Skip to content
RiskTemplates · The Daily Brief Friday, September 11, 2026
Wire SEC's $3.02M Doximity Insider Trading Judgment: The MNPI Control Test SEP 10

Feature Data Privacy

FTC Chairman Ferguson Says a Privacy Enforcement Surge Is Coming in H2 2026. Here's What Financial Services Companies Need in Place.

FTC Chairman Andrew Ferguson publicly warned that reporters covering the FTC will 'have a hard time keeping up' with the number of privacy enforcement cases coming in the second half of 2026. The Kochava settlement and new Section 5 standalone data-security cases telegraph exactly what's in the crosshairs. Here's what financial services companies need to have documented before the cases start landing.

By Rebecca Leung · September 9, 2026 ·
Table of Contents

TL;DR

  • FTC Chairman Andrew Ferguson announced publicly that H2 2026 will see a surge in privacy enforcement cases — reporters covering the FTC will “have a hard time keeping up.”
  • The May 2026 Kochava settlement banning a data broker from selling location data without consent (94 billion geo transactions/month, 35 million daily devices) signals the FTC’s consent standard for sensitive data is now explicit and enforceable.
  • The FTC brought its first standalone Section 5 unfairness claims for data retention and breach notification failures — meaning “we don’t technically fall under statute X” is no longer a defense.
  • Non-bank fintechs covered by the GLBA Safeguards Rule face the 2023 overhaul’s specific technical requirements: encryption, MFA, access controls, pen testing, incident response. Most companies that haven’t reviewed since 2021 have gaps.

FTC Chairman Andrew Ferguson isn’t being subtle about what’s coming. In public statements, he told reporters covering the agency they’re going to “have a hard time keeping up with the number of cases we’re gonna be bringing” in the second half of 2026. The FTC’s updated strategic plan designated privacy, children’s data, and data security as explicit enforcement priorities — and named the Office of Technology as a Goal Leader for identifying enforcement targets.

That combination — a chairman publicly telegraphing a surge, a technology unit scaled to find violations, and a track record of significant enforcement against both data brokers and financial companies — is the backdrop your privacy compliance program needs to be assessed against.

For financial services and fintech companies, the FTC’s authority is more expansive than most compliance teams realize, and the 2026 enforcement environment is meaningfully different from even two years ago.

What the Kochava Settlement Tells You

The May 4, 2026 Kochava settlement is the clearest signal about where the FTC’s standards now sit.

Kochava and its subsidiary Collective Data Solutions were banned from selling or sharing sensitive location data unless they obtain a consumer’s affirmative express consent and the data is used to provide a service directly requested by the consumer. The consent requirement isn’t a notice requirement. It’s an affirmative, express, opt-in standard.

What triggered the enforcement:

  • Scale: Kochava’s data feed handled 94 billion geo transactions per month drawn from 125 million monthly active devices, with approximately 35 million daily active devices.
  • Sensitive locations: The data covered medical facilities, religious organizations, schools and childcare providers, domestic violence shelters, and military or federal law enforcement installations.
  • No meaningful consent: Consumers hadn’t agreed to have their location used for data product sales unconnected to any service they requested.

White & Case’s analysis of the settlement highlights three operational requirements that stand out: a verified consent program (not just a disclosed privacy policy), a designated “sensitive location data” program with specific prohibited categories, and consumer rights to opt out and request disclosure of who received their data.

For a fintech, the relevance isn’t that you’re selling location data at Kochava’s scale. It’s that the FTC has now defined consent standards for sensitive location data with specific, operational precision — and that standard informs how the agency will evaluate any data practice that touches location, health-adjacent, or financial behavior signals. If your analytics platform, marketing vendor, or fraud tool relies on location signals from users who haven’t explicitly opted in to that specific use, you’re operating on assumptions about consent that the FTC has now rejected.

The Fintech-Specific Authority: GLBA Safeguards Rule

For non-bank fintechs — which includes most consumer lending platforms, personal finance apps, payment companies, mortgage technology firms, and earned wage access providers — the foundational privacy law is the Gramm-Leach-Bliley Act Safeguards Rule, enforced by the FTC.

