Why this matters for UK SMEs
If your business collects customer data, and almost every business does, the promises you make about privacy carry legal weight. A new lawsuit in the United States is a timely reminder that regulators, and customers, will hold you to your word.
According to a report from Malwarebytes, the US Federal Trade Commission (FTC), joined by the states of Utah and California, has filed a lawsuit against telehealth firm Hims & Hers. The claim: the company shared sensitive customer health data with advertisers despite marketing itself as privacy-focused.
What Hims & Hers is accused of
The FTC alleges three main failings. First, that the company passed sensitive health information, including details of medical conditions, to advertising platforms such as Meta and Snap, despite its privacy assurances.
Second, that it billed customers before they had spoken to a medical provider, enrolling many in recurring subscriptions straight after they filled in an online intake form.
Third, that cancelling was made deliberately difficult, hidden behind multiple confusing steps, a tactic often described as a “dark pattern” (a website design that nudges people into choices they wouldn’t otherwise make).
A court will decide whether any laws were broken. But the case sends a clear signal that health and data privacy are firmly on regulators’ radar.
The wider lessons for smaller firms
You don’t need to be a health-tech giant to learn from this. Malwarebytes highlights a gap that affects businesses of all sizes: the difference between what a privacy policy promises and what a company actually does.
Many firms embed third-party advertising and analytics tools, often called SDKs (software development kits, small blocks of code that add features to an app), without fully understanding what data those tools quietly send out. That mismatch is exactly what lands companies in trouble.
In the UK, the equivalent risk sits under UK GDPR and the oversight of the Information Commissioner’s Office (ICO). Our guide to staying within UK GDPR when using ChatGPT and Copilot covers the practical side. Sharing customer data in ways your privacy notice doesn’t clearly explain can lead to complaints, fines and lost trust.
Your practical takeaway
Do a simple check of your own house:
- Read your privacy policy and confirm it matches what your website, apps and tools actually do. An AI chatbot set up for your business can summarise a lengthy policy and flag where data may be shared.
- Make cancelling or opting out genuinely easy, customers remember friction, and so do regulators.
- Only collect the data you truly need to deliver your service.
- Audit which third-party trackers and marketing tools run on your site, and switch off anything unnecessary.
Being straight with customers about their data isn’t just compliance, it’s a competitive advantage smart SMEs can own.





