On July 14, 2026, the Seventh Circuit affirmed and held that Section 227(c)(5) does not permit plaintiffs to sue for unwanted text messages. The Seventh Circuit reasoned that text messages would not constitute “calls” under the ordinary meaning of the word because text messaging did not exist when the TCPA was enacted in 1991. The Seventh Circuit acknowledged that Section 227(c)(5) likely covered more than just telephone calls as they existed in 1991 but declined to express too much “liberality” in interpreting terms.
The Seventh Circuit also relied on the context of provisions surrounding Section 227(c)(5), noting that use of the term “telephone solicitations” in other parts of the statute indicated that Congress intended a different meaning for “calls.” The court rejected Plaintiff’s attempt to rely on the FCC’s interpretation of the statute, finding it is no longer bound by the FCC’s guidance post-McLaughlin. The Seventh Circuit also rejected Plaintiff’s policy arguments, finding that the TCPA’s remedial nature was insufficient to overcome the plain language of the statute. It also found that cases interpreting text messages under different provisions of the TCPA and case law from other circuits were similarly unpersuasive.
Accordingly, the Seventh Circuit affirmed the district court’s ruling that text messages are not “calls” under 47 U.S.C. § 227(c). We will continue to monitor these developments, as this issue appears ripe for the Supreme Court to review.
Seth Steidinger, et al. v. Blackstone Medical Services, No. 25-2398 (7th Cir. July 14, 2026).
]]>New York City
Earlier this year, we covered the New York City Department of Consumer and Worker Protection’s (“DCWP”) proposed rule governing the cancellation of automatic renewal and continuous service subscriptions. That proposal has now been finalized and will take effect on October 1, 2026.
Followers of this blog and the FTC will recognize familiar names in Mayor Mamdani’s press release on the rule, with current DCWP Commissioner and former FTC BCP Director Sam Levine and former FTC Chair Lina Khan touting the final NYC “Click to Cancel” Rule and a newly proposed “Junk Fees” Rule. Notably, NYC already proposed and finalized a rule prohibiting a “hotel junk fees” rule earlier this year that prohibits advertising a price for a hotel without clearly and conspicuously disclosing the total price of the stay, including all mandatory fees. (Stay tuned for our coverage of the newly proposed, more broadly applicable NYC fees rule announced last week.)
Here’s a summary of the NYC “Click to Cancel” Rule:
Louisiana
Louisiana passed its own “Click to Cancel Act,” which will take effect on January 1, 2027. As with other automatic renewal laws, the Act requires clear and conspicuous disclosure of terms in visual proximity to the request for acceptance of the offer before the purchasing agreement is fulfilled . Affirmative consent is required “to an agreement that clearly and conspicuously displays the automatic renewal terms.” The law requires an acknowledgment containing the terms. A notice of material changes is required, as is a renewal notice for annual or longer contracts or any trial period conversion, at least three days prior to the renewal/conversion.
Here are some other notable provisions:
Violations will be subject to penalty of up to $500 per violation. However, prior to initiating any enforcement action, the Louisiana Attorney General must provide a business written notice of the alleged violation. If a business cures the violation within 30 days and provides written confirmation of that cure, the AG may not impose a penalty for that violation.
Getting Ready for Compliance
With October 1, 2026 approaching, businesses with subscribers or recurring-charge customers in New York City should assess their practices in light of the new rule. Prior to the new year, companies doing business in Louisiana should also update their renewal notice regimes and business record practices. Both new enforcement mechanisms share a lot in common with the growing patchwork of state laws, but there are various nuances within that patchwork that businesses need to pay attention to. We expect to see a lot of continued enforcement on automatic renewal issues at the federal, state, and now, local levels.
]]>This is not the first time states have alleged that payment transfer services violated UDAP laws through their marketing of safety or security, or permitting fraud on the platform. For example, last year AG James sued the parent company of Zelle on a similar theory, and Texas previously settled with PayPal regarding the Venmo app’s practices.
The Agreed Final Judgment requires Block to:
Key takeaways for all companies:
Mammoth compared the price of a Harry’s Original 8-count refill ($17) and a Harry’s Plus 8-count refill ($25) to a Gillette Fusion5 ProGlide 8-count refill ($39). Mammoth told consumers that Gillette was “straight up taking advantage of you” for “a couple pieces of metal and some plastic” and urged them to “stop getting ripped off by your razor company.”
Gillette took issue with the prices Mammoth quoted, noting that consumers could receive a one-time discount from Gillette other retailers. NAD noted that “price comparisons should reflect prices that are charged on a regular basis and for a reasonably substantial period of time.” Isolated sales prices shouldn’t be used. Accordingly, NAD found that Mammoth’s numbers were appropriate.
