Showing posts with label FTC. Show all posts
Showing posts with label FTC. Show all posts

Friday, September 2, 2016

Guest Post: Why Rental Cars May Present a Serious Loophole in Privacy Policies

By Ragan Riddle
September 2, 2016




If you are charging your phone through a USB port or connecting to Bluetooth in your rental car, you may want to think twice. Last week, an FTC article highlighted the dangers of this seemingly innocent conduct, as it creates an avenue for compromising both you and your clients’ sensitive information.
While individuals connect their devices to rental cars to charge their phones, make calls, listen to music, or use their GPS systems, what these individuals fail to consider is that many cars automatically store this information. If the information is not cleared by the renter or the rental car company, anyone who subsequently rents that car has access to this data. Call and message logs, location coordinates, and contact information then remains long after the rental car is returned.


This can be problematic on two fronts: for rental car companies providing the service and for individuals employed by companies with rigorous privacy standards who compromise this personal information simply by connecting their smart phone to the car.


Rental car companies should consider including a disclosure provision that is given to the customer with the initial pre-rental paperwork. After the rental is returned, these companies should have a policy requiring the information is cleared from the system before the car is rented to anyone else. Failure to address this privacy implication can have unintended compliance consequences as privacy becomes an increasingly prevalent focus for regulatory agencies.


For companies handling sensitive information, however, it is equally important to have a provision within the companies’ existing privacy standards that details appropriate protocol for connecting employee devices to rental cars. As the FTC, CFPB, and other regulatory organizations continue to focus on privacy standards for sensitive consumer information, taking action against those who fail to do so, companies would be remiss to ignore this obvious but often unrecognized privacy loophole.

The FTC article and its mirror article for consumers recommend, among other things, disabling automatic settings that sync electronic devices to rental cars or avoiding connecting mobile devices altogether. While wise, it is unlikely that this will solve the privacy loophole in its entirety.

Though no official action has been taken concerning this issue, it is unlikely that this will refrain from becoming a pressing area for concern and investigation in the future. Recognizing this loophole now may help entities avoid unanticipated privacy issues and impending regulatory action.
About the Author: Ragan Riddle is a summer law clerk with Smith Debnam Narron Drake Saintsing & Myers and a third year law student at Elon University's School of Law


 

Monday, May 30, 2016

Furnisher Duties for Collection Agencies-Creating a Good Compliance Management System

Recent FTC consent orders, as well as the continued focus by the CFPB on credit reporting serve as a good reminder to collection agencies and creditors to carefully scrutinize their FCRA policies and procedures to insure they are in compliance with the FCRA’s Furnisher Rule and the guidelines set forth in 12 CFR 1022, Appendix E.


The Furnisher Rule requires data furnishers to establish and implement reasonable written policies and procedures regarding the accuracy and integrity of the consumer information they furnish to a consumer reporting agency.   It’s not enough to simply establish policies and procedures, furnishers should remain nimble reassessing their policies and procedures to insure they remain relevant and reasonably tailored to address potential weaknesses and deficiencies. 


Here are the keys to an effective and compliant policy:
  • A robust policy will be tailored to the nature, size and complexity of the furnisher. Furnishers need to make sure their policies match the nature, size, complexity, and scope of their business practice.  We suggest considering the following questions and allow the answers to shape or revise your present policies and procedures:
    •  What type of information do you provide?
    • What is your role – are you an original creditor? A servicer? A debt buyer? Third party debt collector?
    • How often do you furnish information?
    • How do you provide the information (i.e. what technology platform is used)?
       
  • A robust policy accomplishes the following:
    • Insures information provided is accurate. Your policies and procedures should be designed to insure that your furnishing of information:
      • Accurately identifies the consumer;
      • Accurately identifies relationships to the account;
      • Accurately reflects the  account terms and liabilities;
      • Accurately reflects consumer performance/conduct regarding the account;
      • Is validated by your records (or your client’s) at the time it is furnished;
      • Is reported in a format that minimizes inaccuracies. This can be done by including consumer identification information, relevant dates, and, if applicable, credit limits for accounts.
    • Promotes reasonable investigation procedures and appropriate actions based on investigation outcomes, including accurately updating information about the current status of the account. A robust policy:
      • Provides adequate training to employees who are responsible for investigating and resolving indirect disputes.
      • Provides adequate training to employees regarding direct disputes from the consumer;
      • Requires documenting the actions taken to process, respond or investigate FCRA disputes;
         
