On January 30, 2020, Avast chief executive Ondrej Vlcek described keeping people safe online as the company’s core mission. Writing on Avast’s blog, he announced that its browsing-data subsidiary, Jumpshot, would close. The privacy promise was also a sales proposition. Advertising reproduced in the Federal Trade Commission’s February 22, 2024 complaint told consumers that Avast products would protect their privacy and stop online tracking.
The FTC’s record describes the opposite transaction inside the same business. Avast collected browsing information through its software, then supplied it to Jumpshot for sale. The protection promise and the data business depended on the same access to consumers’ activity.
What did Avast promise?
The FTC’s administrative complaint names Avast Limited, Avast Software s.r.o. and Jumpshot, Inc. It examines representations made through Avast’s websites, browser extensions and antivirus software.
Those representations mattered because they addressed the activity Avast itself was conducting. According to the complaint, Avast warned consumers about third parties tracking their online behavior. It marketed tools that would block tracking and protect browsing privacy.
The FTC did not treat these statements as a promise that no information would ever leave a computer. Its allegation was more specific. Avast failed to tell consumers adequately that information collected through its protective products would become browsing records sold to other businesses.
A disclosure that software collects information is not necessarily a disclosure that the supplier sells a detailed history of where its users go. The complaint places that missing distinction beside Avast’s affirmative privacy claims.
What did the buyers receive?
According to the complaint, Avast collected consumers’ browsing information through browser extensions and antivirus software from 2014 until January 2020. The FTC alleged that Avast stored that information indefinitely and sold it through Jumpshot without adequate notice or consent.
The information included websites visited, precise timestamps and identifiers associated with browsers or devices. The FTC said browsing records could reveal religious beliefs, health concerns, political leanings, location, financial circumstances and visits to child-directed content.
These were not merely totals showing how many people visited a shopping website. Jumpshot offered products built from individual browsing activity. The complaint describes feeds that allowed a buyer to follow activity associated with the same identifier over time.
The FTC said Jumpshot sold browsing information to more than 100 third parties, including advertising, marketing and data-analytics businesses. That number describes the alleged customer base, not a count of identified consumers harmed. The commercial product was the browsing record, not just a statistical conclusion drawn from it.
Did removing names make it anonymous?
Avast represented that Jumpshot’s information was anonymized and could not be traced back to individual consumers. The FTC challenged that assurance, not merely the presence or absence of names in a file.
A persistent identifier gives separate visits continuity. A timestamp places them in sequence. A detailed address can reveal the particular page, search or transaction involved. Removing a name does not remove those relationships.
The complaint explains how a buyer could combine Jumpshot records with information it already possessed. A business that knew when a particular customer visited its website could potentially match that visit to a supposedly anonymous browsing record. The matching identifier could then connect the customer to other activity in the feed.
The FTC also alleged that Jumpshot’s agreements did not consistently prohibit reidentification. Where restrictions existed, the agency challenged their adequacy. A sales contract could restrict what a buyer was permitted to do. It could not make a technically linkable record incapable of being linked.
Was that risk merely theoretical?
Independent research supports the distinction between removing names and preventing identification. A 2017 study, “De-anonymizing web browsing data with social networks,” demonstrated that browsing histories could be connected to social-media identities by examining the links people were likely to encounter through their networks.
That study did not test Jumpshot’s buyers or establish that a particular Avast customer was identified. It established a narrower point: browsing patterns themselves can supply identifying information.
The National Institute of Standards and Technology makes the same general distinction in its September 2023 guidance on deidentifying government datasets. Deidentification requires assessing disclosure risk, the information retained and the circumstances of release. It is not simply a procedure for deleting direct identifiers.
The FTC’s March 2012 privacy report had already described conditions for treating information as not reasonably linkable to a consumer or device. Those included reasonable deidentification measures, a public commitment against reidentification and contractual prohibitions on downstream recipients attempting it. The Avast complaint tested both the data’s structure and the controls surrounding its sale.
What did Avast say in response?
Vlcek’s January 30, 2020 statement defended the companies’ conduct as lawful. He also acknowledged that Jumpshot had raised questions about trust and announced its closure.
Both parts belong in the record. Avast did not wait for the FTC’s 2024 settlement to end Jumpshot. Nor did the closure establish that the earlier collection and sales complied with Avast’s promises.
The chronology matters. The conduct examined by the FTC preceded the shutdown. The agency’s complaint arrived on February 22, 2024, approximately 4 years after Vlcek’s announcement. The enforcement action concerned a completed data business, not a newly discovered operation that the settlement alone stopped.
Avast’s public statement therefore answered one question clearly: Jumpshot would no longer operate. It did not settle whether consumers had understood and authorized the business while it operated.
What did the settlement establish?
The FTC brought its complaint under Section 5 of the Federal Trade Commission Act, which prohibits unfair or deceptive acts or practices. Its case addressed both the representations Avast made and its handling of consumers’ browsing information.
The consent agreement was not an admission of the complaint’s substantive allegations. The settlement resolved an administrative enforcement proceeding without a trial determining each disputed fact. That is the legal boundary around the account presented here.
The resulting obligations were concrete. The FTC’s final order required a $16.5 million payment. It prohibited Avast from selling or licensing browsing information from Avast-branded products to third parties for advertising purposes.
The order also required affirmative express consent before specified advertising-related sales of browsing information from non-Avast-branded products. It required deletion of covered browsing information transferred to Jumpshot and products or algorithms derived from that information, subject to the order’s terms.
Additional provisions required consumer notification and a comprehensive privacy program. The FTC subsequently established a consumer claims process associated with the settlement. These remedies addressed different parts of the transaction: the money received, the records retained, the future sales and the controls inside the company.
Did Avast sell what it promised to protect?
Yes, according to the FTC’s detailed account. Avast marketed protection against tracking while collecting browsing information that Jumpshot sold to other businesses. The contradiction was not resolved by removing names, because the records retained details that could connect browsing activity to individuals. Avast closed Jumpshot before the enforcement action, and the settlement was not a trial verdict. But the documented business model put the privacy promise on one side of the transaction and the sale of consumers’ browsing records on the other.



