Summary
- House Financial Services members debated a proposal to modernize the Gramm-Leach-Bliley Act by establishing a preemptive national financial privacy standard and granting consumers new data deletion rights.
- Nathan Taylor (Partner, Morrison & Foerster) testified that GLBA remains effective but should be updated with access and deletion rights to match evolving state-level privacy protections.
- Rep. Hill (R, AR-2) and Taylor discussed the importance of "technological neutrality" to ensure financial privacy laws remain functional as new innovations like agentic AI emerge.
- Rep. Waters (D, CA-43) and Democrats warned against weaponizing consumer data for immigration enforcement, while Rep. Barr (R, KY-6) and Republicans prioritized eliminating the "patchwork" of state regulations.
- The committee aims to reconcile industry calls for regulatory certainty with advocate concerns that federal preemption might lower consumer protection floors established by states like California.
Topics Discussed
Transcript
Opening Statements
Committee on Financial Services will come to order. Without objection, the chair is authorized to declare a recess of the committee at any time. Today's hearing is entitled Updating America's Financial Privacy Framework for the 21st Century. Without objection, all members will have five legislative days within which to submit extraneous materials to the chair for inclusion in the record. I now recognize myself for four minutes for an opening statement. Good morning. Today's hearing will examine the current state of consumer financial data policy and potential reforms to the Gramm-Leach-Bliley Act, or GLBA. I want to begin by emphasizing the importance of maintaining the technology-neutral framework of Gramm-Leach, which has readily adapted to innovation for over a quarter century and has the tools to continue to adapt as technology goes in directions that we cannot predict. We will also consider potential additions to the Gramm-Leach framework to give consumers greater control over their data while maintaining the smooth provision of financial services, to give financial institutions greater clarity about their obligations, and to promote competition and increase consumer choice. And as we consider these changes, we're working closely with our colleagues down the hall in the Energy and Commerce Committee to create a workable and comparable set of federal policies for consumer data while accounting for the nuances of the different types of firms, products, and services in our respective jurisdictions. As we consider additions to GLBA, we must strike a balance to achieve consumers' desire for greater control over their financial data on one hand, and on the other hand, their desire for financial services to work as seamlessly as possible and without having to wade through a sea of checkboxes and emails. As we consider additions like access rights, deletion rights, and data minimization standards, we must craft them in a manner that imparts greater control but without the unintended consequences that, for example, an unwitting deletion request could have on a consumer's smooth receipt of financial services. We must also recognize that the states have been running 26 years of experiments. With the results from these laboratories of democracy in hand, it's clear the time is now for a federal standard. Nationwide uniformity will promote competition by lowering barriers to entry created by the current state patchwork, which disincentivizes firms from entering new state markets and competing on price for the ultimate benefit of our consumers. Nationwide uniformity will also give consumers greater choice by making products currently only available in some states available to all. As we consider these and other changes to Gramm-Leach, we must above all be humble as the original authors who knew two key things. One, they could not predict what course technological innovation would take. And secondly, they took a cautious, considered approach that allowed for flexibility and innovation was the best path forward. I urge all of our members on both sides of the aisle in our work on this subject to use a scalpel, not a sledgehammer. And I really look forward to our panel of witnesses today. I yield back. I recognize the ranking member of the committee, Mrs. Waters, for four minutes for an opening statement.
Thank you, Mr. Chairman. In today's digital world, every click, search, and purchase leaves a trail. Yet Americans remain powerless when it comes to how their data is being used, shared, and sold. Companies pay millions of dollars to access it, to analyze it, and profit from it. But not a penny of those profits goes to consumers. And when that information falls in the wrong hands, it is weaponized against the very people it belongs to. This is exactly the risk we're facing now. Trump's administration ignores basic privacy guardrails and treats Americans' personal information like political pawns. For example, this administration has reportedly handed over sensitive personal data to the Department of Homeland Security to target immigrants living in the United States, including people who are here lawfully and have been here for years. Information that people living in America trusted the government to safeguard is now being weaponized to track, monitor, and intimidate entire communities. At the same time, Trump officials are punishing artificial intelligence companies like Anthropic for refusing to hand their technology over to the Department of Defense to conduct mass surveillance on Americans. And now we're learning that Donald Trump wants to turn banks into ICE checkpoints by requiring banks to hand over their customers' data. My Republican colleagues repeatedly decry the intrusive tactics of the Chinese government but are silent when Trump wants to deploy them here. Everyone in America should be alarmed. But this isn't the only terrible thing happening. Trump and Republicans are trying to dismantle the very federal agency responsible for protecting consumers, the Consumer Financial Protection Bureau. The CFPB was created after the financial crisis to protect consumers from abuse and to enforce safeguards around Americans' financial data. It has returned billions of dollars to consumers and held bad actors accountable. But instead of strengthening this agency, Republicans have spent years attacking it, and with Trump, their efforts have been intensified. Republicans voted to slash funding for regulators and weaken the federal workforce responsible for enforcing consumer protections. This means fewer investigators watching the marketplace and fewer protections for hardworking families. It also means Trump officials have let bad actors who admitted to ripping off consumers and even agreed to pay damages off the hook completely. Meanwhile, credit bureaus and data brokers continue to collect and sell Americans' most sensitive financial information every single day. Without strong guardrails in place, that data can be exploited not just by corporations looking to profit, but by bad actors eager to steal and use this data. Committee Democrats believe Americans should have the right to control their own data, plain and simple. Consumers should decide who gets access to their information and how it is used. And we must strengthen, not weaken, protections to make sure corporations, data brokers, law enforcement, and most importantly, the Trump administration cannot misuse our personal information. Protecting Americans' data is not just about privacy. It's about protecting our financial security and our freedom and our basic rights. That is exactly what this committee should be focused on here today. Thank you very much. I yield back.
Ranking member yields back. Chair recognizes the chair of the Subcommittee on Financial Institutions, Mr. Barr, for one minute for an opening statement.
Thank you, Mr. Chairman. Good morning. For over 26 years, GLBA has readily adapted to new technologies, new types of financial firms, and new types of data. In that same 26 years, the states have had ample opportunity to test different approaches and the results are clear. It is time for a national framework. Financial institutions should have consistent obligations, all American consumers should have the same choices for financial products and services, and competition and innovation should be promoted by making it easier to enter new markets. During a similar time period over the past few decades, we have also seen the drawbacks of private rights of action. We must resist the temptation to pursue this enforcement mechanism that would do nothing more than lead to fewer consumer options for financial products and services, potentially limit what options remain to only the well-to-do, and pad the pockets of the trial bar at the expense of consumers. Thank you, and I yield back.
Gentleman yields back. Chair recognizes the ranking member of the Subcommittee on Financial Institutions, Dr. Foster of Illinois, one minute opening statement.
Thank you, Chair Hill, and to our witnesses. In today's data-driven economy, financial institutions, tech companies, merchants, and many others collect vast amounts of information on American consumers, and that's not going to change in the coming era of agentic commerce when the very first thing that happens when my agent starts talking to your agent is that they both do the equivalent of scrolling down and hitting I accept, including on some very complicated and important privacy agreements. Since Congress enacted Dodd-Frank Wall Street Reform Act, the CFPB has led much of the federal government's efforts to protect Americans' financial data. The proposed rules from Dodd-Frank to implement open banking that would have given consumers control over their data and increase competition by making it easier for consumers to switch to a different bank. The Bureau was improving oversight over data brokers who gather and share troves of sensitive data on consumers. While I appreciate the focus on data privacy by this committee, Americans would be best served by allowing the CFPB and its dedicated staff to continue their important work. Look forward to hearing from our witnesses.
Gentleman yields back. Today we welcome the testimony of our panel: Mr. Nathan Taylor, partner at Morrison & Foerster; Ms. Clara Kim, senior vice president of the Bank Policy Institute; Mr. Steve Boms, the executive director of Financial Data and Technology Association; Mr. Jordan Crenshaw, senior vice president, U.S. Chamber's Technology Engagement Center; and Ms. Laura MacCleery, senior director for policy and advocacy at UnidosUS. Want to thank each of you for being with us today. Each of you will be recognized for five minutes to give an oral presentation to your testimony, for your testimony, and without objection, your written testimony will be made part of the record. We'll start with you, Mr. Taylor. You're recognized for five minutes.
Modernizing the Gramm-Leach-Bliley Act
Chairman Hill, Ranking Member Waters, members of the committee, my name is Nathan Taylor. I'm a partner at the law firm Morrison & Foerster. I've spent my legal career advising financial institutions on compliance with financial privacy laws, including Title V of the Gramm-Leach-Bliley Act. For more than 20 years, I've closely monitored the evolution of privacy law in the United States. I'm pleased to be here today to discuss my views on the GLBA and whether there is a need and if so, the appropriate way to modernize the GLBA. Since it was enacted in 1999, the GLBA has stood as the cornerstone of financial privacy law in this country. The GLBA is founded on two core pillars. First, the GLBA requires that a financial institution provide consumers with a privacy policy detailing its privacy practices. Over the past 25 years, I estimate that financial institutions have mailed their customers several billions of privacy notices. Second, the GLBA prohibits a financial institution generally from disclosing non-public personal information about a consumer to a non-affiliated third party without first providing the consumer with the opportunity to opt out of the disclosure. This opt-out right is significant, providing consumers with meaningful control over the disclosure of their non-public personal information. In my view, the GLBA and the privacy rights that it includes are as meaningful in 2026 as they were in 1999. Of course, over the last 25 years, privacy law has developed significantly in this country. Since California enacted the California Consumer Privacy Act in 2018, we have seen rapid development of privacy laws throughout this country. These state privacy laws typically include rights that are not found in the GLBA, such as access and deletion rights. And this of course begs the question, is there a need to modernize the GLBA? This question is debatable. What is not debatable in my view is that any updates to the GLBA must be done with care, with a clear understanding of the context in which the GLBA applies. Financial products are fundamentally different than, for example, social media accounts or online advertising that have been significant drivers behind the state privacy laws. In fact, the CCPA and the state laws that have followed it implicitly recognize this fact. These state privacy laws do not apply to information that's subject to the GLBA. Let me underscore this point. The state privacy laws that include rights not found in the GLBA do not themselves extend those rights to information that's subject to the GLBA. So, back to my original question: should the GLBA be modernized? First, I want to highlight that I believe the GLBA has stood the test of time, providing consumers with meaningful control over the disclosure of their non-public personal information. Nonetheless, in recognition of the evolution of privacy rights in this country, I do think it would be appropriate to update the GLBA to include certain additional rights. If this committee moves forward, I believe that any legislation should include three principles. First, I believe that a consumer should have a right to request that a financial institution provide the individual with access to or a copy of the non-public personal information that the financial institution maintains about the individual. Second, an individual who is a former customer of a financial institution should have a right to request that the financial institution delete non-public personal information that it maintains about the individual. Finally, a bill should preempt state laws. While I recognize that this point can be controversial, I believe that all Americans should be empowered with the same strong privacy rights for their financial information regardless of the states in which they may live. The alternative in my view is an inequitable result. Thank you for the opportunity to speak with you today, and I'd be happy to address any questions that you may have.
The gentleman yields back. And with that, Ms. Kim, you are now recognized for five minutes for an opening statement.
Banking Sector Privacy and Regulatory Oversight
Thank you. Chairman Hill, Ranking Member Waters, and honorable members of the committee, thank you for the opportunity to testify today. My name is Clara Kim, and I am a Senior Vice President at the Bank Policy Institute. Collectively, our banks employ nearly 2,000,000 Americans, make half of the nation's small business loans, and are an engine for economic growth. Financial institutions occupy a unique position in our economy. To keep the financial system safe and to serve customers effectively, banks must collect, use, and retain data in ways that are different from many other sectors. They have obligations under law to prevent fraud and illicit activity, and they rely on consumer financial data to do that work. This data is necessary for other activities and services, such as underwriting a mortgage for a first-time homebuyer or extending credit in underserved communities. In the decades since the Gramm-Leach-Bliley Act established federal privacy standards for financial institutions, many banking services have evolved from a brick-and-mortar face-to-face experience to an always-on digital experience. But while the technology of banking has transformed, GLBA has consistently afforded consumers strong baseline privacy and information security protections. Banks operate under a comprehensive regulatory framework for privacy and data use. These requirements are implemented and enforced through continuous supervision by federal prudential regulators. That combination, GLBA plus prudential oversight, has produced a robust sector-specific federal privacy regime that has worked for more than 25 years to protect consumers while allowing banks to perform their essential functions. The core principles of GLBA have worked well since it was established. In considering changes to the GLBA framework, it will be important to consider the potential for unintended consequences. GLBA was designed for financial institutions with careful calibration between privacy protections and the legitimate legally required uses of data that keep the system safe and inclusive. It has also proven adaptable. The federal regulators have updated implementing rules over time as technology, cyber threats, and consumer expectations have evolved. A key principle for any legislation in this area must be a national uniform financial privacy and information security standard with strong clear federal preemption. Today, comprehensive state privacy laws are typically drafted for a broad universe of entities, some of which are in the business of monetizing data. Almost no other sector has the same responsibilities as banks in terms of using data to manage fraud and credit risk or that is subject to the same degree of prudential supervision. Recognizing the distinct role of financial institutions, legislators in most states have chosen to exempt GLBA-regulated entities. Where state laws do reach into financial services, they can unintentionally interfere with core banking activities that can harm consumers or create conflicting obligations layered on top of the existing federal regime. Any modernized GLBA should provide a single preemptive national standard for the privacy and processing of personal information by financial institutions. To the extent Congress looks to incorporate concepts from state privacy laws, we urge a principles-based approach that respects the specific risk profile and legal obligations of financial institutions. Any new limits on collection, use, or retention should allow banks to gather and use information as necessary to provide requested products and services and for clearly disclosed purposes. If Congress is considering expanded individual rights, it is vital those rights be carefully tailored to the realities of banking. Deletion and similar rights must be reconciled with existing obligations, as well as with the need to preserve evidence of suspicious or criminal activity. Data minimization and similar concepts must be implemented in a way that does not inadvertently curtail essential internal uses, such as fraud detection, cybersecurity, risk management, and the development of alternative underwriting models that can expand access to credit for underserved communities. There is also room in our view to further streamline GLBA's notice requirements without changing the underlying balance of rights and obligations. Consumers expect a single clear privacy notice that is easy to find and understand. GLBA could be updated to better accommodate the use of a unified plain language notice, often made available online, that explains how data is collected, used, and safeguarded. Finally, one of GLBA's strengths is its technology-agnostic and principles-based approach, which allows banks and regulators to adapt to rapid changes without constantly rewriting the statute. If additional guardrails for emerging technology become necessary, they can and should be addressed through tailored guidance rather than by embedding technology-specific mandates into GLBA. There is also the risk that any prescriptive requirements could quickly become outdated as well. Thank you for your attention, and I look forward to your questions.
