Privacy Group Asks F.T.C. to Investigate Google
The Electronic Privacy Information Center formally asked the Federal Trade Commission on Tuesday to investigate the privacy and security safeguards of Gmail, Google Docs and other so-called cloud computing services offered by Google to consumers.
Context & Ripple Effects
This filing extends a running campaign by watchdog groups against Google rather than opening a new front. EPIC and allied organizations first took Google to the FTC in April 2007 over its data practices (an earlier privacy complaint to the agency), followed within months by public demands for limits on the company (coalitions pressing regulators to constrain Google) as its search dominance grew. The new complaint shifts that scrutiny onto consumer-facing infrastructure — Gmail, Google Docs and other hosted services — where users entrust documents and correspondence to remote servers.
First-order effects
- Google now faces a formal regulatory record on cloud security: EPIC's petition asks the FTC to examine whether safeguards around Gmail and Docs match the sensitivity of the consumer data they hold, putting the company on notice even before any investigation opens.
- The complaint reframes cloud computing from an efficiency story into a trust question for mainstream consumers deciding whether to move email and documents off their own machines.
Second-order effects
- Rival cloud and webmail providers get a competitive wedge: any FTC attention to Google's safeguards pressures the whole category toward more visible security commitments, since a finding against Google would tar shared-hosting models generally.
- The tactic validates regulator petitions as cheap leverage — EPIC repeats it against Google repeatedly, from seeking a US right to be forgotten in 2015 (the group's later right-to-be-forgotten complaint) to challenging Google's in-store shopper tracking in 2017 (its suit over opaque Store Sales Measurement tracking), showing the playbook compounds.
Third-order effects
- If the pattern holds, consumer cloud services become standing subjects of privacy enforcement rather than one-off controversies, with agencies treating data custody — not just data collection — as the regulated surface.
- Advocacy groups' petition-first strategy institutionalizes a channel where formal complaints substitute for legislation, shaping platform behavior through the threat of investigation across successive product generations.
The trend: Privacy advocates are steadily migrating their complaints from what search engines know to where consumer data lives, making the cloud itself the next enforcement battleground.