PogoWasRight.org

Menu
  • About
  • Privacy
Menu

Retail Tracking Firm Settles FTC Charges it Misled Consumers About Opt Out Choices

Posted on April 23, 2015June 26, 2025 by Dissent

Nomi Technologies, a company whose technology allows retailers to track consumers’ movements through their stores, has agreed to settle Federal Trade Commission charges that it misled consumers with promises that it would provide an in-store mechanism for consumers to  opt out of tracking and that consumers would be informed when locations were using Nomi’s tracking services.

The FTC’s complaint against Nomi states that beginning in late 2012, the company’s privacy policy promised that Nomi would provide an opt-out mechanism at stores using its services.  This promise implied that consumers would be informed when stores were using Nomi’s tracking technology. The complaint alleges that these promises were not true because no in-store opt-out mechanism was available, and consumers were not informed when the tracking was taking place.

The complaint alleges that Nomi collected information on about nine million mobile devices within the first nine months of 2013. The complaint is the FTC’s first against a retail tracking company.

“It’s vital that companies keep their privacy promises to consumers when working with emerging technologies, just as it is in any other context,” said Jessica Rich, Director of the FTC’s Bureau of Consumer Protection. “If you tell a consumer that they will have choices about their privacy, you should make sure all of those choices are actually available to them.”

Nomi, according to the complaint, places sensors in its clients’ stores that collect the MAC addresses of consumers’ mobile devices as the devices search for WiFi networks.  MAC addresses are unique 12-digit identifiers that are assigned to individual mobile devices.  Although Nomi “hashes” the MAC addresses prior to storing them, the hashing process still results in an identifier that is unique to a consumer’s mobile device and can be tracked over time.

The complaint alleges that Nomi tracked consumers both inside and outside their clients’ stores, tracking the MAC address, device type, date and time the device was observed, and signal strength of consumers’ devices. In reports to clients, Nomi provided aggregated information on how many consumers passed by the store instead of entering, how long consumers stayed in the store, the types of devices used by consumers, how many repeat customers enter a store in a given period and how many customers had visited another location in a particular chain of stores.

The company’s privacy policy said that it “pledged to… always allow consumers to opt out of Nomi’s service on its website, as well as at any retailer using Nomi’s technology.” While the company did provide an opt-out on its website, the complaint alleges that no such option was available at retailers using the service, and that consumers were not informed of the tracking taking place in the stores at all.

Under the terms of the settlement with the FTC, Nomi will be prohibited from misrepresenting consumers’ options for controlling whether information is collected, used, disclosed or shared about them or their computers or other devices, as well as the extent to which consumers will be notified about information practices.

The Commission held a privacy seminar on the issue of mobile device tracking in the retail environment as part of its spring privacy series last year.

The Commission vote to issue the complaint and accept the proposed consent order was 3-2, with Commissioners Maureen K. Ohlhausen and Joshua D. Wright dissenting. Chairwoman Edith Ramirez and Commissioners Julie Brill and Terrell McSweeny issued a separate statement in support of the action. Commissioners Ohlhausen and Wright issued separate dissenting statements.

The FTC will publish a description of the consent agreement package in the Federal Register shortly. The agreement will be subject to public comment for 30 days, beginning today and continuing through May 25, 2015, after which the Commission will decide whether to make the proposed consent order final. Interested parties can submit comments electronically.

SOURCE: Federal Trade Commission

No related posts.

Category: BusinessGovt

Post navigation

← Ca: Cell Phone Privacy Breaches: Forgiven – For Now
Privacy Groups Appeal UK Surveillance Decision →

Search

Contact Me

Email: info[at]pogowasright.org
Security Issue: security[at]pogowasright.org
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]pogowasright.org

Research Report of Note

A report by EPIC.org:

State Attorneys General & Privacy: Enforcement Trends, 2020-2024

Categories

Recent Posts

  • Lawmakers Warn Governors About Sharing Drivers’ Data with Federal Government
  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs
  • Always watching: How ICE’s plan to monitor social media 24/7 threatens privacy and civic participation
  • Who’s watching the watchers? This Mozilla fellow, and her Surveillance Watch map

RSS Recent Posts at DataBreaches.net

  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
©2025 PogoWasRight.org. All rights reserved.