Sunbelt Lending Services, Inc
Volume 139 · 139 F.T.C. 1
privacy data securitycredit lending
Cite this decision
Sunbelt Lending Services, Inc, 139 F.T.C. 1 (2005). Consumer Law Library, https://consumerlawlibrary.org/decisions/v139-0001
Report an error in this record (decision id v139-0001)
Cited by 0 later FTC decisions
Cites
Text (OCR of the scan at left; may contain errors)
IN THE MATTER OF SUNBELT LENDING SERVICES , INC.
CONSENT ORDER, ETC., IN REGARD TO ALLEGED VIOLATIONS OF THE GLB SAFEGUARDS RULE AND THE GLB PRIVACY RULE Docket C-4129; File No. 0423153 Complaint, January 3, 2005--Decision, January 3, 2005 This consent order, among other things, prohibits the respondent, a Floridabased corporation, from violating the GLB Safeguards Rule and the GLB Financial Privacy Rule, and requires the respondent, for ten years, to secure biennial assessments and reports to ensure that its information security program complies with the Safeguards Rule and is sufficiently effective to provide reasonable assurance that the security, confidentiality, and integrity of customer information is protected.
Participants For the Commission: Susan E. McDonald, Kathryn Ratte, Jessica L. Rich, Joel Winston, and Louis Silversin. For the Respondent: Richard Andreano, Jr., and Mitchel H. Kider, Weiner Brodsky Sidman Kider PC. COMPLAINT The Federal Trade Commission (“Commission”), having reason to believe that Sunbelt Lending Services, Inc. has violated the provisions of the Commission=s Standards for Safeguarding Customer Information Rule (ASafeguards Rule@), 16 C.F.R. Part 314, and the Commission=s Privacy of Consumer Financial Information Rule (APrivacy Rule@), 16 C.F.R. Part 313, each issued pursuant to Title V of the Gramm-Leach-Bliley Act (AGLB Act@), 15 U.S.C. ' 6801 et seq., and it appearing to the Commission that this proceeding is in the public interest, alleges: 1. Respondent Sunbelt Lending Services, Inc. (ASunbelt@) is a Florida corporation with its principal office or place of business at 300 South Park Place Blvd., Suite 150, Clearwater, Florida 33759. VOLUME 139 Complaint Sunbelt is a wholly-owned subsidiary of Cendant Mortgage Corporation. In addition to conducting business from its headquarters location in Clearwater, Sunbelt conducts business through loan officers located in Coldwell Banker Residential Real Estate, Inc. (“CB Residential”) offices throughout the state of Florida. CB Residential is a subsidiary of Cendant Mortgage=s parent company, Cendant Corporation.
2. Sunbelt, a mortgage company, is a Afinancial institution,@ as that term is defined in Section 509(3)(A) of the GLB Act, and is therefore subject to the requirements of the Safeguards Rule and the Privacy Rule.
3. The acts and practices of respondent alleged in this complaint have been in or affecting commerce, as “commerce” is defined in Section 4 of the FTC Act, 15 U.S.C. ' 44. SAFEGUARDS RULE 4. The Safeguards Rule, which implements Section 501(b) of the GLB Act, was promulgated by the Commission on May 23, 2002, and became effective on May 23, 2003. The Rule requires financial institutions to protect the security, confidentiality, and integrity of customer information by developing a comprehensive written information security program that contains reasonable administrative, technical, and physical safeguards, including: A. Designating one or more employees to coordinate the information security program;
B. Identifying reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information, and assessing the sufficiency of any safeguards in place to control those risks; SUNBELT LENDING SERVICES, INC. 3 Complaint C. Designing and implementing information safeguards to control the risks identified through risk assessment, and regularly testing or otherwise monitoring the effectiveness of the safeguards= key controls, systems, and procedures; D. Overseeing service providers, and requiring them by contract to protect the security and confidentiality of customer information; and E. Evaluating and adjusting the information security program in light of the results of testing and monitoring, changes to the business operation, and other relevant circumstances. VIOLATIONS OF THE SAFEGUARDS RULE 5. Through loan officers located throughout the state of Florida, Sunbelt collects nonpublic personal information from its customers, including customer names, social security numbers, credit histories, bank account numbers, and income tax returns. From the Rule=s effective date until at least April 2004, respondent failed to implement reasonable policies and procedures to protect the security and confidentiality of the information it collects.
6. For example, respondent failed to assess the risks to its customer information; implement reasonable policies and procedures in key areas, such as employee training and appropriate oversight of the security practices of loan officers working from remote locations; or oversee the collection and handling of information through the Sunbelt Website. Respondent also failed to take steps to ensure that its service providers were providing appropriate security for Sunbelt=s customer information.
