTok (Musical.ly) | 2019 | $5.7M | COPPA | Collecting personal information from children under 13 without parental consent; largest COPPA penalty at time |
| Drizly + CEO personally | 2022 | Injunction + personal liability | Data Security (Section 5) | 2.5M consumer data breach; personal consent order against CEO extending to future companies |
| CafePress | 2022 | $500K civil penalty | Data Security + Deception | Breach of 23M+ consumers; misleading privacy policy claims about data security |
| Wyndham Worldwide | 2015 | Consent order + 20-yr audit | Data Security (Section 5) | Plain-text payment card storage; no firewalls; unpatched systems; landmark case establishing FTC security enforcement authority |
Contract Risk — $97
Scan Your Terms of Service, Subscription Agreement, or Privacy Policy for FTC Compliance
Upload your subscription agreement, terms of service, or privacy policy. BizLegal AI reviews for FTC Section 5 deception risks (material omissions, misleading claims), Negative Option Rule compliance (recurring charge disclosure, express consent, cancellation mechanism), dark pattern risk in subscription enrollment language, COPPA trigger analysis (child-directed content, actual knowledge provisions), data security representation vs actual practice gap (Section 5 deception risk), and CFPB UDAAP exposure for fintech subscription products.
Scan Your Terms or Subscription Agreement →Frequently Asked Questions
What is the FTC's Section 5 authority, and what are the legal standards for "unfair" vs "deceptive" practices?
Section 5 of the Federal Trade Commission Act (15 U.S.C. § 45) prohibits "unfair or deceptive acts or practices in or affecting commerce." The FTC enforces Section 5 against virtually all US businesses — including SaaS companies, fintech startups, mobile apps, data brokers, and online marketplaces. The FTC can bring administrative proceedings (before its own Administrative Law Judges) or federal court actions seeking injunctions, disgorgement, and civil penalties. The two distinct legal standards under Section 5: Standard 1 — Unfair Practices: a practice is "unfair" under Section 5 if it: (a) Causes or is likely to cause substantial injury to consumers: the harm must be real, significant, and not trivial. Financial harm, privacy harm (exposure of sensitive data), health/safety harm, and harm to vulnerable populations all qualify. The harm does not need to have occurred yet — likely future harm is sufficient. (b) Is not outweighed by countervailing benefits to consumers or competition: the FTC weighs the consumer harm against any legitimate business benefits. A practice that harms some consumers but provides significant competitive or economic benefits may not be unfair. (c) Is not reasonably avoidable by consumers themselves: consumers who could have easily discovered and avoided the harm (with information they were given or could readily obtain) cannot claim protection. Information asymmetry — where the company knows the harm risk but the consumer doesn't — is central to the unfairness analysis. The FTC codified these three elements in its 1980 Policy Statement on Unfairness and FTCA Section 5(n) (added by the FTC Act Amendments of 1994). Standard 2 — Deceptive Practices: a practice is "deceptive" under Section 5 if: (a) There is a representation, omission, or practice: can be an express claim, an implied claim, or a material omission that misleads consumers. (b) That is likely to mislead consumers acting reasonably under the circumstances: the FTC applies a "reasonable consumer" standard — what would a typical member of the target population understand from the representation or omission? For vulnerable or unsophisticated consumers (elderly, children, non-English speakers), the standard is adjusted to that population. (c) That is material: the representation or omission is likely to affect consumers' choices or conduct regarding the product or service. Materiality is presumed for express claims, for health and safety claims, and for statements about price. The FTC does NOT need to prove actual harm for a deception case — likelihood of misleading a reasonable consumer is sufficient. The FTC also does not need to prove intent — deception is evaluated by effect on consumers, not the company's state of mind. Enforcement authority and remedies: administrative proceedings: the FTC issues a complaint, an ALJ hears the case, and the Commission issues an order. Violation of a Commission order carries civil penalties of up to $51,744 per day per violation (adjusted annually). Federal court (Section 13(b) — now limited): the Supreme Court's AMG Capital Management decision (2021) held that the FTC cannot seek permanent injunctions and equitable monetary relief (disgorgement) under Section 13(b) in the same proceeding. Congress responded with the FTC Act Amendments of 2022 restoring some monetary relief authority, but Section 13(b) enforcement is now more limited than pre-AMG. Section 19 (post-rule violations): the FTC can seek consumer redress in federal court for violations of Trade Regulation Rules (see the Negative Option Rule below). Civil penalties under Section 19: up to $51,744 per day per violation. State AG enforcement: many state unfair and deceptive acts and practices (UDAP) statutes parallel Section 5 and allow state AG enforcement — 50 "mini-FTC Acts" creating concurrent enforcement jurisdiction.
