ARTICLE
15 September 2022

Lack Of Cyber Security Controls For Financial Firms May Be An Unfair Business Practice

The CFPB explicitly recommends use of password management, multi-factor authentication, and "timely" software updates as part of any security scheme.
United States Finance and Banking
To print this article, all you need is to be registered or login on Mondaq.com.

The Consumer Financial Protection Bureau (CFPB) is jumping on board with the FTC and state attorney general precedent to regulate data privacy and security matters using its authority to police unfair and deceptive practices in the consumer finance arena. The announcement cites prior FTC and other enforcement actions that employed a similar theory. The statement goes so far as to say that even without a data breach, a financial firm could commit unfair practices if its security is lacking, because lax security puts consumer financial information at risk. The CFPB explicitly recommends use of password management, multi-factor authentication, and "timely" software updates as part of any security scheme.

WHY IT MATTERS

The US has no national privacy or data security law (except in limited areas such as healthcare). As state legislatures pass new state privacy laws, the country's federal agencies are trying to fill a perceived gap at the federal level by using their authority to prohibit unfair and deceptive trade practices nationally. These laws, because they do not explicitly concern cyber and privacy matters, may pose more difficult compliance questions. In this case, however, the CFPB has given three explicit measures as a baseline for adequate protection of consumer financial data. Any business that could be subject to the CFPB would do well to adopt these immediately and document the fact that they have done so as a best practice recommended by the agency.

In a newly released circular, the CFPB said that the failure of a bank or nonbank financial firm to adequately safeguard its customers' personal data can meet the criteria for unfairness under the Consumer Financial Protection Act, which prohibits unfair, deceptive and abusive acts or practices.

www.law360.com/...

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More