Imagine a chief compliance officer closing out an internal privacy review.
No material issues found. The report is approved. Leadership is briefed. The team moves on to other priorities.
Six months later, a Civil Investigative Demand arrives from the FTC.
The questions focus on data practices the review never flagged because the assessment reflected the organization's operations at that moment — not the features, vendors, and data flows added afterward.
Nobody in the room can say exactly when the organization's exposure changed.
They only know the review that once looked reassuring no longer describes what the company actually does.
A Compliance Calendar Is Not a Shield
The FTC's 2026 enforcement activity is not waiting for internal audit cycles to catch up. Recent actions involving sensitive location data and privacy promises that did not match operational practices show the agency continuing to use its existing authority rather than waiting for Congress to enact a new privacy law.
Privacy risk does not age gradually — it changes the moment your data practices change. Governance that is not continuously updated eventually becomes historical documentation, not operational protection.
The FTC Doesn't Need a New Law to Act
The FTC continues to use Section 5 of the FTC Act against allegedly unfair or deceptive data practices. On May 4, 2026, the FTC announced a proposed stipulated order involving data broker Kochava and its subsidiary, Collective Data Solutions, that would — subject to court approval — prohibit the companies from selling, sharing, licensing, transferring, or disclosing sensitive location data without consumers' affirmative express consent. On March 30, 2026, the FTC filed a complaint and stipulated order involving Match Group Americas and Humor Rainbow, the operator of OkCupid, alleging the company gave an unrelated third party access to users' personal information — including photos and location information — contrary to representations in its privacy policy.
Separately, the amended Children's Online Privacy Protection Rule was published in April 2025, with most regulated entities required to comply by April 22, 2026, subject to limited exceptions. The amendments strengthen requirements around consent, data retention, disclosure, and the handling of children's personal information. The central lesson across all of it: the FTC does not need a new comprehensive privacy statute to challenge practices it considers unfair or deceptive.
Five Red Flags Every Compliance Team Should Check
If an assessment does not identify when it expires — or which operational changes require reassessment — it becomes stale by default. The problem isn't that the original review was wrong; it's that nobody defined how long its conclusions would remain reliable.
The Kochava matter illustrates the scrutiny applied to the sale, transfer, sharing, and disclosure of sensitive location data, including whether meaningful consumer consent exists. A data flow introduced after an assessment may create exposure the original reviewers never evaluated.
The OkCupid action illustrates the risk created when public privacy representations do not match operational practices. A privacy policy is a representation regulators may compare against what the product, engineering systems, and vendors actually do.
A contract may accurately describe the relationship that existed when it was signed while saying little about the data now being processed. New features, integrations, analytics tools, and subprocessors can quietly outgrow the original assessment.
If legal, privacy, product, security, and engineering teams cannot describe the organization's current compliance threshold, each team may be operating from a different version of reality. Governance breaks when "reviewed" is treated as synonymous with "current."
Who Feels the Gap Between Reviewed and Current
Legal and Compliance Teams
Point-in-time assessments lose value when business practices change but the underlying analysis does not. The operational question is no longer simply "Was this reviewed?" It is: "Does the review still describe what the organization does today?"
Product and Engineering Teams
Every new feature, SDK, analytics integration, location capability, and vendor connection can change the privacy analysis. A technically small release may create a legally significant data flow.
Executive Leadership
A board may be told the organization's privacy posture is sound based on a review that was accurate when delivered. If an investigation later reveals that the product, vendors, or data practices changed without reassessment, the credibility problem becomes larger than the original compliance issue — the gap between reviewed and current becomes the story.
For Organizations
- Inventory every privacy assessment completed during the last 12 months.
- Identify the business, product, vendor, and data-flow changes that occurred after each assessment.
- Define specific re-trigger events, including new vendors, new data categories, new purposes, new disclosures, and material product releases.
- Compare public privacy statements with what engineering, product, and vendor-management teams say the organization currently does.
- Assign one accountable owner to monitor relevant FTC enforcement developments and translate them into internal reassessment triggers.
For Individuals
- Ask when the products and services you use last updated their privacy disclosures.
- Review whether a service has introduced new tracking, personalization, location, or data-sharing features.
- Revisit privacy settings after major product changes rather than assuming previous choices still apply.
- Question whether a company's public privacy promises clearly explain its current third-party sharing practices.
Unpopular Opinion
An annual privacy review is often a compliance ritual — not a defense. If it does not update when data practices change, its conclusions may already be obsolete.
Myth vs Reality
Myth: Passing a privacy review protects the organization until the next scheduled assessment.
Reality: The FTC does not check the organization's audit calendar before examining its current practices.
If the FTC requested your privacy documentation tomorrow, would it describe your current data practices — or the ones your organization had six months ago?
Poll
When does your organization reassess privacy risk after an initial review?