Showing posts with label Fintech. Show all posts
Showing posts with label Fintech. Show all posts

Thursday, October 26, 2017

CFPB Issues “Principles” for the Protection of Consumer Authorized Data Sharing and Aggregation


By Caren Enloe
October 26, 2017


With the growth of technology and the development of the fintech market, an unprecedented amount of consumer financial data has become available.  While protections through the FTC Safeguard Rule and EFTA provide certain consumer protections, there are coverage gaps as the regulatory scheme has struggled to keep up with technological advancements. 

In recognition of these competing forces and this growing market of consumer services, the CFPB issued a Request for Information in November of 2016 inquiring as to market practices related to consumer access to financial information and related data aggregation services.  Last week, the CFPB published their findings, as well as their Consumer Protection Principles which are designed to “reiterate the importance of consumer interests to all stakeholders in the developing market for services based on the consumer-authorized use of financial data.”  While the Principles are “not intended to alter, interpret, or otherwise provide guidance on the scope” of existing consumer protections under existing statutes and regulations or establish binding requirements or obligations relevant to the Bureau’s exercise of its rulemaking, supervisory or enforcement authority”, they appear to be the first step in filling some of the current regulatory gaps.

The CFPB Principles address nine general areas of concern:

  • Access.  The Principles recognize the right of consumers to be “able, upon request, to obtain information about their ownership or use of a financial product or service” from the product or service provider.  The Principles also support the consumer’s right to “authorize trusted third parties to obtain such information from account providers to use on behalf of consumers, for consumers benefit, and in a safe manner.”   
  • Data Scope and Usability.  The Principles set forth that the scope of data that may be made available should be broad; however, the data available to “third parties with authorized access” should be limited to that which is “necessary to provides the product(s) or service(s) selected by the consumer and only maintain such data as long as necessary.”
  • Control and Informed Consent.  The Principles emphasize the consumer’s right to control data access and the need for terms as to access, storage, use and disposal to be clearly communicated and understood by the consumer.  The Principles additionally emphasize the importance that the consumer understand and be provided with data sharing revocation terms that can readily and simply be invoked as to access, use and storage of data.
  • Authorizing Payments.  The Principles advocate for separate and distinct authorizations for data access and payment authorization.
  • Security.  The Principles recognize the gaps that potentially exist in the FTC Safeguard Rules and whether or not certain data aggregation providers are required to comply (as they may fall into a gap between covered financial service providers and vendors).  With regard to security, the Principles recognize the need for market participants to securely access, store, use, and distribute data in formats and manners which protect against security breaches.  The Principles further advocate for secure access credentials and effective processes that “mitigate the risks of, detect, promptly respond to, and resolve and remedy data breaches, transmission errors, unauthorized access, and fraud, and transmit data only to third parties that also have such protections and processes” in place.
  • Access Transparency.  Consumers should be informed of or able to readily ascertain “which third parties that they have authorized are accessing or using information regarding the consumers’ accounts or other consumer use of financial services.”  The Principles emphasize the ability of consumers to ascertain the “identity and security of each such party, the data they access, their use of such data, and the frequency at which they access the data.”
  • Accuracy.  The Principles express the expectation that data that consumers access or authorize others to access is current.
  • Ability to Dispute and Resolve Unauthorized Access.  The Principles set forth the expectation that consumers “have reasonable and practical means to dispute and resolve instances of unauthorized access and data sharing, unauthorized payments conducted in connection with or as a result of either authorized or unauthorized data share access, and failures to comply with other obligations , including the terms of consumer authorizations.”
  • Efficient and Effective Accountability Mechanisms.  Commercial participants are held accountable for “the risks, harms and costs they introduce to consumers” and are “incentivized and empowered effectively to prevent, detect and resolve unauthorized access and data sharing, unauthorized payments” and “failures to comply with other obligations, including terms of consumer authorizations.

The Bureau’s Report as to the November RFI reflects consensus amongst stakeholders that market participants need to work together to develop data access and use practices that are based upon a shared set of standards and expectations that address consumer protection.  Those engaged in fintech should carefully monitor developments in this area, as well as the CFPB’s developing position as to their role in regulating the same.

Monday, January 2, 2017

A Look Back and 2016 and a Look Ahead at 2017


The end of the year is always a time for reflection for me.  As we kick 2016 to the curb, I thought I'd take this opportunity to look back at 2016 and look ahead to 2017. 

2016: A Look Back

Looking back at 2016, the first things that come to my mind are the aggressive rule making agenda undertaken by the CFPB and their struggle to implement rules based upon a less than full understanding of the industries they attempt to regulate.  With 2016 came proposed rules on arbitration and payday lending, adjustments and clarification to the mortgage servicing rules and TRID, as well as an unwieldy and incomplete proposal on debt collection.  The year also saw the CFPB continued to flex its muscle expanding its reach into data privacy and fintech , as well as to inthe way attorneys litigate collection law suits (covered in our prior edition).  Continuing its infatuation with technology, the CFPB also introduced new data tools including its ”Consumer Credit Trends” tools.  In many ways, it was the most ambitious of years for the CFPB. 

