Showing posts with label Data Privacy. Show all posts
Showing posts with label Data Privacy. Show all posts

Thursday, October 26, 2017

CFPB Issues “Principles” for the Protection of Consumer Authorized Data Sharing and Aggregation


By Caren Enloe
October 26, 2017


With the growth of technology and the development of the fintech market, an unprecedented amount of consumer financial data has become available.  While protections through the FTC Safeguard Rule and EFTA provide certain consumer protections, there are coverage gaps as the regulatory scheme has struggled to keep up with technological advancements. 

In recognition of these competing forces and this growing market of consumer services, the CFPB issued a Request for Information in November of 2016 inquiring as to market practices related to consumer access to financial information and related data aggregation services.  Last week, the CFPB published their findings, as well as their Consumer Protection Principles which are designed to “reiterate the importance of consumer interests to all stakeholders in the developing market for services based on the consumer-authorized use of financial data.”  While the Principles are “not intended to alter, interpret, or otherwise provide guidance on the scope” of existing consumer protections under existing statutes and regulations or establish binding requirements or obligations relevant to the Bureau’s exercise of its rulemaking, supervisory or enforcement authority”, they appear to be the first step in filling some of the current regulatory gaps.

The CFPB Principles address nine general areas of concern:

  • Access.  The Principles recognize the right of consumers to be “able, upon request, to obtain information about their ownership or use of a financial product or service” from the product or service provider.  The Principles also support the consumer’s right to “authorize trusted third parties to obtain such information from account providers to use on behalf of consumers, for consumers benefit, and in a safe manner.”   
  • Data Scope and Usability.  The Principles set forth that the scope of data that may be made available should be broad; however, the data available to “third parties with authorized access” should be limited to that which is “necessary to provides the product(s) or service(s) selected by the consumer and only maintain such data as long as necessary.”
  • Control and Informed Consent.  The Principles emphasize the consumer’s right to control data access and the need for terms as to access, storage, use and disposal to be clearly communicated and understood by the consumer.  The Principles additionally emphasize the importance that the consumer understand and be provided with data sharing revocation terms that can readily and simply be invoked as to access, use and storage of data.
  • Authorizing Payments.  The Principles advocate for separate and distinct authorizations for data access and payment authorization.
  • Security.  The Principles recognize the gaps that potentially exist in the FTC Safeguard Rules and whether or not certain data aggregation providers are required to comply (as they may fall into a gap between covered financial service providers and vendors).  With regard to security, the Principles recognize the need for market participants to securely access, store, use, and distribute data in formats and manners which protect against security breaches.  The Principles further advocate for secure access credentials and effective processes that “mitigate the risks of, detect, promptly respond to, and resolve and remedy data breaches, transmission errors, unauthorized access, and fraud, and transmit data only to third parties that also have such protections and processes” in place.
  • Access Transparency.  Consumers should be informed of or able to readily ascertain “which third parties that they have authorized are accessing or using information regarding the consumers’ accounts or other consumer use of financial services.”  The Principles emphasize the ability of consumers to ascertain the “identity and security of each such party, the data they access, their use of such data, and the frequency at which they access the data.”
  • Accuracy.  The Principles express the expectation that data that consumers access or authorize others to access is current.
  • Ability to Dispute and Resolve Unauthorized Access.  The Principles set forth the expectation that consumers “have reasonable and practical means to dispute and resolve instances of unauthorized access and data sharing, unauthorized payments conducted in connection with or as a result of either authorized or unauthorized data share access, and failures to comply with other obligations , including the terms of consumer authorizations.”
  • Efficient and Effective Accountability Mechanisms.  Commercial participants are held accountable for “the risks, harms and costs they introduce to consumers” and are “incentivized and empowered effectively to prevent, detect and resolve unauthorized access and data sharing, unauthorized payments” and “failures to comply with other obligations, including terms of consumer authorizations.

The Bureau’s Report as to the November RFI reflects consensus amongst stakeholders that market participants need to work together to develop data access and use practices that are based upon a shared set of standards and expectations that address consumer protection.  Those engaged in fintech should carefully monitor developments in this area, as well as the CFPB’s developing position as to their role in regulating the same.

