Newsroom
September 22, 2014
GAO report echoes NAFCU concerns with CFPB data collection
A Government Accountability Office report Monday on CFPB's data collection activities echoes numerous concerns raised by NAFCU regarding privacy and security procedures that should be enhanced by CFPB in implementing its data collections.
The report is in response to 12 different large-scale data collections by CFPB.
"NAFCU, in its comment letter to FHFA in May, highlighted some privacy and transparency concerns regarding the data collection efforts of the FHFA and CFPB," Meyster said. "This GAO report notes many of the same concerns, and we'd like to see even more from the CFPB in terms of transparency and accountability when it comes to its data collection efforts."
The GAO report found that "CFPB lacks written procedures and comprehensive documentation for a number of its processes, including data intake and information security risk assessments." GAO recommended that CFPB establish written standards for its data intake, making data anonymous and assessing and managing privacy risk, among other things. It also noted that CFPB has not yet fully implemented a number of privacy control steps and security practices and recommended that the bureau obtain periodic, independent reviews of its privacy processes, and update its remedial action plan.
GAO also expressed concern over compliance with the Paperwork Reduction Act and recommended that CFPB consult with the Office of Management and Budget about "its credit card collection and data-sharing agreement."
The report is in response to 12 different large-scale data collections by CFPB.
"NAFCU, in its comment letter to FHFA in May, highlighted some privacy and transparency concerns regarding the data collection efforts of the FHFA and CFPB," Meyster said. "This GAO report notes many of the same concerns, and we'd like to see even more from the CFPB in terms of transparency and accountability when it comes to its data collection efforts."
The GAO report found that "CFPB lacks written procedures and comprehensive documentation for a number of its processes, including data intake and information security risk assessments." GAO recommended that CFPB establish written standards for its data intake, making data anonymous and assessing and managing privacy risk, among other things. It also noted that CFPB has not yet fully implemented a number of privacy control steps and security practices and recommended that the bureau obtain periodic, independent reviews of its privacy processes, and update its remedial action plan.
GAO also expressed concern over compliance with the Paperwork Reduction Act and recommended that CFPB consult with the Office of Management and Budget about "its credit card collection and data-sharing agreement."
Share This
Related Resources
The Bottom Line on Insurance Tracking and Collateral Protection
Strategy
preferred partner
Allied Solutions
Blog Post
Resiliency In Your Incident Response Plan
Cybersecurity
preferred partner
DefenseStorm
Blog Post
Add to Calendar 2024-04-15 09:00:00 2024-04-15 09:00:00 Mergers and Acquisitions: Unifying Two Different Executive Total Compensation and Benefits Programs Listen On: Key Takeaways: [03:50] With the merger of a smaller credit union into a larger one you are really only dealing with integrating staff into the larger credit union. [05:53] When working with a merger of equals we start with a deep dive into the executive compensation and benefits of each organization. [09:09] If your current executive benefits provider doesn’t conduct regular plan evaluations, consider having a plan audit anyway. [13:46] Don’t overpay for these things if you don’t have to. When you have more options available that means the cost is more appropriate. [17:11] It is in a unified organization’s best interest to do tier timelines where we look at your top executives who are critical to the unified organization’s success today and then slowly add in the next levels. Web NAFCU digital@nafcu.org America/New_York public
Mergers and Acquisitions: Unifying Two Different Executive Total Compensation and Benefits Programs
preferred partner
Gallagher
Podcast
Add to Calendar 2024-04-11 14:00:00 2024-04-11 14:00:00 Regulation E: Impacts Across Your Institution Dive into regulatory excellence with, Regulation E: Impacts Across Your Institution. This webinar is tailored to empower you with the knowledge and strategies necessary to effectively implement the Electronic Funds Transfer Act (EFTA) and Regulation E within your operations. You’ll explore how to apply Regulation E across various business areas to ensure compliance obligations are met with precision. Key Takeaways Learn the basics of EFTA and Regulation E Understand how to apply Regulation E at your organization to detect processes and transactions that require Regulation E compliance Discover how Regulation E may apply to a large breath of areas in your institutions and functions for which you may rely on third-party vendors Review recent enforcement activity for non-compliance with EFTA and Regulation E Register Now $295 Members | $395 Nonmembers(Additional $50 for USB)One registration gives your entire team access to the live webinar and on-demand recording until April 11, 2025Go to the Online Training Center to access the webinar after purchase » Who Should Attend NCCOs NCRMs Compliance and risk titles Education Credits NCCOs will receive 1.0 CEUs for participating in this webinar NCRMs will recieve 1.0 CEUs for participating in this webinar Web NAFCU digital@nafcu.org America/New_York public
Regulation E: Impacts Across Your Institution
Credits: NCCO, NCRM
Webinar
Get daily updates.
Subscribe to NAFCU today.