As we look forward to 2017, we will closely follow the D.C. Circuit’s en banc review of the CFPB’s jurisdiction.  Coupled with the election of Donald Trump and a Republican majority in Congress here are a couple of things ) think we can expect to see in 2017:

  • Reform of the CFPB:  It would not be surprising to see the makeup of the CFPB change to a five person commission and/or to see the CFPB lose its designation as an independent agency.  Challenges have come from the judiciary and legislative branches of government in recent months and we can expect to see reform from the Trump administration. The Financial Services Committee of the House attempted last year to replace Cordray with a bipartisan commission through introduced legislation.  Similarly, the incoming administration has echoed a desire to reign in the Bureau.  Finally, the D.C. Circuit has weighed in on the constitutionality of the CFPB and its ruling is now being considered en banc by its entire panel of judges. Depending upon the outcome of the D.C. Circuit’s en banc review of the PHH decision, the CFPB may become an executive agency vs. an independent agency.  The net result may be that the CFPB and its regulations become subject to the regulatory review process of the Office of Management and Budget. 
  • Pending Rules. The CFPB’s pay day and arbitration rules are in jeopardy and may never see the light of the day if the PHH holding is upheld and the CFPB loses its status as an independent agency or if any of the other forces outlined above come to play.
  • When all else fails, UDAAP Carries the Day. The CFPB will continue to regulate through enforcement using the UDAAP provisions of Dodd Frank when regulatory authority does not otherwise exist.
  • Debt Collection: the CFPB will continue to struggle with the two ton gorilla of debt collection by first putting forward a proposal for first party collections.  We expect to see a SBREFA panel scheduled for some time in the first half of 2017.  Looking further forward, we are likely to see a proposed rule on debt collection by the end of 2017.
  • Marketing and Sales. Regulators will continue to focus on marketing and sales aspects of consumer financial service products and continue to emphasize comprehensive compliance management systems.
  • Status Quo. Institutions subject to enforcement need to continue to do business under the assumption that nothing will change and remain vigilant in their compliance.  As we sit here today, the status quo remains the order of business.
I'm looking forward to see what's next. On a more personal note,thanks to all who continue to support this blog.  What started out as a six month experiment has become a passion.  This blog has brought new people and opportunities into my life and continues to make me a better lawyer.  I'm grateful to my law firm for supporting me in this endeavor, to my good friends Jerry Myers and Mark Dobosz for their guest posts and to NARCA, WebRecon and the many other blogs and trade associations who continue to pass on my posts to others.  We continue to look for guest posts and I invite anyone with an interest in writing on consumer financial service issues to reach out to me.  Happy New Year!

Monday, October 10, 2016

CFPB Enters into Consent Order with Fintech Company


The CFPB has made it abundantly clear that it expects fintech companies to abide by the same rules as traditional brick and mortar lenders.  The Bureau’s consent order with San Francisco online lender Flurish, Inc. highlights the need for startups to effectively vet their products prior to launch to ensure compliance with the consumer protection regulatory scheme. Flurish, Inc., which does business as LendUp, is required to pay $1.82 million in retribution to affected consumers and a $1.8 million civil monetary penalty to the CFPB. 

LendUp held itself out as providing online single payments loans and installment loans and touted its “step up” system as allowing consumers to build up credit and improve credit scores.  The Consent Order highlights violations of multiple consumer protection laws, including the Truth in Lending Act and Fair Credit Reporting Act.  According to the Order,

·        LendUp’s loan-program marketing was misleading.  LendUp marketed its loan programs with claims they would build a consumer’s credit and credit scores by allowing consumers to move up the “LendUp Ladder” by taking out additional loans with more favorable terms.  Although advertised nationally, the two top level tiers of LendUp’s loans, however, were not available except in California.  Moreover, LendUp did not furnish any information to the credit reporting agencies to improve consumer’s credit scores until at least February 2014.



·        LendUp also ran amuck of the Truth in Lending Act in a number of ways:

o   LendUp allowed consumers applying for its lowest tier single payment loans the option to choose a loan maturity date as late as the consumer’s state allowed or an earlier date.  Where the earlier date was selected, the consumer was provided a discount on the origination fee.  If the consumer later extended the repayment fee, the discount was reversed.  According to the Consent Order, LendUp failed to disclose the potential for reversal to the consumer at the time they signed their loan agreement.

o   LendUp also violated the Truth in Lending Act by understating the APR.  According to the Order, LendUp failed to incorporate into its APR the portion of expedited funding fees which were retained by LendUp.  LendUp also used a faulty APR calculation tool for a period of time and did not have adequate testing provisions in place to identify the issue.

·        LendUp also ran afoul of the Fair Credit Reporting Act and Regulation V’s requirement that it have in place written policies and procedures about the accuracy and integrity of the information it furnished to credit reporting agencies. LendUp did not have any such policies and procedures in place until April 2015.

Lessons to be Learned.

·        The Order supports earlier statements by the CFPB that it holds fintech companies to the same standards as other lenders.

·        The CFPB continues to rely upon the Unfair and Deceptive Provisions on the Consumer Financial Protection Act to enforce through consent orders where other statutory authority does not exist.

·        Fintech startups should be reminded that it is essential they review consumer financial service products carefully with a lawyer well versed in the regulatory scheme before they rollout new products to ensure compliance.

·        Marketing is subject to the same scrutiny as the product itself.