The 2022 National Association of Attorneys General (NAAG) Presidential Summit, held last week in Des Moines, Iowa, signaled a clear partnership between state AGs, the Federal Trade Commission (FTC) and the Consumer Financial Protection Bureau (CFPB) to accomplish Iowa AG Tom Miller’s “fight back” presidential initiative: Consumer Protection 2.0: Tech Threats and Tools. Picking up from the 2021 kickoff of Miller’s NAAG initiative this past December, the NAAG Summit featured a variety of speakers from the federal, state, and private sectors, including, most notably, from the FTC and CFPB.Continue Reading Guardians of the Consumer: State AGs team up with FTC and CFPB to protect consumers online – Consumer Protection 2.0: Tech, Threats, and Tools
Consumer Financial Protection Bureau (CFPB)
The CFPB Releases Data Sharing Principles, Setting Off A New Round of Controversy
On October 18, the Consumer Financial Protection Bureau (“CFPB” or “Bureau”) entered into the long simmering debate over consumer-authorized data sharing. This debate pits mainstream financial institutions, which are typically reticent to share customer data with third parties, against data aggregators and other fintechs. Those newer companies provide services directly to consumers—or to enhance the consumer experience—and rely on data from mainstream institutions in order to do so. Both sides are grappling with complex issues surrounding consumer information, including who owns consumers’ financial data, as well as how it can be used, shared, and kept secure.
The CFPB released a set of nine consumer protection principles to address those issues and “help safeguard consumer interests as the consumer-authorized aggregation services market develops.” While pointedly refusing to ease any existing regulatory burden currently on the banks to ensure safety and privacy, the Bureau has now articulated a yet-to-be fully defined set of requirements for traditional financial institutions to cooperate with demands for openness. Each consumer right embedded in these requirements implies a financial institution obligation, in some cases with considerable associated cost and operational disruption.
The release follows a November 2016 Request for Information where the CFPB asked stakeholders to weigh in on the challenges consumers face in accessing, using, and securely sharing their financial records. The CFPB also released a 12-page report that summarized stakeholder insight and informed development of the following principles:
Continue Reading The CFPB Releases Data Sharing Principles, Setting Off A New Round of Controversy
CFPB Takes First Action Against Company for Lax Data Security Practices
The Consumer Financial Protection Bureau (“CFPB”) has announced its first data security enforcement action. On Wednesday (March 2), the CFPB released a consent order against Dwolla, an online payment platform company, alleging it failed to maintain adequate data security practices despite representations made on the company website and in communications with consumers that the company has implemented practices that exceed industry standards. As a result, Dwolla must pay out $100,000 in penalties and endeavor to repair its security initiatives.
Continue Reading CFPB Takes First Action Against Company for Lax Data Security Practices