Consumer Law LibrarySearchBy decadeBy respondentBy topicBy outcomeDataAbout

Genica Corporation

Volume 147 · 147 F.T.C. 370

Citation
147 F.T.C. 370
Docket
C-4252
Complaint
2009-03-16
Decision
2009-03-16
Document type
consent order
Case type
consumer protection
Statutes
FTC Act (section 5)
Industry
computer systems and consumer electronics retail
Outcome
consent order entered
Relief
cease_and_desist; recordkeeping; compliance_reporting; other
Order term (years)
10
Source
Original volume PDF
Original PDF
This decision as a PDF

deceptive advertisingprivacy data securityonline internet

Cite this decision

Genica Corporation, 147 F.T.C. 370 (2009). Consumer Law Library, https://consumerlawlibrary.org/decisions/v147-0010

Report an error in this record (decision id v147-0010)

Order status: active_until:2029-03-16. Sunset may be extended by the latest qualifying federal-court complaint alleging an order violation; complaints, dismissal/appeal outcomes, and respondent-specific extensions are not fully tracked.

Cited by 0 later FTC decisions

Cites

Text (OCR of the scan at left; may contain errors)

IN THE MATTER OF GENICA CORPORATION, AND COMPGEEKS.COM D/B/A COMPUTER GEEKS DISCOUNT OUTLET AND GEEKS.COM, CONSENT ORDER, ETC., IN REGARD TO ALLEGED VIOLATIONS OF SEC. 5 OF THE FEDERAL TRADE COMMISSION ACT Docket No. C-4252; File No. 082 3113 Complaint, March 16, 2009 – Decision, March 16, 2009 This consent order addresses Genica’s representations about the security they provided for sensitive information provided to them by consumers. The Commission’s complaint alleges that respondents represented that they implemented reasonable and appropriate security measures to protect the privacy and confidentiality of personal information. The complaint further alleges that since at least January 2007 and continuing through at least June 2007, hackers repeatedly exploited vulnerabilities by using SQL injection attacks on the www.geeks.com website and web application and found personal information of hundreds of customers, including credit card numbers, expiration dates, and security codes, stored on respondents’ network which they exported over the internet to outside computers. The order prohibits respondents from misrepresenting the extent to which respondents maintain and protect the privacy, confidentiality, or integrity of any personal information collected from or about consumers and requires respondents to establish and maintain a comprehensive information security program that is reasonably designed to protect the security, confidentiality, and integrity of personal information collected from or about consumers.

COMPLAINT The Federal Trade Commission, having reason to believe that Genica Corporation and Compgeeks.com also doing business as Computer Geeks Discount Outlet and geeks.com (“respondents”) have violated the provisions of the Federal Trade Commission Act, GENICA CORPORATION 371 Complaint and it appearing to the Commission that this proceeding is in the public interest, alleges:

1. Respondent Genica Corporation (“Genica”) is a Delaware corporation with its principal office or place of business at 1890 Ord Way, Oceanside, California 92056.

2. Respondent Compgeeks.com also doing business as Computer Geeks Discount Outlet and geeks.com (“Compgeeks.com”) is a California corporation with its principal office or place of business at 1890 Ord Way, Oceanside, California 92056. Compgeeks.com is a wholly-owned subsidiary of Genica, and Genica controlled the acts and practices of Compgeeks.com at issue in this complaint.

3. The acts and practices of respondents as alleged in this complaint have been in or affecting commerce, as “commerce” is defined in Section 4 of the Federal Trade Commission Act. 4. Respondents are in the business of selling computer systems, peripherals, and consumer electronics to consumers over the internet, including through a website (www.geeks.com) operated by respondent Compgeeks.com.

5. Respondents operate a computer network that consumers use, in conjunction with the www.geeks.com website and web application, to obtain information and to buy their products. 6. In selling products through the www.geeks.com website, respondents routinely collect sensitive information from consumers to obtain authorization for credit card purchases, including a first and last name, address, e-mail address, telephone number, credit card number, credit card expiration date, and credit card security code (hereinafter “personal information”). Personal information collected at the website is sent to computers on respondents’ computer network, reformatted, and sent to outside computer networks for payment authorization. Until at least December 2007, VOLUME 147 Complaint respondents stored information in clear, readable text on the network on a computer accessible through the www.geeks.com website. 7. Since at least October 2001, respondents have disseminated or caused to be disseminated privacy policies and statements on the www.geeks.com website, including, but not limited to, the following statements regarding the privacy and confidentiality of the consumer information they collect:

