Consumer Law Library

Sentinel Labs, Inc.

Volume 163 · 163 F.T.C. 488

Citation
163 F.T.C. 488
Docket
C-4608
Complaint
2017-03-29
Decision
2017-03-29
Document type
consent order
Case type
consumer protection
Statutes
FTC Act (section 5)
Industry
endpoint protection software
Outcome
consent order entered
Relief
cease_and_desist; compliance_reporting; recordkeeping
Order term (years)
20
Source
Original volume PDF
Original PDF
This decision as a PDF

deceptive advertisingprivacy data securityonline internet

Cite this decision

Sentinel Labs, Inc., 163 F.T.C. 488 (2017). Consumer Law Library, https://consumerlawlibrary.org/decisions/v163-0012

Report an error in this record (decision id v163-0012)

Order status: active_until:2037-03-29. Sunset may be extended by the latest qualifying federal-court complaint alleging an order violation; complaints, dismissal/appeal outcomes, and respondent-specific extensions are not fully tracked.

Cited by 0 later FTC decisions

Cites

Text (OCR of the scan at left; may contain errors)

IN THE MATTER OF SENTINEL LABS, INC.

D/B/A SENTINELONE AND SENTINELONE.COM CONSENT ORDER, ETC. IN REGARD TO ALLEGED VIOLATIONS OF SECTION 5 OF THE FEDERAL TRADE COMMISSION ACT Docket No. C-4608; File No. 162 3250 Complaint, March 29, 2017 – Decision, March 29, 2017 This consent order addresses Sentinel Labs, Inc.’s alleged false representations that SentinelOne made to consumers concerning its participation in the Asia- Pacific Economic Cooperation (“APEC”) Cross Border Privacy Rules (“CBPR”) system. The complaint alleges that SentinelOne falsely represented that it was a participant in the APEC CBPR system and a TRUSTe privacy program when, in fact, it never sought or obtained either certification. The consent order prohibits SentinelOne from making misrepresentations about its participation in any privacy or security program sponsored by a government or any self-regulatory or standard-setting organization, including, but not limited to, the APEC CBPR and the TRUSTe privacy programs. Participants For the Commission: Monique F. Einhorn. For the Respondents: Janis Kestenbaum, Perkins Coie. COMPLAINT The Federal Trade Commission (“Commission” or “FTC”), having reason to believe that Sentinel Labs, Inc., a corporation, has violated the Federal Trade Commission Act (“FTC Act”), and it appearing to the Commission that this proceeding is in the public interest, alleges:

1. Respondent Sentinel Labs, Inc. is a Delaware corporation also doing business as SentinelOne and SentinelOne.com with a principal office or place of business at 2513 E. Charleston Road, Suite 100, Mountain View, CA 94043.

2. Respondent provides endpoint protection software to enterprise customers.

SENTINEL LABS, INC. 489 Complaint 3. The acts and practices of Respondent as alleged in this complaint have been in or affecting commerce, as “commerce” is defined in Section 4 of the FTC Act.

4. Respondent has set forth on its website, https://sentinelone.com/privacy-policy/, privacy policies and statements about its practices, including (1) statements related to its participation in the Asia-Pacific Economic Cooperation (“APEC”) Cross-Border Privacy Rules (“CBPR”) system, and (2) statements related to its TRUSTe privacy certification. APEC & the Cross-Border Privacy Rules 5. The APEC CBPR system is a self-regulatory initiative designed to facilitate the protection of consumer data transferred across the APEC region. The CBPR system requires participants to abide by the APEC Privacy Framework’s nine information privacy principles: preventing harm, notice, collection limitation, use, choice, integrity, security safeguards, access and correction, and accountability. In the United States, the FTC enforces the CBPR system.

6. Companies that seek to participate in the CBPR system must undergo a review by an APEC-recognized accountability agent to establish compliance with the CBPR program requirements. Companies undergo annual reviews to retain their status as certified CBPR participants. The names of certified companies are posted on a website, www.cbprs.org. TRUSTe Privacy Certification 7. True Ultimate Standards Everywhere, Inc. (“TRUSTe”) provides privacy certifications and seals to businesses. A business that meets TRUSTe’s designated program requirements for a particular certification program receives a corresponding seal for display on the business’s website. Program requirements include specifications related to the transparency of company practices, verification of privacy practices, and consumer choice regarding the collection and use of consumer personal information.

