Governor Cuomo Mandates Compliance by Credit Reporting Agencies with Sweeping New Cybersecurity Requirements
New York Governor Andrew Cuomo has issued a final regulation that requires credit reporting agencies doing business in New York to register annually with the Department of Financial Services (DFS) and also to comply with accompanying cybersecurity regulations, including the implementation of a cybersecurity program consistent with the requirements already in place for banks, insurance companies and other financial services institutions. The purpose of the new regulation is to protect New Yorkers from data breaches, such as the Equifax breach which exposed the private data of millions of individuals.
The new regulation, entitled "Registration Requirements & Prohibited Practices For Credit Reporting Agencies, 23 NYCRR 201, et seq.," largely follows the provisions of the Fair Credit Reporting Act (FCRA). It defines a "consumer credit reporting agency" as one "that regularly engages in the practice of assembling or evaluating and maintaining, for the purpose of furnishing consumer credit reports to third parties bearing on a consumer's credit worthiness, credit standing, or credit capacity, and credit account information from persons who furnish that information regularly and in the ordinary course of business." 23 NYCRR 201.01(d). Note, however, that a "credit report" does not include "(i) any report containing information solely as to transactions or experiences between the consumer and the person making the report, (ii) any authorization or approval of a specific extension of credit directly or indirectly by the issuer of a credit card or similar device, or (iii) any report in which a person who has been requested by a third party to make a specific extension of credit directly or indirectly to a consumer conveys his decision with respect to such request," if the third party provides the consumer with the information of the entity making such request.
Any entity that qualifies as a "consumer credit reporting agency" and which has assembled, evaluated or maintained a consumer credit report for 1,000 or more New York consumers must register with DFS no later than September 1, 2018, and is also required to register annually by February 1 of each successive year. Beginning July 1, 2019, every consumer reporting agency must file a certificate of compliance with DFS.
Failure to register will prohibit a consumer reporting agency from furnishing a consumer credit report on a New York consumer, receiving payment or compensation, or transmitting such credit information to any third party. Any registered credit reporting agency will also be subject to New York laws prohibiting "unfair, deceptive or predatory practice" under federal or state law. A credit reporting agency found to violate any such consumer protection laws may be denied registration or renewal of registration, or face revocation of registration.
With the new law, credit reporting agencies must also comply with the cybersecurity requirements of the DFS. No later than November 1, 2018, credit reporting agencies must implement a cybersecurity program to protect private data of consumers; have written policies approved by the board or a senior officer; designate a Chief Information Security Officer assigned to protect data and systems; and protect consumer data received from third-party vendors. An annual certificate of compliance with the cybersecurity requirements must also be filed with the DFS.
The new law potentially cuts across a wide swath of entities dealing with the private data of consumers, including retail stores, lending institutions and debt collection agencies to the extent that these entities compile, assemble and/or maintain the type of information included in a credit report. Unlike the FCRA, however, this regulation does not define creditors or furnishers of information to credit reporting agencies, much less provide specific provisions as applicable to such entities.
The DFS has proven to be vigilant in monitoring and enforcing New York's regulatory requirements. Because this is a new regulation, we anticipate that DFS will issue further information to clarify its provisions and/or requirements. We shall continue to keep you apprised of regulatory developments to assist you in your compliance efforts.