      • To the extent the furnisher is a servicer or third party vendor includes procedures and policies concerning communications to the creditor regarding the dispute;
      • Provides for document retention for a reasonable period of time to allow for effective training and auditing
      • Provides for review of all relevant information provided by the consumer;
      • Insures a timely and adequate response to the consumer; and
      • Provides for correction, deleting and updated of all disputed information.
    • Provides for updating information as necessary to accurately reflect the current status of the account or any changes in relationships (i.e., a sale or transfer of the account).
    • Prevents re-aging, duplicative reporting, or other problems that affect the accuracy or integrity of information furnished by having an appropriate system to communicate with CRAs.
    • Provides for regular and robust auditing of accounts to help identify and resolve any systemic weaknesses or trends.
      • Furnishers should verify random samples of information furnished; and
      • Furnishers should randomly and regularly audit random disputes.
    • Provides for a regular and periodic evaluation of:
      • Its own practices;
      • Enforcement trends;
      • Consumer reporting agency practices; and
      • Any other factors which may impact the integrity of information being furnished.
    • Requires the use of standard data reporting  formats and procedures; and
    • Establishes and implements internal controls regarding the accuracy and integrity of furnished information

The key to any robust compliance management system is to remain flexible and adjust policies and procedures in a timely fashion to address environmental changes as they occur.

Thursday, March 17, 2016

FTC Adds to its Debt Collection "Hall of Shame"

In a blog post earlier this week, the FTC proudly touted the expansion of its Debt Collection "Hall of Shame."  Originally issued in February of 2015, the list has grown from 63 "inductees" to more than 100.  The quick expansion of the list is largely due to "Operation Collection Protection, the FTC's partnership with federal, state and local law enforcement against debt collectors using illegal debt collection tactics.  Through November of last year, the operation had resulted in 115 actions taken. As an advocate for the debt collection industry, I applaud the FTC's efforts to stop illegal debt collection tactics.  The vast majority of debt collectors are committed to complying with federal and state debt collection laws.  Those who are not tarnish the industry's reputation.

Wednesday, March 2, 2016

FTC Agrees to Settles with Hardware and Software Provider over Data Privacy Breaches


A recent settlement by the FTC with the manufacturer of computer routers serves as a reminder to all that in the growing Internet of Things, it is critical for companies to place adequate security measures in place to protect consumer’s private data. The FTC’s latest proposed consent order targets Taiwan based computer hardware maker ASUSTek Computer, Inc.  (“ASUS”).  ASUS manufactured and sold home routers and related software and services for consumer use.  ASUS’s routers included software features that allowed consumers to wirelessly access and share files through their routers.  The FTC complaint contends that the software was prone to multiple vulnerabilities and that critical security flaws with the routers “put the home networks of hundreds of thousands of consumers at risk.”  FTCPress Release: ASUS Settles FTC Charges that Insecure Home Routers and “Cloud”Services Put Consumers’ Privacy at Risk (Feb. 23, 2016).

With no admission of liability, the parties have agreed to a proposed consent order which requires ASUS to adopt a comprehensive security program subject to independent audits for the next twenty years.  Here are the key takeaways:

  • Take Reasonable Steps to Secure Software Features from Vulnerabilities.  According to the complaint and proposed consent order, ASUS did not take reasonable steps to secure its routers and their software add-ons.  The FTC showed particular concern that the products at issue were routers which the FTC noted “typically function as a hardware firewall for the local network, and act as the first line of defense in protecting consumer devices on the local network”.  The ASUS routers at issue were preset with the same default username and password and their add on software’s web applications included multiple vulnerabilities which would allow unauthorized access with only the router’s IP address, information the FTC contended was easily discoverable.
     
  • Put Processes in Place to Promptly Address Security Vulnerabilities.  According to the complaint and proposed consent order, ASUS did not address security flaws in a timely manner and did not notify consumers of the risks posed.  The FTC alleges that updated firmware was provided initially only to affected routers and the updates were not made available to all registered users until several months later. 
     

The Consent Order should be reviewed by all companies involved in the Internet of Things as a risk management tool.  It requires:

  • ASUS to fully and accurately to make disclosures to consumers regarding the extent to which the company or its products or services maintain:
    • The security of any covered device;
    • The security, privacy, confidentiality or integrity of any covered information;
    • The extent to which a consumer can use a covered device to secure a network; and
    • The extent to which a device is using up to date software.
       
