Module 6 — Ethics & governance

Module time ~2 hours (reading + exercises) · ~3,400 words · 10 cited primary sources · Tool-independent · v1.0 · 2026-06-09

Who this module is for: Founders + SMB owners who don't have a marketing person — or whose first marketing hire needs the framework. Self-paced. Tool-independent. Part of Adytum Education. This module describes legal regimes at awareness level for educational purposes; it is not legal advice. Specific compliance questions go to counsel.
What you'll learn in this module:
  1. 6.0 Why ethics is an operating constraint, not a poster
  2. 6.1 Truth in advertising — claims and substantiation
  3. 6.2 Endorsements and influencers — the 2023 FTC guides
  4. 6.3 Consent and data — email law, GDPR, CCPA
  5. 6.4 Dark patterns — recognizing one in your own funnel
  6. 6.5 Children, sensitive audiences, and inclusive marketing
  7. 6.6 AI-generated content — disclosure and accountability
  8. Reflection prompts (required before Module 7)
  9. Lesson certificate — earn it
  10. Further reading — tiered by depth

6.0 Why ethics is an operating constraint, not a poster

Every module so far has handed you instruments of persuasion: behavioral biases (Module 1), channel mechanics (Module 2), production discipline (Module 3), crisis handling (Module 4), and coalition leverage (Module 5). This module is the governor on the engine. It exists for three stacked reasons, and only one of them is virtue.

The first reason is legal: marketing is a regulated activity in every jurisdiction, and the operator who doesn't know the baseline rules is signing their company up for enforcement actions, fines, and platform bans they never priced in. The second is empirical: the trust research and the brand-equity findings from Module 1 agree that deceptive marketing is economically self-defeating on any horizon longer than a quarter — trust is the asset that makes every future campaign cheaper, and deception is the fastest known way to liquidate it. The third is the one this track holds as a design principle: the Foundations credential certifies someone a founder can trust with their brand. A certified operator who knows how to exploit loss aversion but not where the manipulation line sits is not certifiable — which is why this module's portfolio piece is required for the full Foundations credential, not elective.

The operating rule that organizes everything below: persuasion is legitimate when it helps a customer make a decision they will still endorse after they fully understand it. Deception, manufactured urgency, and engineered confusion fail that test even when they convert. The test travels: apply it to any tactic this module didn't anticipate.

6.1 Truth in advertising — claims and substantiation

The baseline regime in the United States is Section 5 of the FTC Act, which prohibits "unfair or deceptive acts or practices" — and the FTC's deception framework is more demanding than most founders assume. Three points define the operating surface:

  1. The standard is the net impression, not the literal text. A claim is deceptive if it is likely to mislead a reasonable consumer — including by implication, omission, or visual suggestion. "Results not typical" in small print under an atypical result does not cure the impression the headline created; the FTC's own guidance is explicit that disclaimers don't license misleading claims.
  2. Substantiation must exist before the claim runs. The FTC's substantiation doctrine requires advertisers to possess a reasonable basis for objective claims at the time the claim is made — "we'll find the data if anyone asks" is itself a violation. Performance claims, comparison claims, and "studies show" claims carry the highest bar.
  3. Puffery is the narrow exception. Subjective, unmeasurable enthusiasm ("the best coffee in town") is lawful puffery; the moment a claim becomes measurable ("twice the caffeine"), it requires proof. The operational habit: for every claim in every asset, ask is this measurable? — and if yes, attach the evidence to the brief's Support field (Module 2, §2.1) before the asset ships. This is also DoD check #2 from Module 3 (§3.5) — the process layer and the compliance layer are the same checklist line.

For this track's audience the substantiation habit has a second payoff: founder-stage marketing is fertile ground for accidental over-claiming because the founder genuinely believes. Belief is not a reasonable basis. Write the claim you can prove; the provable claim, concretely worded, almost always converts better anyway — specificity is persuasive (Module 1's System 1 trusts concrete detail).

6.2 Endorsements and influencers — the 2023 FTC guides

The FTC's Endorsement Guides — substantially revised in 2023 — govern testimonials, influencer posts, reviews, and any third-party voice in your marketing. The 2023 revision matters because it modernized the regime for exactly the marketing an SMB does today. The load-bearing rules:

The SMB translation: testimonials are your highest-trust asset class (Module 5, §5.6 built the supply chain for them) — and they are an asset class with rules. Real customers, real words, current experience, disclosed relationships. The honest version is more work than the fake version and is also the only version that compounds instead of detonating.

