United States: Summit Provides Insights On Hot Trends And Issues In Consumer Protection And Privacy
Last Updated: December 5 2018

Holland & Knight and the National Bar Association Consumer Law Section (NBA-CLS) on Nov. 16, 2018, hosted the Exploring the New Normal in Consumer Protection Enforcement Summit, a half-day seminar that focused on identifying priorities in consumer protection law, effective strategies in law enforcement investigations, risk areas for companies and the key issues presented in compliance management.

Guest speakers at the Summit included:

  • Serena Viswanathan, Deputy Director, Bureau of Consumer Protection, Federal Trade Commission (FTC)
  • Tom Pahl, Policy Associate Director for Research, Markets & Regulations, Bureau of Consumer Financial Protection (BCFP)
  • Mark Eichorn, Assistant Director, Division of Privacy and Identity Protection, Bureau of Consumer Protection, Federal Trade Commission (FTC)
  • Abigail Stempson, Director, NAGTRI Center for Consumer Protection, National Association of Attorneys General (NAAG)
  • Mark Neeb, CEO, ACA International

The Holland & Knight team included:

  • Tony DiResta, former Director, Southeast Regional Office, Federal Trade Commission (FTC), Partner and Co-Chair of the Consumer Protection Defense and Compliance Practice (Washington, D.C.)
  • Kwamina Williford, Partner and Co-Chair of the Consumer Protection Defense and Compliance Practice (Washington, D.C.)
  • Mark Melodia, Partner (New York)
  • Norma Krayem, Senior Policy Advisor and Chair, Global Cybersecurity & Privacy Policy and Regulatory Team (Washington, D.C.)

Guest Speaker Highlights

Serena Viswanathan, Deputy Director, Bureau of Consumer Protection, Federal Trade Commission (FTC)

Serena Viswanathan, who has served at the Federal Trade Commission for nearly 20 years, shared her insights into the FTC's consumer protection priorities and her advice about how businesses can best navigate FTC investigations. She shared a number of key themes and consumer protection, enforcement and other FTC priorities.

Consumer Protection Priorities

  • Viswanathan, in her personal capacity, stated that while the FTC has five new commissioners and a new director of the Bureau of Consumer Protection, she does not anticipate a substantial shift in enforcement priorities. In fact, she expects to see strong enforcement of the law going forward.
  • Many suspected that, upon the arrival of the new commissioners, there would be frequent disagreements about enforcement decisions falling largely along political lines. This has not been the case.
  • Indeed, most of the FTC's cases have been voted upon unanimously, and Viswanathan has seen no pulling of the punches when it comes to enforcement.
  • The FTC's consumer protection enforcement priorities continue to be the following:

    1. financial technology products
    2. deceptive health or safety claims
    3. influencer marketing
    4. gag clauses regarding negative consumer reviews
    5. data security and privacy
    6. fraud

New Enforcement Practices

  • Viswanathan noted that there are two enforcement practices that will likely change going forward:

    1. the FTC will aggressively enforce court orders
    2. the FTC will seek stronger remedies

      • This means that the FTC will consider seeking monetary relief where it has not considered seeking it in the past.
      • This also means that the FTC will more readily require consumer notification where it may prevent consumer harm.

Effective Advocacy Strategies

  • Although businesses are not likely to see lax enforcement anytime soon, Viswanathan did offer insight into effective advocacy strategies that businesses and their attorneys can use to navigate FTC investigations. Businesses should do the following:

    • Take responsibility for their failings. Corrective action and remediation is critical.
    • Focus on providing the FTC with a factual basis for not taking action. That factual basis will usually consist of effective policies and procedures, which are consistently followed, and will thus make future violations of the law unlikely.
    • Give the FTC enough time to understand what happened before providing the FTC with substantial amounts of information about compliance changes that the business plans to implement or is in the process of implementing.

Tom Pahl, Policy Associate Director for Research, Markets & Regulations, Bureau of Consumer Financial Protection (BCFP)

Tom Pahl, who served at the Federal Trade Commission for more than 20 years and at the Bureau of Consumer Financial Protection for nearly five years, shared his insights into the BCFP's priorities, how businesses can best navigate BCFP investigations, and how business can avoid those investigations in the first place.

