← All resources

7 September 2026 · Data Protection Foundation

Avast – part of Gen Digital Inc. (NASDAQ: GEN) settles UK consumer tracking claim for over £20 million

Avast has offered UK customers a settlement totalling £20.4 million over the tracking and sale of their browsing data, one of the largest personal data related settlements ever in the UK.

AVAST – PART OF GEN DIGITAL INC. (NASDAQ: GEN) - SETTLES UK CONSUMER TRACKING CLAIM FOR OVER £20 MILLION

Avast Limited ("Avast") is the UK's leading online security and privacy software business, selling "maximum protection" to its customers. Ten years ago, Avast acquired a US company called Jumpshot, which it used to process and sell personal browsing data obtained from Avast customers for nearly five years, using tracking software hidden in its antivirus products. Jumpshot boasted that this data included "Incredibly detailed… data from 100 million global online shoppers and 20 million global [Avast] app users" and that buyers could "analyze it however you want: track what users searched for, how they interacted with a particular brand or product, and what they bought." Jumpshot sold device IDs, the web address of each site visited, each mouse and keyboard click, time of visit and inferred user age and gender to over 100 third parties including Google, Microsoft and data broker Omnicom, part of one of the "big four" global advertising companies.

Avast has subsequently been acquired by NASDAQ listed US company, Gen Digital Inc. (NASDAQ: GEN) and continues to offer online security and antivirus protection.

Following the publication of research into Avast's customer tracking and data sale by security researcher Wladimir Palant in 2019,1 Avast ceased its customer tracking within months, shutting down its relationship with Jumpshot in 2020. Avast CEO Ondrej Vlcek stated: "I feel personally responsible and I would like to apologize to all concerned" the Avast board "decided the data collection business was ultimately incompatible with the Group's core security mission" and Avast stated "We recognise that we must now focus on rebuilding the trust of our loyal users, partners, and stakeholders."

In March 2023, the Czech Data Regulator fined Avast £11 million (EUR13.9 million) for breaches of the GDPR and the US Federal Trade Commission (FTC) began an investigation into Avast's practices, resulting in a complaint2 which concluded in June 2024 with a settlement3 that included a £12.2 million ($16.5 million) fine, which was distributed to affected US customers, and a ban on any sales or licensing of web browsing data going forward.

The FTC stated that Avast "unfairly collected consumers' browsing information through the company's browser extensions and antivirus software, stored it indefinitely, and sold it without adequate notice and without consumer consent…and deceived users by claiming that the software would protect consumers' privacy by blocking third party tracking, but failed to adequately inform consumers that it would sell their detailed, re-identifiable browsing data." They further stated: "This browsing data included information about users' web searches and the webpages they visited—revealing consumers' religious beliefs, health concerns, political leanings, location, financial status, visits to child-directed content and other sensitive information."

The FTC complaint further alleged: "Jumpshot products were designed to allow clients to track specific users or even to associate specific users—and their browsing histories—with other information those clients had. For example, Jumpshot entered into a contract with Omnicom…which stated that Jumpshot would provide Omnicom with an "All Clicks Feed" for 50% of its customers in the …United Kingdom... According to the contract, Omnicom was permitted to associate Avast's data with data brokers' sources of data, on an individual user basis." This meant that despite Avast's statements that customer data was "anonymised" and "aggregated" it sold this data knowing that it could be re-identified to the specific user.4

During these investigations, the Data Protection Foundation ("DPF"), an independent data protection organisation focussed on protecting UK citizens' online data rights, advised the initial class representative Lucy Paley with the assistance of legal counsel, on ways to seek to ensure that UK users of Avast products were similarly compensated for this behaviour. This led to negotiations to settle a potential opt-out class action claim for damages and injunctive relief under a procedure known as "bifurcated CPR 19.8" group action. Following extensive pre action correspondence, on 27 August 2026, Avast announced a settlement of Lucy and Claudio's threatened collective action by making an offer to compensate affected UK customers with two years of free software upgrade valued at £170 per customer, subject to the terms of the offer. This offer can be found and accepted via this link: https://www.avast.com/avastclaimsuk. The offer effectively replicates, and financially improves on, the FTC settlement reached with Avast for US users in 20255. Avast has also stated in the UK offer materials that it "has notified that all customers of Jumpshot delete or destroy any remaining data acquired from Jumpshot". The total amount offered by Avast is £20.4 million, making this one of the largest personal data related settlements ever in the UK.6