Monday, January 2, 2017

A Look Back and 2016 and a Look Ahead at 2017


The end of the year is always a time for reflection for me.  As we kick 2016 to the curb, I thought I'd take this opportunity to look back at 2016 and look ahead to 2017. 

2016: A Look Back

Looking back at 2016, the first things that come to my mind are the aggressive rule making agenda undertaken by the CFPB and their struggle to implement rules based upon a less than full understanding of the industries they attempt to regulate.  With 2016 came proposed rules on arbitration and payday lending, adjustments and clarification to the mortgage servicing rules and TRID, as well as an unwieldy and incomplete proposal on debt collection.  The year also saw the CFPB continued to flex its muscle expanding its reach into data privacy and fintech , as well as to inthe way attorneys litigate collection law suits (covered in our prior edition).  Continuing its infatuation with technology, the CFPB also introduced new data tools including its ”Consumer Credit Trends” tools.  In many ways, it was the most ambitious of years for the CFPB. 

As we look forward to 2017, we will closely follow the D.C. Circuit’s en banc review of the CFPB’s jurisdiction.  Coupled with the election of Donald Trump and a Republican majority in Congress here are a couple of things ) think we can expect to see in 2017:

  • Reform of the CFPB:  It would not be surprising to see the makeup of the CFPB change to a five person commission and/or to see the CFPB lose its designation as an independent agency.  Challenges have come from the judiciary and legislative branches of government in recent months and we can expect to see reform from the Trump administration. The Financial Services Committee of the House attempted last year to replace Cordray with a bipartisan commission through introduced legislation.  Similarly, the incoming administration has echoed a desire to reign in the Bureau.  Finally, the D.C. Circuit has weighed in on the constitutionality of the CFPB and its ruling is now being considered en banc by its entire panel of judges. Depending upon the outcome of the D.C. Circuit’s en banc review of the PHH decision, the CFPB may become an executive agency vs. an independent agency.  The net result may be that the CFPB and its regulations become subject to the regulatory review process of the Office of Management and Budget. 
  • Pending Rules. The CFPB’s pay day and arbitration rules are in jeopardy and may never see the light of the day if the PHH holding is upheld and the CFPB loses its status as an independent agency or if any of the other forces outlined above come to play.
  • When all else fails, UDAAP Carries the Day. The CFPB will continue to regulate through enforcement using the UDAAP provisions of Dodd Frank when regulatory authority does not otherwise exist.
  • Debt Collection: the CFPB will continue to struggle with the two ton gorilla of debt collection by first putting forward a proposal for first party collections.  We expect to see a SBREFA panel scheduled for some time in the first half of 2017.  Looking further forward, we are likely to see a proposed rule on debt collection by the end of 2017.
  • Marketing and Sales. Regulators will continue to focus on marketing and sales aspects of consumer financial service products and continue to emphasize comprehensive compliance management systems.
  • Status Quo. Institutions subject to enforcement need to continue to do business under the assumption that nothing will change and remain vigilant in their compliance.  As we sit here today, the status quo remains the order of business.
I'm looking forward to see what's next. On a more personal note,thanks to all who continue to support this blog.  What started out as a six month experiment has become a passion.  This blog has brought new people and opportunities into my life and continues to make me a better lawyer.  I'm grateful to my law firm for supporting me in this endeavor, to my good friends Jerry Myers and Mark Dobosz for their guest posts and to NARCA, WebRecon and the many other blogs and trade associations who continue to pass on my posts to others.  We continue to look for guest posts and I invite anyone with an interest in writing on consumer financial service issues to reach out to me.  Happy New Year!

Tuesday, September 13, 2016

Bankruptcy Court Sanctions Hospital for Proof of Claim Snafu


A recent decision from a North Carolina Bankruptcy Court emphasizes the need for proper training for those who file proofs of claim on behalf of anyone providing consumer credit, including healthcare providers.  Bankruptcy Rule 9037 requires that in all court filings containing an individual’s social security number, taxpayer-identification number, birth date and financial account number be redacted to the last four digits of the social security or taxpayer identification number, the year of the individual’s birth and the last four digits of the account number.  Additionally, if the filing identifies a minor, it may only contain the minor’s initials. 

