CFPB brings its first data security enforcement action

Ballard Spahr LLP
Contact

Last August, we blogged about a Third Circuit decision that held the FTC can regulate cybersecurity policies and procedures as “unfair” acts or practices under Section 5 of the FTC Act. In our blog post, we commented that banks and other companies subject to the CFPB’s jurisdiction faced the possibility that the CFPB could begin using its Dodd-Frank authority  to bring enforcement actions against companies engaged in unfair, deceptive, and abusive acts and practices (UDAAP) to regulate cybersecurity policies and procedures. The CFPB’s announcement yesterday of its first data security enforcement action demonstrates that our concerns were well-founded.

The CFPB’s target in this action was Dwolla, Inc., a company that operates an online payment system and uses consumers’ personal information to complete financial transactions. The CFPB lacks enforcement authority with respect to the data security provisions of Gramm-Leach-Bliley. In targeting Dwolla, the CFPB apparently decided that it could use its UDAAP authority with respect to data security matters. Focusing on the UDAAP deception prong, the CFPB alleged that the company failed to maintain adequate data security practices despite representations made on the company website and in communications with consumers that the company has implemented practices that exceed industry standards. The CFPB’s action significantly ups the ante for large banks and non-banks subject to the CFPB’s enforcement jurisdiction.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Ballard Spahr LLP | Attorney Advertising

Written by:

Ballard Spahr LLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Ballard Spahr LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide