Search

Search bills, members, committees and pages...

Framework for the Future: Reviewing Data Privacy in Today's Financial System

HearingHouse Financial Services Subcommittee on Financial InstitutionsJun 5, 2025 · 10:00 AM

Summary

House Financial Services Subcommittee on Financial Institutions held a hearing on Jun 5, 2025 at 10:00 AM in Rayburn House Office Building, Room 2128. 5 witnesses appeared.


Record

The meeting has its video, its transcript, witnesses and documents on the record.

Video

The proceedings, as the committee streamed them.

Transcript

The transcript runs to 2,585 lines and 137,208 characters, as the Government Publishing Office printed it.

house-hearing-60987.txt
1[House Hearing, 119 Congress]2[From the U.S. Government Publishing Office]34                       FRAMEWORK FOR THE FUTURE:5                    REVIEWING DATA PRIVACY IN TODAY'S6                             FINANCIAL SYSTEM7=======================================================================89                                HEARING1011                               BEFORE THE1213                 SUBCOMMITTEE ON FINANCIAL INSTITUTIONS1415                                 OF THE1617                    COMMITTEE ON FINANCIAL SERVICES18                     U.S. HOUSE OF REPRESENTATIVES1920                    ONE HUNDRED NINETEENTH CONGRESS2122                             FIRST SESSION2324                               __________2526                              JUNE 5, 20252728                               __________2930                           Serial No. 119-263132       Printed for the use of the Committee on Financial Services3334[GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]3536                            www.govinfo.gov3738                                __________3940                   U.S. GOVERNMENT PUBLISHING OFFICE4160-987 PDF                  WASHINGTON : 20264243-----------------------------------------------------------------------------------4445                 HOUSE COMMITTEE ON FINANCIAL SERVICES4647                    FRENCH HILL, Arkansas, Chairman4849BILL HUIZENGA, Michigan, Vice        MAXINE WATERS, California, Ranking50    Chairman                             Member51FRANK D. LUCAS, Oklahoma             SYLVIA R. GARCIA, Texas, Vice52PETE SESSIONS, Texas                     Ranking Member53ANN WAGNER, Missouri                 NYDIA M. VELAZQUEZ, New York54ANDY BARR, Kentucky                  BRAD SHERMAN, California55ROGER WILLIAMS, Texas                GREGORY W. MEEKS, New York56TOM EMMER, Minnesota                 DAVID SCOTT, Georgia57BARRY LOUDERMILK, Georgia            STEPHEN F. LYNCH, Massachusetts58WARREN DAVIDSON, Ohio                AL GREEN, Texas59JOHN W. ROSE, Tennessee              EMANUEL CLEAVER, Missouri60BRYAN STEIL, Wisconsin               JAMES A. HIMES, Connecticut61WILLIAM R. TIMMONS, IV, South        BILL FOSTER, Illinois62    Carolina                         JOYCE BEATTY, Ohio63MARLIN STUTZMAN, Indiana             JUAN VARGAS, California64RALPH NORMAN, South Carolina         JOSH GOTTHEIMER, New Jersey65DANIEL MEUSER, Pennsylvania          VICENTE GONZALEZ, Texas66YOUNG KIM, California                SEAN CASTEN, Illinois67BYRON DONALDS, Florida               AYANNA PRESSLEY, Massachusetts68ANDREW R. GARBARINO, New York        RASHIDA TLAIB, Michigan69SCOTT FITZGERALD, Wisconsin          RITCHIE TORRES, New York70MIKE FLOOD, Nebraska                 NIKEMA WILLIAMS, Georgia71MICHAEL LAWLER, New York             BRITTANY PETTERSEN, Colorado72MONICA DE LA CRUZ, Texas             CLEO FIELDS, Louisiana73ANDREW OGLES, Tennessee              JANELLE BYNUM, Oregon74ZACHARY NUNN, Iowa                   SAM LICCARDO, California75LISA McCLAIN, Michigan76MARIA SALAZAR, Florida77TROY DOWNING, Montana78MIKE HARIDOPOLOS, Florida79TIM MOORE, North Carolina8081                      Ben Johnson, Staff Director8283                                 ------8485                 SUBCOMMITTEE ON FINANCIAL INSTITUTIONS8687                     ANDY BARR, Kentucky, Chairman8889BARRY LOUDERMILK, Georgia,           BILL FOSTER, Illinois, Ranking90    Vice Chairman                        Member91BILL HUIZENGA, Michigan              NYDIA M. VELAZQUEZ, New York92ROGER WILLIAMS, Texas                GREGORY W. MEEKS, New York93JOHN W. ROSE, Tennessee              DAVID SCOTT, Georgia94WILLIAM R. TIMMONS IV, South         BRAD SHERMAN, California95    Carolina                         AL GREEN, Texas96RALPH NORMAN, South Carolina         JUAN VARGAS, California97DANIEL MEUSER, Pennsylvania          SEAN CASTEN, Illinois98YOUNG KIM, California                STEPHEN F. LYNCH, Massachusetts99BYRON DONALDS, Florida               JOYCE BEATTY, Ohio100SCOTT FITZGERALD, Wisconsin          CLEO FIELDS, Louisiana101MIKE FLOOD, Nebraska102MONICA DE LA CRUZ, Texas103TIM MOORE, North Carolina104105                         C  O  N  T  E  N  T  S106107                              ----------108109                         Thursday, June 5, 2025110                           OPENING STATEMENTS111112                                                                   Page113Hon. Andy Barr, Chairman of the Subcommittee on Financial114  Institutions, a U.S. Representative from Kentucky..............     1115Hon. Bill Foster, Ranking Member of the Subcommittee on Financial116  Institutions, a U.S. Representative from Illinois..............     3117118                               STATEMENTS119120Hon. French Hill, Chairman of the Committee on Financial121  Services, a U.S. Representative from Arkansas..................     4122Hon. Maxine Waters, Ranking Member of the Committee on Financial123  Services, a U.S. Representative from California................     4124125                               WITNESSES126127Mr. Scott Talbott, Executive Vice President, Electronic128  Transactions Association.......................................     5129    Prepared Statement...........................................     8130Mr. Andrew Morris, Director of Innovation and Technology,131  America's Credit Unions (ACU)..................................    14132    Prepared Statement...........................................    16133Ms. Rebecca Kuehn, Partner, Hudson Cook, LLP.....................    29134    Prepared Statement...........................................    31135Ms. Jennifer Huddleston, Fellow in Technology Policy, CATO136  Institute......................................................    38137    Prepared Statement...........................................    40138Ms. Zoe Strickland, Senior Fellow, Future Of Privacy Forum.......    46139    Prepared Statement...........................................    48140141                                APPENDIX142                 RESPONSES TO QUESTIONS FOR THE RECORD143144Written responses to questions for the record from Representative145  Maxine Waters146    Mr. Scott Talbott............................................    88147    Mr. Andrew Morris............................................    90148    Ms. Rebecca Kuehn............................................    91149    Ms. Zoe Strickland...........................................    92150Written responses to questions for the record from Representative151  Gregory Meeks152    Ms. Zoe Strickland...........................................    93153154                              LEGISLATION155156H.R. ----, the Advancing the Mentor Protege Program for Small157  Financial Institutions Act.....................................    97158H.R. ----, the Systemic Risk Authority Transparency Act..........   102159160                       FRAMEWORK FOR THE FUTURE:161           REVIEWING DATA PRIVACY IN TODAY'S FINANCIAL SYSTEM162163                              ----------164165                         Thursday, June 5, 2025166167             U.S. House of Representatives,168            Subcommittee on Financial Institutions,169                           Committee on Financial Services,170                                                    Washington, DC.171172    The subcommittee met, pursuant to notice, at 10:09 a.m., in173room 2128, Rayburn House Office Building, Hon. Andy Barr174[chairman of the subcommittee] presiding.175    Present: Representatives Barr, Huizenga, Williams of Texas,176Loudermilk, Rose, Timmons, Kim, Fitzgerald, Flood, De La Cruz,177Moore, Foster, Scott, Sherman, Green, Vargas, Casten, Beatty,178and Fields.179    Also present: Representatives Hill, Davidson, and Waters.180    Chairman Barr. The Subcommittee on Financial Institutions181will come to order.182    Without objection, the chair is authorized to declare a183recess of the committee at any time.184    This hearing is titled ``Framework for the Future:185Reviewing Data Privacy in Today's Financial System.''186    Without objection, all members will have 5 legislative days187within which to submit extraneous materials to the chair for188inclusion in the record.189    I now recognize myself for 4 minutes for an opening190statement.191192     OPENING STATEMENT OF HON. ANDY BARR, CHAIRMAN OF THE193 SUBCOMMITTEE ON FINANCIAL INSTITUTIONS, A U.S. REPRESENTATIVE194                         FROM KENTUCKY195196    Thank you to our witnesses for being here today and lending197your expertise to this complex and critical conversation.198    Today's hearing focuses on financial data privacy, where we199will assess how Congress can ensure consumers' data is used200only as authorized while protecting the innovation that has201transformed our financial system since the Gramm-Leach-Bliley202Act, or GLBA, became law more than 25 years ago.203    Since GLBA's passage, technological advances have204revolutionized how Americans access financial services. We have205seen the rise of mobile banking apps, peer-to-peer payment206platforms, and a shift away from cash toward digital207transactions. These innovations have expanded financial208products and increased access for millions of Americans in209rural communities and urban centers.210    Alongside these developments, the volume and sensitivity of211financial data have surged dramatically. Every transaction and212interaction creates data points that financial institutions and213fintech firms analyze to improve services, assess risk, and214detect fraud and tailor products.215    While these capabilities bring benefits, they also raise216serious privacy and security concerns.217    A key driver of innovation is open banking, allowing218consumers to securely share their financial data with third-219party providers through application programming interfaces, or220APIs. Open banking can empower consumers with more control over221their financial information, foster competition, and spur the222development of new tools and services, but it also raises223questions about data privacy, liability, standard-setting, and224GLBA's applicability.225    GLBA's broad framework has served us well, setting key226protections for consumer data but a quarter of a century is a227long time in tech. So, we must ask, is GLBA still fit for228purpose in today's fast-paced, data-driven environment? Does it229provide the clarity, flexibility, and protection needed in the230digital age?231    As we consider modernization, we must proceed cautiously.232Changes that are too restrictive risk choking off access to233financial options on which consumers rely. Conversely, overly234lax rules could leave Americans vulnerable to misuse of their235sensitive data. Striking the right balance is critical.236    We also cannot examine GLBA in isolation. Data privacy laws237have proliferated at the State level, with 20 States enacting238comprehensive privacy laws. Some exempt financial institutions239that comply with GLBA, while others layer on more stringent240requirements.241    This patchwork creates a complex, costly compliance242landscape, potentially increasing costs and reducing access.243This also risks some States setting de facto national244standards, bypassing Congress and creating uncertainty for245businesses and consumers alike.246    For these reasons, Congress should consider the benefits of247a uniform national data privacy standard that offers clear,248consistent, preemptive rules for financial institutions while249protecting consumers.250    As our colleagues on the Energy and Commerce Committee work251on broader privacy legislation, we must also ask whether252sector-specific laws, like GLBA, warrant carve-outs or tailored253treatment. GLBA already imposes strong data protection254requirements, and financial institutions have built compliance255programs around these rules. Overlapping or conflicting256standards would only add confusion and cost.257    Finally, we must address calls to expand enforcement258mechanisms by granting consumers private rights of action,259which allow individuals to sue firms directly for alleged260violations. Private rights of action open the door to frivolous261lawsuits, benefiting large firms that can absorb litigation262costs and discouraging innovation by increasing legal risks for263financial services providers. Ultimately, consumers lose out264through reduced access and choice of innovative products.265    While these are complex issues requiring thoughtful266consideration, we must balance robust privacy protections with267innovation, access, and reduced regulatory burden.268    I look forward to hearing from our witnesses today and269engaging in a productive discussion on the future of data270privacy in our financial system.271    The chair now recognizes the ranking member of the272subcommittee, Dr. Foster, for 4 minutes for an opening273statement.274275 OPENING STATEMENT OF HON. BILL FOSTER, RANKING MEMBER OF THE276 SUBCOMMITTEE ON FINANCIAL INSTITUTIONS, A U.S. REPRESENTATIVE277                         FROM ILLINOIS278279    Mr. Foster. Thank you, Chairman Barr, and to our witnesses280for their excellent written testimony.281    Today, we will be discussing the framework for data privacy282in today's financial system. At its core are the Gramm-Leach-283Bliley Act; the Fair Credit Reporting Act (FCRA); and section2841033 of the Dodd-Frank Wall Street Reform and Consumer285Protection Act.286    Minor changes have been made to this framework over the287years. However, there are significant questions about how these288laws are adapting to an increasingly digital economy,289innovative financial products, cybersecurity risks, artificial290intelligence, and the growing role of third-party firms in the291financial sector.292    I look forward to discussing many of these issues with our293panel today.294    I was proud to have sat on this committee when we drafted295the Dodd-Frank Act and was happy to see the most recent update296to the financial privacy framework come out last October, when,297after years of bipartisan work under three different298Presidents, the Consumer Financial Protection Bureau (CFPB)299finalized the Personal Financial Data Rights Rule to implement300section 1033 of the act.301    This rule is significant because it gives consumers greater302rights, privacy, and security over their personal financial303data. It makes it easier for consumers to switch between304service providers to find better rates, to make secure305payments, and to utilize innovative tools to manage their306finances. This rule gives consumers the right to revoke access307to their data whenever they choose and promotes the development308of market-driven data standards.309    The rule was developed through a lengthy process spanning310multiple Presidential administrations, gathering public311feedback at several points, starting in 2016. The first Trump312Administration started the process of implementing the rule,313with an advance notice of proposed rulemaking in 2020.314    Despite the work of the first Trump Administration and our315former Chair, Patrick McHenry, supporting the final rule, the316Trump Administration is now apparently working to repeal the317rule.318    This morning, I led 12 of my colleagues from the committee319in sending a letter to acting CFPB Director Russell Vought320urging him not to rescind this rule but, rather, to address321outstanding issues through targeted amendments and future322guidance.323    It has been nearly 15 years since the passage of Dodd-324Frank, and rewriting this rule in its entirety would cause an325unnecessary delay that will hurt privacy, hurt innovation, and326hurt competition.327    Finally, while I support this committee's renewed focus on328data privacy legislation, I am also deeply concerned by other329actions taken by this administration related to Americans'330sensitive data.331    The President and Elon Musk sent members of their332Department of Government Efficiency (DOGE) team to raid333government agencies of their data across our government, where334they accessed and gathered sensitive data on millions of335Americans. This includes data from the Social Security336Administration, from Treasury, from Health and Human Services,337and even the Consumer Financial Protection Bureau, which holds338information on companies that, for example, would directly339compete with Elon Musk's payment company, X Money.340    These efforts pose great risk to the privacy of all341Americans, and anyone that truly cares about privacy should be342calling for immediate accountability and transparency from all343those involved.344    Thank you, and I yield back.345    Chairman Barr. The gentleman yields back.346    The chair now recognizes the chairman of the full347committee, Mr. Hill, for 1 minute.348349  STATEMENT OF HON. FRENCH HILL, CHAIRMAN OF THE COMMITTEE ON350    FINANCIAL SERVICES, A U.S. REPRESENTATIVE FROM ARKANSAS351352    Chairman Hill. Thank you, Chairman Barr.353    Since 1999, when the Gramm-Leach-Bliley Act was passed,354most Americans were still watching movies on their VCRs and355arguing over who was tying up the dial-up internet connection.356Since then, technology has advanced at an extraordinary pace357and so has the amount of sensitivity of personal financial358information being