▶ 0:30:22Committee on Financial Services will come to order. Without objection, the chair is authorized to declare a recess of the committee at any time. Today's hearing is entitled Updating America's financial privacy framework for the 21st century. Without objection, all members will have five legislative days within which to submit extraneous materials to the chair for inclusion in the record.
▶ 0:30:44I now recognize myself for 4 minutes for an opening statement. Good morning. Today's hearing will examine the current state of consumer financial data policy and potential reforms to the Gramm-Leach-Bliley Act or GLBA. I want to begin by emphasizing the importance of maintaining the technology neutral framework of Gramm-Leach, which has readily adapted to innovation for over a quarter century.
▶ 0:31:10And has the tools to continue to adapt as technology goes in directions that we cannot predict. We will also consider potential additions to the Gramm-Leach framework to give consumers greater control over their data while maintaining the smooth provision of financial services, to give financial institutions greater clarity about their obligations, and to promote competition and increase consumer choice.
▶ 0:31:35As we As we consider these changes, we're working closely with our colleagues down the hall in the Energy and Commerce Committee to create a workable and comparable set of federal policies for consumer data while accounting for the nuances of the different types of firms, products, and services in our respective As we consider additions to GLBA, we must strike a balance to achieve consumers' desire for greater control over their financial data on one hand,
▶ 0:32:06and on the other hand their desire for financial services to work as seamlessly as possible and without having to wade wade through a sea of checkboxes and As we consider additions like access rights, deletion rights, and data minimization standards, we must craft them in a manner that imparts greater control, but without the unintended consequences that, for an unwitting deletion request could have on a consumer's smooth receipt
▶ 0:32:37of financial services. We must also recognize that the states have been running 26 years of With the results from these laboratories of democracy in hand, it's clear the time is now for a federal standard. Nationwide uniformity will promote competition by lowering barriers to entry created by the current state patchwork, which disincentivizes firms from entering new state markets and competing on price for the ultimate benefit of our consumers.
▶ 0:33:06Nationwide uniformity will also give consumers greater choice by making products currently only available in some states available to all. As we consider these and other changes to Gramm-Leach, we must above all be humble as the original authors who knew two key things. One, they could not predict what course technological innovation would take.
▶ 0:33:29And secondly, they took a cautious considered approach that allowed for flexibility and innovation was the best best path forward. I urge all of this all of our members on both sides of the aisle and our work on this subject to use a scalpel, not a sledgehammer. And I really look forward to our panel of witnesses today. I yield back. I recognize the ranking member of the committee, Mrs. Waters, for 4 minutes for an opening statement. Uh thank you, Mr. Chairman.
▶ 0:33:57In today's digital world, every click, search, and purchase leaves a trail. Yet Americans remain powerless when it comes to how their data is being used, shared, and sold. Companies pay millions of dollars to access it, to analyze it, and profit from it. But not a penny of those profits goes to consumers.
▶ 0:34:21And when that information falls in the wrong hands, it is weaponized against the very people it belongs to. This is exactly the risk we're facing now. Trump's administration ignores basic privacy guardrails and treats Americans personal information like political pawns.
▶ 0:34:42For example, this administration has reported they handed over sensitive personal data to the Department of Homeland Security to to target immigrants living in the United States including people who are here lawfully and have been here for years. Information that people living in America trusted the government to safeguard is now being weaponized to track, monitor, and intimidate entire communities.
▶ 0:35:12At the same time, Trump officials are punishing artificial intelligence companies like Anthropic of far refusing to hand their technology over to the Department of Defense to conduct mass surveillance on Americans. And now we're learning uh that Donald Trump wants to turn banks into ICE checkpoints by requiring banks to hand over their customers data.
▶ 0:35:39My Republican colleagues repeatedly decry the intrusive tactics of the Chinese government but are silent when Trump wants to deploy them here. Everyone in America should be alarmed, but this isn't the only turbulent thing happening. Trump and Republicans are trying to dismantle the very federal agency responsible for protecting consumers, the Consumer Financial Protection Bureau.
▶ 0:36:08The CFPB was created after the financial crisis to protect consumers from abuse and to enforce safeguards around Americans financial data. It has returned billions of dollars to consumers and held bad actors accountable.
▶ 0:36:30But instead of strengthening this agency, Republicans have spent years attacking it and with Trump, their efforts have been intensified. Republicans voted to slash funding for regulators and weaken the federal workforce responsible for enforcing consumer protections. This means fewer investigators watching the marketplace and fewer protections for hardworking families.
▶ 0:36:58It also means Trump officials have let bad actors who admitted to ripping off consumers and even agreed to pay damages off the hook completely. Meanwhile, credit bureaus and data brokers continue to collect and sell Americans' most sensitive financial information every single day.
▶ 0:37:22Without strongest guardrails in place, that data can be exploited not just by corporations looking to profit, but by bad actors eager to steal and use this data. Committee Democrats believe Americans should have the right to control their own data. Plain and simple, consumers should decide who gets access to their information and how it is used.
▶ 0:37:51And we must strengthen, not weaken, protections to make sure data brokers, law enforcement, and most importantly, the Trump administration cannot misuse our personal information. Protecting Americans' data is not just about privacy, it's about protecting our financial security and for our freedom and our basic rights. Right, now
▶ 0:38:16That is exactly what this committee should be focused on here today. Thank you very much.
▶ 0:38:21Right, remember you're recognized. Chair recognizes the chair of the subcommittee on financial institutions, Mr. Barr, for 1 minute for an opening statement. Thank you, [clears throat] Mr. Chairman. Good morning. For over 26 years, GLBA has readily adapted to new technologies, new types of financial firms, and new types of data. In that same 26 years, the states have had ample opportunity to test different approaches, and the results are clear. It is time for a national framework. Financial institutions should have consistent obligations.
▶ 0:38:51All American consumers should have the same choices for financial products and services, and competition and innovation should be promoted by making it easier to enter new markets. During a similar time period over the past few decades, we have also seen the drawbacks of private rights of action.
▶ 0:39:07We must resist the temptation to pursue this enforcement mechanism that would do nothing more than lead to fewer consumer options for financial products and services, potentially limit what options remain to only the well-to-do, and pad the pockets of the trial bar at the expense of consumers. Thank you, and I yield back. Gentlemen, yield back. Chair recognizes the ranking member of the subcommittee on financial institutions, Dr. Foster of Illinois, 1 minute opening statement.
▶ 0:39:32Thank you, Chair Hill, and to our witnesses. In in today's data-driven economy, financial institutions, tech companies, merchants, and many others collect vast amounts of information on American consumers, and that's not going to change in the coming era of agented commerce when the very first thing that happens when my agent starts talking to your agent is that they both do the equivalent of scrolling down and hitting I accept, including on some very complicated and important privacy agreements.
▶ 0:39:56Since Congress enacted Dodd-Frank Wall Street Reform Act, the CFPB has been led much of the federal government's efforts to protect Americans' financial data. They proposed rules from Dodd-Frank to implement open banking that would have given consumers control over their data and increased competition by making it easier for consumers to switch to a different bank. The bureau was improving oversight over data brokers who gather and share troves of sensitive data on consumers.
▶ 0:40:21While I appreciate the focus of on data privacy by this committee, Americans would be best served by allowing the CFPB and its dedicated staff to continue their important work. Look forward to hearing from our witnesses. Chairman Hill is back. Today we welcome the testimony of our panel, Mr. Nathan Taylor, partner at Morrison Foerster, Ms. Claire Kim, senior vice president of Bank Policy Institute, Mr. Steve Bombs, the executive director of Financial Data and Technology Association, Mr. Jordan Crenshaw, senior vice president US Chamber's Technology Engagement Center, and [snorts] Ms.
▶ 0:40:51Laura McQuery, senior director for policy and advocacy at Unidos US. Want to thank each of you for being with us today. Each of you will be recognized for 5 minutes to give an oral presentation to your testimony for your testimony, and without objection your written testimony will made be made part of the record. We'll start with you, Mr. Taylor. You're recognized for 5 minutes. Chairman Hill, Ranking Member Waters, members of the committee, my name is Nathan Taylor. I'm a partner at the law firm Morrison Foerster.
▶ 0:41:22I've spent my legal career advising financial institutions on compliance with financial privacy laws, including Title 5 of the Gramm-Leach-Bliley Act. For more than 20 years, I've closely monitored the evolution of privacy law in the United States. I'm pleased to be here today to to discuss my views on the GLBA and whether there is a need, and if so, the appropriate way to modernize the GLBA.
▶ 0:41:51Since it was enacted in 1999, the GLBA has stood as the cornerstone of financial privacy law in this country. The GLBA is founded on two core pillars. First, the GLBA requires that a financial institution provide consumers with a privacy policy detailing its privacy practices.
▶ 0:42:12Over the past 25 years, I estimate that financial institutions have mailed their customers several billions of privacy Second, the GLBA prohibits a financial institution generally from disclosing non-public personal information about a consumer to a non-affiliated third party without first providing the consumer with the opportunity to opt out of the This opt-out right is significant providing consumers with meaningful
▶ 0:42:42control over the disclosure of their non-public personal information. In my view, the GLBA and the privacy rights that it includes are as meaningful in 2026 as they were in 1999. Of course, over the last 25 years, privacy law has developed significantly in this country.
▶ 0:43:04Since Since California enacted the California Consumer Privacy Act in 2018, we have seen rapid development of privacy laws throughout this country. These state privacy laws typically include rights that are not found in the GLBA, such as access and deletion And this, of course, begs the question, is there a need to to modernize the This question is debatable.
▶ 0:43:30What is not debatable, in my view, is that any updates to the GLBA must be done with care, with a clear understanding of the context in which the GLBA applies. Financial products are fundamentally different than, for example, social media accounts or online advertising that have been significant drivers behind the state privacy laws. In fact, the CCPA and the state laws that have followed it impliedly recognize this fact.
▶ 0:44:00These state privacy laws do not apply to information that's subject to the GLBA. Let me underscore this point. The state privacy laws that include rights not found in the GLBA do not themselves extend those rights to the to information that's subject to the GLBA. So, back to my original question. Should the GLBA be modernized?
▶ 0:44:25First, I want to highlight that I believe the GLBA has stood the test of time, providing consumers with meaningful control over the disclosure of their non-public personal information. Nonetheless, in recognition of the evolution of privacy rights in this country, I do think it would be appropriate to update the GLBA to include certain additional rights. If this committee moves forward, I believe that any legislation should should include three principles.
▶ 0:44:55First, I believe that a consumer should have a right to request that a financial institution provide the individual with access to or a copy of the non-public personal information that the financial institution maintains about the Second, an individual who is a former customer of a financial institution should have a right to request that the financial institution delete non-public personal information that it maintains about the individual.
▶ 0:45:24Finally, a bill should preempt state While I recognize that this point can be controversial, I believe that all Americans should be empowered with the same strong privacy rights for their financial information, regardless of the states in which they may live. The alternative, in my view, is an inequitable result. Thank you for the opportunity to speak with you today, and I'd be happy to address any questions that you might The gentleman yields back.
▶ 0:45:55And with that, Ms. Kim, you are now recognized for 5 minutes for an opening statement. Thank you. Um Chairman Hill, Ranking Member Waters, and honorable members of the Committee, thank you for the opportunity to testify today. My name is Clara Kim, and I am a senior vice president at the Bank Policy Institute. Collectively, our banks employ nearly 2 million Americans, make half of the nation's small business loans, and are an engine for economic Financial institutions occupy a unique position in our economy.
▶ 0:46:23To keep the financial system safe and to serve customers effectively, banks must collect, use, and retain data in ways that are different from many other sectors. They have obligations under law to prevent fraud and illicit activity, and they rely on consumer financial data to do that work. This data is necessary for other activities and services, such as underwriting a mortgage for a first-time home buyer, or extending credit in underserved communities.
▶ 0:46:48In the decades since the Gramm-Leach-Bliley Act established federal privacy standards for financial institutions, many banking services have evolved from a brick-and-mortar, face-to-face experience to an always-on, digital experience. But, while the technology of banking has transformed, GLBA has consistently awarded avoid afforded consumers strong baseline privacy and information security Banks operate under a comprehensive regulatory framework for privacy and data use.
▶ 0:47:15These requirements are implemented and enforced through continuous supervi- supervision by federal prudential regulators. That combination, GLBA plus prudential oversight, has produced a robust, sector-specific federal privacy regime that has worked for more than 25 years to protect consumers while allowing banks to perform their essential The core principles of GLBA have worked well since it was established.
▶ 0:47:40In considering changes to the GLBA framework, it will be important to consider the potential for unintended GLBA was designed for financial institutions with careful calibration between privacy protections and the legitimate, legally required uses of data that keep the system safe and inclusive. It has also proven adaptable. The federal regulators have updated implementing rules over time as technology, cyber threats, and consumer expectations have evolved.
▶ 0:48:07A key principle for any legislation in this area must be a national, uniform financial privacy and information security standard with strong, clear federal preemption. Today, comprehensive state privacy laws are typically drafted for a broad universe of entities, some of which are in the business of monetizing data. Almost no other sector has the same responsibilities as banks in terms of using data to manage fraud and credit risk or that is subject to the same degree of prudential supervision.
▶ 0:48:34Recognizing this the distinct role of financial institutions, legislatures in most states have chosen to exempt GLBA regulated entities. Where state laws do reach into financial services, they can unintentionally interfere with core banking activities that can harm consumers or create conflicting obligations layered on top of the existing federal regime. Any modernized GLBA should provide a single, preemptive national standard for the privacy and processing of personal information by financial institutions.
▶ 0:49:04To the extent Congress looks to incorporate concepts from state privacy laws, we urge a principles-based approach that respects the specific risk profile and legal obligations of financial institutions. Any new limits on collection, use, or retention should allow banks to gather and use information as necessary to provide requested products and services and for clearly disclosed purposes. If Congress is considering expanded individual rights, it is vital those rights be carefully tailored to the realities of banking.
▶ 0:49:34Deletion and similar rights must be reconciled with existing obligations, as well as with the need to preserve evidence of suspicious or criminal activity. Data minimization and similar concepts must be implemented in a way that does not inadvertently curtail essential internal uses, such as fraud detection, cybersecurity, risk management, and the development of alternative underwriting models that can expand access to to credit for underserved communities.
▶ 0:50:01There's also room, in our view, to further streamline GLBA's notice requirements without changing the underlying balance of rights and Consumers expect a single, clear privacy notice that is easy to find and GLBA could be updated to better accommodate the use of a unified, plain language notice, often made available online, that explains how data is collected, used, and safeguarded.
