Those Other Laws Dino Tsibouris Attorney at Law [email protected] 2006 NCHELP FALL TRAINING...

44
Those Other Laws Dino Tsibouris Attorney at Law [email protected] 2006 NCHELP FALL TRAINING CONFERENCE

Transcript of Those Other Laws Dino Tsibouris Attorney at Law [email protected] 2006 NCHELP FALL TRAINING...

Page 1: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

Those Other LawsDino Tsibouris

Attorney at Law

[email protected]

2006 NCHELP FALL TRAINING CONFERENCE

Page 2: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

It’s all so regulated…• Licensing requirements to do business

• Limits to interest rates and loan fees

• Privacy and information security

2006 NCHELP FALL TRAINING CONFERENCE

Page 3: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

Licensing• National banks and thrifts don’t need a license

from the state

• Non-bank lenders and purchasers of loans may need a license to make or enforce a loan

2006 NCHELP FALL TRAINING CONFERENCE

Page 4: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

Licensing• A common test: Are you in the “business of

lending?”

– NJ includes companies that purchase loans from others

– OH includes the original lender only

– MN excludes loans under other state law

2006 NCHELP FALL TRAINING CONFERENCE

Page 5: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

Licensing• Physical location concerns

• Limits on assignment

• Specific rates of interest and permissible fees

2006 NCHELP FALL TRAINING CONFERENCE

Page 6: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

Loan Pricing• State license lender laws establish permitted

rates and fees

– Interest rates

– Late fees

– Loan origination fees of 1-2%

– Prepayment fees

– Refund of unearned charges

2006 NCHELP FALL TRAINING CONFERENCE

Page 7: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

Loan Pricing• National Bank Act (12 USC 85)

• A national bank located in a state may charge interest at the maximum rate permitted to any state-chartered or licensed lending institution by the law of that state

2006 NCHELP FALL TRAINING CONFERENCE

Page 8: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

Loan Pricing• National Bank Act (12 USC 85) “Interest"

includes any payment compensating a creditor for:

– An extension of credit

– Making available of a line of credit

– Any default or breach by a borrower

2006 NCHELP FALL TRAINING CONFERENCE

Page 9: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

Loan Pricing• National Bank Act 12 USC 85

• “Interest" includes, among other things:

– Numerical periodic rates

– Late fees

– Creditor-imposed NSF fees

2006 NCHELP FALL TRAINING CONFERENCE

Page 10: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

Loan Pricing• National Bank Act 12 USC 85

• “Interest" does not ordinarily include:

– Premiums/commissions for insurance guaranteeing repayment of any extension of credit

– Document preparation

– Fees incurred to obtain credit reports

2006 NCHELP FALL TRAINING CONFERENCE

Page 11: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

Loan Pricing – Tied to State Law• Ohio Revised Code 1109.20

– Interest/finance charges not exceeding APR of twenty-five per cent

– Also may charge, as interest, other fees and charges that are agreed upon by the bank and the borrower

2006 NCHELP FALL TRAINING CONFERENCE

Page 12: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

Loan Pricing – Tied to State Law• RC 1109.20 “Interest”

– Charges for late payments

– NSF fees

– Application, processing, origination fees

– Guarantee fees

– Prepayment fees

2006 NCHELP FALL TRAINING CONFERENCE

Page 13: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

Loan Pricing – Tied to State Law• RC 1109.20 “Interest”

• Any fees and charges shall not be included in the computation of the annual percentage rate or the rates of interest or finance charges for purposes of applying the twenty-five per cent limitation

2006 NCHELP FALL TRAINING CONFERENCE

Page 14: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

Loan Pricing – Tied to State Law• 12 CFR 7.4001  The term “interest” as used in

12 U.S.C. 85 includes … includes, among other things,…

• RC 1109.20 A bank may charge… as interest, other fees and charges that are agreed upon … including, but not limited to,…