collected and shared.359    Remarkably, GLBA has kept the pace of many of these changes360but given the magnitude of today's technological complexity and361the increase of data availability and collection, we must362ensure Americans' privacy is protected while continuing to363support the seamless delivery of the financial services that364they rely on.365    Congress has a major role to play in crafting strong,366modernized guardrails that keep pace with innovation, preserve367consumer trust, and future-proof our laws. Over the last368several Congresses, committee Republicans have worked to craft369a narrowly tailored legislation to modernize our financial370data. We look forward to working on that in this Congress now371with the leadership and partnership of the House Energy and372Commerce Committee.373    I yield back to you, Mr. Barr.374    Chairman Barr. The gentleman yields back.375    The chair now recognizes the ranking member of the full376committee, Ms. Waters, for 1 minute.377378    STATEMENT OF HON. MAXINE WATERS, RANKING MEMBER OF THE379  COMMITTEE ON FINANCIAL SERVICES, A U.S. REPRESENTATIVE FROM380                           CALIFORNIA381382    Ms. Waters. Thank you very much.383    Today, we are considering the important issue of data384privacy. However, I find it rich that any Republican here would385claim to support data privacy, when they have said nothing386about Trump letting Elon Musk and his DOGE minions steal the387sensitive data of hundreds of millions of Americans--everything388from their health records and consumer data to Social Security389numbers and tax data.390    Trump did not stop there. In addition to shuttering the391Consumer Financial Protection Bureau, which fights fraudsters392and helps Americans get remedies from predatory financial393firms, Trump also wrongly vacated the CFPB's Open Banking Rule394that promotes data privacy.395    I would like to think there is bipartisan support to396protect Americans' data, but we must first start by stopping397the biggest threat: Donald J. Trump.398    I yield back.399    Chairman Barr. The gentlelady yields back.400    Today, we welcome the testimony of Mr. Scott Talbott,401Executive Vice President of the Electronic Transactions402Association; Mr. Andrew Morris, Director of Innovation and403Technology at America's Credit Unions; Ms. Rebecca Kuehn,404Partner at Hudson Cook; Ms. Jennifer Huddleston, Fellow in405Technology Policy at the Cato Institute; and Ms. Zoe406Strickland, senior fellow at the Future of Privacy Forum.407    We thank you for taking the time to be here. You each will408be recognized for 5 minutes to give an oral presentation of409your testimony. Without objection, your written statements will410be made part of the record.411    Mr. Talbott, you are now recognized for 5 minutes.412413     STATEMENT OF SCOTT TALBOTT, EXECUTIVE VICE PRESIDENT,414              ELECTRONIC TRANSACTIONS ASSOCIATION415416    Mr. Talbott. Good morning, Chairman Barr, Ranking Member417Foster, and members of the Financial Institutions Subcommittee.418I am Scott Talbott. It is my privilege, as the Executive Vice419President at the Electronic Transactions Association (ETA), to420speak with you today on the future of privacy and the modern421payments system.422    ETA is a trade association representing a broad group of423companies from banks to processors and fintechs who provide424electronic products and services, including mobile wallets,425peer-to-peer products, credit, debit, and prepaid cards, as426well as other forms of digital payments.427    Last year, our industry helped consumers and merchants in428the United States make over $11 trillion in card and peer-to-429peer (P2P) payments securely, reliably, and quickly. In fact,430during the 5 minutes I will speak this morning, roughly 1.5431million transactions will be processed in the United States.432    In each of these transactions, there is a shared433expectation between consumers and the payments industry that434personal data will be kept both private and secure. Given ETA's435members' role in the payments industry, both privacy and436security are top priorities for our members.437    Entities in the payments industry are covered directly or438indirectly by the Gramm-Leach-Bliley Act and a handful of State439privacy laws. The core structure of GLBA imposes both privacy440and data security requirements on the industry. This is441accomplished through the Privacy Rule and the Safeguards Rule.442These requirements in GLBA are tailored to the unique and443complex nature of the financial services industry.444    For financial services, all transactions involve at least445two and quite possibly more entities working together to446execute the customer's request. A prime example is a single447credit card purchase where at least three or sometimes four448entities are involved in moving the data as well as the449payment. GLBA recognizes this reality and allows multiple450entities to share data to work together seamlessly and quickly451to serve customers' needs.452    While GLBA is largely working well for the financial453services industry, a challenge comes with the patchwork of454nearly two dozen State privacy laws, eight of which went into455effect this year alone. These State laws have different456approaches to privacy as well as key definitions that create457confusion for consumers, small businesses, as well as458challenges and expense to financial services and other459businesses working to comply. Sometimes the State laws even460conflict with each other, and in my written testimony I have461given examples of this.462    As Congress considers changes to the privacy laws, there463are a few key things that we urge you to consider.464    First, is the need for a uniform national standard. ETA465member companies serve consumers and businesses, especially466small businesses, in all 50 States. A single, strong, uniform467national privacy standard would serve all American consumers468and businesses by providing common expectations as they conduct469their everyday transactions.470    Any new Federal privacy law should be technology-neutral471and sector-neutral. However, given the complexity of financial472services and its unique needs, the financial services industry473should continue to be governed by GLBA.474    Next, consumers should have rights within this Federal475privacy law. Privacy is a two-way street. For consumers, the476Federal privacy law should include consumer rights such as477disclosure, access, correction, deletion, and opting out of478targeted marketing. We also support using appropriate data479minimization and data usage standards that are reasonably480suited to execute the underlying transaction.481    These key aspects will ensure that institutions know their482responsibilities and consumers know what to expect. This483approach will work to eliminate redundancies, inconsistencies,484and confusion created by the existing State privacy regimes.485    Any privacy law must retain permissible use of data to486fight fraud. The payments industry works tirelessly to detect487and minimize fraud. These efforts to fight fraud benefit488consumers, merchants, as well as the economy. It is important489that any privacy law contains permissible use of the data to490fight fraud. Permissible use exists now in GLBA as well as in491every State privacy law. Other countries' privacy laws also492include this important use case.493    The scenario here that we are focused on is that a thief494commits fraud and then asks for the data to be deleted or495forgotten. This would create a blind spot, allowing fraudsters496room to fester. By including a permissible use of data to fight497fraud in privacy law, the payments industry will continue to498have a 360-degree view of fraud or potential fraud in the499payments space.500    Enforcement by Federal regulators. We encourage any privacy501law to assign enforcement to the appropriate Federal502regulators.503    Next, a key goal of the payments industry is continuous504innovation, and we are constantly developing and deploying new505products and services to make payments safer, faster, and more506convenient for consumers.507    Two new ideas on the horizon include open banking, or508consumer-driven banking, and artificial intelligence. Both of509these are in use in the market today, and both of these utilize510data-sharing between multiple parties.511    Open banking contemplates consumers directing the sharing512of data, and artificial intelligence allows for faster and more513efficient use of the data. Both of these are covered by514existing Federal laws, including GLBA as well as fair lending.515In both examples, policymakers should rely on these existing516laws and look for any gaps and avoid rushing to legislate new517privacy laws here.518    On behalf of ETA and our member companies, thank you once519again for the opportunity to participate in this important520discussion. I look forward to any questions you may have.521522    [The prepared statement of Mr. Talbott follows:]523    [GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]524525    Chairman Barr. Thank you.526    Mr. Morris, you are now recognized for 5 minutes.527528    STATEMENT OF ANDREW MORRIS, DIRECTOR OF INNOVATION AND529              TECHNOLOGY, AMERICA'S CREDIT UNIONS530531    Mr. Morris. Good morning, Chairman Barr, Chairman Hill,532Ranking Member Foster, and members of the subcommittee. My name533is Andrew Morris. I am Director of Innovation Technology at534America's Credit Unions.535    Thank you for the opportunity to testify about how a536comprehensive Federal privacy law can be harmonized with the537existing laws and regulations applicable to credit unions and538other financial institutions.539    First and foremost, America's Credit Unions supports a540comprehensive Federal data security and privacy framework that541includes robust security standards that apply to all who542collect or hold sensitive personal data. It is important that,543as the law evolves to match it, credit unions have rules of the544road that allow them to meet the needs of their members in the545marketplace.546    Depository institutions, including credit unions, have long547been subject to a framework of laws and regulations designed to548ensure a high standard of consumer privacy and data security.549Central to this framework is Title V of the GLBA, which550acknowledges the need for heightened care when handling551sensitive consumer financial information and provides well-552established standards for addressing consumer privacy concerns.553    America's Credit Unions believes that the Gramm-Leach-554Bliley Act should remain the model for depository institution555compliance with any future Federal data privacy and security556standard.557    Credit unions, like many financial institutions, have long558prioritized investments in data security to ensure that their559members' privacy is protected. The GLBA requires financial560regulators to implement safeguards that are comprehensive and561designed to ensure the security, confidentiality, integrity,562and proper disposal of consumer information and other records.563    Under the rules promulgated by the National Credit Union564Administration, every credit union must develop and maintain an565information security program to protect consumer data.566Additionally, the rules require credit unions to ensure that567third-party service providers that have access to credit union568data take appropriate steps to protect the security and569confidentiality of the information.570    As Congress considers potential reforms to data privacy and571security, there are various aspects we believe should be572included or addressed.573    First, there should be an entity-level exemption for credit574unions and similarly regulated financial institutions that are575subject to the GLBA. An entity-level exemption would recognize576the rigor of existing financial institution compliance577activities and allow regulators to tailor supervision based on578changing privacy or data security risks.579    Second, the oversight of credit unions, banks, and other580depository institutions should be left to the functional581financial institution regulators that have experience in this582field.583    Third, preemption of State laws is necessary. Today's584patchwork of State privacy laws has invited idiosyncratic585approaches to data processing activities and technologies. Some586States, by choosing to recognize only a data-level exemption,587have placed strains on credit unions by demanding more complex588procedures for addressing data processing activities. The589resulting compliance burdens, magnified each time a new State590law is passed, siphon resources away from service to consumers591and the core lending activities of credit unions.592    Fourth, there should be limits on data deletion593requirements. Prohibitions on collecting certain types of data594without consumer opt-in or a broad right of deletion can595frustrate efforts to comply with recordkeeping rules or to596detect and prevent fraud.597    Fifth, an opt-out regime should be maintained. The GLBA and598Regulation P generally operate to limit sharing of sensitive599consumer information through an opt-out process, something we600believe should continue and be the standard for financial601institutions in any future data privacy regime.602    Sixth, as outlined in my written testimony, a comprehensive603Federal data privacy framework should provide for principles-604based requirements and offer a safe harbor for businesses that605take the appropriate steps to comply with the law.606    Seventh, any private right of action should be limited. We607have serious concerns with any broad private right of action608due to the risk of frivolous lawsuits being filed against609credit unions, which are already held accountable for610violations by their regulator, the National Credit Union611Administration (NCUA), as well as the Consumer Financial612Protection Bureau (CFPB).613    In conclusion, stringent information security and privacy614practices have long been a part of the financial sector's615business practices and are necessary, as financial institutions616are entrusted with consumers' nonpublic personal information.617We look forward to working with you to achieve a well-balanced618Federal data privacy framework.619    Thank you for holding this important hearing and the620opportunity to appear before you today. I welcome any questions621you may have.622623    [The prepared statement of Mr. Morris follows:]624    [GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]625626    Chairman Barr. Thank you, Mr. Morris.627    Ms. Kuehn, you are now recognized for 5 minutes.628629     STATEMENT OF REBECCA KEUHN, PARTNER, HUDSON COOK, LLP630631    Ms. Kuehn. Good morning. Chairman Barr, Chairman Hill,632Ranking Member Foster, and members of the subcommittee, thank633you for the opportunity to testify today.634    I am Rebecca Kuehn. I am a Partner at Hudson Cook, where I635lead our credit reporting, data privacy, and data security636practice. I formerly served as an Assistant Director at the637Federal Trade Commission, where I led efforts related to638financial privacy and data security.639    Today, I am appearing in my own capacity and not on behalf640of my firm or any client.641    We are here today to consider the framework governing642financial data privacy.643    The United States has a longstanding tradition of financial644privacy protection that balances consumer rights, market645innovation, and regulatory oversight. This balance is important646to consumers and the financial system.647    The cornerstone of the financial privacy regulation is the648Gramm-Leach-Bliley Act, or the GLBA. It requires financial649institutions to provide consumers with clear privacy notices650explaining what personal information is collected and how it is651shared, to offer consumers with the right to opt out of certain652types of data-sharing with nonaffiliated third parties, and to653implement safeguards to protect the confidentiality and654security of consumer financial information.655    The GLBA defines ``nonpublic personal information''656broadly, and it applies to a wide range of entities engaged in657financial activities, from banks to auto dealers, ensuring658consistent privacy standards across the financial services659landscape.660    Through what are known as the 502(e) exceptions, the GLBA661also recognizes that certain forms of data-sharing are critical662to enabling core financial functions such as fraud prevention663and public safety. These include disclosures necessary to664process transactions, disclosures made with the consumers'665consent, and disclosures meant to prevent fraud or unauthorized666transactions. These types of sharing do not require an opt-out667because GLBA draws a clear line between essential, operational,668and service needs and marketing and other nonessential sharing,669where an opt-out is required.670    As of 2015, financial institutions that share data only671within these carefully crafted exceptions are no longer672required to provide duplicative annual notices to consumers as673long as they have not changed their privacy practices. This674change in GLBA reduces regulatory burden and has incentivized675companies to limit their sharing to only those essential676purposes. This benefits both consumers and the industry.677    I recognize there is a larger discussion about data on678consumers and privacy. However, recent proposals, such as the679CFPB's data broker rule, risk undermining this careful balance.680The CFPB's rule proposed to reclassify certain identity and681address information governed by the GLBA as information under682the Fair Credit Reporting Act (FCRA) and would have limited the683ability of companies to use GLBA information for a number of684core purposes, such as fraud prevention.685    The proposal came out of a concern about misuse of consumer686data, but the proposal conflated the responsible, regulated use687of