▶ 0:13:31The subcommittee on financial institutions will come to order. Without objection, the chair is authorized to declare a recess of the committee at any time. This hearing is titled Framework for the Future: Reviewing Data Privacy in Today's Financial System. Without objection, all members will have five legislative days within which to submit extraneous materials to the chair for inclusion in the record. I now recognize myself for four minutes for an opening statement.
▶ 0:13:59Thank you to our witnesses for being here today and lending your expertise to this complex and critical conversation. Today's hearing focuses on financial data privacy where we will assess how Congress can ensure consumers data is used only as authorized while protecting the innovation that has transformed our financial system since the Graham Leech Blly Act or GBA became law more than 25 years ago.
▶ 0:14:26Since GBA's passage, technological advances have revolutionized how Americans access financial services. We've seen the rise of mobile banking apps. peer-to-peer payment platforms and a shift away from cash toward digital transactions. These innovations have expanded financial products and increased access for millions of Americans in rural communities and urban centers. Alongside these developments, the volume and sensitivity of financial data have surged dramatically.
▶ 0:14:56Every transaction and interaction creates data points that financial institutions and fintech firms analyze to improve services, assess risk, and detect fraud and tailor products. While these capabilities bring benefits, they also raise serious privacy and security concerns.
▶ 0:15:14A key driver of innovation is open banking, allowing consumers to securely share their financial data with thirdparty providers through application programming interfaces or APIs. Open banking can empower consumers with more control over their financial information, foster competition, and spur the development of new tools and services. But it also raises questions about data privacy, liability, standard setting, and GLBA's applicability.
▶ 0:15:44GLBA's broad framework has served us well, setting key protections for consumer data. But a quarter of a century is a long time in tech. So we must ask, is GBA still fit for purpose in today's fast-paced datadriven environment? Does it provide the clarity, flexibility, and protection needed in the digital age? As we consider modernization, we must proceed cautiously. Changes that are too restrictive risk choking off access to financial options on which consumers rely.
▶ 0:16:15Conversely, overly lax rules could leave Americans vulnerable to misuse of their sensitive data. Striking the right balance is critical. We also cannot examine GBA in isolation. Data privacy laws have proliferated at the state level with 20 states enacting comprehensive privacy laws. Some exempt financial institutions that comply with GBA, while others layer on more stringent requirements.
▶ 0:16:41This patchwork creates a complex, costly compliance landscape, potentially increasing costs and reducing access. This also risks some states setting de facto national standards, bypassing Congress and creating uncertainty for businesses and consumers alike.
▶ 0:16:59For these reasons, Congress should consider the benefits of a uniform national data privacy standard that offers clear, consistent, preemptive rules for financial institutions while protecting consumers. As our colleagues on the Energy and Commerce Committee work on broader privacy legislation, we must also ask whether sector specific laws like GBA warrant carveouts or tailored treatment.
▶ 0:17:23GBA already imposes strong data protection requirements and financial institutions have built compliance programs around these rules. Overlapping or conflicting standards would only add confusion and cost. Finally, we must address calls to expand enforcement mechanism mechanisms by granting consumers private rights of action which allow individuals to sue firms directly for alleged violations.
▶ 0:17:47Private rights of action open the door to frivolous lawsuits benefiting large firms that can absorb litigation costs and discouraging innovation by increasing legal risks for financial services providers. Ultimately, consumers lose out through reduced access and choice of innovative products. While these are complex issues requiring thoughtful consideration, we must balance robust privacy protections with innovation, access, and reduced regulatory burden.
▶ 0:18:13I look forward to hearing from our witnesses today and engaging in a productive discussion on the future of data privacy in our system. The chair now recognizes the ranking member of the subcommittee, Dr. Foster, for four minutes for an opening statement. Uh thank you, Chairman Bar, and to our witnesses for their excellent written testimony. Uh today, we'll be discussing the framework for data privacy in today's financial system.
▶ 0:18:38At its core are the Graham Leech Blley Act, the Fair Credit Reporting FC act, and section 1033 of the DoddFrank Wall Street Reform and Consumer Protection Act. Minor changes have been made to this framework over the years. However, there's significant questions about how these laws are adapting to an increasingly digital economy, innovative financial products, cyber security risks, artificial intelligence, and the growing role of third party firms in the financial sector. I look forward to discussing many of these issues with our panel today.
▶ 0:19:07I was proud to have sat on this committee when we drafted the DoddFrank Act and was happy to see the most recent update to the Financial Privacy Framework come out last October when after years of bipartisan work under three different presidents, the CFPB finalized the personal financial data rights rule to implement section 1033 of the act. This rule is significant because it gives consumers greater rights, privacy, and the security over their personal financial data.
▶ 0:19:33It makes it easier for consumers to switch between service providers, to find better rates, to make secure payments, and to utilize innovative tools to manage their finances. This rule gives consumers the right to revoke access to their data whenever they choose, and promotes the development of marketdriven data standards. The rule was developed through a lengthy process spanning multiple presidential administrations, gathering public feedback at several points starting in 2016.
▶ 0:20:00The first Trump administration started the process of implementing the rule with an advanced notice of proposed rulemaking in 2020. Despite the work of the first Trump administration and our former chair Patrick Mckenry supporting the final rule, the Trump administration is now apparently working to repeal the rule. This morning, I led 12 of my colleagues from the committee in sending a letter to acting CFPB director Russell Vault, urging him not to rescend this rule, but rather to address outstanding issues through targeted amendments and future guidance.
▶ 0:20:30It's been nearly 15 years since the passage of DoddFrank, and rewriting this rule in its entirety would cause an unnecessary delay that will hurt privacy, hurt innovation, and hurt competition. And finally, while I support this committee's renewed focus on data privacy legislation, I am also deeply concerned by other actions taken by this administration related to American sensitive data.
▶ 0:20:53The president and Elon Musk sent members of their Doge team to raid government agencies of their data across our government where they accessed and gathered sensitive data on millions of Americans. This includes data from the Social Security information from Treasury, from Health and Human Services and even the Consumer Financial Protection Bureau, which holds information on com companies that, for example, would directly compete with Elon Musk's payment company X Money.
▶ 0:21:19These efforts pose great risk to the privacy of all Americans, and anyone that truly cares about privacy should be calling for immediate accountability and transparency from all those involved. Thank you, and I yield back. Gentleman yields back. Gentleman yields back. The chair now recognizes the chairman of the full committee, Mr. Hill, for one minute. Thank you, Chairman Bar.
▶ 0:21:41Since 1999, when the Graham Leech Blley Act was passed, most Americans were still watching movies on their VCRs and arguing over who was tying up the dialup internet connection. Since then, technologies advanced is an extraordinary pace and so is the amount of sensitivity of personal financial information being collected and shared. Remarkably, GBA has kept the pace of many of these changes.
▶ 0:22:07But given the magnitude of today's technological complexity and the increase of data availability and collection, we must ensure Americans privacy is protected while continuing to support the seamless delivery of the financial services that they rely on. Congress has a major role to play in crafting strong, modernized guard rails that keep pace with innovation, preserve consumer trust, and futureproof our laws.
▶ 0:22:33Over the last several congresses, committee Republicans have worked to craft a narrowly tailored legislation to modernize our financial data. We look forward to working on that in this Congress now with the leadership and partnership of the House Energy and Commerce Committee. Yield back to you, Mr. Park. Gentleman yields back. The chair now recognizes the ranking member of the full committee, Mrs. Waters, for one minute. Thank you very much. Today, we are considering the important issue of data privacy.
▶ 0:23:00However, I find it rich that any Republican here would claim to support data privacy when they have said nothing about Trump letting Elon Musk and his Doge minions steal the sensitive data of hundreds of millions of Americans. everything from their health records and consumer data to social security numbers and tax data. Trump didn't stop there.
▶ 0:23:28In addition to shuttering the Consumer Financial Protection Bureau, which fights, fosters, and helps Americans get remedies from predator predatory financial firms. Trump also wrongly vacated the CFPB's open banking rule that promotes data privacy.
▶ 0:23:46I'd like to think there is bipartisan support to protect Americans data, but we must first start by stopping the biggest threat, Donald J. Trump. I yield back. Gentle lady yields back. Today, we welcome the testimony of Mr. Scott Talbot, executive vice president of the Electronic Transactions Association. Mr. Andrew Morris, director of innovation and technology at America's Credit Union unions.
▶ 0:24:17Re Miss Rebecca Keane, partner at Hudson Cook. Miss Jennifer Huddleston, fellow in technology policy at the Ko Institute. Uh and Miss Zoe Strickland, senior fellow at the Future of Privacy Forum. We thank you for taking the time to be here. Uh you each will be recognized for five minutes to give an oral presentation of your testimony. Without objection, your written statements will be made part of the record. Mr. Talbot, you are now recognized for 5 minutes.
▶ 0:24:47Good morning, Chairman Bar, Ranking Member Foster, and members of the Financial Institutions Subcommittee. I'm Scott Talbot. It's my privilege as the executive vice president of the Electronic Transactions Association to speak with you today on the future of privacy and the modern payment system. ET is a trade association representing the broad group of companies from banks to processors and fintexs who provide electronic products and services including mobile wallets, peer-to-peer products, credit, debit, and prepaid cards as well as other forms of digital payments.
▶ 0:25:17Last year, our industry helped consumers and merchants in the US make over 11 trillion in card and peto payments securely, reliably, and quickly. In fact, during the minute, the five minutes I will speak today this morning, roughly 1.5 million transactions will be processed in the US. In each of these transactions, there's a shared expectations between consumers and the payments industry that personal data will be kept both private and secure. Given ETA's members role in the payments industry, both privacy and security are top priorities for our members.
▶ 0:25:46Entities in the entities in the payments industry are covered directly or indirectly by the Graham Ley Act and a handful of state privacy laws. The core structure of GBA imposes both privacy and data security requirements on the industry. This was accomplished through the privacy rule and the safeguards rule. These requirements in in GLPA are tailored to the unique and complex nature of the financial services industry. For financial services, all transactions involve at least two and quite possibly more entities working together to execute the customer's request.
▶ 0:26:15A prime example is a single credit card purchase where at least three or sometimes four entities are involved in moving the data as well as the payment. GBA recognizes this reality and allows multiple entities to share data to work together seamlessly and quickly to serve customers needs. While Glee is largely working well for the financial services industry, a challenge comes with a patchwork of nearly two dozen state privacy laws, eight of which were went into effect this year alone.
▶ 0:26:40These state laws have different approaches to privacy as well as key definitions that create confusion for consumers, small businesses, as well as challenges and expense to financial services and other businesses working to comply. Sometimes the state laws even conflict with each other. And in my written testimony, I've given examples of this. As Congress considers ch changes to the privacy laws, there are a few key themes that we urge you to consider. First is the need for a uniform national standard.
▶ 0:27:06ET member companies serve consumers and businesses, especially small businesses and all 50 states. A single strong uniform national privacy standard would serve all American consumers and businesses by providing common expectations as they conduct their everyday transactions. Any new federal privacy law should be technology neutral and sector neutral. However, given the complexity of financial services and its unique needs, the financial service industry should be continued to be governed by GEIPA. Uh, next, consumers should have rights within this federal privacy law.
▶ 0:27:35Privacy is a two-way street for consumers. The federal privacy law should include consumer rights such as disclosure, access, correction, deletion, and opting out of targeted marketing. We also support using appropriate data minimization and data usage standards that are reasonably suited to execute the underlying transaction. These key aspects will ensure that institutions know the responsibilities and consumers know what to expect. This approach will work to eliminate redundancies, inconsistencies, and confusion created by the existing state privacy regimes.
▶ 0:28:04Any new privacy law must retain permissible use of data to fight fraud. The payments industry works tirelessly to detect and minimize fraud. These efforts to fight fraud benefit consumers, merchants as well as the economy. It is important that any privacy law contain permissible use of the data to fight fraud. This per permissible use exists now in GBA as well as in every state privacy law. Other count's privacy laws also include this important use case.
