CREATORS OF THE COMPLIANCE TUNE-UP®

AARMR | ABA | ACAMS | ALTA | ARMCP | IAPP | IIA | MBA | MERS® | MISMO | NAMB

Showing posts with label Consumer Privacy. Show all posts
Showing posts with label Consumer Privacy. Show all posts

Monday, November 19, 2018

Identity Theft Prevention: How to Catch a Thief


Chairman & Managing Director

Here are four scenarios involving identity theft that mortgage originators encounter from time to time. Read them and then keep them in mind as I discuss how to ask for additional information in order to prevent identity theft.
1.       A law enforcement report containing detailed information about the identity theft and the signature, badge number, or other identification information of the individual law enforcement official taking the report should be sufficient on face value to support a victim’s request.
Question: Without an identifiable concern, such as an indication that the report was fraudulent, would it be reasonable for an information furnisher or Consumer Reporting Agency (CRA) to request additional information or documentation?
Answer: It would not be reasonable.
2.       A consumer might provide a law enforcement report similar to the above report, but certain important information such as the consumer’s date of birth or Social Security number may be missing because the consumer chose not to provide it.
Question: The information furnisher or CRA could accept this report, but would it be reasonable to require that the consumer provide the missing information?
Answer: It would be reasonable.
3.       A consumer might provide a law enforcement report generated by an automated system with a simple allegation that an identity theft occurred to support a request for a tradeline block or cessation of information furnishing.
Question: Would it be reasonable for an information furnisher or CRA to ask that the consumer fill out and have notarized the Commission’s ID Theft Affidavit or a similar form and provide some form of identification documentation?
Answer: It would be reasonable.
4.       A consumer might provide a law enforcement report generated by an automated system with a simple allegation that an identity theft occurred to support a request for an extended fraud alert.
Question: Would it be reasonable for a consumer reporting agency to require additional documentation or information, such as a notarized affidavit?
Answer: It would not be reasonable.
In these scenarios, a financial institution should be responsive in accordance with certain guidelines. Specificity of action must be appropriate, reasonable and proportional to the challenge. However, total reliance on the CRA is inappropriate.

Tuesday, February 24, 2015

The Lead Generation Company: Managing the Risks

Jonathan Foxx
President & Managing Director

Generating leads is an important way to reach consumers. It is also fraught with regulatory risk. A lead is consumer information that signals consumer interest or inquiry into products or services offered by a business, such as residential mortgage lenders and originators. There are several factors to be considered, not just licensing. I will list some rudimentary guidelines in this article, specifically with respect to contact with the consumer. Caution is urged to consult with a risk management professional to ensure compliance with federal and state guidelines required by a marketing campaign to generate leads. Although my focus is primarily on the online lead generation process, virtually all the guidelines provided herein may be extrapolated for use in offline lead generation campaigns.

My firm often is requested by clients to vet a lead generator, which I will call a Lead Generation Company. Careful risk management advice should be considered when developing and managing leads, whether obtained from an outsourced entity or a loan originator’s own website, in-house, or through online lead generation advertisements. Certainly, any loan originator that uses leads must have an internal compliance function that accounts for proper licensing of the Lead Generation Company (where required), monitoring of the data integrity derived therefrom, testing conformance with the originator’s policies, and training of staff in the appropriate use of lead generated, consumer data.

Banking departments these days are not just looking at licensing qua licensing. They are looking for loan originator compensation violations that are triggered by lead generation. For instance, they know that loans may have different cost structures depending on how the loans were initially received by the lender. A lead generated by the loan originator may be compensated differently than those generated by the creditor. As long as this doesn’t constitute a proxy for a loan term or condition, it is generally acceptable; that is, the loan officer may also be reimbursed for lead generation and other legitimate business costs, but the creditor must beware of how this may serve as a proxy for terms and conditions. It is up to the lender to make this determination (and properly document it).