Topics
- ACA
- ACA International
- Amicus Brief
- Anti-Discrimination Policy
- Appellate Decisions
- Appointment Power
- Appraised Value
- Arbitration
- Arbitration Rule
- Article III Standing
- ATDS
- Attorneys' Fees
- Auto-Dialer
- Automatic Telephone Dialing System
- Bankruptcy
- Bankruptcy Code
- behavioral economics
- Biden Administration
- Biometric Information Privacy Act
- Bitcoin
- Blockchain
- BNPL
- Business Records
- California
- California Consumer Financial Protection Law
- California Consumer Privacy Act
- California Court of Appeal
- California Department of Financial Protection and Innovation
- Car Dealership
- CARES Act
- CCPA
- CDC
- CFPA
- CFPB
- Chapter 11 Bankruptcy
- Chapter 13 Bankruptcy
- Chapter 7 Bankruptcy
- Circuit Split
- City of Miami
- Civil Contempt
- Claim-Splitting
- Class Action
- Class Action Fairness Act of 2005
- Class Certification
- Climate Change
- Cole Memorandum
- Colorado
- Commercial Foreclosure
- Communications
- Compliance
- Compliance Audit
- Compliance Corner
- Congressional Review Act
- Connecticut
- Connecticut Insurance Department
- Constitutional Claims
- Consumer Data Privacy
- Consumer Disclosures
- Consumer Financial Protection Act
- Consumer Financial Protection Bureau
- Consumer Protections
- Coronavirus
- Coronavirus Aid, Relief, and Economic Security Act
- Corporate Compliance
- Corporate Governance
- COVID-19
- CPRA
- Craigslist
- Credit Report
- Credit Reporting Agencies
- Creditor
- Cryptocurrency
- cyber regulation
- Cybersecurity
- D.C. Circuit Court of Appeals
- Damages
- Data Breach
- Data Privacy Laws
- Data Security
- Debt Buyers
- Debt Collection
- Debt Collector
- Debt Dispute
- Debt Purchase
- Debtor
- Deceased Debtors
- Default Notice
- Department of Education
- Department of Financial Protection and Innovation
- Department of Financial Services
- DFPI
- DFS
- DFS Part 500
- Digital Financial Asset Law
- Disclosure
- Discovery Rule
- District of Columbia
- Document Retention
- Dodd-Frank
- Dodd-Frank Wall Street Reform and Consumer Protection Act
- Due Process Clause
- ECOA
- Economic Impact Payment
- Education
- Education Debt
- Eighth Amendment
- Electronic Communications
- Eleventh Amendment
- Eleventh Circuit Court of Appeals
- Employee Benefits
- Employer Participation Student Loan Assistance Act
- Equal Opportunity Act
- European General Data Privacy Regulation
- Eviction
- Excessive Fines Clause
- Executive Order
- Exempt Status
- Exemption
- FACTA
- Fair and Accurate Credit Transactions Act
- Fair Credit Billing Act
- Fair Credit Reporting Act
- Fair Debt Collection Practices Act
- Fair Employment and Housing Act
- Fair Lending
- Fair Market Value
- Fairness in Class Action Litigation Act of 2017
- FCBA
- FCC
- FCRA
- FDCPA
- Federal
- Federal Arbitration Act
- Federal Communications Commission
- Federal Housing Administration
- Federal Housing Finance Agency
- Federal Rules of Civil Procedure
- Federal Rules of Civil Procedure 68
- Federal Trade Commission
- FHA
- Fifth Amendment
- Fifth Circuit Court of Appeals
- Final Rule
- Financial CHOICE Act
- Financial Registration
- Financial Regulatory
- Financial Risk
- FinTech
- First Amendment
- First Circuit Court of Appeals
- Florida
- Florida Supreme Court
- For-Profit Student Loans
- Forbearance
- Forbearance Agreement
- Foreclosure
- Foreclosure Sale
- Fourteenth Amendment
- Fourth Circuit Court of Appeals
- FTC
- Furnishers
- GDPR
- hacking
- Hardship Declaration
- HealthTech
- Hearsay
- HMDA
- Hobbs Act
- HUD
