{"id":30518,"date":"2017-11-01T16:13:36","date_gmt":"2017-11-01T20:13:36","guid":{"rendered":"https:\/\/www.saratoga.com\/saratogabusinessjournal\/?p=30518"},"modified":"2017-11-02T17:15:42","modified_gmt":"2017-11-02T21:15:42","slug":"equifax-state-proposes-law-make-credit-agencies-meet-cybersecurity-standard","status":"publish","type":"post","link":"https:\/\/www.saratoga.com\/saratogabusinessjournal\/2017\/11\/equifax-state-proposes-law-make-credit-agencies-meet-cybersecurity-standard\/","title":{"rendered":"After Equifax, State Proposes Law To Make Credit Agencies Meet Cybersecurity Standard"},"content":{"rendered":"

In response to the recent cyberattack that exposed the personal private data of nearly 150 million consumers nationwide, the state Department of Financial Services has proposed a regulation making credit-reporting agencies have to register with New York for the first time and comply with this state\u2019s first-in-the-nation cybersecurity standard.<\/p>\n

The annual reporting obligation also provides the DFS superintendent with the authority to deny and potentially revoke a consumer credit reporting agency\u2019s authorization to do business with New York\u2019s regulated financial institutions and consumers if the agency is found to be out of compliance with certain prohibited practices, including engaging in unfair, deceptive or predatory practices.<\/p>\n

\u201cA person\u2019s credit history affects virtually every part of their lives and we will not sit idle by while New Yorkers remain unprotected from cyberattacks due to lax security,\u201d Gov. Andrew Cuomo said. \u201cOversight of credit reporting agencies will help ensure that personal information is less vulnerable to cyberattacks and other nefarious acts in this rapidly changing digital world. The Equifax breach was a wake-up call and with this action New York is raising the bar for consumer protections that we hope will be replicated across the nation.\u201d<\/p>\n

Under the proposed regulation, all consumer credit reporting agencies that operate in New York must register annually with DFS beginning on or before Feb. 1, 2018 and by Feb. 1 of each successive year for the calendar year thereafter. The registration form must include an agency\u2019s officers or directors who will be responsible for compliance with the financial services, banking, and insurance laws, and regulations.<\/p>\n

<\/p>\n

\u201cThe data breach at Equifax demonstrates the necessity of strong state regulation like New York\u2019s first-in-the-nation cybersecurity actions,\u201d said Financial Services Superintendent Maria T. Vullo. \u201cThis is one necessary action of several that DFS will take to protect New York\u2019s markets, consumers and sensitive information from criminals.\u201d<\/p>\n

The DFS Superintendent may refuse to renew a consumer credit reporting agency\u2019s registration if the superintendent finds that the applicant or any member, principal, officer or director of the applicant, is not trustworthy and competent to act as or in connection with a consumer credit reporting agency, or that the agency has given cause for revocation or suspension of such registration, or has failed to comply with any minimum standard.<\/p>\n

The proposed regulation also subjects consumer reporting agencies to examinations by DFS as often as the superintendent determines is necessary, and prohibits agencies from the following:<\/p>\n

\u2022 <\/b>Directly or indirectly employing any scheme, device or artifice to defraud or mislead a consumer.<\/p>\n

\u2022 <\/b>Engaging in any unfair, deceptive or predatory act or practice toward any consumer or misrepresent or omit any material information in connection with the assembly, evaluation, or maintenance of a credit report for a consumer located in New York state.<\/p>\n

\u2022 <\/b>Engaging in any unfair, deceptive, or abusive act or practice in violation of section 1036 of the Dodd-Frank Wall Street Reform and Consumer Protection Act.<\/p>\n

\u2022 <\/b>Including inaccurate information in any consumer report relating to a consumer located in New York state.<\/p>\n

\u2022 <\/b>Refusing to communicate with an authorized representative of a consumer located in New York state who provides a written authorization signed by the consumer, provided that the consumer credit reporting agency may adopt procedures reasonably related to verifying that the representative is in fact authorized to act on behalf of the consumer.<\/p>\n

\u2022 <\/b>Making any false statement or make any omission of a material fact in connection with any information or reports filed with a governmental agency or in connection with any investigation conducted by the superintendent or another governmental agency.<\/p>\n

In addition, every credit reporting agency must comply with the department\u2019s cybersecurity regulation, on phased in schedule of compliance, starting April 4, 2018.<\/p>\n

DFS\u2019s cybersecurity regulation requires banks, insurance companies, and other financial services institutions regulated by DFS to have a cybersecurity program designed to protect consumers\u2019 private data; a written policy or policies that are approved by the board or a senior officer; a chief information security officer to help protect data and systems; and controls and plans in place to help ensure the safety and soundness of New York\u2019s financial services industry.<\/p>\n","protected":false},"excerpt":{"rendered":"

