Skip to main content
Menu Icon
Close

InfoBytes Blog

Financial Services Law Insights and Observations

Filter

Subscribe to our InfoBytes Blog weekly newsletter and other publications for news affecting the financial services industry.

  • FTC seeks comments on Safeguards and Privacy rules

    Federal Issues

    On March 5, the FTC released proposed amendments to two rules that protect the privacy and security of customer data held by financial institutions. The agency seeks comments on proposed changes to the Safeguards Rule and the Privacy Rule under the Gramm-Leach-Bliley Act. The Safeguards Rule requires financial institutions to develop, implement, and maintain comprehensive information security programs, whereas the Privacy Rule requires financial institutions to notify customers about information-sharing practices, as well as enable customers to opt out of sharing their information with certain third parties. The FTC’s proposed amendments to the Safeguards Rule would, among other things, add more detailed requirements for financial institutions, including mandatory encryption of customer data and the use of multi-factor authentication to prevent unauthorized access to customer information. The proposed amendments to the Privacy Rule would change the rule to account for statutory changes in the Dodd-Frank Act, which gave the majority of the FTC’s rulemaking authority for the Privacy Rule to the CFPB with the exception of certain motor vehicle dealers. The agency plans to remove examples of financial institutions that do not apply to motor vehicle dealers, as well as clarify when annual customer privacy notices must be provided. In addition, the FTC proposes to expand the definition of “financial institution” in both rules to include “finders,” which include persons or entities that charge a fee to introduce consumers to a lender.

    Federal Issues FTC Consumer Finance Privacy/Cyber Risk & Data Security Gramm-Leach-Bliley Safeguards Rule Privacy Rule Dodd-Frank

  • Class settles data breach claims over compromised payment card data

    Courts

    On February 26, the U.S. District Court for the Middle District of Florida granted final approval and class certification, following a final approval hearing, to a settlement resolving class action allegations concerning a data breach involving an international fast-food chain. According to the amended motion for final approval, the data breach occurred in 2016 and involved third-party malware installation on certain franchises’ point of sale systems, which targeted and compromised customer payment card related data. The class ultimately asserted the following claims—breach of implied contract, negligence, and violations of several state consumer laws—and requested reimbursement for (i) costs associated with time spent addressing identity theft or fraud; (ii) losses caused by restricted access to funds; (iii) costs associated with credit reports and credit monitoring; (iv) bank and payment card fees; (v) unauthorized charges; and (vi) documented time spent dealing with the repercussions of the data breach. Under the terms of the settlement, the fast-food chain will pay up to $5,000 per eligible class member as reimbursement for documented out-of-pocket expenses, and up to $15 an hour for up to two hours of undocumented time spent dealing with the repercussions of the data breach. The court also approved $1.02 million in attorneys’ fees and approximately $139,000 in costs to class counsel.

    Courts Privacy/Cyber Risk & Data Security Data Breach Class Action Settlement

  • California AG seeks to strengthen the California Consumer Privacy Act

    State Issues

    On February 25, the California Attorney General announced a legislative proposal that would amend several aspects of the California Consumer Privacy Act (CCPA). The CCPA was originally enacted in June 2018 (covered by a Buckley Special Alert) and subsequently amended in September 2018 (covered by InfoBytes here). The CCPA, which carries an effective date of January 1, 2020, on most provisions, sets forth various requirements for businesses that collect, transfer, or sell a consumer’s personal information. Under SB 561, which was introduced on February 22, the law would be amended to (i) expand the right of California citizens to bring private legal actions, removing aspects of the law that provided exclusivity to the AG; (ii) remove provisions that would allow companies to request guidance from the California AG on how to comply with the law, instead allowing the AG to publish general guidance; and (iii) would allow enforcement actions to be brought immediately, removing the 30-day cure window.

    State Issues Privacy/Cyber Risk & Data Security State Legislation State Attorney General CCPA

  • Video social networking app settles COPPA allegations

    Federal Issues

    On February 27, the FTC announced a $5.7 million settlement with the operators of a video social networking app concerning alleged violations of the Children’s Online Privacy Protection Act (COPPA). Among other things, the FTC claims the operators failed to provide parents notice of its information collection practices, illegally collected personal information from children under the age of 13 without first obtaining verifiable parental consent, failed to delete personal information when parents requested, and retained information “longer than reasonably necessary to fulfill the purpose for which the information was collected.” Under COPPA, operators of websites and online services directed at children are prohibited from collecting personal information of children under the age of 13, unless the company has explicit parental consent. The FTC alleges that the operators knew a “significant percentage” of its users were under 13 and received thousands of complaints from parents that their children under 13 had created accounts on the app. While neither admitting nor denying the allegations, the operators have agreed to the monetary penalty, will change their business practices to comply with COPPA, and will remove all videos made by children younger than 13. According to the FTC, this settlement is the largest civil penalty obtained to date by the agency for COPPA violations.

