Fair and Accurate Credit Transactions Act
   HOME

TheInfoList



OR:

The Fair and Accurate Credit Transactions Act of 2003 (FACT Act or FACTA, ) is a
United States federal law The law of the United States comprises many levels of codified and uncodified forms of law, of which the most important is the nation's Constitution, which prescribes the foundation of the federal government of the United States, as well as ...
, passed by the
United States Congress The United States Congress is the legislature of the federal government of the United States. It is Bicameralism, bicameral, composed of a lower body, the United States House of Representatives, House of Representatives, and an upper body, ...
on November 22, 2003, and signed by President George W. Bush on December 4, 2003, as an amendment to the
Fair Credit Reporting Act The Fair Credit Reporting Act (FCRA), 15 U.S.C. § 1681 ''et seq'', is U.S. Federal Government legislation enacted to promote the accuracy, fairness, and privacy of consumer information contained in the files of consumer reporting agencies. It ...
. The act allows consumers to request and obtain a free
credit report :''This article deals with the general concept of the term credit history. For detailed information about the same topic in the United States, see Credit score in the United States.'' A credit history is a record of a borrower's responsible repa ...
once every 12 months from each of the three nationwide consumer credit reporting companies (
Equifax Equifax Inc. is an American multinational consumer credit reporting agency headquartered in Atlanta, Georgia and is one of the three largest consumer credit reporting agencies, along with Experian and TransUnion (together known as the "Big Th ...
,
Experian Experian is an American–Irish multinational data analytics and consumer credit reporting company. Experian collects and aggregates information on over 1 billion people and businesses including 235 million individual U.S. consumers and more ...
, and
TransUnion TransUnion is an American consumer credit reporting agency. TransUnion collects and aggregates information on over one billion individual consumers in over thirty countries including "200 million files profiling nearly every credit-active consume ...
). In cooperation with the
Federal Trade Commission The Federal Trade Commission (FTC) is an independent agency of the United States government whose principal mission is the enforcement of civil (non-criminal) antitrust law and the promotion of consumer protection. The FTC shares jurisdiction o ...
, the three major credit reporting agencies set up the web site AnnualCreditReport.com to provide free access to annual credit reports. The act also contains provisions to help reduce
identity theft Identity theft occurs when someone uses another person's personal identifying information, like their name, identifying number, or credit card number, without their permission, to commit fraud or other crimes. The term ''identity theft'' was c ...
, such as the ability for individuals to place alerts on their credit histories if identity theft is suspected, or if deploying overseas in the military, thereby making fraudulent applications for credit more difficult. Further, it requires secure disposal of consumer information.


Provisions

The FACT Act contains seven major titles: Identity Theft Prevention and Credit History Restoration, Improvements in Use of and Consumer Access to Credit Information, Enhancing the Accuracy of Consumer Report Information, Limiting the Use and Sharing of Medical Information in the Financial System, Financial Literacy and Education Improvement, Protecting Employee Misconduct Investigations, and Relation to State Laws.


Identity Theft Prevention and Credit History Restoration

This title of the act contains provisions that deal mainly with the prevention of identity theft. In particular, it establishes new regulations concerning 'fraud alerts' and 'active duty alerts', establishes new limitations on the printing of customers' credit card numbers on receipts, and prescribes that new regulations be established by certain government agencies regarding the detection of identity theft by
financial institution Financial institutions, sometimes called banking institutions, are business entities that provide services as intermediaries for different types of financial monetary transactions. Broadly speaking, there are three major types of financial inst ...
s and
creditor A creditor or lender is a party (e.g., person, organization, company, or government) that has a claim on the services of a second party. It is a person or institution to whom money is owed. The first party, in general, has provided some property ...
s.


Fraud alerts

The title requires that consumer reporting agencies, upon the request of a consumer who believes he is or about to be a victim of
fraud In law, fraud is intentional deception to secure unfair or unlawful gain, or to deprive a victim of a legal right. Fraud can violate civil law (e.g., a fraud victim may sue the fraud perpetrator to avoid the fraud or recover monetary compen ...
or any other related crime, must place a fraud alert on that consumer's file for at least 90 days, and notify all other consumer reporting agencies of the fraud alert. Consumers may request an extended fraud alert, in which case requires the reporting agency to disclose this fraud alert in any credit score that it issues for the consumer during a seven-year period. An extended alert also requires the reporting agency to exclude the consumer from any list distributed to third parties for the purpose of extending credit or offering insurance to that consumer. The title also provides for any
active duty Active duty, in contrast to reserve duty, is a full-time occupation as part of a military force. In the United Kingdom and the Commonwealth of Nations, the equivalent term is active service. India The Indian Armed Forces are considered to be o ...
member to request an active duty alert, which requires the reporting agency to disclose such alert with any credit report issued within 12 months of the request and to exclude the active duty member from any list distributed to third parties for the purpose of extending credit or offering insurance for two years from the request.


Truncation of credit and debit card numbers

The act also prohibits businesses from printing more than five digits of any customer's card number or card expiration date on any receipt provided to the cardholder at the
point of sale The point of sale (POS) or point of purchase (POP) is the time and place at which a retail transaction is completed. At the point of sale, the merchant calculates the amount owed by the customer, indicates that amount, may prepare an invoice f ...
or transaction. This provision is enforced with statutory damages ranging from $100 to $1000 per violation, and when claims are aggregated in a
class action A class action, also known as a class-action lawsuit, class suit, or representative action, is a type of lawsuit where one of the parties is a group of people who are represented collectively by a member or members of that group. The class actio ...
(brought by all the customers of a retailer that failed to truncate credit card numbers) the amount of damages can be massive. The provision excludes receipts that are handwritten or imprinted, where the only method of recording the credit card number is by such means. The act did not become effective for three years after its enactment for any cash register manufactured before January 1, 2005, and did not become effective for one year after its enactment for any cash register manufactured after January 1, 2005.


Identification of possible identity theft (Red Flags rule)

The act established the Red Flags Rule, which required the federal banking agencies, the
National Credit Union Administration The National Credit Union Administration (NCUA) is a government-backed insurer of credit unions in the United States, one of two agencies that provide deposit insurance to depositors in U.S. depository institutions, the other being the Feder ...
, and the
Federal Trade Commission The Federal Trade Commission (FTC) is an independent agency of the United States government whose principal mission is the enforcement of civil (non-criminal) antitrust law and the promotion of consumer protection. The FTC shares jurisdiction o ...
to jointly create regulations regarding identity theft prevention applicable to financial institutions and creditors. The Red Flags Rule also addresses how card issuers must respond to changes of address. Regulations that were established as a result include: *One that requires financial institutions or creditors to develop and implement an Identity Theft Prevention Program in connection with both new and existing accounts. The Program must include reasonable policies and procedures for detecting, preventing, and mitigating identity theft; *Another that requires users of consumer reports to respond to Notices of Address Discrepancies that they receive; and *A third that places special requirements on issuers of debit or credit cards to assess the validity of a change of address if they receive notification of a change of address for a consumer's debit or credit card account and, within a short period of time afterward they receive a request for an additional or replacement card for the same account. Another key item was the requirement that mortgage lenders provide consumers with a Credit Disclosure Notice that included their
credit score A credit score is a numerical expression based on a level analysis of a person's credit files, to represent the creditworthiness of an individual. A credit score is primarily based on a credit report, information typically sourced from credit b ...
s, range of scores, credit bureaus, scoring models, and factors affecting their scores. This form is typically available from credit reporting agencies, and many will send this directly to the consumer on the lenders' behalf.