- Human Intervention Test
- Hunstein
- IDFPR
- Illinois
- Illinois Consumer Fraud and Deceptive Business Practices Act
- Illinois Predatory Loan Prevention Act
- Illinois Student Loan Bill of Rights
- Illinois Supreme Court
- Investigation
- IRS
- Judicial Estoppel
- Kathleen Kraninger
- Kentucky
- kickbacks
- Lack of Standing
- Landlord and Tenant
- Least Sophisticated Consumer Standard
- Legal Standing
- Legislation
- Lender Credit Bid
- LGBTQ
- Licensing
- Litigation
- Loan Defaults
- Loan Discharge
- Loan Modification
- Loan Servicing
- Louisiana
- Maine
- Mandatory Arbitration
- Marijuana
- Marketing Services Agreements
- Maryland
- Massachusetts
- Massachusetts Appeals Court
- Massachusetts Consumer Protection Act
- Massachusetts Land Court
- Massachusetts Supreme Judicial Court
- Material Misrepresentation
- Materiality Requirement
- Medical Debts
- Medical Expenses
- Medical Marijuana
- Minnesota
- Monetary Damages
- Mortgage
- Mortgage Acceleration
- Mortgage Debt
- Mortgage Foreclosure
- Mortgage Loan Acceleration
- Mortgage Loans
- Mortgage Servicers
- Mortgage Servicing
- Motion to Dismiss
- MSA
- Municipal Code
- Municipal Code Violations
- Nevada
- New Jersey
- New York
- New York Court of Appeals
- New York Department of Financial Services
- New York Legislation
- New York Real Property Procedures and Acts
- Ninth Circuit Court of Appeals
- NMLS
- North Carolina
- North Carolina Consumer Finance Act
- North Dakota
- Notice of Proposed Rule Making
- NPRM
- NYCRA
- NYS DFS
- Obama Administration
- OFAC
- Office of Foreign Assets Control
- Origination
- Paragraph 22
- Part 500
- Pennsylvania
- Personal Jurisdiction
- Post-Discharge-Communications
- PPP
- Pre-Foreclosure Mediation
- Preemption
- Privacy
- Private Colleges and Universities
- Private Right of Action
- Private Student Loans
- Property Rights
- Property Value
- Proposed Legislation
- Real Estate Settlement Act
- Redlining
- referral fees
- Regulated Entities
- Regulated Non-Depositories
- Regulated Organizations
- Regulation
- Regulation X
- Regulatory
- Regulatory Compliance
- Regulatory Relief
- Remote Working
- Residential Foreclosure
- RESPA
- Reverse Mortgage
- Revocation Claims
- Revocation of Election to Accelerate
- Rhode Island
- Rhode Island Supreme Court
- Richard Cordray
- RICO
- Right of Redemption
- Right to Cure
- Right to Cure Notice
- Right to Reinstate
- Risk Management
- Robocalls
- Rohit Chopra
- S.A.F.E. Mortgage Licensing Act
- Safe-Harbor Provision
- Sanitary Codes
- SCOTUS
- Second Circuit Court of Appeals
- Securities & Exchange Commission
- Separation of Powers
- Settlement
- Settlement Conference
- Seventh Circuit Court of Appeals
- Sixth Circuit Court of Appeals
- Social Media
- Standard of Proof
- Statute of Limitations
- Statutory Damages
- Statutory Interpretation
- Stimulus
- Student Loans
- Students
- Supreme Court of the United States
- Tax
- Tax Implications
- Tax Lien
- TCPA
- Telephone Consumer Protection Act
- Texas
- Texting
- Third Circuit Court of Appeals
- TILA
- Trump
- Trump Administration
- Truth in Lending Act
- U.S. Constitution
- U.S. Department of Housing and Urban Development
- UCC
- UDAAP
- Unauthorized Use
- Undue Hardship
- Unfair and Deceptive Practices
- Unfair Competition
- Uniform Commercial Code
- United States Treasury
- Unsolicited Advertisement
- Usury Laws
- Utah
- Video Conferencing
- Virginia
- Virtual Currency Business Act (VCBA)
- Voluntary Discontinuance
- Voluntary Dismissal
- Washington D.C.
- Wisconsin
- Wisconsin Consumer Act