On May 11, the Senate voted 51-50 to confirm Alvaro Bedoya as a member of the Federal Trade Commission (FTC), requiring Vice President Kamala Harris to cast the tie-breaking vote. Bedoya gives Democrats a 3-2 majority at the consumer protection agency.

Bedoya’s confirmation was not a sure thing. Republicans held up his nomination for eight months. In fact, Bedoya needed to be renominated at the beginning of this year by President Biden. Republican lawmakers cited concerns about his positions on free trade, consumer privacy, and even domestic policy.

Bedoya’s career has spanned from a professor at Georgetown University’s law school to the founding director of the school’s Center on Privacy and Technology. Bedoya was also chief counsel of the Senate Judiciary Subcommittee on Privacy, Technology, and the Law, working extensively on data privacy and surveillance issues.

It would not be an understatement to say that Bedoya’s confirmation is polarizing. It has been welcomed broadly by consumer and privacy advocates. It is not as well-received by companies in the consumer financial services space that worry a Democratic majority at the FTC would negatively affect competitive markets. We may see additional agency activity in coming months now that the Democrats have a majority.

Bedoya said in his confirmation hearing last year that he intended to focus on privacy issues, including consumer data and facial recognition. FTC Chair Lina Khan has also signaled that the agency plans to look at data privacy as both a consumer protection and a competition issue.

Here are some of Bedoya’s notable publications:

  • In the New Mexico Law Review (Vol. 50, No. 3, 2020), Bedoya published a paper titled, “Privacy as a Civil Right.” “In 2020, the hallmark of surveillance is its ubiquity,” Bedoya writes in the abstract.
  • Bedoya drafted the “Location Privacy Protection Act of 2014,” arguing for oversight of telecom companies, specifically regarding customer data, location, and biometric privacy. A frequent example cited by Bedoya was the use of spyware apps on cell phones for abusers to track their spouses.
  • Bedoya, Clare Garvie, and Jonathan Frankle published a paper/website, “The Perpetual Line-Up,” in 2016. The authors focused on facial recognition technology and algorithmic bias.

Like most industries today, Consumer Finance Services businesses are being significantly impacted by the novel coronavirus (COVID-19). Troutman Pepper has developed a dedicated COVID-19 Resource Center to guide clients through this unprecedented global health challenge. We regularly update this site with COVID-19 news and developments, recommendations from leading health organizations, and tools that businesses can use free of charge.

Our bank and loan servicing clients also face novel challenges affecting their industry due to COVID-19, particularly the ever-changing rules and regulations concerning evictions and foreclosures. We closely track these updates and have assembled an interactive tracker containing state orders and guidance documents regarding residential foreclosure and eviction moratoriums.

To help you keep abreast of relevant activities, below find a breakdown of some of the biggest COVID-19 driven events at the federal and state levels to impact the Consumer Finance Services industry this past week:

Federal Activities

State Activities

Privacy and Cybersecurity Activities

Federal Activities:

  • On August 19, the Consumer Financial Protection Bureau (CFPB) released a new Home Mortgage Disclosure Act (HMDA) data report on residential mortgage lending trends. The report found that the total number of closed-end originations and applications increased substantially between 2019 and 2020. Closed-end originations (excluding reverse mortgages) increased in 2020 by 65.2%, from 8.3 million in 2019 to 13.6 million in 2020. While mortgage activity generally increased, year over year, significant differences between demographic groups persisted, including higher interest rates and denials among Black and Hispanic consumers in the mortgage market. For more information, click here.