A series of sanctions motions brought in the Eastern District of North Carolina alleged that a hospital filed a large volume of proofs of claim which contained personal information of the debtors that should have been redacted under Bankr. Rule 9037.  Moreover, a number of the proofs of claim also may have contained protected health information. See In re Wayne Edward Branch, Case No. 14-02379-5-SWH (Bankr. E.D.N.C.); In re Carla Lynette Bostick, Case No. 15-5318-5-SWH (Bankr. E.D.N.C.); In re Janis Monroe Clark, Case No. 15-01265-5-SWH (Bankr. E.D.N.C.).  The debtors asserted that the inclusion of such information violated federal and state identity protection laws and Rule 9037 and also violated the hospital’s own “Privacy Policy” which is provided to patients. See, e.g., In re Wayne Edward Branch, Dkt Nos. 143 and 146. 

Testimony at the sanctions hearing highlights the importance of an adequately training staff.  At the sanctions hearing, staff for the hospital testified that their HIPAA training did not cover bankruptcy claims filing, no audit system was in place and there was no record keeping policy in place with respect to proofs of claim.  At the sanction hearing, staff for the hospital further testified that they were unaware that electronically filed proofs of claim were accessible by persons other than the trustees and believed that the filing of proofs of claim were payment collections and thus, an exception to HIPAA.  Testimony at the sanction hearing further made clear the issues alleged in the sanctions motions were systemic.

In its Sanctions Order, the court first noted that with respect to HIPAA, it did not believe it had jurisdiction to opine or determine sanctions for violations of HIPAA.  The court however, did note that the majority of bankruptcy courts that have reviewed the issue have found there to be no private right of action under HIPAA and the remedy under Bankruptcy Rule 9037 is to restrict the offending information from public view.  In re Branch, 2016 Bankr. LEXIS 3194 (E.D.N.C. Bank. Aug, 31, 2016).  The court went on, however, to award sanctions for violation of Bankruptcy Rule 9037.  The court concluded that the fact that there was no supervision or training indicated that the hospital was more than negligent.  Id. at *34.  “An institution that participates in the bankruptcy process as frequently as Wake Med simply cannot ignore the requirements of the court; the Code and Rules are of equal importance to the requirements of HIPAA and other regulations that govern Wake Med’s business practices.”  Id. “Based upon the sheer volume and the limitations on the ability of the court staff to restrict access to more than 1,410 claims on any given day, it took several weeks for all of the claims to be restricted and/or redacted.” Id.  The court awarded the lead consumers’ their attorney’s fees and ordered the hospital to pay punitive damages in the amount of $70,000.  The court’s order requires remediation by the hospital and the filing of quarterly reports with the Bankruptcy Administrator for five years.

The hospital’s saga emphasizes the need for health care providers and other entities providing non-traditional financial services to examine their compliance management systems and insure compliance with not only HIPAA but also data privacy and other consumer protection statutes. 

For healthcare providers in particular, the order serves as a wake up call.  To the extent proofs of claim are filed, healthcare providers should insure that they are familiar with the Bankruptcy Rule requirements.  Any proofs of claim filed with the bankruptcy court should:

  • Be limited to the last four digits of the social security or taxpayer identification number,
  • Be limited to the year of the individual’s birth
  • Be limited to the last four digits of the account number; and
  • Redact all individuals’ protected healthcare information.

Moreover, healthcare providers should have policies and procedures in place which require the retention of all filed proofs of claim, as well as periodic training and audits to insure there are no violations of HIPAA, federal or state privacy laws or the Bankruptcy Rules. 

 

Friday, September 2, 2016

Guest Post: Why Rental Cars May Present a Serious Loophole in Privacy Policies

By Ragan Riddle
September 2, 2016




If you are charging your phone through a USB port or connecting to Bluetooth in your rental car, you may want to think twice. Last week, an FTC article highlighted the dangers of this seemingly innocent conduct, as it creates an avenue for compromising both you and your clients’ sensitive information.
While individuals connect their devices to rental cars to charge their phones, make calls, listen to music, or use their GPS systems, what these individuals fail to consider is that many cars automatically store this information. If the information is not cleared by the renter or the rental car company, anyone who subsequently rents that car has access to this data. Call and message logs, location coordinates, and contact information then remains long after the rental car is returned.


This can be problematic on two fronts: for rental car companies providing the service and for individuals employed by companies with rigorous privacy standards who compromise this personal information simply by connecting their smart phone to the car.