6.3 Consent and data — email law, GDPR, CCPA

The third regime governs the data your marketing runs on and the channels it touches. Three layers, in ascending strictness:

CAN-SPAM (US email baseline)

The CAN-SPAM Act of 2003 sets the US floor for commercial email: no deceptive subject lines or headers, a functioning unsubscribe mechanism honored within ten business days, a physical postal address in every message, and clear identification of the message as an ad where applicable. Notably, CAN-SPAM is an opt-out regime — it doesn't require prior consent — which routinely misleads US founders into thinking purchased lists are fine. They aren't: the deliverability economics of Module 4 (§4.2) punish non-consented sending long before the FTC does, and the moment any EU resident is on the list, the stricter regime below applies.

GDPR (EU, and de facto global standard)

The EU General Data Protection Regulation (2016, enforced from 2018) is an opt-in regime built on named legal bases for processing personal data. For marketing purposes the practical core: consent must be freely given, specific, informed, and unambiguous — pre-ticked boxes don't count (a point the Court of Justice of the EU confirmed in Planet49, 2019); consent for one purpose doesn't cover another; withdrawal must be as easy as granting; and individuals hold rights of access, deletion, and portability over their data. If your list, your analytics, or your ad targeting touches EU residents, GDPR applies regardless of where your company sits.

CCPA/CPRA (California, and the US state wave)

The California Consumer Privacy Act (2018, amended by the CPRA in 2020) anchors the US state-law wave: rights to know, delete, and opt out of the sale or sharing of personal information, with "sharing" defined broadly enough to cover much ad-tech data flow. A growing set of states has followed with variations. The SMB posture that survives all of them — and the next ones — is the privacy-by-default posture: collect the minimum you need, get real consent, honor deletion requests promptly, and treat the strictest applicable regime as your default rather than maintaining per-jurisdiction behavior.

The consent rule of thumb: if you'd be uncomfortable showing the customer exactly how you got their address and what you're doing with their data, the answer is already no. Consent theater — technically-arguable boxes nobody understood — fails GDPR legally and fails the trust economics everywhere.

6.4 Dark patterns — recognizing one in your own funnel

The fourth section is where the behavioral science of Module 1 meets its misuse. Dark patterns — the term coined by UX researcher Harry Brignull in 2010, cataloged at what is now deceptive.design — are interface and copy designs that engineer users into choices they didn't intend. The FTC's 2022 staff report Bringing Dark Patterns to Light moved the topic from UX ethics into enforcement reality, and subsequent FTC actions (including against subscription-cancellation friction) confirmed the direction. The recognition catalog, in the forms most likely to creep into an SMB funnel:

PatternWhat it looks likeThe honest alternative
Roach motelOne-click subscribe, phone-call-only cancelCancellation as easy as signup — now a legal requirement in several regimes
Manufactured urgencyCountdown timers that reset; "only 2 left" that's falseReal deadlines, real inventory, or no urgency claim (this is §6.1 deception, fully)
Confirmshaming"No thanks, I hate saving money" decline buttonsNeutral decline language
Sneak into basketPre-added items, pre-ticked add-onsNothing in the cart the customer didn't put there
Hidden costsFees revealed at the final stepFull price visible early — drip pricing is an active enforcement target
Trick wordingDouble negatives in consent boxes; toggles whose direction is ambiguousPlain language a tired person parses correctly the first time

The reason this section is called "recognizing one in your own funnel": dark patterns rarely arrive by villainy. They arrive by optimization — each one A/B tests well in the short window, because each one works by exploiting a real bias from Module 1. The conversion lift is real; so is the refund rate, the complaint rate (which feeds the deliverability spiral of §4.2), the review damage, and the regulatory exposure. The governance mechanism is the DoD from Module 3: add the question "does any step of this funnel pass §6.0's endorse-after-understanding test only because the customer won't fully understand it?" — and give whoever runs QA the standing authority to fail an asset on it.

6.5 Children, sensitive audiences, and inclusive marketing

Three audience-specific obligations complete the governance layer:

Children. COPPA (Children's Online Privacy Protection Act, 1998, with updated FTC rules) prohibits collecting personal data from children under 13 without verifiable parental consent — which constrains analytics, retargeting, and email capture on any property directed at children or known to attract them. Beyond data, advertising to children carries heightened FTC attention because the "reasonable consumer" standard scales to the audience: children can't parse persuasive intent the way adults can. The SMB rule: if your audience plausibly includes under-13s, the marketing design conversation starts with COPPA, not ends with it.

Sensitive categories. Module 4 (§4.3) flagged the regulated verticals; the audience-side analogue is data sensitivity: health conditions, financial distress, sexual orientation, immigration status, precise location. Targeting on sensitive attributes — even where technically available — fails the §6.0 test and increasingly fails platform policy and law (GDPR treats these as special categories requiring explicit consent). The practical line: target on context and behavior relevant to the product, not on inferred vulnerability.

