August 10, 2026
Below you will find several key developments in the financial services industry, including related developments in information privacy and data security, from the past week. We add an "Amicus Brief(ly)1" comment to each item, where we briefly (see what we did there?) note for friends (and again?) of CounselorLibrary the important takeaways from the developments outlined in the email. Our legal reporters - CARLAW, HouseLaw, InstallmentLaw, PrivacyLaw, and BizFinLaw - provide more comprehensive, real-time updates of federal and state laws, regulations, litigation, and other industry items of interest. For a personal guided tour and free trial of any of these legal reporters, please contact Michael Willer at 614-855-0505 or mwiller@counselorlibrary.com.
FTC Will No Longer Pursue Disparate-Impact Claims Under FTC Act and ECOA
On August 7, the Federal Trade Commission issued a policy statement clarifying that it will no longer pursue claims based on disparate impact, following President Trump's "Restoring Equality of Opportunity and Meritocracy" executive order issued on April 23, 2025.
The FTC noted that the agency "has previously pursued disparate-impact claims in two contexts: under Section 5 of the FTC Act (where they have been styled as 'unfair discrimination' claims), and under the Equal Credit Opportunity Act ('ECOA'). In both instances, the FTC acted ultra vires. Section 5 contains no antidiscrimination cause of action, let alone a disparate-impact one. And while ECOA does prohibit intentional discrimination, it does not authorize disparate-impact claims."
The FTC determined that Section 5 of the FTC Act is a consumer protection statute, not an antidiscrimination statute. According to the policy statement, "Section 5 lacks any semblance of the most fundamental guardrails that one would expect to find—and does find—in every antidiscrimination statute," including a particular context in which discrimination is illegal, protected classes, and types of prohibited discriminatory acts or practices. Therefore, the FTC concluded that it lacks statutory authority to bring disparate-impact claims under Section 5.
While the FTC stated that the ECOA is an antidiscrimination statute, it found that the statute contains no "results-oriented language" that would "indicat[e] a focus on consequences of actions rather than a discriminatory mindset." Consequently, the FTC determined that disparate-impact claims cannot be brought under the ECOA because the statute creates liability only when there is evidence of an intent to discriminate.
As an additional reason for its decision to abandon disparate-impact liability, the FTC concluded that "[d]isparate-impact liability ... virtually compels regulated entities to engage in racial balancing (and other forms of balancing based on protected characteristics). In doing so, it violates the equal protection guarantee of the Constitution, runs contrary to the civil rights legislation, and harms businesses and the public by preventing businesses from making merit-based decisions."
| Amicus Brief(ly): This action by the FTC may be the final adjustment to the federal agencies' approach to ECOA discrimination claims. Following the administration's executive order from 2025, the Consumer Financial Protection Bureau and the federal banking regulators removed all references to the disparate-impact theory from their guidance and examination materials and made statements similar to those the FTC is making here. For those who are not versed in fair lending work, a "disparate-impact" theory of liability says that even facially neutral underwriting and pricing models with no clear indicia of an intention to discriminate against protected consumers can actually have an adverse effect on those consumers, where they see a less favorable result from the model than their non-protected counterparts. Because statistical studies have shown that the theory holds water, regulators had taken the approach of testing underwriting and pricing data for potential disparate impacts. If they detected any, they would ask the creditor for a business justification for the model. The administration now reads the ECOA to offer a cause of action only for intentional discrimination and has explicitly shut down the disparate-impact theory. With the FTC's policy statement, the federal consumer finance and banking regulators are officially out of the disparate-impact business. If the theory survives, it will be because Congress at some point amends the ECOA or because the states take up the cause. |
|
Illinois Amends Human Rights Act to Include Discriminatory-Impact Liability
On July 31, Illinois Governor JP Pritzker signed Senate Bill 3777 - the Civil Rights Safeguard Act - which amends the Illinois Human Rights Act. The amendments change the definition of "unlawful discrimination" to include discrimination "whether by purpose or effect." The amendments also, among other things, provide that it is a civil rights violation for any financial institution or a person who offers credit cards to the public in Illinois to use criteria or methods, including practices, policies, and groups of practices or policies, "that have the effect of subjecting individuals to unlawful discrimination. Such criteria or methods are unlawful if they are not necessary to achieve a substantial, legitimate, nondiscriminatory interest or if the substantial, legitimate, nondiscriminatory interest could be served by another practice that has a less discriminatory effect."
