FTC Whistleblower Act Would Reward and Protect Whistleblowing About Data Privacy Misconduct and Other Deceptive Practices

Earlier this week, Representatives Jan Schakowsky and Lori Trahan (D-MA) launched the FTC Whistleblower Act of 2021 (FTCWA), which might reward and shield disclosures about potential or suspected violations of any legislation, rule, or regulation enforced by the Federal Commerce Fee (FTC or Fee).  Modeled on the profitable SEC whistleblower reward program, the FTCWA (HR 6093) may supercharge FTC enforcement of legal guidelines that prohibit fraud, deception and unfair enterprise practices.

And an FTC whistleblower reward program may spur whistleblowers at social media and know-how corporations to reveal information privateness and safety practices that hurt shoppers.  As demonstrated by the success of comparable laws rewarding whistleblowing about varied varieties of fraud, providing monetary incentives to encourage potential whistleblowers to take the numerous threat of coming ahead would considerably improve the FTC’s means to detect and fight misleading commerce practices.

Violations that May Qualify for a Whistleblower Award (FTC Enforcement Authority)

The U.S. lacks complete normal privateness and information safety laws.  In some ways this limits the FTC’s means to handle dangerous practices.  Nonetheless, by way of a patchwork of statutory authority, the Fee has surprisingly broad means to handle privateness and information safety considerations.  This expansive scope is sweet information for whistleblowers as a result of the proposed invoice’s protections and incentives would solid a correspondingly large internet.

The FTC has relied on its authority below the FTC Act and narrower particular statutes to cease and remediate privateness and information safety violations.  Part 5 of the FTC Act supplies the first authorized authority for the Fee to manage privateness and information safety.  Part 5 prohibits “deceptive” or “unfair” business acts or practices.  A illustration, omission, or apply is misleading whether it is materials and prone to mislead shoppers appearing fairly.  An act or apply is unfair if (1) it causes or is prone to trigger substantial harm, (2) shoppers can’t fairly keep away from the harm, and (3) advantages to shoppers or competitors don’t outweigh the harm.

Along with the FTC Act, the Fee enforces quite a lot of legal guidelines that shield particular features of privateness, together with the Gramm-Leach-Bliley Act (“GLB”), which protects the privateness of monetary info; the CAN-SPAM Act, which permits shoppers to decide out of receiving business electronic mail messages; the Kids’s On-line Privacy Safety Act (“COPPA”), which protects the net privateness of kids below 13; the Honest Credit score Reporting Act (“FCRA”), which protects the privateness of shopper report info; the Honest Debt Assortment Practices Act, which protects shoppers from harassment by debt collectors; and the Telemarketing and Client Fraud and Abuse Prevention Act, below which the FTC applied the Do Not Name registry.

Understanding the Fee’s jurisdiction is just step one for analyzing whether or not reporting misconduct would result in an award below the invoice.  The FTC’s means to fight privateness and information safety violations is kind of restricted.  First, although Part 5 of the FTC Act offers the Fee its broadest authorized authority to prosecute violations, the legislation’s treatments are restricted.  In AMG Capital Mgmt., LLC v. FTC, the U.S. Supreme Court docket dominated that the FTC Act doesn’t allow the Fee to acquire financial reduction in federal courtroom.  AMG Capital Mgmt., LLC v. FTC, 141 S. Ct. 1341 (2021).  Accordingly, the FTC misplaced its most essential software for recouping cash for individuals who suffered losses due to misleading, unfair, or anticompetitive conduct.

Furthermore, the FTC at present lacks satisfactory sources to totally pursue its enforcement priorities regarding privateness and information safety misconduct.  By means of comparability, the FTC’s Division of Privacy and Identification Safety has solely about 40-45 staff, whereas the U.Ok. Data Commissioner’s workplace has about 768 staff, and the Irish Data Safety Commissioner has about 150 staff.  The Fee estimates that it will want an extra 100 full-time staff to satisfy its enforcement priorities.

Within the meantime, the FTC just lately has targeted on a subset of its priorities.  This contains addressing 1) privateness considerations which may be heightened by the pandemic, and 2) applied sciences or varieties of information that would exacerbate racial inequities. For instance, throughout 2021, the FTC has addressed points the pandemic has dropped at the forefront, together with elevated use of well being apps; accuracy of information used for housing, employment, and credit score; and videoconferencing and schooling know-how.