What are "dark patterns," and how has the FTC enforced against them in SaaS and subscription contexts?
Dark patterns are user interface design choices that manipulate consumers into decisions they didn't intend to make or that are contrary to their interests. The FTC issued its "Bringing Dark Patterns to Light" report in September 2022, identifying the most common dark patterns and signaling aggressive enforcement. The FTC's taxonomy of dark patterns in the 2022 report: (1) Misleading subscription enrollment: enrolling consumers in subscriptions without adequate disclosure of recurring charges; burying subscription terms in fine print; making subscriptions appear to be one-time purchases; automatically converting free trials to paid subscriptions without clear, prominent disclosure before the trial ends. (2) Disguised ads: formatting advertisements to look like organic search results, news articles, or editorial content without clear disclosure that they are paid promotions. Native advertising that is not labeled as advertising. (3) Difficult-to-cancel subscriptions ("roach motel"): making it easy to subscribe but difficult or impossible to cancel. For example: requiring consumers to call a phone number during limited hours to cancel an online subscription; burying cancellation procedures in FAQs or support pages; multiple-step cancellation flows with "are you sure?" screens; save offers that delay cancellation rather than accepting it. (4) Hidden costs: not disclosing all costs until checkout (drip pricing); fees revealed only at the last step of checkout after the consumer has invested time. (5) False urgency / scarcity: countdown timers that reset; false claims of limited availability; "only 2 left" claims that are inaccurate. (6) Trick questions: confusing double-negative opt-out language ("Uncheck to not receive marketing emails"); pre-checked boxes for opt-ins that consumers don't notice. (7) Interface interference: making the "accept" button visually prominent and the "decline" button gray, tiny, or hidden. Notable FTC dark patterns enforcement actions: FTC v. Vonage (2022): $100M settlement for making it difficult to cancel internet services. Vonage required consumers to call a specific cancellation number and subjected them to lengthy retention calls — a classic dark pattern. FTC v. Amazon Prime (2023): the FTC sued Amazon alleging that Amazon used dark patterns to enroll consumers in Prime without their consent (Nag screens, confusing checkout design, confusing cancellation process called "Iliad Flow" internally). Amazon settled for $25M. FTC v. X (formerly Twitter) — Blue verification (2023): FTC investigation into Twitter's relaunch of Blue verification after Elon Musk's acquisition, alleging deceptive practices in how the blue checkmark was represented to consumers after previously being used to indicate authentic, verified accounts. FTC complaint filings related to loot boxes and in-app purchases: multiple warning letters to app developers about dark patterns in children's games that obscure the cost of in-app purchases using virtual currency. Requirements for compliant subscription disclosure: (a) Full disclosure before enrollment: all material terms of the subscription (duration, price, auto-renewal, how to cancel) must be disclosed clearly and conspicuously before the consumer is charged; (b) Express informed consent: separate affirmative consent to the subscription terms (pre-checked boxes are NOT acceptable); (c) Easy cancellation: the cancellation mechanism must be as simple as the enrollment mechanism ("click to cancel" if subscription was sold online); (d) Pre-charge reminder: for free trials, send an email reminder before the trial expires; include the subscription price, auto-renewal date, and cancellation instructions.
What does the FTC's Negative Option Marketing Rule (click-to-cancel rule) require, and when does it apply?
