The FTC Legal Library — where US privacy enforcement is recorded
The United States has no federal privacy regulator in the GDPR sense; the nearest thing is the FTC acting under section 5 of the FTC Act against unfair or deceptive practices. Its Legal Library is the official record of those cases, and its filters make the privacy and security enforcement line easy to isolate.
- Published by
- Federal Trade Commission.
- Type
- Official database of cases and proceedings — complaints, orders and statements.
- Versions and language
- Live web database. English.
- Jurisdiction
- United States (federal).
- Primary audience
- Practitioners advising on US-facing processing, adtech and AI; anyone tracing the Privacy Shield and Data Privacy Framework enforcement record.
- Topic tags
- FTC Act s.5 · data security · children’s privacy (COPPA) · health privacy · Data Privacy Framework · AI
- Availability
- Free, no registration.
Why it matters
As at 11 September 2026 the library held 6,107 records, the newest updated 8 September 2026, with faceted filters for record type, mission, consumer-protection topic (a Privacy and Security branch with sub-topics including children’s privacy, health privacy, consumer privacy, data security, the Gramm-Leach-Bliley Act, the Data Privacy Framework, Privacy Shield and the US–EU Safe Harbor Framework), industry (including artificial intelligence), case status, enforcement type, court and date.
The value for a UK reader is specific. The EU–US and UK–US Data Privacy Framework relies on FTC enforcement of participants’ commitments, and this is where that enforcement — or its absence — is visible. FTC consent orders in data security cases are the closest US analogue to ICO enforcement notices and set out expected controls in some detail. And children’s-privacy and health-privacy actions map to ICO priority areas.
The UK position. FTC action has no legal effect in the UK, and the FTC is a consumer-protection agency working case by case rather than a data protection authority applying a general law — so its orders read best as evidence of what one regulator has required of specific companies, not as a rulebook. Related: the HHS OCR Breach Portal for the health sector; the FTC’s regulator profile sits in Regulators & Authorities.
