Last Week, This Morning

August 3, 2026

Below you will find several key developments in the financial services industry, including related developments in information privacy and data security, from the past week. We add an "Amicus Brief(ly)1" comment to each item, where we briefly (see what we did there?) note for friends (and again?) of CounselorLibrary the important takeaways from the developments outlined in the email. Our legal reporters - CARLAW, HouseLaw, InstallmentLaw, PrivacyLaw, and BizFinLaw - provide more comprehensive, real-time updates of federal and state laws, regulations, litigation, and other industry items of interest. For a personal guided tour and free trial of any of these legal reporters, please contact Michael Willer at 614-855-0505 or mwiller@counselorlibrary.com.

House Financial Services Committee Seeks Comment on Discussion Draft of CFPB Reform Legislation

On July 24, the U.S. House Committee on Financial Services requested feedback from the public on a discussion draft of legislation to reform the structure and powers of the Consumer Financial Protection Bureau. Comments and answers to specific questions posed by the committee must be submitted by August 21, 2026. The discussion draft consists of five titles:

  • Title I - "Reforming Bureau Governance" - reforms the CFPB's structure and governance. The title brings the CFPB under the congressional appropriations process, reforms the use of civil penalty funds, strengthens cost-benefit analysis and small business impact assessments for rulemakings, requires periodic retrospective reviews of major regulations, and establishes a dedicated CFPB Inspector General.
  • Title II - "Restoring Legal Clarity and Procedural Fairness" - provides greater legal certainty by clarifying key statutory authorities, particularly the CFPB's authority to regulate unfair, deceptive, or abusive acts or practices. Title II also adds procedural safeguards for enforcement actions, clarifies statutes of limitations, and addresses jurisdictional boundaries involving attorneys and state-regulated insurance companies.
  • Title III - "Promoting Innovation in Consumer Financial Markets" - supports innovation and consumer access to financial products and services. Title III provides clarity for certain small-dollar loan products offered by depository institutions and requires agencies to clearly distinguish non-binding guidance from legally enforceable requirements.
  • Title IV - "Promoting Effective, Predictable Supervision" - modifies the CFPB's supervisory framework by adjusting supervisory thresholds for banks and credit unions, allowing certain institutions to elect prudential regulator supervision and examination for consumer compliance, strengthening coordination among financial regulators, and tightening the CFPB's authority to supervise nonbanks.
  • Title V - "Preventing Regulation by Enforcement" - reduces reliance on the enforcement process as a means of establishing regulatory policy. Title V amends civil money penalties, market monitoring functions, and indexing of asset-based thresholds provisions and improves the CFPB's complaint procedures.
Amicus Brief(ly): The ping pong game using the CFPB as the ball may rage on for decades with a shot every four or eight years, as administrations turn over. There is a lot to like about the reforms Congress is contemplating. The CFPB has taken its mission to heart and has been a zealous consumer protection agency since it started, but general consensus says that, under certain leadership (including its original leader), the CFPB has had a tendency to go too far. If there is to be a CFPB, we can hope that Congress can look back at the agency's decade plus of activity and come to some agreement about what (objectively) has worked to prevent consumer harm and what (objectively) has not. If you think that sounds like a lot for this Congress, we agree. But the public has an opportunity for the next couple of weeks to provide some input on the effort. A few well-placed comments in support of sensible reform focused on transparency and consistency from the CFPB could resonate and lead to a productive result. We will see.

State AGs Raise Concerns Over Granting National Banking Charters to Nontraditional Entities

A coalition of 20 state attorneys general recently sent a letter to the Office of the Comptroller of the Currency, the Federal Reserve Board, and the Federal Deposit Insurance Corporation to express their concerns over the granting of national banking charters to nontraditional entities, including financial technology companies and online lenders. The AGs specifically argue that allowing such entities into the federal banking system permits them to circumvent state usury limits and other state consumer protections, contending that state interest rate limits are "the most effective way to protect consumers from unfair, abusive, and unaffordable loans in the absence of a national interest rate cap." The AGs also argue that granting national banking charters to nontraditional entities incentivizes predatory lending, claiming that "[t]hese kinds of lenders specifically target the financially vulnerable and further trap them in cycles of debt. They market high-interest products to borrowers with damaged credit. Loans are extended despite borrowers' ability to repay, and as a result, borrowers frequently refinance and default." The AGs further argue that granting national banking charters to nontraditional entities endangers the safety and soundness of the U.S. banking system, arguing, in part, that loans issued by those entities have high default and charge-off rates that result in losses that would make it difficult for such a lender to operate in a safe and sound manner under the federal banking rules. Finally, according to the AGs, "[t]raditional banks with community reinvestment programs, robust compliance infrastructures, and comprehensive consumer protections may also face a competitive disadvantage when compared to companies operating under an alternative charter while enjoying comparable market credibility."