Gillette also objected to the suggestion that it was taking advantage of customers and ripping them off. Although NAD has often taken a strong position on disparaging claims, here NAD noted that “disparagement alone does not warrant discontinuance of a claim that is not false or misleading.” Although the language in the ads was “somewhat hyperbolic,” NAD didn’t seem to be too bothered by it.
This decision provides helpful guidance to advertisers looking to make price comparisons. It’s important to ensure you focus on the regular prices at which products—both yours and your competitor’s—are sold for a reasonably substantial period of time. And while aggressive language can draw scrutiny, truthful claims supported by fair comparisons won’t automatically be shut down just because they’re sharp.
]]>This panel, moderated by Rebecca Borné, Assistant Attorney General, Connecticut Attorney General’s Office was intended as a backdrop for understanding the economics of rising costs. It included an industry representative and an academic participant to discuss prices. The industry representative, general counsel for a large beef processor, explained beef pricing trends and the economic factors driving them. Ryan Nunn, Director of Research at the Budget Lab at Yale University, described short-run and long-run drivers of pricing. In the short run, he noted prices have increased from:
In the long run, prices increased from:
Looking back further, Nunn pointed to a series of economic shocks responsible for inflation, including supply chain disruptions from Covid and the Russian invasion of Ukraine.
Nicole Demers, Deputy Attorney General, Connecticut Attorney General Office kicked off the panel which also included Elizabeth Odette, Assistant Attorney General, Minnesota Attorney General (and Antitrust Task Force Chair) and Christopher Teters, Assistant Attorney General, Kansas Attorney General’s Office, with a representative from the American Economic Liberties Project (AELP).
Demers stated that when markets consolidate, consumers feel the effects including in the areas of housing, groceries, healthcare, and media. AELP posited that concentration is caused by labor exploitation and other “economic termites” such as company uniform rental markets, where bloating causes higher prices. Odette said state AGs are in a unique position to hear from consumers, and state resources have increased in several states including through the creation of additional positions, increased fines, merger notification laws, and laws keeping antitrust actions from being pulled into MDLs. Teters explained the multistate approach is especially important for states like Kansas, as it allows them to put time and effort into big cases and “help swing way above their weight class” to impact consumers.
The panelists discussed several types of consolidation, including in the areas of housing, groceries, and media. Centralized pricing software or algorithmic pricing may exacerbate the issue of housing prices. Panelists admitted that in some cases conduct that looks illegal may not be. Teters pointed to how difficult it is to investigate and convince judges or juries of illegal conduct. He also noted how general issues with drought or the economy, and a state of crisis, breeds opportunity for anticompetitive conduct and obfuscates potential issues. AELP’s panelist claimed that in agriculture, there is a problem with the floor prices going up even after a crisis, such as with eggs, beef, Pepsi, payment companies, and fertilizer. Odette mentioned recent enforcement in Agristats, John Deere, and pesticide loyalty programs and said states are looking at a Restaurant Depot merger. Demers asked how consolidation impacts media, not just with prices and labor but also with the marketplace of ideas and information. Odette said local journalists used to report on local businesses, and consolidation could lead to a decrease in quality of news. AELP said consolidation including Google Adtech and other media companies is eroding the ability to know what is going on in society, and thinks AGs should not overlook vertical integration. He said you can point at anything and find an issue.
Utah Attorney General Derek Brown moderated this panel, the next in a series of similar recent panels, joined by panelists from Instacart, the National Grocers Association, and Stevie DeGroff, First Assistant Attorney General at the Colorado Attorney General’s office.
AG Brown commented that the pricing landscape shifts every couple of weeks. He understood the use of dynamic pricing, such as price changes due to war, as with individualized pricing for auto insurance. But other instances of individual pricing sparked questions. DeGroff defined the terms surveillance, personalized, dynamic, and algorithmic pricing. The term “loyalty programs” has come up with regulations many states are considering, but is not easily defined. Colorado dealt with defining bona fide loyalty programs with its existing privacy law and related regulations, summarized as a program established for genuine purchase to provide defined benefit to a consumer voluntarily participating. DeGroff said when thinking of the contours of surveillance pricing, it is important to consider whether the consumer is getting a benefit versus harm.
DeGroff outlined two main buckets of harms:
AG Brown summed it up as pricing is not just what the market will bear, but what will the consumer bear. While surveillance pricing is “creepy”, he acknowledged there are some misconceptions and discussed those with the industry participants. For example, when data is being individualized, in practice panelists said it is being used to help consumers find what they want or help target coupons or promotions that benefit both consumers and small businesses.
AG Brown asked how to provide disclosure and transparency without suppressing innovation. DeGroff said Colorado’s bill took this question into consideration, and she expects the vetoed bill to reemerge next year. She also pointed out current laws that can address pricing issues, such as consumer privacy laws addressing deleting data, opting out of the sale of data, and opt out of targeted advertising. States can also use unfairness – for example, if there is a fake discount or the discount is not equally applied. If using demographic data, businesses could run afoul of antidiscrimination laws. Finally, states also have laws addressing that the price on the shelf has to be the price at checkout.
DeGroff said it is useful to think of a ground truth for consumers, and what harm to prevent. More sensitive data could lead to more harms, and appropriate controls could be used for data. Should controls be for setting a higher price? Selectively giving discounts? Or set depending on the industry? Where might consumers have more expectation of fairness and ensuring no opportunity for misuse? AG Brown agreed that with discount programs there should be protections, but cautioned on “squishing” innovation including potentially coupons. DeGroff agreed but said a wholesale carve-out for loyalty programs could be harmful with potential misuse.
AG Brown asked about disclosures like the New York law requirement. He questioned whether awareness is good enough – knowing someone is watching and collecting. Panelists responded that it is difficult to have meaningful disclosure, including issues with disclosure fatigue and potential for over disclosure to create antitrust concerns. DeGroff agreed antitrust is a great tool for the price setting world, but price tags are in the stores due to a moral imperative to charge customers the same price and treating customers fairly.
DeGroff proposed rather than meaningful disclosure, control of data such as deletion rights might be more meaningful. Further, the role of data brokers may be different than if a brand or business a customer expects is getting data. She mentioned California’s upcoming data broker law that requires deletion of that data. She also suggested opting out of secondary use of data would be helpful. Finally, a true price, the same as what everyone is seeing, to start at the same place can mitigate potential harms. She does not want customers to be siloed when it comes to pricing.
Expect state AGs to continue to debate:
The fact patterns in these letters are similar to ones we’ve seen before. The companies made various types of “Made in USA” claims—including claims in hashtags, like #madeinUSA—but the letters state that FTC staff has reviewed information which suggests the companies may be importing the products, in whole or significant part.
The letters go on to state that unless companies can adequately substantiate that “all or virtually all” of a product was made in the USA, their claims may violate the law and result in an enforcement action in which the FTC seeks redress for injured consumers and/or the imposition of civil penalties of up to $53,088 per violation.
Christopher Mufarrige, Director of the FTC’s Bureau of Consumer Protection, promised to “hold accountable any company that undermines Americans’ trust with misleading or outright false U.S. origin claims.” If you haven’t evaluated whether you can substantiate your “Made in the USA” claims recently, now may be a good time to do that.
]]>Unlike the forty-three states that elect their AG by popular vote, the Maine Attorney General is selected by its legislature every two years. The Consumer Protection Division in the AG’s Office operates under the Unfair Trade Practices Act (UTPA), which is modeled after the Federal Trade Commission (FTC) Act. Maine courts are guided by FTC and federal court interpretations of the FTC Act.
Consumer complaints are a central driver of enforcement. The office receives regular reports on complaint trends, and scam activity consistently ranks among the top concerns, along with home improvement disputes. Maine pairs enforcement with a consumer mediation program, where staff and volunteer mediators help resolve disputes between consumers and businesses.
From an enforcement standpoint, the UTPA provides pre-suit investigative authority, including through civil investigative demands, which are considered confidential. The law requires the office to provide 10 days’ notice before filing suit. The state is not subject to statutes of limitations under the common-law nullum tempus doctrine. The office prioritizes injunctive relief to stop harmful conduct, while also seeking restitution, disgorgement, and civil penalties of up to $10,000 per intentional violation. The office also participates in multistate investigations, allowing it to leverage resources, draw on expertise from AG offices in other states, and address conduct that extends beyond Maine’s borders.
Recent legislative developments related to consumer protection emphasize a focus on emerging risks, including:
Maine’s Constitution allows citizens to initiate legislation directly, making ballot initiatives a significant force in consumer protection law. After filing an initiative with the Secretary of State, proponents have 18 months to gather signatures equal to 10% of the last gubernatorial vote, or roughly 68,000 signatures currently.
Once qualified, the legislature may pass the proposal, reject it and send it to voters, or offer a competing measure. Even after passage, initiatives often require legislative refinement and may prompt litigation, underscoring the challenge of transposing complex policy into a yes-or-no ballot question.