VOLUME 163 Complaint Violations of Section 5 of the FTC Act 8. Respondent has disseminated or caused to be disseminated privacy policies and statements on https://sentinelone.com/privacy-policy/, including, but not limited to, the following statements:

Sentinel One has received TRUSTe’s Privacy Seal which means that this Privacy Policy and our practices have been reviewed by TRUSTe for compliance with its requirements regarding transparency, accountability and choice regarding the collection and use of your personal information. The TRUSTe certification only covers information collected on our site www.Sentinel One.com and Sentinel One mobile application. The TRUSTe certification does not cover any information collected through any other application or medium. In addition, Sentinel Ones [sic] privacy practices, as described in this policy, comply with the APEC Cross Border Privacy Rules System. To learn more, please visit http://www.apec.org/Groups/Committee-on- Trade-and- Investment/~/media/Files/Groups/ECSG/CBPR/C BPR-PoliciesRulesGuidelines.ashx. . . Any questions about this Privacy Policy should be addressed to support@Sentinel One.com [sic] or to 4440 El Camino Real, Los Altos, CA 94022. Count 1 9. Through the means described in Paragraph 8, Respondent represented, directly or indirectly, expressly or by implication, that it is certified to participate in the APEC CBPR system. 10. In fact, Respondent is not and never has been certified to participate in the APEC CBPR system. Therefore, the representation set forth in Paragraph 9 is false or misleading. SENTINEL LABS, INC. 491 Decision and Order Count 2 11. Through the means described in Paragraph 8, Respondent represented, directly or indirectly, expressly or by implication, that a third party, TRUSTe, reviewed its privacy policy and privacy practices and verified that Respondent complies with its requirements relating to the privacy of personal information. 12. In fact, the third party did not review Respondent’s privacy policy and privacy practices, and did not verify that Respondent complies with its requirements relating to the privacy of personal information. Therefore, the representation set forth in Paragraph 11 is false or misleading.

13. The acts and practices of Respondent as alleged in this complaint constitute deceptive acts or practices, in or affecting commerce, in violation of Section 5(a) of the Federal Trade Commission Act.

THEREFORE, the Federal Trade Commission, this twentyninth day of March, 2017, has issued this complaint against Respondent.

By the Commission.

DECISION The Federal Trade Commission (“Commission”) initiated an investigation of certain acts and practices of the Respondent named above in the caption. The Commission’s Bureau of Consumer Protection (“BCP”) prepared and furnished to Respondent a draft Complaint. BCP proposed to present the draft Complaint to the Commission for its consideration. If issued by the Commission, the draft Complaint would charge Respondent with violation of the Federal Trade Commission Act. VOLUME 163 Decision and Order Respondent and BCP thereafter executed an Agreement Containing Consent Order (“Consent Agreement”). The Consent Agreement includes: 1) statements by Respondent that it neither admits nor denies any of the allegations in the Complaint, except as specifically stated in this Decision and Order, and that only for purposes of this action, it admits the facts necessary to establish jurisdiction; and 2) waivers and other provisions as required by the Commission’s Rules.

The Commission considered the matter and determined that it had reason to believe that Respondent has violated the Federal Trade Commission Act, and that a Complaint should issue stating its charges in that respect. The Commission accepted the executed Consent Agreement and placed it on the public record for a period of 30 days for the receipt and consideration of public comments, pursuant to Commission Rule 2.34, 16 C.F.R. § 2.34. Now, in further conformity with the procedure prescribed in Rule 2.34, the Commission issues its Complaint, makes the following Findings, and issues the following Order: Findings 1. Respondent Sentinel Labs, Inc. is a Delaware corporation also doing business as SentinelOne and SentinelOne.com with a principal office or place of business at 2513 E. Charleston Road, Suite 100, Mountain View, CA 94043.

2. The Commission has jurisdiction over the subject matter of this proceeding and over Respondent, and the proceeding is in the public interest.

ORDER Definitions For purposes of this Order, the following definitions apply: A. “Respondent” means Sentinel Labs, Inc., a corporation also dba as SentinelOne and SentinelOne.com, and its successors and assigns.

SENTINEL LABS, INC. 493 Decision and Order B. “APEC CBPR” means the Asia-Pacific Economic Cooperation (“APEC”) Cross-Border Privacy Rules (“CBPR”) system.

Provisions I. Prohibition against Misrepresentations about Participation in Privacy or Security Programs IT IS ORDERED that Respondent and its officers, agents, employees, and attorneys, and all other persons in active concert or participation with any of them, who receive actual notice of this order, whether acting directly or indirectly, in connection with the advertising, marketing, promotion, offering for sale, or sale of any product or service must not misrepresent in any manner, expressly or by implication, the extent to which Respondent is a member of, adheres to, complies with, is certified by, is endorsed by, or otherwise participates in any privacy or security program sponsored by a government or any self-regulatory or standardsetting organization, including, but not limited to APEC CBPR and the TRUSTe privacy programs.