| Amicus Brief(ly): Speaking of disparate impact, it appears that not all minds think alike. Illinois has explicitly written the theory into its Human Rights Act, making clear that creditors in Illinois cannot fully set disparate impact aside. Other states, like New York, California, and New Jersey, have also taken steps to pick up where the federal government has left off in this context. As a result, it is difficult for creditors to relax their fair lending standards. And why would they? Practically speaking, creditors want to extend credit to creditworthy customers. When they do that, everybody wins. Creditors are constantly tweaking their underwriting and pricing models to see if new data can change outcomes by identifying applicants who may be more creditworthy than current and traditional models suggest. They test those models to ensure they're inclusive and do not leave out consumers who are a good credit risk, whether they are part of a protected class of consumers or not. Watch for other states to consider bills similar to Illinois' new law. |
|
Massachusetts Reminds Businesses of Money Transmission Licensing Requirements
On July 31, the Massachusetts Division of Banks issued a regulatory notice to remind parties involved in money transmission of the Commonwealth's new and more expansive domestic money transmission statute, found at chapter 169B of the Massachusetts General Laws, that was signed by Governor Maura Healey on January 1, 2025. Prior to the adoption of the new law, which became effective on January 1, 2026, Massachusetts only regulated foreign money transmission. The DOB's notice urges businesses to "immediately review their activities, determine whether licensure is required, and take appropriate steps to comply." If parties are engaged in licensable money transmission activities without having obtained a money transmitter license through the Nationwide Multistate Licensing System and Registry or if Foreign Transmittal Agency and/or Check Seller licensees have not transitioned to the new license, the DOB requires those parties to cease and desist those activities until they obtain the proper license. The DOB warns that failure to obtain a required license under chapter 169B could result in penalties, including civil penalties.
| Amicus Brief(ly): The DOB's FAQs on the revised licensing requirements make clear that companies that did not submit their licensing applications before July 1, 2026, cannot "engage in money transmission activities unless and until" they obtain a license. That statement, coupled with the reminders and public notices about the licensing requirements, underscores the agency's focus on ensuring that companies that need a license get that license (and comply with the statute's substantive requirements as well). The biggest addition in this updated and consolidated Massachusetts money transmitter law appears to be the inclusion of domestic payment apps among the companies that must have a license, which was evidently not the case before the change. But this reminder comes to us a little bit on the late side, with the effective date of the new law having passed months ago in January. Either way, Massachusetts is clear on its expectations, and money services providers should review the new statute and make sure they hold the license if necessary. |
|
New York Settles with Money Transmitter over Cybersecurity Deficiencies
On August 5, the New York Department of Financial Services announced that it entered into a consent order with a licensed money transmitter to settle claims that it violated the agency's cybersecurity regulation, 23 N.Y.C.R.R. Part 500. A DFS investigation conducted after the money transmitter experienced a ransomware attack in September 2022 identified deficiencies in the company's cybersecurity program and controls. According to the consent order, the company's cybersecurity deficiencies resulted in the following violations of the regulation:
- failure to conduct a risk assessment sufficient to inform the design of its cybersecurity program;
- failure to design a cybersecurity program based on the company's risk assessment and sufficient to identify and assess risks to nonpublic information; and
- failure to implement and maintain written cybersecurity policies addressing systems and network security.
The press release announcing the consent order claimed that the deficiencies left "the company exposed to vulnerabilities that could be exploited by threat actors" but noted that the company has remediated those deficiencies. Under the terms of the consent order, the company will pay a $250,000 civil monetary penalty. The DFS stated that, in assessing the penalty, it took into consideration the extent to which the company has cooperated with the investigation and the company's size and revenue, which exempt it from many of the regulation's requirements.