7. By failing to implement reasonable security policies and procedures, respondent engaged in violations of the Safeguards Rule, including but not limited to:
VOLUME 139 Complaint A. Failing to identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information;
B. Failing to implement information safeguards to control the risks to customer information and failing to regularly test and monitor them;
C. Failing to develop, implement, and maintain a comprehensive written information security program; D. Failing to oversee service providers and failing to require them by contract to implement safeguards to protect respondent’s customer information; and E. Failing to designate one or more employees to coordinate the information security program.
8. A violation of the Safeguards Rule constitutes an unfair or deceptive act or practice in violation of Section 5(a)(1) of the FTC Act.
PRIVACY RULE 9. The Privacy Rule, promulgated under Section 502 of the GLB Act, went into effect on July 1, 2001. The Rule requires financial institutions, inter alia, to provide customers with clear and conspicuous notices, both when the customer relationship is formed and annually for the duration of the customer relationship, that accurately reflect the financial institution=s privacy policies and practices.
VIOLATIONS OF THE PRIVACY RULE 10. From the Rule=s effective date until at least April 2004, respondent failed to provide its online customers with the notices required by the Privacy Rule.
SUNBELT LENDING SERVICES, INC. 5 Complaint 11. A violation of the Privacy Rule constitutes an unfair or deceptive act or practice in violation of Section 5(a)(1) of the FTC Act.
12. The acts and practices of respondent as alleged in this complaint constitute unfair or deceptive acts or practices in violation of Section 5(a)(1) of the FTC Act. THEREFORE, the Federal Trade Commission this third day of January, 2005, has issued this complaint against respondent. VOLUME 139 Decision and Order DECISION AND ORDER The Federal Trade Commission having initiated an investigation of certain acts and practices of the Respondent named in the caption hereof, and Respondent having been furnished thereafter with a copy of a draft Complaint that the Bureau of Consumer Protection proposed to present to the Commission for its consideration and which, if issued by the Commission, would charge Respondent with violation of the Federal Trade Commission’s Standards for Safeguarding Customer Information Rule (“Safeguards Rule”), 16 C.F.R. Part 314, and the Federal Trade Commission’s Privacy of Consumer Financial Information Rule (“Privacy Rule”), 16 C.F.R. Part 313, each issued pursuant to Title V of the Gramm-Leach-Bliley Act, 15 U.S.C. § 6801 et seq., and Section 5(a)(1) of the Federal Trade Commission Act, 15 U.S.C. § 45(a)(1); and Respondent, its attorney, and counsel for the Commission having thereafter executed an Agreement Containing Consent Order (“Consent Agreement”), an admission by Respondent of all the jurisdictional facts set forth in the aforesaid draft Complaint, a statement that the signing of said Consent Agreement is for settlement purposes only and does not constitute an admission by Respondent that the law has been violated as alleged in such Complaint, or that the facts as alleged in such Complaint, other than jurisdictional facts, are true, and waivers and other provisions as required by the Commission's Rules; and The Commission having thereafter considered the matter and having determined that it has reason to believe Respondent has violated the said Rules, and that a Complaint should issue stating its charges in that respect, and having thereupon accepted the executed Consent Agreement and placed such Consent Agreement on the public record for a period of thirty (30) days for the receipt and consideration of public comments, now in further conformity with the procedure described in Section 2.34 of its Rules, the Commission hereby issues its Complaint, makes the following jurisdictional findings and enters the following Order: SUNBELT LENDING SERVICES, INC. 7 Decision and Order 1. Respondent Sunbelt Lending Services, Inc. is a Florida corporation with its principal office or place of business at 300 South Park Place Blvd., Suite 150, Clearwater, Florida 33759. Sunbelt is a wholly-owned subsidiary of Cendant Mortgage Corporation.
2. The Federal Trade Commission has jurisdiction of the subject matter of this proceeding and of Respondent, and the proceeding is in the public interest.
ORDER DEFINITIONS For purposes of this order, the following definitions shall apply:
1. ACommerce@ shall mean as defined in Section 4 of the Federal Trade Commission Act, 15 U.S.C. ' 44. 2. Unless otherwise specified, Arespondent@ shall mean Sunbelt Lending Services, Inc., its successors and assigns and its officers, agents, representatives, and employees. 3. All other terms are synonymous in meaning and equal in scope to the usage of such terms in the Gramm-Leach-Bliley Act, 15 U.S.C. ' 6801 et seq.
I.
