September 8, 2026
Below you will find several key developments in the financial services industry, including related developments in information privacy and data security, from the past week. We add an "Amicus Brief(ly)1" comment to each item, where we briefly (see what we did there?) note for friends (and again?) of CounselorLibrary the important takeaways from the developments outlined in the email. Our legal reporters - CARLAW, HouseLaw, InstallmentLaw, PrivacyLaw, and BizFinLaw - provide more comprehensive, real-time updates of federal and state laws, regulations, litigation, and other industry items of interest. For a personal guided tour and free trial of any of these legal reporters, please contact Michael Willer at 614-855-0505 or mwiller@counselorlibrary.com.
House Financial Services Committee Introduces CFPB Reform Legislation
On September 1, the U.S. House Committee on Financial Services introduced the Consumer Financial Protection Accountability and Reform Act of 2026 (H.R. 10184). In late July, the committee had requested public feedback on a discussion draft of the legislation to reform the structure and powers of the Consumer Financial Protection Bureau. According to the committee, the goals of the bill are to:
- restore accountability and transparency to the CFPB by bringing the CFPB into the regular congressional appropriations process, establishing a dedicated inspector general, and strengthening the transparency and rigor of its rulemaking process. The bill also requires periodic reviews of major rules to ensure their benefits justify their costs.
- provide clear statutory guardrails by clarifying the CFPB's authority, strengthening due process, and establishing more predictable standards for supervision and enforcement, and make clear that agency guidance is not legally binding.
- promote innovation and competition by reducing duplicative examinations and supervision and ensuring regulation does not hinder the innovation and competition that leads to more choices, better products, and greater access to credit for American consumers.
- establish a more predictable approach to federal oversight by clarifying the CFPB's currently vague statutory authorities, strengthening due process, and establishing more predictable standards for supervision and enforcement. The bill also aims to promote proportionate penalties, reward firms that self-report and remediate problems, and establish durable boundaries that provide consistency for consumers and financial institutions and firms.
| Amicus Brief(ly): As originally conceived, the CFPB was supposed to be independent and apolitical. But with over a decade of performance across four administrations and key court decisions impacting the agency's performance, it is clear that, notwithstanding the statutory structure of the CFPB, it is not immune from political influence. Proponents of change to the CFPB's structure point to its relative unaccountability, given (among other things) the funding and leadership structure. They argue that its performance under zealous leadership, which objectively went too far with its regulation-by-enforcement approach that saw edgy interpretations of longstanding statutes and rules, effectively created new compliance obligations with each new consent order. This bill attempts to resolve some legislators' concerns over the CFPB's perceived overreach by more clearly defining the agency's operating parameters around supervision and enforcement. The legislation is in its infancy, but if Congress can focus on it, the result could be a more even-keeled CFPB. |
|
Federal Agencies and FinCEN Clarify Confidentiality Requirements for Suspicious Activity Reports
On September 2, the Federal Reserve Board, the Federal Deposit Insurance Corporation, the National Credit Union Administration, the Office of the Comptroller of the Currency, and the Financial Crimes Enforcement Network issued a joint statement to clarify confidentiality requirements related to Suspicious Activity Reports, specifically when banks or credit unions communicate with their customers regarding potentially fraudulent or suspicious transactions, including check fraud, involving the customer's account or notify the customer of the bank's or credit union's intention to close the account for potentially fraudulent or suspicious activity. The joint statement notes that the Bank Secrecy Act "prohibits the disclosure of a SAR or information that would reveal the existence of a SAR, including to a customer or other person who is the subject of the SAR. ... However, under FinCEN's implementing regulation for SAR confidentiality, 'a SAR or any information that would reveal the existence of a SAR' does not include 'the underlying facts, transactions, and documents upon which a SAR is based.'" The agencies and FinCEN concluded that the "BSA and its implementing regulations do not prohibit banks or credit unions from communicating with a customer or other person who may be the subject of a SAR about potentially fraudulent or other suspicious transactions involving the customer's account or notifying the customer of the bank's or credit union's intention to close the account for potentially fraudulent or other suspicious activity, so long as that communication does not reveal the existence of a SAR."
The joint statement provides examples of communications with a bank or credit union customer that would not reveal the existence of a SAR:
- requesting customer due diligence-related information or documentation to understand the nature and purpose of customer relationships for the purpose of developing a customer risk profile;
- notifying a customer that a delay, limitation, or restriction on an account or service or closure of an account may be related to suspected fraud or other suspicious activity;
- notifying a customer that a deposit has been rejected because of suspected fraud or other suspicious activity, for example, in the context of altered or counterfeit checks;
- asking a customer about the purpose of a transaction or the source of funds;
- providing warnings or educational resources to a customer about fraud schemes or typologies, including circumstances where a customer may be defrauded or a customer may be participating, knowingly or unknowingly, in a fraud scheme;
- communicating policies or decisions related to account maintenance or services, such as declining a transaction or closing an account; or
- requesting information on the originator or beneficiary of a funds transfer.