Four Rules

In any lead generating marketing, the following four rules should be implemented:

1.     Complete, accessible, and straightforward disclosure of all parties’ intent regarding data collection and usage is essential;
2.     Data should not be brokered or sold without consent (or notice and choice) of all parties involved, including the consumer and the loan originator;
3.     Both the consumer, Lead Generation Company, and the loan originator should be made aware, through clear notices, of all parties involved in data collection and sharing; and,
4.     All parties should be educated and aware of current regulations regarding consumer protection and privacy.

These four rules become the bases of the policies, procedures, contractual arrangements, and protocols that ensure a viable marketing campaign that relies, in whole or in part, on lead generation.

Regulatory Focus

The regulators involved in enforcement of compliance with lead generation rules include, but are not limited to, state banking departments, state Attorneys General, the Federal Trade Commission (“FTC”),[i] and the Consumer Financial Protection Bureau (“Bureau”). We already know that the Bureau examines for whether the lead generator is a third-party provider and reviews the terms and appropriateness of the relationship. The Bureau reviews advertisements and advertising sources. It will review TV, radio, print media, Internet, scripts, recordings, and so forth. It will determine if there was proper consumer disclosure all along the way, from point of contact with the consumer to point of contact with the lender, including any intimation of fees and other terms and conditions. Plus, a review is conducted for online data security and sharing of consumer information.

Although the new loan originator qualification standards do not impose licensing requirements, every lender must ensure that each loan originator in its employ is licensed and registered in compliance with laws related to Secure and Fair Enforcement for Mortgage Licensing Act (SAFE), if applicable. Further, entities engaged in lead generation and marketing activities, as well as the companies that do business with such entities, need to pay particular attention to their activities to ensure that they do not inadvertently engage in loan originator activity. If they do, they’ll need to make sure that they meet the new loan originator qualification standards, including licensing requirements. Failure to meet these standards will give rise to severe civil liability that could impair the collectability of the loan.

The Bureau has stated that anytime a consumer gives out sensitive personal and financial information on the Internet there are risks involved to the consumer. In the context of Pay Day Loans, for instance, the Bureau has already warned consumers that if a consumer applies for a loan online, the consumer could be increasing risk significantly.

The Bureau has expressed concern that an online application or form that consumers fill out could be sold to a loan originator that offers to originate a loan on behalf of the consumer. Indeed, the Bureau also has indicated it has concerns that multiple lenders or other settlement service providers could pay for this information, thereby causing them to contact or email the consumer.

Consumer Advocacy

In a November 11, 2013 announcement to consumers, the Bureau stated, “Lead generators might not find you the lowest cost loans, and you should be cautious of sites that promise they will. Many consumers can also be confused about who actually made the loan, which makes getting help when you need it harder.”[ii] In addition, the Bureau has provided caution regarding key words, tags, and tactics.

Importantly, the Bureau’s view toward the Pay Day lead generator should be applied to residential mortgage lenders and originators that purchase leads from a Lead Generation company. Here’s the point: the Bureau has clearly issued an answer to the question, "What is the difference between an online payday lender and one with a storefront?" Its answer was that consumers need to make sure the online website is licensed to do business in the consumer's state and whether the lead generator follows the state's [payday] lending laws. Consider it a warning to all residential loan originators!

Therefore, when the Bureau starts looking at online lead generation involving residential mortgage loans, it is somewhat certain that it applies an even stricter standard to the Lead Generation Company that solicits mortgage information or a mortgage conversation from consumers and sells it or even passes it on to a loan originator. Questions that the Bureau would resolve, either by promulgating rules or through enforcement action, will likely be: (1) Is the Lead Generation Company violating the SAFE Act if it is not licensed in the state it is operating in?, and (2) If it is licensed under SAFE will it be violating the broadly defined Loan Officer Compensation Rule?

Lead Generation as Advertising

Depending on the advertising used to find a consumer for a loan originator, the Bureau may deem the communication to be an advertisement to generate a lead by using certain phrases, such as “Let us help you find a mortgage! Call us! Or Click Here for More Information!” If deemed an advertisement, the Bureau will move to the view that such advertising is a solicitation for a mortgage conversation from a consumer. The outcome of that position would likely lead to a violation of SAFE, because most states consider such a solicitation a violation of SAFE even if no payment is made by the lender or loan officer to the Lead Generation Company - because this type of solicitation would trigger a license requirement.