▶ 0:28:29The scenario here that we're focused on is that a thief commits fraud and then asks for the data to be deleted or forgotten. This would create a blind spot allowing fraudsters room to f to fester excuse me. By including a permissible use of data to fight fraud and privacy law, the payment tree will continue to have a 360deree view of fraud or potential fraud in the payment space. Enforcement by federal regulators.
▶ 0:28:53We encourage any privacy law to assign it forcement enforcement to the appropriate federal Um, next, a key goal to the payments industry is continuous innovation, and we are constantly developing and deploying new products and services to make payments safer, faster, and more convenient for consumers. Two new ideas on the horizon include open banking or consumer-driven banking and artificial intelligence. Both of these um are in use in the market today, and both of these utilize data sharing between multiple parties.
▶ 0:29:22Open banking contemplates consumers directing the sharing of data, and artificial intelligence is um is allows for faster and more efficient use of the data. Both of these are covered by existing federal laws and including GIA as well as fair lending. And in both examples, policy makers should rely on these existing laws and look for any gaps and avoid rushing to legislate new privacy laws here. On behalf of ETA and our member companies, thank you once again for the opportunity to participate in a sporting discussion. Look forward to any questions you may have.
▶ 0:29:53Thank you, Mr. Morris. Uh you are now recognized for five minutes. Good morning, Chairman Bar, Chairman Hill, Ranking Member Foster, and members of the subcommittee. My name is Andrew Morris. I'm director of innovation technology at America's credit unions. Thank you for the opportunity to testify about how a comprehensive federal privacy law can be harmonized with the existing laws and regulations applicable to credit unions and other financial institutions.
▶ 0:30:19First and foremost, America's Credit Union supports a comprehensive federal data security and privacy framework that includes robust security standards that apply to all who collect or hold sensitive personal data. It's important that as the law evolves to match it, credit unions have rules of the road that allow them to meet the needs of their members in the marketplace. Depository institutions, including credit unions, have long been subject to a framework of laws and regulations designed to ensure a high standard of consumer privacy and data security.
▶ 0:30:49Central to this framework is title five of the GBA, which acknowledges the need for heightened care when handling sensitive consumer financial information and provides wellestablished standards for addressing consumer privacy concerns. America's credit unions believes that the Gram BLY Act should remain the model for depository institution compliance with any future federal data privacy and security standard.
▶ 0:31:12Credit unions like many financial institutions have long prioritized investments in data security to ensure that their members privacy is protected. The GLBA requires financial regulators to implement safeguards that are comprehensive and designed to ensure the security, confidentiality, integrity, and proper disposal of consumer information and other records. Under the rules promulgated by the National Credit Union Administration, every credit union must develop and maintain an information security program to protect consumer data.
▶ 0:31:43Additionally, the rules require credit unions to ensure that thirdparty service providers that have access to credit union data take appropriate steps to protect the security and confidentiality of the information. As Congress considers potential reforms to data privacy and security, there are various aspects we believe should be included or addressed. First, there should be an entity level exemption for credit unions and similarly regulated financial institutions that are subject to the GBA.
▶ 0:32:09An entity level exemption would recognize the rigor of existing financial institution compliance activities and allow regulators to tailor supervision based on changing privacy or data security risks. Second, the oversight of credit unions, banks, and other depository institutions should be left to the functional financial institution regulators that have experience in this field. Third, preeemption of state laws is necessary. Today's patchwork of state privacy laws has invited idiosyncratic approaches to data processing activities and technologies.
▶ 0:32:40Some states by choosing to recognize only a data level exemption have placed strains on credit unions by demanding more complex procedures for addressing data processing activities. The resulting compliance burdens magnified each time a new state law is passed siphon resources away from service to consumers and the core lending activities of credit unions. Fourth, there should be limits on data deletion requirements.
▶ 0:33:02Prohibitions on collecting certain types of data without consumer opt-in or a broad right of deletion can frustrate efforts to comply with recordkeeping rules or to detect and prevent fraud. Fifth, an opt- out regime should be maintained. The GLBA and regulation P generally operate to limit sharing of sensitive consumer information through an opt out process, something we believe should continue and be the standard for financial institutions in any future data privacy regime.
▶ 0:33:28Sixth, as outlined in my written testimony, a comprehensive federal data privacy framework should provide for principles-based requirements and offer a safe harbor for businesses that take the appropriate steps to comply with the law. Seventh, any private right of action should be limited. We have serious concerns with any broad private right of action due to the risk of frivolous lawsuits being filed against credit unions which are already held accountable for violations by their regulator, the NCA as well as the CFBB.
▶ 0:33:54In conclusion, stringent information security and privacy practices have long been a part of the financial sector's business practices and are necessary as financial institutions are entrusted with consumers non-public personal information. We look forward to working with you to achieve a well- balanced federal data privacy framework. Thank you for holding this important hearing and the opportunity to appear before you today. I welcome any questions you may have. Thank you, Mr. Morris. Mrs. Keane, you are now recognized for five minutes. Good morning, Chairman Bar.
▶ 0:34:23Chairman Hill, Ranking Member Foster, and members of the subcommittee. Thank you for the opportunity to testify today. I'm Rebecca Keane. I'm a partner at Hudson Cook, where I lead our credit reporting, data privacy, and data security practice. I formerly served as an assistant director at the Federal Trade Commission, where I led efforts related to financial privacy and data security. Today, I'm appearing in my own capacity and not on behalf of my firm or any client.
▶ 0:34:52We are here today to consider the framework governing financial data privacy. The United States has a longstanding tradition of financial prov privacy protection that balances consumer rights, market innovation and regulatory in innovation is the Graham Ley act or the GBA.
▶ 0:35:18It requires financial institutions to provide consumers with clear privacy notices explaining what personal information is collected and how it is shared to offer consumers with the right to opt out of certain types of data sharing with non-affiliated third parties and to implement safeguards to protect the confidentiality and security of consumer financial information.
▶ 0:35:42The GOBA defines non-public personal information broadly and it applies to a wide range of entities engaged in financial activities from banks to auto dealers ensuring consistent privacy standards across the financial services landscape through what are known as the 502E exceptions.
▶ 0:36:03The GBA also recognizes that certain forms of data data sharing are critical to enabling core financial functions such as fraud prevention and public safety. These include disclosures necessary to process transactions, disclosures made with the consumer's consent, and disclosures meant to prevent fraud or unauthorized These types of sharing do not require an opt- out because GOBA draws a clear line between essential
▶ 0:36:33operational and service needs and marketing and other non-essential sharing which where an opt- out is required. And as of 2015, financial institutions that share data only within these carefully crafted exceptions are no longer required to provide duplicative annual notices to consumers as long as they haven't changed their privacy practices.
▶ 0:36:56This change in GBA reduces regulatory burden and has incentivized companies to limit their sharing to only those essential purposes. This benefits both consumers and the industry. I recognize there is a larger discussion about data on consumers and privacy. However, recent proposals such as this CFPB's data broker rule risk undermining this careful balance.
▶ 0:37:21The CFPB's rule proposed to reclassify certain identity and address information governed by the GBA as information under the Fair Credit Reporting Act and would have limited the ability of companies to use GBA information for a number of core purposes such as fraud prevention. The proposal came out of a concern about misuse of consumer data.
▶ 0:37:45But the proposal conflated the responsible regulated use of financial data by institutions that serve essential functions with very different and concerning practices of bad actors such as entities who sell sensitive geoloccation data on military personnel. This conflation is problematic.
▶ 0:38:04It overlooks the fact that GBA covered entities are already subject to comprehensive privacy and security obligations and that the types of sharing permitted under the GBA are vital for protecting consumers against fraud and ensuring public safety.
▶ 0:38:20As this subcommittee continues to examine financial privacy, I urge a careful fact-based approach, one that recognizes the distinction between the well-racky regulated financial data use and the more opaque or harmful practices of unregulated bad actors. Oversight and modernization are appropriate, but they should not come at the cost of undermining core consumer protections or essential financial system functions. I thank you for your attention and I look forward to your questions.
▶ 0:38:51Thank you, Miss Huleston. You are now recognized for five minutes. Thank you, Chair Bar, Ranking Member Foster, and distinguished members of the House Committee on Financial Services Subcommittee on Financial Institutions. My name is Jennifer Huleston and I'm a senior fellow in technology policy at the Ko Institute. My research focuses on the intersection of law and technology including issues related to data privacy. Therefore, I welcome the opportunity to testify regarding data privacy in today's financial system.
▶ 0:39:21In this testimony, I will focus on three key points. First, data privacy in sensitive areas such as financial services is already regulated by existing law. Second, as state or potential federal data privacy law continue to emerge, careful attention should be paid to the way they may interact with or conflict with these existing laws and what a patchwork might mean regarding the burden, particularly on small players.
▶ 0:39:47This is additionally true if enforcement mechanisms such as private rights of action for statutory damages could significantly raise the risk of costly litigation. Finally, I wish to discuss how any conversations around data privacy should consider the impact on innovation, consumer choice, and smaller players, as well as how such laws could interact with with or hinder the deployment of potentially better solutions when it comes to data privacy and data security.
▶ 0:40:15So, to begin with, some have criticized the United States as a sort of wild west when it comes to data privacy. But instead, the United States approach has been better understood as responding with regulation for particularly vulnerable or sensitive data where consumers may be more likely to face harm should it be abused or insecure, such as the financial services sector.
▶ 0:40:36In this regard, the financial services sector already has consumer focused data privacy laws, including the Graham Leech Blightley Act that regulates the personal data of consumers held by financial services forms and the Fair Credit Reporting Act that regulates consumer credit data from credit reporting agencies.
▶ 0:40:54To my second point, the potential interactions between comprehensive data privacy laws at both a state and federal level and the financial services sector is important to understand how general consumer privacy laws could impact this already regulated data. Additional data privacy laws could further add to to the regulatory burden or conflict with existing laws.
▶ 0:41:17As the chair mentioned in his opening statement, an emerging patchwork of state laws that are both sector specific and general in their application could make this more difficult to navigate with at least 19 states having passed comprehensive consumer privacy laws and more debating similar legislation each year.
▶ 0:41:34While many of these state consumer privacy laws have carveout for existing regulated data under laws like the FC and the GBA, this does not mean they do not impact or create potential conflicts for the financial services sector or financial data.
▶ 0:41:50This can include conversations around different definitions of potentially of particularly sensitive data, including financial information or personally identifiable information and the timelines and steps that entities must take to respond to consumer requests or potential issues. These conflicts can be particularly felt by smaller and more innovative entities who have to navigate various definitions.
▶ 0:42:12Additionally, such laws provide an example of the impact that different enforcement mechanisms, including private rights of action with statutory damages, could have in deterring innovation and particularly in already regulated or riskaverse sectors. While not related to financial data, for example, the Illinois's Biometric Information Privacy Act has such a mechanism and it is illustrative of the problems such enforcement can create even in data considered particularly sensitive because of statutory damages and private right of action.
▶ 0:42:42This law has resulted in significant claims against companies ranging from popular social media apps like Meta to Six Flags Amusement Park, but more for violation than for any actual harm occurring to Finally, I'd like to spend my last minute discussing how privacy law and innovation can potentially conflict. While recognizing the specific risk of economic harm and sensitivity of financial data is logical, law is static and innovation is dynamic.
▶ 0:43:10This yields the potential need for reg review of regulation to allow improvements in data privacy, security, and innovation. as various technologies might provide alternatives that are more protective of privacy and provide better services to consumers who opt in but not might not meet the existing definitions. There are three ways existing data privacy regulation might deter innovation that I'd like to highlight. First, many laws are developed for earlier technologies.
▶ 0:43:38This may make it more difficult to use more secure technologies like blockchain that could actually create greater privacy and security for consumers. Second, enforcement mechanisms around private right of action or the need for government approval could deter companies of all sizes, but particularly smaller companies from trying to find innovative ways to protect ways to protect data.