= Confusion with the scope of the Red Flags rule

= Financial institutions faced a mandatory deadline of November 1, 2008, to comply with the Red Flags Rule, section 114 and 315 of the Fair and Accurate Credit Transactions (FACT) Act. However, due to widespread confusion over coverage under the act, specifically whether the term "creditor" applies to particular businesses, members of Congress repeatedly requested that FTC postpone the deadline for compliance with Section 315 until after December 31, 2010. According to a Business Alert issued by the
Federal Trade Commission The Federal Trade Commission (FTC) is an independent agency of the United States government whose principal mission is the enforcement of civil (non-criminal) antitrust law and the promotion of consumer protection. The FTC shares jurisdiction o ...
in June 2008, the Red Flags Rule applies to a very broad list of businesses including "financial institutions" and "creditors" with "covered accounts". A "creditor" is defined to include "lenders such as banks, finance companies, automobile dealers, mortgage brokers, utility companies and telecommunications companies". However, this is not an all-inclusive list. The regulations apply to all businesses that have "covered accounts". A "covered account" includes any account for which there is a foreseeable risk of identity theft. For example, credit cards, monthly billed accounts like utility bills or cell phone bills, social security numbers, drivers license numbers, medical insurance accounts, and many others. This significantly expands the definition to include all companies, regardless of size, that maintain, or otherwise possess, consumer information for a business purpose. Because of the broad definitions in these regulations, few businesses will be able to escape these requirements.


Protection and restoration of identity theft victim credit history


Summary of rights of identity theft victims

Provisions in this title require that the Federal Trade Commission, in consultation with the Federal banking agencies and the National Credit Union Agency, "prepare a model summary of the rights of consumers ... with respect to the procedures for remedying the effects of fraud or identity theft...". Beginning sixty days after the summary of these rights were established, all reporting agencies are required to provide a copy of this summary to any consumer that contacts an agency and states that he believes he has been a victim of fraud or identity theft.


Blocking of information resulting from identity theft

The Act also requires any reporting agency to block the reporting of any information in a consumer's file that the consumer identifies as information that originated from an alleged identity theft. Such agency must block the information within four days of receiving proof, a copy of an identity theft report, the identification of the information by the consumer, and a statement from the consumer that the information is not a result of any transaction he participated in. Agencies are not required to block any information (and may rescind any existing blocks) in the case that the block was found to be made in error or based on erroneous information as provided by the consumer, or that the consumer "obtained possession of goods, services, or money as a result of the blocked transaction or transactions.


Coordination of identity theft complaint investigations

This section requires that all consumer reporting agencies develop a means of communicating to each other consumer complaints regarding fraud or identity theft, or requests for fraud alerts or blocks. Furthermore, the section requires that each consumer reporting agency release a report each year to the Federal Trade Commission of fraud alert requests and complaints involving fraud or identity theft received by the reporting agency. Finally, the section requires the Federal Trade Commission to set up a means by which consumers can contact the reporting agencies and creditors with a complaint involving identity theft or fraud.


Criticism

After its enactment, some consumer advocacy groups criticized the FACT Act claiming that it preempts some stricter and already-existing state regulations, and provides exceptions that are 'far too generous' to new regulations regarding disclosure of personal information by banks as found in the act. Furthermore, an article in
The Washington Post ''The Washington Post'' (also known as the ''Post'' and, informally, ''WaPo'') is an American daily newspaper published in Washington, D.C. It is the most widely circulated newspaper within the Washington metropolitan area and has a large n ...
criticized the difficulty in retrieving the credit reports in some of the states that were first eligible under the act.


Preemption of state laws

Vermont, Colorado, Georgia, Maine, Maryland, Massachusetts, New Jersey, and California had all established laws by 1994 requiring credit bureaus to provide a free credit report on demand. However, according to U.S. Pirg, " th the FACT Act, the financial industry won its primary goal: permanent preemption of stronger state credit and privacy laws." Specifically, state laws are preempted in certain areas, such as the content of a consumer report, the responsibilities of "furnishers", responses of consumer reporting agencies to disputes over inaccurate information (although there is an exception for statutes in place before 1996), and duties of those who take an adverse action based on a report.