Recent years have seen increased use of this process across issues from economic regulation to social policy, demonstrating its growing role in Maine’s regulatory environment.
For example, Maine’s automotive right-to-repair law, approved by voters in 2023 with overwhelming support, illustrates both the power and complexity of citizen initiatives. The law seeks to ensure that vehicle owners and independent repair shops have access to electronic vehicle data, including wireless telematics through either an interoperable platform or app.
Like other states, Maine is focusing on the intersection of private equity and consumer protection, where profit-driven investment strategies may be viewed as conflicting with consumer interests such as affordability, access, and quality.
Two areas have drawn particular attention for Maine:
These measures demonstrate an effort to balance investment activity with consumer protection, particularly in markets affecting at-risk populations.
***
Maine’s consumer protection regime is unique in that it is not only shaped by the attorney general’s office and market forces, but also directly by voters. For businesses, this means staying attuned not only to enforcement trends but also to legislative developments driven by forces outside the traditional policymaking process.
Summer Associate Bariela Capollari contributed to this post.
]]>Sessions included The Deadly Deception of Counterfeit Drugs; Building Public-Private Partnerships to Protect Public Health and Safety; Mental Health Matters: Equipping Leaders to Make a Difference; Addressing the Rise of Illicit Substances and Related Criminal Markets; The Evolving Debate Over Prediction Platforms; Navigating a New Era in College Sports; and Financial Fraud in Focus.
We elaborate on some key sessions from the meeting below.
New Mexico Attorney General Raúl Torrez set the tone for the conference with a call for bipartisan collaboration and good faith debate. AG Torrez emphasized that regardless of party or state size, AGs are in the “get stuff done business,” and that collaborative policy statements and court actions are intended to shape national policy. He framed AGs as public servants who can model constructive governance for other institutions and urged continued coordination on issues ranging from algorithmic pricing to children’s online safety. AG Torrez was then joined by Jim Steyer, CEO of Common Sense Media, to discuss this year’s Chair’s Initiative on Protecting Children from Online Exploitation and Human Trafficking.
Connecticut AG William Tong moderated a panel on modern pricing, featuring multiple industry representatives and the National Retail Federation (NRF).
AG Tong framed the issue from the consumer perspective: consumers expect a clearly stated price, no hidden fees, and the ability to comparison shop. According to AG Tong, the challenge arises as pricing increasingly involves algorithms, machine learning, and consumer behavioral data. Overall, AG Tong focused on:
Key points from the discussion included:
A company representative noted that they are tracking 75 pricing-related bills; most have not advanced, but Connecticut passed a law and New York has a bill awaiting the governor’s signature. The representative emphasized that “algorithm” can mean a basic formula—like a chocolate chip cookie recipe—and that surveillance pricing raising concerns about race or health data is a fundamentally different question.
NRF pushed back on the “surveillance pricing” framing as a “bogeyman,” stating there is no evidence its members are fluctuating prices real time in stores because doing so would erode customer trust. NRF noted Connecticut’s law takes a more balanced approach: disclosure is required only if a price is increased based on individual data, not decreased.
NRF cautioned that mandatory disclosure of all pricing inputs could create a “black box” that confuses consumers and be collusive. An industry representative similarly warned that requiring companies to divulge how every price is derived could facilitate collusion and disadvantage smaller companies. AG Tong pushed back: “Who better to bear the risk—the retailer or the consumer?”
Affordability, loss leaders, loyalty programs, and discounts were discussed as areas where data legitimately advantages consumers, and where overbroad regulation could chill competitive behavior.
For more information on pricing legislation, including surveillance pricing, see our webinars on the topics here and blog posts here.
Arkansas AG Tim Griffin moderated a conversation with general counsel from a grocery store chain and ride share app. The overall message was businesses that build relationships with AG offices before there is a problem are the ones that navigate enforcement most successfully.
Key points from the panel included:
The grocery store representative noted that AG offices are increasingly active on M&A, organized retail crime, surveillance pricing, and grocery affordability—and that companies must understand these priorities and engage early. They explained that their company proactively educated AG offices on grocery pricing economics (roughly 2% margins).
The ride share company representative emphasized shared interests with AGs—clear rules, safe communities, information sharing—and highlighted partnerships on human trafficking (drivers recognizing signs), and relationship building through staff-level continuity.
AG Griffin noted that “99% of engagement should be relationship building.” According to him, if you call a GC only when there’s a problem, you’ve already lost.