▶ 0:44:00Finally, artificial intelligence may require us to rethink our existing frameworks around data usage, retention, and minimization, including in regulated industries like the financial services sector. I thank you for your time, and I welcome your questions. Thank you, Miss Huleston. Uh, Miss Strickland, you are now recognized for five minutes. Uh, thank you. I am grateful for the opportunity to on this important topic, financial privacy.
▶ 0:44:22I am a senior fellow at the future of privacy forum, which is a leading privacy think tank which supports developing privacy technology and business practices and I lead their open book banking program. I've spent over 30 years working in privacy. This is a fortune 20s and a leading agency across sectors and across technologies. I also led the business roundt financial subgroup in its efforts to reimagine um privacy for the financial sector. Want to touch briefly on general privacy.
▶ 0:44:53Um there are a lot of benefits to having an omnimous privacy um approach in law could be a consistent standard for all consumers. Imagine if we could give consumers a clear set of their rights. It would boost awareness in in the consumer ecosystem and their sense of control over their data.
▶ 0:45:14It would also make our approach more consistent with international um approaches where they do have omnibus laws and it would support data transfers um for multinationals. There are three challenges when we think about omnibus privacy laws. The first one of course is the substance, right? Privacy is principal based and so sometimes it's difficult to define it and be thorough about what those rights are, especially as they evolve over time.
▶ 0:45:41Um been very pleased with recent bills that have really done a very thorough job in thinking about modern privacy principles. The second challenge is around enforcement. Um, I would suggest to policy makers to be careful of approaches that amount to strict liability or per violation penalties. If you think about $1,000 times a million, you get to a billion pretty fast. And on the other hand, be careful to think about um tying enforcement to concrete harms.
▶ 0:46:11In privacy, there often are not out-of- pocket damages, but the but the violations are real. So the focus should instead be on the seriousness of the violation and with the efforts the company made to prevent and mitigate uh the violation. And the third challenge is around existing laws. What do you do with the plethora of state laws that exist and federal laws that exist in terms of uh carveouts or integration?
▶ 0:46:35I I do think as policymakers think about what are good privacy standards that can create some gravity that can uh enable these other existing laws to to fold in uh and to develop that consistent standard. Did want to talk about a pressing issue which is around open banking and the CFPB final rule. Um I do believe it is and can be a part bipartisan um approach and issue. First of all, open banking does represent enormous consumer value.
▶ 0:47:06They really do have the right to have their data and control their data. Enormous um examples of positive use cases, allow better financial planning to transfer and hold their money as they see fit. And just imagine if we could have a focus on Americans having financial health early in their life and the the benefits to them and to society. And I think that that feeling of control over their data and their finances will also um lend itself in other areas of their life as well.
▶ 0:47:35Uh there is a um a challenge if open banking means only the consumer has access to to their records otherwise they're going to have to collect it and transfer it to desired third parties. They'll have it to endlessly update it. I think that would frustrate consumers and it also um unfortunately would would not enable rules for data recipients when they when they obtain that data and they'll have enormous power over over the consumers.
▶ 0:48:03There are many good things about the open banking um principles. One is eliminating screen scraping where consumers give their credentials to a third party. It's terrible privacy and security practice. uh the the rule incorporated industry standards sensibly in a way I think it made it leading in the world and it also enabled privacy and security rules for all parties even though they are difficultly differently regulated um I do think in the final rule there were some misses um some of them impacted data providers some of them impacted
▶ 0:48:34third parties they're detailed in my written testimony but I do think that um those issues can be examined and addressed and then open banking can look forward because it needs and as mentioned in a lot of the consumer and industry and uh the feedback that was provided in that rulemaking process needs to cover more um products things like loans, investments, payroll, EBT to really give that that sense of control and that full picture to consumers.
▶ 0:49:03Um I'm we are very happy to assist in this important effort and I look forward to taking your questions. Thank you. We will now turn to member questions. The chair now recognizes himself for five minutes. Um, Mr. Tabet, my my first question will be directed to you. The section 1033 rulemaking that Miss Strickland was just referencing was a product of the DoddFrank Act.
▶ 0:49:30In the 15 years since the passage of DoddFrank and the rulemaking, the landscape of finan of the financial system has changed massively as we've all been discussing. The rulemaking is currently being debated in the courts. However, there needs to be some certainty and stability so institutions can flourish in the technological ecosystem. Mr.
▶ 0:49:49Talbot, should data privacy legislation potentially modify or replace certain provisions of section 1033 of DoddFrank to codify the beneficial aspects of the rule while moving away from outdated and unclear aspects of the DoddFrank policy as currently written. Sure. Thank you, Mr. Chairman. Appreciate the question.
▶ 0:50:09I think in general the open banking or consumerdriven directed banking is already existing in the marketplace today and it's done through a series of bespoke contracts between the bank data aggregators and fintexs. All of these entities should be subject to GBA or through these contracts. If they're not then possession of the data should trigger coverage of the privacy law. If anybody has a consumer's data and they're not covered they should be covered as a basic principle.
▶ 0:50:36Um, a couple of issues we had with the open banking or consumer-driven banking proposal, final rag that's subject to the courts, is one, it did not address liability for fraud or for a breach. If one entity is is subject to a breach and consumers suffer a loss, that's an area that needs to be addressed uh through either you can do through privacy law or through a future rule making.
▶ 0:50:58So that was one of the misses I think that Zoe referenced earlier and we agreed that there has to be something around um dealing with liability for fraud that was not addressed in that. Additionally, the the law prohibited the collection or assessment of fees by the by the financial institution for the work that they're doing and that's another area that needs to be addressed. But in general, Mr. Chairman, the answer to your question is that existing privacy laws should cover all the all the participants in the open banking system.
▶ 0:51:23But should our privacy legislation that we're considering, should it modify 1033? I I think that in general um it should it should consider it, but I don't think there are any gaps necessarily in the law other than an entity not being subject to GLPA. Okay. Um private rights of actions uh create more problems than they solve. They incentivize trial lawyers to file frivolous class action lawsuits and lead firms to avoid business opportunities that would benefit consumers due to fear of costly litigation.
▶ 0:51:51Miss Keen, based on your experience with the GBA and similar privacy laws, do you believe adding a private right of action to GBA would meaningfully enhance consumer data protection or would it more likely impose litigation risks that hinder innovation and reduce consumer access to financial products? Thank you for the question.
▶ 0:52:13uh what we haven't seen and where I think this concern about do we need to add a private right of action is whether or not there are gaps or problems happening in financial services data there don't seem to be if you look at the history of enforcement and there have been a couple of agencies with enforcement authority over Graham Lee Blly during its existence there haven't been many cases involving privacy of consumers the use of data That tells us
▶ 0:52:43that even though these entities are examined by credential regulators, looked at by different enforcement entities, and we saw a very aggressive enforcement regime for the last four years from the CFPB, and yet what we don't see are cases brought under GBA. So, I think we have the tools that we need if there are problems that exist. Um, and I don't know that additional tools are needed.
▶ 0:53:06So if we have nationwide uniform data privacy standard the reg the the regulatory agencies the financial regulators could handle enforcement I believe so without a private right of action. Yes sir. Thank you. And thanks to advancements in technology over the past few decades financial institutions and firms can partner with more technologyoriented companies in order to compete and serve additional customers with the products and services that work better for them. But state privacy laws have created a patchwork that can complicate these partnerships.
▶ 0:53:36Miss Huddleston, um, how has this patchwork harmed market efficiency and consumers? And would federal preeemption for GBA compliant financial institutions help preserve these innovative partnerships? Thank you for your question, Mr. Chair. When we see this emerging state patchwork, it is particularly burdensome on new ways of using data that might not fit existing models.
▶ 0:53:59Whether that is are firms that wouldn't traditionally be considered financial institutions but may be using financial data in some way to help inform consumers or whether these are just small financial institutions trying to get off the ground. A patchwork means that they're now going to have to seek to comply in 19 different states.
▶ 0:54:17Even if those 19 or 20 different states have the same law on the books, there will be different interpretations of many terms, meaning that uh these firms have to invest significantly in regulatory compliance rather than focusing on providing their consumers with the best possible product. Thank you for that testimony. My time has expired. The gentleman from Illinois, Dr. Foster, is now recognized for five minutes. Thank you, Chairman Bar. Uh quickly, um Mr.
▶ 0:54:42Tell me when you mentioned that banks and fintexs already have a limited data sharing capability between them. It seems to me that the small banks are kind of left out of this. They can't have the the ability to stand up an API team that will go and do all this data sharing. And are there any solutions on the horizon for that or is this going to be one of the things where we're going to have to try to level the playing field to make sure that small banks and credit unions aren't left out? Yeah. So both banks and credit unions, I'll let Andrew speak for himself, but we work together as a as an industry.
▶ 0:55:12We don't want any weak links. And so any data like an API for example through an industry consortium is shared with other other with all entities to allow for yeah there's a problem that I think remains unsolved that the smaller institutions simply don't have the capacity to plug into this very complex ecosystem. Uh, Miss Strickland, um, thank you first off for your very thoughtful testimony and your focus on the important work the CFPB has done on data privacy.
▶ 0:55:37As I said in my opening remarks, I'm really very uncomfortable with the idea of this administration rescending completely the rule to implement section 1033 of DoddFrank. Not only has it been 15 years since the passage of DoddFrank that required the rulemaking, I'm not confident that the CFPB frankly has currently has the staff necessary to do a full rewrite of the rule. Uh, one thing I think is important to recognize that this isn't a rule that came out of nowhere.
▶ 0:56:02You know, there was extensive work on the final rule spanning multiple presidential administrations that solicited public input on various aspects of the rule as well as a notice of proposed rulemaking that was initiated uh during the first Trump administration. Um, can you speak briefly about the extensive work that went into this rule and the huge amount of bipartisan effort uh by your organization and the financial services industry as a whole to prepare for open banking and the impact of this administration's potential rescending of this rule?
▶ 0:56:31Uh, thank you and um very much welcome that question. I included in the written testimony a very detailed description of the extensive process with the relevant links to all the materials. And it was a very long um and extensive and thorough process and had engagement across all industry sectors and consumer groups.
▶ 0:56:53And if you read the comment letters, which I did, and there are a lot of them, and not only were there a lot, but they were very long and thorough and really delved through all the different aspects of the rule and and largely supportive that this is a a positive to the ecosystem. Yes. Um it is has existed for a while, but there were some areas that that um benefited from some consistency of the regulatory framework.
▶ 0:57:16And so you see that um in the in the comment letters and in fact some of them suggested again covering more products and and we really need to do that in terms of giving that that full view to consumers and do it more doing it more quickly since um it is existing now and it is a consumer benefit. I do think um as mentioned in the final rule there were a few misses uh that I think could be addressed. I you know um I think Scott hit on a couple of them um accurately.
▶ 0:57:43Um and I do think that that would be a good place to look um in terms of what happens next either through Congress or the CFPB to address those issues and then look forward um to where we're trying to take open banking um in in the in America.
▶ 0:57:59I did want to comment on your remarks about the smaller players and I do think there's a question if they stay under a regime that is run by screen scraping which is again not a good practice but also isn't better for them too in terms of their understanding of their consumers and their interests. So there are efforts to make that API more widely available and to have core providers who can help lift up uh the smaller players so that they can benefit from this developing ecosystem too and that needs to be paid attention to as well.
▶ 0:58:29I do think the staggering helped because it allows some of this infrastructure to grow and that they can then get um on-ramps onto it but I do think it benefits the whole community that the smaller institutions are ramped on at the right time. Yeah. Thank you. And I I share as someone who's uh done a share a fair share of programming of screen scraping as well as APIs, I share your enthusiasm for getting rid of screen scraping. It's it's unstable. It's dangerous to privacy and it's it's just pain in the ass.
▶ 0:58:59Horrifying, right? And so um but that's the future is probably neither APIs nor the past of screen scraping but agentic interactions where the interaction the consumer interaction is not going to be directly with the consumer but with an agent.