• Many possibilities; uncertain outcomes 

2006 NCHELP FALL TRAINING CONFERENCE

Page 15: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

Important Considerations

• Make sure rates and fees are properly structured

–Within legal limits–Business case for each fee

• Challenges to the relationship between lenders those who buy their loans

2006 NCHELP FALL TRAINING CONFERENCE

Page 16: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

Privacy• GLB

• Contract management

• State privacy law

• FTC

• Breach notification

2006 NCHELP FALL TRAINING CONFERENCE

Page 17: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

Privacy – GLB Permitted Sharing• Third party with notice and opt-out• Permitted disclosure without consent

–Service providers (notice, contract)

–Joint marketing agreements (contract)

• Express consent from consumer

2006 NCHELP FALL TRAINING CONFERENCE

Page 18: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

Privacy – Consent• GLB: “Clear and Conspicuous”

– Reasonably understandable and designed to call attention to the nature and significance of the information contained

– May combine with other clear and conspicuous notices

• FCRA: “Clear and Conspicuous”– Small type on back of mailer in a paragraph of

type about other matters inadequate (Use different type, color - Cole v. U.S. Capital)

2006 NCHELP FALL TRAINING CONFERENCE

Page 19: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

Privacy – Scope of Consent I authorize the release of information pertinent to my

loans: (i) by the school, the lender, and the guarantor, or their agents, to the references on the applicable loans and to members of my immediate family unless I submit written directions otherwise; and, (ii) by and among my schools, lenders, guarantors, the Department of Education, and their agents.

Source: FFELP MPN

2006 NCHELP FALL TRAINING CONFERENCE

Page 20: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

Privacy – Scope of Consent• Agent:

A person authorized to act for and under the direction of another person when dealing with third parties. Can enter into binding agreements on the principal's behalf and may even create liability for the principal if the agent causes harm while carrying out his or her duties.

Source: www.nolo.com

2006 NCHELP FALL TRAINING CONFERENCE

Page 21: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

Security• 88,348,579+ persons had their PFI improperly

accessed/stolen between February 15, 2005 and June 16, 2006 (Privacy Rights Clearinghouse)

• A consumer calling the FTC helpline reported that in one day thieves used her stolen PFI to open 9 credit card accounts and charged $15,000

Page 22: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

Technical Security• Hackers

• Unprotected Wireless Access

• Compromised Passwords

• Unencrypted Data Storage and/or Transmissions

Page 23: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

Physical Security• CDs/Files Lost/Stolen During Transport

• Files Lost/Stolen from Storage

• Improper Destruction of Files

• Lost/Stolen Laptops

Page 24: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

Humans, Contractors, and Vendors

• Dishonest Persons

• Failure to Follow Corporate Security Regulations

• Mistakes/Errors

Page 25: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

Privacy – Contract Management• Privacy Agreements

– Limits on use

– Audit rights

– Notice if breached

– Indemnity for claims and losses

– No limit on liability

2006 NCHELP FALL TRAINING CONFERENCE

Page 26: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

If a Breach Occurs• Key steps

– Identify the information lost

– Identify “affected persons”

– Notify law enforcement

– Prepare customer and media response plan

– Notify affected persons

2006 NCHELP FALL TRAINING CONFERENCE

Page 27: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

State Laws• Consumer protection and deceptive trade

statutes

• State AGs offices are pursuing loss or breach of consumer personal information through traditional consumer protection and deceptive trade practices statutes

Page 28: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

Federal Laws• Federal Trade Commission Act (FTC

Act) prohibits “unfair or deceptive acts or practices.”

• Gramm Leach Bliley Act governs the collection and disclosure of NPI (Privacy Rule); requires design, application, and maintenance of safeguards to protect NPI (Safeguards Rule)

Page 29: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

DSW, Inc.

Both state and federal cases were filed against DSW, Inc.