In response to the recent cyberattack that exposed the personal private data of nearly 150 million consumers nationwide, the state Department of Financial Services has proposed a regulation making credit-reporting agencies have to register with New York for the first time and comply with this state\u2019s first-in-the-nation cybersecurity standard. The annual reporting obligation also provides […]<\/p>\n","protected":false},"author":196,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[],"class_list":["post-30518","post","type-post","status-publish","format-standard","hentry","category-business-news"],"yoast_head":"\r\nAfter Equifax, State Proposes Law To Make Credit Agencies Meet Cybersecurity Standard - Saratoga Business Journal<\/title>\r\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\r\n<link rel=\"canonical\" href=\"https:\/\/www.saratoga.com\/saratogabusinessjournal\/2017\/11\/equifax-state-proposes-law-make-credit-agencies-meet-cybersecurity-standard\/\" \/>\r\n<meta property=\"og:locale\" content=\"en_US\" \/>\r\n<meta property=\"og:type\" content=\"article\" \/>\r\n<meta property=\"og:title\" content=\"After Equifax, State Proposes Law To Make Credit Agencies Meet Cybersecurity Standard - Saratoga Business Journal\" \/>\r\n<meta property=\"og:description\" content=\"In response to the recent cyberattack that exposed the personal private data of nearly 150 million consumers nationwide, the state Department of Financial Services has proposed a regulation making credit-reporting agencies have to register with New York for the first time and comply with this state\u2019s first-in-the-nation cybersecurity standard. The annual reporting obligation also provides […]\" \/>\r\n<meta property=\"og:url\" content=\"https:\/\/www.saratoga.com\/saratogabusinessjournal\/2017\/11\/equifax-state-proposes-law-make-credit-agencies-meet-cybersecurity-standard\/\" \/>\r\n<meta property=\"og:site_name\" content=\"Saratoga Business Journal\" \/>\r\n<meta property=\"article:published_time\" content=\"2017-11-01T20:13:36+00:00\" \/>\r\n<meta property=\"article:modified_time\" content=\"2017-11-02T21:15:42+00:00\" \/>\r\n<meta name=\"author\" content=\"jessewinters\" \/>\r\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\r\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"jessewinters\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\r\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.saratoga.com\/saratogabusinessjournal\/2017\/11\/equifax-state-proposes-law-make-credit-agencies-meet-cybersecurity-standard\/\",\"url\":\"https:\/\/www.saratoga.com\/saratogabusinessjournal\/2017\/11\/equifax-state-proposes-law-make-credit-agencies-meet-cybersecurity-standard\/\",\"name\":\"After Equifax, State Proposes Law To Make Credit Agencies Meet Cybersecurity Standard - Saratoga Business Journal\",\"isPartOf\":{\"@id\":\"https:\/\/www.saratoga.com\/saratogabusinessjournal\/#website\"},\"datePublished\":\"2017-11-01T20:13:36+00:00\",\"dateModified\":\"2017-11-02T21:15:42+00:00\",\"author\":{\"@id\":\"https:\/\/www.saratoga.com\/saratogabusinessjournal\/#\/schema\/person\/b937a48daf87d7a8bd713a73b5d6a1ae\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.saratoga.com\/saratogabusinessjournal\/2017\/11\/equifax-state-proposes-law-make-credit-agencies-meet-cybersecurity-standard\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.saratoga.com\/saratogabusinessjournal\/2017\/11\/equifax-state-proposes-law-make-credit-agencies-meet-cybersecurity-standard\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.saratoga.com\/saratogabusinessjournal\/2017\/11\/equifax-state-proposes-law-make-credit-agencies-meet-cybersecurity-standard\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.saratoga.com\/saratogabusinessjournal\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"After Equifax, State Proposes Law To Make Credit Agencies Meet Cybersecurity Standard\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.saratoga.com\/saratogabusinessjournal\/#website\",\"url\":\"https:\/\/www.saratoga.com\/saratogabusinessjournal\/\",\"name\":\"Saratoga Business Journal\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.saratoga.com\/saratogabusinessjournal\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.saratoga.com\/saratogabusinessjournal\/#\/schema\/person\/b937a48daf87d7a8bd713a73b5d6a1ae\",\"name\":\"jessewinters\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.saratoga.com\/saratogabusinessjournal\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/b496e0843f9d888b12500994b6a8562b?