Mark Stoter OBE, chair of the Data Protection Foundation, stated:

"The data economy is global, yet consumers are expected to navigate opaque and confusing consent policies, often described as 'privacy' policies, before they can exercise their rights when accessing online services. The Data Protection Foundation will continue to seek redress for UK consumers affected by these practices. We are already investigating a number of organisations where they persist despite regulatory fines, particularly where highly sensitive personal data is being tracked, shared and sold."

The DPF would like to congratulate class representatives Lucy Paley and Claudio Pollack, and their legal team Toby Star and Harriet Bush of Humphries Kerstetter and Michael Silverleaf KC of 11 South Square, for achieving this outcome.

Notes for editors:

The DPF is a UK based non-profit membership organisation. We research and investigate online behaviour to help educate consumers about personal data risks online and the harms that flow from them. We are a community interest company, and seek to provide a single, powerful and informed voice to help educate UK consumers about data abuses.

We operate as a member organisation with a leadership team that includes data specialists, technologists, lawyers and academics. Apart from our investigation of Avast, our work to date has focussed on:

  • Online tracking: we have regularly conducted crawler based research against 10,000 website in the UK for the past six years to demonstrate systemic unlawful online tracking by advertising technology "Adtech" companies. This includes Meta's use of a "backdoor" to track Android phone users web browsing when they use Facebook or Instagram.
  • Abuse of sensitive health and sexual orientation data: we have conducted research into apps, websites and loyalty programmes that we suspect have been unlawfully sharing highly sensitive health and sexual related data. This includes Boots and its sale of loyalty card data to Experian and others, Flo Health in relation to the sale of female health data and Grindr in relation to the sale of sexual orientation data, in each case being sold to third parties without adequate consent.
  • Data brokers: we have conducted subject access request based research against the three major UK data brokers – Experian, Equifax and Transunion, to check their legal compliance.
  • Online gambling: we are currently conducting research into gambling related features in games that are targeted at children, and behavioural tracking, including Fortnite and Roblox.
  • Social media issues: we are working with victims of online fraud and abusive content, and in particular children on Instagram, Facebook and TikTok, to seek to develop meaningful redress for them in connection with other leading NGOs in this field.

We are chaired by Mark Stoter OBE. Mark served for twenty years as a technologist in the British Army and the intelligence community. During that time he commanded the cyber and technical intelligence regiment, and was latterly seconded to help develop the National Cyber Force.

In conducting our work, we maintain regular contact with the ICO and other U.K. based and foreign data protection organisations, consumer organisations, data protection activists and academics. We have made several submissions to U.K. government consultations.

To become a member sign up here: https://dataprotectionfoundation.org/membership.

https://dataprotectionfoundation.org

The Data Protection Foundation

1 New Fetter Lane, London, United Kingdom, EC4A 1AN

Footnotes

  1. https://palant.info/2019/10/28/avast-online-security-and-avast-secure-browser-are-spying-on-you/.

  2. https://www.ftc.gov/system/files/ftc_gov/pdf/Complaint-Avast.pdf

  3. https://www.ftc.gov/enforcement/refunds/avast-settlement

  4. This is a common trick used by sellers of customer data to mislead users who rely on privacy policies stating that their data is anonymised, but knowing that a recipient can reidentify a user. The DPF are investigating many other examples of this, including by UK pharmacy retailer, Boots Limited, who uses Experian to profile its customers and sell them to third party data brokers who openly claim to be able to reidentify purchasers of highly sensitive drug and health product information.

  5. In the FTC settlement, US Avast users obtained $148 each). This equates to £109 per accepting user at today's exchange rate.

  6. Although Avast's offer accepts no legal liability as a result of its collection and sale of its customers browsing data, we note that to accept the offer a customer must "irrevocably, fully, finally and forever release, discharge and waive any and all claims against Avast…and its affiliates" as a condition of acceptance.