Moreover, the Fee has collected analysis on racial fairness points, issued enterprise steerage on synthetic intelligence and algorithms, introduced enforcement actions associated to facial recognition and credit score discrimination, and applied the FTC’s Each Neighborhood Initiative.  The Each Neighborhood Initiative examines shopper safety points and the impression of illegal privateness practices on distinct teams, together with Black Individuals, Latinos, Asian Individuals, Native Individuals, older adults, navy service members and veterans, and different teams.

Regardless of the authorized and sensible limitations, whistleblowers have cause to be optimistic that they will help the Fee fulfill its aggressive agenda.  Along with the foregoing points, the FTC goals to: 1) higher combine its privateness and information safety efforts with its mission to advertise competitors, 2) enhance treatments for shoppers, 3) concentrate on digital platforms, and 4) broaden the Fee’s understanding of algorithms.

One of many FTC’s priorities is to raised combine its privateness and information safety efforts with its objective of selling competitors.  Many corporations have develop into gamers in digital markets by advantage of their entry to and management over consumer information. The FTC goals to make sure that it views issues elevating in digital markets by way of a twin lens that addresses each privateness and competitors considerations. For instance, market energy might allow shopper safety violations that in flip lower competitors.  Likewise, corporations might achieve market share by way of misleading reassurances on privateness.  As well as, the FTC desires to use competition-based treatments in shopper safety instances.  (See the Everalbum, Inc., enforcement motion beneath for example of how these ideas might apply in motion.)

One other Fee precedence is to enhance shopper treatments.  In pursuit of its targets to supply reduction for shoppers and deter unfair or misleading privateness and safety practices, the FTC is concentrated on increasing the next varieties of treatments: 1) offering discover to harmed shoppers (see the Flo Well being, Inc., enforcement motion beneath); 2) recovering cash for harmed shoppers (see the Vivint Good House, Inc.; Equifax; and Fb enforcement actions beneath); 3) acquiring non-monetary treatments for shoppers (see the Vivint motion); and 4) stopping corporations from benefitting from illegally collected information (see the Everalbum motion).

Third, the Fee intends to extend its concentrate on the info practices of dominant digital platforms, in order that the company can leverage its restricted sources to redress probably the most egregious practices and have a broader impression.  The FTC sees an elevated concentrate on order enforcement as integral to this objective.  The Fee already has many massive corporations below order for privateness and/or information safety violations, together with Fb, Google, Twitter, Microsoft, and Uber.  The desires its orders to have credibility, disincentivize misconduct, and enhance practices throughout the market.  To perform that objective, the Fee plans to shift sources to order compliance and enforcement, particularly in opposition to massive corporations.

Lastly, the FTC has a selected curiosity in higher understanding algorithms and the patron safety and competitors dangers related to them.  For instance, the FTC Act’s prohibition on unfair or misleading practices contains the sale or use of racially biased algorithms. If an algorithm’s developer guarantees that its product will present unbiased outcomes, however actually it doesn’t, that might be a misleading apply.  Equally, if the usage of a biased algorithm discriminates in opposition to shoppers, inflicting them substantial harm that isn’t fairly avoidable and not outweighed by countervailing advantages – the FTC may problem that use as unfair.

Maybe one of the best ways to grasp these enforcement priorities is to take a look at how the Fee has utilized them in apply.  The next record highlights a few of the FTC’s latest notable privateness and information safety enforcement actions.

  • In Might 2021, the Fee settled its enforcement motion in opposition to Everalbum, Inc., the developer of the photograph storage and group app, Ever. Within the Matter of Everalbum, Inc., FTC File No. 1923172 (2021).  The Fee alleged that the corporate violated the FTC Act by deceiving customers about how it will apply facial recognition know-how to the pictures collected from customers.  The consent order resolving the allegations required the corporate to delete any facial recognition fashions or algorithms it developed with Ever customers’ pictures or movies.  This treatment demonstrates the FTC’s emphasis on not solely stopping unlawful conduct, but additionally prohibiting violators from gaining a aggressive benefit from unlawfully collected information.

