FTC will not fine Google for stealing passwords with Street View cars
Following Google's recent admission that it accidentally stole passwords, emails and other personal information with its Street View cars, the Federal Trade Commission has decided not to issue any fines.
Context & Ripple Effects
Google spent October unwinding the Street View Wi-Fi mess before Washington could act on it: on October 19 it dropped Wi-Fi scanning from its Street View cars entirely, removing the practice that had drawn regulator attention after its admission the cars collected passwords and emails. Eight days later, FTC consumer protection director David Vladeck closed the agency's inquiry into the payload data collection with no fine attached.
The story travelled thinly for its subject — beyond this report, pickup was limited to privacy-focused commentary like The Not-So Private Parts' 'FTC Forgives Google's WiFi Sniffing' — which itself says something about how the enforcement decision landed outside specialist circles.
First-order effects
- Google exits the FTC's Street View inquiry with no monetary penalty despite confirming that its cars harvested passwords, emails and other personal payload data — the remediation burden now falls on disposal of the collected material rather than the company's balance sheet.
- Google has already removed the offending behavior at the source by halting all Street View Wi-Fi scanning as of October 19, so the FTC's no-action decision closes a file on a practice that no longer exists rather than constraining an ongoing one.
Second-order effects
- Privacy advocates and non-US regulators who treated the payload collection more seriously than the FTC now have a documented US enforcement gap to point at when pressing their own cases against Google over the same data.
- Rival mapping and local-search efforts — an area Google was actively reshaping the same week with its Place Search overhaul — get an implicit signal that data-collection missteps carry limited FTC downside in the US.
Third-order effects
- If the pattern holds, US privacy enforcement defaults to case-by-case consent and correction rather than fines for large platforms, pushing meaningful accountability toward foreign regulators and civil litigation — venues where Google still faces open exposure over the same Street View data.
The trend: US regulators are treating accidental mass data collection as a correct-and-move-on event while international bodies treat it as a punishable offense, leaving platform privacy accountability fragmented by geography.