II. Acknowledgments of the Order IT IS FURTHER ORDERED that Respondent obtain acknowledgments of receipt of this Order: A. Respondent, within 10 days after the effective date of this Order, must submit to the Commission an acknowledgment of receipt of this Order. B. For five (5) years after the issuance date of this Order, Respondent must deliver a copy of this Order to: (1) all principals, officers, directors, and LLC managers and members; (2) all employees, agents, and representatives with responsibilities related to the subject matter of the Order; and (3) any business entity resulting from any change in structure as set forth in the Provision titled Compliance Reporting. Delivery must occur within ten (10) days after the effective date of this Order for current personnel. For all others, VOLUME 163 Decision and Order delivery must occur before they assume their responsibilities.

C. From each individual or entity to which Respondent delivered a copy of this Order, Respondent must obtain, within thirty (30) days, a signed and dated acknowledgment of receipt of this Order. III. Compliance Report and Notices IT IS FURTHER ORDERED that Respondent make timely submissions to the Commission:

A. Ninety (90) days after the issuance date of this Order, Respondent must submit a compliance report, sworn under penalty of perjury, in which Respondent must: (a) identify the primary physical, postal, and email address and telephone number, as designated points of contact, which representatives of the Commission, may use to communicate with Respondent; (b) identify all of Respondent’s businesses by all of their names, telephone numbers, and physical, postal, email, and Internet addresses; (c) describe the activities of each business; (d) describe in detail whether and how Respondent is in compliance with each Provision of this Order; and (e) provide a copy of each Acknowledgment of the Order obtained pursuant to this Order, unless previously submitted to the Commission.

B. Respondent must submit a compliance notice, sworn under penalty of perjury, within 14 days of any change in the following: (1) any designated point of contact; or (2) the structure of Respondent or any entity that Respondent has any ownership interest in or controls directly or indirectly that may affect compliance obligations arising under this Order, including: creation, merger, sale, or dissolution of the entity or any subsidiary, parent, or affiliate that engages in any acts or practices subject to this Order. SENTINEL LABS, INC. 495 Decision and Order C. Respondent must submit notice of the filing of any bankruptcy petition, insolvency proceeding, or similar proceeding by or against Respondent within 14 days of its filing.

D. Any submission to the Commission required by this Order to be sworn under penalty of perjury must be true and accurate and comply with 28 U.S.C. § 1746, such as by concluding: “I declare under penalty of perjury under the laws of the United States of America that the foregoing is true and correct. Executed on: _____” and supplying the date, signatory’s full name, title (if applicable), and signature.

E. Unless otherwise directed by a Commission representative in writing, all submissions to the Commission pursuant to this Order must be emailed to [email protected] or sent by overnight courier (not the U.S. Postal Service) to: Associate Director of Enforcement, Bureau of Consumer Protection, Federal Trade Commission, 600 Pennsylvania Avenue, N.W., Washington, D.C. 20580. The subject line must begin: In re Sentinel Labs, Inc., FTC File No. 1623250. IV. Recordkeeping IT IS FURTHER ORDERED that Respondent must create certain records for twenty (20) years after the issuance date of the Order, and retain each such record for 5 (five) years. Specifically, Respondent must create and retain the following records: A. accounting records showing the revenues from all goods or services sold;

B. personnel records showing, for each person providing services in relation to any aspect of the Order, whether as an employee or otherwise, that person’s: name; addresses; telephone numbers; job title or position; dates of service; and (if applicable) the reason for termination;

VOLUME 163 Decision and Order C. all records necessary to demonstrate full compliance with each provision of this Order, including all submissions to the Commission; and D. a copy of each unique advertisement, promotional material, or other marketing material making any representation subject to this Order, and the materials that were relied upon in making the representation. V. Compliance Monitoring IT IS FURTHER ORDERED that, for the purpose of monitoring Respondent’s compliance with this Order: A. Within ten (10) days of receipt of a written request from a representative of the Commission, Respondent must: submit additional compliance reports or other requested information, which must be sworn under penalty of perjury, and produce records for inspection and copying.

B. For matters concerning this Order, representatives of the Commission are authorized to communicate directly with Respondent. Respondent must permit representatives of the Commission to interview anyone affiliated with Respondent who has agreed to such an interview. The interviewee may have counsel present. C. The Commission may use all other lawful means, including posing through its representatives as consumers, suppliers, or other individuals or entities, to Respondent or any individual or entity affiliated with Respondent, without the necessity of identification or prior notice. Nothing in this Order limits the Commission’s lawful use of compulsory process, pursuant to Sections 9 and 20 of the FTC Act, 15 U.S.C. §§ 49, 57b-1.