Enforcement Priorities

  • Pahl, in his personal capacity, stated that the BCFP is in a state of transformation with the primary aim of ensuring that all of its actions are consistent with the Dodd-Frank Wall Street Reform and Consumer Protection Act, as written.
  • Although Pahl expects that Acting Director Mick Mulvaney's BCFP will target the same activity and will conduct the same number of investigations, the products of those investigations will be reviewed for strict compliance with the Dodd-Frank Wall Street Reform and Consumer Protection Act and its implementing regulations.
  • The BCFP is now interested in determining whether there are ways in which it can reduce any undue burden on business through regulatory and enforcement reform.

Regulatory Reforms

  • Pahl confirmed that the following regulatory reformations are at the top of the BCFP's priority list:
  1. reconsidering the rulemaking process
  2. reconsidering the payday lending rule
  3. reconsidering the Home Mortgage Disclosure Act rule
  4. evaluating rules to determine whether they should be revised
  5. revising rules to make them less burdensome
  6. engaging in congressionally mandated rulemaking pursuant to the Dodd-Frank Wall Street Reform and Consumer Protection Act and the Economic Growth, Regulatory Relief, and Consumer Protection Act
  7. engaging in debt collection rulemaking

New Practices

  • In addition to these regulatory reforms, the BCFP is instituting two related practices. They are now focused on the following:

    • Providing written – rather than oral – guidance regarding how businesses should go about complying with the law so as to ensure that all BCFP guidance is consistent and available to the public.
    • Taking enforcement action where there exists, and it can prove, substantial consumer harm.

Compliance Management Systems

  • Pahl went on to underscore the importance of compliance management systems. Maintaining an effective compliance management system, Pahl noted, not only makes a business less likely to come to the BCFP's attention, but also helps the business secure a favorable outcome if it does. If a business has a robust compliance management system it is less likely that the BCFP will 1) bring a case against the business, 2) require that the business remain under court order, or 3) seek a far-reaching remedy.
  • Pahl also shared his advice about how businesses should go about crafting compliance systems. He recommended that businesses should start early and involve internal compliance officials as well as outside counsel with experience with the regulatory agencies. Once a business has created a compliance system it must put it in writing, distribute it to all of the employees tasked with putting it into practice and train those employees how to do so. Finally, the business must ensure that those employees consistently follow the compliance program as written and raise any issues they encounter along the way to the business.

Effective Advocacy Strategies

  • If a business' compliance management system fails and the BCFP opens an investigation, there are, according to Pahl, advocacy strategies that businesses should employ in order to best navigate the investigation. Businesses should do the following:

    • Reduce their positions to writing, in white papers or other memoranda, as early and as often as possible. This will help businesses to create an investigatory record and allow the BCFP to circulate the white papers throughout the agency.
    • Take full advantage of in-person meetings, including the initial meet and confer, if only to ensure that the Civil Investigative Demand is not overbroad and will not cause an undue burden.
    • Do their best to resolve all of their issues at the staff level, raising only their most serious concerns with senior officials.

Mark Eichorn, Assistant Director, Division of Privacy and Identity Protection, Bureau of Consumer Protection, Federal Trade Commission (FTC)

Mark Eichorn, who has served at the Federal Trade Commission for 20 years, shared his insights, in his personal capacity, about the prospects for new data security and privacy legislation as well as FTC coordination with other engaged government officials at the state, federal and international levels.

Domestic Enforcement Cooperation

  • Eichorn began by stating that he is not optimistic that Congress will enact uniform federal legislation providing certainty to businesses as to their data security and privacy responsibilities. Indeed, just this month the FTC reiterated its longstanding call for federal data security and privacy legislation, but, thus far, that call has fallen on deaf ears.
  • While there may not be a single standard for some time, Eichorn noted that, in the meantime, the FTC will continue to closely coordinate with state regulators, including state attorneys general, to ensure that state and federal enforcement actions do not often overlap and that, when they do, those enforcement actions remain consistent. The FTC not only coordinates with the states, which often have concurrent jurisdiction over privacy issues, it also coordinates with other federal agencies, including the U.S. Securities and Exchange Commission (SEC) and the BCFP, each of which may have an interest in investigating or taking action in response to a particular breach or business practice impacting consumer privacy.

Foreign Enforcement Cooperation

Eichorn noted that, although the level of cooperation between the FTC and other domestic regulators may be higher than that between the FTC and foreign regulators, international cooperation on data security investigations is substantial and growing. The FTC cannot share information with foreign regulators if their laws forbid activity permitted in the United States, but international cooperation is commonplace and allows regulators to increase internal efficiency and reduce unnecessary burdens on businesses being investigated by several regulators at once.

