Skip to main content
FTC Order Against Illuminate: Your Data Security AuditBreach & Risk Assessment
6 min readFor Legal and Compliance Teams

FTC Order Against Illuminate: Your Data Security Audit

Could your data security program withstand the FTC's scrutiny? The Commission's order against Illuminate Education Inc. offers a clear guide on regulatory expectations. Use this checklist to evaluate your current program against the standards that emerged from a breach affecting 10.1 million students.

Checklist Overview

This audit aligns with the FTC's core expectations for handling personal data at scale. It's based on the specific requirements imposed on Illuminate after their security lapses led to unauthorized access to student records, health information, and contact details. Each item reflects either a direct order requirement or a control gap that contributed to the enforcement action.

The checklist focuses on three priorities: security program adequacy, data minimization discipline, and breach notification transparency. If you handle personal data for third parties (schools, clients, partners), these requirements apply regardless of your sector.

Prerequisites

Before starting this audit, gather:

  • Your current written information security program
  • Data inventory or processing register showing what personal data you collect and why
  • Your published data retention schedule
  • Vendor security assessment records from the past 24 months
  • Breach notification procedures and templates
  • Any representations you've made to customers about data security or breach notification timelines

You'll need input from your security team, legal counsel, and whoever manages vendor relationships.

Security Program Requirements

☐ 1. You maintain a written, comprehensive information security program

The program must protect the confidentiality, integrity, and availability of personal information you collect. "Comprehensive" means it addresses administrative, technical, and physical safeguards across your processing environment.

Good looks like: A documented program with named owners, defined scope covering all systems that touch personal data, and controls mapped to specific risks identified through assessment.

☐ 2. Your security program includes regular risk assessments

You must identify reasonably foreseeable internal and external risks to personal data. This isn't a one-time exercise.

Good looks like: Annual (or more frequent) documented assessments that examine new processing activities, system changes, and emerging threat patterns. Each assessment produces a prioritized remediation plan.

☐ 3. You act on vendor-reported vulnerabilities within defined timeframes

The FTC specifically called out Illuminate's failure to address vulnerabilities reported by their third-party vendor nearly two years before the breach occurred.

Good looks like: A documented process for triaging vendor security findings, assigning remediation owners, and tracking closure. Critical findings get addressed within 30 days; high-severity within 90 days.

☐ 4. Your cloud database configurations follow least-privilege principles

Many breaches stem from overly permissive cloud storage settings. If you use cloud-based databases for personal data, access controls must restrict who can view, modify, or export that data.

Good looks like: Role-based access controls with documented business justification for each permission grant. Quarterly access reviews that remove unused permissions. Logging enabled for all data access events.

Data Minimization and Retention

☐ 5. You collect only personal data reasonably necessary for requested services

The order prohibits Illuminate from collecting data not reasonably necessary to provide what customers asked for. Apply this standard to every data field you capture.

Good looks like: A field-by-field justification document explaining why each data element is required. Regular reviews that eliminate fields you're collecting "just in case" or for potential future use.

☐ 6. You maintain a publicly available data retention schedule

Your schedule must detail why you collect each category of information and establish set deletion timeframes.

Good looks like: A published retention schedule organized by data category (account data, transaction records, support tickets, etc.) with specific retention periods and legal/business justification for each. The schedule is accessible to customers without login.

☐ 7. You delete personal data when it's no longer reasonably needed

Retention schedules mean nothing without enforcement. You must have processes that actually purge data when retention periods expire.

Good looks like: Automated deletion workflows triggered by Time-to-Live values or Retention Rule rules. Manual review queues for data requiring Preservation Order checks before deletion. Quarterly reports showing deletion volumes by data category.

☐ 8. You've purged legacy data that doesn't meet current necessity standards

The order requires Illuminate to delete unnecessary data already collected. Conduct a retroactive sweep.

Good looks like: A completed data inventory review identifying personal data collected before current minimization standards took effect. Defensible Disposal of data that wouldn't be collected under current policies, with legal sign-off on any retention exceptions.

Vendor Management and Oversight

☐ 9. You receive regular security assessments from vendors who access your systems

The breach occurred despite vendor warnings. You need visibility into vendor-identified risks.

Good looks like: Contractual requirements for vendors to report security findings quarterly or after any penetration test. A centralized register of vendor security findings with assigned remediation owners on your team.

☐ 10. You validate vendor remediation claims before closing findings

Don't accept "fixed" at face value when vendors report closing security gaps.

Good looks like: Documented verification procedures (re-testing, evidence review, or third-party validation) before you mark vendor-reported vulnerabilities as resolved in your tracking system.

Breach Notification and Transparency

☐ 11. Your breach notification procedures include specific customer timelines

The FTC alleged Illuminate failed to notify schools "in a timely manner, as promised." If you've committed to notification timeframes, you must meet them.

Good looks like: Written breach response procedures that specify notification windows (e.g., "affected customers within 48 hours of breach confirmation"). Procedures include escalation paths if timelines are at risk.

☐ 12. You notify the FTC when you report breaches to other government agencies

The order requires Illuminate to inform the FTC whenever they alert federal, state, or local authorities about consumer data breaches.

Good looks like: A step in your breach notification workflow that triggers FTC notification whenever you file with a state attorney general, supervisory authority, or sector regulator. Template language ready for this notification.

☐ 13. Your privacy policy accurately describes current security practices

Don't claim protections you haven't implemented. The order prohibits misrepresenting data security practices.

Good looks like: Annual reviews comparing privacy policy security statements against actual implemented controls. Legal sign-off required before publishing any security-related customer communications.

Common Mistakes

Treating vendor findings as informational. Illuminate received vulnerability reports from their vendor but failed to act. Vendor assessments carry the same remediation obligation as your internal findings.

Publishing aspirational retention schedules. Your schedule must reflect actual deletion practices, not ideal future state. If you're not deleting data on the published timeline, you're misrepresenting your practices.

Defining "reasonably necessary" too broadly. Collecting data because it might be useful someday doesn't meet the necessity standard. You need a current business justification tied to services the customer requested.

Assuming cloud vendors handle all security. Even if you use managed database services, you're responsible for access controls, encryption key management, and monitoring. Shared responsibility models don't eliminate your obligations.

Next Steps

Score your current state: Count how many checklist items you can mark complete with documented evidence. Anything you can't check is a compliance gap.

For items you marked incomplete:

  1. Assign an owner and target completion date within the next 90 days.
  2. Prioritize items related to vendor vulnerability management and Data Purging (these drove the Illuminate enforcement).
  3. Schedule a follow-up audit in six months to verify sustained compliance.

If you marked fewer than 10 items complete, brief your executive team on FTC enforcement risk and request budget for remediation. The cost of implementing these controls is substantially less than the reputational and operational impact of an enforcement action.

Document everything. The FTC's complaint highlighted not just security failures but also the gap between Illuminate's promises and their actual practices. Your audit trail proves you're meeting the commitments you've made to customers.

You Might Also Like