The objective of the safeguarding personal information principle is to assure you that we actively protect your privacy using a variety of security and controls. We use secure technology, privacy protection controls and restrictions on employee access in order to safeguard your personal information. We use state of the art technology (e.g., Secure Socket Layer, or SSL) encryption to keep customer personal information as secure as possible. We have also put in place privacy protection control systems designed to ensure that personal Customer data remains safe and private. (Exhibit A, current privacy policy effective 2007, and Exhibit B, former privacy policy effective between 2001 and 2007) 8. Until at least December 2007, respondents engaged in a number of practices that, taken together, failed to provide reasonable and appropriate security for the personal information stored on their network. Among other things, respondents: (1) stored personal information in clear, readable text; (2) did not adequately assess the vulnerability of their web application and network to commonly known or reasonably foreseeable attacks, such as “Structured Query Language” (“SQL”) injection attacks; (3) did not implement simple, free or low-cost, and readily available defenses to such attacks; (4) did not use readily available security measures to monitor and control connections between computers on the network and from the network to the internet; and (5) failed to employ reasonable GENICA CORPORATION 373 Complaint measures to detect and prevent unauthorized access to personal information, such as by logging or employing an intrusion detection system.

9. Since at least January 2007 and continuing through at least June 2007, hackers repeatedly exploited the failures set forth in Paragraph 8 by using SQL injection attacks on the www.geeks.com website and web application. Through these attacks, the hackers found personal information stored on respondents’ network and exported the information of hundreds of customers, including credit card numbers, expiration dates, and security codes, over the internet to outside computers.

10. Respondents became aware of the breach in December 2007, at which time they took steps to prevent further unauthorized access and to notify law enforcement and affected consumers. 11. Through the means described in Paragraph 7, respondents represented, expressly or by implication, that they implemented reasonable and appropriate measures to protect personal information against unauthorized access.

12. In truth and in fact, respondents did not implement reasonable and appropriate measures to protect personal information against unauthorized access. Therefore, the representation set forth in Paragraph 11 was, and is, false or misleading. 13. The acts and practices of respondents as alleged in this complaint constitute deceptive acts or practices in or affecting commerce in violation of Section 5(a) of the Federal Trade Commission Act.

THEREFORE, the Federal Trade Commission this sixteenth day of March, 2009, has issued this complaint against respondents. By the Commission.

VOLUME 147 Complaint Exhibit A

Geeks.com ISEARCH:) @ HACKER SAFE TESTED DALY 14.APR Systems Barebones / Kits Desktop Computers Laptops / Notebooks PDAs Hardware Bags / Cases / Backpacks Cables Cases CD-ROM Drives CD-RW / CD Burners Cell Phones Consumer Electronics Controllers / Adapters Cooling Fans CPUs / Processors Digital Cameras DVD Drives / DVD Burners External Drive Cases Flash Memory / Card Readers Gadgets / Tools Gaming GPS Hard Drives Joysticks Keyboards Media (CDR, DVD) Mice Memory / System Memory Modems Monitors / LCDs http://web.archive.org/web/20070418191125/http:/www.geeks.com/policies.asp GENICA CORPORATION Complaint Exhibit B Page | of 7 . Items In View | Contact My Subtotal: $0.00 Cart: 0 Cart Us Account Customer \ Tech ' Tech, Volume \ Gilt \ About Service Support Tips Discounts Certificates Us al Go| Get Email Discounts and SAVE! Enter Email Here Subscribe __ SALES AND RETURNS POLICIES yi) Sales and Return Policies:

* Allsales are final, Return of non-defective product within the first 30 days from date of purchase will be subjected to a 15% Return Fee. * Sales Tax will be charged on all orders delivered to an address in California (CA) * Customer must inspect all goods upon receipt and notify Geeks.com within 7 business days if any products are missing or damaged, * Shipping fees and/or Return shipping costs are not refundable and are the sole responsibility of the customer, * Only defective product returns will be accepted after 30 days for repair or replacement only.