The AGs conclude: "Given the implications of these new charter applications for consumers and the broader economy, we ask that you allow ample opportunity for public comment and hold public hearings before making a decision about whether to approve their entry into the banking system. Further, we strongly urge you to deny bank charters, bank holding company applications, bank mergers and acquisitions, deposit insurance, or other banking privileges for companies that make high-cost loans that evade state usury laws or operate with amplified risks to the financial system and endanger consumers."

Amicus Brief(ly): We know from the past few months that it's not just the AGs who take issue with the idea of issuing bank charters to fintech companies and other nontraditional applicants. Regulated banks and credit unions have shared similar concerns with the regulators over the idea that new, nontraditional banks with a singular focus on extending credit (beyond the requisite deposit taking of a bank or credit union business) may not be subject to the same level of oversight as other banks and credit unions because they will not engage in more robust banking work (like community investment), giving them a competitive advantage. Consumer advocates suggest that such companies are just looking for bank charters so they can avoid some level of state regulation - not the best argument, though, because states have plenty of consumer protection laws that apply to banks. The regulatory process will sort this out, and companies seeking bank charters that can make a credible case for running a bank in a manner consistent with the prevailing safety and soundness rules are likely going to get them, even over objections.

New York Issues Final Rules under State's SAFE for Kids Act

On July 28, New York Attorney General Letitia James released final rules implementing the Stop Addictive Feeds Exploitation for Kids Act ("SAFE for Kids Act"), which was enacted on June 20, 2024. The SAFE for Kids Act requires covered operators to restrict algorithmically personalized feeds and notifications from 12 a.m. to 6 a.m. Eastern for users in New York under the age of 18 unless they obtain parental consent. The new rules, effective January 25, 2027, establish criteria to determine which companies must comply with the law, require online platforms to conduct age assurance checks for users who are 18 years of age or older, and outline standards to determine users' age and obtain parental consent.

Applicability

The SAFE for Kids Act rules apply to non-exempt operators of "addictive online platforms," defined as online platforms that offer or provide addictive feeds and have monthly active users who spend at least 20% of their time on the platform's addictive feeds measured over a 6-month period in the prior calendar year.

Age Assurance

  • Covered operators must determine that the user is 18 years of age or older before allowing the user to access addictive feeds and/or nighttime notifications. Covered operators may confirm a user's age using any existing method that is shown to meet accuracy benchmarks and protect users' data. Covered operators must retain certain compliance records for at least five years.
  • Covered operators must offer at least one alternative method for age assurance besides submitting a government-provided ID.
  • Minor users must have an option to update their age status on the platform when they turn 18.
  • Covered operators must choose an age assurance method with a high accuracy rate, perform annual testing, and obtain annual certification. Covered operators must retain the test results, reports, and certifications for a minimum of 10 years.

Parental Consent

  • Minors who want to receive addictive feeds and/or nighttime notifications must consent to their parent being notified. Any parent who wants to grant consent must go through age assurance.
  • Covered operators may not disclose to parents any information that reveals a minor user's use of or activity associated with the platform to obtain parental consent.
  • Parents and minors must have the option to withdraw their consent at any time.

For companies that violate the SAFE for Kids Act and/or its regulations, the law authorizes the AG's office to bring an action to enjoin violations as well as to obtain damages and seek civil penalties of up to $5,000 per violation, among other remedies.

Amicus Brief(ly): This New York rulemaking continues a very busy season for New York State and City regulatory consumer protection work. The final rules implement a two-year-old statute the state passed to try to keep kids off their phones and tablets. Other states have gone down similar paths in attempts to protect minors from the impact of addictive social media sites, but their laws have faced First Amendment challenges in the courts. We anticipate the same for these well-intentioned New York rules, with privacy and First Amendment issues at the center of any such litigation. As of today, we are not aware of any pending lawsuits challenging this New York law, but that does not mean that one will not be filed before the January 25, 2027, effective date.

