Join us on LinkedIn Follow us on Twitter Like us on Facebook Follow us on Instagram
 
  OCTOBER RESEARCH STORE Already a subscriber? LOG IN
AddControlToContainer_DynamicNavigation6

Industry insider expects CFPB data privacy rule to withstand legal challenges

Email A Friend Printer Friendly Version
0 comments
Banking, Consumer Protection, Industry Regulation, Nonbank Financial
Tuesday, October 29, 2024

The latest lawsuit against the Consumer Financial Protection Bureau (CFPB) reflected a familiar theme, according to Garris Horn Senior Partner John Levonick, who sat down with Dodd Frank Update for an exclusive interview.

After combing through the bureau’s nearly 600-word data privacy final rule implementing Sec. 1033 of the Dodd-Frank Act and the subsequent 56-page complaint challenging its legality in a Kentucky district court, Levonick drew parallels to the industry’s reaction to past CFPB rulemakings which also spurred legal challenges.

In this particular case, the plaintiffs (Bank Policy Institute, Kentucky Bankers Association, Forcht Bank) argued the CFPB exceeded its statutory authority with the rulemaking because it will, upon implementation, require banks to share consumer financial data with third-party fintechs and data aggregators and that such a requirement will put consumer financial data at risk because these entities generally have less regulatory oversight than traditional banks.

Noting that many of the third parties in question are not subject to data protection and disclosure requirements outlined under the Gramm-Leach-Bliley Act (GLBA), the lawsuit argued the task of ensuring the accuracy and security of consumers’ sensitive information will fall to traditional financial institutions.

However, Levonick said this argument ignores the fact that banks already have a regulatory obligation to protect their customers’ data and the rule addresses third-party supervision concerns raised in the complaint.  

“The rule clearly defers to the Federal Trade Commission for entities that aren’t subject to GLBA,” Levonick said. “[The plaintiffs] further contend that the rule limits banks’ ability to deny access to potentially unvetted third parties, which could jeopardize both the security of consumer data and the overall soundness of the banking system. However, the final rule gives a data provider ample opportunity to deny access to unvetted third parties if the data provider feels that safety and soundness questions exists. As long as the denial is reasonable, the data provider is fine.”

He also pointed to a section of the rule defining a “reasonable” denial of data access as being “(1) [d]irectly related to a specific risk of which the data provider is aware, such as a failure of a third party to maintain adequate data security; and (2) applied in a consistent and non-discriminatory manner.”

Essentially, the rule represents the codification of best practices in consumer data security regulators have been championing for years, Levonick asserted.

“The subtle message here is that the CFPB is reaching further into creating clear requirements that are going to force financial institutions to be responsible for the actions of their vendors, pulling the veil on the multilayered dependency of technology providers,” he said.

The CFPB’s stated mission to facilitate the establishment of an open banking system in the U.S. to empower consumers by giving them control over their sensitive financial data and the associated implementation costs to banks are likely among the greatest concerns at issue for the industry, Levonick believes.

He noted the tremendous pushback that came when the CFPB introduced its TILA-RESPA Integrated Disclosure (TRID) rule and then again with its Ability-to-Repay/Qualified Mortgage (ATR/QM) standards, which highlighted the industry’s recurring concerns about the cost of compliance. In this respect, the data privacy rule may represent a similar crossroads for traditional brick-and-mortar institutions.

The CFPB gathered several cost estimates for upfront implementation and ongoing maintenance for a variety of institutions and provided a thorough explanation of these figures in the rule, as well as several categories of one-time costs, staffing costs, and various updates to these figures throughout the research phase of the rulemaking process.

“The CFPB is attempting to set the stage to enable financial institutions to become more interoperable, to reduce the financial moats they have created around their products and services, and the CFPB clearly wants to establish that this massive shift in how business is to be conducted is being directed by a prudential regulator,” Levonick said. “Any massive shift in paradigm requires a regulatory framework, however vague it may be initially, as it is a place to start and an assurance that consumers are being protected while ushering in the next generation of banking.”