Practical advice included that companies should engage at staff level (because staff outlast elected AGs), and finding organic partnership opportunities (ORC, human trafficking, drug takeback, gift card fraud, food pricing).
Moderated by Sharon Merriweather of the Maryland AG’s Office, this panel featured Delaware’s John Eakins and Andrew Kingman from Mariner Strategies and was one of the most substantive sessions of the conference for companies navigating state privacy compliance.
The panelists first overviewed the state of play for data privacy in the states, including that:
Vermont just signed the 23rd state comprehensive data privacy law. Twenty state laws are currently effective. Core definitions, consumer rights (access, delete, correct, opt out of sale/targeted advertising), sensitive data consent requirements, and the controller/processor framework are largely consistent—about 85% the same across the state laws.
No state has a private right of action. AGs are the primary enforcers. Cure periods have expired. Bipartisan coalitions are actively enforcing.
Delaware’s just-passed amendments (awaiting governor’s signature) include: explicit treatment of inferences as sensitive data even after collection, location data tied to sensitive locations (like abortion clinics) treated as sensitive, contracting and due diligence requirements for third-party disclosures, and a new impact assessment requirement for automated decision-making with discriminatory impacts.
The panelists then discussed enforcement trends and practical signals from the panel, including:
States have moved beyond reviewing privacy notices to examining actual data use and senior leadership involvement. Mr. Eakins said, “We ask for board minutes. Make sure your bosses know—when the states are looking, they want to know what management is doing.”
Multistate coordination is accelerating. A consortium of state privacy regulators plus the California Privacy Protection Agency (CPPA) has an MOU enabling information sharing. Delaware’s calendar is “80–90% multistate meetings.”
States report 99% cooperation from investigation targets. Companies with mature programs—those that can quickly explain what data they collect, how they use it, and who makes decisions—fare significantly better.
Expect settlements in both data security and privacy practices—under state privacy laws and UDAP statutes (including in states without comprehensive privacy laws).
Kingman emphasized that businesses want consistency and clarity, value consumer trust, and appreciate AG guidance on unique state standards.
***
In all, the 2026 AGA Annual Meeting reinforced several themes that companies should keep in mind going forward:
Multistate coordination is the norm, not the exception, and AGs are working together on privacy, pricing, AI, child safety, and financial fraud.
Companies that engage proactively—before enforcement—are the ones that navigate issues most successfully.
AI is simultaneously an enforcement target and an enforcement tool. AGs are using AI internally and regulating it externally.
Privacy enforcement is accelerating and board-level engagement with data practices is no longer optional according to state AGs.
The pricing debate is moving from theory to law. Companies using algorithmic pricing need a defensible story.
We will continue to monitor developments from the AGA and state AG enforcement trends.
]]>Narrow Duty with Broad Consequences
The Amazon settlement relates to Section 609(e) of the FCRA, 15 U.S.C. § 1681g(e), which requires a business that has potentially transacted with someone who fraudulently used a consumer’s identity to provide the identity-theft victim with the application and business transaction records of the fraudulent transaction. The statute permits a business to require proof of identity and proof of the identity-theft claim, and it allows a business to refuse the request only in narrowly defined circumstances.
According to the complaint, Amazon routinely declined to furnish identity-theft records, citing “security” or “privacy” grounds that the statute does not recognize as valid bases for refusal. The complaint alleges that consumers were forced to navigate a “Kafkaesque” loop to obtain records they were entitled to under Section 609(e): in some instances, customer service agents allegedly would not release records about a fraudulent account unless the victim could first name the identity thief—information available only in the very records being withheld. One victim reportedly guessed more than 30 names before giving up. The FTC also alleged that Amazon refused records to authorized law enforcement absent a subpoena and missed the FCRA’s 30-day deadline in numerous instances.
Compliance Lessons
What makes this settlement instructive is that Amazon’s alleged day-to-day practices, which included identity-verification scripts, escalation protocols, and well-intentioned “fraud prevention” efforts, did not meet the letter of the FCRA. Even after the FTC identified the issue to Amazon’s counsel in 2023, the FTC contends that the company did not implement a required written policy until 2025, after learning it was under investigation.
The parties’ resolution underscores the stakes. Amazon agreed to a $2.25 million civil penalty, detailed injunctive relief, multi-year website-notice requirements, affirmative outreach to “Eligible Identity Theft Victims,” and a decade of compliance reporting and recordkeeping. The order sunsets in 10 years.
