Saturday, 13 December 2025
25.8 C
Singapore
22.2 C
Thailand
20.7 C
Indonesia
26.9 C
Philippines

Avast slapped with a significant fine for privacy violations

Avast incurs a US$16.5 million fine by the FTC for selling user data without consent, underlining the need for ethical data practices.

In a recent and significant development, Avast, a prominent name in cybersecurity, faces a substantial fine of US$16.5 million. This action by the Federal Trade Commission (FTC) follows revelations that the company was covertly selling its users’ browsing data, raising serious questions about privacy violations and the ethical conduct of tech firms.

The case against Avast dates back to the period between 2014 and 2020. During this time, the company allegedly harvested vast web browsing data through its antivirus software and various browser extensions. This data collection wasn’t just extensive but also deeply personal. It included sensitive details about users’ religious beliefs, health concerns, political affiliations, geographical locations, and financial situations. Making matters worse, this information was stored indefinitely and sold to more than 100 different third-party entities without the knowledge or consent of the individuals whose data was being traded.

The issue became public following a collaborative investigation by Motherboard and PCMag in 2020. As a result, Avast ceased operations of Jumpshot, its subsidiary responsible for data harvesting. Despite Avast’s claim of anonymising the data before its sale, the FTC discovered it still contained unique identifiers for each browser. These identifiers gave third parties access to comprehensive browsing histories, timestamps, device and browser types, and user locations.

FTC’s stringent response and Avast’s stance

The FTC’s response to Avast’s malpractices has been robust and uncompromising. The agency’s order includes a substantial monetary fine and imposes strict regulations on Avast’s future operations. The company is now prohibited from misrepresenting its data collection and usage practices and is barred from selling or licensing browsing data for advertising purposes. Additionally, Avast must delete all the web browsing data it acquired through Jumpshot and inform affected customers about the unauthorised sale of their data.

Avast spokesperson Jess Monney expressed the company’s commitment to protecting digital lives in a statement he gave recently. While Avast disagrees with the FTC’s allegations and the portrayal of the facts, it is ready to resolve the matter and focus on serving its global customer base.

Broader implications for digital privacy

This case is not isolated but part of a more significant movement by the FTC to clamp down on inadequate data privacy practices. Earlier in the year, the FTC settled with Outlogic, formerly X-Mode Social, to stop the company from selling location-tracking data. InMarket, another firm, was also banned from selling precise user locations.

The Avast incident serves as a critical reminder of the delicate balance between user privacy and the business objectives of technology companies. In an era where digital privacy is increasingly becoming a paramount concern, businesses are challenged to find innovative solutions that respect user privacy while maintaining commercial viability.

Hot this week

Razorpay Singapore introduces checkout feature to reduce payment costs and boost conversions

Razorpay Singapore launches a checkout feature offering instant discounts to reduce payment fees and boost online conversion rates.

2026 Predictions Part 1: The five forces reshaping Asia’s digital economy

Five forces are redefining Asia’s digital economy in 2026, from AI adoption and data sovereignty to new security and workforce demands.

Enterprise AI adoption accelerates as organisations deepen workflow integration

A new OpenAI report shows rapid global growth in enterprise AI, rising productivity gains, and a widening gap between leading and lagging adopters.

Proofpoint completes acquisition of Hornetsecurity

Proofpoint completes its US$1.8 billion acquisition of Hornetsecurity, expanding its Microsoft 365 and MSP-focused security capabilities.

Kaspersky uncovers macOS malware campaign abusing ChatGPT chat-sharing feature

Kaspersky reports a macOS malware campaign using ChatGPT’s chat-sharing feature to spread the AMOS infostealer.

PlayStation introduces limited edition Genshin Impact DualSense controller

PlayStation announces a limited edition Genshin Impact DualSense controller for PS5, launching in Singapore on 21 January 2026.

PGL brings Counter-Strike 2 Major to Singapore in November 2026

PGL confirms the Counter-Strike 2 Major is coming to Singapore in November 2026, marking the first CS2 Major in Southeast Asia.

Denodo: Rethinking data architecture for AI agility and measurable ROI in Asia-Pacific

Denodo highlights how modern, composable data architectures powered by logical data management are helping Asia-Pacific enterprises accelerate AI adoption, ensure governance, and achieve measurable ROI.

Veeam completes acquisition of Securiti AI to build unified trusted data platform

Veeam completes its US$1.725 billion acquisition of Securiti AI to form a unified trusted data platform for secure and scalable AI adoption.

Related Articles

Popular Categories