▶ 0:50:25Finally, one of GLBA's strengths is its technology-agnostic and principles-based approach, which allows banks and regulators to adapt to rapid changes without constantly rewriting the statute. If additional guardrails for emerging technology become necessary, they can and should be addressed through tailored guidance, rather than by embedding technology-specific mandates into GLBA. There's also the risk that any prescriptive requirements could quickly become outdated as well. Thank you for your attention, and I look forward to your questions.
▶ 0:50:54Gentle lady yields back with that. Mr. Bombs, you are recognized for 5 minutes for your oral remarks. Thank you very much, Chairman Hill, Ranking Member Waters, and members of the committee. Thank you for the opportunity to testify today. My name is Steve Bombs, and I am the executive director of the Financial Data and Technology Association, or FDATA. We represent a diverse ecosystem of fintech companies and open banking platforms that empower over 100 million Americans and small businesses to better manage their financial lives.
▶ 0:51:24The rapid growth of the fintech sector has invited injected vital competition to the marketplace, driving down costs and facilitating the efficient delivery of financial Whether helping consumers build savings through automated round-up apps, preventing fraud in real time, or helping small businesses manage their books or secure capital through alternative underwriting, these tools provide tangible benefits to everyday At the heart of this ecosystem is trust.
▶ 0:51:49Our members believe that consumers and small business owners must have full control over their financial data, including the right to share it with third parties, the right to have it protected when they do so, the right to understand how it is being used, and the right to withdraw their consent from it being accessed at any time. This open banking framework should be the lodestar for any modernization of federal data privacy laws.
▶ 0:52:10There is a common misconception that FinTechs operate in a regulatory vacuum regarding privacy, but this is not the The Gramm-Leach-Bliley Act already unequivocally applies to the data and entities in the open banking ecosystem. This coverage is established through three mechanisms.
▶ 0:52:24First, the significantly engaged test, which applies to any entity significantly engaged in performing financial activities as a regular part of its Second, the 2021 Finders Rule, which expanded the definition of a financial institution under the Act to include entities that bring together buyers and sellers in the financial marketplace. And third, service provider provisions, which mandate that platforms operate under a lattice of bilateral agreements that contractually require GLBA-level security and privacy features.
▶ 0:52:52Under this umbrella, open banking platforms are subject to prescriptive data security and privacy requirements, including providing customers with clear, conspicuous privacy notices at the point of interaction, employing robust data encryption protocols, deploying continuous penetration testing, and complying with data breach notification requirements, among many As the committee considers amendments to the GLBA, it is vital to distinguish these customer permission platforms from data brokers. That distinction hinges on affirmative, explicit consent.
▶ 0:53:22FDATA members access data only because a customer has provided permission to receive a specific service, such as a budgeting or a payment tool. Conversely, data brokers often acquire and sell data through secondary means without the customer's direct Open banking platforms are strictly bound under the GLBA and contractual terms by consumers or small businesses explicit consent and the rigid data minimization requirements of their requested use case.
▶ 0:53:48Applying data broker regulations to customer permission to open banking intermediaries risks negatively impacting competition and consumer FDATA supports a single, robust, and federally preemptive data privacy A fragmented 50-state regulatory patchwork creates massive compliance hurdles, disproportionately harm small startup and innovators, and favors large incumbents. This also results in a highly inequitable system where consumers or small business owners' fundamental privacy rights are dictated entirely by their zip code.
▶ 0:54:18Because data within it is already so heavily regulated under the GLBA, financial services represents one of the few marketplaces in which Congress can leverage a federal regime that already broadly applies and has served customers well for nearly 30 The GLBA is a logical vanguard for a national data privacy standard. The current decentralized approach to data protection and privacy in the US is also at odds with the singular frameworks that have been deployed in other jurisdictions, including the EU and the United Kingdom.
▶ 0:54:44These jurisdictions have deployed regimes that could attract fintech and investment capital that might otherwise be deterred by the increasing complexity of the US market. As it considers amendments to the GLBA, uh we urge the committee to consider four critical pillars in any consideration of revisions. First, we urge Congress to ensure that any new requirements do not inadvertently impede the rights of consumers to access, move, or use their own data.
▶ 0:55:07Second, consumers and small businesses should have the right to control data sharing, including to terminate that sharing immediately, with narrow exceptions for legal or regulatory Third, in the open banking context, the responsibility for correcting inaccurate data must remain with the data provider, the source, and not the platform acting as a secure conduit. And fourth, Congress should maintain the GLBA's agency enforcement mechanisms to ensure continued customer protection without harming innovation and competition. Thank you again for the opportunity to testify.
▶ 0:55:36FDATA's members remain committed to providing your constituents with innovative, secure financial products, services, and tools, and I look forward to your questions. Chairman yields back. With that, Mr. Crenshaw, you are recognized for 5 Thank you, Chairman Hill, Ranking Member Waters, and members of the committee for the opportunity to testify on today's hearing about updating America's financial privacy framework for the 21st My name is Jordan Crenshaw, and I serve as senior vice president at the US Chamber of Commerce's Technology Engagement Center.
▶ 0:56:04For nearly a quarter century, the Gramm-Leach-Bliley Act, or GLBA, has provided a reliable foundation for financial privacy. Now, as we look toward the future of data privacy, rather than creating a new framework, modernization efforts should focus on updating existing law through targeted policies that strengthen clarity, streamline compliance, and preserve the law's proven protections.
▶ 0:56:24My testimony today will focus on four key priorities for any federal privacy First, we must establish strong federal preemption to ensure a uniform national standard harmonizes with state rules. While modernizing the GLBA is important, the broader need for Congress to pass comprehensive national privacy legislation to ensure true uniformity across the country cannot be overstated.
▶ 0:56:46With a growing patchwork of state privacy laws, consumers face confusion, and this complexity disproportionately impacts small businesses, which often lack the resources to manage multiple regulatory regimes. A 2022 report from ITIF highlighted that a fragmented privacy landscape could cost the US economy $1 trillion over 10 years, with 200 billion of that burden falling on small businesses.
▶ 0:57:07In a recent report from the Chamber on the impact of technology on US small business, we found that 65% of small businesses nationwide are worried about having to comply with a patchwork of state privacy, AI, and technology regulations, which would drive up legal and compliance costs. That number is even higher in the financial services context for small businesses. That number is 71%. Businesses and consumers need a clear and consistent federal privacy law, which is why any updates to GLBA and any future national privacy legislation must avoid duplicative regulations and promote harmonization.
▶ 0:57:38The bipartisan consensus approach, which has emerged in states like Kentucky, Texas, Minnesota, Iowa, Florida, Tennessee, and Nebraska, for example, provide a good example on how to do this. Second, we must have clear, predictable enforcement mechanisms. The Chamber supports enforcement authority being vested in appropriate federal and state agencies. For example, GLBA regulated entities should be under the jurisdiction of their appropriate banking and financial regulators.
▶ 0:58:03Other entities regulated by general consumer privacy law should be under the jurisdiction of the Federal Trade These entities have the expertise and resources to enforce privacy laws while effectively maintaining a balanced approach that encourages compliance and However, the Chamber strongly opposes private rights of action to enforce The 17 states that have adopted the consensus privacy approach have explicitly rejected private lawsuits.
▶ 0:58:27Private rights of action have historically led to abusive and exploitative litigation with plaintiffs' attorneys benefiting disproportionately from settlements, providing little relief to consumers, and creating inconsistent enforcement as individual judicial districts may interpret privacy laws differently. Third, we must preserve access to data that enables socially beneficial uses, innovation, and risk management. We know that data is a cornerstone of the modern economy and critical in solving our societal challenges.
▶ 0:58:54From improving public safety and health care to enabling financial inclusion and combating fraud, data-driven technologies have transformed how we solve complex problems. While data minimization is critical to safeguarding consumer privacy and security, standards that are too strict could impede innovation and the ultimate goal of protecting people and systems. We have seen states that have passed the consensus privacy approach have enacted balanced and workable minimization standards.
▶ 0:59:19By contrast, states like Maryland have enacted stricter data minimization requirements that could limit companies' ability to use personal data for important things like anti-fraud protection and help law enforcement with things like preventing against criminal activity and human As Congress considers updating GLBA, the final point I'd like to leave the committee with today is that the Chamber stands ready to help with recommendations regarding issues like consumer notice, access, deletion, and opt-out rights.
▶ 0:59:42In conclusion, the US Chamber of Commerce urges Congress to modernize GLBA in a manner that provides regulatory certainty and also adopt broader comprehensive privacy Both efforts should include strong federal preemption to eliminate a patchwork of state laws and provide a uniform standard for businesses and consumers. Best enforcement authority with proper federal and state agencies while avoiding private rights of action that lead to abusive litigation and inconsistent enforcement.
▶ 1:00:09And strike a balance on data minimization to protect privacy while enabling the beneficial uses of data that drive innovation and address societal challenges. By addressing these priorities, Congress can ensure that the United States remains a global leader in innovation, innovation, economic growth, and consumer protection. Thank you for the opportunity to testify today. I look forward to working with Gentleman yields back. I appreciate all the succinctness today. Nobody's running over. That's unusual on this in this With that, last but not least, Ms.
▶ 1:00:39McCleary, you are recognized for 5 minutes. Thank you so much for the opportunity to testify. My name is Laura McCleary. I'm senior director for policy and advocacy at UnidosUS, the nation's largest Latino civil rights organization with an affiliate network of 300 plus community groups. I've spent 25 years working for the public interest to support democratic systems, consumer protections, and civil rights.
▶ 1:01:01I wrote an amicus brief for the Congressional Hispanic Caucus defending the privacy rights of taxpayers, and I recently published an article in the ABA Journal calling on states to lead on data privacy under state constitutions. Latinos are a growth engine for the economy but underserved by financial institutions. The GDP of US Latinos was $4 trillion in 2025, a total that ranks them fifth among nations.
▶ 1:01:27Yet, low-income Hispanic households are unbanked at rates nearly five times that of comparable families. So, Latinos need high-quality financial services alongside privacy rules that build trust and keep their personal data I offer thoughts on the discussion draft in my written testimony, including that opt-outs in GLBA fail consumers because they default to the least protective But, the draft's most troubling feature is that it preempts states on data privacy and security.
▶ 1:01:56When Congress wrote GLBA, it specifically allowed states to go above a federal floor. California enacted opt-in consent. States like Colorado, Connecticut, Virginia, and more followed suit. The draft would block this progress while failing to raise standards, and the CFPB mainly would be charged with enforcing For context, industry has worked to undermine the authority of the CFPB since its creation. Most major initiatives challenged in court.
▶ 1:02:24The agency's funding went up to the Supreme Court in a case we joined as amicus. The agency won, but last summer Congress slashed its budget anyway. Now, it's a hollow shell with few examinations ongoing and even an oath of humility for Consumer complaints at credit agencies are up. Efforts to level rules of the road for participants across the financial marketplace withdrawn. Enforcement actions dropped or ending in collusive settlements that perpetuate injustice.
▶ 1:02:52In short, consumers would be at the mercy of an agency actively dismantling basic marketplace fairness standards rather than enforcing them. This federal government also cannot be trusted to safeguard anyone's privacy. Taxpayers were promised for decades that information they gave to the Internal Revenue Service would be kept confidential.
▶ 1:03:11Yet, the IRS was asked to share 700,000 records, then 7 million, then 1.28 million, and finally sent 47,000, which a federal judge said 2 weeks ago means the IRS broke the law at least 42,695 DHS initially asked for home addresses, employers, relatives, banking information, IP addresses, and social security or taxpayer identification The headlines are clear.
▶ 1:03:40Data surveillance is an urgent concern, and AI scales it. It makes scams and fraud more credible, and surveillance pricing is being used to micro target consumers and rip them Any 21st century privacy framework must grapple with what this means for fair markets, financial services, and our Here's one way it works.
▶ 1:04:03Whenever an ad appears on the internet, a bundle of your data has been sent to a global auction, which returns a personalized appeal. Those data can include your health concerns, addictions, children's names, ages, schools. With a little effort, almost anyone can know where we sleep, who we know, what we think, click, or buy. Under our Freedom of Information Act, people can request to see what the government has compiled about them.
▶ 1:04:29Access rights are a baseline, alongside meaningful data minimization and deletion rights. I've personally wondered what we might learn if lawmakers had the temerity to ask commercial data data brokers about the deeply personal information being collected about them and their families. Ordinary people can't get this information today, but perhaps lawmakers could. It may be illuminating.
▶ 1:04:50Given technology that we have right now and its increasing capabilities, we must ask ourselves what sort of government what sort of power a government has if it can know everything about everyone all of the time. A genius of both GLBA and our system is checks and balances. Distributed authority means states can provide accountability when people need it. Still, we're not close to being ready. What the states have accomplished is important, but it's just a start. The truth is that data privacy is democratic infrastructure.
▶ 1:05:21We won't be able to keep our First Amendment freedom of speech or Fourth Amendment freedoms against unreasonable search and seizure if we fail to create stronger legal protections for data rights or allow ourselves to experiment to find out what works for consumers. So, if the key question on the table today is whether states should continue to be able to protect people on data privacy and security, my answer is yes, because leadership by these laboratories of democracy is our current best hope. Thank you very much to the panel.
▶ 1:05:51We'll turn to member questions. I recognize myself for 5 minutes for questions. Mr. Taylor, I want to talk start out on the topic of technological neutrality. You know, when Gramm-Leach-Bliley and group wrote GLB back in 1999, they had internet was brand new and uh we were preparing for Y2K, and so technology was a booming topic. The stock market was booming with new technology innovations.
▶ 1:06:17And so, people had no idea which way how technology would evolve. It's amazing how well this law's functioned over the last 25 years. I mean, So, could you tell us the benefits of trying for us as Congress to maintain that technological neutrality approach and you know, are there changes specifically you'd call for in our our It's It's a terrific question, and I was harkening back to the Y2K. We've come a long way.
▶ 1:06:50I mean, I think the key that that Congress achieved in '99 and that hopefully this committee will achieve in 2026 is to future-proof it. Future-proof the GLBA, ensure that come what may, regardless of what types of new new financial products we might come up with or new types of financial that the same exact law applies across the board and I think that Congress achieved that in 1999 with the with with its notice and opt-out rights that apply regardless of
▶ 1:07:20the nature of the financial product or service at issue, regardless of the information at issue, regardless of the type of financial institution at issue. Thank you. Uh likewise as we work to clarify this, we're really sensitive to the customer experience which has been a lot of the advocacy on the part of fintech companies and traditional financial institutions that have worked really hard to enhance their customer service, but that does create this, you know, conflict. Um So, Ms. Kim, let me turn to you.