Difficulty in obtaining credit reports

An article dated March 13, 2005 and published in the Washington Post stated that while " sidents of six East Coast states—Maryland, Georgia, Maine, Massachusetts, New Jersey and Vermont—are already eligible for free reports from all three agencies as a result of state laws", the phone numbers provided to request these reports connected to automated systems that the article described as "maddening in their complexity and unforgiving if your circumstances vary from the system's programming." Furthermore, the article criticised automated systems for forcing consumers to "navigate a thicket of recorded information -- including sales pitches for their products, such as a credit 'score' (an evaluation of your creditworthiness) or a 'monitoring' service to help guard against identity theft". Since 2012, the Consumer Financial Protection Bureau (CFPB) has published a list of consumer reporting agencies (CRAs). It enables consumers to see which CRAs might be important to them and gives them the contact information of each CRA in the list, so consumers can more easily order their personal consumer reports. Many of the CRAs in the list provide personal reports to consumers for free. The 2016 edition of the list is available on the CFPB'
websitehere


The Red Flag rule as a cause of identity theft

As the Red Flag rule widely defines creditors, many businesses (such as utilities) are now required to collect personal information (such as SSN and driver's license numbers) that they do not need and have no use for. This policy is precisely contrary to the FTC's advice to consumers that they should disclose their social security number to companies only when absolutely necessary. This aspect of the Red Flag rule has the unintended consequences of increasing the number of businesses that hold consumers' Social Security numbers, thereby putting consumers at greater risk for identity theft through data theft.


Mass Lawsuits for Including Expiration Date on Printed Receipts

The Act prohibits merchants from including credit- and debit-card expiration dates on electronically printed receipts. When the Act went into effect in 2004, courts received massive amounts of expiration date lawsuits, all federal circuit to have expressly considered the issue now refuse to hear related class-action lawsuits. In 2008 Congress passed the Credit and Debit Card Receipt Clarification Act (Clarification Act), which made merchants who printed expiration dates on receipts, but otherwise complied with the Act, to not in willful noncompliance up to June 3, 2008. In the Clarification Act, Congress found that "Experts in the field agree that proper truncation of the card number, by itself... regardless of the inclusion of the expiration date, prevents a potential fraudster from perpetrating identity theft or credit card fraud." However, despite court rulings and the Clarification Act, the text of the Act remains largely unchanged regarding expiration dates on receipts after June 3, 2008.


