Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Is the CFPB the New Cop on the Data Security Beat?

By Nate Taylor & Angela Kleine on March 3, 2016
Email this postTweet this postLike this postShare this post on LinkedIn

On March 2, 2016, the Consumer Financial Protection Bureau (“CFPB”) broke new ground (at least for the CFPB) when it released a consent order against Dwolla, Inc., an online payment platform, regarding data security. While in many respects the data security “message” sent by the CFPB is not a new one (e.g., companies must live up to their data security promises), the consent order is particularly noteworthy because it represents the CFPB’s first formal foray into the data security area, an area where there has been some question as to the scope of the CFPB’s authority. This consent order clearly indicates the CFPB’s belief that the Consumer Financial Protection Act provides the agency with the authority to police data security practices in the financial space, utilizing its unfair, deceptive or abusive acts or practices (“UDAAP”) authority.

Read our client alert.

  • Posted in:
    Banking, Finance and Securities, Privacy and Cybersecurity
  • Blog:
    MoFo ReEnforcement: The Enforcement Blog
  • Organization:
    Morrison & Foerster LLP

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo