CREATORS OF THE COMPLIANCE TUNE-UP®

AARMR | ABA | ACAMS | ALTA | ARMCP | IAPP | IIA | MBA | MERS® | MISMO | NAMB

Showing posts with label Privacy Law. Show all posts
Showing posts with label Privacy Law. Show all posts

Monday, July 22, 2013

CFPB: Spying to Protect the Consumer

It all began with a Bloomberg article. Although the CFPB spying on the financial habits of at least 10 million consumers seems to be a far cry from NSA's spying on the telephone calls, emails, snail mails, website usage, and many other communication media used by hundreds of millions of US citizens, the timing of the Bloomberg article comes at, shall we say, a rather sensitive time - given its publication just shortly prior to the recent revelations regarding the NSA's rather unique way of interpreting the Fourth Amendment of the US Constitution regarding search and seizure.

Probable Cause Conundrum

I call it the "probable cause conundrum," because (1) the Fourth Amendment expressly states that "the right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized," yet (2) a warrant to spy on Americans these days, at least with respect to probable cause and the requirement that a warrant to spy must be limited in scope according to specific information, has been hugely expanded. At least one of the Supremes has interpreted "probable cause" to mean "reasonable." For some reason, I really don't think that point of view was ever the way the Framers considered it, based on the law extant at the time the Constitution was actually drafted. But I digress.

As a result of Tennessee v. Garner [471 U.S. 1 (1985)], inter alia, we all learned that the "reasonableness requirement" applies not just to a search in combination with a seizure, but also to a search without a seizure, as well as to a seizure without a search. But, again, I digress. So not to go too far afield, let us return to that Bloomberg article which, by the way, was published back in April of this year.

To quote the very first paragraph of the article, its author, Carter Dougherty, writes that "the new U.S. consumer finance watchdog is gearing up to monitor how millions of Americans use credit cards, take out mortgages and overdraw their checking accounts. Their bankers aren’t happy about it." And Mr. Dougherty later on states that "Director Richard Cordray has said that the consumer bureau needs raw material to make 'data-driven' decisions based on how financial products and services are used or abused. Research will improve regulation as well as the marketplace."

We don't like to think that our federal agencies are spying on us, watching our communications, perhaps especially our financial habits, determining therefrom how best to "serve" the public interest. Sure, we know that Google and other web giants are constantly monitoring our financial habits - presumably with our permission to do so. Somehow, it's acceptable if private corporations do it, but when the government does it - not so much!

It all becomes rather weird when the NSA (backed by, say, the DOJ) orders private corporations to spy on us, but the latter are not permitted to admit that the former ordered them to do so - with or without our permission - on the basis of what appears to be a new meaning of "probable cause."

What I find interesting is the similarity between the NSA's and the CFPB's reasons for the need to collect, respectively, virtually all communication data on American citizens and also the financial data on millions of American consumers. It seems that spying has an underlying positive cause, one that apparently we citizens simply don't fully appreciate. For if we did appreciate the workings of these agencies that are just trying to protect us, watch over us to make sure we are safe, and do what they can to mitigate our worst fears, we would overwhelmingly and clearly express our gratitude to the NSA and CFPB for their commitment to our protection - and some Americans certainly seem very grateful.

The Fourth Amendment - how quaint it has become!

Justifying Spying
NSA and CFPB – Two Peas in a Pod

But let's look at some of these justifications that both the NSA and the CFPB have in common for spying on us. Or, if you find that phrase to be nettlesome, perhaps the phrase ‘conducting surveillance on us’ is easier to accept.

First Justification: We need a bogeyman, whom we shall call El Coco, its Spanish version, as when a Spanish-speaking parent tells a child 'si no te portas bien vendrá el coco' ("if you're not good the bogeyman will come and get you"). Almost every civilization has had some version of the bogeyman, that amorphous, unpredictable, malevolent being whose primary role is to scare the living daylights out of us and make us willingly compliant and malleable victims.

So, in the case of the NSA, El Coco comes in the form of terrorists and other malcontents; and, in the case of the CFPB, El Coco seems to be residential mortgage lenders and originators (RMLOs) and other members of the financial markets and sometimes even consumers themselves. In both instances, we can thank the government for protecting us from the mischievous schemes of El Coco.

Friday, January 21, 2011

Privacy & GLBA: Model Forms

On January 12, 2011, the Office of Thrift Supervision (OTS) published information intended to help small thrifts comply with the obligation to send initial and annual privacy notices to their customers. The agency's Small Entity Compliance Guide for the Model Privacy Notice is aimed at helping small thrifts use the model privacy notice form established by the bank and thrift regulatory agencies in December 2009. Proper use of the model forms provides a safe harbor for compliance with the privacy notice duties.

On December 1, 2009, the agencies published the final rule relating to the model privacy notice. Financial institutions that elect to use the model privacy form may rely on the model privacy form as a safe harbor to comply with the GLBA disclosure requirements.

The effective date of the amendments was December 31, 2009, except for the amendments eliminating the sample clauses and associated guidance, which become effective for notices sent after December 31, 2010.

Separator-Glow

Timing and Safe Harbor

Separator-Glow

A model privacy form that meets the privacy regulations' notice content requirements, which institutions may voluntarily rely on as a safe harbor in providing privacy notices as of December 31, 2009, appears in Appendix A to the regulations.

[Sample clauses also relating to the privacy regulations' notice content requirements, applicable in connection with privacy notices provided on or before December 31, 2010, appear in Appendix B to the regulation through December 31, 2011 (and thereafter will be deleted).]

The regulatory agencies have created an on-line form builder that thrifts can use to develop customized versions of the model notices. Although all financial institutions may model forms, they are not required to do so. Other forms, including those that rely on the sample clauses that will be replaced by the model forms, can be used if they comply with the notice requirements. However, only using the model forms will provide a safe harbor after December 31, 2010.

Separator-Glow

Privacy Notice - Form Requirements

Separator-Glow

The model privacy form has several versions:

1. If opt out is provided and include affiliate marketing.

2. If opt out is provided and do not include affiliate marketing.

3. If opt out is not provided and include affiliate marketing.

4. If opt out is not provided and do not include affiliate marketing.

5. If opt out is provided and include affiliate marketing, and mail-back form.

6. If opt out is provided and do not include affiliate marketing, and mail-back form.

To prevent identity theft, institutions should use a truncated form of an account number other than a Social Security Number on privacy notices.

Line-Webpage

Specific disclosure requirements are mandatory, if a financial institution wants to customize the privacy notice. However, the following features are permitted:

  • Print the form on both sides of a single sheet of paper (or on two pages)
  • Incorporate the form in another document or with other notices, and include additional documents or information so long as the form is presented in a clear and conspicuous manner
  • Provide a single form jointly with other affiliated institutions (including affiliated institutions regulated by different agencies), as long as each institution is clearly identified in the correct space of the form
  • Include color and logos to create visual interest, provided they do not interfere with the readability of the form
  • Use different sizes of paper, provided the paper is large enough to meet the minimum 10-point font size and provide sufficient white space around the model form text
  • Include certain information on state and international privacy law in the blank spaces provided
  • Include a mail-in version of the opt-out form as described in the rule
  • Translate the form into languages other than English

Separator-Glow

Online Form Builder - Quick Links

Separator-Glow

On April 15, 2010, the Agencies released an Online Form Builder that financial institutions can download and use to develop and print customized versions of the model consumer privacy notice.

The Online Form Builder, based on the model form regulation published in the Federal Register on December 1, 2009, under the GLB Act, is available with several options. Easy-to-follow instructions for the form builder guide an institution to select the version of the model form that fits its practices.

QUICK LINKS

Online Form Builder

Model Form in PDF

Model Form in HTML

Separator-Glow

Visit Library

Law Library Image

Small Entity Compliance Guide
for the Model Privacy Notice - OTS
January 12, 2011

Post Separator-2-LCG