{"id":2453,"date":"2019-04-05T13:15:46","date_gmt":"2019-04-05T18:15:46","guid":{"rendered":"http:\/\/blogs.luc.edu\/compliance\/?p=2453"},"modified":"2019-04-05T13:15:46","modified_gmt":"2019-04-05T18:15:46","slug":"data-privacy-rules-step-up-to-the-next-level","status":"publish","type":"post","link":"https:\/\/blogs.luc.edu\/compliance\/?p=2453","title":{"rendered":"Data Privacy Rules Step Up to the Next Level"},"content":{"rendered":"<p class=\"MsoNormal\"><i>Blake Koloseike<\/i><\/p>\n<p class=\"MsoNormal\"><i>Associate Editor<\/i><\/p>\n<p class=\"MsoNormal\"><i>Loyola University Chicago School of Law, JD 2020<\/i><\/p>\n<p class=\"MsoNormal\"><span class=\"msoIns\"><ins cite=\"mailto:Tierney%20Mason\" datetime=\"2019-04-04T16:24\">T<\/ins><\/span>he Federal Trade Commission (<span class=\"msoIns\"><ins cite=\"mailto:Tierney%20Mason\" datetime=\"2019-04-04T16:24\">\u201c<\/ins><\/span>FTC<span class=\"msoIns\"><ins cite=\"mailto:Tierney%20Mason\" datetime=\"2019-04-04T16:24\">\u201d<\/ins><\/span>) <span class=\"msoIns\"><ins cite=\"mailto:Tierney%20Mason\" datetime=\"2019-04-04T16:24\">recently <\/ins><\/span>proposed two amendments to the Privacy Rule and Safeguards Rule under the <a href=\"https:\/\/www.ftc.gov\/news-events\/press-releases\/2019\/03\/ftc-seeks-comment-proposed-amendments-safeguards-privacy-rules\">Gramm-Leach-Bliley Act<\/a> (<span class=\"msoIns\"><ins cite=\"mailto:Tierney%20Mason\" datetime=\"2019-04-04T16:32\">\u201c<\/ins><\/span>GLBA<span class=\"msoIns\"><ins cite=\"mailto:Tierney%20Mason\" datetime=\"2019-04-04T16:32\">\u201d<\/ins><\/span>). The <a href=\"https:\/\/www.ftc.gov\/news-events\/press-releases\/2019\/03\/ftc-seeks-comment-proposed-amendments-safeguards-privacy-rules\">Safeguards Rule<\/a> requires financial institutions to develop, implement, and maintain a comprehensive information security system. This rule went into effect in <a href=\"https:\/\/www.adlawaccess.com\/2019\/03\/articles\/raising-the-bar-ftcs-proposed-changes-to-the-safeguards-rule-would-establish-a-new-standard-for-information-security-programs\/\">2003<\/a>. The <a href=\"https:\/\/www.ftc.gov\/news-events\/press-releases\/2019\/03\/ftc-seeks-comment-proposed-amendments-safeguards-privacy-rules\">Privacy Rule<\/a> requires financial institutions to inform customers about its information-sharing practices and allows customers to opt out of having their information shared with certain third parties. This rule went into effect in <a href=\"https:\/\/www.adlawaccess.com\/2019\/03\/articles\/raising-the-bar-ftcs-proposed-changes-to-the-safeguards-rule-would-establish-a-new-standard-for-information-security-programs\/\">2000<\/a>. The<span class=\"msoIns\"><ins cite=\"mailto:Jonathan%20Benowitz\" datetime=\"2019-04-03T10:36\"> recent amen<\/ins><\/span><span class=\"msoIns\"><ins cite=\"mailto:Jonathan%20Benowitz\" datetime=\"2019-04-03T10:37\">dments to these two rules <\/ins><\/span>are intended to further protect consumers\u2019 data from third parties<span class=\"msoIns\"><ins cite=\"mailto:Jonathan%20Benowitz\" datetime=\"2019-04-03T10:37\">. However, <\/ins><\/span>the changes could also adversely affect businesses.<\/p>\n<p><!