* Products sold with a Manufacturer or Direct Warranty must be retumed directly to the product manufacturer for repair or replacement. For these items, the warranty policy from the product manufacturer explicitly requires that any returns, repairs etc. be requested and processed directly by the consumer (or "end-user") of the item. * Due to licensing and copyright laws, we do not accept returns on software once a package has been opened, Defective software will be exchanged for the same title only. * To return a product you must obtain a Return Merchandise Authorization (RMA) number. Geeks.com will not accept retums without prior authorization. * RMA numbers are valid for 30 days. RMA numbers will not be extended and will be closed upon expiration. You must contact Geeks.com to obtain another RMA number. * Once the RMA has been issued you will receive an email explaining what to expect during the return process. It is highly recommended that you use the non-prepaid address label provided on the lower portion of the RMA email sent out upon generation. If the returm is a multiple box shipment the RMA number must be marked on all packages returned. All packages returned must have the RMA number displayed in large bold letters on the outside of the box, * Unauthorized or Unmarked returns will not be honored and may be refused upon receipt and/or shipped back at the customer! 's expense. * Shipments that are refused without authorization, or that are returned due to an invalid address, are subject to a 15% Return Fee plus applicable handling fees. * All product(s) must be return as originally received to include original packaging, manuals, documentation, and all bundled accessories. Returns must be packaged appropriately as to minimize any unnecessary damage during transit. Product(s) damaged during shipment will invalidate both the warranty and RMA and will be returned to the customer at the customer. s expense. 9/23/2008

VOLUME 147 Decision and Order DECISION AND ORDER The Federal Trade Commission, having initiated an investigation of certain acts and practices of the Respondents named in the caption hereof, and the Respondents having been furnished thereafter with a copy of a draft of Complaint which the Bureau of Consumer Protection proposed to present to the Commission for its consideration and which, if issued, would charge the Respondents with violation of the Federal Trade Commission Act; and The Respondents and counsel for the Commission having thereafter executed an agreement containing a consent order, an admission by the Respondents of all the jurisdictional facts set forth in the aforesaid draft complaint, a statement that the signing of the agreement is for settlement purposes only and does not constitute an admission by the Respondents that the law has been violated as alleged in such complaint, or that any of the facts as alleged in such complaint, other than jurisdictional facts, are true, and waivers and other provisions as required by the Commission’s Rules; and The Commission having thereafter considered the matter and having determined that it had reason to believe that the Respondents have violated the Federal Trade Commission Act, and that a complaint should issue stating its charges in that respect, and having thereupon accepted the executed consent agreement and placed such agreement on the public record for a period of thirty (30) days for the receipt and consideration of public comments, now in further conformity with the procedure prescribed in Section 2.34 of its Rules, 16 C.F.R. § 2.34, the Commission hereby issues its complaint, makes the following jurisdictional findings, and enters the following order:

1. Respondent Genica Corporation (“Genica”) is a Delaware corporation with its principal office or place of business at 1890 Ord Way, Oceanside, California 92056.

2. Respondent Compgeeks.com also doing business as Computer Geeks Discount Outlet and Geeks.com GENICA CORPORATION 387 Decision and Order (“Compgeeks.com”) is a California corporation with its principal office or place of business at 1890 Ord Way, Oceanside, California 92056. Compgeeks.com is a wholly-owned subsidiary of Genica. 3. The Federal Trade Commission has jurisdiction of the subject matter of this proceeding and of the Respondents, and the proceeding is in the public interest.

ORDER DEFINITIONS For purposes of this Order, the following definitions shall apply: 1. “Personally identifiable information” or “personal information” shall mean individually identifiable information from or about an individual consumer including, but not limited to: (a) a first and last name; (b) a home or other physical address, including street name and name of city or town; (c) an email address or other online contact information, such as an instant messaging user identifier or a screen name; (d) a telephone number; (e) a Social Security number; (f) a driver’s license or other state-issued identification number; (g) credit or debit card information, including card number, expiration date, and security code; (h) a persistent identifier, such as a customer number held in a “cookie” or processor serial number, that is combined with other available data that identifies an individual consumer; or (i) any information that is combined with any of (a) through (h) above.

2. Unless otherwise specified, “respondents” shall mean Genica, Compgeeks.com, and their subsidiaries, divisions, affiliates, successors and assigns .

3. “Commerce” shall mean as defined in Section 4 of the Federal Trade Commission Act, 15 U.S.C. § 44. VOLUME 147 Decision and Order I.

IT IS ORDERED that respondents and their officers, agents, representatives, and employees, directly or through any corporation, subsidiary, division, website, or other device, in connection with the advertising, marketing, promotion, offering for sale, or sale of any product or service, in or affecting commerce, shall not misrepresent in any manner, expressly or by implication, the extent to which respondents maintain and protect the privacy, confidentiality, or integrity of any personal information collected from or about consumers.