▶ 1:07:51How do we strike the balance between consumers control of their data with, you know, this idea of low friction delivery in financial services while we also maintain the full effectiveness of the privacy features in GLBA? Uh yes, thank you for your question. Um in our view, um the notice and opt-out works because it gives that combination. It gives choice and it is simplistic.
▶ 1:08:17It is a way to balance consumer control of where their information goes, um plus the added benefit of all the effective points um underlying GLBA. Um so, any kind of adjustment would, in our view, require some careful tailoring to not interfere with um information that is necessary, for example, for uh fraud prevention or legal holds. Just as a uh switch Thank you for that. Sw- just staying with you for a minute.
▶ 1:08:47Um most state consumer privacy laws uh exempt either GLBA um compliant institutions or GLBA compliant data, and this is important because that's one of the great strengths of Gramm-Leach is that all those authorities and protections out to anyone in that ecosystem connected to a compliant financial institution. But a lot of the states seem to be moving toward adopting a data level only sort of exemption.
▶ 1:09:16That doesn't sound in keeping with Gramm-Leach. Would you agree with that, Ms. Kim? And what should we How should we reflect that? Uh yes, uh would definitely agree with that. Um uh the data exemptions that you mentioned, um what What happens is it kind of forces these dual compliance regimes. So you have, you know, GLP GLBA for the nonpublic information that is covered, and then you have state rules for other other types of data. Um this results in overlapping notices, in- increased costs.
▶ 1:09:45hard to program your customer experience in that regard and keep track of it. I mean, is that part of the problem?
▶ 1:09:51lot of the costs will trickle down to the customers as well. So, um our our uh recommendation for that would be um any modifications to the GLBA to include very strong federal preemption. Mhm. Um Mr.
▶ 1:10:05Bombs, over the years that I've been in Congress, there's been a lot of conversation in the fintech space and certainly in previous privacy hearings that we've had screen scraping uh and the preference for a lot of businesses uh for the use of APIs to protect people's data from hacking and mistakes. Uh How do you feel we've adopted that in our approach? And how do you Where should we go from here on screen scraping? Thank you, Mr. Chairman.
▶ 1:10:34Uh so, first I would just say that everybody in the ecosystem would like to move more towards APIs and away from screen scraping. Fintechs, banks, data providers, everybody. Ultimately, it's up to the data provider, which in this case is the bank, to make that determination of whether to make an API available or not. And you raise an important reality, which is that larger financial institutions typically have the resources available to deploy the APIs. Smaller ones don't.
▶ 1:10:58If you Oh, all of you if you'd expand on that answer in in writing, it'd be helpful to us to make sure we get this right for all participants in the space. I yield Turn to the ranking member of the full committee, Ms. Waters, for 5 minutes for
▶ 1:11:12Thank you very much, Mr. Chairman. Um as we consider the issue of data I was just sitting here thinking about the fact that I and other members of this committee and thousand several thousand other people were outside the Treasury Department uh after Elon Musk and some of the individuals who worked for him and his companies, SpaceX and uh
▶ 1:11:42had gone into the Treasury and had access to Treasury payment systems as well as sensitive databases at the Consumer Financial Protection Bureau. Now, uh not only did Elon Musk and those who are not government employees, those that he brought in to work with him, I suppose, uh to do whatever it is the president had created DODGE to do, uh but Elon Musk
▶ 1:12:12is a government who should not have access uh to uh government information in all these other agencies, but this is all very And it's been alarming how the Trump administration has tried to shut down the Consumer Financial Protection Bureau, robbing consumers of the only federal watchdog focused on protecting And last week, we learned from a whistleblower
▶ 1:12:42uh that a former DODGE who had access to the Social Security may have shared social security data uh with the private employee that they went to work for. All of this is quite alarming with respect to the DOJ's access to data at the CFPB. I introduced a resolution of inquiry so we could learn more about what DOJ was up to.
▶ 1:13:12What information is gaining uh access to and what has it done with the sensitive data. Ms. McClary, I want to thank you for being here today. um I want to ask what should our committee do um to get this resolution taken up in this committee to investigate and better understand how the administration may have inappropriately accessed and used sensitive data of millions of people and business.
▶ 1:13:43It's unfair for me to ask you this when we're sitting here elected by the people to protect their private data and we have a president of the United States of America who disregards all of this, doesn't care about any of this, and Elon Musk and others who now have this data, they have this information.
▶ 1:14:04So thank you for being here uh but I suppose I could ask you while we have an administration who thinks like this and who exercises extraordinary power to get access to our private data and all of the people of this country, uh do you have any thoughts about what could or should be done? Thank you so much for the question. It is a matter of public trust.
▶ 1:14:34um what was interesting in the litigation um between the IRS and DHS over taxpayer privacy was that when the court ordered the administrative record to see what the exchanges were. The The documents clearly showed that the privacy personnel within the IRS were sidelined in the process of filling these requests. The administrative record is um lengthy, but it has a lot of the back and forth of the details.
▶ 1:15:05And uh we've now learned that even the way that they had styled the request, they did it wrong. They failed to follow their own interpretation of the law and about 2,000 plus cases and they've had to admit that in court. So, I would say you can file Freedom of Information Act requests. You can work with outside groups. Yuri Meyer, the CFPB's former chief technologist, did submit a sworn affidavit in a case about DOJ access.
▶ 1:15:32He said no CFPB employee had ever been granted blanket access to all unclassified data, that the staff typically has to request access only to specific systems, of course, and have it approved by a supervisor. But DOJ staff began examining systems the same day they walked in. He described their access level as god tier. I think there's a lot that we don't know about what's happened at the agencies.
▶ 1:15:55And the more they see, the more the courts have been troubled by the failure to follow even basic information security protocols, the government's own kind of rules for who can access what and for what reason. And uh there's a lot to dig in there. So, I would suggest, you know, you do the use the legal tools that we all have available to ourselves to do what you can to develop the record.
▶ 1:16:18General Woman's time has expired.
▶ 1:16:19Thank you so very, very much.
▶ 1:16:21recognizes the vice chairman of the full committee, Mr. Huizenga from Michigan. You're recognized for 5 minutes. Thank you, Chairman Hill. I'm actually going to take your final question to uh Mr. Bombs and ask everybody to very, very briefly expand kind of a yes or no, uh do you think that the GLBA needs to be clarified with With to screen scraping? That was the chairman's question. Give us a little preview of what your written answers are going to be. Mr. Taylor, do you think yes or no? Candidly, I don't have a strong view. Okay. Ms. Kim?
▶ 1:16:51Uh would believe in a general ban, but maybe GLBA is not the right place to do so. Okay. Mr. Bombs? Screen scraping is still a critical fallback option for millions of consumers. And so, we don't believe that there should be a ban, and we don't think GLBA is the right place.
▶ 1:17:04And if I recall correctly, that was partially because of the size question or size issue that you were bringing up. That's correct. Mr. Crenshaw? Uh likewise, no strong view. Okay. Ms. I'm sorry, could you repeat the question? Uh would do you think GLBA needs to be clarified with regarding to screen scraping? Uh Um I do think it would be helpful to have protocols that encourage APIs um and standards for them. All right. Um Mr. Bombs, I'm going to come back to you.
▶ 1:17:31Do you believe that data aggregators are currently covered by GLBA title five, and in your view, is the law clear on this? Yeah, Congressman Congressman, thanks for the question. Uh yes. The FDATA FDATA's members, including the data aggregators or open banking platforms, our members all believe and act as if the GLBA applies to them. As I mentioned in my testimony, there are three primary ways through the GLBA that they qualify as financial institutions.
▶ 1:17:56That includes the finders provision, uh it includes the uh service provider provision, and the significantly engaged test. So, the answer is yes. Okay. Mr. Taylor, you're nodding your head. I it's Yeah, I I completely agree. I mean, I would highlight that when analyzing the definition of financial institution, it is technically complex, right? You have to refer back to section 4K of the Bank Holding Company Act. And then you have to refer to Reg Y, and you have to go through and and evaluate various permissible activities.
▶ 1:18:24But I would agree that under the the financial and bank data processing uh activity, that financial data aggregators are covered. Okay. Uh Mr. Crenshaw, in your testimony, you spoke about the dangers of including a private right of action under GLBA. Can you expand on that a little bit for the committee as well as help us understand how a private right of action creates inconsistent enforcement? Yes, happy to do so.
▶ 1:18:49One of the main concerns we have is that there is an incentive when you create private rights of action, particularly statutory violations, that it incentivizes lawsuits that seek settlement and don't actually help We've seen many reports, even one from the CFPB, that showed the average class action only gets $32 for a plaintiff or sometimes they get credit monitoring.
▶ 1:19:10minute. It's not about the money back to the those that have been injured? That's that and many of these class action, that's the case.
▶ 1:19:17I'm I'm I'm shocked that lawyers might be taking a large chunk of that. Okay, go ahead.
▶ 1:19:22But but but going back to the district district interpretation piece, it also incentivizes running to different courthouses and you get a different interpretation of the law everywhere you go. I'll give you one example that's happening right now. There's
▶ 1:19:33shopping is real. It's real. But there's also the California Invasion of Privacy Act, which is a wiretapping statute which is only meant really for telephonic communications, listening in on someone's phone call. What we've seen because of the statutory violations that go with that law, a rush to sue anyone who has a website with basic internet functionality that collects to sue under that invasion of privacy statute.
▶ 1:20:00And for example, there's a case right now in the Southern District of California where Adidas is is named as a defendant and a judge has allowed that case to proceed, which means they have to go through discovery. They have to go through litigation costs. Then you have another district in in the Northern District of of California that has not allowed a case like this to go through. And so, when you have private rights of action, it incentivizes a rush to the courts and you don't get one interpretation much like you on the other hand would get under a regulatory agency that's making calls through clarifications.
▶ 1:20:30Okay. Mr. Taylor, real briefly, how important is it for Congress to avoid creating two federal financial data regimes? I mean I think it's I think it's clearly important that we have a single set of standards that applies across the You saw me pause in response to your question because of course the devil's in the details about how you define financial privacy because we have other federal laws like the Fair Credit Reporting Act and the right to financial
▶ 1:20:58Does that does what Mr. Crenshaw was he describing does that seem reasonable? About no
▶ 1:21:04This court this court case with Adidas. About no about the disincentive or about why we should not have private rights of
▶ 1:21:11Yeah, fully agree with everything you said. Okay. Mr. Bombs finish up with you. How about I totally agree. All right. With that Mr. Chairman I will yield back. Gentleman yields back. Gentleman from California the ranking member of our Capital Markets Subcommittee Mr. Sherman you're recognized for 5 minutes. First one to comment on this invasion of our privacy at the IRS.
▶ 1:21:32I headed the second largest tax agency in our country before I came to Congress and we have a vested stake in assuring taxpayers that their tax information will only be used for tax collection. We want to encourage tax compliance. But what worries me more is a president who says he wants to deport the worst of the and then he goes after taxpayers. Let me assure you drug kingpins do not file tax returns.
▶ 1:22:02We've been discussing the CFPB. Remember they've got 19.7 billion dollars returned to Americans, 5 billion dollars in civil penalties, but that isn't the most important thing. It's not remedying the abuse that's most important, it's preventing the abuse. We have fine police officers in Los Angeles and sometimes we rate them based upon the crimes they solve.
▶ 1:22:30But what's most important to me is the crimes they So unfortunately, uh the majority party, at least in the executive branch, has defunded the police. Those namely the police that prevent crime in the sweets rather than the streets. Uh consumer advocates have a tendency to object to federal preemption.
▶ 1:22:57that's reason, you know, that comes from the fact that often federal preemption uh brings us down to the lowest common denominator, the weakest standards, and they're imposed nationwide. Uh I tend to think that we can have national preemption when we have a high standard. Uh standard that matches the best of the states in the country rather than the weakest.
▶ 1:23:23And there are some advantages to preemption, chief among them reducing expenses that banks incur. And keep in mind, we saw with these tariffs that when you impose costs on corporations, eventually those costs are passed through to consumers.
▶ 1:23:42but the other advantage, of course, of national standards is half the country lives in states where they don't have good consumer protection, and getting protection for them is uh almost as important as getting protection for who live in uh great states like we need better third uh regulation of third-party fintech companies with databases because it makes little sense to say we're protecting your data when it's in
▶ 1:24:12the bank uh computers, but then it can be transferred to other computers, and it's not as well protected. Now, my first question, uh rule 1033, is being developed or was developed. The rule didn't ban Ms.
▶ 1:24:35Kim, what amendments or guidance do you have for improving the CFPB rule whether it's adopted at the regulation at the administrative level or by us in Congress. Should we consider developing rules in this space to ensure financial data is safeguarded and should we prohibit screen scraping? Thank you for the question.
▶ 1:25:02Yes, we know the CFPB is working on a rulemaking to address the issue and we look forward to seeing what they put out and making sure if customer financial data is appropriately protected in all We believe access to to customer data held at a bank should be governed by the GLBA to avoid inconsistency and unintended consequences.
▶ 1:25:25And we support extending GLBA like protections for customer data when it leaves the bank and enters into the data aggregation And overall, yes, we would support a general ban on screen scraping. Under the proposed rule or rule that's been stayed, institutions could not charge a fee for these third-party fintech companies to access the banks through their API Ms.
▶ 1:25:54Kim, how costly is it to develop and maintain these portholes and should we consider allowing institutions, particularly smaller institutions, for allow them to charge a fee? Yes, thank you. We are paying attention to certain data exchanges that make the financial system safer by transitioning industry away from dangerous practices like screen scraping and toward APIs. Gentleman yields back.
▶ 1:26:23Chair recognizes the gentleman from Oklahoma, Mr. Lucas, who chairs our task force on monetary policy. You're recognized for 5 minutes. Thank you, Mr. Chairman. Let's start with you, Ms. Kim. Let's pull back up once again and look at the overall situation. What's the status quo and why might we need to update a few provisions of the Gramm-Leach-Bliley Act? Having served with Chairman Leach and Chairman Bliley, I still refer to it by the full Uh yes, thank you.
▶ 1:26:49Um I mean, we believe that GLBA is a simple but effective um framework for privacy and information security. So, any changes that we would recommend uh include things, as I mentioned in my testimony, uh strong, fully preemptive GLBA to ensure predictable standards across the board.
▶ 1:27:08Um secondly, we we definitely advocate for maintaining its technology neutrality and principles-based standards because we believe that is what has made it so relevant today. Continuing with you, Ms. Kim, the discussion draft that the chairman has noticed for the hearing codifies several rules and regulations currently in What challenges do banks face without the durability that codification provides? And what is the effect of regulatory whiplash in the data security framework?