Sophisticated Guidance Matters
The Amazon settlement illustrates that even well-intentioned compliance efforts can falter when they fail to account for the FCRA’s highly specific requirements. The statute imposes precise obligations, measured in days, triggered by specific requests, and subject to carefully delineated exceptions. These obligations intersect with other regulatory regimes, such as the Gramm-Leach-Bliley Act and state law.
Businesses that touch consumer data, payments, fraud response, or identity verification need experienced counsel who understand both the letter of the FCRA and how the Commission develops and resolves these cases.
]]>
Here’s an overview of some of the key allegations in the complaint:
NACA alleges that Polymarket’s conduct violates Washington, DC’s Consumer Protection Procedures Act. Among other things, it asks the court to award equitable relief, including equitable restitution, disgorgement of profits, and a permanent injunction against the defendants’ use of the practices described in the complaint.
We only have one side of the story and it’s too early to tell how this case will turn out, but this case—like the lawsuit against Gymshark that we posted about earlier this month—demonstrates the importance of ensuring that influencer campaigns comply with the FTC’s Endorsement Guides. The FTC may have temporarily stepped away from the table, but plaintiffs’ lawyers and consumer groups are doubling down.
]]>The plaintiff alleges that Abbott’s claims that the product is “Clinically Proven to Help Kids Grow” misled consumers into thinking the product was clinically proven to help typical children grow taller, when that’s not the case. Among other things, she pointed to a giraffe image accompanied by ruler-like marks on the label and to commercials showing parents lifting kids up so that they’re taller as support for her interpretation of the claim.
Abbott argued that the phrase “Clinically Proven to Help Kids Grow” was not misleading because “grow” does not necessarily mean grow taller—instead, it could also refer to weight, body composition, or other forms of child growth. Abbott also argued that its disclaimer made clear that the studies supporting the claim involved children at risk for malnutrition or undernutrition, rather than all children generally.
A New York federal court recently denied Abbott’s motion for summary judgment, holding that a jury could reasonably find that Abbott’s packages and ads communicated a message that the product could help typical children grow taller. The court also held that the disclaimer didn’t change the analysis, holding that a reasonable jury could find it ineffective because it isn’t prominent and the language doesn’t clearly explain how it limits the claim.
This case serves as a reminder that courts will generally look at the whole context of an ad (including images) to figure out what claims reasonable consumers are likely to take away from that ad. Ads can be literally true, but still misleading, if consumers take away a message that an advertiser can’t support. Even a disclaimer may not help, especially if that disclaimer appears in “small print” and is difficult to understand.
We’ll keep reporting about these cases to help you Grow & Gain a better understanding of advertising law.
]]>According to the FTC’s complaint, the enterprise continually launched new product offerings, registered new Delaware shell companies, and opened fresh merchant accounts to hide its true identity from consumers and evade fraud-monitoring programs.
The FTC’s allegations highlight three core tactics that serve as a textbook list of what not to do if you offer recurring subscriptions:
The FTC alleges these practices violate both Section 5 of the FTC Act and the Restore Online Shoppers’ Confidence Act.
While this case involves an extreme example of an alleged multi-layered fraud scheme, the core tenets of the FTC’s enforcement strategy apply to all legitimate companies utilizing automatic renewals. Companies need to clearly and conspicuously disclose all material terms, get affirmative consent from consumers, and make cancellation simple.
We’ll continue to track these subscription cases. In the meantime, now is a good time to audit your signup flows, disclosure placement, and cancellation paths to ensure they match current legal requirements.
]]>This week, the woman filed a class action lawsuit against Gymshark alleging that the company has enlisted “an army of fitness influencers” to promote its products and instructed them to post content “without disclosing to consumers that such posts are paid advertisements.” The complaint alleges that most of the soldiers in the influencer army didn’t disclose their connection to the company, and those that did used small print or text that viewers couldn’t see without clicking a link.
As with similar lawsuits, this complaint leans on the FTC’s Endorsement Guides to argue that it’s misleading for an influencer to promote a product without clearly disclosing her connection to the brand. (The complaint also points to this NAD case for the same principle.) The Florida woman alleges that she wouldn’t have purchased the leggings if it weren’t for the misleading posts and she seeks damages for herself and other people who purchased Gymshark products after seeing similar posts.
There are at least two lessons to learn here. First, if you are a consumer purchasing products based on an influencer’s recommendation, you may want to err on the side of assuming that the influencer is being paid. Second, if you are a company using influencers to promote your products, make sure your influencers disclose their connection to you in a way that complies with the FTC’s Endorsement Guides. If you don’t, you may find yourself doing some heavy lifting in court.