The gentlelady yields back. With that, Mr. Boms, you are recognized for five minutes for your oral remarks.
Open Banking and Fintech Data Standards
Thank you very much. Chairman Hill, Ranking Member Waters, and members of the committee, thank you for the opportunity to testify today. My name is Steve Boms, and I am the Executive Director of the Financial Data and Technology Association, or FDATA. We represent a diverse ecosystem of fintech companies and open banking platforms that empower over 100,000,000 Americans and small businesses to better manage their financial lives. The rapid growth of the fintech sector has injected vital competition to the marketplace, driving down costs and facilitating the efficient delivery of financial services. Whether helping consumers build savings through automated roundup apps, preventing fraud in real time, or helping small businesses manage their books or secure capital through alternative underwriting, these tools provide tangible benefits to everyday Americans. At the heart of this ecosystem is trust. Our members believe that consumers and small business owners must have full control over their financial data, including the right to share it with third parties, the right to have it protected when they do so, the right to understand how it is being used, and the right to withdraw their consent from it being accessed at any time. This open banking framework should be the lodestar for any modernization of federal data privacy laws. There is a common misconception that fintechs operate in a regulatory vacuum regarding privacy, but this is not the case. The Gramm-Leach-Bliley Act already unequivocally applies to the data and entities in the open banking ecosystem. This coverage is established through three mechanisms. First, the significantly engaged test, which applies to any entity significantly engaged in performing financial activities as a regular part of its business. Second, the 2021 finders rule, which expanded the definition of a financial institution under the act to include entities that bring together buyers and sellers in the financial marketplace. And third, service provider provisions, which mandate that platforms operate under a lattice of bilateral agreements that contractually require GLBA-level security and privacy features. Under this umbrella, open banking platforms are subject to prescriptive data security and privacy requirements, including providing customers with clear, conspicuous privacy notices at the point of interaction, employing robust data encryption protocols, deploying continuous penetration testing, and complying with data breach notification requirements, among many others. As the committee considers amendments to the GLBA, it is vital to distinguish these customer-permissioned platforms from data brokers. That distinction hinges on affirmative explicit consent. FDATA members access data only because a customer has provided permission to receive a specific service, such as a budgeting or a payment tool. Conversely, data brokers often acquire and sell data through secondary means without the customer's direct involvement. Open banking platforms are strictly bound under the GLBA and contractual terms by consumers' or small businesses' explicit consent and the rigid data minimization requirements of their requested use case. Applying data broker regulations to customer-permissioned open banking intermediaries risks negatively impacting competition and consumer choice. FDATA supports a single, robust, and federally preempted data privacy regime. A fragmented 50-state regulatory patchwork creates massive compliance hurdles, disproportionately harms small startup innovators, and favors large incumbents. This also results in a highly inequitable system where a consumer's or small business owner's fundamental privacy rights are dictated entirely by their zip code. Because data within it is already so heavily regulated under the GLBA, financial services represents one of the few marketplaces in which Congress can leverage a federal regime that already broadly applies and has served customers well for nearly 30 years. The GLBA is a logical vanguard for a national data privacy standard. The current decentralized approach to data protection and privacy in the U.S. is also at odds with the singular frameworks that have been deployed in other jurisdictions, including the EU and the United Kingdom. These jurisdictions have deployed regimes that could attract fintech and investment capital that might otherwise be deterred by the increasing complexity of the U.S. market. As it considers amendments to the GLBA, we urge the committee to consider four critical pillars in any consideration of revisions. First, we urge Congress to ensure that any new requirements do not inadvertently impede the rights of consumers to access, move, or use their own data. Second, consumers and small businesses should have the right to control data sharing, including to terminate that sharing immediately, with narrow exceptions for legal or regulatory requirements. Third, in the open banking context, the responsibility for correcting inaccurate data must remain with the data provider, the source, and not the platform acting as a secure conduit. And fourth, Congress should maintain the GLBA's agency enforcement mechanisms to ensure continued customer protection without harming innovation and competition. Thank you again for the opportunity to testify. FDATA's members remain committed to providing your constituents with innovative, secure financial products, services, and tools, and I look forward to your questions.
The gentleman yields back. With that, Mr. Crenshaw, you are recognized for five minutes for your oral remarks.
Federal Preemption and Enforcement Mechanisms
Thank you, Chairman Hill, Ranking Member Waters, and members of the committee for the opportunity to testify on today's hearing about updating America's financial privacy framework for the 21st century. My name is Jordan Crenshaw, and I serve as Senior Vice President at the U.S. Chamber of Commerce's Technology Engagement Center. For nearly a quarter century, the Gramm-Leach-Bliley Act or GLB has provided a reliable foundation for financial privacy. Now, as we look toward the future of data privacy, rather than creating a new framework, modernization efforts should focus on updating existing law through targeted policies that strengthen clarity, streamline compliance, and preserve the law's proven protections. My testimony today will focus on four key priorities for any federal privacy law. First, we must establish strong federal preemption to ensure a uniform national standard harmonizes rules. While modernizing the GLBA is important, the broader need for Congress to pass comprehensive national privacy legislation to ensure true uniformity across the country cannot be overstated. With the growing patchwork of state privacy laws, consumers face confusion, and this complexity disproportionately impacts small businesses, which often lack the resources to manage multiple regulatory regimes. A 2022 report from ITIF highlighted that a fragmented privacy landscape could cost the U.S. economy $1 trillion over 10 years, with 200 billion of that burden falling on small businesses. In a recent report from the Chamber on the impact of technology on U.S. small business, we found that 65 percent of small businesses nationwide are worried about having to comply with a patchwork of state privacy, AI, and technology regulations, which would drive up legal and compliance costs. That number is even higher in the financial services context for small businesses; that number is 71 percent. Businesses and consumers need a clear and consistent federal privacy law, which is why any updates to the GLBA and any future national privacy legislation must avoid duplicative regulations and promote harmonization. The bipartisan consensus approach, which has emerged in states like Kentucky, Texas, Minnesota, Iowa, Florida, Tennessee, and Nebraska, for example, provide a good example on how to do this. Second, we must have clear, predictable enforcement mechanisms. The Chamber supports enforcement authority being vested in appropriate federal and state agencies. For example, GLBA-regulated entities should be under the jurisdiction of their appropriate banking and financial regulators. Other entities regulated by general consumer privacy law should be under the jurisdiction of the Federal Trade Commission. These entities have the expertise and resources to enforce privacy laws while effectively maintaining a balanced approach that encourages compliance and innovation. However, the Chamber strongly opposes private rights of action to enforce privacy. The 17 states that have adopted the consensus privacy approach have explicitly rejected private lawsuits. Private rights of action have historically led to abusive and exploitative litigation with plaintiffs' attorneys benefiting disproportionately from settlements, providing little relief to consumers and creating inconsistent enforcement, as individual judicial districts may interpret privacy laws differently. Third, we must preserve access to data that enables socially beneficial uses, innovation, and risk management. We know that data is a cornerstone of the modern economy and is critical in solving our societal challenges. From improving public safety and healthcare to enabling financial inclusion and combating fraud, data-driven technologies have transformed how we solve complex problems. While data minimization is critical to safeguarding consumer privacy and security, standards that are too strict could impede innovation and the ultimate goal of protecting people and systems. We have seen states that have passed the consensus privacy approach have enacted balanced and workable minimization standards. By contrast, states like Maryland have enacted stricter data minimization requirements that could limit companies' ability to use personal data for important things like anti-fraud protection and help law enforcement with things like preventing against criminal activity and human trafficking. As Congress considers updating GLBA, the final point I'd like to leave the committee with today is that the Chamber stands ready to help with recommendations regarding issues like consumer notice, access, deletion, and opt-out rights. In conclusion, the U.S. Chamber of Commerce urges Congress to modernize GLBA in a manner that provides regulatory certainty and also adopt broader comprehensive privacy legislation. Both efforts should include strong federal preemption to eliminate a patchwork of state laws and provide a uniform standard for businesses and consumers; vest enforcement authority with proper federal and state agencies while avoiding private rights of action that lead to abusive litigation and inconsistent enforcement; and strike a balance on data minimization to protect privacy while enabling the beneficial uses of data that drive innovation and address societal challenges. By addressing these priorities, Congress can ensure that the United States remains a global leader in innovation, economic growth, and consumer protection. Thank you for the opportunity to testify today. I look forward to working with you.
Gentleman yields back. I appreciate all the succinctness today. Nobody's running over. That's unusual on this in this setting. With that, last but not least, Ms. MacCleery, you are recognized for five minutes.
Civil Rights and Government Data Surveillance
Thank you so much for the opportunity to testify. My name is Laura MacCleery. I'm senior director for policy and advocacy at UnidosUS, the nation's largest Latino civil rights organization with an affiliate network of 300 plus community groups. I've spent 25 years working for the public interest to support democratic systems, consumer protections, and civil rights. I wrote an amicus brief for the Congressional Hispanic Caucus defending the privacy rights of taxpayers, and I recently published an article in the ABA Journal calling on states to lead on data privacy under state constitutions. Latinos are a growth engine for the economy but underserved by financial institutions. The GDP of U.S. Latinos was $4 trillion in 2025, a total that ranks them fifth among nations. Yet low-income Hispanic households are unbanked at rates nearly five times that of comparable families. So Latinos need high-quality financial services alongside privacy rules that build trust and keep their personal data safe. I offer thoughts on the discussion draft in my written testimony, including that opt-outs in GLBA fail consumers because they default to the least protective choice. But the draft's most troubling feature is that it preempts states on data privacy and security. When Congress wrote GLBA, it specifically allowed states to go above a federal floor. California enacted opt-in consent. States like Colorado, Connecticut, Virginia, and more followed suit. The draft would block this progress while failing to raise standards, and the CFPB mainly would be charged with enforcing it. For context, industry has worked to undermine the authority of the CFPB since its creation. Most major initiatives challenged in court. The agency's funding went up to the Supreme Court in a case we joined as amicus. The agency won, but last summer Congress slashed its budget anyway. Now it's a hollow shell with few examinations ongoing and even an oath of humility for examiners. Consumer complaints at credit agencies are up; efforts to level rules of the road for participants across the financial marketplace withdrawn. Enforcement actions dropped or ending in collusive settlements that perpetuate injustice. In short, consumers would be at the mercy of an agency actively dismantling basic marketplace fairness standards rather than enforcing them. This federal government also cannot be trusted to safeguard anyone's privacy. Taxpayers were promised for decades that information they gave to the Internal Revenue Service would be kept confidential. Yet the IRS was asked to share 700,000 records, then 7 million, then 1.28 million, and finally sent 47,000, which a federal judge said two weeks ago means the IRS broke the law at least 42,695 times. DHS initially asked for home addresses, employers, relatives, banking information, IP addresses, and Social Security or taxpayer identification numbers. The headlines are clear. Data surveillance is an urgent concern, and AI scales it. It makes scams and fraud more credible, and surveillance pricing is being used to microtarget consumers and rip them off. Any 21st-century privacy framework must grapple with what this means for fair markets, financial services, and our democracy. Here's one way it works. Whenever an ad appears on the internet, a bundle of your data has been sent to a global auction, which returns a personalized appeal. Those data can include your health concerns, addictions, children's names, ages, schools. With a little effort, almost anyone can know where we sleep, who we know, what we think, click, or buy. Under our Freedom of Information Act, people can request to see what the government has compiled about them. Access rights are a baseline alongside meaningful data minimization and deletion rights. I've personally wondered what we might learn if lawmakers had the temerity to ask commercial data brokers about the deeply personal information being collected about them and their families. Ordinary people can't get this information today, but perhaps lawmakers could. It may be illuminating. Given technology that we have right now and its increasing capabilities, we must ask ourselves what sort of power a government has if it can know everything about everyone all of the time. A genius of both GLBA and our system is checks and balances. Distributed authority means states can provide accountability when people need it. Still, we're not close to being ready. What the states have accomplished is important, but it's just a start. The truth is that data privacy is democratic infrastructure. We won't be able to keep our First Amendment freedom of speech or Fourth Amendment freedoms against unreasonable search and seizure if we fail to create stronger legal protections for data rights or allow ourselves to experiment to find out what works for consumers. So if the key question on the table today is whether states should continue to be able to protect people on data privacy and security, my answer is yes, because leadership by these laboratories of democracy is our current best hope.