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/b496e0843f9d888b12500994b6a8562b?s=96&d=mm&r=g\",\"caption\":\"jessewinters\"},\"url\":\"https:\/\/www.saratoga.com\/saratogabusinessjournal\/author\/jessewinters\/\"}]}<\/script>\r\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"After Equifax, State Proposes Law To Make Credit Agencies Meet Cybersecurity Standard - Saratoga Business Journal","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.saratoga.com\/saratogabusinessjournal\/2017\/11\/equifax-state-proposes-law-make-credit-agencies-meet-cybersecurity-standard\/","og_locale":"en_US","og_type":"article","og_title":"After Equifax, State Proposes Law To Make Credit Agencies Meet Cybersecurity Standard - Saratoga Business Journal","og_description":"In response to the recent cyberattack that exposed the personal private data of nearly 150 million consumers nationwide, the state Department of Financial Services has proposed a regulation making credit-reporting agencies have to register with New York for the first time and comply with this state\u2019s first-in-the-nation cybersecurity standard. The annual reporting obligation also provides […]","og_url":"https:\/\/www.saratoga.com\/saratogabusinessjournal\/2017\/11\/equifax-state-proposes-law-make-credit-agencies-meet-cybersecurity-standard\/","og_site_name":"Saratoga Business Journal","article_published_time":"2017-11-01T20:13:36+00:00","article_modified_time":"2017-11-02T21:15:42+00:00","author":"jessewinters","twitter_card":"summary_large_image","twitter_misc":{"Written by":"jessewinters","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.saratoga.com\/saratogabusinessjournal\/2017\/11\/equifax-state-proposes-law-make-credit-agencies-meet-cybersecurity-standard\/","url":"https:\/\/www.saratoga.com\/saratogabusinessjournal\/2017\/11\/equifax-state-proposes-law-make-credit-agencies-meet-cybersecurity-standard\/","name":"After Equifax, State Proposes Law To Make Credit Agencies Meet Cybersecurity Standard - Saratoga Business Journal","isPartOf":{"@id":"https:\/\/www.saratoga.com\/saratogabusinessjournal\/#website"},"datePublished":"2017-11-01T20:13:36+00:00","dateModified":"2017-11-02T21:15:42+00:00","author":{"@id":"https:\/\/www.saratoga.com\/saratogabusinessjournal\/#\/schema\/person\/b937a48daf87d7a8bd713a73b5d6a1ae"},"breadcrumb":{"@id":"https:\/\/www.saratoga.com\/saratogabusinessjournal\/2017\/11\/equifax-state-proposes-law-make-credit-agencies-meet-cybersecurity-standard\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.saratoga.com\/saratogabusinessjournal\/2017\/11\/equifax-state-proposes-law-make-credit-agencies-meet-cybersecurity-standard\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.saratoga.com\/saratogabusinessjournal\/2017\/11\/equifax-state-proposes-law-make-credit-agencies-meet-cybersecurity-standard\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.saratoga.com\/saratogabusinessjournal\/"},{"@type":"ListItem","position":2,"name":"After Equifax, State Proposes Law To Make Credit Agencies Meet Cybersecurity Standard"}]},{"@type":"WebSite","@id":"https:\/\/www.saratoga.com\/saratogabusinessjournal\/#website","url":"https:\/\/www.saratoga.com\/saratogabusinessjournal\/","name":"Saratoga Business Journal","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.saratoga.com\/saratogabusinessjournal\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.saratoga.com\/saratogabusinessjournal\/#\/schema\/person\/b937a48daf87d7a8bd713a73b5d6a1ae","name":"jessewinters","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.saratoga.com\/saratogabusinessjournal\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/b496e0843f9d888b12500994b6a8562b?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/b496e0843f9d888b12500994b6a8562b?s=96&d=mm&r=g","caption":"jessewinters"},"url":"https:\/\/www.saratoga.com\/saratogabusinessjournal\/author\/jessewinters\/"}]}},"_links":{"self":[{"href":"https:\/\/www.saratoga.com\/saratogabusinessjournal\/wp-json\/wp\/v2\/posts\/30518"}],"collection":[{"href":"https:\/\/www.saratoga.com\/saratogabusinessjournal\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.saratoga.com\/saratogabusinessjournal\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.saratoga.com\/saratogabusinessjournal\/wp-json\/wp\/v2\/users\/196"}],"replies":[{"embeddable":true,"href":"https:\/\/www.saratoga.com\/saratogabusinessjournal\/wp-json\/wp\/v2\/comments?post=30518"}],"version-history":[{"count":1,"href":"https:\/\/www.saratoga.com\/saratogabusinessjournal\/wp-json\/wp\/v2\/posts\/30518\/revisions"}],"predecessor-version":[{"id":30519,"href":"https:\/\/www.saratoga.com\/saratogabusinessjournal\/wp-json\/wp\/v2\/posts\/30518\/revisions\/30519"}],"wp:attachment":[{"href":"https:\/\/www.saratoga.com\/saratogabusinessjournal\/wp-json\/wp\/v2\/media?parent=30518"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.saratoga.com\/saratogabusinessjournal\/wp-json\/wp\/v2\/categories?post=30518"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.saratoga.com\/saratogabusinessjournal\/wp-json\/wp\/v2\/tags?post=30518"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}