×
Wednesday, October 7, 2026

CFPB Says Companies Violate Federal Law by Not Protecting Consumer Data - ESR NEWS

On August 11, 2022, the Consumer Financial Protection Bureau (CFPB) published guidance to consumer protection enforcers in a Consumer Financial Protection Circular on Insufficient Data Security that confirmed financial companies may violate federal consumer financial protection law when they fail to safeguard consumer data and can be held liable for lax data security protocols, according to a news release from the CFPB.

The CFPB is increasing its focus on potential misuse and abuse of personal financial data. As part of this effort, the CFPB circular explains how and when firms may be violating the Consumer Financial Protection Act with respect to data security. Specifically, financial companies are at risk of violating the Consumer Financial Protection Act (CFPA) if they fail to have adequate measures to protect against data security incidents.

The CFPB circular provides examples of widely implemented data security practices but does not suggest that particular security practices are specifically required under the Consumer Financial Protection Act. However, the circular notes some examples where the failure to implement the following data security measures might increase the risk that a firm’s conduct triggers liability under the Consumer Financial Protection Act, including:

  • Multi-factor Authentication: Multi-factor authentication greatly increases the level of difficulty for adversaries to compromise enterprise user accounts, and thus gain access to sensitive customer...


Read Full Story: https://www.esrcheck.com/2022/08/18/cfpb-says-companies-violate-federal-law-b...