Technological Neutrality and State Law Patchworks
Thank you very much to the panel. We'll turn to member questions. I recognize myself for five minutes for questions. Mr. Taylor, I want to talk start out on the topic of technological neutrality. You know, when Gramm, Leach, Bliley, and group wrote GLB back in 1999, they had internet was brand new and we were preparing for Y2K, and so technology was a booming topic. The stock market was booming with new technology innovations. And so people had no idea which way how technology would involve. And it's amazing how well this law's functioned over the last 25 years. I mean, exceptional. So could you tell us the benefits of trying for us as Congress to maintain that technological neutrality approach and you know, are there changes specifically you'd call for in our our draft?
It's a terrific question, and I was harkening back to the Y2K. We've come a long way. I mean, I think the key that that Congress achieved in 99 and that hopefully this committee will achieve in 2026 is to future-proof it. Future-proof the GLBA, ensure that come what may regardless of what types of new new financial products we might come up with or new types of financial institutions, that the same exact law applies across the board. And I think that Congress achieved that in 1999 with the with with its notice and opt-out rights that apply regardless of the nature of the financial product or service at issue, regardless of the information at issue, regardless of the type of financial institution at issue.
Thank you. Likewise, as we work to clarify this, we're really sensitive to the customer experience, which has been a lot of the advocacy on the part of fintech companies and traditional financial institutions that have worked really hard to enhance their customer service, but that does create this, you know, conflict. So Ms. Kim, let me turn to you. How do we strike the balance between consumers' control of their data with, you know, this idea of low-friction delivery in financial services while we also maintain the full effectiveness of the privacy features in GLBA?
Yes, thank you for your question. In our view, the notice and opt-out works because it gives that combination. It gives choice and it is simplistic. It is a way to balance consumer control of where their information goes, plus the added benefit of all the effective points underlying GLBA. So any kind of adjustment would, in our view, require some careful tailoring to not interfere with information that is necessary, for example, for fraud prevention or legal holds.
Just as a switch thank you for that. Just staying with you for a minute. Most state consumer privacy laws exempt either GLBA-compliant institutions or GLBA-compliant data, and this is important because that's one of the great strengths of Gramm-Leach is it extends all those authorities and protections out to anyone in that ecosystem connected to a compliant financial institution. But a lot of the states seem to be moving toward adopting a data-level only sort of exemption. That doesn't sound in keeping with Gramm-Leach. Would you agree with that, Ms. Kim, and what should we how should we reflect that?
Yes, I would definitely agree with that. The data exemptions that you mentioned, what what happens is it kind of forces these dual compliance regimes. So you have, you know, GLBA for the non-public information that is covered, and then you have state rules for other other types of data. This results in overlapping notices, increased costs...
Really hard to program your customer experience in that regard and keep track of it. I mean, is that part of the...
Right. And a lot of the costs will trickle down to the customers as well. So our our recommendation for that would be any modifications to the GLBA to include very strong federal preemption.
Mr. Boms, over the years that I've been in Congress, there's been a lot of conversation in the fintech space and certainly in previous privacy hearings that we've had about screen scraping and the preference for a lot of businesses for the use of APIs to protect people's data from hacking and mistakes. How do you feel we've adopted that in our approach and how do you where should we go from here on screen scraping?
Thank you, Mr. Chairman. So first, I would just say that everybody in the ecosystem would like to move more towards APIs and away from screen scraping, fintechs, banks, data providers, everybody. Ultimately, it's up to the data provider, which in this case is the bank, to make that determination of whether to make an API available or not. And you raise an important reality, which is that larger financial institutions typically have the resources available to deploy the APIs; smaller ones don't.
If you don't mind all of you, if you'd expand on that answer in in writing, it'd be helpful to us to make sure we get this right for all participants in the space. I yield back. Turn to the ranking member of the full committee, Ms. Waters, for five minutes for questions.
Thank you very much, Mr. Chairman. As we consider the issue of data privacy, I was just sitting here thinking about the fact that I and other members of this committee and several thousand other people were outside the Treasury Department after Elon Musk and some of the individuals who worked for him in his companies, SpaceX and Tesla, had gone into the Treasury and had access to Treasury payment systems as well as sensitive databases at the Consumer Financial Protection Bureau. Now, not only did Elon Musk and those who were not government employees, those that he brought in to work with him, I suppose to do whatever it is the President had created DOGE to do, but Elon Musk is a government contractor who should not have access to government information in all these other agencies. But this is all very outrageous and it's been alarming how the Trump administration has tried to shut down the Consumer Financial Protection Bureau, robbing consumers of their only federal watchdog focused on protecting them. And last week, we learned from a whistleblower that a former DOGE employee who had access to the Social Security Administration database may have shared Social Security data with the private employer that they went to work for. All of this is quite alarming with respect to the DOGE's access to data at the CFPB. I introduced a resolution of inquiry so we could learn more about what DOGE was up to, what information it's gained access to, and what has it done with the sensitive data. Ms. MacCleery, I want to thank you for being here today. And I want to ask what should our committee do to get this resolution taken up in this committee to investigate and better understand how the administration may have inappropriately accessed and used sensitive data on millions of people and businesses. It's unfair for me to ask you this when we're sitting here elected by the people to protect their private data and we have a President of the United States of America who disregards all of this, doesn't care about any of this, and Elon Musk and others who now have this data, they have this information. So thank you for being here, but I suppose I could ask you why while we have an administration who thinks like this and who exercises extraordinary power to get access to our private data and all of the people of this country, do you have any thoughts about what could or should be done?
Thank you so much for the question. It is a matter of public trust. And what was interesting in the litigation between the IRS and DHS over taxpayer privacy was that when the court ordered the administrative record to see what the exchanges were, the documents clearly showed that the privacy personnel within the IRS were sidelined in the process of filling these requests. The administrative record is lengthy, but it has a lot of the back and forth of the details and we've now learned that even the way that they had styled the request, they did it wrong. They failed to follow their own interpretation of the law in about 2,000 plus cases and they've had to admit that in court. So I would say you can file Freedom of Information Act requests, you can work with outside groups. Erie Meyer, the CFPB's former chief technologist, did submit a sworn affidavit in a case about DOGE access. He said no CFPB employee had ever been granted blanket access to all unclassified data, that the staff typically has to request access only to specific systems, of course, and have it approved by a supervisor, but DOGE staff began examining systems the same day they walked in. He described their access level as god tier. I think there's a lot that we don't know about what's happened at the agencies and the more they see, the more the courts have been troubled by the failure to follow even basic information security protocols, the government's own kind of rules for who can access what and for what reason. And there's a lot to dig in there. So I would suggest you use the legal tools that we all have available to ourselves to do what you can to develop the record.
Thank you so very, very much.
Chair recognizes the vice chairman of the full committee, Mr. Huizenga from Michigan. You're recognized for five minutes.
Screen Scraping vs. API Integration
Thank you, Chairman Hill, and I'm actually going to take your final question to Mr. Boms and ask everybody to very, very briefly expand, kind of a yes or no, do you think that the GLBA needs to be clarified with regard to screen scraping? That was the chairman's question. Give us a little preview of what your written answers are going to be. Mr. Taylor, do you think yes or no?
Candidly, I don't have a strong view.
Okay. Ms. Kim?
Would believe in a general ban, but maybe GLBA's not the right place to do so.
Okay. Mr. Boms?
Screen scraping is still a critical fallback option for millions of consumers. And so we don't believe that there should be a ban and we don't think GLBA is the right place.
And if I recall correctly, that was partially because of the size issue that you were bringing up. Okay. Mr. Crenshaw?
Likewise, no strong view.
Okay. Ms. MacCleery?
I'm sorry, could you repeat the question?
Do you think GLBA needs to be clarified with regarding to screen scraping?
I do think it would be helpful to have protocols that encourage APIs and standards for them.
All right. Mr. Boms, I'm going to come back to you. Do you believe that data aggregators are currently covered by GLBA Title V and in your view is the law clear on this?
Yes, Congressman, thanks for the question. Yes. FDATA's members, including the data aggregators, open banking platforms that are members, all believe and act as if the GLBA applies to them. As I mentioned in my testimony, there are three primary ways through the GLBA that they qualify as financial institutions. That includes the finders provision, it includes the service provider provision, and the significantly engaged test. So the answer is yes.
Okay. Mr. Taylor, you're nodding your head.
Yeah, I completely agree. I mean, I would highlight that when analyzing the definition of financial institution, it is technically complex, right? You have to refer back to Section 4(k) of the Bank Holding Company Act, and then you have to refer to Reg Y, and you have to go through and evaluate various permissible activities. But I would agree that under the financial and bank data processing activity that financial data aggregators are covered.
Private Rights of Action and Litigation Risks
Okay. Mr. Crenshaw, in your testimony, you spoke about the dangers of including a private right of action under GLBA. Can you expand on that a little bit for the committee as well as help us understand how a private right of action creates inconsistent enforcement?
Yes, happy to do so. One of the main concerns we have is that there is an incentive when you create private rights of action, particularly with statutory violations, that it incentivizes lawsuits that seek settlement and don't actually help consumers. We've seen many reports, even one from the CFPB, that show the average class action only gets $32 for a plaintiff or sometimes they get credit monitoring.
Wait a minute. It's not about the money back to those that have been injured?
That's, and in many of these class actions, that's the case.
I'm shocked that lawyers might be taking a large chunk of that. Okay, go ahead.
But going back to the district to district interpretation piece, it also incentivizes running to different courthouses and you get a different interpretation of the law everywhere you go. I'll give you one example that's happening right now.
So court shopping is real.
It's real. But there's also the California Invasion of Privacy Act, which is a wiretapping statute which was only meant really for telephonic communications, listening in on someone's phone call. Well, what we've seen because of the statutory violations that go with that law, a rush to sue anyone who has a website with basic internet functionality that collects data to sue under that invasion of privacy statute. And for example, there's a case right now in the Southern District of California where Adidas is named as a defendant and a judge has allowed that case to proceed, which means they have to go through discovery, they have to go through litigation costs. Then you have another district in the Northern District of California that has not allowed a case like this to go through. And so when you have private rights of action, it incentivizes a rush to the courts and you don't get one interpretation much like you on the other hand would get under a regulatory agency that's making calls through clarifications.
Okay. Mr. Taylor, real briefly, how important is it for Congress to avoid creating two federal financial data regimes?
I mean, I think it's clearly important that we have a single set of standard that applies across the country. You saw me pause in response to your question because of course the devil's in the details about how you define financial privacy because we have other federal laws like the Fair Credit Reporting Act and the Right to Financial Privacy Act.
Does what Mr. Crenshaw was describing, does that seem reasonable?
About this court case with Adidas?
About the disincentive or about why we should not have private rights of action.
Yeah, I fully agree with everything you just said.
Okay. Mr. Boms, finish up with you. How about you?
Totally agree.
All right. With that, Mr. Chairman, I will yield back.
Gentleman yields back. Gentleman from California, the ranking member of our Capital Markets Subcommittee, Mr. Sherman, you're recognized for five minutes.
First, want to comment on this invasion of our privacy at the IRS. I headed the second largest tax agency in our country before I came to Congress and we have a vested stake in assuring taxpayers that their tax information will only be used for tax collection. We want to encourage tax compliance. But what worries me more is a President who says he wants to deport the worst of the worst and then he goes after taxpayers. Let me assure you, drug kingpins do not file tax returns. We've been discussing about the CFPB. Remember they got $19.7 billion returned to Americans, $5 billion in civil penalties, but that isn't the most important thing. It's not remedying the abuse that's most important, it's preventing the abuse. We have fine police officers in Los Angeles and sometimes we rate them based upon the crimes they solve, but what's most important to me is the crimes they deter. So unfortunately, the majority party, at least in the executive branch, has defunded the police, those namely the police that prevent crime in the suites rather than the streets. Consumer advocates have a tendency to object to federal preemption. And that's reason, you know, that comes from the fact that often federal preemption brings us down to the lowest common denominator, the weakest standards and they're imposed nationwide. I tend to think that we can have national preemption when we have a high standard, a standard that matches the best of the states in the country rather than the weakest. And there are some advantages to preemption, chief among them reducing expenses that banks incur and keep in mind we saw with these tariffs that when you impose costs on corporations, eventually those costs are passed through to consumers. But the other advantage of course of national standards is half the country lives in states where they don't have good consumer protection and getting protection for them is almost as important as getting protection for those who live in great states like California. We need better regulation of third-party fintech companies with databases because it makes little sense to say we're protecting your data when it's in the bank computers, but then it can be transferred to other computers and it's not as well protected. Now first question, rule 1033 is being developed or was developed. The rule didn't ban screen scraping. Ms. Kim, what amendments or guidance do you have for improving the CFPB rule whether it's adopted at the administrative level or by us in Congress? Should we consider developing rules in this space to ensure financial data is safeguarded and should we prohibit screen scraping?
Thank you for the question. Yes, we know the CFPB is working on a rulemaking to address the issue and we look forward to seeing what they put out and making sure customer financial data is appropriately protected in all circumstances. We believe access to customer data held at a bank should be governed by the GLBA to avoid inconsistency and unintended consequences. And we support extending GLBA-like protections for customer data when it leaves the bank and enters into the data aggregation ecosystem. And overall yes, we would support a general ban on screen scraping.