The 2023 Safeguards Rule overhaul substantially raised the floor. The current requirements include:

Written information security program: Must be based on a risk assessment that identifies reasonably foreseeable internal and external risks to customer financial information, with documented safeguards addressing each identified risk.

Specific technical controls: Encryption of customer data in transit and at rest, multi-factor authentication for accessing systems containing customer information (or equivalent access controls with documented justification), regular penetration testing and vulnerability assessments, and monitoring of authorized users’ access to detect unauthorized use.

Service provider oversight: Written contracts with service providers that handle customer financial information, requiring them to implement appropriate safeguards. This isn’t vendor due diligence as a best practice — it’s a Safeguards Rule requirement.

Incident response plan: A written plan designating a response team, defining internal processes for responding to security events, and specifying notification obligations. After a breach affecting 500 or more customers, the FTC requires notification within 30 days.

Qualified individual: A designated CISO or equivalent responsible for overseeing and implementing the information security program, with regular reporting to the board.

Companies that designed their Safeguards programs before the 2023 overhaul are operating against an outdated baseline. The FTC’s enforcement surge in H2 2026 will test whether the updated requirements are actually implemented.

Standalone Section 5: The ‘We’re Not Covered’ Defense No Longer Works

One of the most significant enforcement developments of 2025–2026 is the FTC’s willingness to bring standalone Section 5 unfairness claims for data retention and breach notification failures.

Section 5 prohibits unfair or deceptive acts or practices. An “unfair” practice must meet three criteria: it causes substantial injury to consumers, the injury is not reasonably avoidable by consumers, and the injury is not outweighed by countervailing benefits. The FTC has historically brought Section 5 data security cases in conjunction with sector-specific laws — a company that violates COPPA is also acting unfairly under Section 5, for example.

The standalone claims break new ground: they assert that inadequate data retention practices and inaccurate breach notification are themselves unfair, regardless of which other statute might or might not apply.

For a fintech that has concluded it doesn’t fall under a specific privacy law, that conclusion is no longer a safe harbor. Inadequate security for customer financial data can be unfair under Section 5 even when the company isn’t technically subject to GLBA, COPPA, or any other sector-specific requirement. The FTC can bring the case anyway.

The FTC’s data security enforcement page documents the range of cases the agency has pursued — financial services companies appear throughout, including cases against companies that sold payday loan application data (containing sensitive personal financial information) to parties with no legitimate business need for it. The FTC characterized that sale as unfair under Section 5.

Financial Data Is Explicitly in Scope

Fox Rothschild’s analysis of the FTC’s 2026 strategic plan is worth reading. The summary: “reports of the death of FTC privacy enforcement have been greatly exaggerated.” The plan doubles down on sensitive data categories — health, financial, location, children’s — and identifies AI-assisted enforcement as a capacity multiplier.

The Office of Technology is now a named Goal Leader, and the FTC is tracking how often its Technology Lab assists with identifying enforcement targets. The agency explicitly stated its intent to expand cross-border cooperation with foreign regulators, with unlawful conduct increasingly treated as cross-border in scope. A fintech with EU customers that has already navigated GDPR compliance has an advantage here; one that has been solely US-focused on privacy compliance needs to broaden its view.

For financial services companies specifically, the FTC’s track record and stated priorities make several data categories high-risk:

  • Precise geolocation data tied to financial behavior (where consumers use their cards, where they visit financial service locations)
  • Account transaction data sold or shared beyond what consumers would reasonably expect
  • Credit application data including income, employment, and credit history shared with non-lenders or unrelated third parties
  • Payment credentials or card data retained beyond operational necessity or shared with analytics vendors without adequate controls
  • Children’s financial data from any product that can be used by or with minors

The COPPA Priority

Chairman Ferguson has been explicit: COPPA enforcement is coming. The Children’s Online Privacy Protection Act applies to online services directed to children under 13 or general-audience services where the operator has actual knowledge they’re collecting data from children under 13.

For fintech, the exposure points are:

  • Family banking apps or teen debit products where minors are account holders or users
  • Financial literacy tools that attract youth users
  • General-purpose apps where parental supervision features bring minors into the data model
  • Savings products designed for children’s education accounts

If your product has any path to use by a minor, the COPPA analysis needs to be explicit in your privacy program. “We don’t market to kids” is not the same as “our product isn’t accessible to or used by kids.” Ferguson’s enforcement posture assumes the FTC will look behind the marketing to the actual user base.