SENTINEL LABS, INC. 497 Decision and Order VI. Order Effective Dates IT IS FURTHER ORDERED that this Order is final and effective upon the date of its publication on the Commission’s website (ftc.gov) as a final order. This Order will terminate on March 29, 2037, or twenty (20) years from the most recent date that the United States or the Commission files a complaint (with or without an accompanying settlement) in federal court alleging any violation of the Order, whichever comes later; provided, however, that the filing of such a complaint will not affect the duration of:

A. any Provision in this Order that terminates in less than twenty (20) years;

B. this Order’s application to any Respondent that is not named as a defendant in such complaint; and C. this Order if such complaint is filed after the order has terminated pursuant to this Provision. If such complaint is dismissed or a federal court rules that Respondent did not violate any provision of the Order, and the dismissal or ruling is either not appealed or upheld on appeal, then the Order as to Respondent will terminate according to this Provision as though the complaint had never been filed, except that the Order will not terminate between the date such complaint is filed and the later of the deadline for appealing such dismissal or ruling and the date such dismissal or ruling is upheld on appeal.

By the Commission.

VOLUME 163 Analysis to Aid Public Comment ANALYSIS OF CONSENT ORDER TO AID PUBLIC COMMENT The Federal Trade Commission (“FTC” or “Commission”) has accepted, subject to final approval, a consent agreement applicable to Sentinel Labs, Inc. dba SentinelOne and SentinelOne.com (“SentinelOne”).

The proposed consent order has been placed on the public record for thirty (30) days for receipt of comments by interested persons. Comments received during this period will become part of the public record. After thirty days, the Commission will again review the agreement and the comments received, and will decide whether it should withdraw from the agreement and take appropriate action or make final the agreement's proposed order. This matter concerns alleged false representations that SentinelOne made to consumers concerning its participation in the Asia-Pacific Economic Cooperation (“APEC”) Cross Border Privacy Rules (“CBPR”) system. The APEC CBPR system is a voluntary, enforceable mechanism that certifies a company’s compliance with the principles in the CBPR and facilitates privacy-respecting transfers of data amongst APEC member economies. The APEC CBPR system is based on nine data privacy principles: preventing harm, notice, collection limitation, use choice, integrity, security safeguards, access and correction, and accountability. Companies that seek to participate in the APEC CBPR system must undergo a review by an APECrecognized Accountability Agent, which certifies companies that meet the standards.

Companies under the FTC’s jurisdiction are eligible to apply for APEC CBPR certification. The names of certified companies are posted on a public-facing website, www.cbprs.org. Companies must re-apply annually in order to retain their status as current participants in the APEC CBPR system. A company that falsely claims APEC CBPR participation may be subject to an enforcement action based on the FTC’s deception authority under Section 5 of the FTC Act.

SentinelOne provides endpoint protection software to enterprise customers. According to the Commission's complaint, SENTINEL LABS, INC. 499 Analysis to Aid Public Comment SentinelOne has set forth on its website, https://www.sentinelone .com/privacy-policy/, privacy policies and statements about its practices, including statements related to its participation in the APEC CBPR system.

The Commission's complaint alleges that SentinelOne falsely represented that it was a participant in the APEC CBPR system and a TRUSTe privacy program when, in fact, it never sought or obtained either certification.

Part I of the proposed order prohibits SentinelOne from making misrepresentations about its participation in any privacy or security program sponsored by a government or any selfregulatory or standard-setting organization, including, but not limited to, the APEC CBPR and the TRUSTe privacy programs. Parts II through VI of the proposed order are reporting and compliance provisions. Part II requires acknowledgment of the order and dissemination of the order now and in the future to persons with responsibilities relating to the subject matter of the order. Part III ensures notification to the FTC of changes in corporate status and mandates that SentinelOne submit an initial compliance report to the FTC. Part IV requires SentinelOne to retain documents relating to its compliance with the order. Part V mandates that SentinelOne make available to the FTC information or subsequent compliance reports, as requested. Part VI is a provision “sunsetting” the order after twenty (20) years, with certain exceptions.

The purpose of this analysis is to facilitate public comment on the proposed order. It is not intended to constitute an official interpretation of the proposed complaint or order or to modify the order’s terms in any way.

VOLUME 163 Complaint

← 163 F.T.C. 477 · 163 F.T.C. 500 →