financial data by institutions that serve essential688functions with very different and concerning practices of bad689actors, such as entities who sell sensitive geolocation data on690military personnel.691    This conflation is problematic. It overlooks the fact that692GLBA-covered entities are already subject to comprehensive693privacy and security obligations and that the types of sharing694permitted under the GLBA are vital for protecting consumers695against fraud and ensuring public safety.696    As this subcommittee continues to examine financial697privacy, I urge a careful, fact-based approach, one that698recognizes the distinction between the well-regulated financial699data use and the more opaque or harmful practices of700unregulated bad actors.701    Oversight and modernization are appropriate, but they702should not come at the cost of undermining core consumer703protections or essential financial system functions.704    I thank you for your attention, and I look forward to your705questions.706707    [The prepared statement of Ms. Kuehn follows:]708    [GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]709710    Chairman Barr. Thank you.711    Ms. Huddleston, you are now recognized for 5 minutes.712713STATEMENT OF JENNIFER HUDDLESTON, FELLOW IN TECHNOLOGY POLICY,714                         CATO INSTITUTE715716    Ms. Huddleston. Thank you.717    Chair Barr, Ranking Member Foster, and distinguished718members of the House Committee on Financial Services719Subcommittee on Financial Institutions, my name is Jennifer720Huddleston, and I am a senior fellow in Technology Policy at721the Cato Institute.722    My research focuses on the intersection of law and723technology, including its use related to data privacy.724Therefore, I welcome the opportunity to testify regarding data725privacy in today's financial system.726    In this testimony, I will focus on three key points.727    First, data privacy in sensitive areas, such as financial728services, is already regulated by existing law.729    Second, as State or a potential Federal data privacy law730continues to emerge, careful attention should be paid to the731way they may interact with or conflict with these existing laws732and what a patchwork might mean regarding the burden733particularly on small players. This is additionally true if734enforcement mechanisms, such as private rights of action for735statutory damages, could significantly raise the risk of costly736litigation.737    Finally, I wish to discuss how any conversations around738data privacy should consider the impact on innovation, consumer739choice, and smaller players, as well as how such laws could740interact with or hinder the deployment of potentially better741solutions when it comes to data privacy and data security.742    So, to begin with, some have criticized the United States743as a sort of Wild West when it comes to data privacy. Instead,744the United States' approach has been better understood as745responding with regulation for particularly vulnerable or746sensitive data where consumers may be more likely to face harms747should it be abused or insecure, such as the financial services748sector.749    In this regard, the financial services sector already has750consumer-focused data privacy laws, including the Gramm-Leach-751Bliley Act that regulates the personal data of consumers held752by financial services forums and the Fair Credit Reporting Act753that regulates consumer credit data from credit reporting754agencies.755    To my second point, the potential interactions between756comprehensive data privacy laws at both the State and Federal757level and the financial services sector, it is important to758understand how general consumer privacy laws could impact this759already-regulated data. Additional data privacy laws could760further add to the regulatory burden or conflict with existing761laws.762    As the chair mentioned in his opening statement, an763emerging patchwork of State laws that are both sector-specific764and general in their application could make this more difficult765to navigate, with at least 19 States having passed766comprehensive consumer privacy laws and more debating similar767legislation each year.768    While many of these State consumer privacy laws have a769carve-out for existing regulated data under laws like the FCRA770and the GLBA, this does not mean they do not impact or create771potential conflicts for the financial services sector or772financial data. This can include conversations around different773definitions of ``particularly sensitive data,'' including774financial information or personally identifiable information,775and the timelines and steps that entities must take to respond776to consumer requests or potential issues. These conflicts can777be particularly felt by smaller and more innovative entities778who have to navigate various definitions.779    Additionally, such laws provide an example of the impact780that different enforcement mechanisms, including private rights781of actions with statutory damages, could have in deterring782innovation and particularly in already-regulated or risk-averse783sectors.784    While not related to financial data, for example, the785Illinois Biometric Information Privacy Act has such a786mechanism, and it is illustrative of the problems such787enforcement can create even in data considered particularly788sensitive. Because of statutory damages and private right of789action, this law has resulted in significant claims against790companies ranging from popular social media apps like Meta to791Six Flags amusement park, but more for violation than for any792actual harm occurring to consumers.793    Finally, I would like to spend my last minute discussing794how privacy law and innovation can potentially conflict.795    While recognizing the specific risks of economic harm and796sensitivity of financial data is logical, law is static and797innovation is dynamic. This yields the potential need for798review of regulation to allow improvements in data privacy799security and innovation, as various technologies might provide800alternatives that are more protective of privacy and provide801better services to consumers who opt in but might not meet the802existing definitions.803    There are three ways existing data privacy regulation might804deter innovation that I would like to highlight.805    First, many laws are developed for earlier technologies.806This may make it more difficult to use more secure technologies807like blockchain that could actually create greater privacy and808security for consumers.809    Second, enforcement mechanisms around private right of810action or the need for government approval could deter811companies of all sizes, but particularly smaller companies,812from trying to find innovative ways to protect data.813    Finally, artificial intelligence may require us to rethink814our existing frameworks around data usage, retention, and815minimization, including in regulated industries like the816financial services sector.817    I thank you for your time, and I welcome your questions.818819    [The prepared statement of Ms. Huddleston follows:]820   [GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]821822    Chairman Barr. Thank you, Ms. Huddleston.823    Ms. Strickland, you are now recognized for 5 minutes.824825 STATEMENT OF ZOE STRICKLAND, SENIOR FELLOW, FUTURE OF PRIVACY826                             FORUM827828    Ms. Strickland. Thank you. I am grateful for the829opportunity on this important topic, financial privacy.830    I am a senior fellow at the Future of Privacy Forum, which831is a leading privacy think tank which supports developing832privacy technology and business practices, and I lead their833Open Banking program.834    I have spent over 30 years working in privacy--this is at835Fortune 20's and a leading agency--across sectors and across836technologies. I also led the Business Roundtable financial837subgroup in its efforts to reimagine privacy for the financial838sector.839    I want to touch briefly on general privacy.840    There are a lot of benefits to having an omnibus privacy841approach in law. It could be a consistent standard for all842consumers. Imagine if we could give consumers a clear set of843their rights. It would boost awareness in the consumer844ecosystem and their sense of control over their data. It would845also make our approach more consistent with international846approaches where they do have omnibus laws, and it would847support data transfers from multinationals.848    There are three challenges when we think about omnibus849privacy laws.850    The first one, of course, is the substance, right? Privacy851is principle-based, and so sometimes it is difficult to define852it and be thorough about what those rights are, especially as853they evolve over time. I have been very pleased with recent854bills that have really done a very thorough job in thinking855about modern privacy principles.856    The second challenge is around enforcement. I would suggest857to policymakers to be careful of approaches that amount to858strict liability or per-violation penalties. If you think about859$1,000 times a million, you get to a billion pretty fast. On860the other hand, be careful to think about tying enforcement to861concrete harms. In privacy, there often are not out-of-pocket862damages but the violations are real. So, the focus should863instead be on the seriousness of the violation and with the864efforts the company made to prevent and mitigate the violation.865    The third challenge is around existing laws. What do you do866with the plethora of State laws that exist and Federal laws867that exist in terms of carve-outs or integration? I do think,868as policymakers think about what are good privacy standards,869that can create some gravity that can enable these other870existing laws to fold in and to develop that consistent871standard.872    I did want to talk about a pressing issue, which is around873open banking and the CFPB final rule. I do believe it is and874can be a bipartisan approach and issue.875    First of all, open banking does represent enormous consumer876value. They really do have the right to have their data and877control their data. Enormous examples of positive use cases878allow better financial planning, to transfer and hold their879money as they see fit. Just imagine if we could have a focus on880Americans having financial health early in their life and the881benefits to them and to society and I think that feeling of882control over their data and their finances will also lend883itself in other areas of their life as well.884    There is a challenge if open banking means only the885consumer has access to their records. Otherwise, they are going886to have to collect it and transfer it to desired third parties,887they will have to endlessly update it. I think that would888frustrate consumers. It also, unfortunately, would not enable889rules for data recipients when they obtain that data, and they890will have enormous power over the consumers.891    There are many good things about the open banking892principles. One is eliminating screen-scraping, where consumers893give their credentials to a third party. It is a terrible894privacy and security practice. The rule incorporated industry895standards sensibly. In a way, I think it made it leading in the896world and it also enabled privacy and security rules for all897parties, even though they are differently regulated.898    I do think in the final rule there were some misses. Some899of them impacted data providers; some of them impacted third900parties. They are detailed in my written testimony.901    I do think that those issues can be examined and addressed,902and then open banking can look forward, because it needs--and903as mentioned in a lot of the consumer and industry feedback904that was provided in that rulemaking process--needs to cover905more products, things like loans, investments, payroll,906electronic benefits transfer (EBT), to really give that sense907of control and that full picture to consumers.908    We are very happy to assist in this important effort, and I909look forward to taking your questions.910911    [The prepared statement of Ms. Strickland follows:]912    [GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]913914    Chairman Barr. Thank you.915    We will now turn to member questions. The chair now916recognizes himself for 5 minutes.917    Mr. Talbott, my first question will be directed to you.918    The section 1033 rulemaking that Ms. Strickland was just919referencing was a product of the Dodd-Frank Act. In the 15920years since the passage of Dodd-Frank and the rulemaking, the921landscape of the financial system has changed massively, as we922have all been discussing.923    The rulemaking is currently being debated in the courts.924However, there needs to be some certainty and stability so925institutions can flourish in the technological ecosystem.926    Mr. Talbott, should data privacy legislation potentially927modify or replace certain provisions of section 1033 of Dodd-928Frank to codify the beneficial aspects of the rule while moving929away from outdated and unclear aspects of the Dodd-Frank policy930as currently written?931    Mr. Talbott. Sure. Thank you, Mr. Chairman. I appreciate932the question.933    I think, in general, the open banking or consumer-directed934banking is already existing in the marketplace today, and it is935done through a series of bespoke contracts between the bank,936data aggregators, and fintechs. All of these entities should be937subject to GLBA or through these contracts. If they are not,938then possession of the data should trigger coverage of the939privacy law. If any entity has a consumer's data and they are940not covered, they should be covered as a basic principle.941    A couple of issues we had with the open banking or942consumer-driven banking proposal, the final reg that is subject943to the courts is: One, it did not address liability for fraud944or for a breach. If one entity is subject to a breach and945consumers suffer a loss, that is an area that needs to be946addressed either through privacy law or through a future947rulemaking, that was one of the misses, I think, that Zoe948referenced earlier, and we agree, that there has to be949something around dealing with liability for fraud that was not950addressed in that.951    Additionally, the law prohibited the collection or952assessment of fees by the financial institution for the work953that they are doing, and that is another area that needs to be954addressed.955    In general, Mr. Chairman, the answer to your question is956that existing privacy laws should cover all the participants in957the open banking system.958    Chairman Barr. Should our privacy legislation that we are959considering, should it modify 1033?960    Mr. Talbott. I think that, in general, it should consider961it, but I do not think there are any gaps, necessarily, in the962law other than an entity not being subject to GLBA.963    Chairman Barr. Okay.964    Private rights of actions create more problems than they965solve. They incentivize trial lawyers to file frivolous class-966action lawsuits and lead firms to avoid business opportunities967that would benefit consumers due to fear of costly litigation.968    Ms. Kuehn, based on your experience with the GLBA and969similar privacy laws, do you believe adding a private right of970action to GLBA would meaningfully enhance consumer data971protection or would it more likely impose litigation risks that972hinder innovation and reduce consumer access to financial973products?974    Ms. Kuehn. Thank you for the question.975    What we have not seen, and where I think this concern about976do we need to add a private right of action, is whether or not977there are gaps or problems happening in financial services978data. There do not seem to be.979    If you look at the history of enforcement--and there have980been a couple of agencies with enforcement authority over981Gramm-Leach-Bliley during its existence--there have not been982many cases involving privacy of consumers, the use of data.983    That tells us that, even though these entities are examined984by prudential regulators, looked at by different enforcement985entities--and we saw a very aggressive enforcement regime from986the last 4 years from the CFPB, yet, what we do not see are987cases brought under GLBA.988    I think we have the tools that we need if there are989problems that exist, and I do not know that additional tools990are needed.991    Chairman Barr. If we have a nationwide, uniform data992privacy standard, the regulatory agencies, the financial993regulators could handle enforcement----994    Ms. Kuehn. I believe so.995    Chairman Barr [continuing]. without a private right of996action?997    Ms. Kuehn. Yes, sir.998    Chairman Barr. Thank you.999    Thanks to advancements in technology over the past few1000decades, financial institutions and firms can partner with more1001technology-oriented companies in order to compete and serve1002additional customers with the products and services that work1003better for them, but State privacy laws have created a1004patchwork that can complicate these partnerships.1005    Ms. Huddleston, how has this patchwork harmed market1006efficiency and consumers and would Federal preemption for GLBA-1007compliant financial institutions help preserve these innovative1008partnerships?1009    Ms. Huddleston. Thank you for your question, Mr. Chair.1010    When we see this emerging State patchwork, it is1011particularly burdensome on new ways of using data that might1012not fit existing models, whether that is firms that would not1013traditionally be considered financial institutions but may be1014using financial data in some way to help inform consumers or1015whether these are just small financial institutions trying to1016get off the ground.1017    A patchwork means that they are now going to have to seek1018to comply in 19 different States. Even if those 19 or 201019different