State Activities:

  • On August 19, Virginia Attorney General Mark Herring issued updated outlines regarding current tenant protections. “The sad reality is that too many Virginians across the Commonwealth continue to find themselves in tough financial situations because of the ongoing COVID-19 pandemic and they may have a hard time making ends meet or paying their rent,” said Attorney General Herring. The outlined protections apply to residential tenants and include: (1) Virginia state protections which are effective through June 30, 2022; (2) Virginia’s Rent Relief Program; and (3) the Center for Disease Control and Prevention Department of Health and Human Services eviction protections through October 3. For more information, click here.
  • On August 17, Virginia Attorney General Mark Herring filed comments with the State Corporation Commission (SCC) in support of a “newly passed ‘bill of rights’ for Virginia student borrowers.” Attorney General Herring stated, “More than one million Virginians are saddled with the crippling weight of student loan debt – something that negatively affects almost every aspect of their lives… My office has worked hard to help student loan borrowers in the Commonwealth, especially in instances where the loan servicer has taken advantage of borrowers and acted deceptively.” In February of last year, the general assembly passed House Bill 10, under which the SCC “protects student borrowers from servicers who would, among other things, engage in unfair or deceptive conduct, misapply loan payments, or misreport information to credit bureaus.” For more information, click here.
  • On August 18, Illinois Attorney General Kwame Raoul issued a consumer alert regarding a cryptocurrency scam involving CoMed (a company providing electric service to 70% of Illinois). According to the alert, thieves have been claiming “to scare people into making wrongful cash or bitcoin payments that are nearly impossible to recover.” During the pandemic, cryptocurrency scams have skyrocketed with “nearly 3,500 imposter scams involving cryptocurrency between Oct. 1, 2020 through March 31, 2021, totaling $64 million in reported losses.” For more information, click here.

Privacy and Cybersecurity Activities:

  • On August 20, the Federal Trade Commission (FTC) warned consumers that they should not purchase fake COVID-19 verification tools or products from scammers, such as “fake vaccination cards, certificates, and test results.” The FTC advises individuals that they should:
    • Know that buying fake vaccine cards, making your own, or filling in blank cards with false information could get them fined “or even land you in jail.”
    • Not share personal information with potential scammers. Scammers may sell personal information to others or use that information to commit identity theft.

To learn more about the FTC’s warning, click here.

  • On August 19, the FTC warned consumers that scammers are “impersonating FTC Chair Lina Khan in a new phishing scheme [that] says the FTC wants to send [individuals] coronavirus relief funds and tells [them] to send some personal information, like [their] name, address, and date of birth.” The FTC reminds consumers that it is “not distributing coronavirus economic stimulus or relief money to people.” Individuals who may have received a possible phishing scam pretending to be FTC Chair Khan have been informed to report the communication to the FTC at ReportFraud.ftc.gov. To read the full announcement, click here.
  • On August 18, NBC News reported that major software developers, such as Google, Apple, and Samsung, are working on quick response (QR) codes that hold COVID-19 vaccination proof on mobile devices. The codes would be stored locally on devices, which will allow individuals to show their vaccination records with a single touch. The report recognizes that privacy concerns still exist. It is unclear how software developers will protect individual privacy. For those interested in learning more about the privacy implications of vaccination certificates, check out Troutman Pepper’s Law360 article by clicking here.

On July 1, the Federal Trade Commission (FTC) voted to approve seven omnibus resolutions authorizing staff attorneys to use compulsory process to investigate key enforcement targets. The vote fell along party lines, with Democratic Commissioners Lina Khan, Rohit Chopra, and Kelly Slaughter voting in favor of the resolutions, while Republican Commissioners Christine Wilson and Noah Phillips voted against them. The vote — along with several others made at the same public hearing — again signals that newly minted Chair Lina Khan intends to remake the FTC into a much more aggressive, and potentially much more partisan, consumer protection agency.

As explained in the FTC’s press release, the omnibus resolutions authorize compulsory process for key enforcement priorities:

Priority targets include repeat offenders; technology companies and digital platforms; and healthcare businesses such as pharmaceutical companies, pharmacy benefits managers, and hospitals. The agency is also prioritizing investigations into harms against workers and small businesses, along with harms related to the COVID-19 pandemic. Finally, at a time when merger filings are surging, the agency is ramping up enforcement against illegal mergers, both proposed and consummated.

FTC staff attorneys must still seek Commission approval before issuing compulsory process demands, which are generally issued as civil investigative demands or subpoenas. But with these resolutions, any single FTC commissioner can authorize compulsory process, and that without seeking the input of any other commissioner or a vote of the entire Commission.

“The reforms are designed to ensure that our staff can comprehensively investigate unlawful business practices across the economy,” said Chair Khan. “They will help relieve unnecessary burdens on staff and cut back delays and ‘red tape’ bureaucracy when it comes to advancing our Commission’s law enforcement priorities.”

Our Take. Newly minted FTC Chair Lina Khan has an aggressive agenda. And the two other Democratic commissioners, Rohit Chopra and Kelly Slaughter, have signaled that Khan has their full support, even when her proposed actions violate longstanding FTC policy or practice. Moving forward, we expect the FTC to be much more aggressive in its enforcement and rulemaking efforts, and much more partisan in its deliberations and voting patterns.

On June 23, Commissioner Christine Wilson, a Republican appointee, confirmed that she has agreed to use the Federal Trade Commission’s (FTC) rulemaking authority to craft comprehensive data privacy regulations. With Commissioner Wilson’s agreement, there is an even stronger chance that the FTC will engage in privacy-related rulemaking, especially since recently appointed FTC Chair Lina Khan has been a vocal supporter of more FTC rulemaking, as we reported here.

Over the last several years, both Republican and Democratic FTC commissioners have urged Congress to pass comprehensive federal privacy legislation. But that has not happened. Instead, states have taken the lead, with California and Virginia enacting comprehensive privacy legislation and with Colorado, as we reported here, now poised to become the third state to enact a comprehensive privacy law.

In the absence of congressional action and in light of a growing patchwork of state privacy laws, Commissioner Wilson has reluctantly agreed to support FTC rulemaking. In voicing her support, she noted that privacy-related rulemaking was not her “first or second choice” or “even the third best option for how this should be handled.” But “in the absence of Congressional action,” she noted, she has “reluctantly come to consider whether we should begin a privacy rulemaking proceeding at the Federal Trade Commission.”

Commissioner Wilson noted that her prior opposition to privacy-related rulemaking was a product of her concern that rulemaking tends to “stifle innovation and competition,” and reflected her belief that Congress is in the best position to craft a federal privacy framework. But she noted that the growing patchwork of state privacy laws is also problematic, as it increases complexity and related compliance costs for affected industries.

Our Take. The FTC will likely engage in significantly more rulemaking under newly appointed Chair Lina Khan. Privacy-related rulemaking at the federal level would not bar additional states from enacting privacy laws, nor would it address the key issues that have divided Congress, like whether a federal privacy regime should include a private right of action or preempt state privacy laws. But it could discourage additional states from enacting privacy laws, and that would be a true gain for privacy professionals and companies struggling to comply with the growing number of state privacy laws.

Like most industries today, Consumer Finance Services businesses are being significantly impacted by the novel coronavirus (COVID-19). Troutman Pepper has developed a dedicated COVID-19 Resource Center to guide clients through this unprecedented global health challenge. We regularly update this site with COVID-19 news and developments, recommendations from leading health organizations, and tools that businesses can use free of charge.

Our bank and loan servicing clients also face novel challenges affecting their industry due to COVID-19, particularly the ever-changing rules and regulations concerning evictions and foreclosures. We closely track these updates and have assembled an interactive tracker containing state orders and guidance documents regarding residential foreclosure and eviction moratoriums.

To help you keep abreast of relevant activities, below find a breakdown of some of the biggest COVID-19 driven events at the federal and state levels to impact the Consumer Finance Services industry this past week:

Federal Activities

State Activities

Privacy and Cybersecurity Activities

Federal Activities:

  • On May 13, the U.S. House of Representatives passed the Comprehensive Debt Collection Improvement Act, a collection of bills intended to reform how debts are collected. The bill now heads to the Senate for its consideration. For more information, click here.
  • On May 14, the Federal Reserve Board (Board) announced the third extension of a rule to bolster the effectiveness of the Small Business Administration’s Paycheck Protection Program (PPP). Like the earlier extensions, this one will temporarily modify the Board’s rules so that certain bank directors and shareholders can apply to their banks for PPP loans for their small businesses. For more information, click here.
  • On May 13, the U.S. Department of the Treasury announced that it distributed $742 million to 42 states and three territories through the Homeowner Assistance Fund (HAF). A part of the American Rescue Plan, HAF seeks to prevent mortgage delinquencies and defaults, foreclosures, loss of utilities or home energy services, and displacement of homeowners experiencing financial hardship due to the COVID-19 pandemic. For more information, click here.
  • On May 12, the Senate Commerce Committee (FTC) voted to proceed with Lina Khan’s nomination as commissioner of the Federal Trade Commission. Previously, Khan served as a legal advisor to former FTC Commissioner Rohit Chopra. For more information, click here.

State Activities:

  • On May 13, the California Senate passed a bill that will require the original creditor or owner of a debt to notify a consumer within five days of the sale or assignment of the debt to someone else, while also giving consumers the right to request certain information about a debt from debt collectors, such as the debt’s delinquency status or the date of the last payment, among other pieces of information. For more information, click here.
  • On May 13, the Nevada Financial Institutions Division (NFID) extended its temporary guidance allowing employees of licensed collection agencies to work from home through July 31. The guidance was previously set to expire on May 31. For more information, click here.
  • On May 12, a bill was introduced to the New Jersey Senate, which would provide financial relief to landlords and tenants in response to the COVID-19 pandemic. Among other measures, the bill would “prohibit a landlord from furnishing information about the nonpayment or late payment of rent which accrued during the covered period, or other court filings or proceedings related to non-payment or late payment of rent which accrued during the covered period, directly to another residential landlord, or to a debt collection or credit reporting agency.” For more information, click here.
  • On May 12, Oregon H.B. 2009 passed through the Housing and Development Committee. The bill “establishes temporary limitations on lenders’ remedies for borrowers’ failures to make payments on obligations secured by mortgages, trust deeds or land sale contracts for certain real property” due to “loss of income that is related to the COVID-19 pandemic.” For more information, click here.
  • On May 10, the Nevada Assembly Committee on Commerce and Labor submitted recommendations to S.B. 248, which limits a collection agency’s ability to collect on medical debt. The proposed amendments include changing the definition of medical debt, allowing medical debtors to initiate contact and make voluntary payments, and preventing certain written communications from being sent via certified mail. For more information, click here.
  • On May 10, the Maine Senate Committee on Appropriations and Financial Affairs received a bill establishing a homeowner assistance fund program through funds received under the American Rescue Plan Act of 2021 to “prevent mortgage delinquencies and defaults, foreclosures, loss of utilities or home energy services and displacements of homeowners experiencing financial hardship.” The proposed legislation invokes an emergency clause making effective upon approval. For more information, click here.

Privacy and Cybersecurity Activities:

  • On May 10, California Attorney General Rob Bonta joined a coalition of 43 state attorneys general in signing a letter to Facebook CEO Mark Zuckerberg, urging Facebook to abandon plans to launch a version of Instagram for children under the age of 13. The collation argues that social media can be harmful to the mental well-being of children, and it allows for cyberbullying to occur. The letter notes that Facebook has historically failed to protect the welfare of minors who use its products. The coalition’s action shows the growing trend of adding extra privacy protections for minors. For example, this trend can be seen in the California Consumer Privacy Act (CCPA) — see Troutman Pepper’s series about CCPA compliance, including provisions on minor privacy protections, available here.
  • On May 14, U.S. Secretary of Commerce Gina Raimondo and U.S. Secretary of Homeland Security Alejandro Mayorkas co-authored an op-ed in CNBC, detailing the impact of the Colonial Pipeline ransomware attack and how this attack creates a learning opportunity for organizations to improve their cybersecurity defenses. The op-ed points to an estimate that over $350 million in ransom was paid to attackers in 2020 — a more than 300% increase over the previous year — with an average payment of over $300,000. Moreover, the op-ed noted that according to a 2021 report, the greatest number of victims in 2020 by industry were in manufacturing, professional and legal services, and construction. The co-authors also discussed practice guidelines and linked to a Department of Commerce’s National Institute of Standards and Technology (NIST) guide to help combat ransomware attacks. In our article here, Troutman Pepper discusses ways business leaders can reduce their organizations’ cyber risks.
  • On May 12, President Joe Biden signed an executive order intended to enhance U.S. cybersecurity practices and protect federal government systems. The executive order calls for collaboration between the federal government and the private sector to confront “persistent and increasingly sophisticated malicious cyber campaigns” that threaten U.S. security. Some specific steps the executive order highlights include:
    • Creating a standardized playbook for federal responses to cyber incidents;
    • Establishing a “Cybersecurity Safety Review Board” of public and private-sector officials, which should convene after major cyber attacks to provide analysis and recommendations; and
    • Improving the security of software sold to the government, including by requiring developers to share certain security data with the public.