--more--><\/p>\n<p class=\"MsoNormal\"><b style=\"font-family: 'Times New Roman';font-size: 12pt\">The Expansion of Data Privacy Will Likely Protect Consumers<\/b><\/p>\n<p class=\"MsoNormal\">The <a href=\"https:\/\/www.natlawreview.com\/article\/ftc-seeks-comment-proposed-amendments-to-safeguards-and-privacy-rules\">proposed changes<\/a> include encryption of all consumer data, implementing access controls to prevent unauthorized uses from accessing consumer information, implementing multifactor authentication to access consumer data, and requiring period reports submitted to the boards of directors to ensure compliance. <a href=\"https:\/\/www.ftc.gov\/news-events\/press-releases\/2019\/03\/ftc-seeks-comment-proposed-amendments-safeguards-privacy-rules\">Andrew Smith<\/a>, Director of the FTC\u2019s Bureau of Consumer Protection, said, \u201c<span class=\"msoIns\"><ins cite=\"mailto:Tierney%20Mason\" datetime=\"2019-04-04T16:26\">w<\/ins><\/span>e are proposing to amend our data security rules for financial institutions to better protect consumers and provide more certainty for business.\u201d The proposals are intended to align with <a href=\"https:\/\/www.natlawreview.com\/article\/ftc-seeks-comment-proposed-amendments-to-safeguards-and-privacy-rules\">technological advancements<\/a>. The FTC has said that having access controls<span class=\"msoIns\"><ins cite=\"mailto:Blake%20Koloseike\" datetime=\"2019-04-04T22:09\">, such as <\/ins><\/span><span class=\"msoIns\"><ins cite=\"mailto:Blake%20Koloseike\" datetime=\"2019-04-04T22:13\">encryption and multifactor authentication,<\/ins><\/span> is a <a href=\"https:\/\/digitalguardian.com\/blog\/ftc-considering-making-changes-glb-acts-safeguards-privacy-rule\">fundamental requirement<\/a> of all information security programs and encryption is a necessary protection for customer information.<\/p>\n<p class=\"MsoNormal\">The FTC\u2019s proposed changes to the Privacy Rule would bring the rules into line with changes implemented by Congress through the <a href=\"https:\/\/www.ftc.gov\/news-events\/press-releases\/2019\/03\/ftc-seeks-comment-proposed-amendments-safeguards-privacy-rules\">Dodd-Frank Act<\/a> in 2010 and the FAST Act in 2015, which modified the annual privacy notice requirement under the GLBA. Further, the amendments would revise the <a href=\"https:\/\/digitalguardian.com\/blog\/ftc-considering-making-changes-glb-acts-safeguards-privacy-rule\">scope<\/a> of the Privacy Rule, altering the definition of \u201cfinancial institution\u201d under the<ins cite=\"mailto:Blake%20Koloseike\" datetime=\"2019-04-04T22:14\"> <\/ins><span class=\"msoIns\"><ins cite=\"mailto:Blake%20Koloseike\" datetime=\"2019-04-04T22:15\">Safeguards and <\/ins><\/span><span class=\"msoIns\"><ins cite=\"mailto:Blake%20Koloseike\" datetime=\"2019-04-04T22:14\">Privacy<\/ins><\/span> Rule. This would expand the definition to include companies engaged in activities \u201c<a href=\"https:\/\/www.natlawreview.com\/article\/ftc-seeks-comment-proposed-amendments-to-safeguards-and-privacy-rules\">incidental to financial activities<\/a>.\u201d <span class=\"msoIns\"><ins cite=\"mailto:Tierney%20Mason\" datetime=\"2019-04-04T16:32\">T<\/ins><\/span>his would <span class=\"msoIns\"><ins cite=\"mailto:Tierney%20Mason\" datetime=\"2019-04-04T16:32\">also <\/ins><\/span>include \u201c<a href=\"https:\/\/www.natlawreview.com\/article\/ftc-seeks-comment-proposed-amendments-to-safeguards-and-privacy-rules\">finders<\/a>\u201d or those who charge a fee to connect consumers looking for a loan to a lender.<\/p>\n<p class=\"MsoNormal\">The proposed amendments are also designed to ensure that <a href=\"https:\/\/www.natlawreview.com\/article\/ftc-seeks-comment-proposed-amendments-to-safeguards-and-privacy-rules\">non-bank financial technology entities<\/a>, <span class=\"msoIns\"><ins cite=\"mailto:Tierney%20Mason\" datetime=\"2019-04-04T16:33\">or \u201c<\/ins><\/span>fintechs<span class=\"msoIns\"><ins cite=\"mailto:Tierney%20Mason\" datetime=\"2019-04-04T16:33\">\u201d<\/ins><\/span>, are subject to the same cyber security requirements as banks are under the <span