The FTC's Negative Option Marketing Rule (16 CFR Part 425), known as the "click-to-cancel" rule, was substantially updated and finalized in November 2024 (effective January 15, 2025 for most provisions). This rule creates specific, binding requirements for subscription, auto-renewal, free-trial-to-paid, and membership plan arrangements. The rule applies when a seller uses a "negative option feature" — defined as any arrangement where: the consumer's silence or failure to take affirmative action is treated as agreement to be charged for goods or services on a recurring basis; OR an initial charge is disclosed but a subsequent, automatic charge is not (auto-renewal). Scope: the rule applies to both B2C and B2B transactions (businesses that sell subscriptions to other businesses are covered). It applies to sales online, by phone, by mail, and in person. SaaS companies with recurring subscriptions (monthly, annual), usage-based billing that auto-renews, free trial periods that convert to paid subscriptions, and freemium plans with automatic upgrades are all covered. The four core requirements of the updated Negative Option Rule: (1) Clear and Conspicuous Disclosure Before Consent: before obtaining the consumer's billing information or enrolling them in a negative option program, the seller must disclose ALL material terms: the amount to be charged and when (or how the amount is determined for usage-based billing); the deadline to prevent a charge; how to cancel; when and how the consumer will be notified of any changes to the subscription. The disclosure must appear immediately adjacent to (or in the same visual field as) the consent mechanism. It may NOT appear only in the terms of service or in a hyperlink. (2) Express Informed Consent: the seller must obtain express, informed consent to the negative option feature — separate from consent to other terms. For online sales: a separate checkbox that the consumer affirmatively clicks to acknowledge the recurring charge (pre-checked boxes prohibited). The consent record (timestamp, IP, consent language shown, checkbox status) must be maintained for evidence. (3) Simple Mechanism to Cancel: the cancellation mechanism must be at least as simple as the enrollment mechanism. Online enrollment → online cancellation option required. If the consumer enrolled online, they must be able to cancel online — the company may NOT require the consumer to call a number, send a letter, or perform any action more burdensome than the enrollment process. The company may show a single "save" offer (a retention offer) during the cancellation process — but may not show multiple screens, cause delays, or use dark patterns to frustrate cancellation. (4) Annual Reminder for Negative Option Plans: for negative option programs where the consumer incurs no charge for more than 12 months, the seller must send an annual reminder notification disclosing the existence of the plan and how to cancel. Violations and penalties: the Negative Option Rule is a Trade Regulation Rule — violations are actionable under FTC Act Section 19. Civil penalties: up to $51,744 per violation per day. The "per violation" count for a subscription company with thousands of non-compliant enrollments could result in massive aggregate penalties. The FTC does not need to prove consumer harm — violation of the rule itself is sufficient for penalty. SaaS implementation checklist for Negative Option Rule compliance: (a) At checkout: disclose subscription terms in a box/panel adjacent to the "Subscribe" button, not just in the linked terms of service; (b) Pre-checked boxes: remove all pre-checked subscription boxes; (c) Cancellation flow: offer a "Cancel Subscription" button within the product UI; maximum of one "save" offer screen before accepting cancellation; (d) Free trial disclosure: send an email with the conversion date, subscription price, and cancel link before the trial ends; (e) Record retention: maintain consent records with timestamp and exact disclosure text shown; (f) Annual reminders: for any plan where billing cycles exceed 12 months, implement annual notification system.
How does the FTC use Section 5 to enforce data security requirements, and what counts as a Section 5 data security violation?
The FTC has enforced data security requirements against companies under Section 5 since its first major case against Guess apparel in 2003. The FTC's theory is straightforward: a company that promises to protect consumer data (in a privacy policy, marketing claims, or user agreement) but fails to implement reasonable security practices makes a material misrepresentation (deception); and failing to implement reasonable security for sensitive data causes substantial, unavoidable consumer harm (unfairness). The FTC's data security jurisprudence has produced a de facto set of reasonable security requirements through consent decrees. The FTC Safeguards Rule (16 CFR Part 314) — for financial institutions: the FTC enforces its Safeguards Rule under the Gramm-Leach-Bliley Act (GLBA) against financial institutions (banks, credit unions, auto dealers, payday lenders, and any other entities engaged in financial activities). The Safeguards Rule was substantially updated effective June 9, 2023 (with the multi-factor authentication requirement deferred to June 2023). The Safeguards Rule requires: (a) Designation of a qualified individual responsible for the information security program; (b) Written information security program (WISP); (c) Risk assessment covering all areas that handle customer information; (d) Safeguards based on the risk assessment — access controls, encryption, secure development, authentication, physical security, change management; (e) Multi-factor authentication for any individual accessing customer information; (f) Encryption of customer information in transit and at rest; (g) Continuous monitoring or penetration testing (annual pen testing + quarterly vulnerability scanning); (h) Security awareness training; (i) Incident response plan; (j) Annual reporting to the Board. The FTC Health Breach Notification Rule (16 CFR Part 318): health apps and personal health record companies not covered by HIPAA are subject to the FTC Health Breach Notification Rule. In May 2021, the FTC issued a Policy Statement clarifying that health apps (period trackers, fitness apps, mental health apps) must comply with the rule. Notification required: within 60 days of discovering a breach, notify affected individuals, the FTC, and (for breaches >500 individuals in one state) prominent media. Section 5 data security enforcement actions — pattern of what the FTC requires: (1) Wyndham Worldwide (2015): first Section 5 case where the FTC successfully defended its authority to bring data security cases as Section 5 violations. The Third Circuit upheld the FTC's authority. Wyndham failed to use firewalls, stored payment card data in plain text, and failed to patch known vulnerabilities. The FTC required Wyndham to establish a comprehensive