Under the proposed rule or rule that's been stayed, institutions could not charge a fee for these third-party fintech companies to access the banks through their API porthole. Ms. Kim, how costly is it to develop and maintain these portholes and should we consider allowing institutions, particularly smaller institutions, for allow them to charge a fee?
Yes, thank you. We are paying attention to certain data exchanges that make the financial system safer by transitioning industry away from dangerous practices like screen scraping and toward APIs.
Gentleman yields back. Chair recognizes the gentleman from Oklahoma, Mr. Lucas, who chairs our task force on monetary policy. You're recognized for five minutes.
Thank you, Mr. Chairman. Let's start with you Ms. Kim. Let's pull back once again and look at the overall situation. What's the status quo and why might we need to update a few provisions of the Gramm-Leach-Bliley Act? Having served with Chairman Leach and Chairman Bliley, I still refer to it by the full title.
Yes, thank you. I mean we believe that GLBA is a simple but effective framework for privacy and information security. So any changes that we would recommend include things as I mentioned in my testimony, strong fully preemptive GLBA to ensure predictable standards across the board. Secondly, we definitely advocate for maintaining its technology neutrality and principles-based standards because we believe that is what has made it so relevant today.
Continuing with you Ms. Kim, the discussion draft that Chairman has noticed for the hearing codifies several rules and regulations currently in effect. What challenges do banks face without the durability that codification provides and what is the effect of regulatory whiplash in the data security framework? If we don't codify it and we do it by regulation, what's the risk that industry and individuals have to deal with?
I'm sorry, I will have to get back to you on that one.
Okay. Mr. Crenshaw, can you describe the interaction between the Gramm-Leach-Bliley and state laws and what are the risk of a patchwork of compliance regimes and where might a national standard be most helpful?
No, happy to do so. In terms of the broad-based consensus privacy approach that we've seen emerge in the states, and this is 17 states, blue states, red states, purple states have all embraced this compromise approach where there is an entity-level carve-out for Gramm-Leach-Bliley regulated entities. This provides regulatory certainty, it prevents overlap. We have though seen the first comprehensive privacy law in the country, it was California, only provides a data-level exemption at that point, only data that's subject to GLBA. And so that creates confusion both for consumers and also for financial institutions as well. But the bottom line is, what we need to do is see one set of rules of the road nationwide in terms of what national privacy legislation will look like. It's critically important because of the fact that I think it's been mentioned earlier in this hearing is that small businesses, small institutions do not have the same resources as larger companies do. For example, if you look at the recent California rulemaking that implemented the latest version of the California privacy law, it has been estimated that those risk assessment, cyber audits and insurance regs will actually cost small businesses $16,000 annually. That is funding that small businesses do not have in many cases and that's why it's so critically important if you look at this from the perspective of that's just California, you start adding on more regs or more conflicting requirements across the country, it's going to be incredibly difficult to be a startup or to be a small business trying to start up in your garage with a website trying to get online and compete. So we need one set of rules across the country to ensure we have consumers being certain of what their rights are but also give certainty to businesses as well about what the rules of the road are.
Mr. Crenshaw, the world has changed rather dramatically since 1999 when this law was signed into place. In your view, what are the provisions in Gramm-Leach-Bliley that need to be clarified?
Several I know, but... Well, what I would say is as part of the consensus privacy approach we've seen emerge in the states, they provide consumers access to things like access to data and also the right to delete. These are things that we're seeing in the discussion draft that are a very good start in terms of solidifying consumer rights. One of the other pieces that we've seen also in this discussion draft and we've seen in similar state privacy regimes is a data minimization component. And that data minimization component provides base privacy protections for consumers but then for more privacy-conscious consumers they can then access that data and they can also request that data be deleted. So it provides a more holistic approach to providing consumers with the protections that they want and need.
Thank you. And Mr. Chairman, I note that I appreciate the effort at codification. Whiplash is a real struggle for people who have to deal with this stuff. With that I yield back.
Gentleman yields back. Chair recognizes the gentleman, distinguished gentleman from Georgia, Mr. Scott, you're recognized for five minutes.
Well thank you Mr. Chairman for that nice compliment. Now Mr. Boms, I think the real key to this hearing is captured in this. That given the volume of the sensitive proprietary data collected by the SEC, it is very important that there are robust internal data protection controls and accountability structure, not only to safeguard from the growing cyber threats but to prevent the risk of internal misuse within the agency. So Mr. Boms, you've defined trust as fundamentally foundational to customer permission data portability and fintech adoption. So my first question to you is this. When the SEC's information security program is assessed as being ineffective, what is the comparable trust impact on registrants, market participants and investors who must submit sensitive data to the commission?
Thank you for the question Congressman. I can answer on behalf of our fintech members, not for the SEC and I'd love to share for you information about what they do to protect that data. The member companies under the GLBA today are required to have written information security programs that are updated continuously. There must be a qualified individual who is responsible for overseeing and enforcing that program. Periodic risk assessments must take place. Data must be encrypted both at rest and in transit. Multi-factor authentication is required for anybody who's accessing that information. And internally, there is the principle of least privilege, which is that employees of companies can only access the data that is absolutely required for them to do their job. All of these obligations also flow down contractually to any service providers.
Now the 2025 OIG report similarly highlighted issues tied to protect and detect elements and I would like to insert both of these reports into the record Mr. Chairman.
Without objection.
All right. Now my question on this is Mr. Boms, what is the root cause driving some of these findings? Is it people, is it process or technology? And we got super technology coming on us, IA, and it can do things in ways and I want to know how all of this, what do you see the playing field will look like in years ahead?
It's the million-dollar question Congressman. I don't think anybody can answer that question because the pace of change is happening so quickly in technology. In the context of the Gramm-Leach-Bliley Act and revisions to it, I think it underscores the need for a technology neutral approach. The oldest member company we have in FDATA is the same age as the Gramm-Leach-Bliley Act. They started business in 1999. It's a real kind of telling indication of the strength and the neutrality of that act that it still applies and is relevant to all of these companies today. And so given that we don't know five years, 10 years, 50 years from now what technology will mean, we need to keep that in mind. We think a lot at FDATA about agentic AI and what that means for data protection and for customer protection. And so as the committee thinks about changes to the GLBA, those are the types of technologies we think it should bear in mind.
Now, let me ask you this. You note that GLBA safeguards rules requirements covered entities to maintain what we call WISP, or written information security programs, with a qualified executive responsible for oversight, monitoring. Now, so my question is, should the SEC be held to a similar WISP-like standard for non-public proprietary data as collected?
Again, Congressman, I can't answer for the SEC, but all of our member companies do have written information security programs and comply with that requirement.
Thank you. You've been very helpful. Thank you.
The gentleman from Texas.
Thank you, Mr. Chairman. You see requests that I be allowed to place questions in the record after the hearing has expired.
That's without objection.
Thank you. Take care of that.
I now have the pleasure of recognizing another gentleman from Texas, our distinguished Mr. Sessions, you're recognized for five minutes.
Mr. Chairman, thank you very much. What a delight it is to have each of you to help us walk through your ideas about potential updates to the Gramm-Leach-Bliley Act. I am one of the few members, as Frank Lucas was, to have voted for this and was here during that period of time. And I think it's always important for us to revisit these issues, and each of you have provided really clear context to your answers. Mr. Crenshaw, I would like to come back to you as a senior member of the U.S. Chamber of Commerce. I think that your vision is somewhat broader than what we see necessarily here as individual members, and I appreciate you being here today. During your conversation with the committee, you said a number of things which I think I agree with. One of them was we need one set of rules nationwide. Then you went further to put that in some context where you said a clear direction for privacy laws evidently have been bettered, or at least in your opinion bettered, by several states as it directly relates to private rights of action. Then you spoke about that the cost of these may be somewhere near a billion dollars. I would like to have you balance that out for me of the need for regulatory oversight, the laws, but the need for maybe these states had performed in their instances a little bit better with laws. Could you please walk me through that issue?
Well, I would say, once again, I emphasize the fact that we do need one single national standard. And your home state, representative, Texas has one of these consensus privacy approach laws on the books that we think is actually a good model in terms of broader comprehensive privacy legislation. In fact, we have seen aggressive enforcement of the Texas Information and Privacy Security Act over the last few years since it was passed. So I think it's really important to note that it provides excellent consumer protections, a good data minimization standard, a right to have access to data, a right to delete data. And once again, also, it explicitly rejects private rights of action as an enforcement mechanism. We believe that expert agencies are the right agencies to enforce privacy legislation, whether it's GLBA or it's a comprehensive privacy law, because these agencies, they know the business of the companies under their jurisdiction. They understand data practices. They understand the law that they're working with. And that's why it's so critically important that we begin to take good aspects of these state consensus privacy laws like the ones we have in Texas and make them national.
So you have spoken about this and I am unaware, I'm sure my staff would have better visibility on this, have you approached, has the Chamber approached members of Congress on this committee about doing just that that you spoke of, or are we utilizing this hearing today to learn about what that approach might include?
Well, broadly speaking, from a comprehensive privacy approach that would fall outside of GLB, we believe that there's a lot that could be drawn upon in the consensus privacy approach. But also what we see in the discussion draft that's before us for the committee hearing today from Representative Huizenga, there are a lot of elements of that consensus privacy approach in there, like the right to access, right to delete, also a data minimization standard that does not outright block the use of innovation. And so we think that that's a good starting point for conversation and we applaud Representative Huizenga for his sponsorship of the discussion draft and the committee's leadership in willing to work with you all as you work through this legislation.
Well, it sounds...
Representative Sessions, do you mind if I add?
Yes, please. Thank you.
I actually don't have as a consumer advocate a blanket position against preemption of state laws. I've been in the position of arguing for preemption of menu labeling on restaurant menus, for example, in my career. I think it's really important to just understand, and the devil is in the details as some of my co-panelists have said, that on each of these provisions, take data minimization, there's a significant amount of language in the current proposal that would essentially allow legitimate business interests and is very broad to be the counter to data minimization. The deletion rights only apply to former customers and other sort of details. So it matters a lot that the very positive aspects of what we've seen that my co-panelists admit is important that's bubbling up from the states and the activity in this area is reflected in any bill that could possibly present as a preemption matter because you'll end the innovation in the states. And I think you're right, sir, that...
The gentleman's time has expired.
...that the lack of privacy rules also has a cost. It has a cost for fraud, it has a cost for pricing and all of that.
The gentleman's time has expired.
Mr. Chairman, thank you very much. I would yield back my time.
I thank the gentleman from Texas. Chair recognizes the gentleman from Illinois, Dr. Foster, who is the ranking member of our subcommittee on financial institutions. You're recognized for five minutes.
AI Governance and Financial Inclusion
Thank you, Mr. Chair. And I'd also like to thank Representative Sessions for jointly sponsoring with me the Stop ID Fraud and ID Theft Act, a bipartisan bill to start providing states with the resources to fully implement digital driver's licenses, mobile IDs, which are really the key tool in authenticating, proving you are who you say you are in an online transaction, which is really a precondition to have an effective privacy regime. I'd also like to thank our witnesses for their discussions of screen scraping versus API versus other agentic things. As someone, it's probably more than 25 years ago I did my first screen scraping piece of software, and the problem with that is that it breaks all the time and you have to actually handle the plain text passwords and other sensitive information. It is a security nightmare and it is very fragile compared to APIs which are better. And I'd also like to highlight the upcoming NIST activities in standardizing agentic communication, which is coming up in the next month. And when that, if we do that right, that will be the next generation of this past simple APIs. Now, the CFPB's rulemaking on personal financial data rights focused not only on consumer consent and access rights for personal financial data, but also the interoperability of information systems and data portability. These frameworks were to be standards-based, going so far as to choose an industry-led group, the Financial Data Exchange, to mediate the development of those standards. This is going to be absolutely crucial. Efforts like this will be absolutely critical in the coming age of agentic commerce. So Mr. Boms, can you speak of the importance of establishing strong standards for data portability, API structure, eventually agentic communication, and how those standards would support innovation and access to financial services?
Congressman, thank you for the question. Absolutely critical component of open banking and technology-based financial services moving forward. You mentioned APIs and the drive of the industry to get more towards APIs and away from screen scraping. If we think about that infrastructure as the railroad tracks basically on which the consumer permissioned data is flowing, it's important that those tracks be standardized across the entire ecosystem. So that when you're traveling from one country to another, you don't have to switch trains and get on a different set of tracks that only work with one set of rails. The industry's done a fantastic job of making that transition through the Financial Data Exchange. There are more than 100 million customer accounts that now flow through FDX APIs. But there is, there has to be this recognition that smaller institutions don't have the resources yet to build those APIs. And so that's a continual source of focus.
And I think that, yeah, the load on small institutions I think can be substantially lightened if the federal government would help support an open source implementation of a full compliance stack. If you're a small fintech startup or a small community bank, if you had access to at least one for nominal cost or zero cost, high quality, cyber secure, sort of an entire software stack for your back office from back office to compliance, I think that that would be the single best thing that we can do to encourage competition and survival of small community institutions. It is the compliance cost that kills small players. And a federally supported open source effort, FINOS, there's a group FINOS who is actually very active in this channel and I had meetings with them recently. I think they are, groups like that I think are going to be crucial in making this of necessity very complex software and very complex compliance something that is financially affordable to small players. Ms. MacCleery, what are the benefits to consumers when they have clear control over how their data is used and ported? Research shows that consumers find it very difficult to switch bank accounts and often stay with the same financial institution for many years. Other jurisdictions have additional measures to make switching financial institutions easier, like the UK's current account switch program, which allows consumer to simply ask their bank to move all their subscriptions, recurring payments, and direct deposits over to a new bank within a week. Do you believe this sort of flexibility would improve competition within the banking system?