On March 25, the Federal Trade Commission (FTC or Commission) released an article reflecting on its work in 2020. The following are some of the most notable actions of the FTC in 2020:

  • The Commission launched a new website, where consumers can report scams and frauds.
  • A new initiative, called the Community Advocate Center, was created to partner with legal aid organizations to expand the FTC’s outreach to low-income communities and encourage them to report fraud.
  • Out of the FTC’s enforcement actions, 25% were against health care pharmaceuticals and medical devices, another 25% for manufacturing and chemicals, and 21% against general health care.
  • The Commission actively worked to preserve competition and challenged a number of mergers from hospitals, in-home nursing services, and pharmaceuticals, to name a few.
  • As always, the FTC stopped deceptive and unfair marketing practices. For example, several cases were brought against companies that failed to deliver on their promises for high-demand goods as a result of the pandemic.
  • In 2020, 1.66 million consumers received $106.8 million in redress directly from the FTC. An additional $376.9 million went to consumers in redress administered by others.
  • The Commission obtained 23 administrative orders; 66 redress, disgorgement, and permanent injunction orders; and eight civil penalty orders.

We are not expecting the FTC to slow down in 2021. Biden’s nomination of Lina Khan, as discussed in our recent blog post, is a clear signal that the FTC — and other federal consumer protection agencies — will pursue an aggressive enforcement strategy during the Biden administration.

To keep you informed of recent activities, below are several of the most significant federal and state events that have influenced the Consumer Financial Services industry over the past week:

Federal Activities

State Activities

Continue Reading Troutman Pepper Weekly Consumer Financial Services Newsletter – October 15, 2024

To keep you informed of recent activities, below are several of the most significant federal and state events that have influenced the Consumer Financial Services industry over the past week:

Federal Activities

State Activities

Continue Reading Troutman Pepper Weekly Consumer Financial Services Newsletter – July 30, 2024

Yesterday, the Federal Trade Commission (FTC) issued a Supplemental Notice of Proposed Rulemaking, seeking public comment on its proposal to amend the Rule on Impersonation of Government and Businesses (Impersonation Rule or Rule), that is being finalized by the FTC today, to add a prohibition on the impersonation of individuals. The amendment would also extend liability for violations of the Impersonation Rule to parties who provide goods and services with knowledge or reason to know that those goods or services will be used in illegal impersonations. The FTC stated the impetus for the amendment is the surging number of complaints it has received around impersonation fraud, including “deepfakes” generated using artificial intelligence (AI).

Continue Reading FTC Issues Supplemental Rulemaking to Combat Impersonation Fraud

On December 12, the Federal Trade Commission (FTC) published the long-awaited regulation specific to motor vehicle dealers to address concerns of consumer deception in the sales process (Final Rule). We covered the proposed rule, introduced in June 2022, in a blog post here and podcast here. In a 3-0 vote, the FTC approved the issuance of the Final Rule, which will be published in the Federal Register in the coming weeks.

Continue Reading FTC Publishes CARS Rule Regulating Motor Vehicle Dealer Sales Practices