March 31, 2023

Volume XIII, Number 90


March 31, 2023

Subscribe to Latest Legal News and Analysis

March 30, 2023

Subscribe to Latest Legal News and Analysis

March 29, 2023

Subscribe to Latest Legal News and Analysis

March 28, 2023

Subscribe to Latest Legal News and Analysis

CFPB Starts Year Seeking Comments on Proposals to Give Consumers Enhanced Control of Financial Data

Recently, the CFPB released an outline of proposed measures related to the Bureau’s Dodd-Frank Section 1033 rulemaking efforts that would allow consumers to take control of their personal financial data and determine which third parties could have access to such data. The CFPB is seeking comments on the rulemaking, by January 25, 2023.

Data aggregation companies have been pursuing such a rule for years, primarily in the face of opposition by banks and other financial institutions concerned about data security and liability related to allowing third-party access to customers’ online accounts. The outline discusses proposed regulations that would require covered financial institutions to make consumer financial data available directly to a consumer and to any third parties authorized by the consumer. In a high-level summary of the proposed regulations, the CFPB discusses the regulatory provisions it is considering proposing, including the following:

  • The types of information to be made available to third parties:

    • periodic statement information for settled transactions and deposits

    • information regarding prior transactions and deposits that have not yet settled

    • other information about prior transactions not typically shown on periodic statements or portals

    • online banking transactions that the consumer has set up but that have not yet occurred

    • account identity information.

  • How and when information would need to be made available. The Bureau is considering ways to define the methods and the circumstances in which a financial institution would need to make information available with respect to both direct access and third-party access.

  • Third party obligations. The CFPB is considering proposals under which authorized third parties would have to limit their collection, use, and retention of consumer information to what is reasonably necessary to provide the product or service the consumer has requested.

  • Implementation period. The Bureau is seeking feedback on timeframes to ensure consumers are able to benefit from a final rule, while also considering implementation factors for data providers and third parties.

The CFPB proposals have parallels to many recent state privacy laws in California, Virginia, Colorado, Utah, and Connecticut that have focused on data access rights, data minimization, and third-party obligations. One meaningful difference from the state regimes is that the CFPB’s outline does not exempt data or entities subject to the Gramm-Leach-Bliley Act (GLBA). In fact, companies subject to GLBA are one of the primary targets of these regulations. 

Putting it Into Practice: Data sharing protocols that have been in place at banks for nearly two decades under GLBA (e.g., notice-and-opt-out requirements) are likely to require significant updates under the new rules, in-line with some of the state privacy laws currently that give consumers more control of how data is shared.

Copyright © 2023, Sheppard Mullin Richter & Hampton LLP.National Law Review, Volume XIII, Number 9

About this Author

Moorari Shah Bankruptcy Lawyer Sheppard Mullin Law Firm

Moorari Shah is a partner in the Finance and Bankruptcy Practice Group in the firm's Los Angeles and San Francisco offices. 

Areas of Practice

Moorari combines deep in-house and law firm experience to deliver practical, business-minded legal advice. He represents banks, fintechs, mortgage companies, auto lenders, and other nonbank institutions in transactional, licensing, regulatory compliance, and government enforcement matters covering mergers and acquisitions, consumer and commercial lending, equipment finance and leasing, and supervisory examinations,...

A.J. S. Dhaliwal Bankruptcy Attorney Sheppard Mullin Washington DC

A.J. is an associate in the Finance and Bankruptcy Practice Group in the firm's Washington, D.C. office. 

A.J. has over a decade of experience helping banks, non-bank financial institutions, and other companies providing financial products and services in a wide range of matters including government enforcement actions, civil litigation, regulatory examinations, and internal investigations.

With a diversified regulatory, compliance, and enforcement background, A.J. counsels financial institutions in matters involving...

Lauren Weiss Associate Washington D.C. Sheppard, Mullin, Richter & Hampton LLP

Lauren Weiss is an associate in the Government Contracts, Investigations & International Trade Practice Group in the firm's Washington, D.C. office.

Areas of Practice Lauren’s practice focuses on government contracts litigation, investigations, and counseling matters including the following areas:  Cybersecurity counseling, Internal Investigations, Regulatory compliance,  Bid protests before the U.S. Government Accountability Office, Civil False Claims Act litigation defense, and Transactional due diligence.