Dating apps

Fake profiles and banned users on dating apps: USA

· 8 min read

Applies to
Online dating services with members in Texas, Utah, Colorado and other states with dating-safety statutes
In force
Texas since 2011; Utah since 2023; Colorado safety policies since 1 January 2025, full annual report content due 31 August 2026
What to do
Treat a ban as a decision about a person, not an account, and keep the numbers that show banned users are not getting back in

In September 2019 the Federal Trade Commission sued Match Group and alleged that "as many as 25 to 30 percent of Match.com members who register each day are using Match.com to attempt to perpetrate scams." In August 2025 the case settled for $14 million. The charges it resolved were about a subscription guarantee, accounts locked after billing disputes, and cancellation. None of them was about the scammers.

That outcome is a fair summary of where US law stands on fake profiles. A dating service is not required to know who is behind an account. What the law regulates instead is narrower and later: what the service tells its members, and what it does once it has decided an account is a fraud.

What the law asks for instead of identity

There is no federal statute requiring a dating app to verify the identity of its members. The state laws written specifically for dating services, of which Texas and Utah are representative, are disclosure laws.

Texas passed its law in 2011. Its Internet Dating Safety Act, chapter 106 of the Business and Commerce Code, does not require a criminal background check. Section 106.004 requires a provider that does not run one to say so to Texas members, "in bold, capital letters, in at least 12-point type." A provider that does run checks must state, under section 106.005, that they "are not foolproof" and "may give members a false sense of security." Section 106.006 adds a safety notice, whose model text opens with "Anyone who is able to commit identity theft can also falsify a dating profile." The civil penalty in section 106.007 is up to $250 for each Texas member registered during the violation.

Utah's Online Dating Safety Act, enacted in 2023, follows the same pattern with more detail. Section 13-67-103 requires the screening disclosure; section 13-67-104 requires a safety notice that tells members "an individual may provide false information in a dating profile."

Read together, these statutes accept fake profiles as a condition of the market and make the service warn about them. The duty that comes closest to acting on a fake profile arrives only after the service has found one.

A ban is a decision about an account

That duty is the fraud ban notification. Utah's section 13-67-105 requires a provider to notify a Utah member who "has received and responded to a message from a banned member." The notice names the banned profile, warns that it "may have been using a false identity," tells the member not to send money, and links to fraud-prevention guidance. It goes out within 24 hours of the ban, or within three days where the provider judges that the circumstances require it.

Everything in this duty turns on the definitions in section 13-67-101. A "fraud ban" is "the expulsion of a member from an online dating service because, in the judgment of the online dating service provider, there is a significant risk the member will attempt to obtain money from another member through fraudulent means." A "banned member" is "a member whose account or profile is the subject of a fraud ban."

Two consequences follow. The trigger is the provider's own judgment, so the statute creates no duty to look for fraud, only a duty to act on fraud once found. And the object of the ban is an account. A member is defined as an individual who submits the information the service requires to access it, so the person who was banned yesterday and registers today with a new email address is, in the statute's terms, a new member with a clean record. The ban ends one account. Whether it ends anything else is left to the service.

For a service, that means every returning fraudster restarts the cycle: new profile, new contacts, a new ban, a new round of notices. The law measures the response to each account and says nothing about the repetition.

Colorado started counting the ones who come back

Colorado is the first state to ask about the repetition directly. Its Online Dating Services Safety Act, Senate Bill 24-011, passed on 5 June 2024 and, as the Colorado Attorney General's office describes it, requires every online dating service with at least one Colorado user to adopt a safety policy by 1 January 2025, register its URL with the office, and file an annual safety report.

The content of that report was set by the Online Dating Safety Act Rules, 4 CCR 904-5, adopted by the Attorney General's office on 4 February 2026. Rule 4.03 requires each service to report:

  • "A summary of the process the Online Dating Service uses to prevent individuals who have been removed or banned for violations of the Safety Policy from re-registering or creating new accounts"
  • The number of members or accounts prevented from re-registering during the reporting period, and their share of active users
  • For services owned by a group, the process for ensuring a person banned on one affiliated service "is subject to review" before holding an account on another, and how many were stopped
  • A summary of the service's identity verification and age verification processes, with the number of accounts removed and people kept out as a result

The rules sort services into five tiers by monthly active users, down to "Less than 500,000", and every tier reports. The first report was due on 31 January 2026; where it held only the minimum, a supplemental report with the full Rule 4.03 content was due by 31 August 2026.

None of this obliges a service to verify identity or to block anyone. It obliges the service to describe what it does and to count the results, in a filing with a state Attorney General. A service that has no way to recognise a banned person on their second attempt will now say so on paper, with a number next to it.

What is moving at the federal level

The Romance Scam Prevention Act, H.R. 2481, would put the fraud ban notification into federal law. It passed the House on 23 June 2025 and was placed on the Senate calendar on 17 June 2026, where it stood when this was written. Its "fraud ban" is "the termination or suspension of the account or profile of a member", the same account-level object as the state laws. Violations would be treated as unfair or deceptive practices enforced by the FTC and state attorneys general, and the act would take effect one year after enactment.

Update, 2 October 2026: the Senate passed the bill without amendment on 23 September 2026, so it now goes to the President. The one-year clock starts at enactment, not at Senate passage.

Its "One National Standard" clause would preempt state laws that govern how a dating service notifies members about contact with a banned account. On its terms the clause is about notification. It does not address Colorado's reporting on re-registration or identity verification, or the Texas and Utah screening disclosures.

Two qualifications apply to everything above. Utah's section 13-67-106 states that the chapter does not create a private right of action or diminish the protections of 47 U.S.C. § 230, so these duties are enforced by the state, not by users. And the question of who is behind an account is separate from the question of how old they are, which US law handles through app stores and federal privacy rules; that is covered in age verification requirements for dating apps in the USA.

What this looks like in practice

  • Map your disclosures by state. Texas and Utah each require a statement on criminal background screening, whichever way you answer it, and a safety notice at registration.
  • Run fraud ban notifications as a pipeline, not a manual task. The 24-hour clock starts at the ban, and the recipients are everyone who received and responded to a message from the banned account.
  • Decide what a ban attaches to. If it attaches only to an email address or an account ID, it will not survive a second sign-up. Something that persists across accounts, such as a verified identity document matched to a face, is what lets a ban apply to the person.
  • Keep the numbers Colorado asks for even if you have no Colorado users yet: bans, re-registration attempts blocked, notices sent, identity checks failed. They are the evidence that your ban means something.
  • Collect only what the purpose needs. Identity data gathered to keep banned users out should be used for that, retained for a defined period, and described in your safety policy.

The law asks what happens after a ban; the question that decides whether the ban works is whether the same person can come back.

Keep reading

ProofAge for Dating Apps — Stop Fake Profiles Before They Kill Trust

ProofAge helps dating platforms reduce fake profiles, speed up review, and verify real users — without the heavy friction of enterprise KYC.

See how it works