▶ 0:59:14And one of the uh interesting arguments the Trump administration CFPB made in the brief that they filed with a court last Friday was that section 10 they claimed section 1033 of DoddFrank requires that the rule only allows consumers themselves to request access to their data which ignores the the language in the DoddFrank Act that quote an agent, trustee or representative acting on behalf of the individual uh which is obviously meant to include third parties and and agents um authorized by the individual. UAL.
▶ 0:59:45So, um Whoops. If you could just comment on that for the record, I' I'd appreciate it. That's a a big Thank you. The gentleman's time is expired. The gentleman from Michigan, Mr. Heisinga, is now recognized. Uh thank you, Mr. Chairman. I'd like to uh say thanks to the ranking member. Um for the kids watching out there, that's a a technical DC term for difficulties in transactions. What he was expressing what where where exactly those pains might occur um earlier.
▶ 1:00:14So apparently that was funnier in my head than it was when he said it. Uh so um uh Mr. Talbick, good to see you again. I think you got it. You you were you were nodding with with me. But yesterday we heard from multiple witnesses uh about the importance of consumer protections when it comes to owning digital assets and when it comes to data privacy. Frankly, I don't see much difference.
▶ 1:00:40um gaining access to a consumer's data data is just as lucrative as gaining access to their bank account. Um and and you in your testimony you noted uh consumers rightly expect strong privacy protections and data security for their personal information and their money. Of course providing protections does come with some costs and and how can Congress strike the balance between consumer protection and excessive compliance?
▶ 1:01:06there's compliance but then there's also excessive compliance so that small providers and I think uh Miss Huddleston was was talking about that a bit or at least alluding to that uh that these small providers are not disproportion disproportionately affected compared to the larger providers thank you for the question I appreciate it I think first is uh areas where we could focus are tightening up the definitions so that all parties know exactly what is data is protected for example in gramly wy they use the phrase consumer and
▶ 1:01:36customer. They make a distinction between the two and that may no longer hold or be as clear to all parties including smaller players. So tightening up the definitions can help so we all know what we're talking about. Secondly, you can look at the rights that are provided uh under the law. Right now, the rights include access, correction, deletion, and those and make sure that those can be applicable for all entities so that consumers get the same rights and benefits regardless of which institution they choose to use.
▶ 1:02:05And so, narrowly focusing on those rights and how they're applicable in the real world can help address the issue for all players, not just small players. You uh you touched on um definitions, tightening up definitions. I want to ask uh does the GBA's definition of financial institution adequately reflect the range of entities handling consumer financial data today? I don't know, Miss Huddleston, you seem to have that. Mr.
▶ 1:02:34Morris, somebody I'm happy to address. Grab it. Yes. All Um so the definition of financial institutions is keyed off to all the variety of activities that financial companies can engage in and that is subject to expansion if over time the agencies decide hey there's some additional things we need to address. So it is a flexible definition. It's also pretty broad. I mean if you think about the definition of financial institutions.
▶ 1:03:04So broad and flexible could be too broad and flexible or is an interpretation of it has then locked out some areas. It's it's not locked out because it's made in reference to uh the Federal Reserve's definition of what types of financial activities banks engage in. And so it lists everything from credit reporting to making loans to doing financial transactions. Okay. How about Mr. Morris? How does this apply to credit unions?
▶ 1:03:31Yeah, the financial activities would definitely encapsulate what credit unions are doing. So we would clearly be So you're do you feel like you're adequately covered by this? Yes. Okay. Great. And see Mr. Talbot nodding. I would agree. Okay. Um, what consumer rights have states incorporated in data privacy laws that Congress should codify at the federal level? In other words, are there some best practices that we're seeing out in the uh out in the states? Mr. Talbot.
▶ 1:04:00Yeah, I think a couple of uh GLBA covers a lot of those rights. Um, but they they don't necessarily have so much uh the right to access a lot of the information or some of the information. So that could be important to update GLBA with. So is there any states specifically doing that? I mean, as we're as we're seeing, obviously privacy frameworks need to evolve. Is there somebody that's actually doing a good job at that that we ought to be looking at? Anybody else? I would Virginia has done a good job.
▶ 1:04:30Texas both have both both states privacy laws capture those. Okay. Anybody else care to weigh in on that? So I would just echo that I think it's important to consider what uh enforcement mechanisms what timelines are involved in some of these things.
▶ 1:04:46So when we look at for example a right to access are there appropriate incentives particularly for sensitive financial information to ensure that it is the correct consumer that's getting that information that we're not seeing something where there's such a short timeline for response that the wrong information is handed over to the wrong consumer. One can look at, for example, GDPR to see how there have been some incidents where recordings or other information not financial has been handed over that way. Great. Yield back. Gentleman's time's expired. The gentleman from Georgia, Mr. Scott, is recognized.
▶ 1:05:17Thank you, Chairman Bar. And I really agree with you, Chairman, that our nation is at a crossroads when it comes to financial privacy. But right now, our constituents banking information, their credit history, their transaction records, and even how they pay their rent is up for grabs for exploitation, wrongdoing, and
▶ 1:05:47even stealing. And without firm protections, that data can be collected, brokered, and misused, often without the consumer ever knowing. And that is precisely why the CFPB section 1033 rulemaking is a step in the right direction.
▶ 1:06:12The CFPB 1030 rule has set up a framework that empowers Americans to take more control of their own financial data safely, securely, and on their own terms. It prohibits data brokers from monetizing data without consent.
▶ 1:06:37Fintech applications to be transparent, not maliferative and and financial institutions to provide data access in a secure machine readable format. But here is the problem. These protections, this progress on behalf of our consumers are now under a great threat.
▶ 1:07:06For we are watching a dangerous roll back, taking shape at the CFPB under the Trump presidency. President Trump is appointing people who have spent their whole careers defending data brokers, avoiding regulatory compliance, weakening the CFP's enforcement capacity,
▶ 1:07:37and threatening CSP's funding and undercutting the CFP's rule making. Now, Miss Strickland, the Trump CFPB has argued that rule imposes a burden on data aggregates and fintech companies.
▶ 1:08:01But let me ask you, isn't it the CFPsb's job to protect the consumers and not the business models of uh companies that profits from oake or predatory data practices? Thank you for your question.
▶ 1:08:23Yeah, I think one thing that was valuable about the 1033 rule is that it did place obligations on the companies receiving data and in fact um um impose sort of modern principles around what those privacy rules should be and to the prior question asked about hey look you know what what are some of those activities that policymakers should look at there's a developing area called individual rights which I Jennifer alluded to which is do I have the right to access delete transport my data data, how
▶ 1:08:53do I understand the data that belongs to me is about me and and do I have rights with regard to that? So and also another very useful feature we see in some um developing bills is around privacy impact assessments and riskbased assessments which is extremely familiar to the financial sector do a lot of risk analysis and so those sort of precepts really lend themselves to how we think about privacy and I do think that's the value in open banking which is the data recipients are going to have a lot
▶ 1:09:24of information now about these consumers and perhaps even move money on their on their behalf and so it's very important that they actually have rules that apply to them as well. And if you don't have open banking rules, you you don't have that ability to really put those controls in place. Now, many of my friends on the uh Republican side have talked about rescending the rule.
▶ 1:09:47Tell me, won't rescending the rule make it easier for bad actors to exploit our I do think that the the proposed rule really did address some issues between the data sharing amongst the parties. There were some good features for data providers. Definitely some good controls over data recipients um that that really should be included in any future rule making activity around this. I think there were very important points.
▶ 1:10:17Thank you, Mr. Strick. The gentleman yields back. The gentleman from Texas, Mr. Williams, is now recognized. Thank you, Mr. Chair, and thank you all for being here today. Uh, community banks have earned the trust of their customers by safeguarding their sensitive financial data because they have long-standing relationships with their cons customers and handle personal information with diligence and care.
▶ 1:10:38Now, we need to ensure that any updates to data privacy maintain flexibility for smaller banks and these smaller institutions struggle with mandates that force them to divert resources from lending in their communities and into legal compliance. So, Miss Miss Huleston, uh, could you elaborate on ways to modernize the GBA that preserve flexibility for smaller I think it's important that we look at this on a federal level as opposed to the state-by-state patchwork that's often emerging.
▶ 1:11:07Additionally, we need to consider not only the way data may be being used these days by smaller entities, but also the ways it may be used in the future. We already see tools like AI being deployed in the fraud alert system and things like that. We certainly wouldn't want to see regulation or changes that may make it more difficult to deploy these tools in the future. And I think when we're talking around about concerns about private right of action that that's particularly relevant to smaller players.
▶ 1:11:34Smaller players who could find even if they win a lawsuit that it's still potentially business crippling or even business ending and so are less able to absorb the cost of that litigation than a larger player. even though larger players also have significant fi um financial regulatory compliance burdens. Thank you for that. One of the most promising developments in financial services over the past decade has been the growing collaboration between banks and fintech companies.
▶ 1:12:03These partnerships allow smaller institutions to offer cutting edge digital tools which uh underserved customers and compete with largest national banks. And much of this innovation relies on responsible data sharing arrangements uh where consumers can securely grant access to their financial information and improve their banking services. M so Mr.
▶ 1:12:23Talbot um how do data sharing arrangements between banks and fintexs improve competition in the marketplace and how can we protect that collaboration while still maintaining strong privacy protections? Sure. Thank you for your question and I just note that Texas is has a number of provisions in its privacy law which are examples for the rest of the country. They have carveouts for small businesses as well as right secure which are good examples in terms of of data sharing between banks and fintex.
▶ 1:12:51Most of this interaction if not all is already covered by Grele Blly both the privacy as well as the security provisions and if it's not it's covered by private contract bespoke contract between the two entities and so there is sufficient coverage there both for privacy as well as data security and so we feel those existing laws and existing contracts will help keep the data safe and secure u the people I represent in Texas like many rural communities across the country allow local lenders and community financial institutions uses
▶ 1:13:21for access to credit, mortgages, and basic financial services. And as we consider new data privacy rules, we have to be careful not to cut off these vital lifelines. And if regulations are too complex or restrictive, small banks and credit unions may scale back services or exit certain markets entirely. So Mr. Morris's question to you. How can we make sure that the privacy regulations don't unintentionally uh limit consumer access to financial products and particularly for those in rural areas like I represent in Texas.
▶ 1:13:52Thank you for the question. I think one area where a federal privacy framework could focus to preserve that access is by preserving um the current opt out framework that is present in the gramly act that facilitates a lot of joint marketing activities which allows community financial institutions, small credit unions, small community banks to partner with fintexs and others to promote the availability of their services in banking deserts and other places where there may be limited access to affordable products.
▶ 1:14:22So having an opt- out framework for sharing information is an intelligent way that the GBA has balanced those concerns whereas the more ownorous opt-in framework could curtail that and limit access to services in those communities. Okay. Thank you. And uh Mr. Chair, I yield my time back. Gentleman yields. Gentleman from California, Mr. Sherman's now recognized.
▶ 1:14:45When I saw the title of this hearing, I thought I'd spend my full five minutes talking about Elon Musk, looking at all the social security data of millions and millions of Americans, but uh I think I'm going to focus on things within the jurisdiction of our committee. The CFPB plays a critical role with data privacy.
▶ 1:15:07The decision of the Trump administration to destroy, dismantle, abolish the CFPB means that not only will Americans not be protected from ripoffs, not only will they not be auh get the information they need to me make intelligent decisions and financial matters, but uh we'll talk grandly about their privacy, but there won't be an agency there uh to uh ensure that their private debt is kept
▶ 1:15:37private. Um, one of the issues that arises is one we've seen for a long time and that is what happens if there's hacking. We've seen this issue with regard to giant retailers having information getting hacked and then turning to the banks and saying you have to pay all the costs of dealing with consumers on this issue. It's been wellestablished in tort law theory for well over a hundred years.
▶ 1:16:06that the liability the cost of an accident should be put on the party who could have invested to protect prevent that accident. So whether uh whenever a fintech company uh is the uh entity that gets hacked, they're the ones that should bear the cost of the consumer Um the 1033 rule a asks uh fintech companies that want to access to BA bank's data
▶ 1:16:37to comply with the same Graham Leech Bileley financial data protection requirements that bank must comply with but there's no specific enforcement mechanism for this rule. The rule also didn't ban screen scalping, a practice by which third party stores your username, your password, then logs into your bank account and collects and maybe sells your financial data. Mr.