States have the same law on the books, there will be1020different interpretations of many terms, meaning that these1021firms have to invest significantly in regulatory compliance1022rather than focusing on providing their consumers with the best1023possible product.1024    Chairman Barr. Thank you for that testimony.1025    My time has expired.1026    The gentleman from Illinois, Dr. Foster, is now recognized1027for 5 minutes.1028    Mr. Foster. Thank you, Chairman Barr.1029    Quickly, Mr. Talbott, when you mentioned that banks and1030fintechs already have a limited data-sharing capability between1031them, it seems to me that the small banks are kind of left out1032of this. They cannot have the ability to stand up to an1033application programming interface (API) team that will go and1034do all this data-sharing.1035    Are there any solutions on the horizon for that or is this1036going to be one of the things where we are going to have to try1037to level the playing field to make sure that small banks and1038credit unions are not left out?1039    Mr. Talbott. Yes, so banks and credit unions--I will let1040Andrew speak for himself--but we work together as an industry.1041We do not want any weak links; so, any data, like an API, for1042example, through an industry consortium, is shared with all1043entities to allow for----1044    Mr. Foster. Yes. There is a problem that I think remains1045unsolved, that the smaller institutions simply do not have the1046capacity to plug into this very complex ecosystem.1047    Ms. Strickland, thank you, first of all, for your very1048thoughtful testimony and your focus on the important work that1049CFPB has done on data privacy.1050    As I said in my opening remarks, I am really very1051uncomfortable with the idea of this administration rescinding1052completely the rule to implement section 1033 of Dodd-Frank.1053Not only has it been 15 years since the passage of Dodd-Frank1054that required the rulemaking, but I am also not confident that1055the CFPB, frankly, currently has the staff necessary to do a1056full rewrite of the rule.1057    One thing I think is important to recognize, that this is1058not a rule that came out of nowhere. There was extensive work1059on the final rule spanning multiple Presidential1060administrations that solicited public input on various aspects1061of the rule, as well as a notice of proposed rulemaking that1062was initiated during the first Trump Administration.1063    Can you speak briefly about the extensive work that went1064into this rule and the huge amount of bipartisan effort by your1065organization and the financial services industry as a whole to1066prepare for open banking and the impact of this1067administration's potential rescinding of this rule?1068    Ms. Strickland. Thank you, and I very much welcome that1069question.1070    I included in the written testimony a very detailed1071description of the extensive process with the relevant links to1072all the materials. It was a very long and extensive and1073thorough process and had engagement across all industry sectors1074and consumer groups.1075    If you read the comment letters, which I did--and there are1076a lot of them. Not only were there a lot, but they were very1077long and thorough and really delved through all the different1078aspects of the rule, and largely supportive, that this is a1079positive to the ecosystem. Yes, it has existed for a while, but1080there were some areas that benefited from some consistency of1081the regulatory framework.1082    You see that in the comment letters. In fact, some of them1083suggested, again, covering more products. We really need to do1084that, in terms of giving that full view to consumers, and doing1085it more quickly since it exists now and it is a consumer1086benefit.1087    I do think, as mentioned, in the final rule there were a1088few misses that I think could be addressed. I think Scott hit1089on a couple of them accurately. I do think that it will be a1090good place to look in terms of what happens next, either1091through Congress or the CFPB, to address those issues and then1092look forward to where we are trying to take open banking in1093America.1094    I did want to comment on your remarks about the smaller1095players. I do think there is a question whether they stay under1096a regime that is run by screen-scraping, which is, again, not a1097good practice but also is not better for them, too, in terms of1098their understanding of their consumers and their interests.1099    So, there are efforts to make that API more widely1100available and to have core providers who can help lift up the1101smaller players so that they can benefit from this developing1102ecosystem too and that needs to be paid attention to as well.1103    I do think the staggering helped, because it allows some of1104this infrastructure to grow and that they can then get on-ramps1105onto it. I do think it benefits the whole community that the1106smaller institutions are ramped on at the right time.1107    Mr. Foster. Yes. Thank you. As someone who has done his1108fair share of programming of screen-scraping as well as APIs, I1109share your enthusiasm for getting rid of screen-scraping. It is1110unstable, it is dangerous to privacy, and it is just a pain in1111the ass.1112    Ms. Strickland. Horrifying.1113    Mr. Foster. Right.1114    The future is probably neither APIs nor the past of screen-1115scraping but agentic interactions, where the consumer1116interaction is not going to be directly with the consumer but1117with an agent.1118    One of the interesting arguments the Trump Administration1119CFPB made in the brief that they filed with the court last1120Friday was that section--they claimed section 1033 of Dodd-1121Frank requires that the rule only allows consumers themselves1122to request access to their data, which ignores the language in1123the Dodd-Frank Act that, quote, an agent, trustee, or1124representative acting on behalf of the individual, which is1125obviously meant to include third parties and agents authorized1126by the individual.1127    If you could just comment on that for the record, I would1128appreciate it. That is a big problem.1129    [The information referred to was not submitted prior to1130printing.]1131    Chairman Barr. Thank you.1132    The gentleman's time has expired.1133    The gentleman from Michigan, Mr. Huizenga, is now1134recognized.1135    Mr. Huizenga. Thank you, Mr. Chairman, and I would like to1136say thanks to the Ranking Member.1137    For the kids watching out there, that is a technical DC1138term for difficulties in transactions, what he was expressing,1139where exactly those pains might occur, earlier.1140    Apparently, that was funnier in my head than it was when he1141said it.1142    Mr. Talbott, good to see you again. I think you got it. You1143were nodding with me.1144    Yesterday, we heard from multiple witnesses about the1145importance of consumer protections when it comes to owning1146digital assets and when it comes to data privacy. Frankly, I do1147not see much difference. Gaining access to a consumer's data is1148just as lucrative as gaining access to their bank account. In1149your testimony, you noted, ``Consumers rightly expect strong1150privacy protections and data security for their personal1151information and their money.''1152    Of course, providing protections does come with some costs.1153How can Congress strike the balance between consumer protection1154and excessive compliance--there is compliance, but then there1155is also excessive compliance--so that small providers--and I1156think Ms. Huddleston was talking about that a bit or at least1157alluding to that--that the small providers are not1158disproportionately affected compared to the larger providers?1159    Mr. Talbott. Sure. I thank you for the question. I1160appreciate it.1161    I think first is, areas where we could focus are tightening1162up the definitions so that all parties know exactly what data1163is protected. For example, in Gramm-Leach-Bliley, they use the1164phrase ``consumer'' and ``customer,'' and they make a1165distinction between the two, and that may no longer hold or be1166as clear to all parties, including smaller players. So,1167tightening up the definitions can help so we all know what we1168are talking about.1169    Secondly, you can look at the rights that are provided1170under the law--right now, the rights include access,1171correction, deletion, and those--and make sure that those can1172be applicable for all entities so that consumers get the same1173rights and benefits regardless of which institution they choose1174to use and; so, narrowly focusing on those rights and how they1175are applicable in the real world could help address the issue1176for all players, not just small players.1177    Mr. Huizenga. You touched on definitions, tightening up1178definitions. I want to ask, does the GLBA's definition of1179``financial institution'' adequately reflect the range of1180entities handling consumer financial data today?1181    Ms. Huddleston, you seem to have that--Mr. Morris?1182Somebody?1183    Ms. Kuehn. I am happy to address that.1184    Mr. Huizenga. Grab it. Yes. All right.1185    Ms. Kuehn. The definition of ``financial institutions'' is1186keyed off to all the variety of activities that financial1187companies can engage in and that is subject to expansion if,1188over time, the agencies decide, ``Hey, there are some1189additional things we need to address.'' So, it is a flexible1190definition.1191    It is also pretty broad. I mean, if you think about the1192definition of ``financial institution''----1193    Mr. Huizenga. So, broad and flexible could be too broad and1194flexible or interpretation of it has then locked out some1195areas?1196    Ms. Kuehn. It is not locked out, because it is made in1197reference to the Federal Reserve's definition of what types of1198financial activities banks engage in. So, it lists everything1199from credit reporting to making loans to doing financial1200transactions.1201    Mr. Huizenga. Okay.1202    How about Mr. Morris? Does it apply to credit unions?1203    Mr. Morris. Yes, the financial activities would definitely1204encapsulate what credit unions are doing. So, we would clearly1205be----1206    Mr. Huizenga. Do you feel like you are adequately covered1207by this?1208    Mr. Morris. Yes.1209    Mr. Huizenga. Okay. Great. I see Mr. Talbott nodding.1210    Mr. Talbott. I would agree.1211    Mr. Huizenga. Okay.1212    What consumer rights have States incorporated in data1213privacy laws that Congress should codify at the Federal level?1214In other words, are there some best practices that we are1215seeing out in the States?1216    Mr. Talbott?1217    Mr. Talbott. Yes. I think a couple of--GLBA covers a lot of1218those rights, but they do not necessarily have so much the1219right to access a lot of the information or some of the1220information. So, that could be important to update GLBA with.1221    Mr. Huizenga. So--but are there any States specifically1222doing that? I mean, as we are seeing, obviously, privacy1223frameworks need to evolve.1224    Mr. Talbott. Right.1225    Mr. Huizenga. Is there somebody that is actually doing a1226good job that we ought to be looking at?1227    Anybody else?1228    Mr. Talbott. I would--Virginia has done a good job. Texas.1229Both States' privacy laws capture those.1230    Mr. Huizenga. Okay.1231    Anybody else care to weigh in on that?1232    Ms. Huddleston. I would just note that I think it is1233important to consider what enforcement mechanisms, and what1234timelines are involved in some of these things.1235    When we look at, for example, a right to access, are there1236appropriate incentives, particularly for sensitive financial1237information, to ensure that it is the correct consumer that is1238getting that information, that we are not seeing something1239where there is such a short timeline for response that the1240wrong information is handed over to the wrong consumer.1241    One can look at, for example, General Data Protection1242Regulation (GDPR) to see how there have been some incidents1243where recordings or other information, not financial, have been1244handed over that way.1245    Mr. Huizenga. Great.1246    I yield back.1247    Chairman Barr. The gentleman's time has expired.1248    The gentleman from Georgia, Mr. Scott, is recognized.1249    Mr. Scott. Thank you, Chairman Barr.1250    I really agree with you, Chairman, that our Nation is at a1251crossroads when it comes to financial privacy. Right now, our1252constituents' banking information, their credit history, their1253transaction records, and even how they pay their rent is up for1254grabs, for exploitation, wrongdoing, and even stealing. Without1255firm protections, that data can be collected, brokered, and1256misused, often without the consumer ever knowing.1257    That is precisely why the CFPB section 1033 rulemaking is a1258step in the right direction. The CFPB 1033 rule has set up a1259framework that empowers Americans to take more control of their1260own financial data safely, securely, and on their own terms. It1261prohibits data brokers from monetizing data without consent,1262fintech applications to be transparent and non-manipulative,1263and financial institutions to provide data access in a secure,1264machine-readable format.1265    Here is the problem: These protections, this progress on1266behalf of our consumers are now under a great threat, for we1267are watching a dangerous rollback taking shape at the CFPB1268under the Trump Presidency.1269    President Trump is appointing people who have spent their1270whole careers defending data brokers, avoiding regulatory1271compliance, weakening the CFPB's enforcement capacity, and1272threatening CFPB's funding and undercutting the CFPB's1273rulemaking.1274    Now, Ms. Strickland, the Trump CFPB has argued that rule1275imposes a burden on data aggregators and fintech companies. Let1276me ask you, is it not the CFPB's job to protect the consumers1277and not the business models of companies that profit from1278opaque or predatory data practices?1279    Ms. Strickland. Thank you for your question.1280    Yes, I think one thing that was valuable about the 10331281rule is that it did place obligations on the companies1282receiving data and, in fact, imposed sort of modern principles1283around what those privacy rules should be.1284    To the prior question asked about what are some of those1285activities that policymakers should look at? There is a1286developing area called individual rights, which Jennifer1287alluded to, which is, do I have the right to access, delete,1288and transport my data? How do I understand the data that1289belongs to me is about me, and do I have rights with regard to1290that?1291    Also, another very useful feature we see in some developing1292bills is around privacy impact assessments and risk-based1293assessments, which are extremely familiar to the financial1294sector, to a lot of risk analysis. So, those sorts of precepts1295really lend themselves to how we think about privacy.1296    I do think that is a value in open banking, which is, the1297data recipients are going to have a lot of information now1298about these consumers and perhaps even will move money on their1299behalf. So, it is very important that they actually have rules1300that apply to them as well and if you do not have open banking1301rules, you do not have that ability to really put those1302controls in place.1303    Mr. Scott. Now, many of my friends on the Republican side1304have talked about rescinding the rule. Tell me, will not1305rescinding the rule make it easier for bad actors to exploit1306our consumers?1307    Ms. Strickland. I do think that the proposed rule really1308did address some issues between data-sharing amongst the1309parties. There were some good features for data providers,1310definitely some good controls over data recipients that really1311should be included in any future rulemaking activity around1312this. I think they were very important points.1313    Mr. Scott. Thank you, Ms. Strickland.1314    Chairman Barr. The gentleman yields back.1315    The gentleman from Texas, Mr. Williams, is now recognized.1316    Mr. Williams of Texas. Thank you, Mr. Chair. Thank you all1317for being here today.1318    Community banks have earned the trust of their customers by1319safeguarding their sensitive financial data because they have1320longstanding relationships with their customers and handle1321personal information with diligence and care.1322    Now, we need to ensure that any updates to data privacy1323maintain flexibility for smaller banks. These smaller1324institutions struggle with mandates that force them to divert1325resources from lending in their communities and into legal1326compliance.1327    Ms. Huddleston, could you elaborate on ways to modernize1328the GLBA that preserves flexibility for smaller banks?1329    Ms. Huddleston. I think it is important that we look at1330this on a Federal level as opposed to the State-by-State1331patchwork that is often emerging.1332    Additionally, we need to consider not only the way data may1333be being used these days by smaller entities but also the ways1334it may be used in the future. We already see tools like1335artificial intelligence (AI) being deployed in the fraud alert1336system and things like that. We certainly would not want to see1337regulation or changes that may make it more difficult to deploy1338these tools in the future.1339    I think when we are talking about concerns about private1340right of action that is particularly relevant to smaller1341players, smaller players who could find, even if they win a1342lawsuit, that it is still potentially business-crippling or1343even business-ending and so are less able to absorb the cost of1344that litigation than a larger player, even though larger1345players also have significant financial regulatory compliance1346burdens.1347    Mr. Williams of Texas. Thank you for that.1348    One of the