| Amicus Brief(ly): When a company, especially one whose model focuses on the movement of money, experiences a cyberattack, it's almost punishment enough to have to dig out of the hole the attack creates. Add to that an enforcement action suggesting that the company had not done enough to avoid the attack and a $250,000 civil penalty to drive the message home, and the subject of the attack and consent order has its hands full. Readers may recall that New York adopted a first-of-its-kind cybersecurity regulation in 2017 imposing numerous substantive requirements on "covered entities," including requirements to run periodic risk assessments that look for risks peculiar to the covered entities' businesses. The company subject to this consent order had evidently performed risk assessments that looked at operational and IT risks but did not consider the type of cybersecurity threat that ultimately struck the company. The lesson for "covered entities" is to make sure that the required periodic risk assessments look not only at cybersecurity risks generally but also the kinds of cyber risks that are specific to the company's business. That type of review is useful in a vacuum as a means of protecting the company's systems, but it can also catch new and evolving risks that could subject a company to expensive regulatory actions in the aftermath of the attack. |
|
FDIC Announces New Office of Supervisory Appeals
On August 4, the Federal Deposit Insurance Corporation announced that it replaced its Supervision Appeals Review Committee with a new Office of Supervisory Appeals. According to the FDIC's press release, the OSA is a standalone office within the agency staffed with independent officials who will serve as the final level of review of material supervisory determinations brought before the agency. According to Financial Institution Letter FIL-46-2026, which was released on the same day as the announcement, amendments to the FDIC's Guidelines for Appeals of Material Supervisory Determinations, which were approved by the FDIC's Board of Directors on January 22, 2026, took effect on the date of the announcement. The FIL Highlights state that an institution may appeal to the OSA after the appropriate division director's review of the material supervisory determination, and institutions now have the ability to appeal certain cases when an enforcement action is proposed or pending.
| Amicus Brief(ly): The newly established OSA replaces the existing committee with an independent office designed to take a fresh look at appeals from banks of exam findings. The amendments to the guidelines should help clarify for banks what kinds of findings are appealable. The stated goal of this change is to have an independent review of exam findings available to banks, where the examiners who made the findings are not part of the independent review team. That, along with the clarifications about appealable findings, is a sensible update. |
|
Massachusetts Issues Temporary Cease and Desist Order Against Check Cashing Business and Owners
On July 31, the Massachusetts Division of Banks issued a temporary cease and desist order against a check cashing business and its two owners, alleging numerous violations of the state's laws governing the operation of a check cashing business, including:
- failure to demonstrate the required character, reputation, integrity, and general fitness to maintain a check casher license;
- failure to demonstrate the financial responsibility necessary to maintain a check casher license;
- unlicensed check cashing activity; and
- failure to maintain adequate records and provide the DOB with access to books and records.
The DOB further alleged that the business and the majority owner knowingly participated in check fraud or an attempt to defraud and that the business engaged in unlicensed check cashing activity via a mobile unit. The DOB concluded that, based on the information in the cease and desist order, "had the facts and conditions found therein existed at the time of [the business's] original check casher license application, the Commissioner would have been warranted in refusing to issue such license."
The cease and desist order, which became effective immediately, requires the business to, among other requirements:
- immediately cease engaging directly or indirectly in the business of a check casher in Massachusetts;
- post a notice on its website and at its licensed location for individuals to contact the DOB with any unresolved complaint;
- secure all records, files, and documents and refrain from destroying, altering, and/or modifying any of those records, files, and documents;
- reimburse all fees collected for unlicensed activity; and
- request a hearing on the order by August 20 or the order will become permanent and final until modified or vacated by the Commissioner.
| Amicus Brief(ly): There are some damning allegations in this order against the company's owners, focused on a period in March and April of this year where the company deposited checks that did not clear at extraordinary rates - 61% of the checks the company deposited in March and a breathtaking 78% in April. The DOB attributes at least some of those returned payments to fraud, alleging that many of the checks were drawn on accounts for companies that had gone out of business and that the handwriting on many of those checks was similar. The DOB alleges other licensing irregularities, but we suspect that the fraud allegations will be the reason the order becomes permanent (assuming the company requests a hearing instead of folding up its tent) if the company cannot explain and disprove these allegations. |
|
1 For the unfamiliar, an “Amicus Brief” is a legal brief submitted by an amicus curiae (friend of the court) in a case where the person or organization (the “friend”) submitting the brief is not a party to the case, but is allowed by the court to file the brief to share information or expertise that bears on the issues in the case.