To print this article, all you need is to be registered on Mondaq.com.

Click to Login as an existing user or Register so you can print this article.

Some comments from our readers…
“The articles are extremely timely and highly applicable”
“I often find critical information not available elsewhere”
“As in-house counsel, Mondaq’s service is of great value”

Press Releases from this Firm
Recent Content from this Firm
By Samuel Brown, Charles Borden, Christopher DeLacy, Andrew Emerson
By Steven Gordon
By J. Michael Cavanaugh, Eric Lee, Daniel Burkard
By Adam Bookbinder, Shannon Britton Hartsfield, Norma Krayem
By Courtney L. Batliner
By Susan Booth
By Dianne Phillips
By Leon Fresco
By Mary Beth Bosco, Taite McDonald, Michael Obeiter, Benjamin E. Dunham
By Dianne Phillips
Font Size:
Register for Access and our Free Biweekly Alert for
This service is completely free. Access 250,000 archived articles from 100+ countries and get a personalised email twice a week covering developments (and yes, our lawyers like to think you’ve read our Disclaimer).
Email Address
Company Name
Confirm Password
Mondaq Topics -- Select your Interests
 Law Performance
 Law Practice
 Media & IT
 Real Estate
 Wealth Mgt
Asia Pacific
European Union
Latin America
Middle East
United States
Worldwide Updates
Registration (you must scroll down to set your data preferences)

Mondaq Ltd requires you to register and provide information that personally identifies you, including your content preferences, for three primary purposes (full details of Mondaq’s use of your personal data can be found in our Privacy and Cookies Notice):

  • To allow you to personalize the Mondaq websites you are visiting to show content ("Content") relevant to your interests.
  • To enable features such as password reminder, news alerts, email a colleague, and linking from Mondaq (and its affiliate sites) to your website.
  • To produce demographic feedback for our content providers ("Contributors") who contribute Content for free for your use.

Mondaq hopes that our registered users will support us in maintaining our free to view business model by consenting to our use of your personal data as described below.

Mondaq has a "free to view" business model. Our services are paid for by Contributors in exchange for Mondaq providing them with access to information about who accesses their content. Once personal data is transferred to our Contributors they become a data controller of this personal data. They use it to measure the response that their articles are receiving, as a form of market research. They may also use it to provide Mondaq users with information about their products and services.

Details of each Contributor to which your personal data will be transferred is clearly stated within the Content that you access. For full details of how this Contributor will use your personal data, you should review the Contributor’s own Privacy Notice.

Please indicate your preference below:

Yes, I am happy to support Mondaq in maintaining its free to view business model by agreeing to allow Mondaq to share my personal data with Contributors whose Content I access
No, I do not want Mondaq to share my personal data with Contributors

Also please let us know whether you are happy to receive communications promoting products and services offered by Mondaq:

Yes, I am happy to received promotional communications from Mondaq
No, please do not send me promotional communications from Mondaq
Terms & Conditions

Mondaq.com (the Website) is owned and managed by Mondaq Ltd (Mondaq). Mondaq grants you a non-exclusive, revocable licence to access the Website and associated services, such as the Mondaq News Alerts (Services), subject to and in consideration of your compliance with the following terms and conditions of use (Terms). Your use of the Website and/or Services constitutes your agreement to the Terms. Mondaq may terminate your use of the Website and Services if you are in breach of these Terms or if Mondaq decides to terminate the licence granted hereunder for any reason whatsoever.

Use of www.mondaq.com

To Use Mondaq.com you must be: eighteen (18) years old or over; legally capable of entering into binding contracts; and not in any way prohibited by the applicable law to enter into these Terms in the jurisdiction which you are currently located.

You may use the Website as an unregistered user, however, you are required to register as a user if you wish to read the full text of the Content or to receive the Services.

You may not modify, publish, transmit, transfer or sell, reproduce, create derivative works from, distribute, perform, link, display, or in any way exploit any of the Content, in whole or in part, except as expressly permitted in these Terms or with the prior written consent of Mondaq. You may not use electronic or other means to extract details or information from the Content. Nor shall you extract information about users or Contributors in order to offer them any services or products.

