IP Law Daily, TECHNOLOGY/INTERNET NEWS: Complying with foreign laws won’t excuse privacy failures, censorship in U.S., FTC chief warns, (Aug 22, 2025)
Organizations Mentioned:Alphabet (Class A) | Apple | Cloudflare, Inc. | Federal Trade Commission | Godaddy, Inc. | Snap, Inc.
By Tom Leithauser, TR Daily
The letters were sent to 13 tech companies, including, Apple, Amazon, Alphabet, Meta, and Microsoft.
Federal Trade Commission Chairman Andrew Ferguson is warning 13 technology, communications, and social media companies that their efforts to comply with the laws of foreign governments could land them in the FTC’s enforcement crosshairs. In letters sent August 21, 2025, Mr. Ferguson cautioned the companies to remember their obligation under section 5 of the FTC Act to keep their promises to their U.S. customers, particularly in areas of privacy, cybersecurity, and free speech.
He cited the United Kingdom’s Online Safety Act and Investigatory Powers Act and the European Union’s Digital Services Act as potential hazards to U.S. companies. He noted recent reports that the U.K.’s Home Office, under its Investigatory Powers Act authorities, had asked Apple, Inc., to give it access to the encrypted iCloud data of Apple’s customers.
“I am concerned that these actions by foreign powers to impose censorship and weaken end-to-end encryption will erode Americans’ freedoms and subject them to myriad harms, such as surveillance by foreign governments and an increased risk of identity theft and fraud,” Mr. Ferguson wrote.
“I am also concerned that companies such as your own might attempt to simplify compliance with the laws, demands, or expected demands of foreign governments by censoring Americans or subjecting them to increased foreign surveillance even when the foreign government’s requests do not technically require that,” he said.
“As you grapple with how your company will comply with these misguided international regulatory requirements, I write to remind you that your company has independent obligations to American consumers under Section 5 of the Federal Trade Commission Act, which prohibits unfair or deceptive acts or practices in or affecting commerce,” he told the companies.
“The Commission has steadfastly maintained that companies that collect, use, share, or transmit consumers’ personal data must employ reasonable security measures, including encryption of sensitive information, to protect such information from unauthorized access, use, or disclosure,” Mr. Ferguson said.
“If a company promises consumers that it encrypts or otherwise keeps secure online communications but adopts weaker security due to the actions of a foreign government, such conduct may deceive consumers who rightfully expect effective security, not the increased susceptibility to breach or intercept desired by a foreign power,” he advised.
“Consumers may be further deceived if companies fail to prominently disclose that weaker security measures were adopted due to the actions of a foreign government, information that might be material to a consumer’s decision to use a service,” he added.
“I invite you to reach out by Thursday, August 28th to schedule a time to meet with my office to discuss how, in the face of competing pressures from global regulators, you will honor your privacy and security commitments to American consumers and meet your ongoing obligations under U.S. law,” Mr. Ferguson concluded.
The letters were sent to Akamai Technologies, Inc., Alphabet, Inc., Amazon.com, Inc., Apple, Inc., Cloudflare, Inc., Discord, Inc., GoDaddy, Inc., Meta Platforms, Inc., Microsoft Corp., Signal, Snap, Inc., Slack Technologies LLC, and X Corp., according to an FTC news release.
News: TechnologyInternet