What to Have in Place Before Cases Start Landing

The FTC’s H2 2026 enforcement surge isn’t a distant threat. Ferguson’s statements were made in August 2026. Cases are being built now.

The companies most exposed are those that:

  1. Haven’t updated their Safeguards program since before the 2023 overhaul. If your written information security program, MFA deployment, encryption inventory, and pen test cadence haven’t been reviewed against the 2023 requirements, start there.

  2. Have data-sharing arrangements with analytics, marketing, or fraud vendors that haven’t been mapped. Every vendor that receives customer financial information should have a written contract with Safeguards-compliant provisions. If that review hasn’t happened since 2021 or 2022, you likely have gaps.

  3. Handle location data or financial signals without explicit consent. The Kochava settlement defines the FTC’s consent standard. If your consent language covers “service improvement” but not the specific data-sharing or analytics use that location signals enable, that language doesn’t satisfy the standard.

  4. Have a product or feature that could be used by minors. If COPPA hasn’t been analyzed as part of your product’s privacy architecture, it needs to be before a case lands.

  5. Don’t have a written incident response plan with a 30-day FTC notification trigger. The Safeguards Rule requires it. The standalone Section 5 cases signal the FTC will treat inaccurate breach notification as independently actionable.

This isn’t an environment where privacy compliance waits for the next annual review cycle. Ferguson has announced enforcement is coming; the agency has scaled its capacity to deliver on it.

So What?

The state-level enforcement landscape compounds the federal picture. California’s Privacy Protection Agency has issued eight data broker fines and a September 2026 enforcement advisory — the CalPrivacy enforcement breakdown covers the operational details. The PADFAA compliance guide addresses the data security requirements affecting fintechs with foreign-adversary-linked financial data. For the GLBA reform proposals that could shift the federal-state preemption balance, see the GLBA overhaul analysis.

Ferguson has given financial services compliance teams an unusual gift: advance warning of an enforcement surge before the cases drop. Most enforcement environments don’t work that way — companies usually learn about the FTC’s priorities after the consent orders land.

The companies that use this window to close gaps in their Safeguards programs, review vendor data-sharing arrangements, assess COPPA exposure, and document consent frameworks for sensitive data signals will be in defensibly better shape than the ones that wait.

The FTC’s enforcement surge will produce consent orders. Those consent orders will describe the violations. Your job is to make sure your company’s practices don’t appear in that description.


