FFIEC Issues Social Media Guidance: Social Media Channels Present Privacy Compliance Challenges

From: Bradley Arant Boult Cummings LLP

Article by Elena A. Lovoy

If you are using social media to attract and interact with customers, you should review the recent supervisory guidance from the Federal Financial Institutions Examination Council (FFIEC). The guidance, titled “Social Media: Consumer Compliance Risk Management Guidance,” (“Guidance”) was released on December 11, 2013, and was immediately effective. The Guidance applies to all banks, savings associations, and credit unions and to all nonbank entities supervised by the Consumer Financial Protection Bureau (CFPB). Among other things, the Guidance reminds financial institutions that the existing privacy rules have a “particular relevance” in the social media space.

For purposes of the Guidance, “social media” includes any form of interactive online communication in which users can generate and share content through text, images, audio, or video—for example, blogging websites, online forums, chat rooms, customer review websites, complaint submission and processing websites, and online bulletin boards. The Guidance recognizes that social media is a dynamic and constantly evolving technology, so the “definition” of social media is for illustration purposes only. Emails and text messages, standing alone, do not constitute social media. However, messages sent through social media channels are subject to the Guidance.

The Guidance identifies certain key issues that all financial institutions need to incorporate into their social media compliance programs, including the following:

Risk Management

The Guidance reminds financial institutions that they should include social media issues in their overall risk management programs. Financial institutions are expected to establish a governance structure for the use of social media, including the implementation of controls and ongoing risk assessments of the institution’s social media activities and the establishment of policies and procedures regarding the use and monitoring of social media. The governance structure should identify and address the compliance and legal risks, reputation risks, operational risks, and risks of harm to consumers associated with the institution’s use of social media.

Vendor Management

The Guidance reminds financial institutions that they are expected to conduct evaluations of, and perform due diligence appropriate to, the risks posed by third-party social media providers, even if the financial institution does not have a traditional vendor relationship with the provider.

Training

Additionally, the Guidance notes that financial institutions should provide training and guidance on social media compliance issues that incorporates the institution’s policies and procedures for official work-related use of social media. Training should be provided to all employees who officially communicate on behalf of the financial institution through any social media channels and also highlight impermissible social media activities.

Complaint Submission and Processing

The Guidance notes that financial institutions should implement an oversight process for monitoring information posted to proprietary social media sites administered by the financial institution or a contracted third-party vendor. Financial institutions are not, however, expected to monitor all communications about the institution, including complaints or inquiries about the institution, on internet sites other than those maintained by or on behalf of the institution.

A financial institution is not expected to treat all negative comments made on its proprietary social media sites as complaints or inquiries. A financial institution may, consistent with other applicable legal requirements, establish one or more specified channels that customers may use for submitting communications directly to the institution. The Guidance notes that even if a financial institution has elected to not use social media, it still should consider the potential for negative comments or complaints that may arise within social media platforms and, when appropriate, evaluate what, if any, action the institution will take to monitor and/or respond to such comments.

Regulatory Requirements

The Guidance reminds financial institutions that all of the legal and regulatory requirements otherwise applicable to their deposit, lending, payment services, marketing, advertising, and other activities remain applicable to the same activities conducted via social media channels. There are no social media exceptions to these requirements. The Guidance includes examples of the regulatory requirements that remain applicable in the social media space, including the following privacy requirements:

Read Complete Article

Facebooktwittergoogle_plusredditpinterestlinkedinmail

Leave a Reply

Your email address will not be published.

Please Answer: *