Urgent.News

One page, thousands of outlets. See who else covered it.

Editions

Finance & Markets

Congress Considers Overhaul of Federal Financial Privacy Law, But There’s a Catch

Congress is considering a major rewrite of federal financial privacy law that could offer banks and other financial companies a consequential bargain: substantially stronger consumer rights over financial data in exchange for a single national privacy regime. The Guidelines for Use, Access, and Responsible Disclosure of Financial Data Act, or GUARD Financial Data Act, H.R. […] The post Congress…

Congress Considers Overhaul of Federal Financial Privacy Law, But There’s a Catch

Congress is contemplating a comprehensive revision of federal financial privacy law, which could potentially provide banks and other financial institutions with a significant advantage: enhanced consumer data rights balanced against a singular national privacy regime. This proposal is encapsulated in the Guidelines for Use, Access, and Responsible Disclosure of Financial Data Act (GUARD Financial Data Act), or H.R.

8398, introduced by Rep. Bill Huizenga (R-Mich.) and co-sponsored by Reps. French Hill (R-Ark.), Andy Barr (R-Ky.), and Bryan Steil (R-Wis.) in April. The legislation seeks to update the privacy guidelines under the Gramm-Leach-Bliley Act (GLBA), the 1999 law that currently governs federal financial data privacy.

The GUARD Act aims to evolve beyond GLBA's emphasis on disclosures and privacy notices to encompass regulations on financial institutions' data collection, utilization, and retention. The proposed law would compel institutions to restrict data collection to what is essential, pertinent, and indispensable for offering a product or service.

Consumers would receive more extensive information about data practices and rights to receive copies of their data, while former customers would be allowed to request deletion, subject to certain exceptions. The bill also proposes the requirement of affirmative consent for specific uses of sensitive information.

In exchange for these enhancements, financial institutions stand to gain broad federal preemption of state financial privacy requirements. The GUARD Act would establish GLBA Title V as the uniform national standard, incorporating both entity- and data-level preemption. Proponents argue that this approach would reduce compliance costs and eliminate the growing inconsistency arising from states adopting increasingly expansive privacy statutes.

This trade-off has already garnered industry backing, with the American Bankers Association (ABA) acknowledging that the GUARD Act and its companion SECURE Data Act contain several industry priorities and applauding lawmakers for striving to create consistent federal oversight while maintaining the GLBA framework for banks.

However, preemption could pose a significant hurdle, as noted in a Congressional Research Service report referenced by Legis1. The National Conference of State Legislatures (NCSL) has voiced opposition to the legislation's broad preemption provisions, contending that they could impede states from addressing emerging privacy risks.

For financial institutions, an additional challenge lies in the intersection of the GUARD Act with open banking. The bill outlines a statutory definition of "financial data aggregator," encompassing entities primarily engaged in accessing, aggregating, collecting, processing, or disclosing nonpublic personal information, which could conflict with the Consumer Financial Protection Bureau's (CFPB) Section 1033 framework, designed to enable consumers to authorize third parties to access financial account information.

Financial institutions may thus confront two policy objectives simultaneously: facilitating the portability of financial data at consumers' discretion while restricting unnecessary collection, use, and retention of the same information. This tension is expected to intensify as the CFPB revises its open-banking regulations. Moreover, the implications extend to artificial intelligence, as banks and fintechs are increasingly leveraging large datasets for various purposes, including fraud detection, underwriting, personalization, risk management, and AI systems.

A statutory mandate that data collection be necessary for providing products or services could compel firms to reassess the permissibility of secondary uses of customer information, such as model development and AI analytics. Financial institutions should closely monitor the legislation's final definitions of permissible data collection and sensitive information, its treatment of aggregators and third parties, and any reconciliation with Section 1033 requirements.

They should also examine the potential impact of stronger federal privacy obligations on compliance burdens when stacked upon state requirements, and the economic differences that could arise if these obligations replace state regulations nationwide. Ultimately, the GUARD Act reflects the evolution of financial services since the inception of GLBA, as institutions are currently endeavoring to govern data collection, utilization, and analysis under a unified framework while contemplating whether bolstered consumer control over financial data is a sacrifice the industry is prepared to accept for a unified set of rules.

Written by urgent.news from PYMNTS's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at pymnts.com →

More in Finance & Markets

More from Tuesday 18 August →