The Data Privacy Compliance Kit at RiskTemplate includes state-by-state applicability matrices across 19 privacy laws, GLBA Safeguards Rule compliance templates, consumer rights request workflows, and breach notification checklists — built for compliance teams without dedicated privacy counsel.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What did FTC Chairman Ferguson say about privacy enforcement in H2 2026?
Chairman Andrew Ferguson stated publicly that the FTC is 'poised for a jump in US privacy enforcement in late 2026,' warning that reporters covering the agency are going to 'have a hard time keeping up with the number of cases we're gonna be bringing.' This was consistent with the FTC's updated strategic plan, which explicitly named privacy, children's data, and data security as enforcement priorities, and designated the Office of Technology as a named Goal Leader for consumer protection enforcement. The signal is unambiguous: H2 2026 is an active enforcement period, not a transition period.
What is the FTC's authority over financial services companies that aren't banks?
For non-bank financial companies — including fintechs, mortgage servicers, auto dealers, and consumer lenders — the FTC's primary enforcement authorities are Section 5 of the FTC Act (prohibiting unfair or deceptive acts or practices), the GLBA Safeguards Rule (requiring a written information security program for customer financial data), and COPPA (for companies with products or services directed to children). Banks, credit unions, and their affiliates are excluded from FTC jurisdiction and fall under federal banking regulators. But most fintechs are squarely within FTC jurisdiction — and the Safeguards Rule was significantly strengthened in 2023, with requirements that many companies are still building toward.
What happened in the Kochava settlement and why does it matter for fintech companies?
In May 2026, the FTC banned Kochava and its subsidiary Collective Data Solutions from selling or sharing sensitive location data without consumers' affirmative express consent. Kochava's data feed handled 94 billion geo transactions per month drawn from 125 million monthly active devices — and covered sensitive locations including medical facilities, religious organizations, schools, domestic violence shelters, and federal law enforcement installations. The settlement requires a verified consent program, a 'sensitive location data' program, incident reporting to the FTC, and consumer opt-out rights. The lesson for fintech: if your data practices involve precise location data, health-adjacent signals, or financial behavior patterns, the FTC's consent standard is now explicit. Consent is not optional.
What is the FTC's Safeguards Rule and who does it cover?
The Gramm-Leach-Bliley Act Safeguards Rule, enforced by the FTC, requires non-bank financial companies to develop, implement, and maintain a comprehensive information security program that safeguards customer financial information. 'Non-bank financial company' is broadly defined: it includes mortgage brokers and servicers, payday lenders, personal finance apps, tax preparers, auto dealers that arrange financing, and businesses that provide financial products or services to consumers. The 2023 Safeguards Rule overhaul added specific technical requirements — encryption, multi-factor authentication, access controls, penetration testing, and an incident response plan — that significantly raised the baseline. A fintech that treats Safeguards compliance as a checkbox from 2021 has almost certainly missed the updated requirements.
What does 'standalone Section 5 unfairness' mean in data security enforcement?
The FTC brought its first standalone Section 5 unfairness claims for unreasonable data retention and inaccurate breach notification — meaning charges based solely on the FTC Act's prohibition on unfair practices, without relying on a separate statute like GLBA or COPPA. An unfair practice under Section 5 must cause substantial consumer injury that is not reasonably avoidable and not outweighed by countervailing benefits. This signals the FTC's willingness to use its general authority to pursue data security failures even when a company doesn't technically fall under a sector-specific privacy law. For fintechs, this closes the 'not covered by X statute' defense — inadequate data security can be unfair under Section 5 regardless of which specific privacy law might apply.
What COPPA requirements does the FTC's 2026 enforcement focus add for fintech?
Chairman Ferguson has publicly stated COPPA enforcement is a priority. The Children's Online Privacy Protection Act applies to operators of websites or online services directed to children under 13, or to general audience services where the operator has actual knowledge that they're collecting personal information from a child under 13. For fintechs, the risk surfaces in family banking products, teen debit accounts, parental controls features, and financial literacy apps that might attract or be used by minors. If your app or website could reasonably be used by children, COPPA's notice, consent, and data deletion requirements apply — and Ferguson has made clear that enforcement in this area is coming.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Data Privacy Compliance Kit

Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.

◆ Keep reading

Related posts.

Data Privacy

CalPrivacy Has Issued Eight Data Broker Fines and Is Still Going. What the September 2026 Enforcement Advisory Means for Your Fintech.

California's Privacy Protection Agency issued Enforcement Advisory 2026-01 on September 3, making clear that inaccurate data broker registration is a live $200-per-day penalty risk. Two August 2026 settlements and eight prior enforcement actions signal that CalPrivacy is done with warnings. Here's what fintech compliance teams need to know.

Sep 7, 2026

Data Privacy

PADFAA Is Real Enforcement Now: What Fintech Data Companies Need to Know Before the FTC Files Its First Case

The Protecting Americans' Data from Foreign Adversaries Act prohibits data brokers from selling sensitive consumer data — including financial records — to entities in China, Russia, Iran, North Korea, Cuba, and Venezuela. The FTC sent 13 warning letters in February 2026. Here's what counts as a data broker, what data is covered, and what your compliance program needs before enforcement begins.

Sep 5, 2026

Data Privacy

GM Paid $12.75M for Selling Driver Data Without Consent. Your Fintech May Have the Same Problem.

California's record $12.75M CCPA settlement with General Motors over unconsented data sales to LexisNexis and Verisk exposes a pattern that runs through fintech: sharing consumer data with analytics firms, credit bureaus, and third parties without adequate notice or consent. Here's what the enforcement signal means for financial services compliance teams.

Sep 3, 2026

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.