]]>With the Antitrust Division's launch of its first-ever whistleblower rewards program, revisions to corporate self-disclosure policies, and a renewed emphasis on cooperation credit across all white-collar enforcement areas, companies that handle consumer data, make advertising claims, or engage in competitive marketing practices face heightened exposure. A complaint that begins as an advertising or privacy matter can quickly escalate into a federal investigation involving allegations of fraud, anticompetitive conduct, or obstruction — particularly where self-regulatory missteps compound underlying compliance failures.
Advertising and privacy professionals are no strangers to multi-agency enforcement. The same conduct that draws an FTC inquiry can attract DOJ attention when it involves deceptive practices at scale, data-sharing arrangements with anticompetitive dimensions, or misleading claims that cross the line into criminal fraud. The DOJ's updated policies now create powerful new incentives for insiders to blow the whistle — and powerful new risks for companies that delay self-disclosure when problems surface.
For in-house counsel and compliance officers managing advertising review processes, privacy programs, or internal investigations triggered by consumer complaints, understanding how the DOJ evaluates corporate cooperation and exercises prosecutorial discretion is no longer optional — it's essential.
Kelley Drye Partners Sean M. Farrell and Thomas F. Rybarczyk — both former senior federal prosecutors — will offer an inside look at how the DOJ evaluates corporate conduct and determines cooperation credit in a webinar titled "Inside the DOJ Playbook: New Guidance on Whistleblowers, Leniency, and Self-Disclosure." The discussion will be moderated by White Collar Partner Sandra L. Musumeci.
Sean served as Chief of the Antitrust Division's New York Office and helped shape its whistleblower and compliance programs. Tom served as Chief of the Public Corruption and Civil Rights Section in the U.S. Attorney's Office in Los Angeles, focused on prosecuting public corruption and fraud. Together, they will draw on firsthand experience to provide practical guidance for companies navigating internal investigations and high-stakes enforcement matters.
Topics will include:
This program is designed for in-house counsel, chief compliance officers, litigation and regulatory practitioners, and anyone advising organizations on government investigations, enforcement risk, and corporate compliance — including those managing advertising and privacy compliance programs where enforcement risk increasingly intersects with DOJ priorities.
]]>The AGs also addressed personalized pricing (also referred to as “surveillance” pricing) and suggested that the use of consumer information to offer individualized pricing and offers (including promotions and discounts) may further complicate transparency and could create harms by, for example, generating higher prices at restaurants consumers visit more often. The AGs claimed that providing customers different discounts based on their personal data is no different than charging different base prices, since the end goal (i.e., increasing revenue) is the same. This could also lead to outcomes, the AGs said, where customers more dependent on delivery may be charged more based on their circumstances. The AGs further stated that customers “cannot meaningfully avoid personalized pricing that they don’t know about.”
The AGs suggested that online food delivery services should be added to the existing Rule on Unfair and Deceptive Fees, with some additional inclusions:
The AGs further suggested that this Rule “may not be appropriate” for addressing personalized pricing, and instead recommended issuing a new rule on that issue for food delivery platforms. Such a rule, they suggested, should include clear and conspicuous disclosure of:
Discounts and promotions, the AGs said, should specifically be included in such a rule and not exempted, and further disclosures are merited when personalized pricing is used as part of a loyalty program. Further, the platforms should be required to disclose the specific customer data used.
While these comments pertain specifically to online food platforms, AGs have voiced similar concerns with other industries (and in some cases, states have already enacted relevant laws). For example, earlier this year 27 state AGs submitted a comment letter pertaining to Rental Housing Fees. The AGs encouraged the FTC to continue its “efforts to address unfair and deceptive pricing practices across the economy.” The AGs continue to stress that any such rules that the FTC adopts should be a floor not a ceiling, allowing states to enact further protections.
Businesses should continue to consider how they are disclosing their fees and the purpose for those fees. Further, they should consider reviewing how any “personalized pricing” is being disclosed to customers, including in the context of any loyalty programs. We anticipate further AG scrutiny in this space, and many of these topics will be discussed at the upcoming NAAG Presidential Summit. We will be in attendance and report on further developments.
]]>Register here.
CLE
Kelley Drye is an accredited provider of CA, IL, NY, and TX CLE. This continuing legal education program has been approved for 1.0 New York non-transitional Professional Practice credit and 1.0 General credit for California, Illinois, and Texas. New York credit can be applied reciprocally to New Jersey requirements and Connecticut requirements. We will apply for CLE credit in other jurisdictions, upon request, but cannot guarantee approval.