While consumers may benefit from greater interoperability between financial institutions and third parties, provided proper security safeguards are in place, banks understandably may be concerned about the prospect of potentially losing depositors at the drop of a hat. Such a prospect is always a concern from a safety and soundness perspective, which is partially why Levonick said he will be interested to see whether the Office of the Comptroller of the Currency weighs in on the CFPB’s rule.

Levonick said he is also keenly interested in the CFPB rule’s revised provisions regarding secondary data use, from the proposed rule to the finalized version. He believes this portion of the rule will have the most immediate impact on financial institutions as they look to deepen their vendor management programs and amend their vendor contracts, accordingly. 

“The proposed rule limited secondary use of consumer-authorized data, requiring separate consumer consent for each use,” Levonick said. “Apparently, there was significant feedback on this subject, as the final rule allows some secondary uses without additional authorization, such as using data for improving the product or service the consumer requested, developing anti-fraud measures, and training underwriting models.”

Many fintech companies attempt to obtain secondary-use authority to hold consumer data beyond the term of their contractual obligations through their service agreement with a financial institution. By doing so, they seek to add valuation value to their business as a whole or provide better market trending analysis. Generally, Levonick said, this would be palatable for institutions if the fintech “deidentified” the data, which entailed removing or altering certain personally identifying attributes from data. Eventually, this concept morphed into requiring full “anonymization” of the data, which is an even more comprehensive way to obscure the link between the data and the person connected to it. 

“With these controls around secondary use, it appears that regulators will now be not only requesting vendor contracts, they will be scrutinizing these vendor contracts to see if they permit any violations of the secondary use constraints and now have another reason to assess data security and privacy controls,” Levonick said.

The CFPB’s data privacy rule and the lawsuit that followed have given the industry a lot to consider. If history is a guide, banks would be well-advised to begin reviewing vendor contracts and other activities necessary for compliance sooner rather than later.

Today's other top stories
New York AG sues Capital One in case mirroring dropped CFPB lawsuit
CFPB withdraws data broker rule proposal
MBA recommends TILA, HMDA revisions in OMB response
Former bank CEO, chair breached fiduciary duty in real estate transaction
Regulatory Roundup: States step up as federal agencies scale back enforcement


COMMENT BOX DISCLAIMER:
October Research is not responsible for the comments posted on its websites by readers. We will do our best to remove comments that include profanity or personal attacks or other inappropriate comments.
Comments:

Be the first to leave a comment.

Leave your comment
CAPTCHA Validation
CAPTCHA
Code:
: 
: 
Your Email is for reporting purposes only. It will NOT be displayed.
Popularity:
This article has been viewed 18278 times.

Monthly Newsletter

Dodd Frank Update May 2025

Cover Story:

Wolters Kluwer experts analyze shifts in banker compliance concerns


News by Topic   News by Edition   News by Agency   News by Industry   In-depth Reports   Events
Banking
Case Law
Conference Coverage
Consumer Protection
Data Privacy
Financial Stability
Industry Spotlight
Legislation
Nonbank Financial
The TRID Journey
 
Dodd Frank Update April 2025
Dodd Frank Update May 2025
Archives
 
CFPB NCUA
CFTC OCC
FDIC OFR
FHFA SEC
FRB States
FSOC Treasury
FTC  
 
Appraisal
Broker-Dealer
Community Banks & Credit Unions
Land Title
Mortgage
Payday Lending
 
2025 State of the Industry
CRA and Affordable Housing
2025 State of the Industry
Who's My Regulator?
Fair Lending
Mortgage Technology
Marketing Compliance for Lenders
Archives
 
National Settlement Services Summit (NS3)
Women's Leadership Summit (WLS)
Webinars

Library   About   Subscribe   Other Publications
Data Privacy Vault Court Actions
Keys to Real Estate podcast Enforcement Documents
Blog - Tuesdays with Mary Guidance Documents
1071 Compliance Guide White Papers
eClosing Solutions Showcase Position Papers
Executive Interview Series Legislation
Lender Associations Regulations
The Dodd-Frank Act Reports, Studies and Surveys
Dodd-Frank Summary & History Federal Register Notices
 