Absolutely. Thank you for the question. S&P Global estimates depositors miss out on $40 billion in savings account interest every year because the largest banks pay below average rates and switching is difficult. The 1033 rule would have lowered those barriers by requiring data holders to provide information the consumers need to move, including bill pay instructions and transaction history. That's a pro-competition, pro-consumer, and pro-privacy matter because the rule imposed strict limits on what third parties could do with the data. Lowering barriers to switching while ensuring the switch is safe and private expands financial inclusion while protecting data. And you know, for portability concerns, I mean, I have a bank account that's bedecked with all sorts of old bills and I don't move banks just because it would be such a pain. So I think it's absolutely a basic consumer and competition issue.
Thank you. Yield back.
Gentleman yields back. Chair recognizes the chair of our Capital Markets Subcommittee, Ms. Wagner of Missouri, for five minutes.
I thank you, Mr. Chairman. Since its passage in 1999, I was not here in Congress then, the Gramm-Leach-Bliley Act has served as the basic data privacy framework for financial institutions across the United States. At the time of its enactment, Gramm-Leach-Bliley was an important step towards modernizing the rules that govern our financial services industry and providing guidance on how customers' data was to be handled. However, it has now been more than 25 years since its passage, and while the basic framework has held strong, we've seen countless changes take place in the financial services sector, and obviously the time is ripe for Congress to make much-needed updates. Since Gramm-Leach-Bliley was signed into law, a patchwork, and we've talked a little bit about it here today, of different compliance regimes has sprung up across the United States. Because it only sets a federal floor for data privacy regulation, states can enact more restrictive rules that require companies to handle data one way in my home state of Missouri and another way in California. Mr. Crenshaw, could you discuss the effects this patchwork of regulation creates on compliance and competition, please?
I'm happy to do so. One of the issues here when it comes to a patchwork is that it harms smaller entities more than it harms larger entities. Larger companies have the resources to bear compliance costs and can innovate around in ways some of the patchwork of regulations. The other piece to this as well is it harms national competitiveness in terms of having different laws in different states that potentially conflict. And one of the examples that is out there is SB 205, which is an AI law that passed in Colorado, which would have imposed a disparate impact liability on developers and deployers of artificial intelligence. At the same time, other states are not in coordination on things like data privacy. You've got a state like Maryland, which has now banned the collection of sensitive data. So if I don't have the data necessary to ensure that my AI is working in the way it's supposed to work or I'm following the law, I'm left in conflict right now over which law I'm going to actually abide by. And the U.S. is behind in those terms. If we look at the economic analysis of what Colorado is doing, we estimated that could be, just from the Colorado law itself, a $50 billion GDP hit, could cost 700,000 jobs. It's a major competitiveness issue for the United States.
Well, many state laws on data privacy requirements provide exemptions for Gramm-Leach-Bliley. Some states provide an exemption for entire financial institutions. Other states exempt requirements for specific regulated information. Then there are states that have enacted laws that do both. Mr. Taylor, could you discuss these approaches and what potential consequences they have individually or in combination?
Well, I think you articulated it well. You can approach this from two ways in terms of how the states have tackled this. There's the financial privacy laws that are similar to the GLBA, which candidly, since 1999, we've only seen a couple, California and Vermont stand out, and that was in the early 2000s, and then the state laboratory, if you will, has been shut down on the issue. Then separately, post-2018 with the CCPA, we've seen a huge proliferation of state privacy laws that Mr. Crenshaw was talking about. And to your point, all of them uniformly exempt data that's subject to the GLBA, and most exempt all financial institutions. So again, taking the laboratory analogy, it's closed, right? If you will, like they're not, the states aren't touching it. So you know, the cost of preemption is low. And on your preemption question, and I'm respectful of your time, Congresswoman, I agree with Mr. Crenshaw's comments about the burden of the patchwork, but I also come at, I land at the same result for a different reason, which is the equity to consumers. Right? Like it seems absurd that all of us in the room from different states could have the same exact credit card issued by the same bank, but we have different rights with respect to that credit card based on where we live and what our state legislatures did. That strikes me as an absurd result.
As we look to make updates to our federal privacy regulations, it is also crucial that we build on what Gramm-Leach-Bliley has gotten right. And under current guidelines, financial institutions are provided an exception to notice and opt-out requirements for sharing consumer data when it comes to fraud detection and prevention and mitigation. I'm going to submit my question for the record, Ms. Kim and anyone else who would like to do that, talking about the importance of maintaining this exception is important for financial institutions to fight fraud. So I'll wait for your response.
The gentlewoman's time has expired. If all of you would respond in writing to Ms. Wagner's question.
I yield back.
Gentlewoman yields back. The chair recognizes the gentleman from Missouri, our ranking member on our Housing and Insurance Subcommittee, Mr. Cleaver. You're recognized for five minutes.
Thank you, Mr. Chairman. Ms. MacCleery, I guess if I have to make this announcement, it means that maybe I'm not sure, but I want to move with the times. I don't want to be some kind of troglodytic member of Congress, but I've got to admit, this AI thing is giving me all kinds of unsettling feelings. Even in connection with churches like the Catholic Church, the Methodist churches, they're even struggling with what happens when a pastor has Reverend AI to put a sermon together. I mean, do we accept that? Just to show you how impactful this is going. But in terms of what we are supposed to do in this committee, I'm wondering what you, would you support a reasonable approach to AI, including safeguards to protect fairness, transparency, and privacy, especially for underserved communities and communities of color? I think history may look back on us with some hostility if we don't deal with AI. And I'm wondering what concrete policy steps do you think we need to ensure AI systems do not entrench or exacerbate already existing inequities?
Well, sir, that is the big question, isn't it? I really appreciate that. You know, we did a listening session just a few weeks ago with our affiliates and talking about whether their community-based organizations are able to use AI tools. And I'm a big proponent in making sure that our communities are technically caught up because I think, you know, we don't want a world that leaves them behind any more than it already does. And their big concern was data privacy. The reason why their staff feel uncomfortable using artificial intelligence in their work is because they don't know what's going to happen to the data and they can't protect the client records that they work with and the other details. So it is a huge impediment to adoption that we don't have data privacy rules for new technologies and that they don't follow the data streams as opposed to being kind of specific to entities. And it can be pro-innovation, of course, that we figure out how to adapt technologies to what consumers need in order to use them. That's been the nature of every technology we've ever had, is that it gets better over time and that that's a source of economic gain and innovation as well. To your sort of bigger question, I would say our UnidosUS governance of AI has three pillars. And we say voice, which means you have to make sure that the outputs are checked, that they're not discriminating against people when it comes to consequential decisions. And there are plenty of ways that you can do that. There's lots of literature on what are less discriminatory alternatives to judging the impact of lending or other kind of areas where economic goods are decided. So voice means that everyone gets a seat at the table and their views are part of the process of regulating AI. We propose like working groups at the federal level that would include wide ranges of stakeholders to look at how AI is actually being used, say in the classrooms or in healthcare, etc. Values is the other thing. It has to be consistent with democratic values. That's the second pillar. So it can't be extractive. It can't take intellectual property without compensation. It can't manipulate us without some kind of public awareness or interpersonal awareness. And it has to be safe to use for consumers. That's the AI psychosis and other problems. The third pillar that we have is investment, which means that we need to bring everybody up to a place where they can use these tools, where they have a voice in the political process that sets the rules for how they're governed. And we need to put some money behind that. So we've proposed a public-private foundation modeled on the CDC Foundation that would take in investment, have a board of stakeholders, and help train up community-based organizations to use the tools and to advocate about their safe use and what they're seeing about the uses and how they impact people on the ground. So that's how you can approach it. It's both with content and with process. We're certainly behind the eight ball in this technology. It's moving very fast and it's getting better very rapidly at this point in time because it's sort of coding itself. And so we have a lot of work to do to make sure that there's accountability and fairness in these systems.
Scary, scary, scary. Thank you.
Gentleman yields back. Chair recognizes the gentleman from Kentucky, the chair of our Financial Institutions Subcommittee, Mr. Barr. You're recognized for five minutes.
Thank you, Mr. Chairman. Before I begin, I would like to ask unanimous consent that three statements be entered into the record, one from the National Association of Mutual Insurance Companies, one from the Defense Credit Union Council, and a third from the American Council of Life Insurers.
Without objection, they'll be included in the record.
Thank you. Let me start with Ms. Kim. Because of GLBA's current framework and because it functions as a federal floor above which states can enact stricter laws and regulations, it has created a nationwide patchwork of standards. This, as you testified, increases compliance costs and creates barriers to entry into certain states for new firms. Those increased compliance costs and competition-killing barriers to entry result in consumers paying higher prices and having less choice. Can you tell us how moving GLBA to a federally preemptive standard would reduce compliance costs, increase competition, and improve consumer welfare?
Yes, thank you for your question. Yes, we strongly have advocated for a fully preemptive GLBA to ensure more predictable standards across the board. And I think as many of my co-panelists have said, most states already preempt at the entity level because they recognize the strengths of covering GLBA-covered financial institutions. A lot of these state privacy laws are written for entities with very other business models than financial institutions. And so we do believe that a fully preemptive GLBA would lower a lot of these compliance burdens.
Well, I think you've convinced me and Chairman Hill, but I know my friend the ranking member who comes from California is concerned about this. So what would you say to her about this?
I mean, we would say that a lot of the compliance burden that our financial institutions have taken on in terms of building separate compliance teams, holding different audits for different regulators, A, that hurts innovation in the financial services space, but I think it's a real opportunity cost. In any business, the resources that you spend in one area will be taken away from another area, and that includes providing better financial products and services to the consumer.
Well, thank you for that. And Mr. Crenshaw, there are some members on this committee on the other side of the aisle who are calling for a private right of action for data privacy, but they rarely speak about its costs. The reality has been that private rights of action result in companies stopping offering products and services altogether to avoid litigation or only offer them to a select group of customers, usually wealthier consumers, so that litigation costs can be minimized and offset by sufficient revenue. Do you think there are actually any benefits to a private right of action, and even if there are, are they outweighed by the significant costs that a private right of action would create?
In the context of privacy, no. And Mr. Chairman, in fact, one of the concerns that we have particularly, I addressed earlier issues around the fact that plaintiffs don't usually see the actual money from these settlements or very minimal, or we could get judicial confusion from these types of sue-and-settle attempts from private rights of action. But the other piece is this. When you look at things like data minimization standards like we have in the current draft before us or we see in the consensus privacy bills, they have data minimization standards that say that companies have to have reasonable use of data or here under the current draft, legitimate business uses. We support that kind of approach. But if you put that in front of a jury with private trial lawyers, we're going to litigate what that means in front of non-experts ad infinitum. And that's why it's so critically important that we put those kinds of decisions at enforcement agencies who actually know the businesses they're working with and have an incentive to go after bad actors.
I couldn't agree, I could not agree with you more. I think that makes a lot of sense. Mr. Boms, everyone, myself, my constituents, my colleagues, we have concerns about the amount of our data that's out there and how it's used. But at the same time, we all want to be able to use our data for our own benefit, whether that be applying for a home or small business or being able to use our data on mobile apps in open banking. Given that we need to strike this balance between the benefits of data minimization and then the potential cost of data over-minimization, can you tell us what your thoughts are on how we should calibrate data minimization standards to successfully strike that right balance?
Congressman, it's a critical balance. And so I would say several things. First, the core of any data minimization framework should be that the end user has full control over their data. And that they're given explicit disclosures, they understand how that data is being interacted with, they have the right to revoke that data, revoke that consent, and they understand what they're getting in exchange for permissioning access to their data, whether it's a budgeting tool or something else. And so fundamentally, that consumer control should be the pillar on which data minimization is built.
Thank you. I yield back.
Gentleman yields back. Chair recognizes the gentleman from California, Mr. Vargas, who is our ranking member on our task force on monetary policy.
Thank you very much, Mr. Chairman. And I also want to thank you for a great hearing today and remembering that it's Saint Patrick's Day with that very handsome green tie. And I have to say that I personally don't trust AI because I asked AI if Saint Patrick drove the snakes out of Ireland and it said no. Clearly, Saint Patrick drove the snakes out of Ireland.
I'm glad to see the gentleman is aware of the possibility of fake news. Thank you. I yield back.
Now, Mr. Cleaver, you, you said that your clients in the context of AI don't trust that their data will be handled appropriately because they don't know exactly where it's going to end up. And I agree with you, good privacy laws only work if the right people with the right training and clearances are the ones handling the sensitive data. But we saw with DOJ that people with no relevant experience were handling access to Treasury payment systems and sensitive CFPB consumer data. And now there are reports that this administration may require banks to collect immigration status from their customers. Is there any legitimate financial or consumer protection reason to require banks to collect immigration status?
No, is the answer. Thank you for the question. It would actually be devastating for financial inclusion where we've made a lot of progress to move people from being unbanked or using a shadowy banking system on the side that's quite expensive for consumers. And it would be expensive for the U.S. Treasury because of what it does is it takes money back into a shadowy marketplace and it's much harder to collect tax revenues at the state and federal level if people are using check cashing places and other unregulated parts of the financial economy. The Yale Budget Lab estimated that the disruption just from the ITIN piece, oh no, I think it's the disruption from this proposal is $300 billion over in revenue over the next decade. So the question is whether we want a financial system that's built on trust or one that functions as an extension of immigration enforcement. And I, you know, I think the banks and credit unions have done a terrific job in many cases, not in all, of extending language, in-language resources and building resources to meet immigrant communities where they are. But what you don't want is the creation of a shadow economy. It also, you know, if you're thinking about money flows and a kind of black market in financial services, you worry about crime and drugs and everything else being present in those markets, which exposes everyday consumers who are just looking to do financial transactions to a whole underworld of nonsense.