  • In June 2021, the FTC resolved its first privacy-related well being app case in opposition to Flo Well being, Inc. Within the Matter of Flo Well being, Inc., FTC File No. 1923133 (2021).  The Fee alleged that, in violation of its guarantees to customers, the corporate disclosed well being information from thousands and thousands of customers of its Flo Interval & Ovulation Tracker app to 3rd events comparable to Fb and Google.  Along with different necessities, the settlement required Flo Well being to inform affected customers concerning the disclosure of their private info.  The FTC emphasised this treatment on the premise that it allowed these customers to determine whether or not to nonetheless use or suggest Flo Well being’s providers in gentle of its actions.  The Fee reasoned that this was a elementary fairness subject as a result of these affected by an organization’s illegal conduct have a proper to find out about it, however many individuals won’t hear about an FTC motion in opposition to an organization they take care of until the corporate tells them.

  • In April 2021, the FTC resolved a federal motion in opposition to Vivint Good House, Inc., that alleged that in some situations shoppers’ credit score info was utilized by Vivint gross sales representatives with out their data or consent to qualify one other particular person for financing for Vivint’s merchandise and providers. S. v. Vivint Good House, Inc., Civil Motion No. 2:21-cv-00267-TS (D. Utah 2021).  Based on the grievance, if prospects certified utilizing these techniques later defaulted on their loans, Vivint referred the harmless third get together to its debt purchaser, doubtlessly harming that shopper’s credit score and subjecting them to debt collectors.  Vivint agreed to pay $20 million to settle the costs, together with a $5 million redress fund for shoppers who didn’t join Vivint’s providers however had been contacted by debt collectors or discovered Vivint accounts improperly listed on their credit score studies.  As well as, the settlement required Vivint to ascertain a customer support activity power to confirm that accounts belong to the precise buyer earlier than referring any account to a debt collector, and to help shoppers who had been improperly referred to debt collectors.

  • In July 2019, the FTC settled allegations that Equifax, Inc., a credit score reporting firm, didn’t take cheap steps to safe its community leading to a 2017 information breach that affected roughly 147 million individuals. In its complaint, the FTC alleged that Equifax’s failure uncovered thousands and thousands of names and dates of delivery, Social Safety numbers, bodily addresses, and different private info that would result in identification theft and fraud.  Equifax Inc. agreed to pay at the least $575 million, and doubtlessly as much as $700 million.  Notably, the Fee supplemented its authority by partnering with different companies and states to get a refund to shoppers, and the FTC has said that such partnerships will proceed to be an particularly essential a part of its enforcement efforts.  This demonstrates that regardless of the AMG determination, the Fee nonetheless has instruments to get better financial reduction for violations of the FTC Act.

  • In April 2020, the U.S. District Court docket for the District of Columbia authorised the 2019 settlement between Fb, the FTC, and the U.S. Division of Justice. The grievance alleged that Fb violated the Fee’s 2012 order in opposition to the corporate by 1) misrepresenting the management customers had over their private info, which tens of thousands and thousands of customers relied upon, and 2) failing to institute and keep an inexpensive program to make sure shoppers’ privateness.  The FTC additionally alleged that Fb deceptively didn’t disclose that it will use telephone numbers offered by customers for two-factor authentication for focused ads to these customers.  The Fee’s order imposed a $5 billion penalty, in addition to a bunch of modifications to the Fee’s unique order designed to alter Fb’s total strategy to privateness.  The $5 billion penalty in opposition to Fb is the most important ever imposed on any firm for violating shoppers’ privateness.

As demonstrated by the foregoing enforcement actions, the FTC has leveraged its restricted sources efficiently to satisfy its enforcement priorities and redress probably the most egregious privateness and information safety violations.  Understanding the broad scope (and substantial limitations) of the Fee’s jurisdiction will assist whistleblowers perceive their rights and incentives below the brand new invoice.