    Federal Issues FTC Enforcement Settlement Civil Money Penalties COPPA Privacy/Cyber Risk & Data Security

  • FCC proposes to strengthen enforcement of caller ID spoofing

    Privacy, Cyber Risk & Data Security

    On February 14, the FCC released a notice of proposed rulemaking intended to strengthen its rules against caller ID spoofing and expand the agency’s enforcement efforts against illegal spoofed text messages and phone calls, including those from overseas. The proposed rules would enact requirements in the recently passed RAY BAUM’S Act of 2018, and expand Truth in Caller ID Act prohibitions against the transmittal of “misleading or inaccurate caller ID information (‘spoofing’) with the intent to defraud, cause harm, or wrongfully obtain anything of value” to text messages and calls to U.S. residents originating from outside the U.S.

    The FCC seeks comments on the proposed rules—adopted unanimously at the agency’s February 14 meeting—on, among other things, what changes to the Truth in Caller ID rules can be made “to better prevent inaccurate or misleading caller ID information from harming consumers.” Comments will be due 60 days after publication in the Federal Register.

    Privacy/Cyber Risk & Data Security FCC Robocalls Enforcement Truth in Caller ID Act

  • Senate Banking Committee seeks data privacy feedback

    Privacy, Cyber Risk & Data Security

    On February 13, Senate Committee on Banking, Housing, and Urban Affairs Chairman Mike Crapo (R-ID) and Ranking Member Sherrod Brown (D-OH) invited stakeholder feedback on “the collection, use and protection of sensitive information from financial regulators and private companies” as a means of informing potential future legislation. In a press release issued by the committee, Crapo noted, “Given the exponential growth and use of data, and corresponding data breaches, it is worth examining how the Fair Credit Reporting Act should work in a digital economy, and whether certain data brokers and other firms serve a function similar to the original consumer reporting agencies.” He further stressed the importance of understanding how consumer data is compiled and protected, and how consumers are able to access and correct sensitive information. The release sought answers to five questions designed to help examine ways in which legislation, regulation, or the implementation of best practices can (i) provide consumers better control over their financial data, as well as timely data breach notifications; (ii) ensure consumers receive disclosures concerning both the type of information being collected and its purpose for collection; (iii) provide consumers control over how their data is being used—including the sharing of information by third-parties; (iv) protect consumer data and ensure the accuracy of reported information in a consumer’s credit file; and (v) allow consumers the ability to “easily identify and exercise control of data that is being . . . collected and shared” as a determining factor when establishing whether a consumer is eligible for, among other things, credit or employment.

    Privacy/Cyber Risk & Data Security Senate Banking Committee Federal Legislation Consumer Protection Fair Credit Reporting Act

  • District Court concludes communications transmitter can be liable under the TCPA

    Courts

    On February 13, the U.S. District Court for the District of Nevada rejected a cloud communication company’s motion to dismiss a TCPA class action. According to the opinion, the plaintiffs’ alleged the company “collaborated as to the development, implementation, and maintenance of [a] telemarketing text message program,” which was used by a theater production company to send text messages without prior consent in violation of the TCPA and the Nevada Deceptive Trade Practices Act (NDTPA). The company moved to dismiss the claims, arguing, among other things, that it was not liable under the TCPA because it was a “transmitter” and not an “initiator” of communications. Citing the FCC’s previous determination that, under certain circumstances transmitters may be held liable under the TCPA, the court rejected this argument, concluding that the company took steps necessary to send the automated messages and that its “alleged involvement was to an extent that [it] could be considered to have initiated the contact.” Moreover, the court determined the plaintiff sufficiently alleged injury under the TCPA, concluding that violations of privacy and injury to the “quiet use and enjoyment of [a] cellular telephone” are consistent with the purpose of the TCPA. The court did dismiss the plaintiff’s NDTPA claims, however, holding that the transaction did not involve the sale or lease of goods or services as the law requires.