most promising developments in financial1349services over the past decade has been the growing1350collaboration between banks and fintech companies. These1351partnerships allow smaller institutions to offer cutting-edge1352digital tools for underserved customers and compete with the1353largest national banks.1354    Now, much of this innovation relies on responsible data-1355sharing arrangements where consumers can securely grant access1356to their financial information and improve their banking1357services.1358    Mr. Talbott, how do data-sharing arrangements between banks1359and fintechs improve competition in the marketplace? How can we1360protect that collaboration while still maintaining strong1361privacy protections?1362    Mr. Talbott. Sure. Thank you for your question.1363    I would just note that Texas has a number of provisions in1364its privacy law which are examples for the rest of the country.1365They have carve-outs for small businesses as well as rights of1366cure, which are good examples.1367    In terms of data-sharing between banks and fintechs, most1368of this interaction, if not all, is already covered by Gramm-1369Leach-Bliley, both the privacy as well as the security1370provisions. If it is not, it is covered by a private contract,1371bespoke contract, between the two entities.1372    So there is sufficient coverage there both for privacy as1373well as data security. We feel those existing laws and existing1374contracts will help keep the data safe and secure.1375    Mr. Williams of Texas. The people I represent in Texas,1376like many rural communities across the country, a lot of local1377lenders and community financial institutions with access to1378credit, mortgages, and basic financial services, and as we1379consider new data privacy rules, we have to be careful not to1380cutoff these vital lifelines. If regulations are too complex or1381restrictive, small banks and credit unions may scale back1382services or exit certain markets entirely.1383    Mr. Morris, this question is to you. How can we make sure1384that the privacy regulations do not unintentionally limit1385consumer access to financial products, and particularly for1386those in rural areas like I represent in Texas?1387    Mr. Morris. Thank you for the question. I think one area1388where a Federal privacy framework could focus to preserve that1389access is by preserving the current opt-out framework that is1390present in the Gramm-Leach-Bliley Act that facilitates a lot of1391joint marketing activities, which allows community financial1392institutions, small credit unions, small community banks to1393partner with fintechs and others to promote the availability of1394their services in banking deserts and other places where there1395may be limited access to affordable products.1396    Having an opt-out framework for sharing information is an1397intelligent way that the GLBA has balanced those concerns.1398Whereas the more onerous opt-in framework could curtail that1399and limit access to services in those communities.1400    Mr. Williams of Texas. Thank you, Mr. Chair, and I yield my1401time back.1402    Chairman Barr. The gentleman yields.1403    The gentleman from California, Mr. Sherman, is now1404recognized.1405    Mr. Sherman. When I saw the title of this hearing, I1406thought I would spend my full 5 minutes talking about Elon1407Musk, looking at all the Social Security data of millions and1408millions of Americans, but I think I am going to focus on1409things within the jurisdiction of our committee.1410    The CFPB plays a critical role with data privacy. The1411decision of the Trump Administration to destroy, dismantle,1412abolish the CFPB means that not only will Americans not be1413protected from rip-offs, not only will they not get the1414information they need to make intelligent decisions and1415financial matters, but we will talk grandly about their1416privacy, but there will not be an agency there to ensure that1417their private data is kept private.1418    One of the issues that arises is one we have seen for a1419long time, and that is what happens if there is hacking. We1420have seen this issue with regard to giant retailers having1421information, getting hacked, and then turning to the banks and1422saying, ``You have to pay all the costs of dealing with1423consumers on this issue.'' It has been well-established in tort1424law theory for well over 100 years that the liability of the1425cost of an accident should be put on the party who could have1426invested to prevent that accident.1427    Whenever a fintech company is the entity that gets hacked,1428they are the ones that should bear the cost of the consumer1429repair. The 1033 rule asks fintech companies that want to1430access to banks' data to comply with the same Gramm-Leach-1431Bliley financial data protection requirements the bank must1432comply with, but there is no specific enforcement mechanism for1433this rule.1434    The rule also did not ban screen scalping, a practice by1435which third-party stores your user, your password, then logs1436into your bank account and collects, maybe sells your financial1437data.1438    Mr. Morris, what amendments or guidance, like perhaps1439banning screen scalping, and having the CFPB regulate fintech1440companies that store financial data, what should we consider to1441the personal financial data rights rule to ensure that we are1442safeguarding this data for consumers?1443    Mr. Morris. Thank you for the question. I think with1444respect to ways to better protect data and address the concerns1445that you mentioned, in the context of 1033, it would be prudent1446for the CFPB to consider a way of allocating liability in the1447event that data is mishandled by downstream third-party1448entities, using that information, collecting it from data1449provider credit unions. The absence of that means that credit1450unions and other data provider financial institutions and their1451members only have a course in the courts. So, addressing that1452in the regulation could be a helpful way to meet the rule.1453    Mr. Sherman. Now, under the CFPB Rule 1031, financial1454institutions currently cannot charge a fee for third-party1455fintech companies to access the bank's data through their API1456application programming interface developer portals.1457    Mr. Morris, is it costly to develop and maintain these API1458portals and should we consider at least allowing the smaller1459institutions to charge a fee to fintech companies to access the1460data through these relatively expensive portals?1461    Mr. Morris. Thank you for the question. I believe that it1462is absolutely correct that it is costly to develop and maintain1463APIs. One of our concerns, again, with the CFPB's rule1464implementing 1033 was the significant cost that is shouldered1465primarily by data providers to essentially subsidize API access1466and development. So, we would like the CFPB to reconsider that1467aspect of the rule to better balance the cost to our credit1468unions.1469    Mr. Sherman. I am going to try to squeeze in one more1470question. Mr. Morris, what protections, like perhaps, banning1471screen scalping across the board should we consider adding so1472that small institutions are protected? Even if they are exempt1473from the rule, what effect on small credit unions and the small1474banks could there be if there is a massive financial data1475breach of a third party potentially exposing financial1476institutions to liability and drying up all its members1477depository accounts?1478    Mr. Morris. We are certainly supportive of moving away from1479screen scraping, which is a less secure way of sharing1480information. As far as tightening up rules that are designed to1481prevent data breaches and minimizing their consequences, I1482think one area in 1033 the CFPB explored, which is sharing1483information necessary to initiate a payment, that is very1484sensitive information, which if it is shared with a third party1485it could lead to fraud.1486    Chairman Barr. All right. The gentleman's time is expired1487and the gentleman from Georgia, Mr. Loudermilk, is now1488recognized.1489    Mr. Loudermilk. Thank you, Mr. Chairman. Thank you all for1490being here. Very important subject. I have 30 years in public1491and private sectors with dealing with intelligence, data1492security, and protecting information. Eight years Active-Duty1493military in the intelligence community, protecting our Nation's1494secret, 2 years with the Defense contractor, and 20 years with1495my own business.1496    Privacy and security are very important to me and the1497number one key to protecting data was a rule that we lived by1498in those 30 years is, you only have to protect what you have.1499Meaning, if you do not absolutely need something, do not keep1500it.1501    While the GLBA focused on the private sector, the elephant1502in the room is not Elon Musk. It is the massive amount of data1503the government has that he had access to. No one on the other1504side of the aisle wants to address that this entity, this 800-1505pound gorilla called the Federal Government, is the largest1506security risk of personal privacy information.1507    Now, what we are discussing here is very important, but1508when we bring up legislation that actually would restrict the1509amount of data, like updating the Bank Secrecy Act and currency1510transaction reports to make them reflective of where they1511should be due to inflation, we do not hear anything from the1512other side, but they are always anxious to deal with the1513privacy data when it comes to the private sector. That is1514important. I am not demeaning it.1515    We do have to understand that our Nation collects and1516forces the private sector to turn over massive amounts of1517personal privacy information and financial information to the1518government, which is the weakest link in our cybersecurity1519protection.1520    With that, Mr. Talbott, dealing with GLBA, what rights do1521consumers currently have regarding their personal data under1522the Gramm-Leach-Bliley Act? Yes, Mr. Talbott. I am sorry.1523    Mr. Talbott. Yes, no problem. I appreciate the question,1524Mr. Loudermilk, as well as your representation of the State of1525Georgia where 70 percent of all credit card and debit card1526transactions run through your State.1527    The rights under GLBA for consumers that exist now is they1528have a right to correct and a right to talk about earlier1529somewhat access the information, like to delete the1530information. These are important rights for consumers. There1531are disclosure notices that are required depending on where you1532sit in the system and so, these are all important rights that1533they have. They have the ability to opt out of target1534marketing, and that is an important right as well.1535    Mr. Loudermilk. That is one thing in this new era because1536we often fail to keep up with technology, which allows for some1537innovation, but also, is defining what is consumer data versus1538privacy data versus company data, that type of thing.1539    In what ways do financial institutions share consumer data1540with affiliated and nonaffiliated third parties?1541    Mr. Talbott. The first and foremost example is with any1542transaction. Let us say a credit card transaction, there are at1543least three, sometimes four parties involved. There is the1544issuing bank, the requiring bank processors, there are networks1545and that data under GLBA is allowed to be shared for purposes1546of processing that transaction. As you well know from the1547credit card space, that is necessary to allow that transaction1548to move in 1.2 seconds when you are standing in the checkout1549line.1550    Mr. Loudermilk. How do fintech companies access consumer1551data to deliver financial products and services and what role1552does consumer consent play in the process?1553    Mr. Talbott. Sure. Right now the concept of open banking or1554consumer-directed banking is happening in the marketplace and1555fintechs will enter into bespoke contracts with banks to allow1556their shared customers to share the data between the two. That1557is governed by a private contract at this point, pending the15581033 rules that may come up at some point.1559    Mr. Loudermilk. Okay. Thank you. Mr. Morris, what are three1560key features that credit unions believe should be included in1561any new data security regime?1562    Mr. Morris. Thank you. I think the first and most important1563is an entity level exemption that recognizes existing1564compliance with the Gramm-Leach-Bliley Act as well as other1565laws like Fair Credit Reporting Act, the Right to Financial1566Privacy Act, and others. The other thing we would like to see1567is preservation of the opt-out framework and a limitation on1568private rights of action which could hinder innovation and1569create enormous litigation risks for small credit unions and1570other institutions.1571    Mr. Loudermilk. Okay. Thank you. Mr. Chairman, I will yield1572back my time.1573    Chairman Barr. The gentleman yields back. The gentleman1574from California, Mr. Vargas, is recognized.1575    Mr. Vargas. Thank you very much, Mr. Chair. First of all, I1576want to thank you and the Ranking Member for convening this1577hearing, and of course I want to thank the witnesses for being1578here.1579    I do want to point out that I was abandoned by Mrs. Beatty1580who normally sits here next to me. Today, she decided not to,1581and I think that should be pointed out. I feel hurt.1582    Secondly, I do want to say this, that I actually agreed1583with half of what my good friend from Georgia said. I actually1584do think the government has way too much information. It1585absolutely does, and it does not protect it as well. In fact, I1586am a little worried today when you go through the airport now,1587they get all sorts of biometric information about you. I do not1588know how they use that either. I think we should be concerned1589about that, and I do not think that the government does protect1590the wealth.1591    I do not agree with Elon Musk. I do think that, in fact, it1592was very dangerous to have him running around with these young1593kids doing things that we do not even know what the hell they1594were doing. I am not sure that they knew either.1595    All that being said, the CFPB has a job of making sure1596consumers are getting straight deals and making one of the ways1597it is done--and one of the ways it is done is by making sure1598consumers are getting a fair deal when it comes to control of1599their own data. When consumers are not in control of their own1600data, financial institutions have to compete on their merits1601for the people's business and more competition is better, I1602think, for everyone.1603    That is what Dodd-Frank Section 1033 is all about. While1604Section 1033 goes back to the Dodd-Frank Act, the CFPB's1605finalized rule ensured consumers could be in control of their1606personal financial data and could be more easily transferred to1607another provider.1608    From the Gramm-Leach-Bliley Act dealing with financial1609information to the Fair Credit Reporting Act dealing with1610credit information, Congress has continued to adapt privacy1611protection laws to an evolving economy. We also have to make1612sure that we continue to adapt those protections, security of1613data as a top of mind, especially in the financial sector, and1614especially in the era as I said earlier of DOGE being given1615access to sensitive data information.1616    I was proud to join a letter this week led by the ranking1617member as he stated urging the CFPB not to vacate and throw out1618the years of progress we have made on finalizing Section 10331619rule.1620    Ms. Strickland, when CFPB finalized the Section 1033 rule1621in October 2014, former Chairman McHenry stated that the CFPB's1622final rule 1033 is a promising step forward to protect1623Americans' financial data privacy. Consumers should know where1624their data is going, how it is used, and be able to terminate--1625and to terminate collection of their data by certain firms.1626    Director Chopra also listened to some of our concerns1627regarding unreasonable restrictions on secondary use of data.1628Why do you believe there was bipartisan support for this rule1629at that time?1630    Ms. Strickland. I am sorry, the question is there were?1631    Mr. Vargas. Why do you think we did come together and there1632was bipartisan support?1633    Ms. Strickland. I think there was. You saw that from the1634comment letters as well. It ranged across all the industry1635sectors as well as the consumer groups. Again, delving very1636deeply into every aspect of the rule.1637    I do think a contributing factor was with all the great1638work that was done to get to the proposed rule--and there was1639enormous amount of work done, including the small business1640review panels--and again, digging deeply into how do the1641parties work together, what are the right obligations? What are1642the right privacy practices? Right security practices--what1643products are we covering? How do we think about small entities?1644A lot of work went into all those aspects.1645    I do think in the final rule, there were a few items that1646were not addressed ideally and that creates----1647    Mr. Vargas. For example.1648    Ms. Strickland. So--and, again, in the written testimony, I1649go through several of them. In my view, the main ones were--and1650you mentioned them? One is the secondary uses of information.1651They did not allow those--even consumers to agree to them and1652that is what open banking is all about. It made for a very1653awkward sort of consumer experience.1654    It also did not really allow the use of the identified1655data, which is a common practice, not only in the financial1656sector, but in every sector. It is a great privacy and security1657practice, too, because you made it nonidentifiable and1658controlled for re-identification.1659    It did not thoroughly look at the