On April 8, the Office of the Comptroller of the Currency (OCC) officially notified Congress of a significant information security incident involving its email system. This notification, mandated by the Federal Information...more
4/11/2025
/ Banks ,
Cyber Attacks ,
Cybersecurity ,
Data Breach ,
Data Security ,
Electronic Communications ,
Email ,
Federal Information Security Modernization Act (FISMA) ,
Financial Institutions ,
Homeland Security Cybersecurity & Infrastructure Security Agency (CISA) ,
Incident Response Plans ,
Information Technology ,
OCC ,
Regulatory Requirements ,
Reporting Requirements ,
U.S. Treasury ,
Vulnerability Assessments
On March 18, President Donald Trump dismissed the two Democratic commissioners from the Federal Trade Commission (FTC). The removal of Commissioners Alvaro Bedoya and Rebecca Kelly Slaughter has sparked significant...more
In the latest episode of Payments Pros, host Carlin McCrory welcomes Kim Phan to discuss the Consumer Financial Protection Bureau's (CFPB) recent inquiries into enhancing privacy protections.
On January 10, the CFPB sought...more
We are pleased to share our annual review of regulatory and legal developments in the consumer financial services industry. With active federal and state legislatures, consumer financial services providers faced a challenging...more
2/17/2025
/ Automotive Loans ,
Consumer Financial Products ,
Consumer Financial Protection Act (CFPA) ,
Consumer Financial Protection Bureau (CFPB) ,
Debt Collection ,
Enforcement Actions ,
Financial Institutions ,
Financial Regulatory Reform ,
Financial Services Industry ,
FinTech ,
Regulatory Agenda ,
Regulatory Requirements ,
TCPA ,
UDAAP ,
Uniform Commercial Code (UCC)
2024 was a pivotal year in the regulation of data practices, with increased scrutiny of artificial intelligence (AI), data brokers, and the ecosystem of commercial data, and the continued proliferation of comprehensive United...more
2/13/2025
/ Artificial Intelligence ,
Consumer Privacy Rights ,
Corporate Counsel ,
Cybersecurity ,
Data Brokers ,
Data Privacy ,
Data Protection ,
Federal Trade Commission (FTC) ,
Machine Learning ,
Privacy Laws ,
Regulatory Agenda ,
State Privacy Laws
On January 30, the Consumer Financial Protection Bureau (CFPB or Bureau) released its updated list of consumer reporting companies for 2025. The list includes nationwide consumer reporting companies as well as several other...more
2/4/2025
/ Consumer Credit Protection ,
Consumer Financial Protection Bureau (CFPB) ,
Consumer Privacy Rights ,
Consumer Reporting Agencies ,
Credit Reports ,
Data Privacy ,
Data Security ,
Fair Credit Reporting Act (FCRA) ,
Financial Services Industry ,
Identity Theft ,
Reporting Requirements
Join host Kim Phan and special guests David Anthony, Stefanie Jackman, and Mark Furletti as they delve into the significant Fair Credit Reporting Act (FCRA) developments of 2024 and provide insights on what to expect in 2025....more
On January 8, the Consumer Financial Protection Bureau (CFPB) officially recognized Financial Data Exchange, Inc. (FDX) as the first standard-setting body under the Personal Financial Data Rights promulgated rule under...more
On January 3, the Federal Trade Commission (FTC) issued a press release announcing that accessiBe Inc. and accessiBe Ltd. (collectively, accessiBe) agreed to pay $1 million to settle allegations of deceptive advertising...more
1/6/2025
/ Advertising ,
Artificial Intelligence ,
Corporate Counsel ,
Disability Discrimination ,
Enforcement Actions ,
False Advertising ,
Federal Trade Commission (FTC) ,
FTC Act ,
Marketing ,
Misleading Statements ,
Settlement ,
Unfair or Deceptive Trade Practices ,
Web Content Accessibility Guidelines (WCAG) ,
Website Accessibility ,
Websites
On December 9, the Consumer Financial Protection Bureau (CFPB or Bureau) announced the launch of a rulemaking process addressing credit reporting on survivors of domestic violence, elder abuse, and other forms of financial...more
12/13/2024
/ Advanced Notice of Proposed Rulemaking (ANPRM) ,
Coercion ,
Comment Period ,
Consumer Financial Protection Bureau (CFPB) ,
Consumer Reporting Agencies ,
Credit Reports ,
Domestic Violence ,
Elder Abuse ,
Fair Credit Reporting Act (FCRA) ,
Financial Abuse ,
Financial Regulatory Reform ,
Financial Services Industry ,
Public Comment ,
Regulation V ,
Regulatory Agenda ,
Rulemaking Process ,
Vulnerable Victims
On December 3, the Consumer Financial Protection Bureau (CFPB or Bureau) issued a proposed rule for public comment aimed at amending Regulation V, which implements the Fair Credit Reporting Act (FCRA). The proposed rule seeks...more