II.

IT IS FURTHER ORDERED that respondents and their officers, agents, representatives, and employees, directly or through any corporation, subsidiary, division, website, or other device, shall, no later than the date of service of this order, establish and implement, and thereafter maintain, a comprehensive information security program that is reasonably designed to protect the security, confidentiality, and integrity of personal information collected from or about consumers. Such program, the content and implementation of which must be fully documented in writing, shall contain administrative, technical, and physical safeguards appropriate to respondents’ size and complexity, the nature and scope of respondents’ activities, and the sensitivity of the personal information collected from or about consumers, including: A. the designation of an employee or employees to coordinate and be accountable for the information security program; B. the identification of material internal and external risks to the security, confidentiality, and integrity of personal information that could result in the unauthorized disclosure, misuse, loss, alteration, destruction, or other compromise of such information, and assessment of the sufficiency of any safeguards in place to control these risks. At a minimum, this risk assessment should include consideration of risks in each GENICA CORPORATION 389 Decision and Order area of relevant operation, including, but not limited to, (1) employee training and management, (2) information systems, including network and software design, information processing, storage, transmission, and disposal, and (3) prevention, detection, and response to attacks, intrusions, or other systems failure;

C. the design and implementation of reasonable safeguards to control the risks identified through risk assessment, and regular testing or monitoring of the effectiveness of the safeguards’ key controls, systems, and procedures; D. the development and use of reasonable steps to retain service providers capable of appropriately safeguarding personal information they receive from respondents and requiring service providers by contract to implement and maintain appropriate safeguards; and E. the evaluation and adjustment of respondents’ information security program in light of the results of the testing and monitoring required by subpart C, any material changes to respondents’ operations or business arrangements, or any other circumstances that respondents know or have reason to know may have a material impact on the effectiveness of their information security program.

III.

IT IS FURTHER ORDERED that, in connection with the online advertising, marketing, promotion, offering for sale, or sale of any product or service to consumers, in or affecting commerce, respondents, and their officers, agents, representatives, and employees, shall obtain initial and biennial assessments and reports (“Assessments”) from a qualified, objective, independent third-party professional, who uses procedures and standards generally accepted in the profession. The reporting period for the Assessments shall cover: (1) the first one hundred eighty (180) days after service of the order for the initial Assessment; and (2) each two (2) year period VOLUME 147 Decision and Order thereafter for ten (10) years after service of the order for the biennial Assessments. Each Assessment shall:

A. set forth the specific administrative, technical, and physical safeguards that respondents have implemented and maintained during the reporting period to comply with Part II of this order;

B. explain how such safeguards are appropriate to respondents’ size and complexity, the nature and scope of respondents’ activities, and the sensitivity of the personal information collected from or about consumers;

C. explain how the safeguards that have been implemented meet or exceed the protections required by Part II of this order; and D. certify that respondents’ security program is operating with sufficient effectiveness to provide reasonable assurance that the security, confidentiality, and integrity of personal information is protected and has so operated throughout the reporting period.

Each Assessment shall be prepared and completed within sixty (60) days after the end of the reporting period to which the Assessment applies by: a person qualified as a Certified Information System Security Professional (CISSP) or as a Certified Information Systems Auditor (CISA); a person holding Global Information Assurance Certification (GIAC) from the SysAdmin, Audit, Network, Security (SANS) Institute; or a similarly qualified person or organization approved by the Associate Director for Enforcement, Bureau of Consumer Protection, Federal Trade Commission, Washington, D.C. 20580.

Respondents shall provide the initial Assessment to the Associate Director for Enforcement, Bureau of Consumer Protection, Federal Trade Commission, Washington, D.C. 20580, within ten (10) days after the Assessment has been prepared. All subsequent biennial GENICA CORPORATION 391 Decision and Order Assessments shall be retained by respondents until the order is terminated and provided to the Associate Director of Enforcement within ten (10) days of request.

IV.