questions raised about1660increased fraud or liability. There was some information given1661about what that could look like. Could there be better1662monitoring done? Some shifts looked at in terms of liability.1663    Mr. Vargas. Okay. I do want to stop you there because,1664again, I think that there are some things that we could do a1665better job at. I have to say this: It is interesting because1666this issue came up in California, many, many, years ago back in16672001, when I was the Chairman of the Insurance Committee. At1668that time we would have had screaming matches here. We do not1669have that anymore, because I think we have come a long way, and1670I do want to praise everyone that has worked on this issue.1671Thank you. Thank you, Mr. Chair.1672    Chairman Barr. The gentleman yields back. The gentleman1673from Tennessee, Mr. Rose, is recognized.1674    Mr. Rose. Thank you, Chairman Barr, and also thank you,1675Ranking Member Foster, for holding this important hearing.1676Thank you to our witnesses for your time today and being part1677of this hearing.1678    Mr. Talbott, in your testimony, you highlight that two1679dozen States have enacted different data privacy laws. Can you1680discuss the challenges that members of the Electronic1681Transactions Association face when it comes to navigating such1682a large number of potentially inconsistent State laws?1683    Mr. Talbott. Sure. Thank you for the question. The biggest1684one is what data is covered. Many States provide either provide1685an entity level exemption, meaning that the bank or the credit1686union is exempt from that State's privacy law because they are1687covered under the GLBA. Some States only have a data-level1688exemption, which means the entity is covered, but certain data,1689the GLBA data is not covered by that State's privacy law but1690the State's privacy law definition of what is covered is1691broader. At that point, and most particularly, California is1692the lead example. Oregon is similar as well. Business-to-1693business (B2B) data is exempt under GLBA but is not exempt1694under California law.1695    So, any entity that may be GLBA compliant still has to map1696out all of its data and all of the uses for the business side1697to ensure that it is in compliance with the California State1698law--the California State privacy laws.1699    There is a perfect example of how different States with1700different definitions can create issues. That creates a lot of1701problems and challenges.1702    Mr. Rose. Sure. Can you--and it may be beyond what you just1703gave as an example, are there examples where--that you can1704provide where State data privacy laws are in conflict at such a1705level that it is impossible to comply with those1706inconsistencies?1707    Mr. Talbott. I do not know if I would say impossible1708necessarily but definitely creates some conflicts. I have a1709list in my written testimony, and the biggest example is with1710California. Where I just talked about where B2B is covered1711under the California privacy law, but it is not covered at the1712Federal law. That is the biggest challenge. Others relate to1713timing, the nature of the disclosures, what data can be1714excluded or not, what opt-out rights the consumer has. Maryland1715has a very stringent opt-out on what can and cannot be covered1716or cannot be shared. Those are just some examples where the1717challenges----1718    Mr. Rose. So not really--I do not think I am hearing of1719examples where you--what you do in one State would actually be1720a violation if you did it in another State. Is that fair to1721say?1722    Mr. Talbott. That is correct. It is fair, yes, sir. It is1723on the implementation side.1724    Mr. Rose. I guess that is good news. Obviously, we need to1725avoid that.1726    Mr. Morris, in your testimony, you touch on the fact that1727the credit unions, like many financial institutions, have long1728prioritized investments in data security to ensure that their1729members or customers' privacy is protected. I think it would be1730helpful if you could expand on just how much credit unions have1731already invested in data security.1732    Mr. Morris. Thank you for the question. I am happy to share1733more statistical information perhaps after, but I can say that1734we have run surveys in the past and consistently year after1735year after year reflecting enormous cost of data breaches and1736the risk of fraud. Credit unions are prioritizing investments1737in cybersecurity and data security. Those things are part of1738the Gramm-Leah-Bliley Act, which mandates that the National1739Credit Union Administration, other financial regulators, and1740other regulators of financial institutions implement technical1741safeguards to ensure that those institutions are adopting1742appropriate data security practices. That drives a lot of cost,1743but it is important for keeping trust.1744    Mr. Rose. Very good. Mr. Talbott, back to you. Would you1745like to discuss the significant investments that the Electronic1746Transactions Association members have already made in data1747security?1748    Mr. Talbott. I think the number would be in the billions.1749We spend equal amounts on developing and deploying new products1750and services to make payments easier, faster, more secure. We1751also spend similar amounts to fight and protect fraud to1752protect both consumers, merchants, as well as the economy. The1753number is easily in the billions of dollars.1754    Mr. Rose. In light of some of the discussion we have had1755about the role of employees of institutions in safeguarding1756data--and I might open this up, but I will start with you, Mr.1757Talbott, any--and we do not have much time--but any criteria in1758any of the law as to the credentialing or qualifications of1759employees of organizations that are charged with protecting1760consumer data that you would like to speak to or take note of?1761    Mr. Talbott. Yes, sir. I appreciate the question. The1762Federal Trade Commission (FTC) safeguard rules as well as good1763business practice require companies to develop a robust system1764internally for security purposes, and that includes addressing1765which of their employees have access to it, how to cutoff that1766access, passwords, et cetera. I mean, all the usual security1767protocols that you would think would go into protecting data as1768well as payments.1769    Mr. Rose. Thank you. My time has expired. I yield back. I1770would appreciate insight from the rest of the panel about that1771question of credentialing of employees that deal with consumer1772information. Thank you. I yield back, Mr. Chairman.1773    Chairman Barr. The gentleman yields. The gentleman from1774Illinois, Mr. Casten, is recognized1775    Mr. Casten. Thank you, Mr. Chair. Last year the CFPB1776finalized their open banking rule that would have given1777consumers greater access and control over their financial data,1778including making it easier for consumers to move their1779financial data from institutions.1780    Ms. Strickland, can you just talk about how that rule would1781increase competition and make our markets more efficient?1782    Ms. Strickland. Yes, so on that actually--and thank you for1783the question--has been a key driver of open banking initiatives1784in the United States as well as in other jurisdictions which is1785how do you make all the players compete for the consumer's1786business, both in terms of good price, but also in terms of1787product offerings? Really encouraging new technology and new1788business models to say, Hey, I have a brand-new idea. How do I1789do this but recognizing they are not always regulated in the1790same way as banks are, which is deep and thorough.1791    So, open banking really does enable these different1792companies to work together and to put both a framework around1793how the data exchanges occur, but also, as I mentioned, put1794some rules on the data recipient who are not regulated in the1795same way. The open banking rule created to the prior question1796on this roll around what you collect, what you can use it for,1797how long you can retain it, which are really important1798safeguards1799    Mr. Casten. To that point, we had, a couple years ago on1800this committee, we had a discussion with former Director Chopra1801about how Facebook had no obligation to ensure that in1802hoovering up your data, they were not essentially violating the1803Fair Lending Act by only promoting certain credit card products1804to one individual or another.1805    Would the open banking rule have fixed some of those gaps1806so that third parties like Facebook are not using your data to1807target you in ways that may be, if not illegal, certainly1808unethical?1809    Ms. Strickland. Yes, I think that is right. I mean,1810presently for large companies, if they are not regulated by1811sectorial law, they are under general FTC jurisdiction which is1812unfair and deceptive; so, their privacy policy is accurate.1813They can proceed as well as the State laws that exist.1814    I do think an open banking benefit was to create modern1815privacy rules for the recipients of this data which are very1816important because they are getting sensitive financial1817information and sometimes the ability to move money. So, having1818that bar and those requirements on data recipients was a real1819value to the rule.1820    Mr. Casten. Just as an aside, I consistently struggle with1821the fact that my extreme libertarian colleagues are petrified1822of the government getting your data but seem to have no problem1823if a private company gets your data and monetizes it and1824refuses to let you see what they have. Rand is pissed is all I1825have to say about that.1826    You mentioned the FTC. This matters, of course, because1827last week the Trump Administration's CFPB filed a motion to1828vacate that rulemaking, which is going to open up this gap. A1829lot of these data privacy rules, as you mentioned under Gramm-1830Leach-Bliley, CFPB has some jurisdiction, the FTC has1831jurisdiction, our balancing regulators have jurisdiction.1832    I guess I will turn to you, Ms. Kuehn. Given your past role1833at the FTC, if the CFPB cannot fulfill their roles to protect1834data privacy and were left with whoever remains standing, what1835are the gaps that emerge in our ability under current law to1836protect the people we represent and their data privacy?1837    Ms. Kuehn. One of the benefits that the Federal Trade1838Commission has is a broad rule related to unfair deceptive1839action practices. There was some discussion about retailers1840getting data and what happens if there is a breach at a1841retailer. The FTC has brought a number of cases involving data1842security, many, many, years ago, just under its general Section18435 authority where it has found a gap.1844    So, one of the benefits of the Federal Trade Commission's1845jurisdiction is that it does have this sort of flexible1846oversight and ability to bring cases where it sees developing1847threats emerging.1848    Mr. Casten. So, I guess the concern--maybe I will turn back1849to you, Ms. Strickland--in theory, I agree with you. In1850practice, we have an entire industry saying I want complete1851absolution of any liability from any of my AI models. In fact,1852all of our Republican colleagues just voted last week to pass a1853piece of legislation that says, there shall be no liability for1854anybody using the AI model.1855    So I steal your data, I put it into the system, I violate1856the deceptive practices, but you are totally absolved because I1857did not do it. The AI optimized an algorithm to solve this, and1858how was I to know? All I did was just not comply--did not say1859that AI would comply.1860    So I guess, Ms. Strickland--there may not be enough time--1861but I would welcome your thoughts on how we might regulate AI.1862In this world, where the CFPB is broken, data privacy still1863matters, what should we be doing to close this barn door,1864especially in light of this big ugly bill that we passed out of1865the House last week if the Senate goes along with that?1866    Chairman Barr. The gentleman's time has expired. The1867witnesses can answer for the record. The gentleman from South1868Carolina, Mr. Timmons, is now recognized.1869    Mr. Timmons. Thank you, Mr. Chairman, and thank you to the1870witnesses for joining us this morning. I often hear from1871constituent companies about the challenges posed by the complex1872State-by-State patchwork of data privacy laws, which makes1873compliance across jurisdictions burdensome and undermines1874consistent consumer protection. Many States vary restrictions1875and laws based on the side of the company. This is1876understandable until you realize that many States have vastly1877different thresholds based on the institutions in common1878handling of consumer data.1879    This issue is compounded by the fact that the Gramm-Leach-1880Bliley Act serves only as a Federal floor for consumer1881financial data privacy, allowing States to impose more or less1882stringent requirements.1883    For instance, California mandates opt-in consent for1884sharing consumer data with nonaffiliate third parties, going1885beyond the GLBA's opt-out standard. While other States, such as1886Alabama, align more closely with the Federal baseline and1887impose fewer additional obligations.1888    This uneven regulatory landscape complicates compliance1889efforts and creates uncertainty for institutions operating1890nationwide.1891    Ms. Kuehn, what challenges do California's law in similar1892State regulations create for consumer access to financial1893services within those States and how do they affect financial1894institutions seeking to enter or operate in those markets?1895    Ms. Kuehn. The former preemption that GLBA has, which1896basically keeps States from going below the standards does1897allow States to set different standards above that. To date,1898until these more recent privacy laws, States have not really1899ventured into that very far. The problem is that as the States1900are looking at these privacy issues, and they want to set1901different or varying standards, that is going to make1902compliance very difficult, particularly for financial1903institutions who operate throughout the United States.1904    So, I am going to have to have an investment in State-by-1905State rules and compliance and controls that is going to take1906away from my ability to provide other products and services to1907consumers. The patchwork is of great concern. If this committee1908were to relook at GLBA, I think revisiting the form of1909preemption that exists in law will be very important in order1910to preserve this sort of uniform approach that financial1911institutions take across the country.1912    Mr. Timmons. Is it fair to say that larger financial1913institutions comply with the patchwork framework more easily1914than smaller?1915    Ms. Kuehn. They have more money to invest in compliance. I1916mean, let us face it, the smaller guys, particularly in a1917competition area, have a tougher time because they have to1918build the kind of processes and services and have the personnel1919to deal with consumer inquiries, for example, you name it. It1920is the big investment for the clients that I work on. It is1921often a hardship.1922    Mr. Timmons. It really stifles entrepreneurship because1923startups are unable to comply, and it really creates a major,1924and we need to address it.1925    Mr. Talbott, what problems do these regulations create for1926innovative institutions trying to deliver a seamless experience1927for consumers, especially when offering products and services1928if those consumers have actively requested?1929    Mr. Talbott. Thank you for the question. We will deliver1930the products and services as the market demands, but the1931challenge will be in compliance with the various State laws.1932You have disclosures, you got opt-ins, you have opt-outs. All1933of those will slow down the process of getting customers on-1934boarded in the first instance.1935    Once they are on-boarded, once that has been addressed,1936then the products will be delivered quickly, accurately,1937seamlessly. The challenge would be in the compliance side we1938are doing.1939    Mr. Timmons. Thank you for that. How do these frictions1940hinder new market participants, such as fintechs, to compete1941with larger more established institutions?1942    Mr. Talbott. They too must comply with the privacy and data1943security rules. There are cost, time, and expense associated1944with compliance. In addition, they have to navigate all the1945different States, depending on which States they operate in, as1946well as GLBA, depending on where the State exemption is. That1947creates enormous amounts of complexity, challenge, compliance1948costs.1949    Mr. Timmons. As we consider how to address this problem, I1950think the general perspective is that Europe has gone too far,1951and they have really restricted competitiveness. What would1952your recommendation be--obviously, California has a standard,1953and the European standard is the most developed--how do we1954thread this needle to accomplish the objective without being1955overly burdensome?1956    Mr. Talbott. Two points: GDPR is the European version. They1957actually have a good definition that many States borrow from.1958That is positive. They also allow for a private right of action1959which creates off the back end the number of legal issues and1960challenges and complexities.1961    Initially, the number of these private rights of action can1962distort or change or slowly case by case modify the law which1963creates more challenges in terms of compliance versus having1964enforcement at the Federal regulatory system.1965    Mr. Timmons. Thank you for that. It is past time for1966Congress to act, and we need to preempt State law and create1967one standard so we can compete in the global economy. With1968that, I yield back. Thank you.1969    Chairman