Over the last several years, financial technology (“FinTech”) companies have captured the attention of the marketplace with innovative financial products and processes. Now FinTech companies are capturing the attention of the Consumer Financial Protection Bureau (“CFPB”). Two recent actions by the CFPB within the last fourteen days make clear that FinTech companies can expect some of the same regulatory burdens as faced by Federal Deposit Insurance Corporation (“FDIC”) insured banks. In the first action, the CFPB assessed a civil money penalty against a FinTech company for data security deficiencies, the first-ever such action brought by the CFPB. In the second action, the CFPB announced to the public that it would begin accepting consumer complaints regarding online marketplace lenders.
Data Security Protections
On March 2, 2016, the CFPB and Dwolla, Inc., an Iowa-based online peer-to-peer payment system provider (“Dwolla”), entered into a Consent Order that imposed the CFPB’s first-ever civil money penalty for data security violations under the Dodd-Frank Wall Street Reform and Consumer Protection Act of 2010 (the “Dodd-Frank Act”).
In the Consent Order, the CFPB alleged that Dwolla made misrepresentations relating to Dwolla’s data security practices that otherwise constituted deceptive acts and practices likely to cause substantial consumer harm, in violation of the Dodd-Frank Act. Specifically, the CFPB alleged that between 2010 and 2014, Dwolla advertised falsely on its website that all its payment transactions were “safe and secure,” and that its data security processes and protections “met or exceeded” industry standards. The CFPB claimed that Dwolla failed to employ reasonable and appropriate measures to protect sensitive consumer data from unauthorized access by failing to:
- adopt and implement data security policies and procedures reasonable and appropriate for the organization;
- use appropriate measures to identify reasonably foreseeable security risks;
- ensure that employees who had access to consumer information receive adequate training and guidance about security risks;
- use encryption technologies to properly safeguard sensitive consumer information (at rest and in transit); and
- practice secure software development, particularly with regard to consumer facing applications developed at an affiliated website.