Appeals Court Affirms FTC Authority Over Corporate Data-Security Practices
Brent Kendall / Wall Street Journal :
Context & Ripple Effects
This 2015 appellate ruling settles the question companies kept raising when the FTC pursued them over data-security failures: whether the agency has statutory standing to police breaches at all under its general consumer-protection mandate. With the answer affirmed, the FTC's later courtroom record in this corpus reads differently — its unlimited-data suit against AT&T was allowed to proceed, judges let an amended monopoly complaint against Meta survive dismissal, and the agency ultimately won a green light for antitrust claims against Amazon.
It also rhymes with enforcement developments abroad: in 2022, Europe's top court affirmed that consumer-protection agencies can sue over GDPR infringements, so both major regulatory blocs were confirming by court action what their legislatures had left ambiguous.
First-order effects
- Companies facing FTC data-security actions lose their strongest legal defense — that the agency lacks jurisdiction over security lapses — leaving the FTC free to keep prosecuting breach-related cases without waiting for Congress.
Second-order effects
- A settled authority base lets the FTC extend the same litigation playbook into adjacent territory, from the AT&T data-plan case to the monopoly complaints against Meta that judges allowed to advance after earlier setbacks.
Third-order effects
- If courts keep affirming FTC latitude — as they did years later on the Amazon antitrust claims — judicial validation effectively substitutes for federal data-security legislation, making appellate rulings the de facto drafting mechanism for US breach regulation, mirroring the EU's court-backed GDPR enforcement model.
The trend: Courts, not legislatures, are becoming the venue where the boundaries of consumer-protection regulators' power over corporate data practices get drawn.