Showing posts with label EFTA. Show all posts
Showing posts with label EFTA. Show all posts

Thursday, October 26, 2017

CFPB Issues “Principles” for the Protection of Consumer Authorized Data Sharing and Aggregation


By Caren Enloe
October 26, 2017


With the growth of technology and the development of the fintech market, an unprecedented amount of consumer financial data has become available.  While protections through the FTC Safeguard Rule and EFTA provide certain consumer protections, there are coverage gaps as the regulatory scheme has struggled to keep up with technological advancements. 

In recognition of these competing forces and this growing market of consumer services, the CFPB issued a Request for Information in November of 2016 inquiring as to market practices related to consumer access to financial information and related data aggregation services.  Last week, the CFPB published their findings, as well as their Consumer Protection Principles which are designed to “reiterate the importance of consumer interests to all stakeholders in the developing market for services based on the consumer-authorized use of financial data.”  While the Principles are “not intended to alter, interpret, or otherwise provide guidance on the scope” of existing consumer protections under existing statutes and regulations or establish binding requirements or obligations relevant to the Bureau’s exercise of its rulemaking, supervisory or enforcement authority”, they appear to be the first step in filling some of the current regulatory gaps.

The CFPB Principles address nine general areas of concern:

  • Access.  The Principles recognize the right of consumers to be “able, upon request, to obtain information about their ownership or use of a financial product or service” from the product or service provider.  The Principles also support the consumer’s right to “authorize trusted third parties to obtain such information from account providers to use on behalf of consumers, for consumers benefit, and in a safe manner.”   
  • Data Scope and Usability.  The Principles set forth that the scope of data that may be made available should be broad; however, the data available to “third parties with authorized access” should be limited to that which is “necessary to provides the product(s) or service(s) selected by the consumer and only maintain such data as long as necessary.”
  • Control and Informed Consent.  The Principles emphasize the consumer’s right to control data access and the need for terms as to access, storage, use and disposal to be clearly communicated and understood by the consumer.  The Principles additionally emphasize the importance that the consumer understand and be provided with data sharing revocation terms that can readily and simply be invoked as to access, use and storage of data.
  • Authorizing Payments.  The Principles advocate for separate and distinct authorizations for data access and payment authorization.
  • Security.  The Principles recognize the gaps that potentially exist in the FTC Safeguard Rules and whether or not certain data aggregation providers are required to comply (as they may fall into a gap between covered financial service providers and vendors).  With regard to security, the Principles recognize the need for market participants to securely access, store, use, and distribute data in formats and manners which protect against security breaches.  The Principles further advocate for secure access credentials and effective processes that “mitigate the risks of, detect, promptly respond to, and resolve and remedy data breaches, transmission errors, unauthorized access, and fraud, and transmit data only to third parties that also have such protections and processes” in place.
  • Access Transparency.  Consumers should be informed of or able to readily ascertain “which third parties that they have authorized are accessing or using information regarding the consumers’ accounts or other consumer use of financial services.”  The Principles emphasize the ability of consumers to ascertain the “identity and security of each such party, the data they access, their use of such data, and the frequency at which they access the data.”
  • Accuracy.  The Principles express the expectation that data that consumers access or authorize others to access is current.
  • Ability to Dispute and Resolve Unauthorized Access.  The Principles set forth the expectation that consumers “have reasonable and practical means to dispute and resolve instances of unauthorized access and data sharing, unauthorized payments conducted in connection with or as a result of either authorized or unauthorized data share access, and failures to comply with other obligations , including the terms of consumer authorizations.”
  • Efficient and Effective Accountability Mechanisms.  Commercial participants are held accountable for “the risks, harms and costs they introduce to consumers” and are “incentivized and empowered effectively to prevent, detect and resolve unauthorized access and data sharing, unauthorized payments” and “failures to comply with other obligations, including terms of consumer authorizations.

The Bureau’s Report as to the November RFI reflects consensus amongst stakeholders that market participants need to work together to develop data access and use practices that are based upon a shared set of standards and expectations that address consumer protection.  Those engaged in fintech should carefully monitor developments in this area, as well as the CFPB’s developing position as to their role in regulating the same.

Tuesday, January 24, 2017

CFPB Sues Bank Over Overdraft Sales Pitch


The CFPB’s concern with incentives and overdrafts continues and has resulted  in a lawsuit filed against a Minnesota based TCF National Bank.  In the lawsuit, the CFPB alleges that TCF National Bank violated the UDAAP provisions of the Consumer Financial Protection Act and the Electronic Funds Transfers Act (“EFTA”).  In 2010, EFTA was amended to require consumers “opt in” to overdraft coverage for ATM and one-time debit card transactions. 

