Last Week, This Morning

August 17, 2026

Below you will find several key developments in the financial services industry, including related developments in information privacy and data security, from the past week. We add an "Amicus Brief(ly)1" comment to each item, where we briefly (see what we did there?) note for friends (and again?) of CounselorLibrary the important takeaways from the developments outlined in the email. Our legal reporters - CARLAW, HouseLaw, InstallmentLaw, PrivacyLaw, and BizFinLaw - provide more comprehensive, real-time updates of federal and state laws, regulations, litigation, and other industry items of interest. For a personal guided tour and free trial of any of these legal reporters, please contact Michael Willer at 614-855-0505 or mwiller@counselorlibrary.com.

CFPB Ceases Publication of Complaint Narratives and Visualizations

On August 14, the Consumer Financial Protection Bureau ceased publication of consumers' unverified complaint narratives and visualizations in the Consumer Complaint Database. According to the CFPB's news release, "the publication in the Consumer Complaint Database of unverified complaint narratives and associated data visualizations is entirely discretionary. Many years of experience have demonstrated that the utility of such publication is minimal, while often causing confusion and providing misleading data. By their very nature, complaint narratives reflect negative consumer experiences and present only one side of an issue. Additionally, these unverified allegations do not always describe violations of the law[,] and the complaint process does not verify the allegations in each consumer's complaint narrative, nor can it, as a practical matter. Publishing such narratives in the Database provides a less-than-representative sample of one-sided experiences that cannot provide consumers with a balanced and accurate view of companies' compliance with their legal obligations. Publishing narratives and visualizations given these deficiencies risks confusing and misleading consumers, who should otherwise be able to rely on the Bureau for authoritative information as they choose the products and services that meet their individual needs. It also needlessly harms companies' reputations."

The Bureau is placing previously published consumer narratives in its Freedom of Information Act Reading Room.

Amicus Brief(ly): Good for the CFPB - no argument from us on this one. Our subscribers are companies focused on regulatory compliance and operating within the confines of federal and state law. It has never sat well with them (or us) that the CFPB's database published unverified consumer complaints for the world to see, effectively taking those complaints as facts and creating a sense that providers that were subject to those complaints were guilty until proven innocent. There are plenty of instances where the published consumer complaints were based on a simple misunderstanding of the customer. In other cases, disgruntled customers without legitimate disputes would post complaints about the customer's creditor, servicer, or debt collector simply because they were irritated about having accounts in collections. Posting those complaints publicly and without verification led to distrust of financial services providers. Consumers may still take complaints to the CFPB, state regulators, and state attorneys general, but they may be better served by taking legitimate consumer complaints directly to the company that can provide solutions to their concerns. However consumers react to this news, we are content to see the withdrawal of unverified complaints in the database.

California Privacy Protection Agency Obtains Orders Against Data Brokers for Delete Act and/or California Consumer Privacy Act Violations

On August 11, the California Privacy Protection Agency announced that it obtained a stipulated final order against a data broker, resolving allegations that the data broker violated California's Delete Act and the California Consumer Privacy Act.

The CPPA found that the company failed to register with the agency by the January 31, 2026, deadline for its data broker activity during the 2025 calendar year, in violation of the Delete Act.

Additionally, the CPPA found that the company violated the CCPA by requiring consumers to provide the last four digits of their social security numbers and mailing addresses before allowing them to opt-out of the sale/sharing of their personal information. According to the order, under the CCPA, a "business may not require consumers to submit verifiable consumer requests to opt-out of the sale/sharing of their personal information. A 'verifiable consumer request' is a request made by the consumer (or on behalf of the consumer) that the business can verify, using commercially reasonable methods, to be the consumer about whom the business has collected personal information." "At most, a business may ask consumers for information necessary to complete a request to opt-out of sale/sharing. However, the CCPA regulations are clear that 'to the extent that the business can comply with a request to opt-out of sale/sharing without additional information, it shall do so.' Requiring consumers to provide more personal information than necessary to submit a request to opt-out of sale/sharing violates the CCPA's data minimization requirements." In this case, the company provided an online form for consumers to use to submit requests to opt-out of sale/sharing. The form required consumers to provide their full name, their email address, the last four digits of their social security number, and their mailing address. The CPPA found that requiring consumers to provide part of their social security number and their mailing address unlawfully required consumers to provide more information than necessary to exercise their right to opt-out of sale/sharing.

