CUNA sends data privacy letter to Homeland Security subcommittee

WASHINGTON, DC (March 7, 2019) — Credit Union National Association (CUNA) wrote to the House Homeland Security subcommittee on investigations Wednesday ahead of their hearing on private sector data breaches. CUNA maintains that the cornerstone of any new data privacy requirements should be robust data security requirements for entities that collect consumers’ personal information.

“Credit unions have met with members of this committee to detail damage to credit unions and their members from data breaches. The current gaps in data protection and privacy laws hurt consumers and businesses as information is misused by criminals and other actors with malicious intent. Financial institutions are at the vanguard for misuse of stolen data,” the letter reads.

The growing issue extends beyond the financial services industry and robust privacy and data security requirements for all industries is becoming increasingly necessary.

CUNA also called on Congress to work with the administration to “finally industry to finally address consumer data privacy in a meaningful way,” and stating:

  • Any new privacy law should cover both privacy and data security. There cannot be privacy of data without protection from loss due to breach or other types of theft;
  • The law should cover all institutions, not just tech companies, credit-rating agencies, and other narrow sectors of the economy. Any company that collects, uses or shares personal data or information has the opportunity to misuse the data or lose the data through breach;
  • Data security requirements should be based upon protection of data to prevent theft and misuse;
  • Notification or disclosure after the fact are important but are not the stopping point for adequate protection. By the time a breach is disclosed, harm could already have befallen hundreds of thousands, if not millions, of individuals, so robust protection is paramount for any new requirements;
  • A law should provide mechanisms to address the harms that result from privacy violations and security violations, including data breach. Increasingly courts are recognizing rights of action for individuals and companies (including credit unions). However, individuals and companies should be afforded a private right of action to hold those that violate the law accountable, and  regulators should have the ability to take action against entities that violate the law; and
  • Any new law should preempt state requirements to simplify compliance and create equal expectation and protection for all consumers. Just like moving away from the sector specific approach, the goal should be to create a national standard for all to follow.

About CUNA

Credit Union National Association (CUNA) is the only national association that advocates on behalf of all of America’s credit unions, which are owned by 135 million consumer members. CUNA, along with its network of affiliated state credit union leagues, delivers unwavering advocacy, continuous professional growth and operational confidence to protect the best interests of all credit unions. For more information about CUNA, visit To find your nearest credit union, visit


CUNA Communications


More News