The complaint which appears to be based upon statements taken from former employees (rather than from customer complaints) is filed in the United States District Court for the District of Minnesota.  See generally, Consumer Financial Protection Bureau v. TCF National Bank, 17-cv-00166, Dkt No. 1 (D. Minn. Jan. 19, 2017).  According to the complaint, TCF utilized consumer testing to determine the best strategy for gaining maximum opt in consent from account holders.  The bank  then designed its opt in program in a manner that did not provide consumers with the ability to provide informed consent.  According to the complaint, employees were provided scripts and strategies which were designed to achieve opt in by the customer.  According to the CFPB, TCF’s explanation was so short that “consumers tended not to pay attention to the decision” and were left with the impression that opting in was mandatory.  Moreover, the CFPB alleged that the script characterized opting in as a choice to allow the Bank to provide a benefit.  The complaint further alleges that the bank incentivized its employees through 2010 by offering “substantial financial incentives” of up to $7,000.00/year for managers of large branches for achieving performance goals related to opt ins.  After incentives were phased out, the CFPB alleges the bank set performance goals which required branch employees to maintain an opt-in rate of 80% or higher on all new accounts they opened.  The complaint additionally alleges that TCF’s opt in rates were significantly higher than those of other similarly situated banks. 

TCF’s press release indicates that it intends to defend the lawsuit and “rejects the claims made by the CFPB”.  “We believe we have strong, principled defenses to the CFPB’s complaint.  We also believe the CFPB’s claims are based on data not representative of TCF’s customers and mischaracterizes our opt-in practices and disclosures, which we believe clearly informed customers about their choice before, during, and after their opt-in decision.”  TCF further asserts that the complaint is contradicted by two key facts.  “First, TCF customers who opened accounts online between 2010 and 2016, with no face-to-face interaction with TCF employees, opted in to TCF’s overdraft protection at a consistent rate of over 60%.  Second, there were virtually no complaints from customers stating that they did not understand they had opted in to overdraft protection.  From 2010 to 2015, there were a total of only 341 complaints from our 2.6 million customers related to their decision to opt-in.”

 The law suit bears watching for several reasons.  First, it raises the issue as to what constitutes informed consent.  Regulation E requires that financial institutions provide consumers with a written statutory notice which contains specific disclosures and that consumers be given a reasonable opportunity to opt in.  See 12 CFR 1005.17.  The Complaint does not appear to take issue with the form or content of the notice but rather takes issue with the sales pitch. Secondly, the complaint once again takes up the issue of the relationship between consumer protection and sales, focusing on incentivizing employees and the establishment of aggressive performance goals.  Thirdly, it appears the CFPB takes issue with the fact TCF was obtaining a 66% opt in rate – “a rate more than triple the average opt-in rate at other banks.”  CFPB Prepared Remarks of Richard Cordray (January 19, 2017).  This is likely one of the reasons the CFPB has focused on TCF’s opt-in procedures.
Financial institutions should continue to follow this matter and examine their own opt-in provisions as this has been a point of discussion in multiple CFPB enforcement actions and reports over the past two years.  Additionally, the complaint re-emphasizes the CFPB’s concerns with employee incentives and the importance of insuring performance goals are aligned  carefully with compliance with consumer protection statutes.



Monday, November 14, 2016

CFPB Supervisory Highlights: A Mixed Bag for Debt Collectors


The CFPB’s Fall Supervisory Highlights contains a mixed bag for debt collectors.  As you may recall, the Report highlights examinations that were conducted between May and August 2016 and provides a high level summary of the key findings made by the CFPB and the current emphasis of examiners.  Debt collection appears to be back as a point of emphasis for examiners.  The Report makes the following observations which should be heeded by debt collectors:

  • CONVENIENCE FEES. Convenience fees continue to be a theme carried over from the Summer Supervisory Highlights.  The CFPB again noted in one or more examinations, the CFPB observed one or more debt collectors charging unauthorized convenience fees to process payments by phone or online.
  • INADEQUATE CALL PROCEDURES.  The Report notes that weak Compliance Management Systems attributed to a number of concerns with communications both between the debt collector and the consumer and the debt collector and a third party. While noting these deficiencies, the Report also offered praise for those debt collectors who had “well-established, formal compliance program[s] that met CFPB’s supervisory expectations”, particularly those who used scripts to improve adherence to compliance policies and regularly monitored script adherence. The following deficiencies are highlighted:
    • In one or more examinations, examiners identified collection calls in which the debt collector made false representations regarding the impact that the debt or payment of the debt may have on a consumer’s creditworthiness;
    • The CFPB noted deficiencies with the practices of one or more examined entities concerning third party communications.  Specifically, the Report notes that in one or more examinations, collectors disclosed the debt to third parties, disclosed their employer to third parties without first being asked.