Rental car companies should consider including a disclosure provision that is given to the customer with the initial pre-rental paperwork. After the rental is returned, these companies should have a policy requiring the information is cleared from the system before the car is rented to anyone else. Failure to address this privacy implication can have unintended compliance consequences as privacy becomes an increasingly prevalent focus for regulatory agencies.


For companies handling sensitive information, however, it is equally important to have a provision within the companies’ existing privacy standards that details appropriate protocol for connecting employee devices to rental cars. As the FTC, CFPB, and other regulatory organizations continue to focus on privacy standards for sensitive consumer information, taking action against those who fail to do so, companies would be remiss to ignore this obvious but often unrecognized privacy loophole.

The FTC article and its mirror article for consumers recommend, among other things, disabling automatic settings that sync electronic devices to rental cars or avoiding connecting mobile devices altogether. While wise, it is unlikely that this will solve the privacy loophole in its entirety.

Though no official action has been taken concerning this issue, it is unlikely that this will refrain from becoming a pressing area for concern and investigation in the future. Recognizing this loophole now may help entities avoid unanticipated privacy issues and impending regulatory action.
About the Author: Ragan Riddle is a summer law clerk with Smith Debnam Narron Drake Saintsing & Myers and a third year law student at Elon University's School of Law


 

Sunday, March 6, 2016

No Consumer Harm? No Direct Enforcement Authority? No Problem – CFPB Enters into Consent Order with Dwolla


This week, the CFPB made its first foray into the data privacy arena by entering into a Consent Order with online payment processor, Dwolla. Inc. via an administrative proceeding.  The Consent Order sends a clear message across the consumer financial services arena that the CFPB will use its UDAAP umbrella to extend its reach and that no consumer harm is required for the CFPB to flex its muscle.

According to the CFPB, it took action because Dwolla “deceived consumers about its data security practices and the safety of its online payment system.”  Without admitting any wrongdoing, the Consent Order includes findings that Dwolla collected and stored consumers’ private information and provided a platform for financial transactions.  According to the findings, Dwolla represented that it maintained “reasonable and appropriate measures to protect data obtained from consumers from unauthorized access.”  However, the CFPB concluded that Dwolla in fact did not take reasonable and appropriate measured to protect consumer data. Specifically, the Order finds that, among other things:

·        For a significant period of time, Dwolla did not adopt or implement reasonable and appropriate data-security policies and procedures to govern the collection, maintenance or storage of consumers’ personal information;

·        For a significant period of time, Dwolla failed to conduct adequate regular risk assessments to identify reasonably foreseeable internal and external risks to information and to assess the safeguards in place to control these risks;

·        For a significant period of time, Dwolla did not provide adequate employee training as to the handling and protection of consumers’ personal information;

·        For a significant period of time, Dwolla transmitted consumers’ personal information without encrypting it; and

·        For a significant period of time, Dwolla did not adequately manage its vendors as to data security.

Pursuant to the Consent Order, Dwolla is required, to the extent it has not done so already:

·        Accurately represent in its marketing, advertising, promotion or administration of its electronic payment networks the data security practices implemented by Dwolla;

·        Implement a comprehensive Written Information Security Plan which mirrors the requirements of GLBA’s Safeguard Rules and which:

o   Designates a qualified person to coordinate its data security program;

o   Identifies reasonably foreseeable internal and external risks to the security and confidentiality of consumer nonpublic information and assess the sufficiency of the institution’s  safeguard in place to control those risks, including risks in areas of operation specifically:

§  Employee training and management; and

§  Confidentiality and integrity of Dwolla’s network systems or apps and storage systems;

o   Implement safeguards to manage the identified risks and regularly test and monitor risks;

o   Develop, implement and maintain reasonable procedures for the selection and retention of service vendors capable of maintaining security practices consistent with the Consent Order; and

o   Evaluate and adjust the data security program in light of the results of the risk assessments and monitoring.

·        Retain a third party independent auditor to conduct an annual data-security audit of Dwolla’s data security practices; and

·        Pay a civil monetary penalty of $100,000.00.