Even if the Lead Generation Company is properly licensed under a particular state's SAFE Act, if it sells that lead to an unlicensed loan originator in that state the Bureau could pursue an action against the Lead Generation Company because it assisted or facilitated a consumer’s information to be sold to an unlicensed entity, pursuant to various third party vendor management bulletins.

Some states already require a Lead Generation Company collecting consumer information to be licensed as "mortgage brokers" such as Arizona and Virginia. The licensing requirement varies from state to state. Referencing Pay Day lenders, most of the Pay Day lenders in Ohio, for example, have become Mortgage Brokers under the SAFE Act as it takes them out of the state usury statute for Pay Day lenders.

Three Concerns

What type of online Lead Generation Company could cause issues of concern?

(1) Unlicensed Lead Generation Company that tells consumers, for instance, whether they are "Qualified for a Loan or Not";

(2) Online Lead Generation Company that collects any sort of non-public personal information data (the definition of what is “NPI” may vary from state to state, but is also federally settled in Gramm-Leach-Bliley, et alia) and fails to inform and obtain the consumers consent that their information will be shared with a third party; and,

(3) Online Lead Generation Company where it has spoken directly with the consumer and then transfers the "Live Handoff" over to the loan originator (especially if the Lead Generation Company is not licensed, where required by state law). If the Lead Generation company acts as a special kind of mortgage broker then it may be best to stay away because this could violate the standards associated with the Loan Officer Qualifying Rule, mentioned above, which became effective on January 1, 2014.

Additionally, please note that the Bureau has broad authority to enforce Fair Lending Laws, the Telemarketing Sales Rule, Mortgage Lending and Regulations, Mortgage Acts and Practices Advertising Rule, and most certainly Unfair, Deceptive and Abusive Acts or Practices (UDAAP).[iii]

Tuesday, March 12, 2013

Social Media Compliance: Frequently Asked Questions

Last month, I discussed some of the salient compliance requirements associated with using Social Media.* Then, a few days later, I offered to you my article, entitled Social Media and Networking Compliance. This month, on March 6th, I was one of three presenters who gave a webinar for American Banker on Social Media, with special reference to the new rules of the Federal Financial Institutions Examination Council (FFIEC). The proposed rule, issued January 23rd, is entitled "Social Media: Consumer Compliance Risk Management Guidance."
My webinar topic: Social Media – Employee Manual. 
The webinar was very well attended by a diverse cross-section of financial institutions. I found it quite interesting that, when polled during the webinar, by a factor of two to one these companies did not have an Employee Manual, even if about a third of them have policies and procedures relating to Social Media.
I have harped on a certain point regarding policy statements, so here it goes again: policies and procedures are a rather abstract concept to employees; employee manuals, however, for certain rules and regulations, are the most effective means to ensure compliance. Training is an important and an ancillary tool, but employees do not always mentally retain training information. Keep this in mind: an employee manual is a constant reminder of a company's expectations and policies.
One aspect of social media that deserves considerable attention is trolling, using anonymity, and general blogging guidelines. Everybody knows that, for the most part, blogging is electronically available to the public. However, with regard to an individual's employment with a financial institution, what restrictions should be placed on an employee who blogs? From my own research and experience, it would seem that many employees actually have no idea of the implications, requirements, and, in some cases, the potential to easily cross over into violations of federal law or state law.
Here are the risks at stake in social media networking and blogging - though by no means less so for forms of advertising through and use of social media: financial risk, regulatory risk, sales risk, reputation risk, legal risk, strategic risk, and operational risk, such as adverse consequences to business plans, projects, Internet Technology and Information Security protections, and many core departmental functions.
In this article, I will offer a high level FAQs about the use of Social Media (SM), with some additional emphasis on blogging. I will also provide bulleted guidelines to give to employees.
________________________________________________
What is Social Media?
SM is a form of interactive online communication in which users can generate and share content through text, images, audio and/or video.
________________________________________________
Do companies use Social Media?
HubSpot found that by November 2012 companies that blog incurred an average of 55% more visitors to their sites than companies that did not blog. Statistically, blogging companies may generate 97% more external website links and 434% more indexed pages, both of which are critical to a company’s search rank. And a global survey by McKinsey of approximately 1,700 corporate executives finds that 69% of respondents claim measurable advantages from social media, including a lower cost of doing business, better access to knowledge, increased marketing effectiveness, insight for developing more innovative products and services, and higher revenues.
________________________________________________
Does SM cover micro-blogging?
SM includes, but is not limited to, micro-blogging sites (i.e., Facebook, Google Plus, MySpace, and Twitter); forums, blogs, customer review websites and bulletin boards (i.e., Yelp); photo and video sites (i.e., Flickr and YouTube); sites that enable professional networking (i.e., LinkedIn); virtual worlds (i.e., Second Life); and social games (i.e., FarmVille and CityVille).
________________________________________________
How do some financial institutions use SM?
SM has been used to receive and respond to complaints, provide loan pricing, and offer generic information about products and services.
________________________________________________

