ARTICLE
30 October 2008

Privacy And Security Alert: Breaking News: FTC "Red Flags Rule" Enforcement Delayed

M
Mintz

Contributor

Mintz is a general practice, full-service Am Law 100 law firm with more than 600 attorneys. We are headquartered in Boston and have additional US offices in Los Angeles, Miami, New York City, San Diego, San Francisco, and Washington, DC, as well as an office in Toronto, Canada.
The Federal Trade Commission announced today that it will suspend enforcement of the new identity-theft “Red Flags Rule” from the rule’s compliance deadline of November 1, 2008 until May 1, 2009 to give creditors and financial institutions additional time to develop and implement the required written identity-theft prevention programs.
United States Privacy
To print this article, all you need is to be registered or login on Mondaq.com.

The Federal Trade Commission (FTC) announced on October 22, 2008 that it will suspend enforcement of the new identity-theft "Red Flags Rule" from the rule's compliance deadline of November 1, 2008 until May 1, 2009 to give creditors and financial institutions additional time to develop and implement the required written identity-theft prevention programs.

The Red Flags Rule was developed pursuant to the Fair and Accurate Credit Transactions (FACT) Act of 2003. Under the rule, financial institutions and creditors—including any business that accepts deferred payments for services—with covered accounts must have identity-theft prevention programs to identify, detect, and respond to patterns, practices, or specific activities that could indicate identity theft. Some examples of creditors are finance companies, automobile dealers, mortgage brokers, utility companies, telecommunications companies, healthcare providers, and nonprofit and government.

During the course of outreach efforts, the FTC staff learned that some industries and entities within the FTC's jurisdiction were uncertain about their coverage under the rule and learned of the rule's requirements too late to be able to come into compliance by November 1, 2008. The Commission says that its delay of enforcement will enable these entities sufficient time to establish and implement appropriate identity-theft prevention programs as required by the rule.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

We operate a free-to-view policy, asking only that you register in order to read all of our content. Please login or register to view the rest of this article.

See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More