class=\"msoIns\"><ins cite=\"mailto:Blake%20Koloseike\" datetime=\"2019-04-04T22:14\">Federal Financial Institutions Examination Council (\u201c<\/ins><\/span>FFIEC<span class=\"msoIns\"><ins cite=\"mailto:Blake%20Koloseike\" datetime=\"2019-04-04T22:14\">\u201d)<\/ins><\/span> interagency guidelines. These proposed regulations could impose a new minimum security standard that implicates many businesses, including those outside the coverage of the current<span class=\"msoIns\"><ins cite=\"mailto:Blake%20Koloseike\" datetime=\"2019-04-04T22:15\"> Safeguards and Privacy<\/ins><\/span> Rule.<\/p>\n<p class=\"MsoNormal\"><b>FTC Commissioners Concerned by the Proposed Changes<\/b><\/p>\n<p class=\"MsoNormal\">Two of the FTC commissioners, Noah Phillips and Christine Wilson, <a href=\"https:\/\/digitalguardian.com\/blog\/ftc-considering-making-changes-glb-acts-safeguards-privacy-rule\">voted against<\/a> increasing the requirements. They believe that it may not be appropriate to mandate such <a href=\"https:\/\/www.ftc.gov\/system\/files\/documents\/public_statements\/1466705\/reg_review_of_safeguards_rule_cmr_phillips_wilson_dissent.pdf\">prescriptive standards<\/a> for all market participants. Some of the specific proposals are in response to <a href=\"https:\/\/www.ftc.gov\/system\/files\/documents\/public_statements\/1466705\/reg_review_of_safeguards_rule_cmr_phillips_wilson_dissent.pdf\">shortcomings<\/a> in data security enforcement cases and investigations. The <span class=\"msoIns\"><ins cite=\"mailto:Blake%20Koloseike\" datetime=\"2019-04-04T22:15\">c<\/ins><\/span>ommissioners <a href=\"https:\/\/www.ftc.gov\/system\/files\/documents\/public_statements\/1466705\/reg_review_of_safeguards_rule_cmr_phillips_wilson_dissent.pdf\">argue<\/a> that not all of the shortcomings concern firms covered by the Safeguard and Privacy Rules. Further, these prescriptive standards impose a <a href=\"https:\/\/www.ftc.gov\/system\/files\/documents\/public_statements\/1466705\/reg_review_of_safeguards_rule_cmr_phillips_wilson_dissent.pdf\">one-size-fits-all<\/a> approach, which they believe could be troublesome. Phillips and Wilson also believe that the regulations may be premature. The proposed regulations are based on regulations by the <a href=\"https:\/\/www.ftc.gov\/system\/files\/documents\/public_statements\/1466705\/reg_review_of_safeguards_rule_cmr_phillips_wilson_dissent.pdf\">New York State Department of Financial Services<\/a> that were enacted just two years ago with no data regarding the efficacy of those regulations. They believe it is too early to adopt them at a federal level.<\/p>\n<p class=\"MsoNormal\">Furthermore, the current regulations are <a href=\"https:\/\/www.ftc.gov\/system\/files\/documents\/public_statements\/1466705\/reg_review_of_safeguards_rule_cmr_phillips_wilson_dissent.pdf\">flexible<\/a> in their approach, determined by the company\u2019s size and complexity. The proposed regulations would <a href=\"https:\/\/www.ftc.gov\/system\/files\/documents\/public_statements\/1466705\/reg_review_of_safeguards_rule_cmr_phillips_wilson_dissent.pdf\">move away<\/a> from that flexibility. Phillips and Wilson believe the expansion could lead to <a href=\"https:\/\/www.ftc.gov\/system\/files\/documents\/public_statements\/1466705\/reg_review_of_safeguards_rule_cmr_phillips_wilson_dissent.pdf\">traps<\/a> for small and innovative businesses. Large companies can more easily absorb <a href=\"https:\/\/www.ftc.gov\/system\/files\/documents\/public_statements\/1466705\/reg_review_of_safeguards_rule_cmr_phillips_wilson_dissent.pdf\">regulatory compliance<\/a> costs than smaller companies. These regulations could