Establishing an FTC Whistleblower Reward Program

Part 3 of the FTCWA would create a whistleblower reward program on the FTC, below which a whistleblower may acquire an award starting from 10 to 30 p.c of collected financial sanctions that the FTC recovers in an administrative or judicial motion introduced by the FTC or DOJ wherein the combination financial sanctions exceed $1,000,000.  To be eligible for an award, the whistleblower should voluntarily present unique info to the FTC that the whistleblower fairly believes pertains to a possible or suspected violation of any legislation, rule, or regulation enforced by the FTC and that unique info should result in an FTC enforcement motion.

The financial sanctions collected in any judicial or administrative motion that will qualify for an FTC whistleblower award embody any monies, together with penalties, disgorgement, or curiosity ordered or agreed to be paid however excludes any reduction essential to redress harm to shoppers.

The FTCWA would set up a reward program on the FTC much like the SEC whistleblower program that Congress enacted within the Dodd-Frank Act, which has proven successful in enhancing the SEC’s means to detect and halt fraud schemes and shield traders. Because the inception of the SEC whistleblower program, whistleblower suggestions have enabled the SEC to get better roughly $5 billion in financial sanctions and return $1.3 billion to harmed traders.  The SEC has issued awards totaling roughly $1.2 billion to 234 people.

There may be, nevertheless, a flaw within the textual content of the FTCWA authorizing the fee of awards in that HR 6093 states that the FTC “may pay an award,” whereas the Dodd-Frank Act states that the SEC “shall pay an award.”  And the FTCWA supplies that the “determination of whether, to whom, or in what amount to make an award shall be in the discretion of the FTC.”

Rewarding “Original Information” Resulting in FTC Enforcement Actions

The FTCWA whistleblower incentive provision would encourage whistleblowers to supply “original information,” i.e., info that’s derived from the impartial data or evaluation of a whistleblower or will not be recognized to the FTC from another supply, until the whistleblower is the unique supply of the knowledge.  Offering info that’s solely derived from an allegation made in a judicial or administrative listening to, governmental report, listening to, audit, or investigation, or from the information media wouldn’t qualify for a whistleblower award until the whistleblower is a supply of the knowledge.

The FTCWA permits a whistleblower to be represented by counsel.  However in distinction to the SEC whistleblower program, the FTCWA doesn’t expressly authorize whistleblowers to report violations to the FTC anonymously by way of an lawyer.

Whistleblowers Ineligible for an Award

Underneath the FTCWA, the FTC might deny an award to  any  whistleblower  who

  • is convicted  of  a  prison  violation  associated  to  the  coated  motion;

  • appearing with out  course  from  a  coated  entity, intentionally  causes  or  considerably  contributes  to  the  alleged  violation  in  the  coated motion; or

  • fails to supply unique info to the FTC in such type because the FTC might require.

The FTCWA doesn’t restrict award eligibility to whistleblowers who achieve info by way of the efficiency of compliance or audit duties.

Figuring out the Quantity of an FTC Whistleblower Award

To find out the quantity of an AMLA whistleblower award, the FTC will think about:

  • the importance of the knowledge offered by the whistleblower to the success of the coated judicial or administrative motion;

  • the diploma of help offered by the whistleblower and any authorized consultant within the coated motion; and

  • further related elements that the FTC deems related.

Defending FTC Whistleblowers Towards Retaliation

Part 2 of the FTCWA creates a non-public proper of motion for whistleblowers who’ve suffered retaliation for disclosing a possible violation of any legislation,  rule, or regulation enforced by the FTC.  It prohibits an entity or particular person topic to the jurisdiction of the FTC from retaliating in opposition to a whistleblower for:

  • Making a coated disclosure (a proper or casual communication or transmission that a person fairly believes pertains to a possible or suspected violation of any legislation, rule, or regulation enforced by the FTC) to the FTC or a Federal entity, together with any Member or committee of Congress; an individual with supervisory authority over the person; or one other particular person who the person fairly believes has the authority to research, uncover, or terminate the violation.

  • Initiating, testifying, aiding, or taking part in an investigation or judicial or administrative continuing by a certified entity.

  • Objecting to, or refusing to take part in, any exercise, coverage, apply, or assigned activity that the person fairly believes is a  potential or suspected violation of any legislation, rule, or regulation enforced by the Fee.

