It’s hard to find the most shocking detail about FTX, the cryptocurrency exchange that has imploded so dramatically. Whether it’s borrowing billions of dollars from customer deposits to service debts or using company funds to purchase employee homes and “personal items”, the story of FTX’s rapid demise is punctuated by blatant acts of exploitation by the now bankrupt exchange.
If these types of abusive practices intuitively seem like they should be illegal, that’s because under current US securities law they are. But FTX (which was based in the Bahamas, with the exception of its much smaller FTX US operation) and other crypto companies are largely outside the scope of securities law. Instead, they live in a regulatory gray area. Although FTX is currently under investigation and prosecutors may find ways to hold its decision makers accountable under US law, it may be more difficult than expected. The fact is, crypto companies are not governed by existing financial and securities regulations – and crypto is just the tip of the financial technology iceberg.
Under the current U.S. regulatory regime, fintech companies are viewed more as technology companies than financial companies. The sector has therefore largely been governed by the same “light regulation” regime as the tech industry, as opposed to the much stricter regulation of the financial industry.
This has significant implications for, among other things, users’ sensitive financial data. Laws governing the financial industry provide users of financial and banking information with special rights of protection and privacy, recognizing that consumer financial data is deeply personal and sensitive. The US approach to technology regulation, on the other hand, which tends toward a freer market than its European counterparts, has led to a regulatory system that allows user data to be treated as a commodity – one that can be collected , privatized, aggregated , and sold by industry.
The impact of this regulatory approach is considerable, given the ubiquity of fintech companies. While cryptocurrency remains relatively niche, other fintech services, from Apple Pay to Zelle, are increasingly integrating into our daily lives. Even though the word fintech conjures up something vaguely futuristic and aquatic to you, chances are you’ve used a fintech service at some point. Fintech refers to a rapidly growing sector of companies that are using new technologies to compete with traditional financial services companies, such as Acorns, Affirm, Square and Robinhood. As financial consumers have increasingly shifted their businesses from analog to digital, with a recent survey showing that 78% of Americans now prefer to bank digitally, fintech companies have proliferated.
In this online financial frenzy, which is expected to peak during the Cyber Monday sales, it’s easy to overlook one thing that gets bought and sold: consumer data.
What many users don’t realize when signing up for fintech services is the amount of sensitive financial data they are giving up. Typically, once a customer has linked their bank account to a fintech app, they can access and collect financial data through the provisions of its terms of service. A look at your typical fintech app’s privacy policy reveals a long list of data points collected about you.
Take fintech payment facilitator Plaid, for example. You may not have heard of it, but if you use Venmo or Coinbase, you have used Plaid. And Plaid collects, among other things, very specific information about users’ bank accounts, credit accounts, loans and investments, as well as personal information such as social security number and geolocation. The volume and type of information retrieved is far beyond what many customers would reasonably expect when signing up for fintech services like Venmo that use Plaid as a payment facilitator. (Indeed, Plaid recently paid $58 million to settle a lawsuit alleging the company deceptively obtained more financial data than necessary.)
Because they are regulated largely as technology companies, fintech companies are able to monetize the data they collect by selling it to third parties, like hedge funds, and creating information about customer behavior, thus facilitating targeted marketing. The industry is opaque, so it’s hard to quantify exactly how much data is being sold and to whom. The American Bankers Association observes, however, that “many data aggregators [including fintech firms] use the data for purposes other than the service sought by the customer. Access to all data allows the aggregator to profit from selling the information to other third parties, even if the customer was unaware of this potential use or requested services or marketing additional.
This Faustian bargain is the bread and butter of the tech industry: you receive seemingly “free” services in exchange for your data. Except that the data that fintech companies process is singular, it is particularly sensitive financial information and must be treated accordingly.
The commodification of data can generally be disastrous. Nevertheless, fintech data practices are particularly insidious because the dissemination of highly sensitive financial information can have significant effects on individuals’ participation in society (for example, by increasing consumers’ mass exposure to fraud and theft). of identity). By moving users’ financial data from their more secure and legally protected home in the bank into the unruly market for data services, these companies are exposing users to risks they are probably not even aware of.
This calls on lawmakers to place fintech under the umbrella of existing financial regulations, creating fintech regulation that emphasizes the “end” rather than the “technology.” This would ensure, among many other benefits, that users’ financial data is subject to protection under the Gramm-Leach-Bliley Act financial privacy rule. Additionally, regulating fintech companies at the federal level, rather than through the current patchwork of state laws, would create a more cohesive and cohesive regulatory regime.
While the fintech sector has the potential to make our financial lives more convenient, efficient and fair, it needs to be regulated appropriately so that the risks presented to consumers do not outweigh the benefits. Closing the fintech loophole is necessary to address the current ambiguity and create a more unified, common-sense regulatory landscape. Otherwise, we can say goodbye to our finances privacy.
Future Tense is a partnership between Slate, New America and Arizona State University that examines emerging technologies, public policy and society.