Financial Privacy, Security & Open Banking
Overview
Recent efforts by the Consumer Financial Protection Bureau (CFPB) and other regulators have raised the profile around the collection, use and sharing of consumer financial data, which has in turn put a spotlight on financial privacy and data use practices.
Through progressive rulemakings and guidance by the CFPB, the FTC and other regulators, financial institutions (like banks and credit unions) and other financial services providers (fintechs, credit marketplaces, data brokers, financial management apps, and more) are becoming increasingly subject to a rapidly evolving legal landscape governing consumer financial data.
DWT's Financial Privacy, Security and Open Banking team is a cross-practice, multi-disciplinary group of attorneys with expertise in banking and payments, fintech, privacy and data security, and technology transactions. Our team helps financial services clients manage all aspects of collecting, using and sharing consumer financial data – from complying with law to negotiating data sharing agreements, as well as enforcement counseling and defense.
Our Capabilities
Privacy
Open Banking
The era of open banking and finance is here. Since the days of screen scraping, we have helped data providers, data aggregators, and fintech data users adapt to changing regulations—and you can trust us to keep you informed about the ever-evolving regulatory regime.
Credit Reporting
The CFPB has stepped up its scrutiny over companies' credit reporting practices, with particular focus on "furnisher" obligations under the FCRA to accurately report information and to investigate and correct errors. This has led to a number of CFPB guidance and enforcement actions.
Efforts are underway to delve further into the credit reporting practices of users of consumer report, as evidenced by the CFPB's recent proposal to ban medical bills from credit reports and potentially more FCRA rulemakings addressing data brokers, FCRA permissible purpose, CRA data security and consumer disputes.
We assist clients on FCRA compliance, transactional and enforcement/litigation matters, including counseling clients on identity verification, fraud detection and similar "non-FCRA" services.
Data Security
Financial institutions and other companies are increasingly finding themselves subject to a slew of data security obligations, from data breach and security laws to technical, sector-specific requirements. We help clients gain a comprehensive and holistic understanding of how these obligations apply to them, including information security and data breach response, incident and breach readiness, security program development, security compliance, and transaction counseling.