Tuesday, February 5, 2013

Social Media and Networking Compliance

When you think of advertising, do you include social media? These days, most of you do!
However, social media compliance - which I shall call "SMC" - is a considerable undertaking, far more involved than just issuing a policy and procedure. Often, implementing SMC includes working with internet technology and information security professionals, collaborating with sales, compliance, legal, marketing, and human resources personnel, and ensuring that virtually all employees understand their own obligations with respect to using internet communications.
We have drafted SMC policy statements that call for constant vigilance by management and appointed staff to monitor for and find the appropriate remedies to transgressions relating to use of a company's name, logo, products, and services, in casual and even formal social media interactions.
Recently, Federal Financial Institutions Examination Council (FFIEC) issued a request for comments, entitled Social Media: Consumer Compliance Risk Management Guidance ("Notice"). FFIEC issued this notice on behalf of its six members, Office of the Comptroller of the Currency (OCC); the Board of Governors of the Federal Reserve System (Board); the Federal Deposit Insurance Corporation (FDIC); the National Credit Union Administration (NCUA); the CFPB (collectively, the "Agencies"); and the State Liaison Committee (SLC). Succinctly put, whatever the federal agencies eventually adopt, the states will issue the final guidance as a supervisory guidance not only to the institutions that are, by extension, under its supervision but also through the State Liaison Committee, thereby encouraging state regulators to adopt the guidance.
This means that institutions will be expected to use the forthcoming guidance in their efforts to ensure that their policies and procedures provide oversight and controls commensurate with the risks posed by their social media activities. State agencies that adopt the guidance will expect the entities that they regulate to use the guidance in their efforts to ensure that their risk management and consumer protection practices adequately address the compliance and reputation risks raised by activities conducted via social media.
In this article, I will consider certain features of FFIEC's social media Notice as well as some important subjects to be addressed in constructing an SMC policy and procedure.*
_______________________________________________________
IN THIS ARTICLE
Defining Social Media
Use of Social Media
Risks of Social Media
Risk Management
Risk Areas
Laws and Regulations
Major Risks
Policy and Procedures
_______________________________________________________
Defining Social Media
Social media has been defined in a number of ways. For purposes of the proposed guidance, the Agencies consider social media to be a form of interactive online communication in which users can generate and share content through text, images, audio, and/or video.
Social media can take many forms, including, but not limited to, micro-blogging sites (i.e., Facebook, Google Plus, MySpace, and Twitter); forums, blogs, customer review Websites and bulletin boards (i.e., Yelp); photo and video sites (i.e., Flickr and YouTube); sites that enable professional networking (i.e., LinkedIn); virtual worlds (i.e., Second Life); and social games (i.e., FarmVille and CityVille).
A simple test to distinguish social media from other online media in that the social media communication tends to be more interactive.
_______________________________________________________
Use of Social Media
Financial institutions use social media in a variety of ways, including marketing, providing incentives, facilitating applications for new accounts, inviting feedback from the public, and engaging with existing and potential customers.
For instance, social media has been used to receive and respond to complaints. They have been used to provide loan pricing. Since this form of customer interaction tends to be informal and occurs in a less secure environment, it presents some unique challenges to financial institutions.