▶ 1:17:00Morris, uh what amendments or guidance like perhaps banning uh uh screen scalping uh and having the CFPB regulate fintech companies that store financial data. what should we consider uh to the uh personal financial uh data rights rule to ensure that um we're safeguarding this data for consumers? Thank you for the question.
▶ 1:17:25I think with respect to ways to better protect data um and address the concerns that you mentioned in the context of 1033, it would be prudent for the CFB to consider a way of allocating liability in the event that data is mishandled um by downstream thirdarty entities uh using that information collecting it from data provider credit unions.
▶ 1:17:50The absence of that means that credit unions and other data provider financial institutions um and their members um only have recourse in the courts. So addressing that in the regulation could be a helpful way to tweak the rule.
▶ 1:18:04Now, under the CFPB rule 1031, financial institutions currently can't charge a fee for thirdparty fintech companies to access the bank's data through their API application programming uh interface uh developer port holes. Uh Mr. Morris, uh is it costly to develop and maintain these API port holes?
▶ 1:18:27And should we consider at least allowing the smaller institutions to charge a fee to fintech companies to access the data uh through these uh relatively expensive port holes? Thank you for the question. I believe that's absolutely correct that it is costly to develop and maintain APIs and one of our concerns again with the CFPB's rule implementing 1033 was the significant cost that is shouldered primarily by data providers to essentially subsidize APA access
▶ 1:18:57API access and development. So we would like the CFB to reconsider um that aspect of the rule to better balance costs to credit unions. going to try to squeeze in one more question, Mr. Morris. Uh what protections like perhaps banning screen scalping across the board should we consider adding so that small institutions are protected uh even if they're exempt from the rule? What effect on small credit unions and small banks?
▶ 1:19:24Uh could there be if there's a massive financial data breach of a third party potentially exposing financial institutions to liability and drying up all its members depository accounts? Uh we're certainly supportive of moving away from screen scraping, which is a less secure way of sharing information as far as tightening up rules that are designed to prevent data breaches um and minimizing their consequences.
▶ 1:19:48I think one area in 1033 the CFPB explored which was sharing um information necessary to initiate a payment that is very sensitive information which if it's shared with a third party can lead to All right, the gentleman's time is expired and the gentleman from Georgia, Mr. Louderdermilk, is now recognized. Well, thank you, Mr. Chairman. Thank you all for being here. Very important subject.
▶ 1:20:12I've got 30 years in uh uh in public and private sector with dealing with intelligence, data security, protecting information. Eight years active duty military and the intelligence uh community protecting nation our nation secret. two years with a defense contractor and 20 years with my own business.
▶ 1:20:33Privacy and security is very important with to me and and the number one key to protecting data was a rule that we lived by in those 30 years is you only have to protect what you have. Meaning if you don't absolutely need something, don't keep it. And while the GLBA focuses on the private sector, the elephant in the room isn't Elon Musk.
▶ 1:21:00It's the massive amount of data the government has that he had access to. But no one on the other side of the aisle wants to address that this entity, this 800 pound gorilla called the federal government is the largest security risk of personal privacy information.
▶ 1:21:18Now what we're discussing here is very important but when we bring up legislation that actually would restrict the amount of data like upgrade updating the bank secrecy act and cons and uh currency transaction reports to make them reflective of where they should be due to inflation. We don't hear anything from the other side but they're always anxious to deal with with the privacy data when it comes to the private sector and that is that is important. I'm not not demeaning it.
▶ 1:21:45Um, but we do have to understand that our nation collects and forces the private sector to turn over massive amounts of personal privacy information, financial information to the government, which is the weakest link in our cyber security protection. So with that, um, Mr. Talbot, dealing with GOBA, what rights do consumers currently have regarding their personal data under the Graham Leachch Blley Act?
▶ 1:22:15Yeah, Mr. Tab, sorry. I'm sorry. Have to kind of look around to see. No, no problem. Appreciate appreciate the question, Mr. Lad Milk, as well as your representation of the state of Georgia where 70% of all credit card debit card transactions run through your state. So, the the rights under GBA for consumers that exist now is they have a right to to correct and a right to we talked about earlier, someone access the information, right, to delete the information. These are important rights for consumers. There's there's disclosure notices that are required depending on your where you sit in the system.
▶ 1:22:45And so these are all important uh rights that they have. They have the ability to opt out of target marketing and that's an important right as well. So that's one things in this new era because we often fail to keep up with technology which allows for some innovation um but also is defining what is consumer data versus uh you know privacy data versus company data uh that type of thing.
▶ 1:23:10But in what ways do financial institutions share consumer data with affiliated and non-affffiliated third parties? Yeah, the first and foremost example is with any transaction. Let's say a credit card transaction. There are at least three, sometimes four parties involved. There's the issuing bank, the acquiring bank, processors, there's networks, and that data under GLB is allowed to be shared for purposes of processing that transaction.
▶ 1:23:34As you well know from the credit card space, that's necessary to allow that transaction to move in 1.2 two seconds when you're standing at the checkout line. How do fintech companies access consumer data to deliver financial products and services and what role does consumer consent play in the process? Sure.
▶ 1:23:50Right now the concept of open banking or consumerdirected banking is happening in the marketplace and FinTex will enter into bespoke contracts with banks to allow their shared customers to share the data between the two and that's governed by a private contract at this point pending the 1033 rules that may come out some point. Okay, thank you. Mr. Morris, what are uh three key features that credit unions believe should be included in any new data security regime? Thank you.
▶ 1:24:18I think uh the first and most important is an entity level exemption that recognizes existing compliance with the Graham BL act as well as other laws like fair credit reporting act the right to financial privacy act and others. Um the other thing we would like to see is a preservation of the opt- out framework and a limitation on private rights of action which could um hinder innovation and create enormous litigation risks for small credit unions and other institutions. Okay. Thank you uh Mr. Mr.
▶ 1:24:47Chairman, I'll yield back my time. The gentleman yields back. The gentleman from California, Mr. Vargas, is recognized. Thank you very much, Mr. Chair. First of all, I want to thank you and the ranking member for convening this hearing. And of course, I want to thank the witnesses for being here. And I do want to point out that I was abandoned by Miss Batty, who normally sits here next to me. Today, she decided not to. And I think that that should be pointed out. I feel hurt.
▶ 1:25:17But secondly, I do want to say this that I actually agree with half of what my good friend from Georgia said. I actually do think the government has way too much information. It absolutely does and it doesn't protect it well. And in fact, I'm a little worried today when you go through the airport now, they get all sorts of biometric information about you. I don't know how they use that either. I think we should be concerned about that and I don't think that the government does protect it. Well, I don't agree with the Elon Musk thing.
▶ 1:25:46I do think that in fact it was very dangerous to have him running around with these young kids doing things that we don't even know what the hell they were doing. I'm not sure that they knew either. All that being said, the CFPB has the job of making sure consumers are getting straight deals and making one of the ways it's done and one of the ways it's done is by making sure consumers are getting fair deal when it comes to control of their own data.
▶ 1:26:09When consumers aren't in control of their own data, financial institutions have to compete on their merits for the people's business and a more compet and more competition is better, I think, for everyone. That's what DoddFrank section 1033 is all about. While section 1033 goes back to the DoddFrank Act, the CFPB's finalized rule ensured consumers could be in control of their personal financial data and could be more easily transferred to it another provider.
▶ 1:26:37From the Graham Leech Blley Act dealing with financial information to the Fair Credit Reporting Act dealing with credit information, Congress has continued to adapt privacy protection laws to evolving economy. And we also have to make sure that we continue to adapt those protections. Security of data is the top of mind especially in the financial sector and especially in the era as I said earlier of Doge being given access to sensitive data information.
▶ 1:27:02I I was proud to join the letter this week led by the ranking member as he stated urging the CFPB not to vacate and throw out the years of progress we've made on finalizing section 1033 rule. So for Miss Strickland, when CFPB finalized the section 33 rule in October of 2014, former chairman Mckenry stated that the CFPB's final rule 1033 is a promising step forward to protect Americans financial data privacy.
▶ 1:27:33Consumers should know where their data is going, how it is used, and be able to determinate and to terminate collection of their data by certain firms. Director Chopra also listened to some of our concerns regarding unreasonable restrictions on secondary use of data. Why do you believe this there was a bipart there was bipartisan support for this rule at that time? I'm sorry. The question is there why why do you think we did come together and there was bipartisan support there?
▶ 1:28:02I think there was and you saw that from the comment letters as well that it ranged across all the industry sectors as well as the consumer groups and again delving very deeply into every aspect of the rule. I do think a contributing factor was with all the great work that was done to get to the proposed rule and there was enormous amount of work done including the small business review panels and again digging deeply into how do the parties work together? What are the right obligations? What are the right privacy practices, right practices? What products are we covering? How do we think about small entities?
▶ 1:28:32A lot of work went into all those aspects. I do think in the final rule there were a few items that were not addressed um ideally and that um create for example. So I I in in again in the written testimony I go through several of them. In my view the the the main ones were um and you mentioned them. One is the secondary uses of information. They didn't allow those even consumers to agree to them. And that's what open banking is all about.
▶ 1:29:01So it made for a very awkward sort of consumer experience. Um it also didn't really allow the use of deidentified data which is a common practice not only in the financial sector but in every sector and it's a great privacy and security practice too because you've made it nonidentifiable and controlled reidentification. It didn't thoroughly look at the questions raised about increased fraud or liability. Um and there was some information given about what that could look like.
▶ 1:29:29So, could there be better monitoring done, some shifts um uh looked at in terms of liability? Okay. So, I do want to stop you there because I I again I I think that there are some things that we we could do a better job at, but I have to say this. It's interesting because this issue came up in California many many many years ago back in 2001 when I was the chairman of the insurance committee. And at that time, we would have had screaming matches here, but we don't have that anymore because I think we've come a long way. And I do want to praise everyone that's worked on this issue. Thank you.
▶ 1:29:59Thank you, Mr. Chair. The gentleman yields back. The gentleman from Tennessee, Mr. Rose, is recognized. Thank you, Chairman Bar, and and also thank you uh ranking member Foster for holding this important hearing, and thank you to our witnesses for your time today and being part of this uh hearing. Mr. Talbot, in your testimony, you highlight that two dozen states have enacted different data privacy laws.
▶ 1:30:23Can you discuss the challenges that members of the Electronic Transactions Association face when it comes to navigating such a large number of potentially inconsistent state laws? Sure. Thank you for the question. So, the biggest one is what data is covered. Uh, many states provide either entity provide an entity level exemption, meaning that the bank or the credit union is exempt from that state's privacy law because they're covered under GBA.
▶ 1:30:48Some states only have a data level exemption which means the entity is covered but certain data GBA data is not covered by that state's privacy law but the state's privacy law definition if what's covered is broader and so at that point in most particular California is is the lead example Oregon is similar as well so B2B data is exempt under GBA but is not exempt under California law and so any entity that may be GBA compliant still has to map
▶ 1:31:18out all of its data and all the uses for the business side to ensure that is in compliance with the California state law, the California state privacy laws. So there there's a perfect example of how different states with different definitions can create issues. So that creates a lot of problems, challenges. Sure.
▶ 1:31:36And and can you can you I mean maybe beyond what you just gave as an example, are there examples where that you can provide where state data privacy laws are in conflict at such a level that it's impossible to comply uh with with those inconsistencies. Yeah, I don't know if I would say impossible necessarily, but definitely creates some conflicts.
▶ 1:31:58I've got a list in my u in my written testimony and the biggest example is with California uh where I just talked about where B2B is covered under the California privacy law but it is not covered at the federal law. So that's that's the biggest challenge. Others relate to uh timing the nature of the disclosures what data can be excluded or not what opt- out rights the consumer has.