Dodd Frank Update
Contact / Editors
Advertise
Request a Media Kit
Social Media
Are You An Expert?
Subscriber Agreement
 
Subscriptions
Free Email Updates
Try a Free Edition
 
The Title Report
The Legal Description
Valuation Review
RESPA News
Copyright © 2011-2025 Dodd Frank Update
An October Research, LLC publication
3046 Brecksville Road, Suite D, Richfield, OH 44286
(330) 659-6101, All Rights Reserved
www.doddfrankupdate.com | Privacy Policy
VISIT OUR OTHER WEBSITES
> The Legal Description
> RESPA News
> The Title Report
> Valuation Review
> NS3 The Summit
> Women's Leadership Summit
> October Research, LLC
> The October Store


Loading... Loading...
Featuring:
  • Delivery 3X a week plus breaking news as it happens
  • Comprehensive title insurance industry news
  • Recent acquisitions, mergers, real estate stats
  • Exclusive in-depth coverage of the industry's hottest stories
Featuring:
  • Delivery 2X a week plus breaking news as it happens
  • Comprehensive Dodd-Frank coverage
  • The latest information from the CFPB
  • Full coverage of Congressional hearings
  • Updates on all agency actions
  • Analysis of controversial provisions
  • Release of newest studies and reports
Sign up today and...
  • Be one of the first to know where NS3 is being held
  • Learn about NS3 speakers and sessions
  • Save on registration with Super-Early Bird rates
  • Discover the networking opportunities NS3 offers
  • Find out if CE credits will be offered for your area
  • And much more
Featuring:
  • Delivery 2X a week plus breaking news as it happens
  • Preview the latest RESPAnews.com Top Story
  • RESPA related headline news
  • Quote of the Week
Featuring:
  • Delivery 2X a week plus breaking news as it happens
  • Legal, regulatory and legislative information impacting the settlement services industry
  • News from HUD, Congress, state legislatures and other regulatory agencies
  • Follow the lobbying efforts of all the major national real estate services organizations.
Featuring:
  • Delivery 2X a week plus breaking news as it happens
  • The industry's only full-time newsroom
  • Relevant, up-to-date appraisal industry news
  • Covering the hottest stories and industry trends
NEWS BY TOPIC
EDITION
AGENCY
IN-DEPTH REPORTS
INDUSTRY
EVENTS
LIBRARY
EMAIL UPDATES
ABOUT
SUBSCRIBE
Banking
Case Law
Conference Coverage
Consumer Protection
Data Privacy
Financial Stability
Industry Spotlight
Legislation
Nonbank Financial
The TRID Journey
Current Edition
April 2025
March 2025
February 2025
Archives
CFPB
CFTC
FDIC
FHFA
FRB
FSOC
NCUA
OCC
OFR
SEC
States
Treasury
2025 State of the Industry
Real Estate Compliance Outlook
CRA and Affordable Housing report
Who's My Regulator?
Fair Lending
Marketing Compliance for Lenders
Archives
Appraisal
Broker-Dealer
Community Banks & Credit Unions
Land Title
Mortgage
Payday Lending
National Settlement
Services Summit (NS3)
Women's Leadership
Summit (WLS)
Webinars
CFPB's Shake-Up & Its Impact on You
2025 Economic Outlook Series
Data Privacy Compliance
Fintech Partner Compliance
Strategies post-NAR settlement
Industry and Regulatory Outlook
Securing Your Cyber Network
Compliant Marketing Tactics
2024 Economic Forecast Series
Webinar Archives
Data Privacy Vault
Keys to Real Estate podcast
Blog - Tuesdays with Mary
1071 Compliance Guide
eClosing Solutions Showcase
Executive Interview Series
Lender Associations
The Dodd-Frank Act
Dodd-Frank Summary
Court Actions
Enforcement Documents
Guidance Documents
White Papers
Position Papers
Legislation
Regulations
Reports, Studies and Surveys
Federal Register Notices
Proposals
Final Rules
GAO
Agency
Contact Us
Advertise
Request a Media Kit
Social Media
Are You An Expert?
Subscriber Agreement