Scarinci Hollenbeck, LLC, LLCScarinci Hollenbeck, LLC, LLC

Firm Insights

CFPB Makes Example of Dwolla Inc. in Monmouth County

Author: Scarinci Hollenbeck, LLC

Date: April 8, 2016

Key Contacts

Back

CFPB Makes Example of Dwolla Inc. in Monmouth County

CFPB Makes Example of Dwolla Inc. in Monmouth County

Monmouth County businesses have another “cybercop” to worry about. The Consumer Financial Protection Bureau (CFPB) recently pursued its first cybersecurity enforcement action, alleging that Dwolla, Inc., an online payment platform, misled consumers about its data security practices.

The CFPB’s Allegations

Dwolla operates an online payment system with more than 650,000 users and conducts transactions of more than $5 million per day. For each account, Dwolla collects personal information including the consumer’s name, address, date of birth, telephone number, Social Security number, bank account and routing numbers, a password, and a unique 4-digit PIN.

According to the CFPB, Dwolla failed to employ reasonable and appropriate measures to protect data obtained from consumers from unauthorized access, although it represented to consumers that its data-security practices “surpass” or “exceed” industry standards. Most notably, the company allegedly failed to encrypt sensitive consumer information stored on its servers and released applications without conducting sufficient security testing. Although Dwolla maintained that its transactions, servers, and data centers were compliant with the Payment Card Industry (PCI) Security Standard, the CFPB alleged that Dwolla’s data security practices in fact, fell far short.

In pursuing the enforcement action, the CFPB relied on its authority under the Dodd-Frank Wall Street Reform and Consumer Protection Act, which empowers the agency to take action against institutions engaged in unfair, deceptive or abusive acts or practices, or that otherwise violate federal consumer financial laws. The agency based the action on the company’s misrepresentations to consumers rather than any deficiency in its cybersecurity practices.

The Consent Order

To resolve the enforcement action, Dwolla agreed to pay a penalty of $100,000 and entered into a five-year consent agreement. The consent order requires Dwolla to adopt and implement reasonable and appropriate data-security measures to protect consumers’ personal information on its computer networks and applications. More specifically, the company must:

  • Establish, implement, and maintain a written, comprehensive data-security plan that is reasonably designed to protect the confidentiality, integrity, and availability of sensitive consumer information;
  • Designate a qualified person to coordinate and be accountable for the data-security program;
  • Conduct data-security risk assessments twice annually of each area of relevant operation to identify internal and external risks to the security, confidentiality, and integrity of the network, systems, or apps, and to consumers’ sensitive consumer information stored by Respondent, and to assess the sufficiency of any safeguards in place to control these risks;
  • Conduct regular, mandatory employee training on a) the Company’s data-security policies and procedures; b) the safe handling of consumers’ sensitive personal information; and c) secure software design, development and testing.
  • Develop, implement, and update, as required, security patches to fix any security vulnerabilities identified in any web or mobile application;
  • Develop, implement and maintain an appropriate method of customer identity authentication at the registration phase and before effecting a funds transfer;
  • Obtain an annual data-security audit from an independent, qualified third-party, which must be submitted to the CFPB.

Pursuant to the consent order, Dwolla’s Board of Directors is tasked with ensuring compliance going forward. The agreement specifically states that the “Board will have the ultimate responsibility for proper and sound management of Respondent and for ensuring that it complies with Federal consumer financial law and this Consent Order.”

The Message for Monmouth County Businesses

The CFPB will be policing businesses under its purview to make sure they have “reasonable” cybersecurity policies and procedures in place. As highlighted in the consent order, the CFPB believes that businesses should be conducting bi-annual risk assessments, regularly reviewing customer-facing privacy policies to ensure they match current practices, and involving the highest levels of management, including the board of directors, in all cybersecurity-related decisions.

No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.