The FTCWA’s definition of “whistleblower” clarifies that it protects present or former full-time,  part-time, or non permanent staff, contractors, subcontractors (at any tier), grantees, subgrantees, or brokers of a coated entity or any individual that assists or is perceived as aiding a whistleblower.

Broad Scope of Prohibited Retaliatory Opposed Actions

Much like the Sarbanes-Oxley whistleblower protection law, the FTCWA prohibits a variety of retaliatory acts, together with instantly or not directly discharging, demoting, suspending, threatening, harassing, blacklisting, or in another method discriminating or taking an antagonistic personnel motion.  The catch-all class of retaliation (“in any other manner” discriminating in opposition to a whistleblower) encompasses non-tangible employment actions, comparable to “outing” a whistleblower in a way that forces the whistleblower to endure alienation and isolation from work colleagues.


A prevailing AMLA whistleblower is entitled to the next treatments:

  • reinstatement;

  • triple again pay with curiosity;

  • uncapped consequential and compensatory damages, which incorporates emotional misery damages; and

  • cheap lawyer charges, litigation prices, and professional witness charges.

FTCWA retaliation claims can be introduced instantly in federal courtroom.  There isn’t any administrative exhaustion requirement. And FTCWA retaliation claims wouldn’t be topic to necessary arbitration.

Strong Anti-Gag Provisions

The FTCWA accommodates sturdy anti-gag provisions.  It could prohibit a coated entity from taking any motion that impedes or prevents a person from speaking instantly with a certified entity a few coated disclosure, together with imposing, or threatening to implement, a confidentiality or non-disparagement settlement.  And a coated entity (an entity topic to the jurisdiction of the FTC) can be prohibited from requiring the consent of the counsel of the coated entity for a certified entity (the FTC, a Federal entity, or Congress) to speak instantly with a person or the lawyer of a person (if the person is represented by an lawyer)  relating to a potential coated disclosure.  A violation of the anti-gag provisions can be deemed an unfair or misleading act or apply topic to FTC enforcement authority, together with penalties.

FTCWA Would Not Preempt or Diminish Further Retaliation Cures

The FTCWA’s whistleblower safety provision wouldn’t preempt or  supersede another Federal or State legislation regarding whistleblower protections.  Nor would it not diminish the rights, privileges, or treatments of any  whistleblower below any Federal or State legislation, or below any collective bargaining settlement.


If enacted, the whistleblower rewards and safety provisions of the FTCWA will play a essential function in figuring out and combating shopper safety fraud.

Goal of FTC Whistleblower Act of 2021

press release from Congresswoman Jan Schakowsky states the aim of the FTCWA:

“Whistleblowers risk their livelihoods to bring truth to light and help safeguard the public from corporate wrongdoing,” stated Congresswoman Schakowsky. “Recent events have again proven how indispensable whistleblowers are to our society, to democracy, and to American families. That is why today my colleague Representative Trahan and I take action to support whistleblowers. The FTC Whistleblower Act of 2021 will help the Commission to take bold action against wrongdoers by protecting whistleblowers from retaliation for their bravery and incentivizing the disclosure of unlawful activity that harms American consumers.”

Congresswoman Trahan added, “Time and time again, whistleblowers have proven key in uncovering information critical to protecting consumers. As the Federal Trade Commission works to investigate harmful behavior by massive corporations, it’s important that the agency offers safeguards to protect and incentivize potential whistleblowers, as is standard with several other investigatory agencies. I’m proud to join with Chairwoman Schakowsky to introduce the FTC Whistleblower Act of 2021, which will enable the Commission to establish these essential standards and bolster its important work.”

“Whistleblowers play an essential role in exposing waste, fraud, and misconduct that directly impacts consumers,” stated Melissa Wasser, coverage counsel, Undertaking On Authorities Oversight. “Establishing a whistleblower award program at the Federal Trade Commission (FTC) will incentivize whistleblowers to come forward with tips and protect those whistleblowers from retaliation. POGO thanks Representative Schakowsky and her team for their commitment to protect whistleblowers at the FTC by mirroring best practices within this new award program. This legislation ensures more whistleblowers will come forward with important disclosures that will strengthen consumer protection.”

Whistleblower Rewards and Protections Provisions of the FTC Whistleblower Act of 2021

Click Here for the Full Document


Source link