Barr. The gentleman yields. The gentlewoman from1970Ohio, Mrs. Beatty, is recognized.1971    Mrs. Beatty. Thank you, Mr. Chairman, and Ranking Member.1972    Ms. Strickland, I will start with you where Ranking Member1973Foster ran out of time, and so, I will pick it up there. He was1974making the point that one of the points outlined by the Bureau1975is that Section 1033 only allows CFPB to write rule-granting1976consumers access to their financial data, and it does not allow1977for sharing that data with third parties.1978    Would consumers not be harmed most if they do not have the1979ability to share their financial information with third party1980tools and products to help them manage their financial well-1981being? Could you elaborate on that?1982    Ms. Strickland. Yes, I will be happy to. Yes, I do think if1983consumers get access to their own information in a machine-1984readable format, that is great. That is progress but the real1985benefit of open banking is their ability to direct the sharing1986and transporting of that data from a data provider to authorize1987third parties who have been adequately vetted to make sure they1988have the right privacy and security practices. If you do not1989enable that, I think it will frustrate consumers because what1990they are going to keep it on, their computer, and then they are1991to send a data recipients, and they are going to update it. It1992seems unworkable.1993    I also think of a downside to that which might be an1994unintended consequence, which I have touched on is that then1995the third parties are no longer under an umbrella that requires1996them to have rules about what they can and cannot do with that1997data once they receive it. They are not vendors of the data1998provider. What is it that they can and cannot do with that1999data? The 1033 rule did put restrictions on what they can use2000it for, which is the purpose of the transaction, right?2001    So, it did put some rules around, A, them being vetted and,2002B, that they actually had some requirements of their own when2003they received this data. Both of those aspects of the2004portability piece of this were very important.2005    Mrs. Beatty. Okay. Thank you so much for that. Mr. Morris,2006let me go to you. First, let me thank you for your work with2007America's Credit Unions. As you may be aware, I have a bill the2008Advancing the Mentor Protege Program for Small Financial2009Institutions Act, which is actually noticed in today's hearing.2010It would codify the Treasury Department's financial agent2011Mentor-Protege Program to encourage partnerships between large2012and small financial institutions, including credit unions.2013Codifying this program would help small and community financial2014institutions across the country increase their capacity,2015improve their relationship, lending business modeling, and even2016become a financial agent to Treasury.2017    Can you briefly discuss how this bill will help credit2018unions better serve their communities because I also look at it2019when we talk about open banking and technology? It is supposed2020to be new ways also to bring institutions together. I would2021like to hear your comments on that.2022    Mr. Morris. Thank you for the question. I think the Mentor2023Protege bill is one that aligns well with the cooperative2024nature of the credit union industry, and we are certainly2025supportive of it and ways to enable Minority Depository2026institutions (MDIs), small institutions to partner with their2027larger peers to learn best practices, learn how to comply with2028complex rules and regulations. Today, we have spoken about the2029costs of complying with a rigorous data privacy regime. It is2030certainly a mentor protege arrangement that can help facilitate2031learning among smaller institutions.2032    Mrs. Beatty. Thank you for that. I think I have time for2033one more question since I am down here on this row by myself2034that my colleague took great pleasure, Mr. Chair, Ranking2035Member took great pleasure in telling me that he was going to2036pull rank on me, and now I see why.2037    Let me address it also to Mr. Fields, our Ranking Member,2038thank you for letting me ask this last question. I will come2039back to you, Ms. Strickland.2040    Tell me your comments or thoughts on in the time I have2041left. What would happen if we abandoned Section 1033 which2042means that all of the consumer protections imposed on those2043third parties would also be rescinded?2044    Ms. Strickland. Thank you for your question. As other2045witnesses have mentioned, open banking does exist today and has2046been a developing practice in the United States for a few2047years. It would still continue, it just would not have the same2048framework around it, around, how does that data sharing work?2049What are the rules in terms of vetting these third parties?2050What are the obligations on the third parties?2051    It does phase out screen scraping. Yes, perhaps, it could2052have done it more directly, but it did phase it out and say2053once compliant data sharing APIs are employed, you cannot--2054screen scraping can be prohibited, which is, I think, very2055important for both the consumers' benefit as well as website2056security.2057    Chairman Barr. The time has expired.2058    Mrs. Beatty. My time is up.2059    Chairman Barr. The gentlewoman from California, Mrs. Kim,2060is now recognized.2061    Mrs. Kim. Thank you, Chairman Barr, Ranking Member, thank2062you for hosting this hearing. I want to thank all our witnesses2063for joining us today too. As you know, for too long, our2064Federal laws have not evolved to keep up with the issue of data2065privacy. As a result, we have seen States take action because2066we have failed to lead at the Federal level.2067    In California, we have implemented legislation such as the2068California Financial Information Privacy Act and the California2069Consumer Privacy Act. While the intent of these bills has been2070good, the unfortunate result is that the financial institutions2071have dual compliance obligations at the State and Federal2072levels. That, coupled with patchwork State laws, has made it2073both costly and very confusing for institutions as they have to2074comply with the jurisdictions in which they operate.2075    I want to ask my first question to you, Mr. Talbott. Can2076you explain how in States like California, which I am sure you2077are very familiar with the conflicting State privacy laws have2078created damaging dual compliance?2079    Mr. Talbott. I am sorry, I missed your last part.2080    Mrs. Kim. Yes, the damaging--how do these conflicting2081privacy laws have created damaging dual compliance?2082    Mr. Talbott. Sure. Thank you for the question. Thank you2083for your leadership with the financial literacy and wealth2084creation caucus as well as you and Mrs. Beatty. The challenge2085is in terms of the costs of compliance, the complexity, because2086financial services institutions are not exempt in California at2087the entity level, only at the data level. Any data that they2088use is not GLBA-compliant has to be mapped out and evaluated in2089terms of making sure they are compliant with the California2090laws that you mentioned. That is costly. That is time-2091consuming. Additionally, there are----2092    Mrs. Kim. Yes, can you talk about, like, the regulatory2093cost? What are the companies looking at when they have to2094develop these processes to meet those divergent State privacy2095laws?2096    Mr. Talbott. Sure, they have to assign personnel. They have2097to assign lawyers. They have to hire regulatory counsel.2098Outside counsel is usually hired. There are compliance experts2099that are brought in. The whole team that has been developing2100system for the financial institutions at the Federal level also2101has to spend time, if not create a separate team focused on2102California.2103    In addition, California changes their law frequently, and2104currently there is a current proposal to amend it. Now all of2105those changes have to be discussed and analyzed and executed,2106and that takes time and resources.2107    Mrs. Kim. Sure. Another issue I hear a lot about is the2108question of opt-out versus opt-in as it relates to data2109privacy. Ms. Kuehn, I want to ask you in the Gramm-Leach-Bliley2110Act can you explain to us why there was an intentional decision2111to offer consumers the ability to opt out rather than opt in?2112    Ms. Kuehn. Yes, so GLBA provides a requirement that2113financial institutions have to clearly disclose to consumers2114exactly what happens with their data and where they have2115choices about that data. They do that at the start of the2116relationship. If you are going to share data that is subject to2117an opt-out, you have to tell the consumer every year, hey, I am2118sharing your data, you can change your mind about it. The2119reason it did that was because there are a number of things2120companies do to share data the consumers sort of expect. I2121might not want to opt out of my bank sharing my data for2122certain purposes, but I might want to opt out, say, for a car2123dealer using it. You have those choices on an entity-by-entity2124level to do that.2125    Also, the privacy notices, I know people pick on them, but2126they are the subject of a lot of research and development to2127make sure that consumers can clearly understand in plain2128language exactly what is happening with their data and what2129choices they have.2130    Mrs. Kim. I think consumers are rightfully concerned that2131they have limited understanding about how their financial data2132is being utilized. That is why I think it is important that we2133also address the annual privacy notice that consumers receive.2134    Ms. Kuehn, can you talk about the annual privacy notice2135that a consumer receives, and what kind of research does the2136agency or agencies conduct to make notices more consumer-2137friendly?2138    Ms. Kuehn. Yes, the FTC and the bank regulators worked on2139the current form of the privacy notice. I think one of the most2140recent innovations is the understanding that the consumers do2141not necessarily need to get a repeat annual notice if, number2142one, their financial institution is not sharing it subject to2143an exception, meaning that the purpose their financial2144institution is sharing data for things like fraud prevention2145and to process their transactions.2146    Mrs. Kim. Can you quickly talk about when the last time the2147annual policy model form that FTC posted was revisited or2148reformed?2149    Ms. Kuehn. That was back when I was at the Federal Trade2150Commission, which was about 15 years ago.2151    Mrs. Kim. Completely outdated. I think that explains the2152reason why----2153    Mr. Moore [presiding]. Representative, the lady's time has2154expired.2155    Mrs. Kim [continuing]. Okay. Thank you. Thanks for2156answering that question.2157    Mr. Moore. The gentleman from the great State of Louisiana,2158Representative Fields is recognized.2159    Mr. Fields. Thank you, Mr. Chairman. Let me thank all the2160witnesses for being here, and I thank you for this hearing. I2161just have two very simple questions. The first question I want2162to ask Ms. Strickland. Lower-income families often rely on free2163and low-cost, third-party financial tools to plan their2164financial futures. When big banks restrict these tools by2165blocking data portability, who gets hurt? How does Section 10332166address this rule inequity?2167    Ms. Strickland. Yes, thank you for your question. I do2168think both predating 1033 and then under the 1033 rule, the2169goal was to encourage consumer commission data sharing and2170doing it in a responsible fashion so that data providers did2171not put up unnecessary hurdles to that data portability2172request. The third party had rules as well in terms of privacy2173and security obligations because they had that information and2174then not in the same regulated field as the banks do. There2175were important steps made to think through those issues to make2176sure responsible data transfers and data portability occurred2177at the consumer's direction.2178    As I mentioned, one of the things that many commenters2179remarked upon and is still unfinished business in the 1033 rule2180is how are you making sure that other parts of people's2181financial health are also included so that they can have that2182full picture of their financial wherewithal. One of the2183comments dealt with things like if you would have government2184benefits, like EBT. There were a lot of comments there about2185how does that community also able to aggregate the information2186about themselves? These were items that were considered to be2187like future rulemakings. I think they are really important so2188that there really is that complete picture that people can have2189a full understanding of their financial situation, are able to2190direct the use of products and services that benefit them, and2191that it is done in a way that treats the data providers, data2192recipients fairly and ethically so that the data transfers are2193well-managed. I do think it is an important step in terms of2194that ecosystem as well as future products that should be2195addressed.2196    Mr. Fields. Thank you. My next question is for Mr. Morris.2197Section 1033 rule had broad support precisely because it2198promotes competition and empowers consumers. Credit unions2199compete on service, not market power. How does maintaining the2200current system where big banks can block data access harm2201credit unions' competitive position in serving working2202families?2203    Mr. Morris. Thank you for the question. I think in terms of2204competition, 1033 can offer benefits to credit unions in a2205general sense that data portability is helpful for consumers to2206switch financial institutions. However, we do have concerns2207around the CFPB specific implementation of Section 1033, the2208cost of API development, the lack of a framework for allocating2209liability of a third party's mishandled data, as well as2210concerns around the type of nonstatutorily enumerated data2211elements that the CFPB will want to see shared, like sensitive2212payment information.2213    So, while we think that the statute is good in the sense2214that it provides a core principle of data portability, there is2215work to be done, in our view, on refining the final rule.2216    Mr. Fields. I want to thank you, Mr. Chairman. I yield2217back.2218    Mr. Moore. The gentleman yields back. The gentleman from2219Wisconsin, Representative Fitzgerald, is recognized.2220    Mr. Fitzgerald. Thank you, Chairman. Mr. Morris, from your2221perspective, how does overlapping or inconsistent enforcement2222approach impacted your member credit unions' ability to2223innovate and serve their customers efficiently? What role2224should Congress play in ensuring Federal regulators do not2225stifle credit union-led innovation that is already subject to2226any different State-level scrutiny?2227    Mr. Morris. Thank you for the question. I think there are2228areas of inconsistency in terms of the patchwork of State2229privacy laws just in terms of how different types of data are2230handled, whether you are opt in, whether you are opt out,2231whether there is specific regulation targeting a technology,2232like artificial intelligence. Certainly, those are areas where2233credit unions can leverage technology to innovate, provide2234better fraud detection and prevention, for example.2235    On the Federal regulatory side, I think some of the2236inconsistency can arise simply due to the fact that these2237technologies are evolving at a very quick pace. It may be2238beneficial for there to be pilot programs or other ways to test2239innovative products without necessarily the fear of compliance2240driving those innovation decisions.2241    Mr. Fitzgerald. As a former State Senator, a lot of the2242work we did at the State level, I now have a different2243perspective of. Financial institutions like credit unions are2244always subject to robust Federal privacy requirements,2245including the regular oversight and enforcement by the2246regulators. There is a growing concern adding a Federal private2247right of action would trigger a wave of abuse of class action2248lawsuits, right? We have seen this in Illinois. We saw it in2249California with California Consumer Privacy Act (CCPA).2250    So these suits, obviously, often result in huge settlements2251with minimal benefit to consumers and kind of leave the small2252and mid-sized institutions exposed to sue or settle.2253    How would introducing a private Federal, private right of2254action for data privacy violations affect credit unions'2255ability to just serve their members, I guess?2256    Mr. Morris. Thank you. I think it would absolutely have a2257detrimental effect to include a private right of action and any2258comprehensive Federal privacy framework. Certainly, when you2259talk about the individual private right of action that might2260arise across however many States, that does have an impact2261across the board. It influences decisions, again, around2262innovation, but it can also just add to litigation costs and2263litigation risks. Those settlements can add up and detract from2264the core mission of credit unions, which is serving their2265communities with affordable products and services.2266    So, to the extent that litigation drives compliance costs2267or litigation costs up, that is money that is coming out of the2268community.2269    Mr. Fitzgerald. While the State privacy law wholly exempt2270banks and other institutions subject to Federal Gramm-Leach-2271Bliley Act law, there are some others, such as California2272Consumer Privacy Act, which I just mentioned, and a successor2273of the California Privacy Act. This obviously means that2274financial institutions will still implement programs to comply2275with the laws, even though it only applies to just a limited2276kind