Several things make this order significant and banks and nonbanks alike should take note:

·        Prior to this action, there had been no indication by the CFPB, either through its website or other publications, that it was focused on data security leading many to assume they would defer to the FTC and other regulators on issues of data privacy;

·        Gramm Leach Bliley and its Safeguard Rules (which provide for the protection of consumer nonpublic information by financial service providers) are not among the enumerated consumer protection statutes over which the CFPB has jurisdiction;

·        The Consent Order reflects the CFPB’s position that its UDAAP (unfair and deceptive acts) umbrella liability is expansive enough to take on data security issues; and

·        The Consent Order makes no finding of a data breach or some other sort of consumer or injury.  

Banks and nonbanks alike should pay close attention to the Dwolla Order and expect to see the CFPB continue take expansive views of its authority to regulate.

Wednesday, March 2, 2016

FTC Agrees to Settles with Hardware and Software Provider over Data Privacy Breaches


A recent settlement by the FTC with the manufacturer of computer routers serves as a reminder to all that in the growing Internet of Things, it is critical for companies to place adequate security measures in place to protect consumer’s private data. The FTC’s latest proposed consent order targets Taiwan based computer hardware maker ASUSTek Computer, Inc.  (“ASUS”).  ASUS manufactured and sold home routers and related software and services for consumer use.  ASUS’s routers included software features that allowed consumers to wirelessly access and share files through their routers.  The FTC complaint contends that the software was prone to multiple vulnerabilities and that critical security flaws with the routers “put the home networks of hundreds of thousands of consumers at risk.”  FTCPress Release: ASUS Settles FTC Charges that Insecure Home Routers and “Cloud”Services Put Consumers’ Privacy at Risk (Feb. 23, 2016).

With no admission of liability, the parties have agreed to a proposed consent order which requires ASUS to adopt a comprehensive security program subject to independent audits for the next twenty years.  Here are the key takeaways:

  • Take Reasonable Steps to Secure Software Features from Vulnerabilities.  According to the complaint and proposed consent order, ASUS did not take reasonable steps to secure its routers and their software add-ons.  The FTC showed particular concern that the products at issue were routers which the FTC noted “typically function as a hardware firewall for the local network, and act as the first line of defense in protecting consumer devices on the local network”.  The ASUS routers at issue were preset with the same default username and password and their add on software’s web applications included multiple vulnerabilities which would allow unauthorized access with only the router’s IP address, information the FTC contended was easily discoverable.
     
  • Put Processes in Place to Promptly Address Security Vulnerabilities.  According to the complaint and proposed consent order, ASUS did not address security flaws in a timely manner and did not notify consumers of the risks posed.  The FTC alleges that updated firmware was provided initially only to affected routers and the updates were not made available to all registered users until several months later. 
     

The Consent Order should be reviewed by all companies involved in the Internet of Things as a risk management tool.  It requires:

  • ASUS to fully and accurately to make disclosures to consumers regarding the extent to which the company or its products or services maintain:
    • The security of any covered device;
    • The security, privacy, confidentiality or integrity of any covered information;
    • The extent to which a consumer can use a covered device to secure a network; and
    • The extent to which a device is using up to date software.
       
  • ASUS to develop and maintain a comprehensive written security program (“WISP”) reasonably designed to address security risks related to the development and management of their devices and to protect the privacy, security, confidentiality and integrity of consumer information.  The WISP should, among other things:
    • Identify internal and external risks to privacy, security, confidentiality and integrity of consumer personal information; and the identification of risks should take into consideration all relevant operations, including product design, development and research and secure software design development
    • Identify internal and external risks to security of their devices what could result in unauthorized access and the identification of risks should take into consideration all relevant operations, including product design, development and research and secure software design development;
    • Assess the company’s processes in reviewing, assessing and responding to both third party security vulnerability reports and to attacks, intrusions or system failures;
    • Design and implement safeguards from the outset to identify potential security failures and verify that access to devices and consumer information is restricted consistent with a user’s security settings;
    • Regularly test and monitor the effectiveness of the safeguards’ key controls, systems and procedures;
    • Continue to evaluate and adjust the WISP as needed in light of the results of testing and monitoring.

Thursday, January 21, 2016

Guest Post: Technology, Automation and the Coming of Age – Can the CFPB and the Credit and Financial Services Sectors Partner?

