Washington, D.C. – A proposed rulemaking by California’s privacy agency imposing requirements on banks’ cybersecurity programs, automated decision-making tools, and risk management is yet another overreaching state law that undercuts longstanding federal rules, BPI said in a comment letter submitted today.
“A patchwork approach to bank regulation is bad policy and contrary to law. Banks are already subject to stringent federal rules on their cybersecurity, AI tools, and risk management, and invest billions of dollars into protecting their customers’ data. What’s more, the rule disregards the longstanding federal framework that enables national banks to serve customers efficiently and finance business growth across the country. Forcing banks to comply with different and conflicting requirements detracts from real risk management and innovation.” — Greg Baer, BPI President and CEO.
Here’s the background: The California proposal goes beyond the limited mandate the legislature granted to the state privacy agency and imposes far-reaching requirements that attempt to dictate banks’ cybersecurity and risk management practices, as well as how they use AI technology. As a result it would interfere with critical bank operations like underwriting small business loans and preventing fraud.
- What authority does California’s privacy agency have? The California legislature granted the privacy agency the authority to only regulate activities not already covered by the Gramm-Leach-Bliley Act (GLBA), which governs banks’ privacy practices that are subject to unique supervision by federal regulators. However, in practice, the rulemaking risks encroaching on data already covered by GLBA, among other instances of significant statutory overreach by the agency.
- What is national bank preemption? Under federal law, states may not impose requirements on national banks – that is, banks chartered and primarily regulated by the OCC – if the law would significantly interfere with the bank’s exercise of its powers. This principle ensures that banks can operate efficiently across state lines without being ensnared in a jumble of 50 different regulatory frameworks.
- Backdoor audits: Key parts of the proposed rules would interfere with the exclusive powers granted to federal regulators under the law. For example, the rulemaking would mandate that banks submit to California risk assessments and cybersecurity audits that adhere to highly specific requirements established by the agency. But California cannot directly inspect national banks on their cybersecurity or risk management, which is the responsibility of bank examiners, and so it cannot indirectly achieve that result by having banks conduct and then provide a highly prescriptive audit on its behalf. Such a policy would usurp the powers of federal regulators.
Crucial context: National bank preemption has been at the forefront of recent legal debates as states have adopted new laws aimed at banks, such as an Illinois interchange fee restriction that was recently enjoined for national banks.
Bottom line: To avoid duplicative regulation and conflict with federal law, banks already subject to federal oversight should be exempt from California’s proposed rules.
###
About Bank Policy Institute.
The Bank Policy Institute is a nonpartisan public policy, research and advocacy group that represents universal banks, regional banks and the major foreign banks doing business in the United States. The Institute produces academic research and analysis on regulatory and monetary policy topics, analyzes and comments on proposed regulations, and represents the financial services industry with respect to cybersecurity, fraud, and other information security issues.
Media Contacts
- Tara Payne, Bank Policy Institute, Tara.Payne@bpi.com