FTC, California, and Utah Sue Telehealth Provider over Billing, Subscription, Cancellation, and Privacy Practices

On July 29, the U.S. Federal Trade Commission, along with California and Utah, sued telehealth provider Hims & Hers Health, Inc., in federal court for allegedly deceiving consumers about its billing, subscription, and cancellation practices and for sharing consumers' sensitive health information with third-party advertising platforms without their consent.

With regard to the billing, subscription, and cancellation practices claims, the plaintiffs alleged that the company, which provides telehealth services and direct-to-consumer prescription medications, fails to clearly disclose that it charges consumers for prescriptions almost immediately after they submit an intake form, despite telling them that they will be able to consult with a healthcare provider free of charge to find an appropriate treatment. Consumers are asked to provide their billing information on the intake form but are informed that they will not be charged unless and until medications are prescribed. However, the plaintiffs alleged that the company does not give most consumers a medical consultation but instead charges them for and subscribes them to a prescription treatment without their review or approval, enrolls them in recurring subscription plans for those prescriptions, and makes it difficult for them to cancel before prescriptions are refilled. According to the complaint, "most consumers have already been charged for and enrolled in a subscription before they even learn what treatment the provider has recommended."

With regard to the privacy practices claims, the plaintiffs alleged that the company shared consumers' sensitive health information with third-party advertising platforms, despite promising to protect their privacy. According to the plaintiffs, the company shared lists of certain customers and shared consumers' health information and the actions of the consumers on the company's website via third-party tracking technologies.

Amicus Brief(ly): The FTC is compiling quite a caseload of claims involving practices like those alleged in its complaint against Hims & Hers Health. Armed with its unfair or deceptive acts or practices enforcement authority, the agency has telegraphed how seriously it takes concerns about billing practices, consent to and cancellation of services where consumers receive recurring bills, misleading and deceptive disclosures, and similar concerns typically raised in enforcement actions where the focus is marketing and billing practices. Filing this suit together with California and Utah reflects the FTC's consistent approach to cracking down on practices it finds unfair or deceptive. The case serves as another reminder to companies engaged in subscription services and price advertising to make sure they understand and avoid the types of practices that trouble the FTC and state attorneys general. Even if a company reaches an impasse with the government in an investigation focused on these practices, reviewing for and addressing concerns like those raised in this complaint in advance of the investigation will help with the defense, especially if (as the company alleges in its defense of this case) the government is reaching.

DOJ Settles Claims Against LHPH Dealership for Violating SCRA in Connection with Servicemembers' Vehicle Leases

On July 30, the U.S. Department of Justice announced that it settled claims with a "lease here, pay here" dealership, over allegations that it violated the federal Servicemembers Civil Relief Act over a 6-year period. According to the parties' settlement agreement, the DOJ alleged that the dealership, which has locations in Mississippi, Alabama, and Georgia, illegally repossessed three vehicles leased by SCRA-protected servicemembers without obtaining required court orders. In at least one of those cases, the dealership repossessed the servicemember's vehicle even after the servicemember provided a copy of military orders requiring deployment. The DOJ also alleged that the dealership failed to timely refund lease amounts paid in advance when servicemembers terminated five vehicle leases early after receiving qualifying military orders.

Under the settlement, the dealership will pay $77,348 in compensation to affected servicemembers, will pay a $60,000 civil penalty to the U.S. Treasury, will be required to make policy, procedure, and training changes to avoid committing future violations, and will incur additional reporting and recordkeeping requirements.

Amicus Brief(ly): The DOJ's Servicemembers and Veterans Initiative has been running strong for over 10 years, and the DOJ has been very consistent with its SCRA enforcement efforts. The initiative has not focused just on "big fish," as this case against an LHPH dealership reveals. Rather, the DOJ has pursued and settled cases against towing companies, finance companies, storage facilities, municipalities, and others. Unfortunately, it seems that the industry keeps making cases available for the DOJ to pursue. If the facts in this case are true, the dealership had copies of orders for three of the servicemembers whose vehicles it repossessed. Those unforced errors make for an easy case for the DOJ, which has demonstrated its willingness to run these cases down, whether big or small.


1 For the unfamiliar, an “Amicus Brief” is a legal brief submitted by an amicus curiae (friend of the court) in a case where the person or organization (the “friend”) submitting the brief is not a party to the case, but is allowed by the court to file the brief to share information or expertise that bears on the issues in the case.