By: Mark Dobosz
January 21, 2016





Public-Private partnerships have often proven to be some of the best examples of meeting the needs of a variety of infrastructures the US economy and its consumers. An article by Andrew Deye in the June 2015 Kennedy School Review indicates that “In a September 2014 report, Moody’s Investors Service stated, ‘the United States has the potential to become the largest P3 market in the world, given the sheer size of its infrastructure’.”
                            

The data centers of our regulatory agencies are a key infrastructure to consumer information and deserve no less than one that can be best built for the 21st century through a Public Private Partnership (P3).

                                                                                          
According to KPMG’s independent audit report of the CFPB, released on January 13, 2016,  
 

The bureau can be more effective in its mission where trust exists between consumers and the agency that works to protect them... The current process for maintaining the inventory of these data sets is manually intensive. In an effort to improve transparency, the CFPB’s Chief Data Office is transitioning from this manual process of tracking these data sets to an automated tool…The CFPB’s chief data office is in the process of transitioning the manual process to the use of an automated tool.

 KPMG’s findings on the CFPB’s privacy policies and procedures

The CFPB has been highly emphatic in requiring the financial services and the debt collection industry to increase compliance by establishing and maintaining systems and procedures to ensure consumer data privacy in all transactions.  All of which have utilized “automated” systems that have proven to be effective and efficient in the credit ecosystem. Millions have been spent by the industry to meet these demands in the past 5-7 years. The National Creditors Bar Association (NARCA) members report a 300%+ increase in compliance costs from 2011-2014.

The experience of implementing secure data automation of consumer financial and personal information is an asset that is currently underutilized by the CFPB. A Public Private Partnership (P3) between industry and the regulatory agency would bring to market the exact types of automation and systems that the regulatory agency has been requiring industry to implement in their financial services and credit ecosystem operations in the past few years. Why offer consumers two standards and systems of data privacy and security protection when a standardized system that is recognized as best in class could be built through a P3 and provide consumers with the confidence that both government and the private sector are on the same page.

As Deye concludes in his article, at a conceptual level, the primary drivers of infrastructure P3s—new sources of capital, cost savings, risk transfer, and accountability—remain strong. Government officials at all levels (federal, state, and local) continue to operate in an environment of constrained financial resources and citizen expectations for efficient and timely operations.”

If I-595, the Port of Baltimore and the Long Beach Courthouse (all recent successful P3 projects) can provide citizens with safe, secure and efficient infrastructure, then a CFPB-Financial Services P3 should be pursued to provide US consumers with the same level of benefits. This P3 could be a “coming of age” in the regulator’s history.

About the Author:  Mark Dobosz currently serves as the Executive Director for NARCA – The National Creditors Bar Association. Mark is a one of NARCA’s speakers on many of the creditors rights issues impacting NARCA members. 




The National Creditors Bar Association (NARCA) is a trade association dedicated to creditors rights attorneys. NARCA's values are: Professional, Ethical, Responsible

Thursday, December 17, 2015

Lessons to be Learned from the Wyndham Hotels Data Breach


The FTC entered into a Consent Order last week with Wyndham Hotels and Resorts resolving the FTC’s allegations that Wyndham did not do enough to prevent its customer’s credit card data from three data breaches that occurred in 2008 and 2009.  The Consent Order comes on the heels of the Third Circuit’s opinion in the case in which the court held that the FTC has authority to hold companies accountable for failing to safeguard consumer data.  See Federal Trade Commission v. Wyndham Worldwide Corp., 799 F. 3d 236 (3rd Cir. 2015).

Specifically, the Complaint alleges that:

  • Wyndham allowed its hotels to store payment card information in clear readable text;
  • Wyndham allowed the use of easily guessed passwords to access the property management systems;
  • Wyndham failed to use readily available security measures such as firewalls to limit access between the hotels’ property management systems, corporate network and the internet;
  • Wyndham did not insure that its hotels implemented adequate information security policies and procedures;
  • Wyndham failed to adequately restrict access of third party vendors to its network and servers;
  • Wyndham failed to employ reasonable measures to detect and prevent unauthorized access to its computer network or to conduct security investigations;
  • Wyndham did not follow proper incident response procedures.  Wyndham did not monitor its network for malware used in the prior intrusions.  As a result, the hackers in each of the three breaches used similar methods to gain access to credit card information.

