The Federal Trade Commission announced a settlement order against Avast Limited, requiring the UK-based software company to pay $16.5 million and banning it from selling or licensing web browsing data for advertising purposes, resolving charges that the company sold users' detailed browsing information after promising its products would protect them from online tracking.DOCUMENTED
The FTC's complaint alleges that, through its Czech subsidiary, Avast unfairly collected consumers' browsing information since at least 2014 through the company's browser extensions and antivirus software, stored it indefinitely, and sold it without adequate notice or consumer consent.DOCUMENTED
- Avast will pay $16.5 million, used to compensate consumers, and is permanently banned from selling browsing data for advertising.
- The FTC alleges Avast collected browsing data dating back to at least 2014 through antivirus software and browser extensions.
- Avast sold the data — more than 8 petabytes in total — to more than 100 third parties through its subsidiary Jumpshot.
- The collected information revealed users' religious beliefs, health concerns, political leanings, location, and financial status.
- The FTC has since sent claim notices to more than 3.5 million eligible consumers who bought Avast antivirus software between 2014 and 2020.
A privacy promise, and what happened behind it
Since at least 2014, the FTC says Avast collected consumers' browsing information through browser extensions and antivirus software installed on computers and mobile devices — including information revealing users' web searches and the webpages they visited, data that could expose religious beliefs, health concerns, political leanings, location, financial status, and visits to child-directed content.DOCUMENTED
According to the complaint, Avast did not merely fail to disclose this collection — it affirmatively marketed its products as protecting user privacy. When consumers searched for Avast's browser extensions, they were told the product would "block annoying tracking cookies that collect data on your browsing activities," and the company promised its desktop software would "shield your privacy."DOCUMENTED
The scale of the data sale
After Avast acquired Jumpshot, a competing antivirus provider, the company rebranded the firm as an analytics business. From 2014 to 2020, Jumpshot sold the browsing information Avast had collected from consumers to a range of clients, including advertising, marketing, and data-analytics companies and data brokers, according to the complaint.DOCUMENTED The FTC alleges Avast's total collected dataset ran to more than 8 petabytes — roughly 8,000 terabytes — of consumer browsing data, sold to more than 100 third parties through products including an "All Clicks Feed" that tracked every URL a particular consumer clicked during a browsing session.DOCUMENTED
The company claimed it used a special algorithm to remove identifying information before transferring the data to clients, but the FTC's complaint alleges the data remained detailed and re-identifiable, meaning individual consumers could potentially be identified from the supposedly anonymized browsing records.DOCUMENTED
Avast's collected dataset ran to more than 8 petabytes of browsing data, sold to over 100 third parties — while the company's own marketing promised to shield users' privacy.
What the order requires
The settlement order prohibits Avast from selling, licensing, transferring, or otherwise disclosing browsing information collected from any Avast-branded product to a third party for advertising purposes, without affirmative express consumer consent.DOCUMENTED It also bars the company from misrepresenting the purpose of its data collection or the extent to which it anonymizes information, and requires Avast to delete and destroy the data Jumpshot had collected, and to instruct any buyers of that data to do the same.DOCUMENTED Avast must also implement a comprehensive privacy program, subject to independent review every two years for the next 20 years, and must certify annually that it has maintained that program as ordered.DOCUMENTED
Getting money back to affected consumers
The FTC finalized the settlement order in June 2024. Beginning in February 2025, the agency started sending email notices to more than 3.5 million people who bought Avast antivirus software between August 2014 and January 2020, informing them they may be eligible for a redress payment.DOCUMENTED The agency later sent nearly $15.3 million in payments to 103,152 Avast customers who filed valid claims, reflecting how the settlement's $16.5 million fund was ultimately distributed among the pool of eligible, claim-filing consumers.DOCUMENTED
Why the case set a benchmark for browsing-data enforcement
The Avast settlement remains one of the FTC's most detailed enforcement actions addressing the sale of granular consumer browsing data, both for the scale of data involved and for the directness of the gap between the company's stated privacy promises and its underlying business model.REVIEWED The case illustrates a recurring theme in the FTC's privacy enforcement: software explicitly marketed as protecting user privacy carries a particular obligation to ensure its actual data practices match that marketing, since consumers who purchase a privacy-focused product have even less reason than usual to expect their information is being collected and monetized behind the scenes.REVIEWED
The re-identification problem
Avast's defense, as reflected in its marketing, rested heavily on the idea that any data it sold had been anonymized or aggregated before reaching a buyer — a claim companies across the advertising-technology industry commonly make to justify data-sharing practices under privacy law.REVIEWED The FTC's complaint challenges that defense directly, alleging the browsing records sold through Jumpshot remained detailed and re-identifiable — meaning a sufficiently motivated buyer with access to other data sources could plausibly connect specific browsing histories back to identifiable individuals, defeating the purpose of anonymization.REVIEWED Re-identification risk has become a central technical and legal question across privacy enforcement generally, since a browsing history containing a person's searches, visited pages, and click patterns over time can often be uniquely identifying even without an attached name, given how distinctive an individual's combined online behavior tends to be.REVIEWED
For any software company marketing a privacy or security benefit as part of its core value proposition, the Avast case stands as a clear warning that the underlying data-handling practices need to match the marketing exactly — a mismatch between a privacy promise and an actual data-monetization business model is treated by the FTC as a serious deception, not a technical footnote.REVIEWED
Sources behind this report
Have documents relevant to this story? Reach us through our tips channel.