  • ASUS to develop and maintain a comprehensive written security program (“WISP”) reasonably designed to address security risks related to the development and management of their devices and to protect the privacy, security, confidentiality and integrity of consumer information.  The WISP should, among other things:
    • Identify internal and external risks to privacy, security, confidentiality and integrity of consumer personal information; and the identification of risks should take into consideration all relevant operations, including product design, development and research and secure software design development
    • Identify internal and external risks to security of their devices what could result in unauthorized access and the identification of risks should take into consideration all relevant operations, including product design, development and research and secure software design development;
    • Assess the company’s processes in reviewing, assessing and responding to both third party security vulnerability reports and to attacks, intrusions or system failures;
    • Design and implement safeguards from the outset to identify potential security failures and verify that access to devices and consumer information is restricted consistent with a user’s security settings;
    • Regularly test and monitor the effectiveness of the safeguards’ key controls, systems and procedures;
    • Continue to evaluate and adjust the WISP as needed in light of the results of testing and monitoring.

Tuesday, February 23, 2016

FTC Releases Annual Report on its Debt Collection Enforcement


On February 17, 2016, the FTC provided the CFPB with its annual update of its activities in the debt collection field. The update was provided to assist the CFPB in preparing its annual report to Congress and makes clear that debt collection is a point of emphasis for the FTC and emphasizes its close collaboration with the CFPB and law enforcement.  Highlighted within the report was the FTC’s first initiative involving all three levels of law enforcement to crack down on illegal debt collection practices.  The initiative has included over 70 different law enforcement agencies and led to the commencement of more than 130 enforcement actions.  The FTC also filed 12 new FDCPA cases in 2015, which is the most in its history, and resolved nine cases, resulting in $94 million in judgments.  The report also proudly touts the Debt Collector’s Black List published by the FTC which includes every company and individual banned from debt collection.  Additionally, the FTC Report highlights the three debt collection dialogues conducted by the FTC this past year which brought together actors from all sectors, including debt collectors, collection attorneys, law enforcement agencies, and consumers.  Finally, the report confirms the close collaboration which is ongoing between the CFPB and FTC as to the impending debt collection rules. 

Friday, February 12, 2016

FTC Continues to Focus on Fair Lending Issues in Auto Finance


Earlier this week, the FTC provided the CFPB with its annual update of FTC enforcement activities related to compliance with the Equal Credit Opportunity Act.  The update was provided to assist the CFPB in preparing its annual report to Congress.  The update makes clear that fair lending in the auto finance sector remains a high priority for the FTC. 
Since 2015, the FTC has brought more than 25 cases regarding auto finance transactions.  On December 29, 2015, the FTC announced that it was seeking public comment on a proposed survey to consumers regarding their experiences buying and financing automobiles at dealerships.    The annual report explains that the survey is intended to provide useful insights about current consumer protection issues that exist and could be addressed through enforcement initiatives.  The annual update reinforces this focus also pointing toward a conference cohosted by the FTC and NAACP in 2015 which included a discussion of key consumer issues including auto finance.  The update notes that “some conference participants provided information about auto loan fraud, and about the denial of mortgages to African Americans at a higher rate than other groups.”

Thursday, December 17, 2015

Lessons to be Learned from the Wyndham Hotels Data Breach


The FTC entered into a Consent Order last week with Wyndham Hotels and Resorts resolving the FTC’s allegations that Wyndham did not do enough to prevent its customer’s credit card data from three data breaches that occurred in 2008 and 2009.  The Consent Order comes on the heels of the Third Circuit’s opinion in the case in which the court held that the FTC has authority to hold companies accountable for failing to safeguard consumer data.  See Federal Trade Commission v. Wyndham Worldwide Corp., 799 F. 3d 236 (3rd Cir. 2015).

Specifically, the Complaint alleges that:

  • Wyndham allowed its hotels to store payment card information in clear readable text;
  • Wyndham allowed the use of easily guessed passwords to access the property management systems;
  • Wyndham failed to use readily available security measures such as firewalls to limit access between the hotels’ property management systems, corporate network and the internet;
  • Wyndham did not insure that its hotels implemented adequate information security policies and procedures;
  • Wyndham failed to adequately restrict access of third party vendors to its network and servers;
  • Wyndham failed to employ reasonable measures to detect and prevent unauthorized access to its computer network or to conduct security investigations;
  • Wyndham did not follow proper incident response procedures.  Wyndham did not monitor its network for malware used in the prior intrusions.  As a result, the hackers in each of the three breaches used similar methods to gain access to credit card information.

