United States of America: Announced investigation into CafePress over alleged failure to implement reasonable security measures to protect sensitive information stored on its network

Description

Announced investigation into CafePress over alleged failure to implement reasonable security measures to protect sensitive information stored on its network

On 15 March 2022, the Federal Trade Commission (FTC) announced an investigation into the online custom merchandise platform CafePress. The FTC alleges that CafePress failed to secure consumers' sensitive personal data and concealed a major breach. The company is accused of not implementing reasonable security measures to protect sensitive information stored on its network, including plain text Social Security numbers, inadequately encrypted passwords, and answers to password reset questions. The proposed order requires CafePress to enhance its data security and its former owner to pay half a million dollars to compensate small businesses.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cybersecurity regulation
Regulated Economic Activity
platform intermediary: e-commerce
Implementation Level
national
Government Branch
executive
Government Body
consumer protection authority

Complete timeline of this policy change

Hide details
2022-03-15
under deliberation

On 15 March 2022, the Federal Trade Commission (FTC) announced an investigation into the online cus…

2024-01-10
under investigation

On 10 January 2024, the Federal Trade Commission (FTC) launched a claims process for consumers who …

2024-09-18
in force

On 18 September 2024, the Federal Trade Commission (FTC) announced that it was distributing over US…