    Courts TCPA State Issues Standing Privacy/Cyber Risk & Data Security FCC

  • FDIC issues 2018 annual report

    Federal Issues

    On February 14, the FDIC released its 2018 Annual Report, which includes, among other things, the audited financial statements of the Deposit Insurance Fund and the Federal Savings and Loan Insurance Corporation (FSLIC) Resolution Fund. The report also provides an overview of key FDIC initiatives, performance results, and other aspects of FDIC operations, supervision developments, and regulatory enforcement. Highlights of the report include: (i) the FDIC’s efforts to adopt and issue proposed rules on key regulations under the Economic Growth, Regulatory Relief and Consumer Protection Act (EGRRCPA); (ii) efforts to strengthen cybersecurity oversight and help financial institutions mitigate cyber risk; (iii) supervision focus on Bank Secrecy Act/Anti-Money Laundering compliance; and (iv) financial institution letters providing regulatory relief to institutions affected by natural disasters. The report also highlights the FDIC’s monitoring of financial technology developments through its various research groups and committees to better understand how technological efforts may affect the financial market. Lastly, the report covers the agency’s efforts to encourage de novo bank applications, including the December 2018 request for information soliciting comments on the deposit insurance applications process (covered by InfoBytes here).

    Federal Issues FDIC Bank Supervision EGRRCPA Bank Secrecy Act Anti-Money Laundering De Novo Bank Fintech Privacy/Cyber Risk & Data Security Deposit Insurance

  • State AGs urge FTC to update identity theft rules

    State Issues

    On February 11, a bipartisan group of 29 state Attorneys General, the District of Columbia Attorney General, and an official from the Hawaii Office of Consumer Protection, responded to the FTC’s request for comment on whether the agency should make changes to its identity theft detection rules (the Red Flags Rule and the Card Issuers Rule), which require financial institutions and creditors to take certain actions to detect signs of identity theft affecting their customers. (Covered by InfoBytes here.) 

    In their response, the Attorneys General urge the FTC not to repeal the Rules, arguing that it “would place consumers at greater risk of identity theft, especially consumers in states that have not enacted” laws that complement the Rules. Instead, the response letter requests the FTC modify the Rules to “ensure their continued relevance” and “keep pace with the ingenuity of identity thieves.” The suggestions include: (i) that notices of changes to email addresses and cell phone numbers be sent to both the prior and updated addresses and phone numbers, an expansion of the current use of mailing addresses; (ii) the encouragement of more current forms of authentication, including multi-factor authentication, to replace examples which imply that knowledge-based authentication by itself is sufficient; and (iii) the addition of new suspicious activity examples related to the use of an account, such as a covered account accessed by unknown devices or IP addresses, an unauthorized user unsuccessfully trying to guess account passwords through multiple attempts, and attempts by foreign IP addresses to access multiple accounts in a close period of time.

    State Issues FTC Identity Theft RFI State Attorney General Privacy/Cyber Risk & Data Security

  • District court orders TCPA suit to mediation, states FCC’s interpretation of autodialer may take years

    Courts

    On February 1, the U.S. District Court for the Eastern District of Missouri issued an order referring the parties in a putative TCPA class action to mediation. The plaintiff’s complaint alleges that the defendant’s insurance company sent her text messages without her consent using an automatic telephone dialing system (autodialer). In response, the defendant argued that the software it used to send the text messages does not qualify as an autodialer because it calls numbers from a pre-set list, instead of one that is randomly or sequentially generated. The defendant further argued that the case should be stayed because the FCC is currently considering whether systems such as the one at issue qualify as autodialers under the TCPA following the D.C. Circuit’s March 2018 ruling in ACA International v. FCC, which set aside the FCC’s 2015 interpretation of an autodialer as “unreasonably expansive.” (Covered by a Buckley Special Alert.) The decision to refer the case to mediation comes after the court’s August 2018 order denying the defendant’s motion to stay the proceeding. In that order the court explained that, although the FCC issued a notice in May 2018 (covered by InfoBytes here) seeking comments on the interpretation of the TCPA, the rulemaking process would likely take years and may not even resolve the issue in the case.

    Courts TCPA Autodialer Mediation FCC Privacy/Cyber Risk & Data Security

Pages

Upcoming Events