The order requires the company to pay an administrative fine of $110,490 and a $6,000 fee to effectuate its 2026 registration for its data broker activity in 2025. The CPPA noted in its press release that "[its] decision imposes a substantial fine even though a mere handful of consumers submitted requests [to the company] to opt out."

A couple days later, on August 13, the CPPA announced another decision requiring a data broker to pay a $52,400 fine after failing to register with the agency's data broker registry.

Amicus Brief(ly): The real story here appears to be the fine for failing to register. The CCPA is not new, and the registration requirement is familiar and broad. So, what happened? This may be a case of a data broker existing before the CCPA and not staying up on legal updates - a failure of Regulatory Compliance 101. We have seen it before, where a business is comfortably operating in an unregulated space and simply misses a game-changing legal development (usually at the state level) because the company's compliance management system (if any) does not include a legal monitoring component. It's also possible that the company had a system and just missed the update, which would be even harder to explain. But that is all speculation.

State AGs Sue to Vacate OCC's Final Rules Regulating National Bank Escrow Accounts

On August 11, the attorneys general of California, Connecticut, Maine, Maryland, Massachusetts, Minnesota, New York, Oregon, Rhode Island, and Vermont filed a joint lawsuit seeking to vacate and set aside two rules issued in May 2026 by the Office of the Comptroller of the Currency that together purport to preempt state interest-on-escrow laws as applied to national banks and federal savings associations.

The first is the OCC's Preemption Determination: State Interest-on-Escrow Laws final rule that concludes that federal law preempts state laws that eliminate national banks' and federal savings associations' flexibility to decide whether and to what extent to pay interest or other compensation on funds placed in real estate escrow accounts and/or assess fees in connection with those accounts. Specifically, the final rule amends the OCC's real estate lending and appraisals regulations to provide that federal law preempts: (1) New York's interest-on-escrow law, which dictates a minimum interest that national banks must pay on funds held in escrow accounts and generally prohibits them from assessing related service charges; (2) similar laws in California, Connecticut, Maine, Maryland, Massachusetts, Minnesota, Oregon, Rhode Island, Utah, Vermont, Wisconsin, Guam, and the U.S. Virgin Islands; and (3) laws in other states that have substantively equivalent terms.

The second is the OCC's Real Estate Lending Escrow Accounts final rule that codifies longstanding powers of national banks and federal savings associations to establish real estate lending escrow accounts and to exercise flexibility in maintaining those accounts. The final rule: (1) amends the OCC's real estate lending and appraisals regulations applicable to national banks and its lending and investment regulations applicable to federal savings associations to add a definition of "escrow account"; (2) expressly codifies national banks' and federal savings associations' power to establish and maintain escrow accounts; and (3) clarifies that the terms and conditions of escrow accounts, including the investment of escrowed funds, fees assessed for the provision of such accounts, and whether and to what extent interest or other compensation is calculated and paid to customers whose funds are placed in the escrow account, are business decisions to be made by each national bank or federal savings association in its discretion.

Amicus Brief(ly): This case will be interesting to follow. Readers will recall that, in the aftermath of the U.S. Supreme Court's Loper-Bright decision, agency interpretations of the laws they administer are no longer entitled to Chevron deference from courts. That means that the courts are free to disagree with agencies like the OCC on issues like the OCC's preemption rule on escrow accounts. In light of the Supreme Court's most recent bank preemption cases, it is not at all clear that the OCC is going to prevail in this litigation by the states. If the case gets to the substance, the outcome will turn on whether the OCC can convince the court(s) that state laws requiring interest on escrow accounts significantly interfere with a national bank's or thrift's exercise of statutory powers. We will see.

Regulators of 47 States Reach $15.5 Million Settlement with Mortgage Servicer over Force-Placed Insurance Practices

On August 12, the Conference of State Bank Supervisors announced that the banking regulators of 47 states entered into a joint settlement agreement and consent order with one of the nation's largest mortgage servicers after discovering during a multistate examination of the servicer that it had imposed force-placed insurance costs on more than 4,200 borrowers who had active homeowners insurance policies, in violation of the provisions of the Real Estate Settlement Procedures Act and Regulation X governing force-placed insurance.