▶ 1:32:22Maryland has a very has a very stringent opt out and what can and cannot be covered or cannot be shared. But those are just some examples where the challenge. So not really I don't think I'm hearing of examples where you you what you do in one state would actually be a violation if you did it in another state. Is that is that correct fair to say? Okay, that is fair. Yes, sir. It's more on the implementation side. I guess that's good news. Obviously, we need to avoid that. Mr.
▶ 1:32:48Morris, in your testimony, you touch on the fact that the credit unions uh like many financial institutions have long prioritized investments in data security to ensure that their members or customers privacy is protected. I think it would be helpful if you could expand on just how much credit unions have already invested in data security. Thank you for the question.
▶ 1:33:09Um, happy to share uh more statistical information perhaps after, but I can say that we've run surveys in the past and consistently year after year after year reflecting the the enormous cost of data breaches and the risk of fraud, credit unions are prioritizing investments in cyber security and data security.
▶ 1:33:29And those things are part of the Graham Lee Bllye Act which mandates that the National Credit Union Administration, other financial regulators, other other regulators of financial institutions implement technical safeguards to ensure that those institutions are adopting appropriate data security practices and that drives a lot of cost but is important for keeping trust. Very good. Mr. Talbot, back to you.
▶ 1:33:52Would you like to discuss the significant investments that the Electronic Transactions Association members have already made in data security? I I think the number would be in the billions. Uh we spend equal amounts on developing and deploying new products and services to make payments easier, faster, more secure. We also spend similar amounts to fight fraud, fight and detect fraud, to protect both consumers, merchants as well as the economy. So the number is easily in the billions of dollars.
▶ 1:34:19And in in light of some of the discussion we've had about uh the the role of employees of institutions in safeguarding data um and I might open this up but I'll start with you Mr. TA but any uh and we don't have much time but uh any criteria in any of the law as to the credentiing or qualifications of employees of organizations that are charged with protecting consumer data that you would like to speak to or take note of? Yes sir. Appreciate the question.
▶ 1:34:48So the the FTC safeguard rules as well as good business practice require companies to develop a robust system internally for security purposes and that includes addressing which which of their employees have access to it how to cut off that access passwords et all the usual security protocols that you would think would go into protecting uh data as well as payments. Thank you. My time is expired. I yield back and I would appreciate insight from the rest of the panel about that question of credentiing of employees that deal with consumer information. Thank you.
▶ 1:35:18Yield back, Mr. Chair. Gentleman yelled. Gentleman from Illinois, Mr. Casten, is recognized. Thank you, Mr. Chair. Um, so last year, the CFPB finalized their open banking rule um that would have given consumers greater access and control over their financial data. Um, uh, including making it easier for consumers to move their financial data from institutions. Miss Strickland, can you just talk about how that rule would would increase competition and make our markets more efficient?
▶ 1:35:48Yes. Um that actually and thank you for the question has been a key driver of open banking initiatives in the United States as well as in other jurisdictions which is how how do you make all the players compete for the consumer's business and both in terms of price but also in terms of product offerings and um really encouraging new technology and new business models to say hey I've got a brand new idea. How do I do this?
▶ 1:36:14but recognizing they're not always regulated the same way as banks are, which is is deep and thorough. So, open banking really does enable these different companies to work together and to put both a framework around how the data exchanges occur, but also as I mentioned put some rules on the data recipients who are not regulated in the same way.
▶ 1:36:35So the open banking rule created to the prior question on this rules around what you collect, what you can use it for, how long you can retain it, which are really important safe. So So to to that point, we had a couple years ago on this committee, we had a discussion with former director Chopra about how Facebook had no obligation to ensure that in hoovering up your data, they weren't essentially violating the Fair Lending Act by only promoting certain credit card products to one individual or another.
▶ 1:37:03Would would the open banking rule have have fixed some of those gaps so that third parties like Facebook, you know, are not using your data to target target you in ways that may be, you know, if not illegal, certainly Yeah, I think that's right. I mean, presently, uh, for large companies, if they're not regulated by a sectoral law, they're under general FTC jurisdiction, which is unfair and deceptive. So, their privacy policy is accurate. You know, they can they can proceed, as well as the state laws that exist.
▶ 1:37:30Um I do think an open banking benefit was to create um modern privacy rules for the recipients of this data which are very important because they're getting sensitive financial information and sometimes the ability to move money and so having that bar and those requirements on data recipients was was a real value to the rule.
▶ 1:37:49I must say, just as an aside, I'm I'm con consistently struggle with the fact that my, you know, extreme libertarian colleagues are petrified of the government getting your data, but seem to have no problem if a private company gets your data and monetizes it and refuses to let you see what they have. Um, and Rand is pissed is all I have to say about that. Um, you you mentioned the FTC.
▶ 1:38:11Now this matters of course because last week the Trump uh administration CFPB filed a motion to vacate that rulemaking which is going to open up this gap and a lot of these data privacy rules as you mentioned you know under Gram by CF CFPB has some jurisdiction the FTC has jurisdiction our banking regulators have jurisdiction um I guess I'd turn to you Miss given your past role at the FTC if if the CFPB can't fulfill their roles to protect data privacy and we're left with you know whoever remains in standing.
▶ 1:38:42What are the gaps that emerge in in our ability under current law to protect the people we represent and their data privacy? Well, one of the benefits that the Federal Trade Commission has is a broad rule related to unfair deceptive acts and practices. And there was some discussion about retailers getting data and what happens if there's a breach at a retailer.
▶ 1:39:03The FTC has brought a number of cases involving data security many many years ago just under its general section five authority where it has found a gap. So one of the benefits of the Federal Trade Commission's jurisdiction is it does have this sort of flexible oversight and ability to bring cases where it sees developing threats emerging. So I I guess the concern maybe I'll turn back to you Miss Strickland. In theory I agree with you.
▶ 1:39:30In practice, we have an entire industry saying, "I want complete absolution of any liability from any of my AI models." And in fact, all of our Republican colleagues just voted last week to pass a piece of legislation that says there shall be no liability for anybody using the AI models. So, I steal your data. I put it into the system. I violate the deceptive practices, but you're totally absolved because, well, I didn't do it. The the AI optimized an algorithm to solve this. And how was I to know? All I did was just didn't comply.
▶ 1:39:59didn't say that the eye would comply. So, I guess Miss Strickland, and we may not be enough time, but I'd welcome your thoughts on how we might regulate AI in this world where the CFPB broke, data privacy still matters. What should we be doing to close this barn door, especially in light of this big ugly bill that we passed out of the House last week, if the Senate goes along with that? The gentleman's time is expired. Uh the witnesses can answer for the record.
▶ 1:40:29The gentleman from South Carolina, Mr. Timmons, is now recognized. Thank you, Mr. Chairman, and thank you to the witnesses for joining us this morning. I often hear from constituent companies about the challenges posed by the complex state-by-state patchwork of data privacy laws, which makes compliance across jurisdictions burdensome and undermines consistent consumer protection. Many states vary restrictions and laws based on the size of the company.
▶ 1:40:54This is understandable until you realize that many states have vastly different thresholds based on the institution's income and handling of consumer data. This issue is compounded by the fact that the Graham Lee Blighty Act serves only as a federal floor for consumer financial data privacy, allowing states to impose more or less stringent requirements. For instance, California mandates opt-in consent for sharing consumer data with non-affiliated third parties going beyond the GBA's opt- out standard.
▶ 1:41:21While other states such as Alabama align more con more more closely with the federal baseline and impose fewer additional obligations. This uneven regulatory landscape complicates compliance efforts and creates uncertainty for institutions operating nationwide. Miss Keane, what challenges do California's law and similar state regulations create for consumer access to financial services within those states and how do they affect financial institutions seeking to enter or operate in those markets?
▶ 1:41:49the the form of preeemption that GBA has, which is to basically keep states from going below the standards, um does allow states to set different standards above that. To date, until these more recent privacy laws, states have not really ventured into that very far.
▶ 1:42:07The problem is is that as the states are looking at these privacy issues and they want to set different or varying standards, that's going to make compliance very difficult, particularly for financial institutions who operate throughout the United States. So, I'm going to have to have an investment in statebystate rules and compliance and controls that's going to take away from my ability to provide other products and services for to consumers.
▶ 1:42:32So the patchwork is a ve of a great concern and if this committee were to reook at GBA I think revisiting the form of preeemption that exists in law would be very important in order to perform you know preserve the sort of uniform approach that financial institutions take across the country. Is it fair to say that larger financial institutions comply with these this the patchwork framework more easily than smaller? They have more money to invest in compliance.
▶ 1:42:59I mean, let's face it, the smaller guys, particularly in the competition area, have a tougher time because they have to build the kind of processes and services and have the personnel to deal with consumer inquiries, for example, you name it. It's a it's a big investment for the clients that I work on. It's often a hardship and it really uh stifles entrepreneurship because startups are unable to comply and it really creates a ma major problem. We need to address it. U Mr. Mr.
▶ 1:43:24Talbot, um, what problems do these regulations create for innovative institutions trying to deliver a seamless experience to consumers, especially when offering products and services that those consumers have actively requested? Yeah, thank you for the question. So, we will deliver the products and services um as the market demands, but the challenge will be in the compliance with the various state state laws. So you've got disclosures, you've got opt-ins, you've got opt outs.
▶ 1:43:50All of those will slow down the process for getting customers onboarded in the first instance. Uh but once they're onboarded, once that has been addressed, then the products will be delivered quickly, accurately, and seamlessly. But the challenge will be in the compliance side of it dealing. Thank you for that. And how do these frictions hinder new market participants such as FinTech to compete with larger, more established institutions? Yeah, they too must comply uh with the privacy and data security rules and there's cost, time, expense associated with compliance.
▶ 1:44:20In addition, they have to navigate all the different states depending on what states they operate in as well as GBA depending on where the the state exemption is. So that creates enormous amounts of complexity challenge compliance costs. As we consider how to address this problem, I I think the the general perspective is that Europe has gone uh too far and they have really restricted competitiveness. What would your recommendation be?
▶ 1:44:47Obviously, California has a standard and the European standard is the most um developed. How how do we thread this needle to accomplish the objective without uh being overly burdensome? So, so two points, GDPR is the European version. They actually have a good definition of that many states borrow from. So that's positive. But they also allow for a private right of action which creates on the back end a number of legal issues and challenges and complexities.
▶ 1:45:13Additionally, the number of these private rights of actions can distort or change or slowly case by case modify the law which creates more challenges in terms of compliance versus having enforcement at the federal regulatory system. So thank you for that. It's past time for Congress to act and we need to preempt state law and create one standard so we can compete in the global economy. With that, I yield back. Thank you. Gentleman yields. The gentleoman from Ohio, Miss Batty is recognized. Thank you, Mr.
▶ 1:45:43Chairman, and ranking member Miss Strickland. I'll start with you where ranking member uh Foster ran out of uh time and so I'll I'll pick it up there. He was making the point that uh one of the points outlined by the bureau is that section 1033 only allows CFPB to write rule granting um consumers access to their financial data and it doesn't allow for sharing that data with with third parties.
▶ 1:46:14Um, wouldn't consumers be h harmed most if they do not have the ability to share their financial information with third-party tools and products to help them manage their uh financial well-being. Could you elaborate on that? Yes, I'd be happy to. Yeah, I I do think if consumers get access to their own information in a machine vertical format, that's great. That that's progress.
▶ 1:46:38But um the real benefit of open banking is their ability to direct the sharing and transporting of that data from the data provider to authorized third parties who are who have been adequately vetted to make sure they've got the right privacy and security practices. And if you don't enable that, I think it will frustrate consumers because what they're going to keep it on their computer and then they're going to send it data recipients and then they're going to update it. It it seems unworkable.
▶ 1:47:04Um, and I also think a downside to that, which might be an unintended consequence, which I touched on, is that then the third parties are no longer under an umbrella that requires them to have rules about what they can and can't do with that data once they receive it. They are not vendors of the data provider. So, what is it that they can and can't do with that data? And the 1033 rule did put restrictions on what they can use it for, which is the purpose of the transaction, right?