Specifically, the FTC’s complaint alleges that on three separate occasions in 2008 and 2009 hackers gained access to Wyndham’s network and property management systems and obtained unencrypted information for over 619,000 consumers.  The complaint alleges that Wyndham participated in deceptive and unfair acts or practices related to their data security because it was not proactive in its response after the first data breach specifically by not addressing the weaknesses of its system that led to the initial attack.  As a result, hackers were able to successfully use similar methods in each of the two subsequent attacks.  The Consent Order, which will remain in effect for twenty years, requires Wyndham, among other things:

  • To establish and implement a comprehensive written information security program that is reasonably designed to protect the security, confidentiality, and integrity of its customer’s credit card data;
  • To annually obtain written assessments of its compliance with certain agreed upon data security standards; and
  • To maintain records of its efforts, including audits, policies, and assessments which may be accessed by the FTC upon request.

Businesses which store nonpublic personal information should take note of the FTC Consent Order and take the following lessons to heart:

  • Businesses must develop a Written Information Security Program (“WISP”) which identifies reasonably foreseeable internal and external risks to the security and confidentiality of customer information that could lead to the unauthorized disclosures of personal private information;
  • Businesses must continually assess the sufficiency of the institution’s safeguards and operational risks including detecting, preventing and responding to attacks against the institution’s systems;
  • Businesses must evaluate and adjust the WISP in light of relevant circumstances and changes in the companys environment, business offerings and operations, as well as the results of security testing and monitoring and any cybersecurity breaches which may occur;
  • The FTC has established through the Wyndham litigation that it has authority to bring claims against businesses for cybersecurity intrusions under Section 5 of the FTC Act’s unfair and deceptive umbrella;
  • Businesses are on notice of the FTC’s interpretation of what cybersecurity practices are required by Section 5 of the FTC Act; and
  • Businesses should carefully monitor FTC Consent Orders regarding data breaches and use those consent orders to better model their practices.
Additionally, businesses which store nonpublic personal information should familiarize themselves with state statutes which govern cybersecurity attacks in the event one occurs.  The majority of states have adopted state breach statutes setting forth the notice requirements to consumers, credit reporting agencies and law enforcement in the event a breach occurs.

Wednesday, December 9, 2015

FTC Sends Warning to Creditors Collecting Their Own Debts: Winter is Coming


Creditors collecting their own debts have often sought solace in the fact that they were not covered by the FDCPA; however, over the past few years that solace has been called into question by the CFPB and now the FTC.  In a blog post entitled “ThinkYour Company’s Not Covered by the FDCPA? You May Want to Think Again”, the FTC yesterday warned creditors to carefully consider whether they are covered by the FDCPA and, more importantly, warned that whether or not they are covered by the FDCPA, they are not immune from debt collection violations.  The warning was timely as I spent most of yesterday morning with a bank client discussing the same issue. So why should banks and other first party creditors be concerned?

The FTC Act and Dodd Frank generally prohibit deceptive and unfair practices and both the FTC and CFPB have used this umbrella to punish creditors for unfair and deceptive debt collection issues even where they were not covered by the FDCPA.  For instance, the draconian CFPB Consent Order with JP Morgan Chase which was entered in July, was premised in part on Dodd Frank’s general prohibition on unfair, deceptive or abusive acts because the bank did not fall under the FDCPA.  The FTC’s blog post makes no bones about the Commission’s intent to continue using the FTC Act’s general prohibition in absence of FDCPA coverage stating that “even if the FDCPA doesn’t apply, your collection activities are still covered by Section 5 of the FTC Act’s general prohibition against deceptive or unfair practices….[T]he FTC has taken action under Section 5 when first-party creditors engage in other practices expressly prohibited by the FDCPA – for example, revealing the existence of a debt to anyone other than the debtor.”

The CFPB Has Left Little Doubt that Impending Regulation F Will Encompass Creditors Collecting on Their Own Behalf.  To borrow a phrase from Jon Snow on Game of Thrones, “winter is coming” for the debt collection world even for those of us to consider it already here.  The CFPB will likely issue proposed regulations concerning debt collection in the first half of 2016 and those regulations are anticipated to address first party collections, as well as third party collections.  The Bureau’s recent enforcement actions, as well as other publications make clear their position that anyone collecting consumer debt, whether first or third party, cannot do so in an unfair or deceptive manner and all debt collectors will likely be encompassed in Regulation F. 