Specifically, the FTC’s complaint alleges that on three separate occasions in 2008 and 2009 hackers gained access to Wyndham’s network and property management systems and obtained unencrypted information for over 619,000 consumers.  The complaint alleges that Wyndham participated in deceptive and unfair acts or practices related to their data security because it was not proactive in its response after the first data breach specifically by not addressing the weaknesses of its system that led to the initial attack.  As a result, hackers were able to successfully use similar methods in each of the two subsequent attacks.  The Consent Order, which will remain in effect for twenty years, requires Wyndham, among other things:

  • To establish and implement a comprehensive written information security program that is reasonably designed to protect the security, confidentiality, and integrity of its customer’s credit card data;
  • To annually obtain written assessments of its compliance with certain agreed upon data security standards; and
  • To maintain records of its efforts, including audits, policies, and assessments which may be accessed by the FTC upon request.

Businesses which store nonpublic personal information should take note of the FTC Consent Order and take the following lessons to heart:

  • Businesses must develop a Written Information Security Program (“WISP”) which identifies reasonably foreseeable internal and external risks to the security and confidentiality of customer information that could lead to the unauthorized disclosures of personal private information;
  • Businesses must continually assess the sufficiency of the institution’s safeguards and operational risks including detecting, preventing and responding to attacks against the institution’s systems;
  • Businesses must evaluate and adjust the WISP in light of relevant circumstances and changes in the companys environment, business offerings and operations, as well as the results of security testing and monitoring and any cybersecurity breaches which may occur;
  • The FTC has established through the Wyndham litigation that it has authority to bring claims against businesses for cybersecurity intrusions under Section 5 of the FTC Act’s unfair and deceptive umbrella;
  • Businesses are on notice of the FTC’s interpretation of what cybersecurity practices are required by Section 5 of the FTC Act; and
  • Businesses should carefully monitor FTC Consent Orders regarding data breaches and use those consent orders to better model their practices.
Additionally, businesses which store nonpublic personal information should familiarize themselves with state statutes which govern cybersecurity attacks in the event one occurs.  The majority of states have adopted state breach statutes setting forth the notice requirements to consumers, credit reporting agencies and law enforcement in the event a breach occurs.

Friday, November 13, 2015

Initial Thoughts on TRID and the Potential Regulatory Traps for Lenders


The Truth in Lending RESPA Integrated Disclosure Rule (TRID) took effect October 3, 2015 and placed the mortgage industry in unchartered waters.  Our office has spent immeasurable hours reviewing the rule, the commentary, the CFPB Guidelines and listening to lenders’ concerns about the Rule.  Here are our initial observations.

Initial Examinations:  All of the relevant regulators have provided assurances to their supervised entities that examiners will “evaluate an institution’s compliance management system and overall efforts to come into compliance, recognizing the scope and scale of changes necessary for each supervised institution to achieve effective compliance.”  So what does this mean?  It means that examiners will likely be focused on the implementation of policies and procedures and due diligence testing of software in initial examinations.  The good news is that most lenders began implementing policies and procedures regarding TRID well ahead of October 3rd; however, reports from the CFPB and lenders themselves indicate that the software roll out from vendors may not have been as smooth.  Several lenders have indicated that software is still being updated making it difficult for them to do their due diligence in testing the software.  The CFPB has indicated some awareness of the issue, acknowledging that the implementation process "was not as smooth as we would have hoped" and placing the blame largely at the feet of the software vendors.  Our message for lenders, however, remains the same:  make sure you are adequately testing the software and remember, TRID places liability for noncompliance squarely on the lender.

Private Rights of Action/Class Actions:  Simply put, TRID provides more risk for litigation exposure to lenders.  Under TRID, lenders are solely responsible for compliance with the rule.  While RESPA did not provide a private right of action; the TRID Rule relies on the Truth in Lending Act for all disclosure, timing and content requirements.  Truth in Lending does provide a private right of action and thus, it is a foregone conclusion that we will see more litigation under TRID.  Additionally, class actions are likely to become more prevalent.