Scarinci Hollenbeck, LLC, LLC

Related Posts

See all
Business Mediation: An Overview and Practical Tips post image

Business Mediation: An Overview and Practical Tips

Business mediation is a confidential, voluntary process in which a neutral third party helps companies negotiate a resolution to a commercial dispute without going to trial. Because working with a mediator is very different from litigating in the courtroom, it is important to understand how commercial mediation works, when it makes sense for your dispute, […]

Author: Paul Grossman

Link to post with title - "Business Mediation: An Overview and Practical Tips"
Top 5 Causes Leading to Construction Defect Litigation post image

Top 5 Causes Leading to Construction Defect Litigation

The five most common causes of construction defect litigation are design defects, substandard materials, workmanship defects, code violations, and subsurface defects. Because these flaws can compromise a building’s integrity, functionality, or safety, they frequently lead to disputes involving multiple parties and high financial stakes. Key takeaways: What is Construction Defect Litigation? Construction litigation is complex, […]

Author: Paul Grossman

Link to post with title - "Top 5 Causes Leading to Construction Defect Litigation"
How to Protect Your New Jersey Business When Going through a Divorce post image

How to Protect Your New Jersey Business When Going through a Divorce

The most effective ways to protect your business in a divorce are put in place before one begins: a prenuptial or postnuptial agreement, clean separation of business and personal finances, and divorce contingencies built into your operating or buy-sell agreements. If divorce is already underway, the priorities shift to establishing how the business is classified […]

Author: Jay McDaniel

Link to post with title - "How to Protect Your New Jersey Business When Going through a Divorce"
10 Common Issues in Franchise Disputes post image

10 Common Issues in Franchise Disputes

The most common franchise disputes involve breach of contract, franchise termination and non-renewal, intellectual property rights, territorial encroachment, royalty and fee payments, franchisor support obligations, and violations of state franchise laws such as the New Jersey Franchise Practices Act. Franchisors and franchisees can often resolve these conflicts by providing written notice detailing the dispute and […]

Author: Paul Grossman

Link to post with title - "10 Common Issues in Franchise Disputes"
Reputational Risk and Legal Exposure: Why New Jersey Businesses Must Manage Them Together post image

Reputational Risk and Legal Exposure: Why New Jersey Businesses Must Manage Them Together

New Jersey businesses must manage legal and reputational risk together because modern disputes play out on two fronts at once: the legal proceeding itself and the court of public opinion, where customers, employees, investors, and business partners often reach conclusions long before a judge or jury has had the opportunity to evaluate the facts. Success […]

Author: Sean M. Pena

Link to post with title - "Reputational Risk and Legal Exposure: Why New Jersey Businesses Must Manage Them Together"
Eviction Is Not Always the End: Understanding Post-Possession Rent Claims in New Jersey and New York post image

Eviction Is Not Always the End: Understanding Post-Possession Rent Claims in New Jersey and New York

No. An eviction does not automatically end a tenant’s obligation to pay rent. Post-eviction rent claims are common because recovering possession resolves who has the right to occupy the premises, but it does not extinguish the tenant’s contractual obligations under the lease. Whether unpaid or future rent remains owed depends on three factors: the lease’s […]

Author: Donald M. Pepe

Link to post with title - "Eviction Is Not Always the End: Understanding Post-Possession Rent Claims in New Jersey and New York"

No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.

Sign up to get the latest from our attorneys!

Explore What Matters Most to You.

Consider subscribing to our Firm Insights mailing list by clicking the button below so you can keep up to date with the firm`s latest articles covering various legal topics.

Stay informed and inspired with the latest updates, insights, and events from Scarinci Hollenbeck. Our resource library provides valuable content across a range of categories to keep you connected and ahead of the curve.

Let`s get in touch!

* The use of the Internet or this form for communication with the firm or any individual member of the firm does not establish an attorney-client relationship. Confidential or time-sensitive information should not be sent through this form. By providing a telephone number and submitting this form you are consenting to be contacted by SMS text message. Message & data rates may apply. Message frequency may vary. You can reply STOP to opt-out of further messaging.
“If you would like to submit a file, please email it directly to info@sh-law.com.

Sign up to get the latest from the Scarinci Hollenbeck, LLC attorneys!