The comment highlights how modern FTC orders can impose substantial and enduring compliance burdens that extend well beyond their remedial purpose. These obligations often require companies to maintain extensive internal governance structures, third-party audits, and detailed reporting systems long after they have demonstrated compliance. In addition, the comment observes that the FTC’s approach to order duration is increasingly out of step with other federal agencies, such as the Federal Communications Commission (FCC) and the Consumer Financial Protection Bureau (CFPB), which typically impose shorter, more tailored order terms. Lengthy orders also risk locking companies into outdated compliance frameworks that may hinder innovation in rapidly evolving areas. The comment further notes that consent orders may divert resources away from emerging technologies, including artificial intelligence, toward ongoing compliance efforts.
In light of these concerns, the comment encourages the Commission to adopt a more flexible and modern approach to order duration, including a default ten-year limit with tailored, provision-specific sunset periods where appropriate. You can read the full comment to the FTC here.
Summer Associate Bariela Capollari contributed to this post.
]]>Kalshi declined to participate in the process, so NAD announced they would refer the matter “to the appropriate regulatory authorities, including relevant state Attorneys General, and to the platforms on which the advertising appeared and with which NAD has reporting relationships….”
What’s most notable about the press release is what it doesn’t say. Typically, NAD would refer this type of issue to the FTC (especially given that the issue relates to compliance with the FTC’s own Endorsement Guides). It’s interesting to note, then, that NAD didn’t say that it would refer this matter to the FTC.
Any bets as to how this will turn out?
]]>The term “synthetic performer” generally refers to an asset that was created using generative AI or a software algorithm and is intended to emulate an actual (but not identifiable) human. Here are some common questions advertisers have been asking themselves about that term:
In the absence of any guidance, many companies plan to take a conservative approach and include disclosures for “extras” and parts of performers that were created by AI. Note, though, that the statute also encompasses creation by a “software algorithm”—a term that isn’t defined—so it could also encompass assets created by other technologies.
There are also questions about how to make the required disclosures. For example:
Although some advertisers plan to use the term “synthetic performer” in their disclosures, others plan to use more commonly understood terms, such as “AI-generated image.” As for the “conspicuous” requirement, there are other laws and cases that illustrate what that could mean but it remains to be seen what NY regulators will expect in this context.
The law includes some exceptions. For example, it generally doesn’t apply to ads or promotional materials for expressive works, audio ads, or instances in which the use of AI “solely involves the language translation of a human performer.” Most other ads are covered, though.
Advertisers will want to work with their agencies to understand when ads include synthetic performers so that they can add the necessary disclosures to their ads. A violation of the law may result in a civil penalty of $1,000 for a first violation and $5,000 for any subsequent violation. Fortunately, there is no private right of action.
]]>CMG and two of its agencies—MindSift and 1010 Digital Works—advertised a service that could use a special algorithm to listen in on and detect pertinent conversations from smart devices in order to target ads to consumers within a specific geographic region. According to CMG’s ads: “We can identify buyers based on casual conversations in real time. It may seem like black magic, but it’s not—it’s AI.”
According to the FTC, though, it was neither black magic nor AI. In fact, the FTC alleged that the service did not listen in on consumers’ conversations or use voice data at all. Moreover, the service did not accurately place ads in customers’ desired locations. Instead, the FTC alleged that the service consisted of CMG reselling—at a significant markup—email lists obtained from other data brokers.
The companies also claimed that consumers had opted in to the (non-existent) listening by agreeing to terms of service for certain apps. According to the FTC, accepting an app’s terms does not constitute consent for an “invasive service” of this type. In fact, in its press release, the FTC notes that if the “service had functioned as advertised, this collection and use of consumers’ voice data without adequate consent would itself violate Section 5 of the FTC Act.”
The FTC charged all three companies with violating the FTC Act. The FTC also charged MindSift and 1010 Digital Works with a second count of violating the FTC Act by providing CMG with the “means and instrumentalities” to deceive customers through marketing materials, sales pitches, and responses to questions that misled potential customers about the service.
Under the proposed settlement orders, CMG must pay $880,000 while MindSift and 1010 Digital Works will each pay $25,000, which will be used to provide redress to customers impacted by the companies’ practices. In addition, each company agreed not to make certain misrepresentations about its services.
In 2023, the FTC provided some helpful guidance to companies making AI claims. Among other things, the FTC warned against claiming that something is powered by AI if it isn’t. “FTC technologists and others can look under the hood and analyze other materials to see if what’s inside matches up with your claims.” Although the current administration seems to have taken that guidance down, you can read our summary here.
]]>