The Federal Trade Commission (FTC) has delayed enforcement for the new “Red Flags” data security laws – again – to give mortgage companies and other non-bank financial institutions more time to come under compliance.
But by Aug. 1, any company handling sensitive customer data like credit card, bank account and Social Security numbers must have programs to detect and respond to security breaches. Every financial institution should already be in compliance – the original deadline was Nov. 1, 2008 – but the FTC has promised to delay enforcement to allow smaller companies to catch up.
Take Three
“A lot of it is about writing the program for the institution, training the employees and then maintaining records,” said Elisabeth Phalen, treasurer for the Massachusetts Mortgage Bankers Association (MMBA). “While postponing it might be necessary in order to get this implemented properly, it is important that the concepts within the regulations are followed and adhered to, given the heightened numbers of identity thefts that are still happening.”
This is the second time the FTC has delayed enforcement, with the previous deadline set at May 1, but many companies were still lagging behind.
“We are aware, though, that there are some sectors out there, and they tend to be of the lower risk variety, were just getting their feet underneath them and realizing they do need to get into compliance with this,” said Betsy Broder, the FTC’s assistant director in division of privacy and identity protection. We heard a lot from the health care sector, particularly smaller practices that routinely defer payments for their patients and therefore are creditors.”
Most large companies and banks have had their plans in place since November. But with the decimation of the mortgage industry, reduction in staffing and the subsequent low interest rate refinance boom, Phalen said many small mortgage shops have had to put compliance to the “Red Flags” law on the back burner, too.
Broder said coming into compliance with the law can actually be a major boon to companies, which use the training component as a trial run for an actual identity theft disaster.
“Some of the most complex and sophisticated institutions … from the beginning said, ‘You don’t know how hard this is going to be,’” Broder said. “Then at the end, they said ‘What a valuable exercise this has been.’”
Broder also pointed to another benefit: saving money.
“Our articulated goal is to protect consumers from fraud, but if companies aren’t being defrauded, then they aren’t losing money,” she said.