In 2013, the Bureau issued Compliance Bulletin 2013-07 which clearly laid out its position: “[a]lthough the FDCPA definition of “debt collector” does not include some persons who collect consumer debt, all covered persons and service providers must refrain from committing UDAAPs in violation of the Dodd-Frank Act.” Specifically, the CFPB identified several practices that they are particularly concerned with, including:

  • Collecting or assessing a debt and/or any additional amounts in connection with a debt (including interest, fees, and charges) not expressly authorized by the agreement creating the debt or permitted by law.
  • Failing to post payments timely or properly or to credit a consumer’s account with payments that the consumer submitted on time and then charging late fees to that consumer.
  • Falsely representing the character, amount, or legal status of the debt.
  • Misrepresenting that a debt collection communication is from an attorney or a government source.
  • Misrepresenting whether information about a payment or nonpayment would be furnished to a credit reporting agency.
  • Misrepresenting to consumers that their debts would be waived or forgiven if they accepted a settlement offer, when the company does not, in fact, forgive or waive the debt.
  • Threatening any action that is not intended or the covered person or service provider does not have the authorization to pursue
  • False threats of lawsuits, arrest, prosecution, or imprisonment for non-payment of a debt.

The CFPB concluded by stating that “[o]riginal creditors and other covered persons and service providers involved in collecting debt related to any consumer financial product or service are subject to the prohibition against UDAAPs in the Dodd-Frank Act.  The CFPB will continue to review closely the practices of those engaged in the collection of consumer debts for potential UDAAPs, including the practices described above.”

The FDCPA does not provide a blanket exception for creditors collecting on their own behalf.  As the FTC blog aptly notes, the definition of debt collector under the FDCPA may include creditors collecting on their own behalf under several limited scenarios.  First, the FTC points out that “if a creditor collects its own debt but uses a different name that suggests that it’s a third party debt collector…then the company is now a debt collector subject to the FDCPA”.   The FTC also points to a second scenario – when a creditor is collecting a debt on its own behalf which was in default at the time it was obtained by such person.  What is troubling, however, is that the FTC, misses the second crucial element of the definition of a debt collector - specifically, that the creditor’s principal business purpose must be debt collection.  The FTC blog suggests by implication that banks who acquire loans may be subject to the FDCPA; however, the majority of courts who have examined that issue have ruled to the contrary.

The Bottom Line?  Creditors who collect debt on their own behalf need to examine their policies, procedures and compliance management systems to insure their collection efforts are consistent with the FDCPA whether or not they are “debt collectors” under the Act.  Both the FTC and CFPB have made clear their intention to enforce unfair and deceptive debt collection practices under the FTC Act and Dodd Frank when the FDCPA is unavailable.  Additionally, it is likely that any debt collection regulation proposed by the CFPB will include creditors collecting on their own behalf.  Winter is coming – creditors should be prepared.

Tuesday, November 24, 2015

Guest Post: NARCA Supports Eliminating “Bad Players”

By: Mark Dobosz, Executive Director - NARCA
November 24, 2015


The Federal Trade Commission’s announcement of its coordinated efforts with other law enforcement agencies against deceptive and unscrupulous debt collectors is hailed by NARCA as a positive move to rid the industry of the “bad apples” that tarnish reputable and legal debt collection businesses.


 NARCA supports the efforts of both industry entities and other agencies to root out the businesses that harm consumers through truly deceptive practices. The industry and consumers are much better off by collaborative and complementary practices to insure that “bad players” are eliminated from practicing debt collection.


 NARCA has been at the forefront of insuring that its members abide by a Code of Ethics and Professional Conduct that is separate and in addition to the rules in their respective states which govern their law licenses. .  Harvey Moore, NARCA Board President commented, “Collaboration, communication and cooperation between industry groups and the regulatory bodies which enforce laws to eliminate those who consciously harm consumers through deceptive practices is key to keeping the credit eco-system for this country strong.”

About the Author:  Mark Dobosz currently serves as the Executive Director for NARCA – The National Creditors Bar Association. Mark is a one of NARCA’s speakers on many of the creditors rights issues impacting NARCA members. 

