PogoWasRight.org

Menu
  • About
  • Privacy
Menu

Senators challenge head of Dodd-Frank agency on financial snooping

Posted on November 13, 2013 by pogowasright.org

Brendan Bordelon reports:

The director of Dodd-Frank’s chief enforcement agency clashed Tuesday with the ranking Republican on the Senate Banking Committee over the agency’s sweeping collection of Americans’ personal finance records.

Consumer Financial Protection Bureau (CFPB) Director Richard Cordray visited Capitol Hill to testify before the committee as part of a semi-annual report to Congress. But he spent much of that time defending his agency’s massive data collection program against Republican senators, chief among them Idaho’s Mike Crapo.

[…]

But after repeated pressing, Cordray finally confirmed that his agency is collecting data on 80 percent of the credit card market, information on individual transactions for around 900 million credit card accounts.

I’ll omit his justification for the data collection – even though there are legitimate privacy concerns to be raised about that – to focus on the data security concerns that accompany the privacy concerns. Although the government asserts the data are always “anonymized,” how easy would re-identification be, and are the data adequately secured?

Contracts with one third-party data firm indicate that the CFPB intends to maintain the postal code, census identifier and age of birth along with the financial information of 5 to 10 million Americans.

“We’ve had experience in other agencies where phenomenal abuses of this kind of information have been undertaken,” Crapo worried. “And all that is necessary for this massive amount of information being collected to be made available [to hackers] is for someone to find the key.”

Keeping sensitive data secure is a big concern at the CFPB. The Daily Caller News Foundation reported last week that Ashwin Vasan, the agency’s new tech head, has almost no experience in information technology.

And Pennsylvania Republican Sen. Pat Toomey discovered that data security flaws revealed nearly one year ago in a report by the CFPB’s inspector general have yet to be fixed.

“We have been working to adopt their recommendations,” Cordray said, “and we are paying very appropriate, precise, diligent attention to the privacy and security of this data.”

Senator Crapo asked the Government Accountability Office to review the CFPB’s data collection last summer, and the agency agreed to open a probe in July. The investigation remains ongoing.

Read more on Daily Caller. While Senator Crapo to focus on external threats to data security, I’d be just as worried about internal threats and the reported lack of contractor monitoring noted in the November 2012 report. I do not know which of the report’s recommendations the CFPB has already implemented and which remain a concern.

Category: BusinessFeatured NewsGovtU.S.

Post navigation

← Oregon woman falsely arrested after identity was stolen wins $100K lawsuit
NYC parents sue NYSED in state court over sharing data with inBloom; allege violation of state privacy law (UPDATED) →

Now more than ever

Search

Contact Me

Email: info@pogowasright.org

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

Categories

Recent Posts

  • Apple Siri Eavesdropping Payout Deadline Confirmed—How To Make A Claim
  • Privacy matters to Canadians – Privacy Commissioner of Canada marks Privacy Awareness Week with release of latest survey results
  • Missouri Clinic Must Give State AG Minor Trans Care Information
  • Georgia hospital defeats data-tracking lawsuit
  • No Postal Service Data Sharing to Deport Immigrants
  • DOGE aims to pool federal data, putting personal information at risk
  • Privacy concerns swirl around HHS plan to build Medicare, Medicaid database on autism

RSS Recent Posts on DataBreaches.net

  • Nova Scotia Power hit by cyberattack, critical infrastructure targeted, no outages reported
  • Georgia hospital defeats data-tracking lawsuit
  • 60K BTC Wallets Tied to LockBit Ransomware Gang Leaked
  • UK: Legal Aid Agency hit by cyber security incident
  • Public notice for individuals affected by an information security breach in the Social Services, Health Care and Rescue Services Division of Helsinki
©2025 PogoWasRight.org. All rights reserved.
Menu
  • About
  • Privacy