IT IS ORDERED that respondent shall not, directly or through any corporation, subsidiary, division, Web site, or other device, violate any provision of the Gramm-Leach-Bliley Act=s (AGLB Act@) Standards for Safeguarding Customer Information Rule (ASafeguards Rule@), 16 C.F.R. Part 314, or the Gramm- Leach-Bliley Act’s Privacy of Consumer Financial Information Rule (APrivacy Rule@), 16 C.F.R. Part 313. VOLUME 139 Decision and Order In the event the Safeguards Rule or Privacy Rule is hereafter amended or modified, respondent’s compliance with these Rules as so amended or modified shall not be a violation of this order.
II.
IT IS FURTHER ORDERED that, in connection with its compliance with the Safeguards Rule, respondent shall obtain an assessment and report (an AAssessment@) from a qualified, objective, independent third-party professional, using procedures and standards generally accepted in the profession, within one hundred and eighty (180) days after service of the order, and biennially thereafter for ten (10) years after service of the order, that:
A. sets forth the specific administrative, technical, and physical safeguards that respondent has implemented and maintained during the reporting period; B. explains how such safeguards are appropriate to respondent’s size and complexity, the nature and scope of respondent=s activities, and the sensitivity of the nonpublic personal information collected from or about consumers;
C. explains how such safeguards meet or exceed the protections required by the Safeguards Rule; and D. certifies that respondent=s security program is operating with sufficient effectiveness to provide reasonable assurance that the security, confidentiality, and integrity of nonpublic personal information is protected and, for biennial reports, has so operated throughout the reporting period. Each Assessment shall be prepared by a person qualified as a Certified Information System Security Professional (CISSP); a person qualified as a Certified Information Systems Auditor SUNBELT LENDING SERVICES, INC. 9 Decision and Order (CISA); a person holding Global Information Assurance Certification (GIAC) from the SysAdmin, Audit, Network, Security Institute (SANS); or by a similarly qualified person or organization approved by the Associate Director for Enforcement, Bureau of Consumer Protection, Federal Trade Commission. Respondent shall provide the first Assessment, as well as all plans, reports, studies, reviews, audits, audit trails, policies, training materials, and assessments, whether prepared by or on behalf of respondent, relied upon to prepare such Assessment to the Associate Director for Enforcement, Bureau of Consumer Protection, Federal Trade Commission, Washington, D.C. 20580, within ten (10) days after the Assessment has been prepared. Respondent shall retain all subsequent biennial Assessments until the order is terminated and shall retain all materials relied upon in preparing each such Assessment, as listed above, for a period of three (3) years after the date of preparation of such Assessment. Respondent shall provide such subsequent Assessments and related materials to the Associate Director of Enforcement within ten (10) days of request.
III.
IT IS FURTHER ORDERED that respondent shall deliver a copy of this order to all current and future principals, officers, directors, and managers, and to all current and future employees, agents, and representatives having supervisory responsibilities with respect to the subject matter of this order. Respondent shall deliver this order to such current personnel within thirty (30) days after the date of service of this order, and to such future personnel within thirty (30) days after the person assumes such position or responsibilities.
IV.
IT IS FURTHER ORDERED that respondent shall notify the Commission at least thirty (30) days prior to any change in the corporation that may affect compliance obligations arising under VOLUME 139 Decision and Order this order, including, but not limited to, a dissolution, assignment, sale, merger, or other action that would result in the emergence of a successor corporation; the creation or dissolution of a subsidiary, parent, or affiliate that engages in any acts or practices subject to this order; the proposed filing of a bankruptcy petition; or a change in the corporate name or address. Provided, however, that, with respect to any proposed change in the corporation about which respondent learns less than thirty (30) days prior to the date such action is to take place, respondent shall notify the Commission as soon as is practicable after obtaining such knowledge. All notices required by this Part shall be sent by certified mail to the Associate Director, Division of Enforcement, Bureau of Consumer Protection, Federal Trade Commission, Washington, D.C. 20580.
V.
IT IS FURTHER ORDERED that respondent shall within one hundred eighty (180) days after service of this order, and at such other times as the Federal Trade Commission may require, file with the Commission a report, in writing, setting forth in detail the manner and form in which it has complied with this order. This report shall include a copy of the initial biennial Assessment required by Part II of this order. VI.
This order will terminate on January 3, 2025, or twenty (20) years from the most recent date that the United States or the Federal Trade Commission files a complaint (with or without an accompanying consent decree) in federal court alleging any violation of the order, whichever comes later; provided, however, that the filing of such a complaint will not affect the duration of: A. Any Part in this order that terminates in less than twenty (20) years;
SUNBELT LENDING SERVICES, INC. 11 Decision and Order B. This order's application to any respondent that is not named as a defendant in such complaint; and C. This order if such complaint is filed after the order has terminated pursuant to this Part.
Provided, further, that if such complaint is dismissed or a federal court rules that the respondent did not violate any provision of the order, and the dismissal or ruling is either not appealed or upheld on appeal, then the order will terminate according to this Part as though the complaint had never been filed, except that the order will not terminate between the date such complaint is filed and the later of the deadline for appealing such dismissal or ruling and the date such dismissal or ruling is upheld on appeal.
VOLUME 139 Analysis Analysis of Proposed Consent Order to Aid Public Comment The Federal Trade Commission (“Commission”) has accepted a consent agreement, subject to final approval, from Sunbelt Lending Services, Inc. (“Sunbelt”). Sunbelt is a mortgage broker with headquarters in Clearwater, Florida. Sunbelt collects sensitive customer information, including customer names, social security numbers, credit histories, bank account numbers, and income tax returns, and is a “financial institution” subject to the Gramm-Leach-Bliley Act’s Standards for Safeguarding Customer Information Rule, 16 C.F.R. Part 314 (“Safeguards Rule”) and Privacy of Consumer Financial Information Rule, 16 C.F.R. Part 313 (“Privacy Rule”).
The proposed consent agreement has been placed on the public record for thirty (30) days for receipt of comments by interested persons. Comments received during this period will become part of the public record. After thirty (30) days, the Commission will again review the agreement and the comments received, and will decide whether it should withdraw from the agreement and take appropriate action or make final the agreement’s proposed order. This matter concerns Sunbelt’s alleged violations of the Safeguards and Privacy Rules. The Safeguards Rule, which became effective on May 23, 2003, requires financial institutions to implement reasonable policies and procedures to ensure the security and confidentiality of customer information, including: • Designating one or more employees to coordinate the information security program;
• Identifying reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information, and assessing the sufficiency of any safeguards in place to control those risks;
• Designing and implementing information safeguards to control the risks identified through risk assessment, and regularly testing or otherwise monitoring the effectiveness of the safeguards= key controls, systems, and procedures; SUNBELT LENDING SERVICES, INC. 13 Analysis • Overseeing service providers, and requiring them by contract to protect the security and confidentiality of customer information; and • Evaluating and adjusting the information security program in light of the results of testing and monitoring, changes to the business operation, and other relevant circumstances. The Privacy Rule, which became effective on July 1, 2001, requires financial institutions to provide customers with clear and conspicuous notices that explain the financial institution’s information collection and sharing practices and allow customers to opt out of having their information shared with certain nonaffiliated third parties.
The Commission’s proposed complaint charges that Sunbelt failed to implement the protections required by the Safeguards Rule and, specifically, that it failed to: (1) identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information; (2) implement information safeguards to control the risks to customer information and regularly test and monitor them; (3) develop, implement, and maintain a comprehensive written information security program; (4) oversee service providers and require them by contract to implement safeguards to protect respondent’s customer information; and (5) designate one or more employees to coordinate the information security program. The proposed complaint also alleges that Sunbelt failed to provide its online customers with the notice required by the Privacy Rule. The proposed order contains provisions designed to prevent Sunbelt from future practices similar to those alleged in the complaint. Specifically, Part I of the proposed order prohibits Sunbelt from violating the Safeguards Rule or the Privacy Rule. Part II of the proposed order requires that Sunbelt obtain, within 180 days after being served with the final order approved by the Commission, and on a biennial basis thereafter for ten (10) years, an assessment and report from a qualified, objective, independent third-party professional, certifying that: (1) Sunbelt has in place a VOLUME 139 Analysis security program that provides protections that meet or exceed the protections required by the Safeguards Rule and (2) Sunbelt’s security program is operating with sufficient effectiveness to provide reasonable assurance that the security, confidentiality, and integrity of consumer’s personal information has been protected. This provision is substantially similar to comparable provisions obtained in prior Commission orders under Section 5 of the FTC Act. See Tower Records, FTC Docket No. C-4110 (June 2, 2004); Guess?, Inc., FTC Docket No. C-4091 (July 30, 2003); and Microsoft Corp., FTC Docket No. C-4069 (Dec. 20, 2002). Part II of the proposed order requires Sunbelt to retain documents relating to compliance. For the assessments and supporting documents, Sunbelt must retain the documents for three years after the date that each assessment is prepared. Parts III through VI of the proposed order are reporting and compliance provisions. Part III requires dissemination of the order now and in the future to persons with supervisory responsibilities. Part IV ensures notification to the FTC of changes in corporate status. Part V mandates that Sunbelt submit compliance reports to the FTC. Part VI is a provision “sunsetting” the order after twenty (20) years, with certain exceptions.
The purpose of this analysis is to facilitate public comment on the proposed order. It is not intended to constitute an official interpretation of the proposed order or to modify its terms in any way.
WHITE SANDS HEALTH CARE SYSTEM, L.L.C., ET AL. 15 Complaint