The National Creditors Bar Association (NARCA) is a trade association dedicated to creditors rights attorneys. NARCA's values are: Professional, Ethical, Responsible



Monday, October 26, 2015

FTC Settles Fair Credit Claims with Sprint Over Risk Based Pricing


The Federal Trade Commission and Sprint Corporation have entered into a consent order which resolves the FTC allegations that Sprint violated the Fair Credit Reporting Act (“FCRA”) and it’s Risk Based Pricing Rule.  Without admitting liability, Sprint has agreed to pay the FTC $2.95 million in civil penalties.

The Complaint alleges that Sprint placed consumers with lower credit scores into an Account Spending Limit ("ASL") program through which they were required to pay an additional $7.99 per month.  According to the complaint, Sprint used consumers’ credit scores to ascertain whether they should be subject to the ASL program.  According to the complaint, Sprint failed to provide adequate and/or timely notification to consumers that were placed in the ASL Program that they were receiving risk based pricing.  As a result, the complaint contends that consumers were not provided notice until it was too late to switch to another service provider.

Risk Based Pricing occurs when lenders offer different interest rates or loan terms to borrowers based on their individual creditworthiness.  The Rule requires that notice be provided to consumers who receive materially less favorable credit terms than a substantial proportion of consumers based upon their credit score. “Materially less favorable” can mean a higher APR, but where there is not APR, it can mean other things, like a deposit required by a telephone company or an annual membership fee for a credit card.  16 CFR 640.2(o).  The Risk Based Pricing Rules require that notice be provided to consumers affected by Risk Based Pricing.

The Order requires Sprint to send consumers impacted by Risk Based Pricing notice by the earlier of either five (5) days after the consumer activates service or a date that give the consumer a reasonable opportunity to avoid incurring future financial obligations to Sprint.  Sprint additionally must provide revised notifications to all consumers who previously received the incomplete notices.  The Order further sets forth specifically the contents required for all Risk Based Pricing Notices moving forward.  Beyond the specific remediation and civil penalty, and as is typical with FTC Orders, Sprint is required to provide compliance reporting to the FTC at the FTC’s request for ten (10) years.

Sunday, September 20, 2015

Collection Agencies May Need to Reconsider Collection Strategies for Time Barred Accounts

Following on the heels of the Sixth Circuit’s decision in Buchanan v. Northland Group, Inc. 776 F.3d 393 (6th Cir. 2015), a Texas District Court has held that a complaint alleging that debt collector’s use of the term "settlement" in a letter to collect a time barred debt may violate the FDCPA absent a disclosure that the underlying debt is time barred.

In Carter v. First National Collection Bureau, the consumer received a letter which provided: "We would like to extend the following settlement offer: A 90% discount payable in 4 payments of $138.92. Each payment within 30 days of the previous payment. We are not obligated to renew this offer. For your convenience you may pay via a check over the phone or credit card. You have our word that your account executive will treat you fairly and with respect…" Carter v. First National Collection Bureau. C.A. No. 4:15-cv-1695 (S.D. Tex. Sep. 11, 2015), Slip Op. at 1-2. The consumer alleged that the letter was unfair and deceptive and violated sections 1692e and 1692f of the FDCPA. The collection agencies moved to dismiss because the letter did not contain any inference or threat of litigation and did not contain any misrepresentations of the status of the debt.

Section 1692e of the FDCPA contains a broad prohibition against the use of false, deceptive or misleading representations or means in connection with the collection of a debt. It also contains within it specific non-exclusive examples of representations that violate the statute including the false representation of the character, amount or legal status of any debt. The courts are currently split as to whether seeking to collect a time barred debt, without the threat of suit or disclosure of the time barred nature of the debt, violates section 1692e. Decisions from the Sixth and Seventh Circuits suggest that adequate disclosure of the time barred nature of the debt is required. See Buchanan, supra; McMahon v. LVNV Funding, LLC, 774 F.3d 1010 (7th Cir. 2014). Courts in the Third and Eighth Circuit disagree and have held that "the FDCPA permits a debt collector to seek voluntary repayment of the time-barred debt so long as the debt collector does not initiate or threaten legal action in connection with its debt collection efforts." Huerta v. Galaxy Asset Mgmt., 641 F.3d 28, 32-33 (3d Cir. 2011); see also Freyermuth v. Credit Bureau Sers., Inc., 248 F.3d 767 (8th Cir. 2001).

