FTC Announces Enforcement for Inadequate Third-Party Risk Management Practices Under the GLBA's Safeguards Rule
Time 2 Minute Read

On December 15, 2020, the Federal Trade Commission announced a proposed settlement with Ascension Data & Analytics, LLC, a Texas-based mortgage industry data analytics company (“Ascension”), to resolve allegations that the company failed to ensure one of its vendors was adequately securing personal information of mortgage holders. The FTC alleged that Ascension’s vendor, OpticsML, stored documents with information, such as names, Social Security numbers and loan information, pertaining to tens of thousands of mortgage holders on a cloud-based server in plain text without any protections to block unauthorized access. The FTC further alleged that, as a result of the inadequate protections, the cloud-based server was subject to unauthorized access dozens of times.

In its complaint, the FTC alleged that Ascension violated the Gramm-Leach Bliley Act (“GLBA”) by failing to develop, implement and maintain a comprehensive information security program, as required under the GLBA’s Safeguards Rule. As part of such a program, financial institutions must vet and oversee vendors to ensure they are capable of implementing and maintaining appropriate security for customer information, in addition to including information security requirements in vendor contracts.

Pursuant to the proposed settlement, Ascension is required to implement a comprehensive information security program. In addition to implementing an information security program, the proposed settlement also requires Ascension to undergo biennial assessments of the effectiveness of its information security program by an independent organization, which the FTC has authority to approve. The proposed settlement also requires a senior manager to certify annually that the company is complying with the order and is not aware of any material noncompliance. Ascension must also report any future data breaches to the FTC within 10 days of notifying any other federal or state government agencies.

Andrew Smith, Director of the FTC’s Bureau of Consumer Protection, stated that “[o]versight of vendors is a critical part of any comprehensive data security program, particularly where those vendors can put sensitive consumer data at risk.”

Read the proposed settlement.

You May Also Be Interested In

Time 3 Minute Read

The Connecticut Attorney General recently issued a legal memorandum regarding the application of existing Connecticut laws, such as the Connecticut Data Privacy Act, to the use of artificial intelligence.

Time 3 Minute Read

On March 20, 2026, Oklahoma Governor Kevin Stitt signed SB 546 into law, enacting the Oklahoma Consumer Data Privacy Act, which will take effect on January 1, 2027.

Time 2 Minute Read

On February 5, 2026, Alabama Governor Kay Ivey signed Alabama House Bill 161, the App Store Accountability Act, establishing age categorization, age verification and parental consent requirements for mobile application marketplace providers operating in Alabama, effective January 2027.

Time 2 Minute Read

On March 5, 2026, the California Privacy Protection Agency announced that the agency had reached a settlement with Ford Motor Company resolving an enforcement action against the company that alleged noncompliance with the California Consumer Privacy Act’s opt-out of sale/sharing rights.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page