# Consent Decree Compliance

> SKILL 50: Consent Decree Compliance

- Skill: `nickgallick/consent-decree-compliance` (Agent Skill)
- Install (CLI): `npx skillmds@latest add nickgallick/consent-decree-compliance`
- Raw SKILL.md: https://api.skillmd.com/api/skills/nickgallick/consent-decree-compliance/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- Author: nickgallick (https://skillmd.com/u/nickgallick)
- Updated: 2026-09-21
- Page: https://skillmd.com/skills/nickgallick/consent-decree-compliance

---

# SKILL 50: Consent Decree Compliance

## Purpose
Understand what a consent decree means operationally, how to live under one, and how to negotiate better terms before signing.

## What a Consent Decree Is
- Legally binding agreement between you and a regulator to resolve an enforcement action
- Entered as a federal court order (for FTC/DOJ) or administrative order (for CFTC/SEC)
- Typical duration: 10–20 YEARS (FTC standard: 20 years)
- Violation: contempt of court OR additional fines — up to $50,349 per violation per day (FTC)

## Common Consent Decree Terms
- **Injunction**: "You shall not [operate unregistered prediction market / sell unregistered securities]"
- **Compliance program**: implement and maintain a written compliance program
- **Independent monitor**: hired at YOUR expense, reports to the regulator ($200K–$1M+/year)
- **Periodic reporting**: quarterly or annual compliance reports submitted to regulator
- **Audit rights**: regulator can audit compliance at any time with reasonable notice
- **Disgorgement**: pay back ill-gotten gains
- **Civil penalty**: pay the fine
- **Cooperation**: cooperate with ongoing investigations
- **Neither admit nor deny**: standard language — but you CANNOT publicly deny the findings either

## Living Under a Consent Decree
- Every business decision evaluated against decree terms
- Launching a new product? Check if it violates the injunction (get monitor's approval if required)
- Changing compliance program? Monitor must approve
- Monitor has ACCESS to: internal communications, financial records, systems
- New employees must be briefed on decree obligations
- Decree follows the COMPANY (and potentially key individuals), not just the product

## How to Negotiate Better Terms (Do This BEFORE Signing)

### Duration
- Argue for 5–10 years instead of 20
- Basis: quick remediation, good faith cooperation, limited harm to consumers
- FTC has accepted shorter terms for smaller violations with prompt remediation

### Scope of Injunction
- Narrow it to the SPECIFIC product/practice at issue
- Push back on: "and any substantially similar product or service" (overly broad)
- Define terms precisely: what counts as a "prediction market" vs. a "skill competition"

### No Monitor
- Argue internal compliance program is sufficient
- Offer: enhanced reporting obligations instead of an independent monitor
- Cost savings: $200K–$1M+/year (worth fighting hard for)

### Reduced Penalty
- Cooperation credit: if you cooperated early, provided documents promptly, self-reported → argue for 30–50% reduction
- Ability to pay: document financial constraints
- No prior violations: first-time violators get significant reductions
- Consumer harm limited: if few users were affected

### Sunset Provisions
- Decree terms relax or terminate if compliance metrics are met
- Example: monitoring obligation drops from quarterly to annual after 3 years of clean reports

### Right to Modify
- Preserve the ability to petition the court to modify terms if business circumstances change substantially
- Crucial for a technology company where the product landscape changes rapidly

## Case Studies

### FTC v. Epic Games (2023) — $520M, 20-Year Consent Decree
- Violation: COPPA violations (collected data from children), dark patterns for purchases
- Terms: $275M civil penalty, $245M refunds, 20-year privacy compliance program, biennial audits
- Lesson: COPPA violations are extremely expensive. Age verification is non-negotiable.

### CFTC v. Polymarket (2022) — $1.4M Fine
- Violation: operating unregistered event contracts exchange
- Terms: $1.4M civil monetary penalty, agreed to cease offering to US persons, wind down US-facing operations
- Outcome: Polymarket restructured, geo-blocked US users, continued offshore operations
- Lesson: A focused, limited decree can allow the business to survive in restructured form

### SEC v. Block.one / EOS (2019) — $24M Fine
- Violation: unregistered securities offering (ICO raised $4 billion)
- Terms: $24M fine (0.6% of proceeds raised). No ongoing compliance requirements. No admission of wrongdoing.
- Lesson: Early cooperation + good legal strategy can produce remarkably favorable terms even on large violations. Block.one walked away without ongoing obligations.

### FTC v. Facebook/Meta (2019, modified 2020) — $5B Penalty, Ongoing Decree
- Terms: $5B civil penalty (largest FTC penalty ever), 20-year decree, independent privacy committee on board of directors, mandatory privacy reviews for new products
- Lesson: Systematic privacy violations at scale → maximum FTC enforcement response

## Pre-Enforcement Mitigation Strategy
Best protection against a devastating consent decree: don't get one.
1. Get legal opinions BEFORE launching regulated products
2. Self-report problems when discovered (cooperation credit)
3. Remediate quickly and document the fix
4. Engage proactively with regulators (sandbox programs, no-action letters)
5. Build genuine compliance programs (not paper programs) — regulators can tell the difference

---
*This is legal research and intelligence, not legal advice. Consult qualified legal counsel before taking action.*