Loan Estimates:  The timing requirements for Loan Estimates (3 business days from application) places immense pressure on underwriters to perform their analysis of credit worthiness in a very tight time frame.  The ramifications of this are that lenders are going to make loan decisions without adequate time to fully vet credit worthiness.  Additionally, we see the following pitfalls for Loan Estimates:

  • Product Description: When it takes 50+ pages for the CFPB to explain how to fill out a three page form, the form does not meet its goal of simplification.  Case in point: TRID requires that products be described in terms of any payment feature that may change the periodic payment and the duration of the relevant payment feature.  For example, the Commentary to the Rule suggests that an adjustable rate where the introductory rate is 5 years and then adjusts every three years– “5/3 Adjustable Rate.”   It is unlikely that the average consumer is going to understand the import of that product description.
  • Projected Payment Changes: TRID requires that projected payment changes be disclosed.  TRID expressly requires that lenders include within those changes the automatic termination of Mortgage Insurance.  The CFPB has indicated recently that it is concerned that lenders are not appropriately terminating Mortgage Insurance.  This disclosure on the Loan Estimate is therefore likely to receive a lot of attention in Initial Examinations.
  • Overestimating Costs:  Inevitably, there will be an inclination to overestimate costs in order to not run afoul of the Good Faith Estimate Test and tolerance thresholds.  Lenders need to be careful in doing so as a practice of doing so is likely to be scrutinized by examiners for fair lending violations and unfair and deceptive violations.

Closing Disclosures and Consummation:

  • Lenders and their settlement agents need to be cognizant of their obligations to prevent the impermissible disclosure of Nonpublic Personal Information to third parties. 
  • Lenders and their settlement agents need to fully contemplate that Closing Disclosures are likely to need to be revised and have a clear idea as to when an additional three day waiting period is required and when it is not.
  • Additionally, we anticipate that initial examinations will scrutinize the timeliness of refunds to consumers for overpayment of costs as a result of inaccurate Closing Disclosures and whether revised charges were impermissibly charged to the consumer rather than being absorbed by the lender (as determined by the Good faith Test and permissible tolerances).

Monday, April 13, 2015

FTC Announces Settlement with Debt Brokers


The FTC announced today that it has settled two data breach cases with debt brokers. In complaints filed last year, the FTC contended the debt brokers posted consumers’ personal identifying information, including bank account information, credit card numbers, birth dates, and information about debts the consumers allegedly owed on public websites in an unencrypted manner.   See Federal Trade Commission v. Bayview Solutions, LLC, Doc. No. 1:14-cv- 01830 (D.D.C. Apr. 13, 2015); Federal Trade Commission v. Cornerstone and Company, LLC, Doc. No. 1:14-cv-01479 (D.D.C. Apr. 13, 2015). The FTC contended the disclosures violated the consumers’ privacy, put them at risk of identity theft, and exposed them to “phantom” debt collection, resulting in violations of Section 5 of the FTC Act and the Safeguard Rules of the Gramm Leach Bliley Act.  Under the Stipulated Orders, the debt buyers are required to establish, implement and maintain a written information security program in compliance with the Safeguard Rules which will be assessed, audited and certified periodically for twenty (20) years. 
Debt buyers and sellers should keep in mind that they are subject to Gramm Leach Bliley’s safeguard rules and are required to maintain, protect and secure consumers’ records and information. Under the Safeguard Rules, covered entities must develop a written information security plan (“WISP”) to protect customer information. The Rules require that the WISP be appropriate to the financial institution's size and complexity, the nature and scope of its activities, and the sensitivity of the customer information at issue.  Covered institutions are required to:
·       designate one or more employees to coordinate the program;
·       identify and assess the reasonably foreseeable risks to customer information in each relevant area of the company's operation, and evaluate the effectiveness of current safeguards for controlling these risks;
·       design and implement a safeguard plan to manage the identified risks and regularly test or monitor such safeguards;
·       select and oversee appropriate service providers and require them (by contract) to implement safeguards; and
·       continue to evaluate the program and make adjustments in light of changes to its business arrangements or the results of its security tests.
The FTC has published its tips for keeping data secure for companies buying and selling debt:
·       Don’t publicly post or make consumer information publicly available when selling portfolios.
·       Store information securely.  The FTC recommends limiting access to only those employees who need access and maintaining data in password protected files.
·       Minimize the amount of information shared with potential buyers, verify their identities and insure they have safeguards in place to protect any information shared.
·       Transfer data securely using encrypted or password protected files.
·       Dispose of data safely.
·       Have a plan in place to deal with a breach and be familiar with any relevant state statutes governing data breaches.
·       Consult the FTC website for free information