IT IS FURTHER ORDERED that respondents shall maintain and upon request make available to the Federal Trade Commission for inspection and copying, a print or electronic copy of: A. for a period of three (3) years after the date of preparation of each Assessment required under Part III of this order, all materials relied upon to prepare the Assessment, whether prepared by or on behalf of the respondents, including but not limited to all plans, reports, studies, reviews, audits, audit trails, policies, training materials, and assessments, and any other materials relating to respondents’ compliance with Parts II and III of this order, for the compliance period covered by such Assessment;

B. unless covered by IV.A, for a period of five (5) years from the date of preparation or dissemination, whichever is later, all other documents relating to compliance with this order, including but not limited to:

1. all advertisements and promotional materials containing any representations covered by this order, with all materials relied upon in disseminating the representation; and 2. any documents, whether prepared by or on behalf of respondents, that call into question respondents’ compliance with this order.

V.

IT IS FURTHER ORDERED that respondents shall deliver a copy of this order to all current and future principals, officers, VOLUME 147 Decision and Order directors, and managers, and to all current and future employees, agents, and representatives having responsibilities relating to the subject matter of this order. Respondents shall deliver this order to such current personnel within thirty (30) days after service of this order, and to such future personnel within thirty (30) days after the person assumes such position or responsibilities. VI.

IT IS FURTHER ORDERED that respondents shall notify the Commission at least thirty (30) days prior to any change in the corporation(s) that may affect compliance obligations arising under this order, including, but not limited to: a dissolution, assignment, sale, merger, or other action that would result in the emergence of a successor corporation; the creation or dissolution of a subsidiary, parent, or affiliate that engages in any acts or practices subject to this order; the proposed filing of a bankruptcy petition; or a change in the corporate name or address. Provided, however, that, with respect to any proposed change in the corporation(s) about which respondents learn fewer than thirty (30) days prior to the date such action is to take place, respondents shall notify the Commission as soon as is practicable after obtaining such knowledge. All notices required by this Part shall be sent by certified mail to the Associate Director, Division of Enforcement, Bureau of Consumer Protection, Federal Trade Commission, Washington, D.C. 20580. VII.

IT IS FURTHER ORDERED that respondents shall, within one hundred eighty (180) days after service of this order, and at such other times as the Commission may require, file with the Commission a report, in writing, setting forth in detail the manner and form in which they have complied with this order. VIII.

This order will terminate on March 16, 2029, or twenty (20) years from the most recent date that the United States or the GENICA CORPORATION 393 Decision and Order Commission files a complaint (with or without an accompanying consent decree) in federal court alleging any violation of the order, whichever comes later; provided, however, that the filing of such a complaint will not affect the duration of: A. any Part in this order that terminates in fewer than twenty (20) years;

B. this order’s application to any respondent that is not named as a defendant in such complaint; and C. this order if such complaint is filed after the order has terminated pursuant to this Part.

Provided, further, that if such complaint is dismissed or a federal court rules that respondent(s) did not violate any provision of the order, and the dismissal or ruling is either not appealed or upheld on appeal, then the order as to such respondent(s) will terminate according to this Part as though the complaint had never been filed, except that the order will not terminate between the date such complaint is filed and the later of the deadline for appealing such dismissal or ruling and the date such dismissal or ruling is upheld on appeal.

By the Commission.

VOLUME 147 Analysis to Aid Public Comment ANALYSIS OF CONSENT ORDER TO AID PUBLIC COMMENT The Federal Trade Commission has accepted, subject to final approval, a consent agreement from Genica Corporation (“Genica”) and Compgeeks.com, also doing business as Computer Geeks Discount Outlet and Geeks.com (“Compgeeks.com”). The proposed consent order has been placed on the public record for thirty (30) days for receipt of comments by interested persons. Comments received during this period will become part of the public record. After thirty (30) days, the Commission will again review the agreement and the comments received, and will decide whether it should withdraw from the agreement and take appropriate action or make final the agreement’s proposed order. Genica and its wholly-owned subsidiary, Compgeeks.com, (collectively “respondents”) sell computer systems, peripherals, and consumer electronics to consumers over the internet, including through a website (www.geeks.com) operated by Compgeeks.com. Respondents operate a computer network that consumers use, in conjunction with the www.geeks.com website and web application, to obtain information and to buy their products. In selling products through the www.geeks.com website, respondents routinely collect sensitive information from consumers to obtain authorization for credit card purchases, including a first and last name, address, e-mail address, telephone number, credit card number, credit card expiration date, and credit card security code (hereinafter “personal information”). This information is particularly sensitive, because it can be used to facilitate payment card fraud and other consumer harm. This matter concerns alleged false or misleading representations respondents made about the security they provided for this information.