12/5/2024
/ Comment Period ,
Consumer Financial Products ,
Consumer Financial Protection Bureau (CFPB) ,
Consumer Reports ,
Credit Reporting Agencies ,
Data Brokers ,
Fair Credit Reporting Act (FCRA) ,
Financial Regulatory Reform ,
Financial Services Industry ,
Proposed Rules ,
Regulation V ,
Regulatory Agenda
In this episode of FCRA Focus, hosts Kim Phan and Dave Gettings welcome Mark Furletti, co-leader of Troutman Pepper's Consumer Financial Services Regulatory practice. Mark shares his extensive knowledge on the Fair Credit...more
On November 12, the Consumer Financial Protection Bureau (CFPB) released a new report titled, “State Consumer Privacy Laws and the Monetization of Consumer Financial Data.” The report provides an overview of the state...more
11/18/2024
/ Consumer Financial Products ,
Consumer Financial Protection Bureau (CFPB) ,
Consumer Information ,
Consumer Privacy Rights ,
Data Privacy ,
Data Protection ,
Fair Credit Reporting Act (FCRA) ,
Financial Services Industry ,
GLBA Privacy ,
Lending ,
State Privacy Laws ,
Unfair or Deceptive Trade Practices
The California Consumer Privacy Act of 2018 (as amended, including by the California Privacy Rights Act, the “CCPA”) was drafted by a privacy rights activist, initially passed and later amended multiple times by the...more
In this episode of The Consumer Finance Podcast, Chris Willis is joined by Partner Kim Phan to discuss the latest cybersecurity guidance from the New York Department of Financial Services (NYDFS) concerning artificial...more
The California Consumer Privacy Act of 2018 (as amended, including by the California Privacy Rights Act, the CCPA) was drafted by a privacy rights activist, initially passed and later amended multiple times by the California...more
On October 16, the New York State Department of Financial Services (NY DFS) issued an industry letter to entities regulated by NY DFS (covered entities) providing guidance addressing the cybersecurity risks associated with...more
10/31/2024
/ Artificial Intelligence ,
Covered Entities ,
Cyber Attacks ,
Cybersecurity ,
Data Management ,
Financial Services Industry ,
NYDFS ,
Risk Assessment ,
Risk Management ,
Social Engineering ,
Third-Party Risk
This week, the Consumer Financial Protection Bureau (CFPB or Bureau) issued its final rule on personal financial data rights, purportedly aimed at enhancing consumer control over their financial data and promoting competition...more
10/24/2024
/ Banks ,
Consumer Data Requests ,
Consumer Financial Products ,
Consumer Financial Protection Bureau (CFPB) ,
Data Management ,
Dodd-Frank ,
Final Rules ,
Financial Institutions ,
Financial Regulatory Reform ,
Financial Services Industry ,
Open Banking
On September 24, the Consumer Financial Protection Bureau (CFPB or Bureau) announced a significant development in its efforts to implement open banking rules in the United States. The Bureau has initiated a public comment...more
Join Kim Phan, co-host of the Troutman Pepper podcast, FCRA Focus, as she welcomes special guests from the Credit Builders Alliance (CBA). In this episode, Chief Technical Officer Elisabeth Johnson-Crawford and Manager of...more
Using AI in HR - Hire or Hover? Hiring executives are asking if the compliance costs and discrimination risks outweigh the anticipated benefits of using artificial intelligence (AI) tools for hiring and employment-related...more
9/18/2024
/ Algorithms ,
Americans with Disabilities Act (ADA) ,
Artificial Intelligence ,
Civil Rights Act ,
Corporate Counsel ,
Data Protection ,
Data Protection Impact Assessments (DPIAs) ,
Employment Discrimination ,
Hiring & Firing ,
Human Resources Professionals ,
Machine Learning ,
Title VII
In this episode of The Consumer Finance Podcast, Chris Willis is joined by privacy Partner Kim Phan and Rami Haddad, deputy general counsel at PRA Group. This episode delves into a range of emerging privacy issues impacting...more
In this special crossover episode of The Consumer Finance Podcast and FCRA Focus, host Kim Phan is joined by fellow Troutman Pepper partner Stefanie Jackman and Michelle Macartney, managing partner and chief compliance...more
In this episode of FCRA Focus, host Kim Phan is joined by fellow Troutman Pepper partner Stefanie Jackman and Michelle Macartney, managing partner and chief compliance officer at Bridgeforce. Together, they delve into the...more
Rhode Island has become the 19th U.S. state to enact a comprehensive privacy law. On June 25, Rhode Island Governor Daniel McKee (D) transmitted the Rhode Island Data Transparency and Privacy Protection Act (RI-DTPPA) into...more