of subset, I guess you would say, of their data.2277    Ms. Kuehn, what is a level of effort for these compliance2278products?2279    Ms. Kuehn. I believe Mr. Talbott testified to this as well.2280You have to sort of map all of the data that you have. You have2281to have personnel involved with that. You have to have often2282bring out third-party technology companies to help you assess2283and it figure out which data is covered, which data is not. So,2284there is a compliance investment for financial companies that2285operate in California that may not exist elsewhere that have an2286entity-specific exemption, for example.2287    Mr. Fitzgerald. Chairman, I will just say that it is these2288kinds of legal burdens that drive financial institutions, like2289the credit unions and the banks, to kind of pursue the mergers2290in order to better absorb the compliance costs. With that, I2291will yield back.2292    Mr. Moore. The gentleman yields. The gentleman from Texas,2293Representative Green, is recognized.2294    Mr. Green. Thank you, Mr. Chairman. I thank the Ranking2295Member and the witnesses for appearing today. Mr. Chairman, I2296would also like to thank the Chairman, Mr. Barr, for honoring2297his commitment to bring H.R. 3716, as it is today, to the2298attention of the Congress again. This was done at a previous2299hearing.2300    Mr. Barr, if you are somewhere within the sound of my2301voice, or any place where you might find out, I am grateful. I2302am also grateful to the staff for helping us with this2303legislation. Many times when we say I, ``I'' is properly2304defined as ``we.'' The personal pronoun is rarely efficacious2305when it comes to passing legislation.2306    This legislation, H.R. 3716, deals with something that I2307hold dear, and it is the belief that the public has a right to2308know what Congress needs to know. This legislation satiates2309both of these concerns. I introduced this legislation--2310remember, ``I'' as ``we''--the Systemic Risk Authority2311Transparency Act on June 4, 2025. It was first introduced on2312June 14, 2023, in the 118th Congress. The legislation was2313developed following the failures of Silicon Valley Bank and2314Signature Bank in 2023 when the The Federal Deposit Insurance2315Corporation (FDIC) invoked the systemic risk exception to2316guarantee uninsured deposits at those banks.2317    The key provisions of this piece of legislation would2318include within 60 days of such an invocation of a systemic risk2319exception, the Government Accountability Office will be2320required to produce a preliminary post failure report. Within232190 days, the appropriate bank regulator, including the FDIC,2322the Office of the Comptroller of the Currency (OCC), and the2323Federal Reserve System (Fed)--or the Fed will be required to2324issue a preliminary post-failure report. Then, within 180 days,2325the Government Accountability Office (GAO) and the bank2326regulators will be required to issue a comprehensive post-2327failure report.2328    This timeline provides an opportunity for us to get some2329initial evidence of what happened, to get a better2330understanding, and then get a comprehensive report. More2331appropriately said, these reports will provide Congress and the2332public with an analysis to identify the causes of the bank2333failures, including any management, supervisory, or regulatory2334shortcomings. The committee passed similar legislation by a 50-2335to-zero vote last year.2336    Again, I see this as necessary legislation. Congress needs2337to know certain things, and these are the things that the2338public has a right to know. When banks fail, I think people2339need to know why and I think that they should know why without2340having to speculate.2341    I have found in life that where you have few facts, you2342have much speculation. This will provide the facts so that we2343can avoid speculation.2344    In closing, members of the panel today, this is a process2345that I used when I was a litigator. It is called voir dire, or2346voir dire depending on where you are from. We called it voir2347dire in Texas, and it requires you to tell the truth. It is the2348truth-telling portion of a trial.2349    So, this is a simple question for you. Given what I have2350shared with you about this legislation, given what you know2351about banking failures, given what you know about the public2352right to know what Congress needs to know, do you think this2353legislation would be helpful? If you think so, kindly extend a2354hand into the air. Was that question too complicated for you?2355Do you think the legislation would be helpful?2356    Mr. Talbott. I think we would have to take a closer look at2357it.2358    Mr. Green. Okay.2359    Mr. Talbott. I am happy to get back to you2360    Mr. Green. I will ask all of you to take a closer look and2361give me your opinions. Would you do this for me, please?2362    Mr. Talbott. Yes.2363    Mr. Green. Ms. Strickland?2364    Ms. Strickland. Certainly.2365    Mr. Green. Okay. Thank you. Thank you, Mr. Chairman, I2366thank all of you for your participation today. I know that this2367is without the lane that you normally negotiate and navigate2368and traverse, but I hope that you will give it some thought and2369give me an answer. Thank you so much. I yield back.2370    Mr. Moore. The gentelman yields. The gentleman from Ohio,2371Representative Davidson, is recognized.2372    Mr. Davidson. Thank you, Chairman. I am excited about this2373important hearing. Privacy is one of the most abused portions2374of the Bill of Rights. I mean, we have seen technology2375radically change what is possible since Gramm-Leach-Bliley2376became law. It is timely, relevant, probably a little past due2377that we update GLBA. Frankly, not long after GLBA laid a great2378foundation, the Patriot Act passed and massively expanded what2379the government was doing, and frankly, what the government was2380directing other people to do on its behalf.2381    Technology has grown rapidly over these 25 years, but2382especially fast since the innovation of artificial2383intelligence. I hope that we can kind of get the horse before2384the cart and not the other way around.2385    Privacy is really foundational. Before we can really get a2386correct framework for artificial intelligence, we really need2387to look at what is happening to the underlying data because if2388we have artificial intelligence laid out there, it only2389functions by having access to the data. If that data in the2390private hands is not cared for in the proper way, you are going2391to see it exponentially exploited by the technology that2392artificial intelligence is making possible.2393    I hope we get this right in short order.2394    Ms. Kuehn, your testimony highlights that GLBA's broad2395definitions of financial institutions in nonpublic personal2396information cover a wide range of entities and data.2397    During the evolving financial landscape, including the rise2398of fintechs, data aggregators, and whatnot, how would you2399recommend updating GLBA's definitions?2400    Ms. Kuehn. At this time, in my experience, it has pretty2401much covered anyone I have looked in the financial sphere. It2402is a large, flexible definition. It also covers not only the2403entities who are financial institutions themselves, but also2404entities that receive information under the Gramm-Leach-Bliley.2405There are restrictions on their ability to reuse or re-disclose2406the data they get.2407    It was surprisingly forward-looking and thinking about all2408the ways in which financial institutions and the endless2409financial industry are intertwined. It covers a lot of those2410uses that exist already.2411    Mr. Davidson. A lot of times we do regulation here in2412Congress is because we have committees of jurisdiction, so we2413do not really holistically solve problems. When you look at2414GLBA, it kind of says that we have one set of privacy laws for2415financial firms but then if you run a website or put automation2416into cars that really does quite a lot of surveillance in your2417automobile, it is governed by a whole different set of laws.2418Does it make more sense to have a comprehensive privacy law2419that recognizes that individuals have a property right in their2420data versus a sector-based approach? Does anyone have thoughts2421on that?2422    Mr. Talbott. Happy to, real quickly. Yes. I appreciate2423the--I think given the unique nature of financial services and2424the fact that we have both your account numbers as well as your2425money and your information, that it is unique versus other2426industries, but I think the rest of the marketplace could2427benefit from a uniform national standard.2428    Mr. Davidson. Thanks.2429    Mr. Morris?2430    Mr. Morris. I would agree that a sectorial approach is2431appropriate for the financial sector, just because we are2432already subject to so many laws and regulations. I think, to2433your point about other sectors maybe not having the same rules2434of the road. I think a comprehensive Federal privacy framework2435should address that.2436    Mr. Davidson. Yes. Here is an example. Google paid a2437small--for the scale of the size of the entity--fine because2438they set up the Android operating system, and they said that2439you could select ``do not track,'' for your geolocation, in2440theory, would not be tracked. When they were caught tracking2441everyone's geolocation, they said, Oh, no. What we meant was2442you could select do not track. We, of course, are going to2443track you.2444    That was pretty dishonest. I mean, that would not be just2445simple negligence, not really gross negligence. That was2446willful misconduct. They should have gotten in trouble for2447that.2448    Right now, because the FTC or Federal Communications2449Commission (FCC) would regulate a product like that, they put2450terms and conditions down in the fine print, five-point fonts2451with pop-ups that hit you until you relentlessly click okay,2452fine. I just want to get on with what I am trying to do, and2453there is not really much accountability for it.2454    Financial firms, I would love to say, are totally2455different, but Wells Fargo did not accidentally do what they2456did with consumer data and set up false accounts and2457everything. They paid over $4 billion in fines, but no one was2458prosecuted. In other sectors, when you abuse the access to data2459or you commit fraud, people go to jail. I think we ought to2460consider much stronger privacy protections, and I hope we do.2461    I yield back.2462    Mr. Moore. The gentleman yields.2463    The gentleman from Nebraska, Representative Flood, is2464recognized.2465    Mr. Flood. Thank you, Mr. Chairman.2466    The topic of today's hearing is extremely important. Data-2467sharing is at the center of financial interactions and2468transactions. In many cases, a consumer's data has to be shared2469between many parties in order to even fulfill a transaction.2470Let us use the example of a consumer applying for a mortgage to2471demonstrate the point.2472    The consumer initially applies for their mortgage with2473their lender. They need to provide documentation verifying2474their income, their assets, their liabilities, their2475employment, among other things, in order for that application2476to be complete. At that point, the lender uses those pieces of2477information from the consumer's application to determine2478whether or not to approve the mortgage.2479    They have to go to the credit bureaus to get the consumer's2480credit report. The consumer's credit score needs to be polled,2481involving the credit scoring companies. They may go to another2482bank to verify information regarding the borrower's assets.2483They may go directly to the consumer's employer to verify their2484employment. Then an underwriting decision needs to be made.2485Sometimes the lender will work with an outside underwriter who2486would also need to access all of the same information that we2487discussed in order to even confirm their credit risk and2488compliance with local relevant loan programs.2489    After all of those steps are complete, and many more I did2490not name for the sake of time, it is possible for the lender to2491make an informed decision on whether or not to approve the2492mortgage.2493    Think about all the different third parties I just2494mentioned that were involved in completing just one act for the2495consumer, filing a mortgage application. We live in a world2496today that is far more complex than it was 10, 20, 30 years2497ago, and we have relationships between financial institutions2498and third parties today that did not exist when the Gramm-2499Leach-Bliley was written. That, in a nutshell, is why we are2500having this conversation today. When you layer on the fact that2501some States are now moving in competing directions as it2502relates to rules around sharing and protecting your consumer2503financial data, you have even more complexity to the underlying2504problem.2505    Mr. Talbott, in your testimony, you mentioned some examples2506of conflicting State privacy laws. Can you please describe an2507example of conflicting State law on data privacy that you feel2508really represents the broader problem that I just talked about?2509    Mr. Talbott. Yes. I think that California, unfortunately2510again, is probably the lead example where it has both private2511right of action which do not exist in any other State, as well2512as it does not exempt GLB entities--does not exempt the--does2513not exempt the entity. It exempts the data. In California, for2514example, the B2B transactions are covered by that State's2515privacy law, whereas the rest of the country, it is not. That2516is a challenge right there.2517    Mr. Flood. For those of us, Mr. Talbott, that are2518interested in open banking, how should we think about a Federal2519financial data privacy law and how that could ensure that the2520consumers' information is both protected while also leaving the2521door open for them to choose to use tools that are offered by2522third parties?2523    Mr. Talbott. Yes. So, the entities engaged in open banking2524or consumer-directed banking are already covered by GLBA, so2525the privacy protections and the data security protections are2526there. To the extent that an entity, maybe a fourth party, is2527not, it should be, given the fact it will have data or access2528to the data. So, that is an important structure that is already2529in place.2530    Mr. Flood. Ms. Huddleston, can you speak to some of the2531results of the private right of action connected to the2532Illinois Biometric Information Privacy Act?2533    Ms. Huddleston. As mentioned in my written statement, we2534have seen significant litigation against a variety of entities.2535This includes small timekeeping entities; this includes large2536social media companies, like Meta. It also includes people2537that--or entities that one might not traditionally think of2538with data, like Six Flags Amusement Park. This litigation has2539not only been when actual harm occurs. It has also been over2540statutory issues, such as the exact method of the language of2541consent or things like that then become overly burdensome on2542launching new products.2543    We have also seen products not being launched in Illinois2544because of a concern around compliance. This, of course, means2545that the residents of that State do not have the benefits of2546some of the better technologies that might improve security2547through the use of biometrics, as well as fun things like2548Google's Art Selfie match a few years ago.2549    Mr. Flood. I am a strong believer in States' rights. I2550served in a legislature, like our Chairman here, both in the2551role of speaker. This is the one area that I do think we need a2552national standard. I truly believe that this only happens if2553Congress acts and we can let people do business. That is the2554reason I put that mortgage application example in there.2555    I will go to bat for States' rights whenever I can. This is2556one of the few times that I think this is a very appropriate2557direction. I thank Chairman Barr for his leadership on this2558issue and would love to deal with this in the 119th Congress.2559    Thank you, and I yield back.2560    Mr. Moore. The gentleman yields.2561    We would like to thank all of our witnesses today for2562taking the time to be here and for your testimony on behalf of2563all the committee members. We do appreciate that.2564    Without objection, all members will have 5 legislative days2565to submit additional written questions for the witnesses to the2566chair. The questions will be forwarded to the witnesses for2567their response. Witnesses, if you receive those, we please ask2568that you respond no later than July 10th, 2025.25692570    [The information referred to can be found in the appendix.]25712572    There being no further business before the committee, the2573Chair declares the hearing adjourned.25742575    [Whereupon, at 12:16 p.m., the subcommittee was adjourned.]25762577                                APPENDIX25782579                              ----------25802581                   MATERIALS SUBMITTED FOR THE RECORD25822583[GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]25842585                                 [all]

Witnesses

5 witnesses appeared, with 15 papers on file.

NamePositionPapers
Ms. Rebecca KuehnPartner, Hudson Cook, LLPBiography · Testimony · Truth in Testimony
Ms. Zoë StricklandSenior Fellow, Future of Privacy Forum (FPF)Biography · Testimony · Truth in Testimony
Ms. Jennifer HuddlestonFellow in Technology Policy, Cato InstituteBiography · Testimony · Truth in Testimony
Mr. Scott TalbottExecutive Vice President, Electronic Transactions AssociationBiography · Testimony · Truth in Testimony
Mr. Andrew MorrisDirector of Innovation and Technology, America's Credit Unions (ACU)Biography · Testimony · Truth in Testimony

Documents

The committee filed 4 documents for the meeting.