information security program and submit to biennial third-party audits for 20 years. (2) LabMD (2016): the FTC sued a medical testing company for unreasonable data security — a file containing over 9,000 patients' insurance information was found on a peer-to-peer file sharing network. The Eleventh Circuit's LabMD decision narrowed Section 5 unfairness for data security (requiring the injury to be real, not just speculative exposure), but the FTC continues to use Section 5 for data security enforcement. (3) Drizly / James Corcoran (2022): the FTC sued Drizly and its CEO personally for failing to secure 2.5 million consumers' personal information despite internal warnings. The consent order required Drizly to minimize data collection and imposed obligations on the CEO personally in any future company he leads (an unprecedented extension of personal liability). (4) CafePress (2022): $500,000 civil penalty for a data breach affecting over 23 million consumers and for making misleading statements about data security in the privacy policy. Practical Section 5 data security minimum requirements derived from FTC consent decrees: (a) Written information security program with identified responsible personnel; (b) Risk assessment covering all personal data systems and assets; (c) Access controls: least privilege, unique user IDs, multi-factor authentication for sensitive systems; (d) Encryption: sensitive data encrypted at rest and in transit; (e) Patch management: timely patching of known vulnerabilities; (f) Vulnerability scanning and penetration testing; (g) Incident response plan with designated response team; (h) Security awareness training for all personnel; (i) Data minimization: only collect and retain data that is necessary for legitimate business purposes; (j) Third-party audits: regular third-party security assessments for high-risk categories.
What does COPPA require for apps and websites that collect personal information from children under 13?
The Children's Online Privacy Protection Act (COPPA), enacted in 1998 and implemented by 16 CFR Part 312, applies to operators of commercial websites and online services — including mobile apps — that are directed to children under 13 OR have actual knowledge they are collecting personal information from children under 13. COPPA is enforced by the FTC, and violations carry civil penalties of up to $51,744 per violation per day. The 2024 proposed COPPA 2.0 rule update would significantly expand COPPA protections — see below. Who must comply: (1) Operators of websites and online services "directed to children" — the FTC uses multiple factors to determine if a site is directed to children: subject matter, visual or audio content, use of animated characters, celebrities appealing to children, activities or incentives appealing to children, age of models, language. (2) General audience services that have "actual knowledge" they are collecting personal information from children under 13 — even if the site is not specifically directed to children, if the operator knows (from user self-identification, use of third-party age verification data, or other means) that a user is under 13, COPPA applies to that user's data. The "actual knowledge" standard means: if your age gate captures ages and a user provides a date of birth indicating they are under 13, you have actual knowledge. If you receive a government letter or complaint identifying child users, you have actual knowledge. COPPA requirements: (1) Privacy notice: publish a clear and comprehensive privacy policy explaining what personal information is collected from children, why, and how it is used or shared. The policy must be on the service homepage AND in any area where personal information is collected. (2) Parental consent before collection: before collecting personal information from children under 13, the operator must: (a) Provide direct notice to the parent (email notice at minimum); (b) Obtain verifiable parental consent (VPC) using a verifiable method such as a signed consent form submitted by postal mail, fax, or scan; a credit card transaction combined with additional steps; a toll-free phone number; or video conference with trained personnel. (3) What constitutes "personal information" under COPPA (16 CFR § 312.2): full name, home/physical address, online contact information (email, IM, social media handle), screen name or user name that functions as online contact information, telephone number, Social Security number, persistent identifier (cookie ID, device ID, IP address — if used to recognize the user over time or across sites), photo/video/audio file that contains a child's image or voice, geolocation information sufficient to identify street name and city/town, and any other information about the child or parent combined with the above. (4) Right of parental access, correction, and deletion: parents have the right to review personal information collected from their child, request corrections, request deletion, and refuse ongoing collection even if they previously consented. (5) Data security: operators must establish and maintain reasonable procedures to protect personal information collected from children. (6) Retention limitation: keep personal information only as long as necessary for the purpose collected. (7) Prohibition on conditioning participation on providing more information than necessary. FTC COPPA enforcement actions (selected): (a) TikTok (Musical.ly) (2019): $5.7M civil penalty — the largest COPPA penalty at the time — for collecting personal information from children under 13 without parental consent. The app had millions of accounts of children who lied about their age. (b) YouTube / Google (2019): $170M civil penalty (largest COPPA penalty to date) for collecting persistent identifiers (cookies) on child-directed channels and using them for ad targeting without parental consent. Post-settlement, YouTube implemented a "made for kids" content designation system. (c) Epic Games / Fortnite (2023): $275M civil penalty for COPPA violations including default-on voice chat for child users, social features allowing children to be contacted by adults, and collection of child personal information without parental consent. Epic simultaneously paid $245M to settle FTC dark patterns charges. Total Epic settlement: $520M — the largest FTC privacy/dark patterns settlement. Proposed COPPA 2.0 rule update (FTC NPRM, January 2024): the FTC proposed significant COPPA amendments that would: (a) Restrict ed-tech companies from monetizing children's data collected for school purposes; (b) Expand the definition of "personal information" to explicitly include biometrics; (c) Add a "right to deletion" resembling CCPA for children's data; (d) Require targeted advertising opt-in consent for teens 13-16; (e) Expand parental consent to require a "central parental consent hub" where parents can manage child data across multiple services. As of July 2026, the COPPA 2.0 final rule has not been published.