– DSW is based in Ohio and sells shoes in 206 stores nationwide

– Ohio Attorney General filed suit under Ohio Consumer Sales Practices Act

– Federal Trade Commission filed suit under FTC Act

Page 30: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

DSW, Inc.• DSW retained consumers’ names, credit/debit

card numbers, checking account information and drivers’ license numbers

• March 8, 2005 DSW learns that the data it retained from some 1.4M sales transactions was removed from its custody

Page 31: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

State of Ohio v. DSW, Inc.• Attorney General suit claimed DSW’s failure to

notify all affected consumers was “unfair or deceptive” act under Ohio’s Consumer Sales Practices Act

• Asked court to order DSW to send written notice to all affected consumers

Page 32: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

State of Ohio v. DSW, Inc.• DSW: Difficult to contact all customers

because it did not keep detailed information on all customers' addresses

• DSW SEC filing: Set aside $6.5 million to handle claims from the case and indicated total exposure could reach $9.5 million

Page 33: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

In re DSW, Inc.

FTC: DSW violated FTC Act when it “failed to provide reasonable and appropriate security for personal information collected at its stores”

Page 34: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

In re DSW, Inc.• Alleged violations:

– Storing data it didn’t need to keep – Not using available security measures to

limit wireless access to computer networks– Storing data in unencrypted files, accessed

via a well known user ID and password– Failing to employ sufficient measures to

detect unauthorized access

Page 35: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

In re DSW, Inc. Settlement DSW must establish a comprehensive information security program:

– Reasonably designed to protect the security, confidentiality, and integrity of personal information collected from or about consumers

– Fully documented in writing– Contain administrative, technical, and

physical safeguards appropriate to DSW’s size and complexity

Page 36: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

In re DSW, Inc. Settlement• “Security Program” Requires:

– Designated employee(s) to coordinate and be accountable for IS program

– Identify internal/external risks to NPI that could result in unauthorized disclosure or misuse

– Assessment of the sufficiency of any safeguards used to control risks

Page 37: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

In re DSW, Inc. Settlement• “Security Program” Requires:

– Regular testing of the key controls, systems, and procedures

– Evaluation and adjustment of the program based on results of testing, material changes to operations or business arrangements

Page 38: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

In re DSW, Inc. Settlement• “Security Program” Requires:

– Initial/biennial assessments and reports from independent third-party professional, using industry procedures and standards for a period of twenty (20) years

Page 39: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

Gramm Leach Bliley Act– Violations of the G-L-B Act’s Privacy

and Safeguards Rules are an “unfair or deceptive act or practice” in violation of the FTC Act

– Privacy Rule mainly concerns drafting and delivery of “Privacy Notices” to consumers

– Safeguards Rule mainly concerns security protection for NPI

Page 40: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

In re NATIONWIDE MTGE GRP, INC.

– FTC complaint alleged Nationwide and its owner collected NPI and failed to protect it

– Violation of Privacy Rule is an unfair and deceptive practice under the FTC Act

– Violation of Safeguards Rule is an unfair and deceptive practice under the FTC Act

Page 41: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

In re NATIONWIDE MTGE GRP, INC.

Security Rule settlement requirements:

– Assign employee(s) to oversee program; – Conduct a risk assessment; – Put safeguards in place to control the risks

identified and regularly test them; – Require service providers, by written

contract, to protect NPI; and – Periodically update its security program

Page 42: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

In re NATIONWIDE MTGE GRP, INC.

• Additional requirements:

– Nationwide must obtain an assessment on its safeguards from a qualified, independent third-party

– Must use industry procedures and standards

– biennially for ten (10) years

Page 43: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

Guin v. Brazos Higher Education Service Corp., Inc.

• NO duty under GLB to encrypt; Brazos acted with “reasonable care”

• Laptop containing unencrypted NPI stolen from employee’s home office

• Guin alleged Brazos’ failure to encrypt violated duty under GLB Act to protect security and confidentiality of NPI

Page 44: Those Other Laws Dino Tsibouris Attorney at Law dino@tsibouris.com 2006 NCHELP FALL TRAINING CONFERENCE.

2006 NCHELP FALL TRAINING CONFERENCE

Questions?

Dino Tsibouris

[email protected]