Consumer Financial Protection Circular 2022-04

Insufficient data protection or security for sensitive consumer information

Question presented

Can entities violate the prohibition on unfair acts or practices in the Consumer Financial Protection Act (CFPA) when they have insufficient data protection or information security?

Summary answer

Yes. In addition to other federal laws governing data security for financial institutions, including the Safeguards Rules issued under the Gramm-Leach-Bliley Act (GLBA), “covered persons” and “service providers” must comply with the prohibition on unfair acts or practices in the CFPA. Inadequate security for the sensitive consumer information collected, processed, maintained, or stored by the company can constitute an unfair practice in violation of 12 U.S.C. 5536(a)(1)(B). While these requirements often overlap, they are not coextensive.

Acts or practices are unfair when they cause or are likely to cause substantial injury that is not reasonably avoidable or outweighed by countervailing benefits to consumers or competition. Inadequate authentication, password management, or software update policies or practices are likely to cause substantial injury to consumers that is not reasonably avoidable by consumers, and financial institutions are unlikely to successfully justify weak data security practices based on countervailing benefits to consumers or competition. Inadequate data security can be an unfair practice in the absence of a breach or intrusion.


More

Mobile ID World: Biometric Cards, IoT Standards, Selfie Onboarding, and More: This Week’s Top Stories

As for securing the Internet of Things, the FIDO Alliance piqued readers’ interest with its…

Read More →

IT&Production: FIDO Alliance Introduces FDO Protocol

With the open IoT standard FDO, the Fido Alliance wants to enable the integration of…

Read More →

Mobile ID World: FIDO Introduces IoT Device Onboarding Standard

The automated, open-standard protocol specifically addresses the ways in which a device connects to on-premises…

Read More →