Avast [1] [2] [3] [4] [5] [6] [7] [8] [9] [10], a UK-based cybersecurity firm [5], has been fined $16.5 million by the US Federal Trade Commission (FTC) for unlawfully collecting and selling customer web browsing data to over 100 third parties for advertising purposes.


The FTC found that Avast deceived customers by claiming to protect their privacy while selling sensitive information [9], including URLs of webpages visited [5], search queries [5], and cookies [5], through its subsidiary Jumpshot [2] [3] [8] [10]. This data included personal information such as religious beliefs, health concerns [1] [2] [7] [8] [10], political leanings [1] [2], and financial situations [8]. Avast has been collecting browsing data since 2014 [10], with Jumpshot collecting and selling over 8PB of browsing information [4]. As part of the settlement [3] [9], Avast will be banned from selling or licensing user browsing data for advertising purposes and has voluntarily closed Jumpshot [9]. The company must pay affected consumers [10], obtain consent before selling data [3] [6] [10], delete transferred information [3] [10], notify consumers of sold data [10], and implement a privacy program to address misconduct [8] [10]. Avast has responded by stating that they disagree with the allegations but are pleased to resolve the matter [5]. The FTC has also issued a proposed order to prevent future violations. Additionally, Avast and its subsidiaries are prohibited from misrepresenting their data usage practices and must delete the transferred browsing information and implement a comprehensive privacy program [2].


The fine imposed on Avast and the measures required by the FTC highlight the importance of protecting consumer privacy and ensuring transparency in data collection practices. This case serves as a reminder to companies to uphold ethical standards and comply with regulations to avoid facing similar consequences in the future.