Force-placed insurance is a hazard insurance policy purchased by a servicer on behalf of the owner or assignee of a mortgage loan that insures the property securing the loan. Force-placed insurance is often required when a homeowner's policy is cancelled, lapses, or is insufficient in coverage and the borrower has failed to comply with the mortgage loan contract's requirement to maintain hazard insurance. Premiums for force-placed insurance are often much more expensive than a standard policy bought by the borrower.

The total amount of the settlement is $15.5 million, which is comprised of administrative penalties, costs, and consumer remediation. The mortgage servicer worked with state regulators to self-identify and proactively remediate more than $4.5 million to the impacted borrowers, and it will pay nearly an additional $11 million for costs and penalties. The mortgage servicer will be required to implement and conduct enhanced monitoring for loans that have force-placed insurance and implement other actions to strengthen controls.

Amicus Brief(ly): Ouch. The big penalties attached to this settlement on top of the $4.5 million in restitution to consumers will drive home for the mortgage servicer that its controls around force-placed insurance have to be sharper. According to the settlement, although the servicer did not admit or deny the allegations, it has "implemented, and will continue to maintain" procedures designed to ensure compliance with state force-placed insurance requirements and limitations. Though it is not clear from the announcement or the settlement, those procedures should ideally include system controls to monitor for borrowers' maintenance of required insurance and steps to comply with state notification requirements designed to allow borrowers a chance to obtain insurance to replace lapsed coverage. The settlement imposes a requirement for monthly transaction testing for newly boarded loans where the servicer has placed insurance in the past month - that should identify pretty quickly whether the servicer's procedures have achieved the desired results. This settlement serves as a useful reminder for mortgage servicers to regularly conduct transaction testing as part of their internal audit processes to catch this kind of issue before it blossoms into an expensive multistate investigation.

NYC Releases FAQs on Revised Debt Collection Rule

On August 10, the New York City Department of Consumer and Worker Protection released a "Frequently Asked Questions" document intended to provide guidance to regulated entities on its revised debt collection rule (the "SHIELD Rule"). The revised SHIELD Rule takes effect January 1, 2027. (Originally, it was scheduled to go into effect on September 1, 2026, but the DCWP delayed implementation earlier this summer.)

The FAQs address the scope of the SHIELD Rule and clarify that the entire SHIELD Rule does not apply unless and until a person engages in "debt collection procedures." The FAQs also:

  • provide guidance on how to deliver the mini-Miranda warning;
  • include examples of how to comply with the SHIELD Rule around the effective date (in particular, whether the revised debt validation notice is required if the initial communication occurs at the very end of 2026 and whether the debt collector must comply with the SHIELD Rule's verification requirements if the validation notice was provided before the effective date);
  • clarify that closing an account is not an appropriate response to a dispute or request for verification and that debt collectors must send the Notice of Unverified Debt (see template at https://www.nyc.gov/site/dca/businesses/templates.page#debt);
  • attempt to distinguish between the "front-end itemization" provided in the validation notice and the expanded itemization required if the debtor disputes any item in the front-end itemization. (Based upon the FAQs, it appears that for creditors that accrue interest and other charges on the account, there is little difference between the front-end itemization and the expanded itemization.); and
  • reiterate that a debt collector is not required to conduct collection communications in the consumer's preferred language except in very specific circumstances.

The list above is not exhaustive but highlights some of the more useful guidance in the FAQs (which, in certain places, simply restate the SHIELD Rule).

The FAQs may be subject to further revision. The FAQs note that the DCWP will update the document as appropriate. Creditors and third-party debt collectors should periodically check the DCWP Business/Licenses - Debt Collector tab to ensure they have the most current version (indicated by the date in the lower left-hand corner of each page).

Amicus Brief(ly): The DCWP did not give us much with these FAQs and responses. Rather, the FAQs appear to function more as a summary of the SHIELD Rule for those who have not had a chance to read it yet (or who did not believe what they read). Too bad because this was an opportunity to provide some interpretive gloss on parts of the rule and to make its position on some of the thornier questions clear. It is not a complete disappointment, though. For example, the DCWP provided a template for the required Notice of Unverified Debt. The FAQs are a living document, so the DCWP could (and hopefully will) come back at a later date and provide additional clarification of the rule.


1 For the unfamiliar, an “Amicus Brief” is a legal brief submitted by an amicus curiae (friend of the court) in a case where the person or organization (the “friend”) submitting the brief is not a party to the case, but is allowed by the court to file the brief to share information or expertise that bears on the issues in the case.