In denying the motion to dismiss, the court bought into the consumer’s argument that the mere use of the term "settle" or "settlement" is enough to potentially mislead the least sophisticated consumer into believing that a stale debt is legally enforceable -particularly where there is no disclosure that the debt is time barred. In doing so, the court relied upon the FDCPA’s general prohibition against false, deceptive or misleading representations and particularly those regarding the legal status of the debt. The court also relied heavily upon the FTC and CFPB findings that "consumers can be misled or deceived when debt collectors seek partial payments on stale debt," as well as a research study submitted by plaintiff’s counsel which found that "consumers who are aware that a debt is not legally enforceable will, in a statistically significant number of cases, decline to pay it." Slip Op. at 10-12.

The decision is troubling on a number of levels. First, a statute of limitations only bars judicial remedies but does not eliminate the debt or bar voluntary repayment of the debt. Thus, the debt is still subject to credit reporting and settling the debt is of some intrinsic value to the consumer. Secondly, in Texas, a partial payment on a time barred debt does not revive the statute of limitations. So while a more compelling case can be made that nondisclosure of the time barred nature of a debt may violate the FDCPA in a jurisdiction which provides for revival, that was not the underlying law at issue in this case. Finally and most troubling, the court appears to have given significant deference to the findings of the FTC and CFPB. Given the high volume of reports being published by the CFPB, it is likely that consumers will continue to push courts to rely upon favorable CFPB findings to help advance creative legal theories for recovery.

Debt collectors need to keep a close eye on this issue and may need to rethink their settlement strategies. While a few states, including North Carolina, expressly require disclosure of the time barred nature of debts, most states do not. Where state statutes are silent (as is the FDCPA), cases like this one and Buchanan should be taken into account when assessing risk and determining collection strategies on time barred accounts.

Tuesday, April 21, 2015

Mortgage Servicer Settles with CFPB and FTC

The CFPB and FTC have announced a settlement with Green Tree Servicing LLC, a national mortgage servicing company, regarding its loan servicing and debt collection practices.  Under the proposed settlement, Green Tree will pay $63 million dollars of which $48 million will be paid to affected consumers and the remainder will be paid as a civil penalty.  Additionally, Green Tree will be subjected to significant and onerous remediation requirements.

According to the complaint, Green Tree engaged in deceptive practices which included requiring good faith or upfront payments in violation of HAMP and refusing to honor “in process” loan modifications between the consumer and prior loan servicer.  Additionally, the complaint alleges that Green Tree engaged in unlawful debt collection practices both under the FDCPA as well as the general prohibition on unfair and deceptive acts set forth in §5 of the FTC Act and §§1031 and 1036(a)(1)(B) of the CFPA.  The proscribed debt collection practices set forth in the Complaint include:

• Disclosing debts to third parties, including family members, employers, coworkers and neighbors;
• Calls as early as 5 AM and as late as 11 PM;
• The use of profane language;
• Calling consumers between 7-20 times a day on a daily basis;
• Leaving multiple voice mail messages each day;
• Threatening consumers with arrest and imprisonment;
• Pressuring consumers to use a payment method that includes a $12 convenience fee per transaction without offering other alternatives for payment; and
• Taking payment from consumer accounts with their consent.

The complaint further alleges inaccurate credit reporting and problems with the administration of consumer escrow accounts.  Significantly with respect to the debt collection activities, the complaint encompasses accounts covered by the FDCPA (those accounts in which Green Tree became the servicer when the account was already past due) and those covered by the FTC Act and the CFPA (accounts in which Green Tree became the servicer pre-default). The Complaint additionally asserts claims under the FCRA and RESPA.

The Proposed Consent Order, in which Green Tree admits no wrongdoing, requires both monetary payments as well as remediation.  The Consent Order:

• Requires payment of $18 million dollars for the alleged misrepresentations relating to the alleged misrepresentations concerning payment methods requiring a convenience fee;

• Requires payment of $30 million dollars for the alleged misconduct involving short sales and in-process loan modifications;

• Requires payment of $15 million dollars in civil penalties to the CFPB;

• Prohibits the conduct complained of;

• Requires the establishment and use of a “comprehensive data integrity program reasonably designed to ensure the accuracy, integrity, and completeness of the data and other information about the accounts that” Green Tree services, collect or sells;

• Requires ongoing testing and correction of errors;

• Requires the submission and approval by the CFPB of a data integrity program;

• For eight years, requires a biennial assessment and report by a third party professional assessing the data integrity program which will be subject to review by the FTC;

• Requires the establishment of a “home preservation plan”, effective for five years, designed to “identify and review” identified consumers for "loss mitigation options, provide for the solicitation and fast-track evaluation of loss mitigation applications and stop pending foreclosure sales for such consumers to the extent necessary to permit the consumers to be solicited and considered for loss mitigation”;

