Your Privacy Policy Is a Promise: The FTC's OkCupid Action is the Latest Example of What Happens When You Break It

On March 30, 2026, the Federal Trade Commission (FTC) filed a complaint and simultaneously settled with Match Group Americas, LLC and Humor Rainbow, Inc., the entity that owns and runs OkCupid, over a data-sharing deal that broke OkCupid's own privacy policy. The case shows exactly how the FTC treats privacy promises: as binding commitments, not aspirational statements.
What Happened
The Data Transfer to Clarifai
In September 2014, OkCupid's parent, Humor Rainbow, gave a third-party facial recognition company, Clarifai, Inc., access to nearly three million OkCupid user photos, plus demographic and location data. OkCupid put no restrictions on how Clarifai could use the data.
Clarifai had no business relationship with Humor Rainbow and paid nothing for the data. The transfer happened because OkCupid's founders were personally invested in Clarifai.
The Privacy Policy OkCupid Broke
The disclosure itself wasn't the only problem. OkCupid's 2014 privacy policy said user data would only go to:
- Service providers
- Business partners
- Other companies within the Match family of businesses
- Recipients required by legal process
The policy also promised users would be told, and given a chance to opt out, before any other sharing happened.
Clarifai fit none of those categories. Users were never told. And according to the complaint, Match and Humor Rainbow hid and denied the transfer for over a decade, including a statement to the New York Times that the FTC says obscured what actually happened.
The Legal Violation: FTC Act Section 5(a)
The FTC's complaint alleges this violates Section 5(a) of the FTC Act, 15 U.S.C. § 45(a), which bans unfair or deceptive acts, including misrepresentations or deceptive omissions of material fact. The FTC says OkCupid's actions were deceptive. Alongside the complaint, it filed a settlement barring future misrepresentation in OkCupid's privacy policies.
What the Settlement Requires
What's Permanently Banned
The stipulated order runs for 20 years. It permanently bars the defendants from misrepresenting:
- How they collect, maintain, use, disclose, delete, or protect user data
- Why they collect or use that data
- What any privacy control actually does, including any feature presented as letting users limit or manage how their data is processed
What's Required for the Next 10 Years
The order also requires:
- 10 years of compliance reporting to the FTC
- Distributing the order to every officer, director, and employee responsible for consumer-facing privacy statements
- Ongoing FTC monitoring
Why This Matters Beyond OkCupid
The FTC's theory is simple: a privacy policy is a promise to consumers. Break that promise, even for a founder's personal interest rather than a formal data strategy, and it's a deceptive act under Section 5.
Notably, there was no data breach here. No rogue employee. The transfer was deliberate, approved internally, and then hidden.
That reasoning applies broadly. If your actual data-sharing practices don't match what your privacy policy says, you're carrying this risk, whether the gap was intentional or just an ad tech integration nobody updated the policy for.
What This Means Going Forward
The OkCupid case reinforces something that's easy to keep putting off: your privacy policy needs to describe what your organization actually does with data today, not what it intended to do when someone drafted the policy years ago.
That means real scrutiny of third-party relationships, vendor data flows, and any arrangement that started outside the formal business process. State laws already require a lot of privacy commitments. If your policy claims you meet those requirements and your actual practices can't back that up, you're not just risking a state law violation. You're risking an FTC Section 5 action too.
Rikka helps organizations audit their privacy representations against what they actually do with data, and structure third-party arrangements that hold up under regulatory review. See our Privacy & Cybersecurity work, or contact us to talk through where your policy and practice might not match.

