I agree with you. But the other thing I would add to that is, you know, this administration might like this information, but the next administration might want other information. I mean, you always have to remember that administrations change and then you could get information, for example, who bought weapons, you buy guns legally, okay, we want to know who that information is. So I always tell my friends on the other side, be careful when you allow something to happen here because administrations change and the rules then change when the next administration comes in. So you don't want to necessarily give them all this information. And I have to say too, the sad thing is we used to trust that the federal government when they got, when they got this information, with, with exception, I mean there were the black helicopter people that believe that people are out there, now they unfortunately kind of does exist. But we thought when the information went to the federal government that we kept it in a very secure way. Now we're finding that it's being, you know, used all over the place in ways that it was very inappropriate. The courts are saying this. So it's very sad. Now I do, because I don't have a whole lot of time, you guys were starting to have a good discussion about the preemption. And you, you came back and said a few things. Could you say a little bit more about that and maybe give a little bit of a chance to the other side to say something about preemption? So don't take all the time. You got a minute. Go ahead.
I'll try to be brief. Take 30 seconds. The question is whether the juice is worth the squeeze and whether the issue is formed enough and whether the proposal on the table is good enough to substitute for any other forms of accountability. If you take away a private right of action, you're depending on federal enforcement alone, which means you have to trust that the current federal agencies that we have are going to put the law to the test. I don't have that faith in the current CFPB or the other federal regulators which feel ideologically co-opted against regulation as a blanket matter. And the particulars of the bill...
That's 30 seconds. I want to give the other side an opportunity. Anybody want to answer on the other side?
On the federal preemption side, we have strong federal preemption in the aviation context where we could fly over five states in a matter of an hour. When we're dealing with the digital context, we could have data go across five states in a matter of seconds. So it's entirely appropriate for us to have a single national standard to ensure that we have rules of the road that are easy to comply with and we also have rules that businesses have certainty about.
Okay. My time is up and I yield back. Thank you, Mr. Chairman.
Gentleman yields back. Chair recognizes the gentleman from Georgia, Mr. Loudermilk, you're recognized for five minutes.
Thank you, Mr. Chairman. And in response to my friend from California, I'm not sure about Saint Patrick driving out snakes from Ireland, but I do know that 250 years ago today, General George Washington drove the redcoats out of Boston and in his own words with an act of divine providence. But I would also say if Saint Patrick did drive the snakes out, I'm afraid a few of them ended up in Washington, D.C. So. Again, thank you, Mr. Chairman. This is a topic that's been very important to me, spending a lot of my career in data privacy and security. Mr. Taylor, many state data privacy laws contain rights for a consumer to be able to request access to and deletion of their data held by a firm. Could you discuss how these work in practice?
Yeah. Well, it's, it can be terribly complex, right? When someone says, hey, tell me all the data you have about me, you have to go through your various information systems and try and identify all the different pieces of data that you have about that individual and then put it in a package that is readily understandable to the average consumer and then give it to them.
Okay. Do you believe adding rights like these to GLBA would afford consumers greater control over their data?
Yeah, 100 percent, right? And one of the themes in this hearing has been the debate over preemption and Ms. MacCleery mentioned is the juice worth the squeeze. And I think Representative Huizenga's bill by adding several strong rights to it, I think that tips the balance in terms of, yeah, the juice is worth the squeeze here and I think a federal preemption is absolutely important.
Do you feel that that would, it would help in striking the balance if we were to legislatively identify what is considered a consumer's privacy data, data that they would inherently own?
I think that's a different matter and outside of the GLBA, I think that's, it's, that's, it feels more like an E and C discussion to me personally.
Okay. That was a good dodge, by the way. Do you believe that adding rights like these to GLBA could address security vulnerabilities that are presented by storing vast amounts of consumer financial data?
Yes, 100 percent. I mean, in particular the deletion right that's included in the discussion draft. I mean, that, that gets terribly to the heart of, of the point that you're making, which is if you're a former customer and when the relationship ends after some time passes and subject to certain exceptions, you can request that a financial institution delete the data. They can't lose what they don't have.
Right. When I worked in military intelligence and data security, we always lived by the mantra is you don't have to secure what you don't have. And so unless you absolutely need it, get rid of it. I think the federal government needs to learn that as well. Ms. Kim, in your testimony you write that deletion and similar rights must be considered with existing obligations as well as with the need to preserve evidence of suspicious or criminal activity. Do you believe there's a way to strike a proper balance between giving consumers greater control over their data and maintaining tools for law enforcement to identify suspicious or criminal activity?
Yes, thank you for the question. Yes, I, we do believe that there is a way to incorporate further consumer rights into the GLBA, but that it just must be done carefully without interfering with existing data pools that exist for purposes of fraud prevention, for reasons under the BSA, AML, CFT reasons, and for legal holds and responding to subpoenas.
All right. Thank you. Mr. Crenshaw, in your testimony you write that mandating the deletion of data for certain inactive accounts is impractical for regulated financial institutions. Can you give a bit more detail about why you think that would be impractical?
Well, I think our position really is mandating deletion and starting from a position of deletion is not a position that enables companies to fulfill many of their obligations, whether it's having the data that's necessary for training systems for security purposes or also potentially having to defend legal claims down in the line in the future or also having to look at things like fraud and having solutions that can be developed. And that's why we think it's critically important that we start with a data minimization baseline, opt-out rights for sharing, and then also deletion on behalf of a consumer request along with access rights. We think that strikes the right balance.
Okay. Thank you, Mr. Chairman. I yield back.
May I, may I comment on the deletion rights piece?
Sure.
I would say the 45-day business window is longer than California's or the GDPR, the European deletion rate. It's limited to former customers only and it's broad enough in terms of the exemptions to substantially narrow the provision.
Gentleman's time has expired and we welcome you to expand on that in your written comments.
I will do. Thank you.
The ranking member.
I have a unanimous consent request. Earlier you said we should use a scalpel and not a sledgehammer to our data privacy laws. I agree and hope we can work together, but I have two statements from the National Consumer Law Center and another from the Electronic Privacy Information Center explaining how the Republicans' draft bill would take a sledgehammer to many consumer protections. Thank you, I yield back.
They'll be included in the record without objection. Chair recognizes the gentleman from Illinois, Mr. Casten, you're recognized for five minutes.
Thank you, Mr. Chair. So before I get to questions, I just want to just want to raise for the committee, I have this nagging concern with the way a lot of this this conversation is going. And I think I can best explain it by reminding everybody back in 2021, the FTC had a settlement with Ascension Data. This was a mortgage analytics firm that they had a third-party vendor that had had gobbled up data that was that was private and there was a recognition that Ascension Data was themselves guilty. Entirely non-controversial, entirely good law. I think we all recognize that if if I want to commit a crime and I can essentially indemnify myself from criminal activity by hiring a third party to commit the crime for me, that's a bad idea. Right? It's why we have RICO statutes, it's why aiding and abetting a crime is is also a crime. And yet if I hire a robot to commit the crime, everybody wants indemnification. The whole AI industry is trying to be indemnified for crimes. And if and if we focus on this idea of of state preemption and all we do is just run to the bottom level, we've essentially said go commit crime with robots. And if if I hope we don't have that in the final text of this bill, but I don't want us to lose sight. Moving to my questions, I I'd like to joke sometimes that I've never met a non-schizophrenic libertarian. And the way you can tell that you meet a non-schizophrenic that you have met a schizophrenic libertarian is you ask them whether they want to share their data with powerful entities in the United States government, they say no, and then you ask them if location services are on on their phone and then you sail your way into the schizophrenia. We are at a point right now where that schizophrenia is starting to cross the line. Last year, CISA's acting director uploaded sensitive information into ChatGPT. That information in ChatGPT was then in their public servers. We have received information in our office that information that ChatGPT is using in OSHA files, in in air permitting rules, is allowing it to hoover up company confidential information. So you can now use these tools to get information that people thought was safely protected inside data sets. And and I guess, Mr. Boms, the is it is it technically possible to use an AI tool to ring-fence that data so that a company who wants to use the power of AI can confidently know that all of their internal data stays stays within within their controlled environment or does it always have to leach out into the broader public?
Thank you for the question. Thank you for the question, Congressman. This is part of the importance of transitioning to APIs where that the flow of that data can be better managed across the ecosystem. The industry is doing that. One of the things that we spend time thinking about at FDATA is read access for agentic AI versus write access for agentic AI. So in other words, an AI agent can look at your data and make a recommendation to you about a financial choice. That's read-only. It's not actually doing anything for you, it's giving you advice. Another option in a future state would be the AI agent saying, do you want me to go ahead and make that change for you, say in your portfolio management?
And and I'm sorry to cut you off just because I'm sensitive of time, but are you are you satisfied then that you can use AI and make sure that that data is ring-fenced so your confidential information is not leaching out?
In the context of APIs, yes.
Okay. Because my understanding is that Anthropic is one of the few ones that does that and I am really concerned with Department of Defense saying we don't want to use Anthropic because now this is getting out since we're seeing it leach out in other areas. We've also of course had these high-profile issues that I think many of my colleagues have talked about with DOGE hacks into the system, the hacks of the Treasury payment system. Ms. MacCleery, I think you had mentioned in your opening remarks this gentleman at DOGE who said that he had had God-level access to Social Security information data. It should be noted that he also said that if he's ever convicted, he expects to be pardoned. I assume it's a he, might be a she. This was a whistleblower report. Which means that that DOGE employee is looking for indemnification and I'm sure he would love to have state-level preemption if he can move to a state where he gets the right coverage. Let's assume the worst case. These DOGE employees have accessed that Social Security information, the banking information, they've accessed the Treasury payment system. Can we put that genie back in the bottle or is that information all out just gone now?
I think it would be very difficult to ever know what's actually happened to the data. And there there is reports that there were back-end plug-ins to the actual data servers and you're supposed to have, as you probably know, you know, use logs ...
So they could still be accessing the data.
Well, no, I mean, I think at the time, right? And so you're supposed to have even when the Inspector General's office, for example, audits an activity related to a data set, it never has modification access to the data because then it's clouded the audit trail. So as a basic matter of data security hygiene, you're never supposed to be in a position where you can actually modify the underlying data within a government database, especially a highly sensitive ...
We're out of time and look, let's fix this GLBA, but we have a whole bunch of issues that this committee should be doing oversight on, the Treasury payment system hack, what's happening in DOGE, all of that risk.
Gentleman's time has expired. Yield back. Chair recognizes the gentleman from Ohio, the chair of our National Security Subcommittee, Mr. Davidson, you're recognized for five minutes.
Thank you, Chairman, for holding this timely hearing or frankly, with respect to privacy, I think we're we're hard to say we're timely. We we really haven't kept up with the digital era very well at all. Gramm-Leach-Bliley kind of predates a lot of use cases. And I'd associate myself with at least a sentence or two that Mr. Casten highlighted with the concern that artificial intelligence is somehow blanket immunity to basically harvest data in any way you can get access to it because once it's in the model, how could you have any attribution? Frankly, that was one of my big concerns last May that that the Senate eventually corrected when they had to vote on the matter, 99 to one, to say, no, let's let's not do a one or two sentence blanket immunity. I do think, you know, AI preemption makes sense and one AI framework for the country makes sense, but privacy is the base layer for ethical AI and we really haven't got the foundation right with privacy. With respect to financial services, Gramm-Leach-Bliley is, you know, one of those examples where it doesn't really apply to everybody in the country. There's no single unifying law for most things in the country, it's all segmented. And part of that's due to the structure of Congress where, you know, you've committees of jurisdiction and part of that's people lobby a lot for something that certainly advances their interest versus everybody's. I want a base privacy law that recognizes that it is your data and so you of course should have a right to that data. Not what data do you have of mine? And I think the other thing you should know is how's it been acquired and then how's it shared. So when you look at, you know, Mr. Crenshaw, I think one of the basic frameworks is is opt-out adequate or should the framework be opt-in?
Once again, as we we look at the the base approach to privacy, fundamentally speaking, we need to have a base data minimization requirement across the board. So that means that that companies can use data in a way that's reasonable and relevant to the purposes that they're disclosing to their consumers, that they have to live up to that standard and if they don't live up to that standard, they not only have issues with, you know, their current regulator, particularly as we see in the states, but the FTC can then come in and say that a company's not fulfilling its its obligations under an unfairness and deceptiveness claim. But then we also believe that if you have privacy-conscious consumers who who also want to have increased data protections, they have the right to opt out, they have the right to delete, they have the right to access that data and that provides baseline protections. I think the concern with starting with an opt-in approach is that you begin to dry up data pools and I think as you mentioned earlier, we need to have good data to have applicable AI and responsible AI. And and if we don't get a full and complete data set, then we can't get AI working in a way that works for everyone.