▶ 1:27:39Sorry, could you repeat that What challenges do banks face without the durability that codification provides? Because codification, several of those points are in the discussion draft today. What is the effect of regulatory whiplash in the data security framework? If we don't codify it and we do it by regulation, what's the risk that industry and individuals have to deal Um I'm sorry, I will have to get back to you on that one. Ms. Crenshaw.
▶ 1:28:10I can answer that. Can you describe the interaction between the Gramm-Leach-Bliley and state laws, and what are the risk of a patchwork of compliance regimes, and where might a national standard be most helpful? Yeah, happy to do so.
▶ 1:28:25Um in terms of the broad-based consensus privacy approach that we've seen emerge in the states, and this is 17 states, blue states, red states, purple states have all embraced this compromise approach where there is an entity level carve out for the Gramm-Leach-Bliley regulated entities. Um this provides regulatory certainty, it prevents overlap. Um we have though uh seen the first comprehensive privacy law in the country, it was California, uh only provides a data level uh exemption at that point, only data that's subject to GLBA.
▶ 1:28:56Uh and so that creates confusion uh both for consumers and also um for financial institutions as well. But the bottom line is, you know, what we need to do is see one set of rules of the road nationwide in terms of what national privacy legislation will look like. Um it's critically important because of the fact that I think it's been mentioned earlier in this uh hearing, is that small businesses, small institutions do not have the same resources as larger companies do.
▶ 1:29:23Um you know, for example, uh if you look at the recent California rulemaking um that implemented the latest version of the California privacy law, um it's been estimated that those that risk assessment, cyber audits, and insurance regs will actually cost small businesses $16,000 annually.
▶ 1:29:40That is uh funding that small businesses do not have in many cases, and that's why it's so critically important if uh you look at this from the perspective of that's just California, you start adding on more regs or more conflicting requirements across the country, it's going to be incredibly difficult to be a startup or to be a small business trying to start up in your in your garage and with a website trying to get online and and and compete.
▶ 1:30:00So we need one set of rules across the country to ensure we have consumers uh being certain of what what their rights are, but also give certainty to businesses as well about what the rules of the road are. Mr. Crenshaw, the world has changed rather dramatically since 1999 when this law was assigned into place. In your view, what are the provisions in Gramm-Leach-Bliley that need to be Well, some of the things
▶ 1:30:22Several, I know, but
▶ 1:30:25Well, I what I would say is is part of the consensus privacy approach we've seen emerge in the states, uh they provide consumers access to things like access to data and also the right to delete. Um you know, these are things that we're seeing in the discussion draft that are a very good start in terms of solidifying consumer rights. Uh one of the other pieces that we've seen also in this discussion draft and we've seen uh in in similar uh state privacy regimes is is a data minimization component.
▶ 1:30:50And and that data minimization component provides base privacy protections uh for consumers, but then for more privacy-conscious consumers, they can then uh access that data and they can also request that data be deleted. So, it provides a more holistic uh approach to providing consumers with the protections that they want and need. Thank you. And Mr. Chairman, I note that I appreciate the effort at codification. Whiplash is a real struggle for people who have to deal with this stuff. With that, I yield back. Gentleman yields back.
▶ 1:31:20Chair recognizes the gentleman, distinguished gentleman from Georgia, Mr. Scott. You're recognized for 5 minutes. Well, thank [clears throat] you, Mr. Chairman, for that nice compliment. Now, Mr. Bone, I think the real key to this hearing is captured in this.
▶ 1:31:41That given the volume of the sensitive proprietary data collected by the SEC, it is very important that there are robust internal data protection controls and accountability structures not only to safeguard from the growing cyber threats, but to prevent the risk of internal
▶ 1:32:14within the agency. So, Mr. Bombs, you define trust as uh foundational to customer permission data portability and fintech adoption. So, my first question to you is this.
▶ 1:32:35When the SEC's information security program is assessed as being ineffective, what is the comparable trust impact on registrants, market participants participants, and investors who must submit sensitive data to the commission? Thank you for the question, and a compliment.
▶ 1:33:02I can answer on behalf of our fintech members, not for the SEC, and I'd love to share for you information about what they do to protect that data.
▶ 1:33:16Yes. The member companies under the GLBA today are required to have written information security programs that are updated continuously. There must be a qualified individual who's responsible for overseeing and enforcing that program. Periodic risk assessments must take place. Data must be encrypted both at rest and in transit. Multi-factor authentication is required for anybody who's accessing that information.
▶ 1:33:41And internally, there is the principle of least privilege, which is that employees of companies can only access the data that is absolutely required for them to do their job. Uh all of these obligations also flow down contractually to any service providers.
▶ 1:33:56Now, the 2025 OIG report similarly re- highlighted issues tied to protect and detect I would like to insert both of these reports into the record, Mr. Chairman. Without objection. All right. Now, my question on this is, Mr.
▶ 1:34:21Bones, what is the root cause driving some of these findings? Are this Is it people? Is it process? Or technology? we got uh super technology coming on us. And it can do things in ways.
▶ 1:34:48And I want to know how all of this What do you see the playing field will look like in years ahead? It's the million-dollar question, Congressman. I don't think anybody can answer that question uh because the pace of change is happening so quickly in technology.
▶ 1:35:07In the context of the Gramm-Leach-Bliley Act and revisions to it, I think it underscores the need for a The oldest member company we have in FDATA is the same age as the Gramm-Leach-Bliley Act. They started business in 1999. Mhm. It's a a real kind of telling indication of the strength and the neutrality of that act, that it still applies and is relevant to all of these companies today. And so, given that we don't know 5 years, 10 years, 50 years from now what technology will mean, we need to keep that in mind.
▶ 1:35:36We think a lot at FDATA about agentic AI and what that means [clears throat] for data protection and for customer protection. And so, as the committee thinks about changes to the GLBA, those are the types of technologies we think it should bear in Now, let me ask you this, uh you know that GLBA Safeguards Rules requires covered entities to maintain what we call WISP or written information security programs
▶ 1:36:07with a qualified executive responsible for oversight monitoring. Now, so my question is, should the SEC be held to a similar WISP like standard for nonpublic proprietary data is collected? Again, Congressman, I can't answer for the SEC, but all of our member companies do have written information security programs and comply with that requirement. Thank you.
▶ 1:36:37You've been very helpful. Thank you. Uh the gentleman from Texas. Thank you, Mr. Chairman. You see request that I be allowed to place questions in the record uh after the hearing has expired. Uh that's without objection. Thank you. Take care of that. I now have the pleasure of recognizing another gentleman from Texas, our distinguished Mr. Sessions. You're recognized for 5 minutes. Mr. Chairman, thank you very much.
▶ 1:37:03Uh what a delight it is it is to have each of you to help us a walk through your ideas about potential updates to the Gramm-Leach-Bliley Act. I am one of the few members, as Frank Lucas was, to have voted for this and was here during that period of time, and I think it's always important for us to revisit these issues, and each of you have provided really clear context to your answers. Uh Mr.
▶ 1:37:32Crenshaw, I would like to come back to you as a senior member of the Chamber of US Chamber of Commerce, I think that your vision is somewhat broader than what we see necessarily here as individual members, and I appreciate you being here today. During your conversation with the committee, you said a number of things which I think I agree with. One of them was, we need one set of rules nationwide.
▶ 1:37:59Then you went further to put that in some context where you said a clear direction for privacy laws evidently have been bettered, or at least in your opinion bettered, uh by several states as it directly relates to private rights of action.
▶ 1:38:19Then you spoke about that the cost of these may be somewhere near a billion I would like for have to have you balance that out for me of the need for regulatory oversight, the laws, but the need for maybe these states had performed uh in their instances a little bit better with laws. Could you please walk me through that issue?
▶ 1:38:47Well, I would say, you know, once again, I emphasize the fact that we do need one single national standard. Um and your home state um representative, Texas, has one of these consensus privacy approach uh laws on the books uh that we think is actually a good model in terms of broader comprehensive privacy legislation. In fact, um we have seen aggressive enforcement uh of of the Texas Information and Privacy and Security Act um over the last few years since it was passed.
▶ 1:39:15Uh so, uh I think it's really important to note that it provides um excellent uh protections, a a good data minimization standard, a right to have access to data, a right to delete data, um and once again also uh it explicitly rejects private rights of action uh as an enforcement mechanism.
▶ 1:39:35Uh we believe that expert agencies are the right agencies to enforce uh privacy legislation, whether it's it's GLBA uh or it's a comprehensive privacy law, because these agencies, they know the of the companies under their jurisdiction. They understand data practices. They understand the law that they're working with.
▶ 1:39:55And that's why it's so critically important that that we begin to take good aspects of these state consensus privacy laws like the ones we have in Texas and make them national. So, you have spoken about this and I am unaware. I'm sure my staff would have better visibility on this.
▶ 1:40:15Have you approached as the Chamber approached members of Congress on this committee about doing just that that you spoke of or or we utilizing this hearing today to learn about what that approach might might include? Well, broadly speaking from a comprehensive privacy approach that would fall outside of of GLB, you know, we we believe that there's a lot that can be drawn upon in the consensus privacy approach.
▶ 1:40:40But also what we see in the discussion draft that's before us for the committee hearing today from Representative Huizenga, there are a lot of elements of that consensus privacy approach in there like the right to access, right to delete, also a data minimization standard that does not outright block the use of innovation. And so, we think that that's a good starting point for conversation and we applaud Representative Huizenga for his sponsorship of the discussion draft and the committee's leadership and willing to work with you all as you work through this legislation.
▶ 1:41:09Well, it's not Sasha, do you mind if I add Yes, please. Thank you. I I actually don't have as a consumer advocate of blanket position against preemption of state I've been in the position of arguing for preemption of menu labeling on restaurant menus for example in my I think it's really important to just understand and the devil is in the details as some of my co-panelists have said that on each of these provisions, take data minimization, there's a significant
▶ 1:41:40amount of language in the current proposal that would essentially allow legitimate business interests and is very broad to be the counter to data minimization. The deletion rights only apply to former customers and other sort of details.
▶ 1:41:53So it matters a lot that the um very positive aspects of what we've seen that my co-panelists admit is important that's bubbling up from the states and the activity in this area is reflected in any bill that could possibly um present as a preemptive matter because you'll you'll end the innovation in the states. And I think your rights are that Gentleman's time is up. that the that the lack of um privacy rules also has a cost. It has a cost for fraud.
▶ 1:42:24It has a cost for pricing and all of that.
▶ 1:42:26Mr. Chairman, thank you very much. I would yield back my I'll thank the gentleman from Texas. Chair recognizes the gentleman from Illinois, Dr. Foster, who is the ranking member of our subcommittee on financial institutions. You're recognized for 5 minutes. Uh thank you, Mr. Chairman.
▶ 1:42:39I'd also like to thank Representative Sessions for jointly sponsoring with me the Stop ID Fraud and ID Theft Act, a bipartisan bill to start providing states with the resources to fully implement digital driver's licenses, mobile IDs, which are really the the key tool in in authenticating, proving you are who you say you are in an online transaction, which is really a a precondition to have an effective privacy regime.
▶ 1:43:05Um I'd also like to thank our witnesses for their discussions of screen scraping versus API versus other agentic things. As someone I It's probably more than 25 years ago I did my first screen scraping a piece of software. And the problem with that is it breaks all the time, and you have to actually handle the the plain text passwords and other sensitive information. It is a security nightmare, and it is very fragile compared to APIs, which are better.
▶ 1:43:30And I'd also like to highlight the upcoming NIST activities in standardizing agentic communication, which is coming up in the next month. And when that if we do that right, that will be the next generation of this past simple APIs. Now the CFPB's rule making on personal financial data rights focused not only on consumer consent and access rights for personal financial data, but also the interoperability of information systems and and data portability.
▶ 1:43:58These frameworks were to be standards based going so far as to choose an industry led group, the Financial Data Exchange, to mediate the development of those This is going to be absolutely crucial. Efforts like this will be absolutely critical in the coming age of agentic commerce. So Mr. Bombs, can you speak of the importance of establishing strong standards for data portability, API structure, eventually agentic communication, and how those standards would support innovation and access to financial services? Congressman, thank you for the question.
▶ 1:44:28Absolutely critical component of open banking and technology-based financial services moving forward. You mentioned APIs and the drive of the industry to get more towards APIs and away from screen scraping. If we think about that infrastructure as the railroad tracks, basically, on which the consumer permission data is flowing, it's important that those tracks be standardized across the entire ecosystem. So that when you're traveling from one country to another, you don't have to switch trains to get on a different set of tracks that only work with one set of rails.
▶ 1:44:56The industry has done a fantastic job of making that transition through the Financial Data Exchange. There are more than 100 million customer accounts that now flow through FDX APIs, but there is there has to be this recognition that smaller institutions don't have the resources yet to build those APIs. And so that's a continual source of focus. And I think that you know, the the load on small institutions I think can be substantially lightened if the federal government would help support open source implementation of a full compliance stack.
▶ 1:45:26If you're are small fintech startup or a small community bank, if you had access to at least one for nominal cost or zero cost, high quality cyber secure sort of an entire software stack for your back off from back office to compliance. I think that that would be the single best thing that we can do to encourage competition and survival of small community institutions.
▶ 1:45:50It is the compliance cost that kills small players you know, federally supported open source effort. Find it's a group finals f i n o s who is actually very active in this channel and I had meetings with them recently. I think they are you know, groups like that I think are going to be crucial in making this of necessity very complex software and very complex compliance something that is financially affordable to small players. Mrs.
▶ 1:46:18McLaren, what are the benefits to consumers when they have clear control over how their data is used and ported? Research shows that consumers find it very difficult to switch bank accounts and often stay with the same financial institution for many years. Other jurisdictions have additional measures to make switching financial institutions easier like the UK's current account switch program which allows consumer to simply ask their bank to move all their subscriptions, recurring payments and direct deposits over to a new bank within a week.
▶ 1:46:47So do you believe this sort of flexibility would improve competition within the banking system? Absolutely and thank you for the question. S&P Global estimates depositors miss out on 40 billion dollars in savings account interest every year because the largest banks pay below average rates and switching is difficult. The 1033 rule would have lowered those barriers by requiring data holders to provide information that consumers need to move including bill pay instructions and transaction history.
▶ 1:47:16That's a pro-competition, pro-consumer and pro-privacy matter because the rule imposed strict limits on what third parties could do with the data. Lowering barriers to switching while ensuring the switch is safe and private expand expands financial inclusion while protecting data. And you know, for portability concerns, I mean, I have a bank account that's bedecked with all sorts of old bills and I don't move banks just because it would be such a pain. So, I think it's absolutely a basic consumer and competition issue. Thank you. You're back.