In your use of the Website and/or Services you shall: comply with all applicable laws, regulations, directives and legislations which apply to your Use of the Website and/or Services in whatever country you are physically located including without limitation any and all consumer law, export control laws and regulations; provide to us true, correct and accurate information and promptly inform us in the event that any information that you have provided to us changes or becomes inaccurate; notify Mondaq immediately of any circumstances where you have reason to believe that any Intellectual Property Rights or any other rights of any third party may have been infringed; co-operate with reasonable security or other checks or requests for information made by Mondaq from time to time; and at all times be fully liable for the breach of any of these Terms by a third party using your login details to access the Website and/or Services

however, you shall not: do anything likely to impair, interfere with or damage or cause harm or distress to any persons, or the network; do anything that will infringe any Intellectual Property Rights or other rights of Mondaq or any third party; or use the Website, Services and/or Content otherwise than in accordance with these Terms; use any trade marks or service marks of Mondaq or the Contributors, or do anything which may be seen to take unfair advantage of the reputation and goodwill of Mondaq or the Contributors, or the Website, Services and/or Content.

Mondaq reserves the right, in its sole discretion, to take any action that it deems necessary and appropriate in the event it considers that there is a breach or threatened breach of the Terms.

Mondaq’s Rights and Obligations

Unless otherwise expressly set out to the contrary, nothing in these Terms shall serve to transfer from Mondaq to you, any Intellectual Property Rights owned by and/or licensed to Mondaq and all rights, title and interest in and to such Intellectual Property Rights will remain exclusively with Mondaq and/or its licensors.

Mondaq shall use its reasonable endeavours to make the Website and Services available to you at all times, but we cannot guarantee an uninterrupted and fault free service.

Mondaq reserves the right to make changes to the services and/or the Website or part thereof, from time to time, and we may add, remove, modify and/or vary any elements of features and functionalities of the Website or the services.

Mondaq also reserves the right from time to time to monitor your Use of the Website and/or services.


The Content is general information only. It is not intended to constitute legal advice or seek to be the complete and comprehensive statement of the law, nor is it intended to address your specific requirements or provide advice on which reliance should be placed. Mondaq and/or its Contributors and other suppliers make no representations about the suitability of the information contained in the Content for any purpose. All Content provided "as is" without warranty of any kind. Mondaq and/or its Contributors and other suppliers hereby exclude and disclaim all representations, warranties or guarantees with regard to the Content, including all implied warranties and conditions of merchantability, fitness for a particular purpose, title and non-infringement. To the maximum extent permitted by law, Mondaq expressly excludes all representations, warranties, obligations, and liabilities arising out of or in connection with all Content. In no event shall Mondaq and/or its respective suppliers be liable for any special, indirect or consequential damages or any damages whatsoever resulting from loss of use, data or profits, whether in an action of contract, negligence or other tortious action, arising out of or in connection with the use of the Content or performance of Mondaq’s Services.


Mondaq may alter or amend these Terms by amending them on the Website. By continuing to Use the Services and/or the Website after such amendment, you will be deemed to have accepted any amendment to these Terms.

These Terms shall be governed by and construed in accordance with the laws of England and Wales and you irrevocably submit to the exclusive jurisdiction of the courts of England and Wales to settle any dispute which may arise out of or in connection with these Terms. If you live outside the United Kingdom, English law shall apply only to the extent that English law shall not deprive you of any legal protection accorded in accordance with the law of the place where you are habitually resident ("Local Law"). In the event English law deprives you of any legal protection which is accorded to you under Local Law, then these terms shall be governed by Local Law and any dispute or claim arising out of or in connection with these Terms shall be subject to the non-exclusive jurisdiction of the courts where you are habitually resident.

You may print and keep a copy of these Terms, which form the entire agreement between you and Mondaq and supersede any other communications or advertising in respect of the Service and/or the Website.

No delay in exercising or non-exercise by you and/or Mondaq of any of its rights under or in connection with these Terms shall operate as a waiver or release of each of your or Mondaq’s right. Rather, any such waiver or release must be specifically granted in writing signed by the party granting it.

If any part of these Terms is held unenforceable, that part shall be enforced to the maximum extent permissible so as to give effect to the intent of the parties, and the Terms shall continue in full force and effect.

Mondaq shall not incur any liability to you on account of any loss or damage resulting from any delay or failure to perform all or any part of these Terms if such delay or failure is caused, in whole or in part, by events, occurrences, or causes beyond the control of Mondaq. Such events, occurrences or causes will include, without limitation, acts of God, strikes, lockouts, server and network failure, riots, acts of war, earthquakes, fire and explosions.

By clicking Register you state you have read and agree to our Terms and Conditions