Can I add a little here? I would ... oh no. Just a second because I want to get to a follow-up here. When you look at, you know, you talk about protections, you know, you're already not supposed to sell data outside of what you've agreed to, but you do do it in an aggregated way. And when you look at, you know, within two or three moves, you can sort of disaggregate that and with the age of AI, that's going to be increasingly easy to do. And you know, I think the the real premise for for a lot of the industry was lost first and foremost in the financial sector with the Bank Secrecy Act because it changed the idea that once you've shared it with somebody, albeit somebody you essentially have to share it with, a financial institution, you no longer have an expectation of privacy. And we should recognize that as a corruption of natural rights, natural law. I mean, the right to transact predates any government. It would be a little nosy for the government to interject and say, hey, why are you trading fish for fruit with this guy? You know, you go mind your own business, we're doing our own little transaction. But government's done that and they've put themselves between the consumer and whoever they're transacting with on nearly every transaction. In fact, if you don't spy on your customers, you don't get to operate a financial services business for the most part. So in the age of AI, how do you safeguard against disaggregation with all of the things? Granted, you got the disintermediation, you get three or four data points, you can you can unbundle anything. Anybody have an answer for that?
Well, I don't want to I don't want to push back because I mean, I think there is some some some truth there. What I was going to say is everything is data set specific, right? If I have a aggregate credit score for 100,000 accounts, you're not three steps away from identifying the credit score of the individual. So you know, I I do think the concerns you raise are legitimate. I think AI and computing, you know, does sort of raise the stakes and increase the likelihood, especially if if if you have enough data to compare against.
Gentleman's time has expired. So re- rethink the exception. Thank you and I yield back. Gentleman yields back. Chair recognizes the gentlewoman from Massachusetts, Ms. Pressley, you're recognized for five minutes.
Thank you, Mr. Chair. I want to put this hearing in perspective for the American public watching this hearing just to demonstrate why it is time to move to open banking. So imagine Mark, a 30-year-old renter in my district, the Massachusetts Seventh. Now Mark splits bills with his roommate and uses a property management website like Greystar or Peabody Properties to pay the rent directly with a credit card. And uses an app to send money to his roommate for the water and electricity bills that they share. Now Mark likely has no clue exactly what happens when he clicks the send button. He, like millions of Americans, is likely completely unaware financial information is being shared with marketing platforms and credit reporting agencies and even data brokers without his explicit permission. But what he does know is that when he checks his mailbox, there's random junk mail with his name and address for new credit cards and when he checks his emails, there is spam about opening a bank account. That doesn't happen by chance. It is by design. Our financial system enables big banks and fintech companies to abuse our financial data for their own profit. Meanwhile, Mark and the rest of us are limited in told what we can and cannot do with our own data. Now here's the thing. We can actually do something about this. We have the opportunity to change that with the open banking rule to really empower consumers to decide how their financial data is used and shared. The Consumer Financial Protection Bureau open banking rule would allow consumers to not only share financial information with platforms to pay your rent or bills like many already do, it would also allow consumers to take their financial history with them to other banks and have the choice to make decisions that work best for them. It would empower consumers. Ms. MacCleery, what should the everyday person understand about the move toward open banking and how it would benefit them when they want to purchase a home, retire, or start a business, for example?
Thank you so much for the question. It's a really important one. Data portability and data rights in terms of how you negotiate your rights with systems are key to building consumer understanding of this. And you might say that the current regime under GLBA, which is the opt-out regime, does nothing to advance consumer understanding of this because it's essentially a passive mechanism. If you get one of these form letters in the mail that's just a sort of notice on paper and you're expected to be the one to act, the default is that you're in the data unless you've chosen otherwise. That is not deepening people's sense that they have a right to their data and that they are a good custodian of their data. So I would say one of the reasons why opt-ins are the preferred mechanism by different consumer groups and across the data privacy world and in the California law is because it helps build that sense of ownership among the public. Someone can say, wait a second, I didn't sign up for that. When you've just got a paper letter that is part of your junk mail stack in the mail, you're not going to have that same sense of ownership or sense that you might be able to stick up for yourself in terms of the company's rights. So that's it's moving the default that would matter the most.
Yeah, I mean, look, it's the people's data, it's the people's money, and we can't innovate financial privacy laws without our communities being at the center of those decisions. Given all the benefits of open banking, could you just speak to why exactly are people opposed? Why would they work so actively to obstruct this progress and this empowering of the consumer?
Why do large corporations that benefit from people being locked into their services oppose the ability of people to walk away in response to market forces? I think that's the question sort of answers itself, unfortunately.
Fair enough. Okay. Well, finally, having read your written testimony you submitted, you spoke about some of the ways in which we could improve accessibility, acknowledging limitations for those for whom English is not their first language, impacts of AI. So what should Congress be keeping in mind to make it more accessible for people to know their financial rights?
If a financial transaction was negotiated in a particular language, all of the related documents, legal documents, disclosures, and everything else should be in that language. It shouldn't be that you're marketing to someone in their language, but then you turn around and hand them a stack of papers they can't read. So that's a pretty simple rule of thumb, and I think that belongs in any kind of disclosure regime.
All right. Thank you. I yield back.
I'll now recognize myself for five minutes for questions. I'd like to ask Mr. Taylor the first question if I could about the supremacy clause of the United States Constitution. As a nation, we value our federalism and we try to let states regulate when appropriate, yet the founders recognized the supremacy of the Congress in matters of interstate commerce. Sometimes we need a predictable standard to avoid impairing commerce among the states. Can you please discuss the need for a federal standard for financial data privacy that potentially could preempt state regulations?
Absolutely. Others on the panel are focused, I think, on preemption a little bit from the burden and the patchwork standpoint. I approach it from a consumer standpoint, which it seems inequitable to me that the privacy rights you have for your sensitive financial information are going to be dictated by the state in which you live. That's not fair. And this is, I think, inarguably very sensitive information, and I think we need a single standard and not a weak standard, but a strong standard that applies across the board.
Mr. Boms, if I could get to another area. In the context of the Gramm-Leach-Bliley Act, the GLBA, do you believe that consumers have sufficient understanding of the risks of sharing their non-public information to make an informed decision?
Congressman, thanks for the question. I think our view is that generally speaking, consumers and small businesses are smart enough to decide when presented with clear and conspicuous disclosures whether they are comfortable sharing their data for an open banking use case and to weigh that against the benefit that they would receive from the product that they are going to be enrolling in. As I think you know, the GLBA requires that disclosure and transparency at the point of interaction when you're first saying I want this service and I want to share my data with it. And then pursuant to the GLBA and other both statutory and contractual and regulatory requirements, the open banking enabled products, tools, and services that our members offer operate on the principle of necessity, which is that to the extent that NPI is being collected, it's only the NPI that's necessary to deliver the use case that the consumer has said I want.
And Ms. Kim, one of the questions that came up earlier that I asked Mr. Taylor deals with again this issue of the interstate commerce issue. I'd like to know your opinion on that as well, if you could, please.
Yes. So because of the patchwork of federal privacy laws and state comprehensive laws, I would agree with a lot of my co-panelists that it has hurt interstate commerce because it serves as a barrier to entry for many businesses, financial institutions who maybe cannot afford to do business in those areas.
And Mr. Taylor again, the idea that the opt-out rates are less than seven percent. How do we solve an issue like that in a proactive manner to actually look out for consumers, because many of them just aren't aware of the risks that are associated with this?
This is truly a very challenging issue. And as I noted in my oral testimony, I believe that billions of privacy notices have been physically mailed to customers under the GLBA over the past 25 years. So there's certainly notice is being accomplished, and the banking agencies developed a model privacy form that was intended to simplify it and make a privacy notice like a nutritional label, for example, and make it more easily understood. So it is candidly, as a practitioner working with financial institutions, it's baffled me that opt-out rates are so low, but I'm not ready to take that control and make the decision for consumers and flip over to an opt-in regime.
All right. At this time, I'll yield back my time and the gentleman from California, Mr. Liccardo, is now recognized for five minutes.
Thank you, Mr. Chair. Appreciate all the testimony of the witnesses. Certainly I've got many residents at home, as we all do, who are deeply concerned about how their data is being used and what they don't know about how it's being used. And I was looking at a 2021 survey from NORC that found that 93 percent of fintech app users are not aware that data aggregators are scraping their data and how they're using their data. I have a lot of fintech companies in my neck of the woods, I represent a big part of Silicon Valley, and so I understand the very important work that they do and the service they provide for millions and millions of Americans. But it seems to me that there are really two basic ways here that fintech companies could get access to the data they needed to provide the service. One is through secure API that the bank would provide or other financial institution, or through screen scraping where essentially they take on the identity of the or they gather the passwords and so forth, they get access to the account and then are able to scrape all the data. Mr. Boms, as you could tell, this is coming your way. If we had an open banking rule with clearly established protocols, would we need screen scraping anymore?
Thank you for the question, Congressman. The answer is we would not need it as much as we do today, but we still might need it. And I'd say that because we are one of the last G7 countries to create an open banking framework. Several other jurisdictions have moved before us, we can learn lessons from what they've seen. In those jurisdictions, APIs are much more ubiquitous than they are here. We have a much more diverse financial ecosystem with smaller entities. But screen scraping still exists as a fallback option. And the reason for that is, as we've heard before, there are some competitive interests at play in this market and there are some reasons why a large data provider might not want to share their data with a third party. And so if screen scraping remains as a fallback if an API isn't available, if an API isn't reliable, if the API doesn't have the data that's required for the use case.
In a world where you had clear protocols about what data they had to provide, theoretically we shouldn't need it, should we? The bank's under clear obligation to provide the data.
And then you still have the long tail problem, Congressman, which is there are thousands of smaller financial institutions that don't have the resources to deploy those APIs today. And for those consumers, the question of whether or not you can use a fintech tool if screen scraping was prohibited would be a binary yes-no. They wouldn't have access to those tools.
But these secure APIs are nearly ubiquitous, certainly a tool. I am absolutely incompetent at software development, but I can even vibe code some surprisingly good results. Why can't we simply require all the financial institutions to develop their own APIs? We've heard from the banking industry they're not opposed to banning screen scraping. Why wouldn't we simply say everyone develop a secure API and you're going to be held to account for it?
Congressman, it's not a question for us and our members because we're reliant on the data providers and the method that they choose to make the data available. All I can say is we strongly prefer APIs where they're reliable and accessible.
So Ms. Kim, as you can imagine, this is coming back to you. If in fact, as you said, you support screen scraping or the elimination of screen scraping, a ban on it, what about a requirement that all of your members and all financial institutions would be required to be able to create a secure API that fits a protocol that CFPB presumably would create?
Thank you. Yes. I would say that for the vast majority of our members, we already do use APIs. And so like I mentioned before, we are paying attention to certain data exchanges that will continue to transition that system away from dangerous practices like screen scraping and toward API development.
Okay. Well, I guess you can tell where I'm pushing here. I just think that this is something that's long overdue, that is prohibition on screen scraping. I can see how it can be abused. I understand why fintech companies may need to use it given the current state of play, but certainly that's something we should be able to fix at the federal level and I urge us to do so. And as we talk about this issue of preemption, I appreciate that preemption gives us uniformity of application of rules, it reduces compliance costs for all our financial institutions. But unfortunately, we're enduring an administration where we have completely defunded the financial police, CFPB is simply a shadow of itself, and there is no private right of action. Consumers have absolutely no ability to take a violator to court for abusing their privacy. I don't understand in that context how we can at the same time advocate for preemption when we leave consumers in this country with no means of recourse when they are harmed because federal law and this government does not allow for it. Thank you. I yield.
Gentleman having yielding back. [END: 012:40] The gentleman from Montana, Mr. Downing, you are recognized for five minutes.
Thank you, Mr. Chairman. I appreciate the committee's focus to ensuring that the United States remains the leader in innovation around the world. And that doesn't just mean creating regulatory clarity for digital assets and allowing artificial intelligence to flourish, but also ensuring that our data privacy laws reflect the 21st century. I'm going to start with Mr. Boms. With innovation in mind, why is it important that any data privacy law remain technology neutral?
Thank you, Congressman. The drafters of the Gramm-Leach-Bliley Act in 1999 could not possibly have imagined the way that the financial services regime would look 27 years hence. And so similarly, those of us in this room, though I think we're all very focused on this, cannot possibly imagine what the regime will look like 27 years from now. And so it's very important, to paraphrase Wayne Gretzky, that we go where the puck is going, not where the puck is. We don't know where the puck is going. And so we have to be technology agnostic. The GLBA generally takes an activity-based approach to deciding whether or not you are subject to its provisions. That feels like the right way to continue the statute moving forward.
So do you believe that the GLBA was written sufficiently technology neutral?
Congressman, I do. And I think the proof is that several of our members who did not exist back in 1999 are subject to the GLBA today.
Right. Appreciate that. Move on to Mr. Taylor. The implementing regulations for banks and credit unions under the GLBA Title V Regulation P are written by the CFPB, while for other types of financial institutions, the implementing regulations are written by the CFTC, the FTC, the SEC, and state insurance regulators working through the NAIC. Could you discuss the advantages and the disadvantages of this approach?
Well, the CFPB became the sort of lead, I would characterize lead rule writer with Dodd-Frank. Before that, you had the functional regulators like the banking agencies, the Fed, the OCC, at the time the OTS, NCUA were writing rules. I've always been a fan of the historical pre-Dodd-Frank Act regime where the regulators who are the ones who are actually going to be examining and enforcing the law are also the ones writing it, and they know the industry, and I think that's the appropriate approach.
Right. I appreciate that. So just to kind of double down on that, do you believe that Congress should take a look at removing the CFPB from its role in GLBA rulemaking enforcement?
I mean, it having listened to both sides here throughout this hearing, there seems to be some concern with the CFPB, and I know there's historic concern. It's something that this committee should at least consider.