potentially <a href=\"https:\/\/www.ftc.gov\/system\/files\/documents\/public_statements\/1466705\/reg_review_of_safeguards_rule_cmr_phillips_wilson_dissent.pdf\">decrease competition<\/a> in the marketplace. Additionally, the prescriptive standards may have <a href=\"https:\/\/www.ftc.gov\/system\/files\/documents\/public_statements\/1466705\/reg_review_of_safeguards_rule_cmr_phillips_wilson_dissent.pdf\">unintended consequences<\/a> of diluting data security measures under the existing Safeguard Rule<span class=\"msoIns\"><ins cite=\"mailto:Tierney%20Mason\" datetime=\"2019-04-04T16:36\">, such as\u2026 [include an example]<\/ins><\/span>. Finally, the Commissioners believe that firms, rather than federal regulators, are in a better position of deciding <a href=\"https:\/\/www.ftc.gov\/system\/files\/documents\/public_statements\/1466705\/reg_review_of_safeguards_rule_cmr_phillips_wilson_dissent.pdf\">board engagement<\/a> on data security. The Commissioners are aware that these regulations are merely being proposed currently, but they believe that if these new regulations pass, there may be <a href=\"https:\/\/www.ftc.gov\/system\/files\/documents\/public_statements\/1466705\/reg_review_of_safeguards_rule_cmr_phillips_wilson_dissent.pdf\">unplanned negative repercussions<\/a>.<\/p>\n<p class=\"MsoNormal\">Overall, the FTC is seeking comment on the proposed amendments for sixty days. Phillips and Wilson are encouraging those in the industry, academia, and civil society with expertise in data privacy to <a href=\"https:\/\/www.ftc.gov\/system\/files\/documents\/public_statements\/1466705\/reg_review_of_safeguards_rule_cmr_phillips_wilson_dissent.pdf\">comment<\/a> and provide evidence on the proposal. Although these regulations protect consumers\u2019 data, they could prove to have negative effects on businesses that must comply with them.<\/p>\n<p><!--EndFragment--><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Federal Trade Commission (\u201cFTC\u201d) recently proposed two amendments to the Privacy Rule and Safeguards Rule under the Gramm-Leach-Bliley Act (\u201cGLBA\u201d). The Safeguards Rule requires financial institutions to develop, implement, and maintain a comprehensive information security system. This rule went into effect in 2003. The Privacy Rule requires financial institutions to inform customers about its information-sharing practices and allows customers to opt out of having their information shared with certain third parties. This rule went into effect in 2000. The recent amendments to these two rules are intended to further protect consumers\u2019 data from third parties. However, the changes could also adversely affect businesses.\u00a0<\/p>\n","protected":false},"author":38,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[571,837,974,1623,1632,1690,1757],"class_list":["post-2453","post","type-post","status-publish","format-standard","hentry","category-finance-banking","tag-data-privacy","tag-federal-trade-commission","tag-gramm-leach-bliley-act","tag-cybersecurity","tag-privacy-rule","tag-regulation","tag-safeguards-rule"],"_links":{"self":[{"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/posts\/2453","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/users\/38"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2453"}],"version-history":[{"count":0,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/posts\/2453\/revisions"}],"wp:attachment":[{"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2453"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2453"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2453"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}