▶ 1:47:46Chairman Huizenga recognizes the chair of our Capital Markets Subcommittee, Ms. Wagner of Missouri for 5 minutes. I uh thank you, Mr. Chairman. Since its passage in uh 1999, I was not here in Congress then. Um the Gramm-Leach-Bliley Act has served as the basic data privacy framework for financial institutions across the United States.
▶ 1:48:10At the time of its enactment, Gramm-Leach-Bliley was an important step towards modernizing the rules that govern our financial services industry and providing guidance on how customers data was to be handled.
▶ 1:48:26However, it has now been more than 25 years since its passage and while the basic framework has held strong, we've seen countless changes take place in the financial services sector and obviously the time is ripe for Congress to make much needed updates. Since Gramm-Leach-Bliley was signed into law, a patchwork, and we've talked a little bit about it here today, of different compliance regimes has sprung up across the United States.
▶ 1:48:56Uh because it only sets a federal floor for data privacy regulation, states can enact more restrictive rules that require companies to handle data one way in my home state of Missouri uh and another way in California. Mr. Crenshaw, could you discuss the effects this patchwork of regulation creates on compliance and competition, please? I'm happy to do so.
▶ 1:49:26I One of the issues here when it comes to a patchwork is that it harms smaller entities more than it harms larger entities. Larger companies have the resources to bear compliance costs and and can innovate around in ways some of the patchwork of regulations. The other piece to this as well is it harms national competitiveness in terms of having different laws in different states that potentially conflict.
▶ 1:49:52And one of the examples that is out there is SB205, which is an AI law that passed in which would have imposed disparate impact liability on developers and deployers of artificial intelligence. At the same time, other states are not in coordination on things like data privacy. You've got a state like Maryland, which is now banned the collection of sensitive data.
▶ 1:50:14So, if I don't have the data necessary to ensure that my AI is is is working in the way it's supposed to work or I'm following the law, I'm left in conflict right now over which law I'm going to actually abide by. And and the US is behind in those terms. If we look at the economic analysis of what Colorado is doing, we estimated that could be just from the Colorado law itself a $50 billion GDP hit. It could cost 700,000 jobs. It It's a major competitiveness issue for the United States.
▶ 1:50:41Well, many state laws on data privacy requirements provide exemptions for Gramm-Leach-Bliley. Some states provide an exemption for entire financial institutions. Other states exempt requirements for specific regulated information. Then there are states that have enacted laws that do both. Mr.
▶ 1:51:05could you discuss these approaches and what potential consequences they have individually or in combination. Well, I think you articulated it well. I you can approach this from two ways in terms of how the states have tackled this. There's the financial privacy laws that are similar to the GLBA, which candidly, since 1999, we've only seen a couple.
▶ 1:51:29California and Vermont stand out, and that was in the early 2000s, and then the state laboratory, if you will, has been shut down on the issue. Then separately, post-2018 with the CCPA, we've seen a huge proliferation of state privacy laws that Mr. Crenshaw was talking about. And to your point, all of them uniformly exempt data that's subject to the GLBA, and most exempt all financial institutions.
▶ 1:51:54So, again, taking the laboratory analogy, it's closed, right, if you will, like they're not the states aren't touching it. So, uh you know, if the cost of preemption is low. And on on your preemption question, and I'm respectful of your time, Congressman Moorman, I agree with Mr. Crenshaw's comments about the burden of the patchwork, but I also come at I land at the same result for a different reason, which is the equity to consumers. Right?
▶ 1:52:18Like it seems absurd that all of us in the room from different states could have the same exact credit card with issued by the same bank, but we have different rights with respect to that credit card based on where we live and what our state legislatures did. That strikes me as an absurd result. As we look to make updates to our federal privacy regulations, it is also crucial that we build on what Gramm-Leach-Bliley has gotten right.
▶ 1:52:43And under current guidelines, financial institutions are provided an exception to notice and opt-out requirements uh for sharing consumer data uh when it comes to fraud detection and prevention and mitigation. I'm going to submit my question for the record at uh Ms. Kim and anyone else would like to to do that. Talking about the importance of maintaining this exception um um is important for financial institutions.
▶ 1:53:11time has expired.
▶ 1:53:12fraud. So, I'll I'll wait for your
▶ 1:53:14of you respond in writing to Ms. Wagner's question? You bet. Gentlewoman, your time is back. The recognizes the gentleman from Missouri, our ranking member on our Housing and Insurance Subcommittee, Mr. Cleaver. You're recognized for 5 minutes. Thank you, Mr. Chairman. Ms. McClain, I guess if I have to make this announcement, it means maybe I'm not sure, but uh I'm I want to I want to move with the times.
▶ 1:53:41I want to be uh uh I don't want to be, you know, some kind of um member of Congress, uh but I got to admit, this AI thing is giving me all kinds of unsettling feelings.
▶ 1:54:04even in in the in connection with churches like the Catholic Church, the the Methodist churches, they're even struggling with uh what happens when the when a pastor has uh Reverend AI to put a sermon together. I mean, uh do we accept it? That just to show you how how impactful this is is going.
▶ 1:54:28but I in terms of of what we are supposed to do in this committee, I'm wondering would you would you support uh a reasonable approach to AI including safeguards to protect fairness, uh [clears throat] transparency, uh and privacy, especially for uh underserved communities and communities of color.
▶ 1:54:53I think history may look back on us with hostility if we don't deal with AI. And and I I I'm what concrete policy steps uh do you think we need to ensure AI uh do not entrench or exacerbate already existing inequities? Well, sir, that is the big question, isn't it? I really appreciate that.
▶ 1:55:19You know, we did a listening session just a few weeks ago with our affiliates and uh talking about whether their community-based organizations are able to use AI tools. And I'm a big proponent in making sure that our communities are technically caught up uh because I think, you know, we don't want a world that leaves them behind any more than it already does. And uh their big concern was data privacy.
▶ 1:55:44The reason why their staff feel uncomfortable using artificial intelligence in their work is because they don't know what's going to happen to the data. And they they can't protect the client records that they work with and the other details. So, it is a huge impediment to adoption that we don't have data privacy rules uh for uh new technologies and that they don't follow the data streams as opposed to being kind of specific to entities.
▶ 1:56:10Um and it can be pro-innovation, of course, that we figure out how to adapt technologies to what consumers need in order to use them. That's been the nature of every technology we've ever had is that it gets better over time and that that's a source of economic gain and innovation, as well. Um to your sort of bigger question, I would say our Unitas US governance of AI has three pillars.
▶ 1:56:35We say voice, which means you have to make sure that the outputs are checked, that they're not discriminating against people when it comes to consequential decisions. And there are plenty of ways that you can do that. There's lots of literature on what are less discriminatory alternatives to um judging the impact of lending or other kind of areas where economic goods are decided.
▶ 1:56:56Um, the uh so uh uh voice means that everyone gets a seat at the table and their views are um part of the process of regulating AI. We propose like uh working groups at the federal level that would include wide ranges of stakeholders to look at how AI is actually being used, say in the classrooms or in healthcare, etc. Values is the other thing. It has to be consistent with democratic values. That's the second pillar. So, it can't in uh be extractive.
▶ 1:57:25It can't take intellectual property without compensation. It uh can't uh manipulate us without some kind of public awareness or interpersonal awareness. And it has to be safe to use for consumers. That's the AI psychosis and other problems. The third pillar that we have is investment, which means that we need to bring everybody up to a place where they can use these tools, where they have a voice in the political process that sets the rules for how they're governed, and we need to put some money behind that.
▶ 1:57:52So, we've proposed a public-private foundation model on the CDC Foundation that would take an investment, have a board of stakeholders, and help train up community-based organizations to use the tools and to advocate about their safe use and what they're seeing about the uses and how they impact uh people on the ground. So, that's how you can approach it. It's both with content and with process. We're certainly behind the eight ball on this technology. It's moving very fast.
▶ 1:58:17It's getting better um very rapidly at this point in time because it's using it's sort of coding itself. And so, we have a lot of work to do to make sure that there's accountability um and fairness in these systems. Scary, scary, scary. Thank you. Gentleman yields back. Chair recognizes the gentleman from Kentucky, the chair of our Financial Institutions Subcommittee, Mr. Barr. You're recognized for 5 minutes. Thank you, Mr. Chairman. Uh before I begin, I would like to ask unanimous consent that uh three statements be entered into the record.
▶ 1:58:46One from the National Association of Mutual Insurance Companies, one from the Defense Credit Union Council, and a third from um the American Council of Life Insurers. Without objection, it'll be included in the record. Thank you. Um Let me start with uh Ms.
▶ 1:59:01Kim um because of uh GLBA's uh current framework uh and it and because it functions as a federal floor above which states can enact stricter laws and um it has created a nationwide patchwork of standards. This, as you testified, increases compliance costs and creates barriers to entry into certain states for new firms.
▶ 1:59:25Uh those increased compliance costs and competition-killing barriers to entry results in consumers paying higher prices as having and having less choice. Can you tell us how moving GLBA to a federally preemptive standard would reduce compliance costs, increase competition, and improve consumer Uh yes, thank you for your question. Yes, we strongly have advocated for a fully preemptive GLBA to ensure more predictable standards um across the board.
▶ 1:59:55Um and I think as as many of my co-panelists have said, most states already uh preempt at the entity level because they recognize the strengths of covering GLBA uh covered financial institutions. A lot of these state privacy laws are written for um entities with very other uh business models than financial institutions. And so, uh we do believe that a fully preemptive GLBA would lower a lot of these compliance
▶ 2:00:20Well, I think you've convinced me and Chairman Hill and and but uh I know uh my friend the ranking member uh who comes from California is concerned about this. So, what would you say to her about this? I mean, we would say that a lot of the compliance burden that our financial institution institutions have taken on um in terms of building separate compliance teams, um holding different audits for different regulators, um A, that hurts innovation in in the financial services space, but
▶ 2:00:50I think it's a it's a real opportunity cost. Um, in any business, uh, the resources that you spend in one area will be taken away from another area and that includes providing better financial products and services to the consumers. Uh, well well well so well thank you for that. And Mr. Crenshaw, there are some members uh on this committee on the other side of the aisle who are calling for a private right of action for data uh, but they rarely speak about its costs.
▶ 2:01:16The reality has been that private rights of actions result in companies stopping offering products and services all together to avoid litigation or only offer them to a select group of customers, usually wealthier uh consumers, so that litigation costs can be minimized and offset by sufficient revenue. Do you think there are actually any benefits to a private right of action? Uh, and even if there are, are they outweighed by the significant costs that a private right of action would create? In the context of privacy, no. Uh, and Mr.
▶ 2:01:43Chairman, in fact, um, one of the concerns that we have, particularly addressed earlier issues around the fact that plaintiffs don't usually see the the actual money from these settlements or very minimal or we could get judicial confusion from these types of of sue and settle attempts, uh, from uh private rights of action.
▶ 2:02:00But the other piece is this, when you look at things like data minimization standards like we have in the current draft before us or we see in the consensus privacy bills, they have data minimization standards that that say that companies have to have reasonable use of data or here under the current draft legitimate business uses. We support that kind of approach. But if you put that in front of a jury with private trial lawyers, we're going to litigate what that means in front of non-experts ad infinitum.
▶ 2:02:24And that's why it's so critically important that we put those kinds of decisions at enforcement agencies who actually know the businesses they're working with and have an incentive to go after bad actors. I couldn't agree I could not agree with you more. I think that makes a lot of sense. Uh, Mr. Bombs, everyone, myself, my constituents, my colleagues, we have concerns about the amount of our data that's out there and how it's used, but at the same time we all want to be able to use our data for our own benefit, whether that be applying for a home or small business, or being able to use our data on mobile apps in in open banking.
▶ 2:02:56given that we need to strike this balance between the benefits of data minimization and then the potential cost of data over minimization, can you tell us what your thoughts are on how we should calibrate data minimization standards to successfully strike that right balance? Congressman, it's a critical balance. And so, I would say several things. First, the core of any data minimization framework should be that the end user has full control over their data, and that they're given explicit disclosures and understand how that data is being interacted with.
▶ 2:03:25They have the right to revoke that data, revoke that consent, and they understand what they're getting in exchange for permissioning access to their data, whether it's a budgeting tool or something else. Um and so, fundamentally that consumer control should be the pillar on which data minimization Thank you. I yield back. Gentleman, yields back. Chair recognizes the gentleman from California, Mr. Vargas, who is our ranking member on our task force on monetary policy. Thank you very much, Mr. Chairman, and I also want to thank you for a great hearing today, and remembering that St.
▶ 2:03:55Patrick's Day with that very handsome uh green tie. I have to say that I personally don't trust AI because I asked AI if St. Patrick drove the snakes out of Ireland, and it said no. Clearly, St. Patrick drove the snakes out of Ireland. I'm glad I'm glad to see the gentleman is aware of the possibility of fake news. Thank you. You're back.
▶ 2:04:20but clearly, you um you said that your clients in the context of AI don't trust that their data will be handled appropriately cuz they don't know exactly where it's going to end up. And I agree with you, good privacy laws only work if the right people with the right training clearances are the ones handling the sensitive data. But we saw with DOJ that people with no relevant were handling access to Treasury payment systems and sensitive CFPB consumer data.
▶ 2:04:48And now there are reports that this administration may require banks to collect immigration status from their customers. Is there any legitimate financial or consumer protection reason to require banks to collect immigration Is the answer. [clears throat] Thank you for the question. It would actually be devastating for a financial inclusion where we've made a lot of progress to move people from being unbanked or using a shadowy banking system on the side that's quite expensive for consumers.
▶ 2:05:18And it would be expensive for the US Treasury because what it does is it takes money back into a shadow marketplace and it makes much harder to collect tax revenues at the state and federal level if people are using check-cashing places and other unregulated parts of the financial the Yale Budget Lab estimated that the disruption just from the ITIN piece Oh, no, I think it's the a disruption from um this proposal is $300 billion over in revenue over the next decade.
▶ 2:05:49So, the question is whether we want a financial system that's built on trust or one that functions as an extension of immigration enforcement. And I you know, I think um the banks and credit unions have done a terrific job in many cases, not in all, of extending language in language resources and building uh resources to to um meet immigrant communities where they are. But what you don't want is the creation of a shadow economy.