▶ 1:47:29And so it did put some rules around a them being vetted and b that they actually had some requirements of their own when they received this data. So both of those aspects of the portability piece of this were very important. Okay. Thank you so much for that. U Mr. Morris, let me go to you and first let me thank you for your work with America's credit unions.
▶ 1:47:52As you may be aware, I have a bill, the advancing of the mentor protege program for small financial institutions act, which is actually noticed in today's hearing, and it would cautify the treasuries department's financial agent men's protege program to encourage partnerships between large and small financial institutions, including credit unions.
▶ 1:48:18Codifying this program would help small and community financial institutions across the country increase their capacity uh improve their relationship lending businesses model and and even become a financial agent to treasury. Can you briefly discuss how this bill will help credit unions better serve their communities? Because I also look at it when we talk about open banking and technology.
▶ 1:48:46it's supposed to be new ways also to bring uh institutions together. So I'd like to hear your comments on that. Thank you for the question. I think the mentor protege bill is one that aligns well with the cooperative nature of the credit union industry and we are certainly supportive of it and ways to enable MDI's small institutions to partner with their larger peers to learn best practices, learn how to comply with complex rules and regulations.
▶ 1:49:13And today we've spoken about the costs of complying with a rigorous data privacy regime and certainly a mentor protege uh arrangement can help facilitate learning um among smaller institutions. Thank you for that. And I have I think I have time for one more question since I'm down here on this row by myself that my uh colleague took great pleasure uh Mr. uh chair ranking member took great pleasure in telling me that he was going to pull rank on me and now I see why.
▶ 1:49:42So, let me address it also uh to Mr. Fields, our our ranking member. Thank you for letting me ask this last question. I'll come back to you uh Miss Strickland. Uh tell me your comments or or thoughts on in the times I have left uh what would happen if we abandon section 1033 uh means that all of the consumer would mean that all of the consumer protections imposed on thies would also rescended.
▶ 1:50:12Uh thank you for your question. Um as as other uh witnesses have mentioned, open banking does exist today and has been um a developing practice in the United States for a few years. So it would still continue. It just wouldn't have the same framework around it around well how does that data sharing work? What are the rules in terms of vetting these third parties? What are the obligations on the third parties? It does phase out screen scraping.
▶ 1:50:37Yes, perhaps it could have done it more directly, but it did phase it out and say, you know, once the compliant data sharing APIs are um employed, you can't screen or the screen scraping can be prohibited, which is, I think, very important for both the consumer's benefit as well as um website security. Time is up. The gentleoman from California, Miss Kim, is now recognized. Thank you, Chairman Bar, Ranking Member.
▶ 1:51:03Thank you for hosting this hearing and I want to thank our witnesses for joining us today too. As you know uh for too long our federal laws have not evolved to uh keep up with the issue of data privacy. As a result we have seen states take action because we have failed to lead at the federal level.
▶ 1:51:25In California, we have implemented legislation such as the California Financial Information Privacy Act and the California Consumer Privacy Act. While the intent of these bills has been good, the unfortunate result is that the financial institutions have dual compliance uh obligations at the state and federal levels.
▶ 1:51:49That coupled with patchwork state laws have made it both costly and very confusing for institutions as they have to uh comply in the jurisdictions in which they operate. So I want to ask my first question to you Mr. Telvet. Can you explain how in states like California which I'm sure you are very familiar with you know with the conflicting state privacy laws have created damaging doer Do I'm sorry I missed your last part.
▶ 1:52:18Yeah, the the damaging how these conflicting state privacy laws have created damaging dual compliance. Thank you for the question and thank you for your leadership with the financial literacy and wealth creation caucus. You as well as Miss Batty. U so the challenge is in terms of the cost of the compliance, the complexity because financial services institutions are um not exempt uh in California at the entity level only at the data level.
▶ 1:52:43any data that they use that's not GB compliant has to be mapped out and evaluated in terms to make sure they're compliance with the two California laws that you mentioned. So that is costly that is time consuming. Additionally, there are Can you talk about like the the regulatory costs? What are we what are the companies looking at when they have to develop these uh processes to meet those diversion uh state privacy laws? Sure. They have to sign personnel. They have to sign lawyers. they have to hire regulatory counsel.
▶ 1:53:12Outside council usually hired there's compliance experts that are brought in. So the whole team that has been developing the system for the financial institution at the federal level also has to spend time if not create a separate team focused on California. In addition, California changes their law frequently and currently there's a current proposal to amend it. Now all of those changes have to be discussed and analyzed and executed and that takes time and resources. Sure.
▶ 1:53:38You know, another issue I hear a lot about is the question of opt out versus opt in as it relates to data privacy. So, uh, Miss Ken, I want to ask you, um, in Graham Leech Bllye Act, you know, can you explain to us why there was an intentional decision to offer consumers the ability to opt out rather than opt in? Yes.
▶ 1:54:01So, Grammarly Blly provides a requirement that financial institutions have to clearly disclose to consumers um exactly what happens with their data and where they have choices about that data. And they do that at the start of the relationship. And if you're going to share data that's subject to an opt out, you have to tell the consumer every year, hey, I'm sharing your data. You can change your mind about it.
▶ 1:54:26Um, and the reason it did that was because there are a number of things that companies do to share data that consumers sort of expect. So I might not want to opt out of sh of my bank sharing my data for certain purposes, but I might want to opt out say for a car dealer using it. Um, and so you have those choice on an entity by entity level to do that.
▶ 1:54:48It also um you know the privacy notices I know people pick on them but they are the subject of a lot of research and development to make sure that consumers can clearly understand in plain language exactly what's happening with their data and what choices they have. Sure. You know I think consumers are rightfully concerned that they have limited understanding about how their financial data is being utilized. And that's why I think it's important that we also address the annual privacy notice that consumers receive.
▶ 1:55:19So, Miss Ken, can you talk about the the annual privacy notice that consumer receives and what kind of research does the uh the agency or agencies conduct to make notices more consumer friendly? Yeah. So, the FTC and the bank regulators worked on a worked on the current form of the privacy notice.
▶ 1:55:39I think one of the most recent innovations is the understanding that a consumers don't necessarily need to get a repeat annual notice if number one their financial institution isn't sharing it subject to an exception meaning that the purposes their financial institution is sharing data for are things like fraud prevention and to process their transactions. Can you quickly talk about when the last time it was when the annual policy model form that FTC posted was revisited or reformed?
▶ 1:56:10I was back when I was at the Federal Trade Commission which is about 15 years ago. Completely outdated. So I think that explains the reason why um Representative Kim the the the wage time is expired. Okay. Thank you. Thanks for answering that question. The gentleman from the great state of Louisiana, Representative Fields is recognized. Thank you, Mr. Chairman. And let me thank all the witnesses uh for being here and I thank you for this hearing. I I just have two two very simple questions.
▶ 1:56:37First question I want to uh I want to ask Miss uh Strickland. Uh lower income families often rely on uh free and lowcost third-party financial tools uh to plan their financial futures. Uh when big big banks uh restrict these twos by blocking data portability, who gets hurt? Uh and how does section 1033 uh address this rule in equity?
▶ 1:57:09Yeah, thank you for your question. Uh I do think um both predating 1033 and then under the 1033 rule the goal was to encourage consumer permission data sharing and doing it in a responsible fashion so that data providers didn't put up um unnecessary hurdles to that to that um data portability request.
▶ 1:57:30and the third party had rules as well in terms of privacy and cert security obligations because they had that information and not in the same regulated um field as as the banks do. So there were important steps made to think through those issues to make sure responsible data transfers and data portability occurred at the consumer's direction.
▶ 1:57:50And as I mentioned, one of the things that many many commenters remarked upon and is still unfinished business in the 1033 rule is how are you making sure that other parts of people's financial health are also included so that they can have that full picture of of their um financial wherewithal.
▶ 1:58:09And one of the comments dealt with things like if you have government benefits like EBT, there were a lot of comments there about how how do those how does that community also able to aggregate the information about themselves. And so these were these were items that were um considered to be like future rulemakings, but I think they're really important so that there really is that complete picture that people can have a full understanding of their financial situation are able to direct the use of products and services that benefit them and that it's done in a way
▶ 1:58:39that um treats the data providers, data recipients fairly and ethically so that the data transfers are well managed. So I do think it's an important step in terms of that ecosystem as well as future products that that should be um addressed. Thank you. Uh my next question is uh for Mr. Morris.
▶ 1:59:00Uh section 1033 uh ru um had broad support precisely because it promotes uh competition and empowers consumers. Credit unions compete on service, not uh market power.
▶ 1:59:18How does maintaining the current system where big banks can block data access harm credit unions competitive position in serving working Thank you for the question and I think in terms of competition 1033 can offer benefits to credit unions in the general sense that data portability is helpful for consumers to switch financial institutions.
▶ 1:59:43However, we do have concerns around the CFB specific implementation of section 1033, the cost of API development, the lack of a framework for allocating liability of third parties mishandled data, as well as concerns around the type of non-stutoily enumerated data elements that the CFB would want to see shared like sensitive payment information.
▶ 2:00:05So while we think that the statute is good in the sense that it provides a core principle of data portability, there's work to be done in our view on refining the final rule. Well, thank you, Mr. Chairman. I yield back. Gentleman yields back. The gentleman from Wisconsin, Representative Fitzgerald, is recognized. Thank you, Chairman. Uh, Mr. Morris, excuse me.
▶ 2:00:29From your perspective, how have overlapping or inconsistent enforcement approaches impacted your member credit unions ability to innovate and and serve their customers efficiently? And what role should Congress play in ensuring federal regulators do not stifle credit unionled innovation that's already subject to many different state level scrutinies? Thank you for the question.
▶ 2:00:56I think there are areas of inconsistency in terms of the patchwork of state privacy laws just in terms of how different types of data is handled. Whether you're opt in, whether you're opt out, um whether there is specific regulation targeting a technology like artificial intelligence. Um certainly those are areas where credit unions can leverage technology to innovate, provide better fraud detection and prevention for example.
▶ 2:01:21On the federal regulator side, I think some of the inconsistency can arise simply due to the fact that these technologies are evolving at a very quick pace and it may be beneficial for there to be pilot programs um or other ways to test innovative products without necessarily the fear of compliance driving those innovation decisions. As a former um state senator, a lot of the work we did at the state level uh I now have a different perspective of.
▶ 2:01:50So financial institutions like credit unions are they're they're always subject to robust federal privacy requirements including the regular oversight and enforcement of the by the regulators. But there's a growing concern adding a federal uh private right of action would trigger a wave of abuse of class action lawsuits. Right. Um and we've seen this in Illinois. We saw it in California with CCPA.
▶ 2:02:16So these suits obviously often result in huge settlements uh with minimal benefit uh consumers and kind of leave the um small and midsize institution exposed to sue to settle. So how would how would introducing a private federal uh private right of action for data privacy violations affect credit unions ability to just serve their members? I guess thank you.
▶ 2:02:44I I think it would absolutely have a detrimental effect to include a private right of action in any comprehensive federal privacy framework. Certainly when you talk about the individual private rights of action that might arise across however many states that does have an impact across the board. Um it influences decisions again around innovation, but it can also just add to litigation cost and litigation risk. And those settlements can add up and detract from the core mission of credit unions, which is serving their communities with affordable products. um and services.
▶ 2:03:15So to the extent that litigation drives compliance costs or litigation costs up, that's money that's coming out of the community. So while state privacy laws wholly exempt banks and other institutions subject to federal Graham Leech Blly Act law, um there are some others such as California Consumer Privacy Act, which I just mentioned and a successor of uh the California Privacy Act.
▶ 2:03:42Uh this obviously means that financial institutions will still implement programs to comply with the laws even though it only applies to just a limited kind of subset I guess you'd say of their data. Uh Miss Keane, what's a level of effort for these compliance Well, and I believe Mr. Talbot testified to this as well. Um you have to sort of map all of the data um that you have. You have to have personnel involved with that.
