Skip to content
← BlogStrategyAnalysis5 min read

The FTC just sued a company for quietly sharing customer data with advertisers

The FTC sued Hims & Hers on July 30, 2026 over sharing sensitive data with advertisers. What the case means for B2B teams enriching or sharing prospect data.

By David Lara, Founder

Founder-reviewed ·How we research and correct articles

On July 30, 2026, the FTC filed suit against telehealth company Hims & Hers, alleging the company shared customers’ sensitive health information with advertisers without the disclosure or consent the law requires for data that sensitive. The case is still working through the courts, and the specific allegations remain to be tested — but the filing itself is the latest entry in a pattern that’s been building through 2026, and it’s worth understanding regardless of how this particular case resolves.

This isn’t an isolated case

The Hims & Hers suit lands on top of a year of increasingly aggressive FTC and state-level action against companies that share personal data with advertisers or marketing partners in ways customers didn’t clearly agree to. Earlier in 2026, the FTC reached a settlement with data broker Kochava over the sale of geolocation data — including a requirement that Kochava implement a “privacy block” preventing raw location data tied to sensitive venues like healthcare facilities from being shared or sold. California’s state privacy regulator separately pursued action against a data broker for buying and reselling contact information tied to people’s health conditions for targeted advertising, and forced another to shut down entirely.

The common thread across all of these cases isn’t the type of data — location, health, contact information — it’s the use. Regulators aren’t primarily objecting to companies collecting data. They’re objecting to that data being repurposed for advertising or resale in ways the person never agreed to when they handed it over in the first place.

The line that actually matters: purpose, not possession

That distinction is the practical takeaway for any business that touches personal data, B2B included, and it’s more specific than “get consent” as a blanket rule. The line regulators keep drawing is about purpose limitation: data collected for one stated reason being quietly used for a different one.

Translate that into a B2B context and it maps onto practices that are genuinely common in outbound and marketing operations:

  • Enriching a prospect record with third-party intent or firmographic data the prospect never knew was being layered onto their profile.
  • Piping a CRM contact list into an ad platform for retargeting, when the contact was collected for outreach, not advertising.
  • Sharing a lead list with a co-marketing partner without the person who filled out a form knowing their information would leave your organization.
  • Silently excluding suppressed or unsubscribed contacts from email while still using their data for ad targeting — technically honoring the unsubscribe in one channel while ignoring its spirit in another.

None of these are exotic edge cases. They’re standard operating procedure at a lot of B2B companies, done without much thought about whether the original collection point implied consent for the downstream use. The regulatory trend through 2026 is a signal that “we had the data, so we used it” is no longer a safe assumption, even outside consumer-facing health and location data specifically.

What this actually requires in practice

The fix isn’t a blanket “stop using data,” it’s documentation and boundaries that match the purpose the data was actually collected for:

  • Know why you collected each field. An email address collected through a demo-request form implies outreach about that product. It doesn’t automatically imply consent to be added to an ad-retargeting audience or resold to a data partner.
  • Treat unsubscribe and suppression as a full stop, not a channel-specific pause. Data minimization means a suppressed contact stays suppressed everywhere that record flows, not just in the next email send.
  • Be able to answer “where did this record come from and what was it collected for” for any contact in your system. That’s the practical version of what regulators are increasingly checking when they investigate a complaint — not a hypothetical, but an actual audit trail.
  • Honor deletion requests completely, not partially. A GDPR-style right to erasure that removes a contact from your sending list but leaves them in an enrichment vendor’s cache or an ad platform’s audience isn’t compliance — it’s the same gap the FTC is now suing over.

Where Norbelys draws this boundary by design

Norbelys’s suppression list enforcement and data-isolation guarantees exist precisely to keep purpose limitation simple rather than something you have to police manually across a sprawl of connected tools: your contact data is isolated from other tenants, it isn’t resold or shared with third-party ad platforms as part of the product, and deletion requests remove a contact from the system rather than leaving a shadow copy behind in some downstream integration. That’s not a compliance add-on bolted onto the platform — it’s the default, on every plan, because the alternative is exactly the kind of quiet secondary use regulators spent 2026 building enforcement cases around.

If this case has you auditing where your own prospect data actually flows once it’s collected, see how Norbelys handles data by plan — the isolation and suppression guarantees aren’t a Scale-tier feature, they’re how the product works from Starter up. Start sending with a system built around purpose limitation, not around finding out the hard way where the line was.

FTC data-sharing enforcement — quick answers

What did the FTC allege against Hims & Hers?

The FTC filed suit on July 30, 2026 alleging the telehealth company shared customers' sensitive health information with advertisers without the disclosure or consent the law requires for data of that sensitivity. The case was still in early proceedings at the time of writing.

Is this only about health data, or does it apply more broadly?

The specific case involves health data, but it fits a broader 2026 pattern of FTC and state-level enforcement against undisclosed secondary use of personal data generally, including location data and contact information collected by data brokers.

How does this apply to B2B cold email and prospecting?

The underlying principle — data collected for one purpose shouldn't be silently repurposed for another without consent — applies to common B2B practices like feeding CRM contacts into ad-retargeting platforms or sharing lead lists with partners, not just to consumer health or location data specifically.

What's the practical fix for a sales or marketing team?

Document why each piece of contact data was collected, treat suppression and unsubscribe requests as applying everywhere that record flows (not just the next email send), and be able to trace where any given contact's data goes once it leaves your primary system.