▶ 2:06:13It also, you know, if you're thinking about um money flows and a kind of um black market in financial services, you worry about crime and drugs and everything else being present in those markets which exposes everyday consumers who are just looking to do financial
▶ 2:06:28with you, but the other thing I would add to that is
▶ 2:06:30you know, this administration
▶ 2:06:34like this information, but the next administration might want other information. I mean, they you always have to remember that administrations change, and then you could get information, for example, who bought weapons and you know, that you buy guns legally. Okay, we want to know who that information is. So, I always tell my friends on the other side, be careful when you allow something to happen here because administrations change. And the rules then change when the next administration comes. So, you don't want to necessarily give them all this information.
▶ 2:07:03I have to say too, the sad thing is we still trust that the federal government when they got when they got this information. With with with exception. You know, there were the black helicopter people that believed that people now they unfortunately kind of does exist. But we thought when the information went to the federal government that we kept it in a very secure way. Now we're finding that it's being, you know, used all over the place in in ways that it was very inappropriate. The courts are saying this. Yes.
▶ 2:07:30sad. Now, I do because I don't have a whole lot of time. You guys were starting to have a good um discussion about the preemption. And you you came back and said a few things. Could you say a little bit more about that and maybe give a little bit of a chance to the other side to say something about preemption. So, it won't take all the time. You got a minute. Go ahead.
▶ 2:07:48I'll try to be brief.
▶ 2:07:48Take 30 seconds.
▶ 2:07:49The question is whether the juice is worth the squeeze and whether the issue is formed enough and whether the proposal on the table is good enough to substitute for any other forms of accountability. If you take away a private right of action, you're depending on federal enforcement alone, which means you have to trust that the current federal agencies that we have are going to put the law to the test.
▶ 2:08:10I don't have that faith in the current CFPB or the other federal regulators which feel ideologically co-opted against as a blanket matter. And the particulars of the bill
▶ 2:08:22seconds. I want to give the other side an opportunity. Anybody want to answer on the other side? On the federal preemption side, we have strong federal preemption in the aviation context where we could fly over five states in a matter of an hour. When we're dealing with the digital context, we could have data go across five states in a matter of seconds. So, it's entirely appropriate for us to have a single national standard to ensure that we have rules of the road that are easy to comply with, and we also have rules that businesses have certainty about. Okay. My time is up, and I yield back. Thank you, Mr. Chairman.
▶ 2:08:52Chairman yields back. The chair recognizes the gentleman from Georgia, Mr. Loudermilk. You're recognized for 5 minutes. Thank you, Mr. Chairman. In response to my friend from California, I'm not sure about St. Patrick driving out snakes from Ireland, but I do know that 250 years ago today uh General George Washington drove the redcoats out of Boston, and in his own words with an act of divine providence, but I would also say, if St. Patrick did drive the snakes out, I'm afraid a few of them ended up in Washington D.C. So.
▶ 2:09:24Again, thank you, Mr. Chairman. Um this is a a topic that's been very important to me. I've spent a lot of my career in data privacy and security. Mr. Taylor, um many state data privacy laws contain rights for a consumer to be able to request access to and deletion of their data held by a firm. Could you discuss how these work in Yeah. Well, it's it it's it can be terribly complex, right?
▶ 2:09:52Um when when someone says, "Hey, tell me all the data you have about me," you have to go your various information systems and try and identify all the different pieces of data that you have about that individual, and then put it in a package that is readily understandable to the average consumer, and then give it to Okay. Do you believe um adding rights like these to GLBA would afford consumers greater control over their data? Yeah, 100%, right?
▶ 2:10:20And the And one of the themes in this hearing has been the debate over preemption and and uh Ms. McCrary mentioned is the juice worth the squeeze. And I think uh Representative Huizenga's bill, by adding several strong rights to it, I think that tips the balance in terms of yeah, the the juice is worth the squeeze here. And I think a federal preemption is absolutely important.
▶ 2:10:42Do you feel that that would it would help in striking the balance if we were to legislatively identify what is considered a consumer's privacy data, data that they would inherently own? I I think that's a different matter and out outside of the GLBA, I think that's it's that's a that's it feels more like an ENC discussion to me, personally.
▶ 2:11:12that was a good dodge, by the way. Um do you believe that adding rights like these to GLBA could address security vulnerabilities that are presented by storing vast amounts of consumer financial data? Yes, 100%. I mean, in particular, the deletion right that's included in the discussion draft, I mean, that that gets terribly to the heart of of the point that that you're making, which is if you're a former customer and when the relationship ends after some time passes and subject to certain exceptions, you can request that a financial institution delete
▶ 2:11:43the data. They can't lose what they don't have. Right. Uh when I worked in military intelligence and data security, we always live by the mantra is you don't have to secure what you don't have. And so, uh unless you absolutely need it, get rid of it. I think the federal government needs to learn that as well. Uh Ms.
▶ 2:12:04Kim, in your testimony, you write that deletion and similar rights must be considered with existing obligations as well as with the need to preserve evidence of suspicious or criminal Do you believe there's a way to strike a proper balance between giving consumers greater control over their data and maintaining tools for law enforcement to identify suspicious or criminal Um yes, thank you for the question.
▶ 2:12:26Um yes, I we do believe that there is a way to incorporate further consumer rights into the GLBA uh but it that it just must be done carefully um without interfering with existing data pools that exist uh for purposes of fraud um for reasons under um the BSA AML CFT reasons um and for legal holds and uh responding to subpoenas. All right, thank you. Mr.
▶ 2:12:52Crenshaw, in your testimony, you write that mandating the deletion of data for certain inactive accounts is impractical uh impractical for regulated financial institutions. Can you give a bit more detail about why you think that would be impractical?
▶ 2:13:08Well, I think our position really is mandating deletion and starting from a position of deletion is not a uh position that enables companies to fulfill many of their obligations, whether it's having the data that's necessary for uh training systems for security purposes or also potentially having to defend legal claims down in the line in the future or also um having to uh look at things like fraud and having solutions that can be developed um and that's why we think it's critically important that we start with a data minimization baseline, opt-out
▶ 2:13:38rights for sharing, and then also deletion on on behalf of a consumer request along with access rights. We think that strikes the right balance. Thank you, Mr. Chairman. I yield back. May I uh may I comment on the deletion Sure. Um I would say the 45-day business window is longer than California's or the GDPR, the European um deletion right. It's limited to former customers only, and it's broad enough to um in terms of the exemptions substantially now with the
▶ 2:14:06we welcome you to handle that in your written comments.
▶ 2:14:09I will do. Thank you. Uh the ranking member. I have a unanimous consent request. The gentlewoman is recognized.
▶ 2:14:14Earlier, you said uh, we should use a scalpel and not a sledgehammer to our data uh, privacy laws. I agree and hope we can work together, but I have two statements from the National Consumer Law Center and another from the Electronic Privacy Information Center explaining how the Republican's draft bill would take a sledgehammer to many consumer protections. Thank you. I yield back.
▶ 2:14:37They'll be included in the record without objection. The chair recognizes the gentleman from Illinois, Mr. Casten. You're recognized for 5 minutes. Thank you, Mr. Chair. Um, so before I get to questions, I just want to just want to raise for the committee. I have this nagging concern with the way a lot of this this conversation is going. And I I think I can best explain it um, by reminding everybody back in 2021, the FTC had a settlement with Ascension Data.
▶ 2:15:03This was a mortgage analytics firm that they had a third-party vendor that had had gobbled up data that was that was private and there was a recognition that Ascension Data was themselves Entirely non-controversial, entirely good law. I think we all recognize that if if I want to commit a crime and I can essentially indemnify myself from criminal activity by hiring a third party to commit the crime for me, that's a bad idea, right? Um, it's why we have RICO statutes.
▶ 2:15:31Um, it's why aiding and abetting a crime is a is also a crime. And yet, if I hire a robot to commit the crime, everybody wants indemnification. The whole AI industry is trying to be indemnified for crimes. And if And if we focus on this idea of of state preemption, and all we do is just run to the bottom level, we've essentially said go commit crime with robots.
▶ 2:15:57And if if I hope we don't have that in the final text of this bill, but I don't want us to lose sight. moving to my questions, I'd I'd I'd like to joke sometime that I've never met a non-schizophrenic libertarian. And the way you can tell that you meet a non-schizophrenic that you have met a schizophrenic libertarian is you ask them whether they want to share their data with powerful entities in the United States government, they say no, and then you ask them if location services are on on their phone, and then you sail your way into the We are at a point right now where that schizophrenia is
▶ 2:16:27starting to cross the Last year, CISA's acting director uploaded central sensitive information into ChatGPT. That information in ChatGPT was then in their public We have received information in our office that information that ChatGPT is using in OSHA files in in in air permitting rules is allowing it to hoover up company confidential information, so you can now use these tools to get information that people thought was safely
▶ 2:16:57protected inside data And and I guess Mr. Bombs, the is it is it technically possible to use an AI tool to ring-fence that data so that a company who wants to use the power of AI can confidently know that all of their internal data stays confident stays within within their controlled environment, or does it always have to leach out into the broader public? Thank you for the question, Congressman.
▶ 2:17:24This is part of the importance of transitioning to APIs where that the flow of that data can be better managed across the ecosystem. Industry is doing that. One of the things that we spend time thinking about about that data is read access for agentic AI and write access for agentic AI. So, in other words, an AI agent can look at your data and make a recommendation to you about a financial choice. That's read only.
▶ 2:17:46It's not actually doing anything for you, it's giving you Another option in a future state would be the AI agent saying, "Do you want me to go ahead and make that change for you?" Say in your portfolio management.
▶ 2:17:56And and and I'm sorry to cut you off just cuz I'm sensitive time, but are are you satisfied then that you can use AI and make sure that that data is fenced, so your confidential information is not leaking out.
▶ 2:18:04In the context of APIs, yes. Okay. Cuz my understanding is that Anthropic is one of the few ones that does that, and I am really concerned with Department of Defense saying we don't want to use Anthropic because now this is getting out since we're seeing it leak out in other areas. We've also, of course, had these high-profile issues that I think many of my colleagues have talked about with DOJ hacks into the system, the hacks of the Treasury payment system. Ms.
▶ 2:18:27McCleary, I think you had mentioned in your opening remarks this gentleman at DOJ who said that he had had god-level access to social security information data. It should be noted that he also said that if he's ever convicted, he expects to be pardoned. I assume it's a he, might be a she. This was whistleblower report. Which means that that DOJ employee is looking for indemnification, and I'm sure he would love to have state-level preemption if he can move to a state where he gets the right coverage. let's assume the worst case.
▶ 2:18:56These DOJ employees have accessed that social security information, the banking information. They've accessed the Treasury payment system. Can we put that genie back in the bottle, or is that information all out just gone now? I think it would be very difficult to ever know what's actually happened to the data, and there there is reports that there were back-end plugins to the actual data servers, and you're supposed to have, as you probably know, you know, use logs.
▶ 2:19:21could still be accessing the data. Well, no. I don't I mean, I think at the time, right? And so, you're supposed to have even when the Inspector General's office, for example, audits an activity related to a data set, it never has modification access to the data because then it's clouded the audit trail. So as a basic matter of data security hygiene, you're never supposed to be in a position where you can actually modify the underlying data within a government database, especially a highly sensitive
▶ 2:19:48We're out of time, and look, let's fix this in the FY 23 budget, but we have a whole bunch of issues that this committee should be doing oversight on the Treasury payment system hack, what's happening at DOJ, all of that risk.
▶ 2:19:57has expired. The gentleman from Ohio, the chair of our national security subcommittee, Mr. Davidson, you're recognized for 5 minutes. Thank you, chairman, for holding this timely hearing. You know, frankly, with respect to privacy, I think we're we're hard to say we're timely. We we really haven't kept up with the digital era very well at all. Gramm-Leach-Bliley kind of predates a lot of use cases. And I'd associate myself with at least a sentence or two that Mr.
▶ 2:20:24Casten highlighted with the concern that artificial intelligence is somehow blanket immunity to basically harvest data in any way you can get access to it. Because once it's in the model, well, how could you have any attribution?
▶ 2:20:38Frankly, that was one of my big concerns last May that that the Senate eventually corrected when they had to vote on the matter, 99 to one to say, "No, let's let's not do one or two sentence blanket I do think, you know, AI preemption makes sense and one AI framework for the country makes sense, but privacy is the base layer for ethical AI.
▶ 2:21:02And we really haven't got the foundation right with With respect to financial services, Gramm-Leach-Bliley is, you know, one of those examples where it doesn't really apply to everybody in the country. There's no single unifying law for most things in the country. It's all And part of that's due to the structure of Congress where, you know, you you have committees of jurisdiction and part of that's people lobby a lot for something that certainly advances their interests versus everybody's.
▶ 2:21:29I want a base privacy law that recognizes that it is your data. And so you of course should have a right to to that data. What what data do you have of mine? And I think the other thing you should know is how's it been acquired? And then how's it shared? So when you look at, you know, Mr. Crenshaw, I think one of the basic frameworks is is opt is opt out adequate or should the framework be opt in?
▶ 2:21:59And once again as we we look at the base approach to privacy, fundamentally speaking, we need to have a base data minimization requirement across the board. So, that means that that companies can use data in a way that's reasonable and relevant to the purposes that they're disclosing to their consumers.
▶ 2:22:16They have to live up to that standard and then if they don't live up to that standard, they not only have issues with you know their current regulators especially as we see in the states, but the FTC can then come in and say that a company is not fulfilling its its its obligations under an unfairness and deceptiveness claim. But then we also believe that if you have privacy conscious consumers who who also want to have increased data protections, they have the right to opt out.
▶ 2:22:43They have the right to delete, they have the right to access that data and that provides baseline protections. I think the concern with starting with an opt-in approach is that you begin to dry up data pools and I think as you mentioned earlier, we need to have good data to have ethical AI and responsible AI. And and if we don't get a full and complete data set, then we can't get AI working in a way that works for Can I add a little here? I would I know.
▶ 2:23:13Okay. Second cuz I want to get to a follow-up here. When you look at you know, you talk about protections, you know, you're already not supposed to sell data outside of what you've agreed to, but you do do it in an aggregated way. And when you look at you know, within two or three moves, you can sort of disaggregate that. And with the age of AI, that's going to be increasingly easy to do.
▶ 2:23:39Um and you know, I think the the real premise for for a lot of the industry was lost first and foremost in the financial sector with the Bank Secrecy Act because it changed the idea that once you shared it with somebody, albeit somebody you essentially have to share it with, a financial institution, you no longer have an expectation of privacy. And we should recognize that as a corruption of natural rights, natural law. I mean, the right to transact predates any government.