Inclusive marketing. The affirmative obligation: marketing that excludes — through imagery that renders parts of your market invisible, copy that assumes one family shape or ability level, or assets unusable with assistive technology — is both an ethics gap and a commercial one (excluded customers buy elsewhere; the Inclusion Practitioner track treats accessibility as a full discipline). Foundations-level practice: representation in imagery reviewed at QA, plain language as default, alt text and caption habits on every published asset, and the W3C's Web Content Accessibility Guidelines (WCAG) as the floor for every landing page the funnel touches.

6.6 AI-generated content — disclosure and accountability

The newest governance surface, and the one this curriculum — itself drafted with AI assistance under named human ownership — treats with particular care. The settled core, ahead of still-moving regulation:

  1. Accountability does not transfer to the tool. Every rule in this module — substantiation, endorsement honesty, consent, deception — applies identically to AI-generated output. "The model wrote it" is not a defense; the advertiser owns the claim. Operationally: AI-drafted assets go through the same DoD, the same factual verification (§3.5 check #2), with more scrutiny on factual claims, not less, because generative tools produce confident, plausible, unverified statements by design.
  2. Fake personas are fake endorsements. AI-generated "customers," synthetic reviews, and invented testimonials fall squarely under §6.2's fake-review enforcement. An AI-generated spokesperson is lawful; an AI-generated person presented as a real customer is not.
  3. Disclosure where deception would otherwise occur. The emerging norm — visible in platform policies requiring synthetic-media labels and in the EU AI Act's transparency provisions — is that AI content requires disclosure where a reasonable person would otherwise be deceived about what they're seeing: synthetic humans, cloned voices, fabricated events. Routine AI-assisted copy does not currently require a label; synthetic media that could be mistaken for reality does. This line is moving — recheck it quarterly with the same discipline as §4.2's platform policies.
  4. Data hygiene extends to prompts. Customer personal data pasted into third-party AI tools is a data transfer under the §6.3 regimes. The practical rule: no customer PII in prompts to tools that haven't been vetted for it.

The closing thought returns to where this module began. Marketing's behavioral instruments keep getting sharper — AI makes persuasion cheaper to produce and easier to personalize. The governance layer is what makes the sharpening safe to hold: the operator who can generate a thousand ad variants overnight and still applies the endorse-after-understanding test to each is the operator the Foundations credential exists to certify.

Reflection prompts (required before Module 7)

Write your responses somewhere you can find them. You will reuse them in later modules. Submit nothing; just write them down.

  1. The substantiation sweep. Take your three strongest current marketing claims. Classify each: puffery, or measurable? For each measurable one, write down the evidence you hold today. Which claim needs rewording or a real test before it runs again?
  2. The disclosure audit. List every third-party voice in your marketing: testimonials, reviews you display, affiliates, influencers, employee posts. For each: is the material connection (if any) disclosed where a viewer can't miss it?
  3. The consent inventory. For your email list: what fraction can you trace to a specific, informed opt-in? What's your honest plan for the fraction you can't?
  4. The dark-pattern mirror. Walk your own funnel start to cancel, as a tired stranger. Score it against the six-pattern table in §6.4. Which single step comes closest to the line — and what's the honest redesign?
  5. The AI disclosure line. List where AI currently touches your marketing output. For each: would a reasonable person be deceived about what they're seeing? Apply §6.6's rule and write down your disclosure decisions — with today's date, because the line will move.
adytum.mk.foundations.ethics-governance

Earn this lesson's certificate

Each module in Foundations is independently certifiable. Pass the focused micro-portfolio for this module — a marketing governance review of a real or chosen funnel: substantiation table for all measurable claims, disclosure audit, consent inventory, and dark-pattern walk-through with one honest redesign (~90 min) — and earn an Open Badges 3.0 micro-credential displayable on LinkedIn. The lesson cert stacks toward the full Growth Operator Foundations credential.

See rubric + submit →

No attendance certificates. Competence must be demonstrated. Pass = ≥4 of 5 rubric dimensions at threshold. Fail = 14-day cooldown then retry.

Further reading — tiered by depth

This module synthesized material from primary regulatory sources and the deceptive-design research literature. Adytum does not reproduce those sources; we point you at them. Regulatory documents are freely available from the issuing agencies. No affiliate revenue from any of these links.

Essential — read first if you read nothing else

Deepening — read after Essential

Specialist — when you want to go deep

Disclosure: Adytum does not receive affiliate revenue, referral fees, or any compensation from any of the publishers, journals, or platforms listed above. Recommendations are based solely on relevance to the curriculum.