▶ 2:04:11you have to have um often bringing out thirdparty technology companies to help you assess and to figure out which data is covered, which data is not. And so there's a compliance investment um for financial companies that operate in California that may not exist elsewhere um that have uh an entity specific exemption for example.
▶ 2:04:30Yeah, chairman, I'll just say that um it's these kinds of legal burdens that drive financial institutions like the credit unions and the banks uh to kind of pursue the mergers in order to better absorb the compliance costs. So, with that, I'll yield back. The gentleman yields. The gentleman from Texas, Representative Green, is recognized. Thank you, Mr. Chairman. I thank the ranking member and the witnesses for appearing today. Mr. Mr.
▶ 2:04:57Chairman, I'd also like to thank the chairman, Mr. Bar, for honoring his commitment to bring HR 3716 as it is today uh to the attention of the Congress. Again, this was done at a previous hearing. So, Mr. Bar, if you're somewhere within the sound of my voice or any place where you might find out, I'm grateful. I'm also grateful to the staff for helping us with this legislation.
▶ 2:05:28Many times when we say I, I is properly defined as we, the personal pronoun is ver rarely efficacious when it comes to passing legislation. This legislation um HR 3716 deals with something that I hold dear and it is a belief that the public has a right to know but Congress needs to know. This legislation satiates both of these concerns.
▶ 2:05:56Uh I introduced this legislation, remember I as we uh the systemic risk authority transparency act on June 4th, 2025 and uh it was first introduced um on June 14, 2023 in the 118th Congress.
▶ 2:06:15The legislation was developed following the failures of Silicon Valley Bank and Signature Bank in 2023 when the FDIC invoked the systemic risk exception to guarantee uninsured deposits at those banks.
▶ 2:06:32Key provisions of this piece of legislation would include uh within 60 days of such an invocation of a systemic risk exception, the Government Accountability Office will be required to produce a prelim preliminary postfailure report within 90 days.
▶ 2:06:53the appropriate bank regulator including the FDIC, the OC and the Fed or the Fed will be required to issue a preliminary postfailure report and then within 180 days the GAO and the bank regulators will be required to issue a comprehensive postfailure report.
▶ 2:07:17This timeline provides an opportunity for us to get some initial evidence of what happened to get a better understanding and then get a comprehensive report. more appropriately said, "These reports will provide Congress and the public an analysis to identify the causes of the bank failures, including any management, supervisory, or regulatory shortcomings.
▶ 2:07:47The committee passed similar legislation by a 50 to zero vote last year. Again, I see this as necessary legislation. Uh, Congress needs to know certain things and these are the things that the public has a right to know. Uh, when banks fail, I think people need to know why. And I think that they should know why without having to speculate.
▶ 2:08:16I have found in life that where you have few facts, you have much speculation. This will provide the facts so that we can avoid the speculation. In closing, members of the panel today, uh, this is a process that I used when I was a litigator. It's called vor dire or vier, depending on where you're from. We called it vorire in Texas. Um, and it requires you to tell the truth.
▶ 2:08:45This the truthtelling portion of a trial. So, this is a simple question for you. Given what I've shared with you about this legislation, given what you know about bank failures, given what you know about the public right to know what Congress needs to know, do you think this legislation would be helpful? If you think so, kindly extend a hand into the air. Was that question too complicated for you?
▶ 2:09:15Do you think the legislation would be If you'd have to take a closer look at it. Okay. Happy to get back to you. I I would ask all of you to take a closer look and give me your opinions. Would you do this for me, please? Yes. Okay, Miss Strickland. Certainly. Okay. Thank you. Uh, thank you, Mr. Chairman. I thank all of you for your participation today.
▶ 2:09:41And I know that this is without the uh lane that you normally negotiate and navigate and traverse, but uh I hope that you'll give it some thought and give me an answer. Thank you so much. I yield back. Gentleman yields. The gentleman from Ohio, Representative Davidson, recognized. Thank you, Chairman. I'm excited about this important hearing. Privacy is one of the most abused portions of the Bill of Rights.
▶ 2:10:08I mean, we've seen uh technology radically change what's possible since Graham Leech Blly became law. So, it's timely, relevant, probably a little past due that we update GBA. I mean, frankly, not long after GBA laid a great foundation, the Patriot Act passed and massively expanded what the government was doing and frankly what the government was directing other people to do on its behalf.
▶ 2:10:34technology has uh has grown rapidly over this 25 years, but especially fast since the innovation of artificial intelligence. And so um I hope that we can kind of get the horse before the cart and not the other way around. Privacy is really foundational.
▶ 2:10:55Before we can really get a correct framework for for artificial intelligence, we really need to look at what is happening to the underlying data is we have artificial intelligence laid out there, it only functions by having the access to the data.
▶ 2:11:11And so if if that data in the private hands isn't cared for uh in the proper way, you're going to see it exponentially exploited um by the technology that artificial intelligence um is ma is making possible. So I I hope we get this right in short order. Um, Miss your testimony highlights that GOBA's broad definitions of financial institutions in non-public personal information cover a wide range of entities and data.
▶ 2:11:42Given the evolving financial landscape, including the rise of fintex, data aggregators, whatnot, how would you recommend updating GBA's definitions? Well, at this time, in my experience, it's pretty much covered anyone I've looked at in the financial sphere. Um it's a large flexible definition and it also covers not only the entities who are financial institutions themselves but also entities that receive information under the gram blightly.
▶ 2:12:10So there are restrictions on their ability to reuse or redisclose the data they get. So uh it you know it's was surprisingly forward-looking in thinking about all the ways in which financial institutions and the ind financial industry are intertwined and covers a lot of those uses that exists already. A lot of times we do regulation here in Congress because we have committees of jurisdictions. So we don't really holistically solve problems.
▶ 2:12:36when you look at um GLBA, it kind of says that we've got one set of privacy laws for financial firms, but then if you, you know, run a website or, you know, put automation into cars that really does quite a lot of surveillance in your in your automobile, uh is it governed by a whole different set of laws? Does it make more sense to have a comprehensive privacy law that recognizes that individuals have a property right in their data versus a sectorbased approach?
▶ 2:13:04Does anyone have thoughts on Happy to real quickly uh appreciate the qu I think given the unique nature of financial services and the the fact that we have both your account numbers as well as your money and your information that it is unique versus other industries. But I think the rest of the marketplace could benefit from a uniform national standard. Thanks Mr. Morris. I would agree that a sectoral approach is appropriate for the financial sector just because we're already subject to so many laws and regulations.
▶ 2:13:35Um, I think to your point about other sectors maybe not having uh the same rules of the road, I think a comprehensive federal privacy framework should address that. Um, yeah, here's an example. Google paid a small for the scale of the size of the entity fine because they set up the Android operating system and they said that you could select do not track so your geoloccation in theory wouldn't be tracked. But then when they were caught tracking everyone's geo location, uh they said, "Oh, no.
▶ 2:14:04What we meant was you could select do not track. We we of course are going to track you." Uh that was pretty dishonest. I mean, that would be not just simple negligence, not really gross negligence. That was willful misconduct. They should have gotten in trouble for that. But right now, because the FTC or FCC would regulate a product like that, um, you know, they they put terms and conditions down in the fine print, the five point fonts with popups that hit you until you relentlessly click, okay, fine.
▶ 2:14:34I just want to get on with what I'm trying to do. And there's not really much accountability for it. You know, financial firms, I'd love to say, are totally different, but Wells Fargo didn't accidentally do what they did with consumer data and set up false accounts and everything. and they paid over $4 billion in fines, but no one was prosecuted. In other sectors, when you abuse uh the access to data or you commit fraud, people go to jail. I think we ought to consider much stronger privacy protections, and I hope we do.
▶ 2:15:04I yield back. Gentleman yields. The gentleman from Nebraska, Representative Flood, is recognized. Thank you, Mr. Chairman. The topic of today's hearing is extremely important. Data sharing is at the center of financial interactions and transactions. In many cases, a consumer's data has to be shared between many parties in order to even fulfill a transaction. Let's use the example of a consumer applying for a mortgage to demonstrate the point. The consumer initially applies for their mortgage with their lender.
▶ 2:15:32They need to provide documentation verifying their income, their assets, their liabilities, their employment, among other things, in order for that application to be complete. At that point, the lender uses those pieces of information from the consumer's application to determine whether or not to approve the mortgage. They have to go to the credit bureaus to get the consumer's credit report. The consumer's credit score needs to be pulled involving the credit scoring companies. They may go to another bank to verify information regarding the borrower's assets.
▶ 2:16:01They may go directly to the consumer's employer to verify their employment. Then an underwriting decision needs to be made. Sometimes a lender will work with an outside underwriter who would also need to access all of the same information that we discussed in order to even confirm their credit risk and compliance with local relevant loan programs. After all of those steps are complete and many more I didn't name for the sake of time, it's possible for the lender to make an informed decision on whether or not to approve the mortgage.
▶ 2:16:29Think about all the different third parties I just mentioned that were involved in completing just one act for the consumer filing a mortgage application. We live in a world today that is far more complex than it was 10, 20, 30 years ago. And we have relationships between financial institutions and third parties today that didn't exist when the Graham Leech BY was written. That in a nutshell is why we are having this conversation today.
▶ 2:16:54And when you layer on the fact that some states are now moving in competing directions as it relates to rules around sharing and protecting your consumer financial data, you have even more complexity to the underlying problem. Mr. Talbot, in your testimony, you mentioned some examples of conflicting state privacy laws. Can you please describe an example of conflicting state law on data privacy that you feel is uh really represents the broader problem that I just talked about? Yeah.
▶ 2:17:20So I think that California unfortunately again is probably the lead example where it has both private right of action which doesn't exist in any other state as well as it does not exempt GLB entities uh doesn't exempt the exempts doesn't exempt the entity exempts the data and so in California for example the B2B transactions are covered by that state's privacy law whereas the rest of the country it is not. So that could create that's a challenge right there for those of us Mr. Talba that are interested in open banking.
▶ 2:17:50How should we think about a federal financial data privacy law and how that could ensure that the consumer's information is both protected while also leaving the door open uh for them to choose to use tools that are offered by third parties. Yeah. So the entities engaged in open banking or consumerdirected banking are already covered by GBA and so the privacy protections and the data security protections are there.
▶ 2:18:13to the extent that an entity maybe a fourth party is not it should be given the fact that we'll have data access to the data so that's an important structure that's already in place hules stunn uh can you speak to some of the results of the private right of action connected to the Illinois biometric information privacy act as mentioned we've se in my written statement we've seen significant litigation against a variety of entities this includes small timekeeping entities this includes large social
▶ 2:18:43media companies like Meta and it also includes people that or entities that one might not traditionally think of with data like Six Flags Amusement Park. These this litigation hasn't only been when actual harm occurs. It's also been over statutory issues such as the exact method of the language of consent or or things like that that then become overly burdensome on launching new products. We've also seen products not be launched in Illinois because of a concern around compliance.
▶ 2:19:11And this of course um means that the residents of that state don't have the benefits of some of the better technologies that might improve security through the use of biometrics as well as fun things like Google's art selfie match a few years ago. You know, I'm a strong believer in states rights. I served in a legislature like our chairman here, both in the role of speaker, but this is the one area that I do think we need a national standard.
▶ 2:19:35Uh, I I truly believe that this only happens if Congress acts and we can let people do business. That's the reason I put that mortgage application example in there. Uh, I will go to bat for states rights whenever I can, but this is one of the few times uh that I think this is a very appropriate uh direction and I thank Chairman Bar for his leadership on this issue and would love to deal with this in the 119th Congress. Thank you and I yield back. Gentleman yields.
▶ 2:20:05Uh would like to thank all of our witnesses today for taking the time to be here and for your testimony on behalf of all the committee members. We do appreciate that. And without objection, all members will have five legislative days to submit additional written questions for the witnesses to the chair. The questions will be forwarded to the witnesses for their response. Witnesses, if you receive those, we would please ask that you respond no later than July 10th, 2025. There being no further business before the committee, the chair declares the hearing ajourned.