▶ 2:24:05It would be a little nosy for the government to interject and say, "Hey, why are you trading fish for fruit with this guy?" You know, what's I don't know. You go mind your own business. We're doing our own little transaction. But government's done that and they've put themselves between the consumer and whoever they're transacting with on nearly every transaction. In In fact, if you don't spy on your customers, you don't get to operate a financial services business for the most part. So, in the age of AI, how do you safeguard against disaggregation with all of the things?
▶ 2:24:34Granted, you got the disintermediation. You get three or four data points, you can you can unbundle anything. Anybody have an answer for that? I don't want to I don't want to push back because I mean, I think there is some some some truth there. I What I was going to say is everything is data set specific, right? If I have a aggregate credit score for 100,000 accounts, you're not three steps away from identifying the credit score of the individual.
▶ 2:25:03So, you know, I I I do think the concerns you raise are legitimate. I think AI and computing, you know, does sort of raise the stakes and increase the likelihood, especially if if if if you have enough data to compare against. So, re- rethink the exception. Yeah. Thank you. And I yield back. Gentleman yields back. Chair recognizes the gentlewoman from Massachusetts, Ms. Pressley. You're recognized for 5 Thank you, Mr. Chair.
▶ 2:25:32I want to put this uh hearing in perspective uh for the American public uh watching this hearing just to demonstrate why it is time to move to open banking. imagine Mark, a 30-year-old renter in my district, the Massachusetts 7th. Now, Mark splits bills with his roommate and uses a property management website like uh Greystar or Peabody Properties to pay the rent directly with a credit card.
▶ 2:26:00And uses an app to send money to his roommate for the water and electricity bills that they share. Now, Mark likely has no clue exactly what happens when he clicks the send button. He, like millions of Americans, likely completely unaware financial information is being shared with marketing platforms and credit reporting agencies and even data brokers without his explicit permission.
▶ 2:26:27But what he does know is that when he checks his mailbox, there's random junk mail with his name and address for new credit cards. And when he checks his emails, there's spam about opening a bank account. That isn't happening by chance. It is by design. Our financial system enables big banks and fintech companies to abuse our financial data for their own profit. Meanwhile, Mark and the rest of us are limited and told what we can and cannot do with our own data. Now, here's the thing.
▶ 2:26:56We can actually do something about this. We have the opportunity to change that with the open banking rule to really empower consumers to decide how their financial data is used and shared. The Consumer Financial Protection Bureau open banking rule would allow consumers to not only share financial information with platforms to pay your rent or bills like many already do. It would also allow consumers to take their financial history with them to other banks and have the choice to make decisions that work best for them.
▶ 2:27:26It would empower consumers. Ms. McClary, what should the everyday person understand about the move toward open banking and how it would benefit them uh when they want to purchase a home, retire, or start a business, for example. Thank you so much for the question. It's a really important one. Data portability and data rights, in terms of how you negotiate your rights with systems, are key to building consumer understanding of this.
▶ 2:27:52And you might say that the current regime under GLBA, which is the opt-out regime, does nothing to advance consumer understanding of this because it's essentially a passive mechanism. If you get a one of these form letters in the mail, that's just a sort of notice on paper, and you're expected to be the one to act. The default is that you're in the data whether you what unless you've chosen otherwise.
▶ 2:28:15That is not um deepening people's sense that they have a right to their data and that they are a good custodian of their data. So, I would say the one of the reasons why opt-ins are the preferred mechanism by different consumer groups and across the data privacy world and in the California law is because it helps build that ownership among the public.
▶ 2:28:38Someone can say, "Wait a second, I didn't sign up for that." When you've just gotten a paper letter that is part of your junk mails junk mail stack in the mail, you're not going to have that same sense of ownership or or um uh sense that you might be able to stick up for yourself in terms of the company's rights. So, so that's it's moving the default that would matter the most. Yeah, I mean, look, it's the people's data, it's the people's money, and we can't innovate financial privacy laws without our communities uh being at the center of those decisions.
▶ 2:29:08Um given all the benefits of open banking, could you just speak to why exactly are people opposed? Why would they uh work so actively to uh to obstruct this progress and this empowering of the consumer? Why do you large corporations that benefit from people being locked into their services oppose the ability of people to walk away when in response to market forces. I think that's the the question sort of answers itself,
▶ 2:29:39Fair enough. Okay. Well, finally, um you know, having read your written um the testimony you submitted, um you spoke about uh some of the ways in which we could improve accessibility, acknowledging limitations for those for whom English is not their first language, uh impacts of uh you know, AI. So, what should Congress be keeping in mind to make it more accessible for people to to know their financial rights?
▶ 2:30:01Yeah, if a financial transaction was negotiated in a particular language, all of the related documents, legal documents, disclosures, and everything else should be in that language. It shouldn't be that you're marketing to someone in their language, but then you turn around and hand them a stack of papers they can't read. So, that's a pretty simple rule of thumb, and I think that belongs in any kind of disclosure All right. Thank you. I yield back.
▶ 2:30:30I'll now recognize myself for 5 minutes for questions. Um I'd like to ask Mr. uh Taylor the first question if I could about uh the supremacy clause of the United States Constitution. As a nation, we value our federalism, and we try to let states regulate when appropriate. Yet, the founders recognized the supremacy of the Congress in matters of interstate commerce. Sometimes we need a predictable standard to avoid impairing commerce among the states.
▶ 2:30:56Can you please discuss the need for a federal standard for financial data privacy that potentially could preempt state regulations? Yeah, absolutely. Um you know, another others on the panel are focused, I think, on preemption a little bit from the burden and the patchwork standpoint.
▶ 2:31:14I I I approach it from a consumer standpoint, which it seems inequitable inequitable to me that the the privacy rights you have for your sensitive financial information are going to be dictated by the state in which you live. That's not fair. And and this is I think inarguably very sensitive information, and I think we need a single standard. And and and not a weak standard, but a strong standard that applies across the Mr.
▶ 2:31:44Bombs, if I could get into another area, um in the in the context of the Gramm-Leach- uh Bliley Act, GLBA, do you believe that consumers have sufficient understanding of the risks of sharing the non their nonpublic information to make an informed decision? Congressman, thanks for the question.
▶ 2:32:03Uh I think our view is that generally speaking, consumers and small businesses are smart enough to decide, when presented with clear and conspicuous whether they are comfortable sharing their data for an open banking use case, and to weigh that against the benefit that they would receive from the product uh that they are going to be enrolling in.
▶ 2:32:20As I think you know, the GLBA requires that disclosure and transparency at the point of interaction, when you're first saying, "I want this service, and I want to uh share my data with it." Uh and then, pursuant to the GLBA and other both statutory and contractual and regulatory requirements, the open banking-enabled products, tools, and services that uh our members offer operate on the principle of necessity, which is that to the extent that NPI is being collected, it's only the NPI that's necessary to deliver the use case that the consumer has said, "I And Ms.
▶ 2:32:50Kim, uh one of the questions that came up earlier that I asked Mr. um Taylor deals with again this issue of uh the the interstate commerce issue. Uh I'd like to know your opinion on that as well, if we could, please. Um yes, uh so because of the patchwork of um federal privacy laws and state comprehensive laws, um I would agree with a lot of my co-panelists that um it has hurt interstate commerce because um it serves as a barrier to entry for uh
▶ 2:33:20many businesses, financial institutions, uh, who maybe cannot afford to do business in those areas. And good, Mr. Taylor, again. Um, the idea that the opt-out rates are less than 7%. Uh, how do we solve an issue like that in a pro- more proactive manner to actually look out for consumers cuz many of them just aren't aware of the risks that are associated with this? It's It's This is truly a very challenging issue.
▶ 2:33:46And, you know, as I noted in my oral testimony, I you know, in my I believe that billions of privacy notices have been physically mailed to customers under the GLBA over the past 25 years. So, there's certainly notice is being accomplished and the banking agencies developed a model privacy form that was intended to simplify it and make a privacy notice like a nutritional label, for example, and make it more easily understood.
▶ 2:34:14So, you know, it is candidly, as a practitioner working with financial institutions, it's baffled me that opt-out rates are so low, but I'm not I'm not ready to make to take that control and make the decision for consumers and flip over to an opt-in All right, at this time I'll yield back my time and, uh, the gentleman from California, Mr. Luardo, is now recognized for 5 minutes. Thank you, Mr. Chair. Uh, appreciate all the testimony the witnesses.
▶ 2:34:42Uh, certainly I've got uh, many residents at home, as we all do, who are deeply concerned about how their data is being used and what they don't know about how it's being used. And, uh, I was looking at a 2021 survey from from NORC, uh, that, uh, found that 93% of fintech app users are not aware that data aggregators are scraping their data and how they're using their data. Um, I have a have a lot of fintech companies um, in my neck of the woods.
▶ 2:35:12I represent a big part of Silicon Valley, and so I understand the very important work that, uh, they do and and the service they provide for for millions and millions of But, it seems to me that there are two basic ways here that fintech companies could get uh access to the data they needed to provide the service.
▶ 2:35:30One is through secure API uh that the bank would provide or other financial institution or through screen scraping where essentially they take on the identity of the or they they gather the the the passwords and so forth. They get access to the account and then are able to scrape all the Ms. Broms, as you could tell this is coming your way. Uh
▶ 2:35:52if we had an open banking rule with clearly established protocols, would we need screen scraping anymore? Thank you for the question, Congressman. The answer is we would not need it as much as we do today, but we still might need it. And I'd say that because we are one of the last G7 countries to create a an open banking framework. Several other jurisdictions have moved before us.
▶ 2:36:17We can learn lessons from what they've In those jurisdictions, APIs are much more ubiquitous than they are here. We have a much more diverse financial ecosystem with smaller entities. Uh but, screen scraping still exists as a fallback option. And the reason for that is, as we've heard before, there are some competitive interests at play in this market. And there are some reasons why a large data provider might not want to share their data with a third party.
▶ 2:36:41And so, if screen scraping remains as a fallback if an API isn't available, if an API isn't reliable, if the API doesn't have the data that's required for the use case. In a world where you had clear protocols about what data they had to provide, theoretically, we shouldn't need it, should we? The banks are under clear obligation to provide the data. And then you still have the long tail problem, Congressman, which is there are thousands of smaller financial institutions that don't have the resources to deploy those APIs today.
▶ 2:37:06And for those consumers, the question of whether or not you you use a fintech tool if if screen scraping was permitted, it would be a binary yes no. They wouldn't have access to those tools. But these secure APIs are nearly ubiquitous. It's certainly our tool. I I'm absolutely incompetent at software development, but I can even write code some surprisingly good results. Why can't we simply require all the financial institutions develop their own APIs?
▶ 2:37:35And we've heard from banking industry, they're not opposed to banning screen scraping. Why wouldn't we simply say everyone develop a secure API and you're going to be held to account for it? Congressman, it's it's a not a question for us and our members because we're reliant on the data providers and the method that they choose to make the data available. All I can say is we strongly prefer APIs where they're reliable and So, Ms. Kim, as you can imagine, this is coming back to you.
▶ 2:38:02if in fact, as you said, you support screen scraping or the elimination of screen scraping, a ban on it, uh what about a requirement that all of your members and all financial institutions would be required to be able to create a secure API that fits protocol that CFPB presumably would create. Uh thank you. Yes, um I I would say that uh for the vast majority of our members, we uh already do use APIs.
▶ 2:38:30And so, uh like I mentioned before, we we are paying attention to a certain data exchanges that will continue to transition that um that system away from dangerous practices like screen scraping and toward API development. Okay. Well, I I guess you can tell where I'm pushing here. I just think that this is something that's long overdue. Um that is prohibition on screen scraping. I can see how it can be abused.
▶ 2:38:53I understand why fintech companies may need to use it given the current state of play, but certainly that's something we should be able to fix at the federal level, and I urge us to do so. Uh and as we talk about this issue of uh I appreciate that preemption gives us uniformity uh of application of rules. It reduces compliance costs for all our financial institutions. But, unfortunately, we're enduring an administration where uh we have completely defunded the financial police.
▶ 2:39:22The CFPB CFPB is simply a shadow of itself, and there is no private right of action. Consumers have absolutely no ability to take a violator to court for abusing their privacy. I don't understand in that context how we can at the same time advocate for preemption when we lead leave consumers in this country with no means of recourse when they are harmed because federal law and this government does not allow for it.
▶ 2:39:52Thank you, IU. Gentleman having yielding back. Gentleman from Montana, Mr. Daines, you're recognized for 5 minutes. Thank you, Mr. Chairman. You know, I appreciate the committee's focus to ensuring that the United States remains the leader in innovation around the And that doesn't just mean creating regulatory clarity for digital assets and allowing artificial intelligence to flourish, but but also ensuring that our data privacy laws reflect the 21st century. Uh I'm going to start with uh Mr. Bombs.
▶ 2:40:21With innovation in mind, why is it important that any data privacy law remain technology neutral? Thank you, Congressman. Uh the drafters of the Gramm-Leach-Bliley Act in 1999 could not possibly have imagined the way that the financial services regime would look 27 years hence. And so, similarly, those of us in this room, though I think we're all very uh focused on this, cannot possibly imagine what the regime will look like 27 years from now.
▶ 2:40:46And so, it's very important, to paraphrase Wayne Gretzky, that we go where the puck is going, not where the puck is. We don't know where the puck is going. And so, we have to be technology agnostic. The GLBA generally takes an activity-based approach to deciding whether or not you are subject to its provisions. That feels like the right way to continue uh the statute moving forward. So, do you believe that the GLBA was written sufficiently technology neutral? Congressman, I do.
▶ 2:41:13And I think the proof is that several of our members who did not exist back in 1999 are subject to the GLBA today. All right. I appreciate that. Move on to Mr. Taylor. The implementing regulations for banks and credit unions under the GLBA Title 5 Regulation P are written by the CFPB while for other types of financial institutions the implementing regulations are written by the CFTC, the FTC, the SEC, and state insurance regulators working through the Could you discuss
▶ 2:41:43the advantages and the disadvantages of this approach? Well, the CFPB became the sort of lead, I would characterize lead rule writer with Dodd-Frank. Before that, you had the functional regulators like the banking agencies, the Fed, the OCC, at the time the OTS, NCUA were writing I've always been a fan of the historical regime where the regulators
▶ 2:42:14who are the ones who are actually going to be examining and enforcing the law are also the ones writing it and they know the industry and I think that's the appropriate approach. All right. I appreciate that. Um you know, so just to kind of double down on that do you believe that Congress should take a look at removing the CFPB from its role in GLBA rule making I mean it it having listened to to both sides here throughout this hearing,
▶ 2:42:44there there seems to be some concern with the CFPB and I know there's historic concern. Um it it's something that this committee should at least consider. Appreciate that. You know, there's been a lot of discussion today about the need to preempt state data privacy laws to promote uniformity and to promote innovation. You know, as a I was a former state regulator and I'm typically hesitant about broad federal I can see the merits of it for data privacy laws.