| Amicus Brief(ly): In addressing the current administration's concerns about perceived "debanking" of certain customers or groups of customers ostensibly for safety and soundness reasons (i.e., reputational risk), the federal banking agencies may be hamstringing an otherwise-effective system for rooting out financial fraud and other illegal activity. How are banks and credit unions supposed to communicate with customers suspected of participating (whether knowingly or unknowingly) in financial fraud in the ways described in the statement without tipping their hands about the investigation? This joint statement seems optimistic, if not a little naïve. In some cases, the regulators will be helping unsuspecting customers avoid being victims of fraud, but, in other cases, the regulators will be helping bad actors by beating around the SAR bush closely enough to scare them off and allow them to cover their tracks without allowing the agencies' enforcement arms to do their important work. |
|
Seventh Circuit Concludes that TCPA's Reference to "Telephone Calls" in Private Right of Action Provision Does Not Include Text Messages
The U.S. Court of Appeals for the Seventh Circuit recently decided a case in which an individual received a series of unsolicited marketing text messages from a sleep testing provider, despite the fact that his cell phone number was registered on the National Do Not Call Registry and that he had replied "stop" to the provider's messages. In response, the individual filed a putative class action complaint alleging violations of the Telephone Consumer Protection Act and Florida law. The provider moved to dismiss the individual's TCPA claims, arguing that the statute's private right of action provision for privacy-related standards was limited to "telephone calls," to the exclusion of text messages. The trial court agreed with the provider, dismissed the individual's TCPA claims, and declined to exercise supplemental jurisdiction over his remaining state law claims.
On appeal, the Seventh Circuit affirmed the trial court's decision. The TCPA's private right of action provision for the law's privacy-related standards applies to recipients of "telephone calls." For many years, the Federal Communications Commission took the position that this reference included text messages, even though the first text message was not sent until one year after the TCPA was enacted. Courts hearing TCPA cases deferred to the FCC on this interpretation. Two recent U.S. Supreme Court decisions have directed federal courts to stop deferring to the FCC and to conduct an independent review of FCC interpretations. In this case, the appellate court found that the term "telephone call," when Congress originally used it in the TCPA in 1991, referred to attempts to communicate by sound. This finding led to the conclusion that text messages were not included. While some courts have held that the term "telephone call" refers to attempts to communicate by telephone, which would generally include text messages, the Seventh Circuit refused to take that approach.
| Amicus Brief(ly): The TCPA is the statutory interpretation gift that keeps on giving, as technology and evolution outpace Congress's and the FCC's ability to adjust. The Seventh Circuit casts very reasonable doubt about whether certain specific provisions of the TCPA extend beyond voice calls to text messages and decides that at least one subsection, which gives rise to a private right of action, does not apply to text messaging because text messages are not "telephone calls." The Seventh Circuit deconstructs the statute to correctly identify that Section 227(c)(5) specifically allows for a private right of action for unwanted "telephone calls" but differs from other parts of Section 227(c) that expansively apply to "telephone solicitations," the statutory definition of which specifically includes a "telephone call or message." The Seventh Circuit was absolutely right in its conclusion, even if Congress did not mean for the statute to work this way. Nevertheless, providers that want to avoid litigation in other jurisdictions where plaintiffs may want to test their preferred interpretation to see if they can get a different outcome should ensure that their policies and procedures are designed to read the statute liberally and avoid sending text messages to consumers whose numbers are on the DNC registry. |
|
California Privacy Protection Agency Cautions Data Brokers About Providing Incorrect Information in Data Broker Registry
On September 3, the California Privacy Protection Agency issued its first enforcement advisory of 2026, which advises data brokers that they must provide "true and correct" information in their annual registration with California's data broker registry. Doing so provides consumers with insight into the data collection and distribution practices of each data broker.
California's Delete Act requires businesses that operated as data brokers in the prior year to register with the CPPA each year and disclose certain information. The law requires data brokers to provide information about the data they collected and whether they shared data in the past year with certain categories of entities. According to the CPPA, "the Delete Act does not distinguish unintentional mistakes from intentional misrepresentation: both result in incorrect information." The advisory states that data brokers are liable for a $200 fine for each day the incorrect information appears in the registry.
| Amicus Brief(ly): As always, we appreciate clarity from state and federal regulators about their regulatory and enforcement priorities. In this case, the CPPA is relaying to industry that, in at least some cases, the agency has observed registered data brokers providing incorrect information about their data collection and sharing practices in their initial and renewal registrations. The guidance makes clear that the CPPA can impose the Delete Act's fines even for inadvertent misrepresentations, cautioning data brokers to use care when providing information in connection with their registrations. The guidance also includes four illustrations of common scenarios that data brokers face when submitting their registrations and how they should be preparing responses to the registration questions based on those scenarios. Whether providers agree with the guidance or not, it is useful to know how the CPPA is thinking about these things. |
|
1 For the unfamiliar, an “Amicus Brief” is a legal brief submitted by an amicus curiae (friend of the court) in a case where the person or organization (the “friend”) submitting the brief is not a party to the case, but is allowed by the court to file the brief to share information or expertise that bears on the issues in the case.