Appreciate that. You know, there's been a lot of discussion today about the need to preempt state data privacy laws to promote uniformity and to promote innovation. As a former state regulator, and I'm typically hesitant about broad federal preemption, but I can see the merits of it for data privacy laws. And I know we've already discussed this a little bit, but I'm going to move on to Mr. Crenshaw. What role should the states have over regulating enforcing data privacy laws?
I also would recognize your home state has one of the comprehensive privacy laws that follows the consensus approach, which we think is a good model for comprehensive privacy legislation. You know, going back all the way to Federalist 42, where there is conversation about the reason we have our Constitution and not the Articles of the Confederation is that we need economic cohesion. And that's why it's so critically important as we're dealing with a technology that, as I mentioned earlier, you could be clicking and having data go in five states within a millisecond, that we need to have one national standard around that. And so I think as we look kind of at the broader comprehensive context when it comes to privacy, we see a role for state AGs. We also see a role as well too for in the GLBA context for state insurance regulators as well. But at the same time, we think in the GLB context overall, it should be with the appropriate federal regulators who have that responsibility.
Right. Thank you. I'm not sure if I have time, but I'm just going to go down the line. If Congress can make only one change to federal privacy laws, what should it be? And we'll start here with Mr. Taylor and just move down.
With respect to the GLBA, I would say adding additional consumer rights.
Strong federal preemption.
I'm missed on the concept of control over data.
Strong field preemption.
Opt-in.
Outstanding. Well, thank you all for your time. And on that, Mr. Chair, I yield.
Thank you. The gentlewoman from Michigan, Ms. Tlaib, is now recognized for five minutes.
So we all know and we've been talking about this hearing, which I'm so glad we are, especially with the growing use of our private data for surveillance pricing and a number of other issues. We know that companies using personal data and, you know, the way they're using their algorithms to make lending and other financial decisions is hurting Americans. I know CFPB, which is a Consumer Financial Protection Bureau, was the primary agency investigating how these algorithms might be baked in racial, gender, or other biases in financial decision-making. However, we've seen CFPB be gutted, slashing funding, cutting staff, dramatically reducing any sort of supervisor capacity. In addition, we know that CFPB has closed all under the Trump administration fair lending investigations. I don't think the American people know this, based on disparate impact liability under the Equal Credit Opportunity Act. And for folks listening, I mean, this is so incredibly important. It was one of the ways that we were able to push against housing discrimination. So Ms. MacCleery, is it can you briefly describe the disparate impact liability? Like our moms are watching. Like what are explain it to folks to understand just how harmful this is going to be.
It means that if some group is being treated unfairly in terms of access to loans or financial products, no one will know.
Somebody with a disability.
Somebody with a disability, a mom, a single mom with children.
Yeah, or a person of color, right?
Yeah, any group that you would think that is already struggling against bias and access to, you know, housing, lending, bank accounts will not show up anymore in terms of harms.
And it's like a bright green light. It's just a bright green light to allow discrimination. It's not just, of course, CFPB. We already know that it's also ending disparate impact enforcement within the Department of Housing and Urban Development as well Department of Justice, Department of Transportation, and the Federal Trade Commission. All of those agencies will not be investigating discrimination based on disparate impact. With CFPB sidelined, Ms. MacCleery, I mean, who's left to ensure that our data privacy isn't being used to shield or hide systemic discrimination in the financial market?
States. That's who's left. And I think that's why we see this move to federalize all of the liability and accountability mechanisms from this committee. It is about states being innovative, passing laws that hold folks accountable. It is about individuals using state law in the class action to bring forward information about harms and hold people accountable. And in some cases, it's about both Republican and Democratic attorneys general who have been very good at trying to protect people in their states.
Which is one of the things I agree. So let's go to price gouging, or they call surveillance pricing, but it's a way to price gouge, which I find incredibly concerning. You know, I introduced the Stop Price Gouging in Grocery Stores Act, which bans surveillance pricing at grocery stores. And it's not just companies using your personal information, like they're using like your zip code, your browsing history when you go grocery shopping. Many companies, including grocery stores, they're becoming data brokers. People don't realize this. They use like sexy terms like precision, quote, precision marketing and advertising. But I want my colleagues and the public to know this. In 2024, Kroger, which is a huge presence in Michigan, made an estimated $527 million in profits by selling your shopping data. That was something like one-third of its total net income in 2024. And data broker market is expected to grow $545 billion by 2028. So Ms. MacCleery, you noted that more data going to third parties expands the raw material available for surveillance. Can you discuss the biggest concerns related to surveillance pricing or government surveillance given the rapidly expanding data broker market?
Yeah, it's the right question to be asking. All of these new smart appliances, all the apps that want us to join, they're mostly data scraping. And the idea is that they turn everything we do inside of our homes or online into a separate profit stream that they can then sell into the data broker marketplace. And so there's just an extraordinary amount of information. And what we see with surveillance pricing is that you would think that people who have less ability to pay might get a better deal, but it turns out the opposite is true.
Absolutely opposite. That's the thing. We've been seeing that it's the opposite. The fact that they're going to price eggs, milk, and basic food products based on where someone lives, whether what they've been searching online is absolutely appalling. Shame on Kroger, shame on anybody using surveillance pricing. And I wish my colleagues would understand the importance of this. Prices are going up on our residents, and guess what? It's not just the cost of making these products as they claim. It's corporate greed, and we need to do something about it. Thank you.
Having yielded back, the gentleman from Wisconsin, Mr. Steil, is recognized and our chairman of the subcommittee on digital assets is recognized for five minutes.
Thank you very much, Mr. Chairman. Appreciate all of our witnesses being here today, a productive conversation today. I'm going to start with you if I can, Mr. Taylor. Gramm-Leach-Bliley Act and its data privacy framework, as we know, written at the end of the 90s, 1999, at a time when the financial services landscape looked very different. People are still dialing up on AOL, you hear the noise when you would connect. Right? I mean, this is we've made great strides, and you almost have to take your mind back to what Congress would have looked like in the late 90s. Probably people probably explaining to members what email was, what a digital footprint would be. The idea of data privacy was kind of in its infancy as it relates to the digital age, Web3 era that we're entering. Knowing that and thinking about how the financial rails have really transformed pretty dramatically during that time, the ability to store metadata, etc. I want to go back and think about GLBA as written and in the manner that it was written. Do you think it was sufficiently drafted to adapt and cover all of the financial services companies and products we have in today's world? Or do you need do we need to be really updating the definition of quote, financial institution, end quote, to cover the wide variety of entities providing financial services today?
Great questions. I think it's two, not one. On on the first, I do believe the GLBA is sufficiently technology neutral. I began practicing law in 2003 working on GLBA. I've seen the financial services market change, but, you know, the law and the regs that I work with have been flexible across every type of product that's evolved and the technology that's evolved. Your second question about gets to the heart of the I think the definition of financial institution and is it sufficiently clear? You know, as a practitioner in the weeds, I find it clear, but it is very dense and is it...
Do you think the courts have found it clear, though? We're looking at, you know, some of the litigation in different states. I'm thinking about data aggregators. Do you think the courts are viewing it as clear? Or why is there so much litigation in the space if it is clear?
Well, I don't I don't think it's GLBA litigation because there isn't isn't that private right of action that people were mentioning. But I I view it and I put this in my written testimony, I think it's unequivocal that financial data aggregators are financial institutions for purposes of the GLBA. But it's a somewhat complex analysis, and there seems to be a pretty easy fix, which is what Representative Huizenga's draft does, which is just add an additional clarification of, you know, a simple parenthetical of including financial data aggregators.
Thank you. Let me jump to you, Mr. Crenshaw, if I can, stay on the topic of data privacy. As you discussed in your testimony, there's a strong case for federal preemption and state-to-state coordination. This is the constant challenge we have here between federalism and the commerce clause, where one economy in the United States, we love states to take the lead. I'd love your thoughts on this as we analyze this balance here in this committee, in particular as we look at some states that are probably doing things that actually, if they implemented, would do more harm to consumers than good. Can you talk about the existing landscape of state data privacy laws and maybe give us some indication of what, in your opinion, what states are on the right track and what states are on the wrong track as it relates to giving consumers the best products available and protecting them?
There are 17 states that have adopted what we call the consensus privacy approach. Virginia was the first state to adopt this model, and it's spread in other states like Kentucky and Montana and even all the way out on the West Coast in Oregon. And it provides very workable privacy rights where there is a data minimization standard where companies have to use data in a way that's relevant and reasonable in relation to how they disclose it to consumers, but then gives them a whole bevy of other rights: right to delete, right to opt out of data sales, right to opt out of things like targeted advertising across non-affiliated websites. But at the same time, we are seeing an influx of new proposals in other states that could really upset this balance and create conflict and confusion. For example, Maryland has passed the Online Data Privacy Act, which would bar the collection of any sensitive data. And as I talked a little bit earlier is that, you know, we heard the conversation earlier about disparate impact. I don't know how as a company you run a disparate impact analysis and stay compliant if you don't have the full picture of data.
And people operating in other states are then in effect, right, because we're one economy, are then beholden to the least common denominator. So if one state gets it wrong, all states can be negatively impacted. Is that accurate?
I mean, we've heard that the states are the laboratories of democracy, and sometimes bad experiments leak. And I think we want to be in a position where we make sure that we have one cohesive set of rules across the country.
Thank you for your testimony. I appreciate all of you being here. Mr. Chairman, I yield back.
Thank you. Next we have the gentleman from Indiana, Mr. Stutzman, is now recognized for five minutes.
Thank you, Mr. Chairman. And thank you, panel, for being here. I'd like to begin with GLBA's legal framework and how it interacts with state laws. As we know, GLBA sets a federal floor. States can then enact additional data privacy laws should they choose to do so. The result is a patchwork framework in which businesses in different states can face different financial data privacy standards. For example, in Indiana, if a business is classified as a financial institution under GLBA, like a bank or credit union, it is typically exempt from the state's data privacy law. However, in California, those same GLBA-compliant businesses are held to the additional heightened standards of California's financial privacy laws. Ms. Kim, I'd like to ask you, could you describe the kinds of compliance burdens and barriers to competition this patchwork quilt across the country creates for financial institutions?
Yes, thank you for the question. The compliance burden that results from this patchwork is you get multiple compliance teams, one handling federal regulations, one handling the state level. Also in terms of audit teams, you may have different expectations based on state-by-state. These are all valuable resources that could be spent elsewhere. So as a result, a lot of businesses or new market entrants would avoid high-cost states and take their business elsewhere, limiting that service.
So follow up on that, from a consumer's perspective, what might those burdens and barriers look like? And would California's more stringent requirements effectively limit certain firms from operating or offering particular products in the state? You mentioned that a little bit. Could you expand on that a little bit?
Yes, so I would agree with that final point on limiting service to California, for example, for having overlapping state rules as well. And I think on the consumer side, what you're met with are kind of this picture of the multiple stacks of notices because you're dealing with competing regulations. You're faced with also learning about your different rights. There's opt-in versus opt-out. It's very confusing for the actual consumer, and it probably lowers overall privacy awareness.
All right. So Mr. Vice Chairman Huizenga's discussion draft noticed to this hearing would establish a national financial data privacy standard that preempts more burdensome state laws, such as those in California. So I'd like the entire panel with about 30 seconds for each of you, do you support creating a uniform national standard? And if so, why? Why don't we start down on the my right, your left, and just go right down the line.
No. The states that moved forward did so because the federal framework fell short. This bill maintains an opt-out approach, sets response timelines that are weaker than both Europe and California, includes a consent exception so broad the industry can basically just keep doing what it's always done so long as it documents it, and has no private right of action. This converts the floor to a ceiling at a moment when federal enforcement has been deliberately diminished. It's deregulation dressed as reform.
So you're a no. Mr. Crenshaw.
Absolutely in favor because a patchwork of state laws, including things like opt-in and strict data minimization, put us at risk of financial and technology leadership.
All right. Mr. Boms.
FDATA is supportive of a preemptive federal statute provided that consumer control rules the day under that federal framework.
All right. Ms. Kim.
Yes, interstate banks would need one clear rulebook.
All right. Thank you. Mr. Taylor.
Absolutely support preemption. I think it's the right result for the American consumer that we all have the same rights regardless of where we live.
Very good. I've got a minute, so I'm going to go to Mr. Crenshaw. GLBA does not include a private right of action that would allow consumers to sue firms for alleged violations. While some of my colleagues across the aisle would support such a right, federal courts have consistently reaffirmed that no such rights exist under current law. What negative consequences might result from creating a private right of action? Would some type of businesses feel those impacts more than others?
Small businesses are more inclined to settle because they're afraid of incurring legal costs. And that's why having out-of-control private rights of action are a problem. It's also an important note why we have strong preemption because there are attempts to get creative in inserting private rights of action in other laws that would regulate privacy in the states as well. And so if we have one clear set of privacy rules that occupies the field with preemption, we can also prevent those abuse of lawsuits that are going to get creatively snuck into other state laws from going forward.
Very good. Thank you, Mr. Chairman. I'll yield back.
Thank you. I would like to thank all the witnesses for testimony today. Without objection, all members will have five legislative days to submit additional written questions for the witnesses to the chair. The questions will be forward to the witnesses for their response. Witnesses, please respond no later than April 21, 2026. Again, thank you for your time, and this hearing is adjourned.
Same-day access
Read every hearing transcript the day it happens
Paid seats unlock fresh transcripts immediately, including synced video and clear summaries.