▶ 2:43:15And I know we've already discussed this a little bit, but I'm going to move on to Mr. Crenshaw. What role should the states have over regulating enforcing David data privacy laws? I I also would recognize your home state has one of the comprehensive privacy laws that follows the consistent approach, uh which we think is a good model for comprehensive privacy legislation. Um you know, going back all the way to Federalist 42 where there is conversation about the reason we have our Constitution and not the Articles of the Confederation is that we need economic cohesion.
▶ 2:43:44And that's why it's so critically important as we're dealing with a technology that as I I mentioned earlier, you could be clicking and having data go in five states within a millisecond. Um that we need to have one national standard around that. Um and so I I I think as we look kind of at the broader comprehensive context when it comes to privacy, we see a role for state AGs. Um we also uh see a role in as well too for in the GLBA context for for state, you know, insurance regulators as well.
▶ 2:44:12Um but at the same time, um you know, we think in the the GLB context overall, uh it should be with the appropriate federal regulators um who have that Right, thank you. Um I'm not sure if I have time, but I'm just going to go down the line. If Congress can make only one change to federal privacy laws, what should it be? And we'll start here with Mr. Taylor and just move down. With respect to the GLBA, I would say uh adding additional consumer rights. Um strong federal preemption.
▶ 2:44:43Premised on the concept of control over Strong field preemption. Outstanding. Well, thank you all for your time and on that, Mr. Chair, I Thank you. The gentlewoman from Michigan, Ms. Tlaib, is now recognized for 5 minutes. So, we all know and we've been talking about this hearing, which I'm so glad we are, especially with the growing use of our private data for surveillance pricing and a number of other um issues.
▶ 2:45:11We know that companies using personal data and, you know, the way they're using their algorithms uh to make lending and other financial decisions is hurting uh Americans. I know CFPB, which is a Consumer Financial Protection Bureau, was the primary agency investigating how these algorithms might be baked in racial, gender, or other biases in financial decision-making. However, we've seen CFPB be gutted, slashing funding, cutting staff, dramatically reducing any sort of supervisory capacity.
▶ 2:45:40In addition, we know that CFPB has closed all under the Trump administration fair lending investigations. I don't think the American people know this. Uh uh based on disparate impact uh liability under the Equal uh Credit Opportunity Act. And for folks listening, I mean, this is so incredibly important. It was one of the ways that we were able to push against housing discrimination. So, is Ms. McClary, is it Can you briefly describe the disparate disparate impact liability? Like, our moms are watching.
▶ 2:46:08Like, what are Explain it to folks to understand just how um harmful this is going to be. It means that if some group is being in terms of access to loans or financial products, no one will know.
▶ 2:46:25Somebody with a disability. Somebody with a disability, somebody who's
▶ 2:46:28mom with children. Yeah, or a person of color, right? Any any group that you would think that is already struggling against uh bias and access to, you know, housing, lending, bank accounts um will not uh show up anymore
▶ 2:46:47green light.
▶ 2:46:48It's just a bright green light uh to allow discrimination. It's not just of course the CFPB. We already know that it's also ending disparate impact enforcement within the Department of Housing and Urban Development as well, Department of Justice, Department of Transportation, and the Federal Trade Commission. All of those agencies will not be investigating discrimination based on disparate impact. Um with CFPB sidelined, Ms. McCreary, I mean, who's left to ensure that our data privacy isn't being used to shield or hide systematic uh discrimination in the financial market? States.
▶ 2:47:18That's who's left. And I think that's why we see this move to federalize all of the liability and accountability mechanisms from this committee. It it is about states being innovative, passing laws that hold folks accountable. It is about individuals using state law in the class action to bring forward information about harms and hold people accountable.
▶ 2:47:42And in some cases it's about both Republican and Democratic Attorneys General who've been very good at trying to protect people in their states.
▶ 2:47:51So let's go to price gouging, or they call surveillance pricing, but it's a way to price gouge, which I find incredibly concerning. You know, I introduced the Stop Price Gouging in Grocery Stores Act, which bans surveillance pricing at grocery stores. And it's not just companies using your personal informa- like they're using like your zip code, your browsing history. Yes. that many companies including grocery stores are becoming data brokers.
▶ 2:48:15If people don't realize this, they they they use like sexy terms like precision quote precision marketing and advertising. But I want my colleagues and the public to know this. In 2024, which has a huge presence in Michigan, made an estimated $527 million in profits by selling your shopping data. That was something like 1/3 of its total net income in 2024.
▶ 2:48:43And data broker market is expected to grow billion in 20 by 2028. So, Ms. McCrary, you noted that more data going to third parties expands the raw material available for surveillance. Can you discuss the biggest concerns related to surveillance pricing or government surveillance given the rapidly expanding data broker market? Yeah, it's the right question to be asking. All of these new smart appliances, all the apps that want us to join, they're mostly data scraping.
▶ 2:49:11And the idea is that they turn everything we do inside of our homes or online into a separate profit stream that they can then sell into the data broker marketplace. And so, um there's just an extraordinary amount of information. And what we see with surveillance pricing is that you would think that people who have less ability to pay might get a better deal, but it turns out the opposite is true. Absolutely opposite. That's the thing.
▶ 2:49:36We've been seeing that it's the The fact that they're going to price milk, and basic food products based on where you someone lives, whether what they've been searching online, is absolutely appalling. Shame on Kroger. Shame on anybody using surveillance pricing. And I wish my colleagues would understand the importance of this. Prices are going up on our residents. And guess what? It's not just the cost of making these products, as they claim. It's corporate greed, and we need to do something about it.
▶ 2:50:06Thank you. Having yielded back, the gentleman from Wisconsin, Mr. Steil, is recognized. And our chairman of of the subcommittee on digital assets is recognized for 5 minutes. Thank you very much, uh Mr. Chairman. I appreciate all of our witnesses being here today, a productive conversation today. Um I'm going to start with you, if I can, Mr. Taylor.
▶ 2:50:25Um Gramm-Leach-Bliley Act, uh its data privacy framework, as we know, written at the end of the '90s, 1999, uh at a time when the financial services landscape uh looked very different. People were still dialing up on AOL. You hear the noise when you would connect, right? I mean, this is we've made great strides, and you almost have to take your mind back to what Congress would have looked like uh in the late '90s.
▶ 2:50:49Uh probably people probably explaining to what email was, uh what a digital footprint would be, the idea of data privacy was kind of in its infancy as it relates to the digital age, Web 3 era uh that we're entering. Um knowing that and thinking about how the financial rails uh have really transformed pretty dramatically uh during that time, the ability to store metadata, etc. Um I want to go back and think about GLBA uh as written in the manner that it was written.
▶ 2:51:18Uh do you think it was uh sufficiently drafted to adapt uh and cover all of the financial services companies and products we have in today's world, or uh do you need do we need to be really updating the definition of {quote} financial institution {end quote} uh to cover the wide variety of entities providing financial services today? Great questions. I think it's two, not Um on on the first, I do believe that GLBA is sufficiently technology-neutral.
▶ 2:51:48Uh I began practicing law in 2003 working on GLBA. I've seen the financial services market change, but, you know, the the law and the regs that I work with have been flexible across every type of product um that's evolved and the technology that's Um your your second question about gets to the heart of the I think the definition of financial institution and and is it sufficiently clear?
▶ 2:52:15Um you know, as a practitioner in the weeds, I find it clear, but it is very dense. And if you
▶ 2:52:21the courts have found it clear, though? We're looking at, you know, some of the um litigation in different states. I'm thinking about data aggregators. Um do you think the courts are viewing it as clear? Or why is there so much litigation in the space if it is clear? Well, I don't I don't think it's GLBA litigation because there isn't isn't that private right of action that people were mentioning, but uh I I view it and I put this in my written testimony.
▶ 2:52:46I I think it's unequivocal that financial data aggregators are financial institutions for purposes of the GLBA, but it's a somewhat complex analysis and there seems to be a pretty easy fix, which is what uh uh Representative Huizenga's draft does which is just add a an additional clarification of, you know, simple parenthetical of including financial data aggregators. Thank you. Let me jump to you, Mr. Crenshaw, uh if I can, uh staying on the da- on the topic of data privacy.
▶ 2:53:15Um, as you discussed in your testimony, there's a strong case for federal preemption uh and state uh to state coordination. This is the constant challenge we have here uh between federalism and the commerce clause, we're one uh economy in the United States. We love states to take the lead. I'd love your your thoughts on this as we uh analyze that this balance I hear in this committee um in particular as we look at some states that are probably doing things that actually, if they implemented, would do more harm to consumers than good.
▶ 2:53:44Uh can you talk about the existing landscape of state data privacy laws uh and maybe give us some some indication of what, in your opinion, what states are on the right track and what states are on the wrong track as it relates to giving consumers the best products available and protecting them. There are 17 states that have adopted uh what we call the consensus privacy approach. Virginia was the first state to adopt this model and it's uh spread in other states like Kentucky and and Montana and and even now all the way out in the West Coast in Oregon.
▶ 2:54:12Uh and it it provides very workable privacy rights um where there is a data minimization standard where uh companies have to use data in a way that's relevant and reasonable in relation to how they disclose it to consumers, but then gives them a whole uh bevy of other rights, right to delete, right to opt out of data sales, right to opt out of things like targeted advertising across non-affiliated websites.
▶ 2:54:34But at the same time, we are seeing an influx of new proposals in other states that could really upset this balance and create conflict and confusion. For example, Maryland has passed the online data privacy act, which would bar the collection of any sensitive data. And as I talked a little bit earlier is that is that you know we heard the conversation earlier about disparate impact. I don't know how as a company you run a disparate impact analysis and stay compliant if you don't have the full picture of data.
▶ 2:55:03And people operating in other states are then in effect, right? Because we're one one economy or then beholden to the least common denominators. If one state gets it wrong, all states can be negatively impacted. Is that accurate? I mean, we've heard that states are the laboratories of democracy and sometimes bad experiment experiments leak. And and I think we want to be in a position where we make sure that we have one cohesive set of rules across the country.
▶ 2:55:26Thank you for your testimony. I appreciate all of you being here. Mr. Chairman, I yield back. Thank you. Next, we have the gentleman from Indiana, Mr. Stutzman is now recognized for 5 minutes. Thank you, Mr. Chairman, and thank you, panel, for being here. I'd like to begin with GLBA's legal framework and how it interacts with state laws. As we know, GLBA sets a federal floor.
▶ 2:55:48States can then enact additional data privacy laws should they choose to do The result is a patchwork framework in which businesses in different states can face different financial data privacy standards.
▶ 2:56:01For example, in Indiana, if a business is classified as a financial institution under GLBA, like a bank or credit union, it is typically exempt from the state's data privacy However, in California, those same GLBA-compliant businesses are held to the additional heightened standards of California's financial privacy laws. Ms.
▶ 2:56:24Kim, I'd like to ask you, could you describe the kinds of compliance burdens and barriers to competition this patchwork quilt across the country creates for financial institutions? Yes, thank you for the question. Um the compliance burden that results from this patchwork is you get multiple compliance teams, one handling federal regulations, one handling handling the state level.
▶ 2:56:50Um also in terms of audit teams, you may have different expectations based on state by state. Um these are all valuable resources that could be spent elsewhere. Um so it's high it it So as a result, a lot of uh businesses or new market entrants uh would avoid avoid high-cost states um and take their business elsewhere, limiting that service. So follow up on that, from a consumer's perspective, what might those burdens and barriers look like?
▶ 2:57:18And would California's more stringent requirements effectively limit certain firms from operating or offering particular products in the state? You mentioned that a little bit, could you expand on that a little bit? Uh yes. Um so I would agree with that final point on uh limiting service um to California, for example, um for having uh overlapping state uh rules as well.
▶ 2:57:38And I think on the consumer side, what you're what you're met with are kind of this uh this picture of the multiple stacks of of notices because you're dealing with competing uh regulations. You're you're faced with also learning about your different rights. There's opt-in versus opt-out. Um it's very confusing for the for the actual consumer, and it probably lowers overall privacy awareness.
▶ 2:58:01All right. Um and so Mr. our Vice Chairman uh Huizenga's discussion draft to this hearing would establish a national financial data privacy standard that preempts more burdensome state laws, such as those in California. So I'd like the entire panel, with about 30 seconds for each of you, uh do you support creating a uniform national standard and if so, why? Why don't we start down on the my right, your left. Yeah. And just go right down the line. No. The states that move forward did so because the federal framework fell short.
▶ 2:58:30this bill maintains an opt-out approach, sets response timelines that are weaker than both than both Europe and California, includes a consent exception so broad the industry can basically just keep doing what it's always done so long as it documents it and has no private right of action. This converts the floor to a ceiling at a moment when federal enforcement has been deliberately diminished. It's deregulation dressed as
▶ 2:58:55no. Um, Mr. Crenshaw. Absolutely in favor because a patchwork of state laws including things like opt-in and strict data minimization put us at risk of a financial and [snorts] and technology leadership. All right. Mr. Bombs. I do support of a preemptive federal statute provided that consumer control rules the day under that federal framework. All right. Ms. Kim. Um, yes. Interstate banks would need one clear rulebook. All right. Thank you. Mr. Kim.
▶ 2:59:22Absolutely support preemption. Um, I think it's the right result for the American consumer that we all have the same rights regardless of where we live. Very good. I I've got a minute so I'm going to go to Mr. Crenshaw. Um GLBA does not include a private right of action that would allow consumers to sue firms for alleged violations. While some of my colleagues across the aisle would support such a right, federal courts have consistently reaffirmed that no such rights exist under current law.
▶ 2:59:49What negative consequences might result from creating a private right of action? Would some type of businesses feel those impacts more than others? Small businesses are more inclined to settle because they're afraid of incurring legal costs and that's why having out of control private rights of action are a problem. It's also an important note why we have strong preemption because there are attempts to get creative in inserting private rights of action in other laws that would regulate privacy in the states as well.
▶ 3:00:16And so, if we have one clear set of privacy rules that occupies the field of preemption, we can also prevent those abusive lawsuits that are going to get creatively snuck into other state laws from from going forward. Very good. Thank you, Mr. Chairman. I'll yield Thank you. I would like to thank all the witnesses for testimony today. Without objection, all members will have 5 legislative days to submit additional written questions for the witnesses to the chair. The questions will be forwarded to the witnesses for their response. Witnesses, please respond no later than April 21, 2026.
▶ 3:00:47Again, thank you for your time, and this hearing is