How do FTC enforcement priorities interact with CCPA, CFPB, and state AG enforcement for fintech and SaaS companies?
Fintech and SaaS companies operate in an overlapping multi-regulator enforcement environment where a single practice can trigger simultaneous enforcement actions from federal (FTC, CFPB, SEC, FinCEN) and state (state AG, state banking regulators) authorities. Understanding the multi-regulator landscape helps companies prioritize compliance investments and respond appropriately to enforcement investigations. FTC vs CFPB — jurisdiction carve-out: the Dodd-Frank Act (2010) transferred FTC jurisdiction over banks, savings associations, and federal credit unions to the CFPB. However, the FTC retains concurrent jurisdiction over non-bank financial companies (fintech startups, payday lenders, debt collectors, credit reporting agencies, companies selling financial products online). Result: most fintech companies (non-bank) are subject to BOTH FTC Section 5 AND CFPB enforcement under UDAAP (Unfair, Deceptive, or Abusive Acts and Practices). The CFPB's UDAAP authority differs from the FTC's Section 5 in one critical respect: the CFPB can pursue "abusive" practices — practices that materially interfere with a consumer's ability to understand a term or condition, or that take unreasonable advantage of consumer lack of understanding, inability to protect their own interests, or reliance on the company to act in their interests. "Abusive" is a broader standard than unfair or deceptive and has been increasingly used by the CFPB in its enforcement. Example of an "abusive" practice: a lending app that shows a low headline APR but buries total cost of credit in confusing disclosures takes advantage of consumers' limited understanding of APR calculations — potentially "abusive" even if technically disclosed somewhere in the terms. FTC vs state AG: state UDAP statutes allow state AGs to bring independent enforcement actions that parallel FTC Section 5. Many state AGs coordinate with the FTC (particularly California, New York, and Illinois), and some enforcement actions are joint FTC-state AG settlements. California: the CPPA enforces CCPA/CPRA but also coordinates with the California AG's UDAP authority under Business & Professions Code § 17200. New York: NY Consumer Protection Act (General Business Law § 349) is frequently used by the NY AG for dark patterns, subscription traps, and data security enforcement. Illinois: the Biometric Information Privacy Act (BIPA) is enforced by private right of action (not the AG) for biometric data — including face recognition, fingerprint time clocks, and voice analysis. FTC-CFPB-state AG coordination in practice: the Consumer Financial Protection Bureau, FTC, and state AGs have formal coordination mechanisms. Joint enforcement investigations have targeted: subscription trap practices (FTC lead with state AGs as co-plaintiffs); data broker practices (FTC with state AGs); payday lending (CFPB primary, state AG secondary); consumer credit advertising (CFPB + state AGs). When a SaaS or fintech company receives an FTC Civil Investigative Demand (CID): a CID is the FTC's investigative tool (equivalent to a subpoena) demanding documents and information in an FTC investigation. A CID does not mean a company is being sued — it may be a market study or a preliminary investigation. Response obligations: a CID has the force of law; failure to respond or producing incomplete/inaccurate responses can itself become the basis for FTC action. Immediate steps when a CID arrives: (a) engage specialized FTC regulatory counsel (not general commercial counsel); (b) implement a legal hold for all documents potentially responsive to the CID; (c) do not destroy, alter, or conceal any documents related to the investigation; (d) conduct an internal investigation to understand the scope of the practices being investigated; (e) assess parallel exposure (CFPB, state AG, SEC, state AG) so counsel can coordinate response strategy. Key coordination point: if the FTC, CFPB, and one or more state AGs are conducting simultaneous investigations (which is common in major enforcement targets), any statements or representations made in one proceeding can be used in others. A unified response strategy coordinated across all proceedings is essential.