Cybersecurity software company Avast is facing a $16.5 million fine after regulators discovered it stored and sold customer information without their consent. The U.S. Federal Trade Commission (FTC) announced the fine on Thursday and said it banned Avast from selling user data for advertising purposes.

According to the FTC's investigation, from at least 2014 to 2020, Avast collected users' web browsing information through its antivirus software and browser extensions, which allowed the company to collect data about religious beliefs, health concerns, political opinions, geographic location and financial status. The company then stored the information "indefinitely" and sold it to more than 100 third parties without customers' knowledge, the complaint alleges.

In 2020, a joint investigation by Motherboard and PCMag first brought attention to Avast's data privacy practices. Shortly after the reports emerged, Avast shut down its data collection unit called Jumpshot. Although Avast said it deidentified user data before selling it, the FTC found that it "failed to adequately anonymize consumers' browsing information." Instead, it sells data with a unique identifier for each browser, showing the websites visited, timestamps, the type of device and browser used, and location.

The FTC also alleges that Avast deceived users by saying its software helped eliminate online tracking, when in fact it was tracking itself. In addition to the $16.5 million fine, the FTC's proposed order prohibits Avast from making false statements about the data it collects. The company must stop "selling or licensing any browsing data from Avast products" to advertisers and delete all web browsing data obtained by Jumpshot. Avast must also notify affected customers that their data has been unknowingly sold.

In response, Avast spokesperson Jess Monney said in a statement: "We are committed to our mission of protecting and empowering people's digital lives. While we disagree with the FTC's allegations and characterization of the facts, we are pleased to resolve this matter and look forward to continuing to serve our millions of customers around the world."

The Federal Trade Commission has been cracking down on bad data privacy practices in recent weeks. In January, the Federal Trade Commission reached a settlement with Outlogic (formerly known as X-ModeSocial), banning the data broker from selling information that could be used to track users' locations. It also prohibits InMarket from selling precise user locations.