After months of anticipation, the U.S. Court of Appeals for the Third Circuit’s recent decision in Federal Trade Commission v. Wyndham Worldwide Corp. provided the highest-profile examination to date of the FTC’s authority to police data security practices under Section 5 of the Federal Trade Commission Act. The opinion dismissed Wyndham’s arguments that the FTC lacks the authority to regulate data security practices under the “unfairness” prong of Section 5, in addition to holding that Wyndham received fair notice of the potential standard that would be applied to its practices under the section.
The Wyndham decision has widely—and correctly—been characterized as a significant victory for the FTC, and its implications for the FTC’s data security enforcement power are significant. At the same time, general counsel should be aware that although the Third Circuit decision confirmed that data security practices could be “unfair” for purposes of Section 5, the case turned largely on particular facts that the court believed should have alerted Wyndham to a significant problem in its systems. Below are five takeaways for general counsel on the significance, and the limitations for the FTC, from the Third Circuit’s opinion.
This content has been archived. It is available through our partners, LexisNexis® and Bloomberg Law.
To view this content, please continue to their sites.
Not a Lexis Subscriber?
Subscribe Now
Not a Bloomberg Law Subscriber?
Subscribe Now
LexisNexis® and Bloomberg Law are third party online distributors of the broad collection of current and archived versions of ALM's legal news publications. LexisNexis® and Bloomberg Law customers are able to access and use ALM's content, including content from the National Law Journal, The American Lawyer, Legaltech News, The New York Law Journal, and Corporate Counsel, as well as other sources of legal information.
For questions call 1-877-256-2472 or contact us at [email protected]