Friday, April 6, 2012

FTC Issues New Consumer Privacy Guidelines

Recently, we notified you that on March 12, 2012, the Consumer Financial Protection Bureau (CFPB) announced proposed amendments to the confidential treatment of information obtained from persons in connection with its exercise of authorities under federal consumer financial law. *
The proposed amendments would add a new section to the rules which provide that the submission by any person of any information to the Bureau in the course of the Bureau's supervisory or regulatory processes will not waive or otherwise affect any privilege such person may claim with respect to such information under federal or state law as to any other person or entity. Additionally, the CFPB is proposing to adopt a provision which provides that privileged information given by the CFPB to another federal or state agency does not waive any applicable privilege, whether the privilege belongs to the CFPB or any other person.
Today, we will take a brief look at consumer privacy protection updates at the Federal Trade Commission (FTC), the watchdog enforcement agency charged with protecting consumer privacy, issued a sweeping revisions to its privacy rules.
In this article, we will take a look at the FTC's call for companies to adopt best privacy practices. These best practices include making privacy the "default setting" for commercial data practices and giving consumers greater control over the collection and use of their personal data through simplified choices and increased transparency.
_______________________________________
IN THIS ARTICLE
Overview
Privacy by Design
Simplified Choice for Businesses and Consumers
Greater Transparency
What Has Changed?
Future Issues
_______________________________________
OVERVIEW
On March 26, 2012, the FTC issued a final report of 112 pages, setting forth best practices for businesses to protect the privacy of American consumers and give them greater control over the collection and use of their personal data.
In the report, Protecting Consumer Privacy in an Era of Rapid Change: Recommendations For Businesses and Policymakers, the FTC also recommends that Congress consider enacting general privacy legislation, data security and breach notification legislation, and data broker legislation.
The Report follows a preliminary staff report that the FTC issued in December 2010. The preliminary report proposed a framework for protecting consumer privacy with respect to the new communication technologies of this century.
Like this Report, the framework urged companies to adopt the following practices, consistent with the Fair Information Practice Principles first articulated almost 40 years ago:
  • Privacy by Design: Build in privacy at every stage of product development.

  • Simplified Choice for Businesses and Consumers: Give consumers the ability to make decisions about their data at a relevant time and context, including through a Do Not Track mechanism, while reducing the burden on businesses of providing unnecessary choices.

  • Greater Transparency: Make information collection and use practices transparent.
PRIVACY BY DESIGN
Companies should build in consumers' privacy protections at every stage in developing their products. These include reasonable security for consumer data, limited collection and retention of such data, and reasonable procedures to promote data accuracy.
SIMPLIED CHOICES FOR BUSINESSES AND CONSUMERS
Companies should give consumers the option to decide what information is shared about them, and with whom. This should include a Do-Not-Track mechanism that would provide a simple, easy way for consumers to control the tracking of their online activities.
GREATER TRANSPARENCY
Companies should disclose details about their collection and use of consumers' information, and provide consumers access to the data collected about them.
WHAT HAS CHANGED?
The Report changes the guidance's scope; that is, the preliminary report of December 2010 recommended that the proposed framework apply to all commercial entities that collect or use consumer data that can be linked to a specific consumer, computer, or other device, but now this final Report concludes that the framework should not apply to companies that collect and do not transfer only non-sensitive data from fewer than 5,000 consumers a year.
The Report also responds to comments filed by organizations and individuals that, with technological advances, more and more data could be "reasonably linked" to consumers, computers, or devices. Thus, the Report concludes that data is not "reasonably linked" if a company takes reasonable measures to re-identify the data, commits not to re-identify it, and prohibits downstream recipients from re-identifying it.