Federal Trade Commission Chairman Andrew Ferguson told reporters on June 18, 2026, that the agency is heading into a stretch of privacy enforcement so heavy that people covering it would "have a hard time keeping up with the number of cases we're gonna be bringing." Three weeks later, the docket started proving him right. The FTC settled with tenant-screening company RentGrow on July 9, four days after a Fair Credit Reporting Act settlement with Amazon on June 30, which itself landed four days after the agency finalized a ban on Kochava's sale of sensitive location data on June 26. Add the March 30 settlement with Match Group and OkCupid over data shared with an outside AI firm, and four privacy or privacy-adjacent enforcement actions have landed inside four months, with the gaps between them shrinking sharply in the weeks around Ferguson's statement. None of that counts the $2.5 billion Amazon separately agreed to pay over its Prime enrollment design, a case still working through a July 27, 2026 consumer claims deadline. For any business whose defense against this kind of case starts with an accurate privacy policy, the direction the FTC is signaling is not subtle.

Privacy + Security Academy's session description for "FTC Privacy Enforcement in 2026 and Beyond," evidence that the enforcement trend has become its own conference topic

Source: Privacy + Security Academy, "FTC Privacy Enforcement in 2026 and Beyond", captured August 1, 2026.

What Ferguson actually told reporters

Ferguson's June 18 comments came two months after his first appearance before the Senate Commerce Committee's oversight hearing of the FTC in six years, where he told lawmakers the agency's near-term focus included hidden fees, misleading pricing, and continued scrutiny of deceptive online design. By June, Ferguson was framing the FTC's caseload for the rest of 2026 in blunter terms, according to reporting from MLex: more privacy cases than the agency's watchers could easily follow, with additional personnel and computing capacity potentially on the way if Congress advances the proposed SECURE Data Act, which would expand the FTC's role as the primary federal privacy enforcer. He also pointed to the TAKE IT DOWN Act, in force since May 19, 2026, as an example of Congress handing the agency both a new mandate and the resources to enforce it.

The agency's own independence is facing a separate legal test this year, one we covered in our look at the EU-US Data Privacy Framework's legal risk, but that uncertainty has not visibly slowed the pace of case filings. Ferguson was not speculating about what regulators might eventually do. He was the sitting FTC chairman describing, on the record, an enforcement pipeline he said was already loaded.

Four cases in four months

The Match Group and OkCupid action came first, on March 30, 2026: the FTC alleged OkCupid gave an outside artificial intelligence firm, Clarifai, unrestricted access to users' photographs, geolocation data, and other sensitive information despite OkCupid's own privacy policy promising otherwise, an arrangement the agency traced back to early OkCupid investors who also held a stake in Clarifai. The proposed order would bar OkCupid and Match from misrepresenting how they handle user data for 20 years and require annual compliance reporting for a decade.

Kochava's case, originally filed in August 2022, reached its conclusion on June 26, 2026, when the FTC finalized an order prohibiting Kochava and its Collective Data Solutions subsidiary from selling, licensing, or otherwise disclosing sensitive location data, including data tied to visits to health clinics and places of worship, unless the company first obtains a consumer's affirmative express consent connected to a service the consumer actually asked for.

Four days later, on June 30, the FTC settled a separate Fair Credit Reporting Act case against Amazon for $2.25 million, over allegations the company knowingly refused to give identity theft victims the transaction records they needed to dispute fraudulent charges made in their name. Nine days after that, on July 9, RentGrow agreed to pay the same $2.25 million to resolve FCRA allegations that its tenant-screening reports duplicated criminal and eviction records, mishandled consumer disputes, and failed to disclose that part of its data came from a LexisNexis product called Accurint.

None of the four cases matches the $2.5 billion Amazon agreed to pay last year over Prime's enrollment and cancellation design, a case whose consumer claims window does not close until July 27, 2026. What the four newer cases share instead is a common underlying pattern: personal data changing hands, being sold, or being described to consumers in terms that did not match what the company was actually doing with it.

The pace is the real story

Days between recent FTC privacy enforcement actions Match/OkCupid to Kochava88 daysKochava to Amazon FCRA4 daysAmazon FCRA to RentGrow9 days

Figure: Days elapsed between each of the FTC's four privacy and privacy-adjacent actions since March 2026. Source: FTC press releases and case dockets for each action.

Match/OkCupid to Kochava's finalized order spans 88 days, a gap consistent with routine casework moving through the agency's normal pace. What changed is what came after: Kochava to the Amazon FCRA settlement took four days, and Amazon to RentGrow took nine. Both of the shortest gaps sit inside the same window as Ferguson's June 18 statement, which is one reason his warning read less like a general prediction and more like a chairman describing a caseload his staff was already clearing.

What is actually driving the caseload

Read the four cases together and three fact patterns keep showing up. The first is deceptive data-sharing claims: a company's privacy policy or marketing promises one thing about who gets access to a user's data, and the company's actual practice, as with OkCupid and Clarifai, is something else. The second is dark patterns in how consent and cancellation are designed, the same underlying issue behind the $2.5 billion Amazon Prime settlement, where the FTC argued the enrollment flow was easy and the cancellation flow deliberately was not. The third is undisclosed or under-disclosed data sales, whether that means Kochava selling sensitive location data without the affirmative consent the FTC says the practice requires, or RentGrow failing to tell consumers where part of their tenant-screening data actually came from.

None of the three patterns needs a novel legal theory to prosecute. Section 5 of the FTC Act has banned unfair and deceptive practices for decades, and the FCRA's accuracy and disclosure requirements are not new either. What Ferguson's statement signals is enforcement intensity against practices the agency already has clear authority to pursue, a more immediate risk for most businesses than waiting on federal privacy legislation that has not passed.

Why your privacy policy is the first line of defense

Every one of the four recent cases turns, at least in part, on a gap between what a company told consumers about its data practices and what the company actually did. OkCupid's privacy policy did not disclose the access it gave Clarifai. Kochava's location-data sales outran the consent standard the FTC says the practice needs. RentGrow did not tell consumers that part of their report came from a specific third-party data source. In each case, the regulator did not have to prove some novel harm. It had to show the practice and the disclosure did not match.

That mismatch is exactly what an accurate privacy policy closes. A policy has to describe the categories of personal information a business actually collects, name the categories of third parties it actually shares or sells that information to, and reflect the consent and opt-out mechanisms genuinely in place, not a generic template's assumptions about what a similar business probably does. Our Privacy Policy Generator builds those disclosures around your business's real data-sharing relationships, third-party integrations, and consent flows, so what you publish matches what your business is actually doing with personal data rather than describing a version of your practices that would not survive the kind of scrutiny Ferguson says is coming.

The information in this article is for informational purposes only and should not be construed as legal advice on any matter, and does not create a lawyer-client relationship.