• For 5 years requires quarterly disclosures to consumers with past due debts serviced by the Defendant which include customer service information, as well as directions as to how to contact the FTC and CFPB concerning the manner in which the account is being collected;

• Requires the provision to all employees, who are required to acknowledge their receipt in writing, of a lengthy and detailed notice of their responsibilities under the FDCPA;

• For five years, requires the delivery to all officers, directors, managers and members a copy of this Order, the FDCPA, the FCRA and RESPA;

• For five years, requires that a copy of the Order must also be provided to all employees, along with a copy of the aforementioned statutes relevant to their job responsibilities;

• Requires the delivery of certain compliance notices to the FTC for 15 years; 

• For fifteen years, subjects Green Tree to stringent record keeping (with a five year retention period) which includes a record of all complaints received from consumers, recordings to the extent allowed by state law of 90% of all telephone calls (limited to a two year retention period), copies of all training materials, accounting records, personnel records;  and

• Provides that the monetary obligations are nondischargeable in bankruptcy.

Key takeaways:

• The investigation is consistent with the targets identified by the CFPB:  markets where the consumer has no choice in his provider and businesses with large market share;

• In its attack on the pre default accounts Green Tree was servicing, the complaint is consistent with the CFPB’s position that it can regulate debt collection even regarding actors not covered by the FDCPA. It is important to note that the complaint did not limit itself to the authority of the FDCPA for accounts that Green Tree was servicing post default but also asserted authority to regulate violations with respect to accounts which were assigned to Green Tree pre-default and for which Green Tree was not a debt collector under the FDCPA; and

• While the debt collection activities complained of are egregious, the primary focus of the Consent Order appears to be directed towards the convenience fee issue and the loan modification and short sale issues.

Monday, April 13, 2015

FTC Announces Settlement with Debt Brokers


The FTC announced today that it has settled two data breach cases with debt brokers. In complaints filed last year, the FTC contended the debt brokers posted consumers’ personal identifying information, including bank account information, credit card numbers, birth dates, and information about debts the consumers allegedly owed on public websites in an unencrypted manner.   See Federal Trade Commission v. Bayview Solutions, LLC, Doc. No. 1:14-cv- 01830 (D.D.C. Apr. 13, 2015); Federal Trade Commission v. Cornerstone and Company, LLC, Doc. No. 1:14-cv-01479 (D.D.C. Apr. 13, 2015). The FTC contended the disclosures violated the consumers’ privacy, put them at risk of identity theft, and exposed them to “phantom” debt collection, resulting in violations of Section 5 of the FTC Act and the Safeguard Rules of the Gramm Leach Bliley Act.  Under the Stipulated Orders, the debt buyers are required to establish, implement and maintain a written information security program in compliance with the Safeguard Rules which will be assessed, audited and certified periodically for twenty (20) years. 
Debt buyers and sellers should keep in mind that they are subject to Gramm Leach Bliley’s safeguard rules and are required to maintain, protect and secure consumers’ records and information. Under the Safeguard Rules, covered entities must develop a written information security plan (“WISP”) to protect customer information. The Rules require that the WISP be appropriate to the financial institution's size and complexity, the nature and scope of its activities, and the sensitivity of the customer information at issue.  Covered institutions are required to:
·       designate one or more employees to coordinate the program;
·       identify and assess the reasonably foreseeable risks to customer information in each relevant area of the company's operation, and evaluate the effectiveness of current safeguards for controlling these risks;
·       design and implement a safeguard plan to manage the identified risks and regularly test or monitor such safeguards;
·       select and oversee appropriate service providers and require them (by contract) to implement safeguards; and
·       continue to evaluate the program and make adjustments in light of changes to its business arrangements or the results of its security tests.
The FTC has published its tips for keeping data secure for companies buying and selling debt:
·       Don’t publicly post or make consumer information publicly available when selling portfolios.
·       Store information securely.  The FTC recommends limiting access to only those employees who need access and maintaining data in password protected files.
·       Minimize the amount of information shared with potential buyers, verify their identities and insure they have safeguards in place to protect any information shared.
·       Transfer data securely using encrypted or password protected files.
·       Dispose of data safely.
·       Have a plan in place to deal with a breach and be familiar with any relevant state statutes governing data breaches.
·       Consult the FTC website for free information