See also

*
Fair Credit Reporting Act The Fair Credit Reporting Act (FCRA), 15 U.S.C. § 1681 ''et seq'', is U.S. Federal Government legislation enacted to promote the accuracy, fairness, and privacy of consumer information contained in the files of consumer reporting agencies. It ...
* Policy and Economic Research Council—think tank that did much of the research on FACTA *
Securities regulation in the United States Securities regulation in the United States is the field of U.S. law that covers transactions and other dealings with securities. The term is usually understood to include both federal and state-level regulation by governmental regulatory agencies, ...
*
Commodity Futures Trading Commission The Commodity Futures Trading Commission (CFTC) is an independent agency of the US government created in 1974 that regulates the U.S. derivatives markets, which includes futures, swaps, and certain kinds of options. The Commodity Exchange Act ...
* Securities Commission *
Chicago Stock Exchange NYSE Chicago, formerly known as the Chicago Stock Exchange (CHX), is a stock exchange in Chicago, Illinois, US. The exchange is a national securities exchange and self-regulatory organization, which operates under the oversight of the U.S. ...
*
Financial regulation Financial regulation is a form of regulation or supervision, which subjects financial institutions to certain requirements, restrictions and guidelines, aiming to maintain the stability and integrity of the financial system. This may be handle ...
*
List of financial regulatory authorities by country The following is an incomplete list of financial regulatory authorities by country. List A-B * Afghanistan - Da Afghanistan Bank (DAB) * Albania - Albanian Financial Supervisory Authority (FSA) * Algeria - Commission d'Organisation et de ...
*
NASDAQ The Nasdaq Stock Market () (National Association of Securities Dealers Automated Quotations Stock Market) is an American stock exchange based in New York City. It is the most active stock trading venue in the US by volume, and ranked second ...
*
New York Stock Exchange The New York Stock Exchange (NYSE, nicknamed "The Big Board") is an American stock exchange in the Financial District of Lower Manhattan in New York City. It is by far the world's largest stock exchange by market capitalization of its liste ...
*
Stock exchange A stock exchange, securities exchange, or bourse is an exchange where stockbrokers and traders can buy and sell securities, such as shares of stock, bonds and other financial instruments. Stock exchanges may also provide facilities for t ...
*
Regulation D (SEC) In the United States under the Securities Act of 1933, any offer to sell securities must either be registered with the United States Securities and Exchange Commission (SEC) or meet certain qualifications to exempt them from such registration. ...
;Related legislation * 1933 -
Securities Act of 1933 The Securities Act of 1933, also known as the 1933 Act, the Securities Act, the Truth in Securities Act, the Federal Securities Act, and the '33 Act, was enacted by the United States Congress on May 27, 1933, during the Great Depression and after ...
* 1934 –
Securities Exchange Act of 1934 The Securities Exchange Act of 1934 (also called the Exchange Act, '34 Act, or 1934 Act) (, codified at et seq.) is a law governing the secondary trading of securities ( stocks, bonds, and debentures) in the United States of America. A land ...
* 1938 –
Temporary National Economic Committee The Temporary National Economic Committee (TNEC) was established by a joint resolution of the United States Congress on June 16, 1938 and operated until its defunding on April 3, 1941. The TNEC's function was to study the concentration of economic p ...
(establishment) * 1939 -
Trust Indenture Act of 1939 The Trust Indenture Act of 1939 (TIA), codified at , supplements the Securities Act of 1933 in the case of the distribution of debt securities in the United States. Generally speaking, the TIA requires the appointment of a suitably independent and ...
* 1940 -
Investment Advisers Act of 1940 The Investment Advisers Act of 1940, codified at through , is a United States federal law that was created to monitor and regulate the activities of investment advisers (also spelled "advisors") as defined by the law. It is the primary source of r ...
* 1940 -
Investment Company Act of 1940 The Investment Company Act of 1940 (commonly referred to as the '40 Act) is an act of Congress which regulates investment funds. It was passed as a United States Public Law () on August 22, 1940, and is codified at . Along with the Securities Ex ...
* 1968 –
Williams Act The Williams Act (USA) refers to 1968 amendments to the Securities Exchange Act of 1934 enacted in 1968 regarding tender offers. The legislation was proposed by Senator Harrison A. Williams of New Jersey. The Williams Act amended the Securities ...
(Securities Disclosure Act) * 1975 – Securities and Exchange Act * 1982 –
Garn–St. Germain Depository Institutions Act The Garn–St Germain Depository Institutions Act of 1982 (, , enacted October 15, 1982) is an Act of Congress that deregulated savings and loan associations and allowed banks to provide adjustable-rate mortgage loans. It is disputed whether the a ...
* 1999 – Gramm-Leach-Bliley Act * 2000 –
Commodity Futures Modernization Act of 2000 The Commodity Futures Modernization Act of 2000 (CFMA) is United States federal legislation that ensured financial products known as over-the-counter (OTC) derivatives remained unregulated. It was signed into law on December 21, 2000 by President ...
* 2002 –
Sarbanes–Oxley Act The Sarbanes–Oxley Act of 2002 is a United States federal law that mandates certain practices in financial record keeping and reporting for corporations. The act, (), also known as the "Public Company Accounting Reform and Investor Protect ...
* 2006 - Credit Rating Agency Reform Act of 2006 * 2010 –
Dodd–Frank Wall Street Reform and Consumer Protection Act The Dodd–Frank Wall Street Reform and Consumer Protection Act, commonly referred to as Dodd–Frank, is a United States federal law that was enacted on July 21, 2010. The law overhauled financial regulation in the aftermath of the Great Rece ...


References


External links


White House press releaseFull text of the "Fair and Accurate Credit Transactions Act of 2003"
* Federal Register, Vol 72. No. 217, Friday, November 9, 2007, Rules and Regulations. pp 63718–63775.
Consumer Financial Protection Bureau (CFPB) List of consumer reporting companies current as of January 2016
{{DEFAULTSORT:Fair And Accurate Credit Transactions Act United States federal banking legislation Acts of the 108th United States Congress
2003 File:2003 Events Collage.png, From top left, clockwise: The crew of STS-107 perished when the Space Shuttle Columbia disintegrated during reentry into Earth's atmosphere; SARS became an epidemic in China, and was a precursor to SARS-CoV-2; A ...
Fraud legislation