The Commission’s complaint alleges that respondents represented that they implemented reasonable and appropriate security measures to protect the privacy and confidentiality of personal information. The complaint alleges that this representation GENICA CORPORATION 395 Analysis to Aid Public Comment was false because respondents engaged in a number of practices that, taken together, failed to provide reasonable and appropriate security for sensitive personal information stored on their network. Among other things, respondents allegedly: (1) stored personal information in clear, readable text; (2) did not adequately assess the vulnerability of their web application and network to commonly known or reasonably foreseeable attacks, such as “Structured Query Language” (“SQL”) injection attacks; (3) did not implement simple, free or low-cost, and readily available defenses to such attacks; (4) did not use readily available security measures to monitor and control connections between computers on the network and from the network to the internet; and (5) failed to employ reasonable measures to detect and prevent unauthorized access to personal information, such as by logging or employing an intrusion detection system.

The complaint further alleges that since at least January 2007 and continuing through at least June 2007, hackers repeatedly exploited these vulnerabilities by using SQL injection attacks on the www.geeks.com website and web application. Through these attacks, the hackers allegedly found personal information stored on respondents’ network and exported the information of hundreds of customers, including credit card numbers, expiration dates, and security codes, over the internet to outside computers. The proposed order applies to personal information respondents collect from or about consumers. It contains provisions designed to prevent respondents from engaging in the future in practices similar to those alleged in the complaint.

Part I of the proposed order prohibits respondents, in connection with the advertising, marketing, promotion, offering for sale, or sale of any product or service, from misrepresenting the extent to which respondents maintain and protect the privacy, confidentiality, or integrity of any personal information collected from or about consumers.

VOLUME 147 Analysis to Aid Public Comment Part II of the proposed order requires respondents to establish and maintain a comprehensive information security program that is reasonably designed to protect the security, confidentiality, and integrity of personal information collected from or about consumers. The written security program must contain administrative, technical, and physical safeguards appropriate to respondents’ size and complexity, the nature and scope of respondents’ activities, and the sensitivity of the personal information collected from or about consumers. Specifically the order requires respondents to: $ Designate an employee or employees to coordinate and be accountable for the information security program; $ Identify material internal and external risks to the security, confidentiality, and integrity of personal information that could result in the unauthorized disclosure, misuse, loss, alteration, destruction, or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks;

$ Design and implement reasonable safeguards to control the risks identified through risk assessment, and regularly test or monitor the effectiveness of the safeguards’ key controls, systems, and procedures;

$ Develop and use reasonable steps to retain service providers capable of appropriately safeguarding personal information they receive from respondents and requiring service providers by contract to implement and maintain appropriate safeguards; and $ Evaluate and adjust respondents’ information security program in light of the results of the testing and monitoring, any material changes to respondents’ operations or business arrangements, or any other circumstances that respondents know or have reason to know may have a material impact on the effectiveness of their information security program. GENICA CORPORATION 397 Analysis to Aid Public Comment Part III of the proposed order requires that respondents, in connection with the online advertising, marketing, promotion, offering for sale, or sale of any product or service to consumers, obtain within 180 days, and on a biennial bases thereafter for a period of ten (10) years, an assessment and report from a qualified, objective, independent third-party professional, certifying, among other things, that respondents have in place a security program that provides protections that meet or exceed the protections required by Part II of the proposed order; and (2) respondents’ security program is operating with sufficient effectiveness to provide reasonable assurance that the security, confidentiality, and integrity of consumers’ personal information is protected. Parts IV through VIII of the proposed order are reporting and compliance provisions. Part IV requires respondents to retain documents relating to their compliance with the order. For most records, the order requires that the documents be retained for a fiveyear period. For the third-party assessments and supporting documents, respondents must retain the documents for a period of three years after the date that each assessment is prepared. Part V requires dissemination of the order now and in the future to persons with responsibilities relating to the subject matter of the order. Part VI ensures notification to the FTC of changes in corporate status. Part VII mandates that respondents submit an initial compliance report to the FTC, and make available to the FTC subsequent reports. Part VIII is a provision “sunsetting” the order after twenty (20) years, with certain exceptions.

The purpose of the analysis is to aid public comment on the proposed order. It is not intended to constitute an official interpretation of the proposed order or to modify its terms in any way.

VOLUME 147 Complaint

← 147 F.T.C. 328 · 147 F.T.C. 398 →