  • COMPLIANCE WITH THE FCRA. The Report also noted issues with compliance with Regulation V and the FCRA, continuing a theme raised in the Summer Supervisory Highlights. 
    • Specifically, the Report notes that entities are still struggling with differentiating FCRA disputes from general consumer inquiries, complaints and debt validation requests.  To that end, Supervision directed one or more entities to develop and implement reasonable policies and procedures and establish training to ensure FCRA disputes are appropriately logged, categorized and resolved. 
    • Along similar lines, the Report noted inadequate dispute resolution policies and procedures at one or more examined entities. The Report noted that one or more debt collectors never investigated indirect disputes that either lacked detail or were not accompanied by documentation with relevant information. 
    • The Report also notes concerns with direct disputes.  Regulation V requires that furnishers provide consumers with a notice of determination if a dispute is determined to be frivolous.  In one or more examinations, the examiners noted that the notices failed to advise the consumers of what additional information was needed for the collector to complete its investigation.
  • REGULATION E.  The examiners also noted deficiencies with one or more entities compliance with Regulation E.  Specifically,
    • Examiners found that one or more debt collectors failed to provide consumers with the requisite copies of the terms of the authorization, either electronically or in paper form; and
    • Examiners also found that one or more debt collectors who did provide notice, sent deficient notices that failed to describe the recurring nature of the preauthorized transfers from the consumer’s account.
       

The Report reflects that examiners are now focusing on issues aside from compliance with the FDCPA.  Compliance officers need to take a comprehensive look at their policies and procedures and insure their compliance management systems are reflective of compliance with all applicable consumer financial laws which impact their operations.

 

Tuesday, July 5, 2016

CFPB Issues its Summer Supervisory Highlights


The CFPB published its Summer Supervisory Highlights last week, highlighting examinations that were conducted between January 2016 and April 2016 across various financial products.  The Report comes on the heels of a Supervisory highlight report devoted entirely to mortgage servicing. The Report highlights key findings made by the CFPB and provides insight into the current focus of examiners.  The Report highlights a number of technology failures and covers auto finance, debt collection, mortgage origination, payday lending and fair lending.  The CFPB noted the following issues worthy of mention:



AUTO FINANCE


The Report makes two specific observations and one very general observation.  As suggested in other recent CFPB activity, the CFPB is scrutinizing add on products and the representations made by lenders regarding the same.  Specifically, the Bureau noted that add on products and specifically, gap coverage products, should be accurately described. The CFPB also noted that one or more auto lenders engaged in deceptive practices when allowing consumer to defer payments in that they omitted details as to how interest would accrue and how payments would be applied as a result of the deferral. 
The Bureau also noted compliance management system weaknesses in one or more examinations.  Specifically, the Bureau noted the following deficiencies and auto lenders, both direct and indirect, should take note:
·      Failure to raise compliance-related issues to the institution’s board of directors or their principal;
·      Failure to monitor and correct business line practices to align with federal consumer financial law;
·       Failure to adequately track training completed by employees and the Board;
·       Failure to follow up on consumer complaints; and
·      Failure of compliance audits to highlight deficiencies in the consumer complaint response process.

DEBT COLLECTION


· Banks and other original creditors who sell debt should carefully review their technology and their use of coding.  The Bureau noted that, as a result of coding errors, one or more debt sellers sold accounts which were in bankruptcy, accounts that were products of fraud and accounts that had been paid in full.
· The Bureau also found that one or more debt collectors made false representations to collect debt. Particularly, the Bureau noted instances of debt collectors making representations that down payments were required to establish a repayment plan and that use of a checking account was the only option for repayment.  In both instances, the debt collector’s policies and procedures did not support the representations and the Bureau concluded that the practice was deceptive.


MORTGAGE ORIGINATION

The majority of the Report is devoted to mortgage origination issues and reflect some of the struggles faced by lenders since the implementation of TRID.  Specifically, the Bureau’s examinations indicated that:

·       One or more lenders incorrectly calculated the amount financed on loans with discount credits and subsequently incorrectly calculated the finance charge on the same loans, resulting in a negative finance charge and an amount financed that exceeded the stated loan amount;

·       One or more lenders offering bridge loans failed to accurately disclose the interest payments due to a software failure;

·       One or more institution demonstrated weak oversight of their automated systems, including inadequate testing of codes that calculate the finance charge and the amount financed when originating residential loans to consumers.

The Report also noted failures to comply with the Fair Credit Reporting Act.  The Report indicates that one or more institutions failed to comply with the FCRA’s adverse action notice requirements.



PAYDAY LENDING

It should not come as a surprise to those following the proposed payday rules, the CFPB has concerns as to electronic fund transfers on small short term loans.  The Bureau’s examinations noted issues with compliance with the Electronic Fund transfer Act.  Specifically, the Report notes that one or more lenders’ loan agreements were ambiguous as to the acceptable range of amounts to be debited.  As a consequence, lenders were required to revise their loan agreements for new loans. For existing loans, the Bureau required one or more entity to notify borrowers of the amount of any new transfer that will vary from the amount of the previous or preauthorized amount before initiating the new transfer.