The Fair and Accurate Credit Transactions Act of 2003 (FACT Act or FACTA, Pub. L. 108–159 (text)(PDF)) is a U.S. federal law, passed by the United States Congress on November 22, 2003,[1] and signed by President George W. Bush on December 4, 2003,[2] as an amendment to the Fair Credit Reporting Act. The act allows consumers to request and obtain a free credit report once every 12 months from each of the three nationwide consumer credit reporting companies (Equifax, Experian, and TransUnion). In cooperation with the Federal Trade Commission, the three major credit reporting agencies set up the web site AnnualCreditReport.com to provide free access to annual credit reports.[3]
The act also contains provisions to help reduce identity theft, such as the ability for individuals to place alerts on their credit histories if identity theft is suspected, or if deploying overseas in the military, thereby making fraudulent applications for credit more difficult. Further, it requires secure disposal of consumer information.
The FACT Act contains seven major titles: Identity Theft Prevention and Credit History Restoration, Improvements in Use of and Consumer Access to Credit Information, Enhancing the Accuracy of Consumer Report Information, Limiting the Use and Sharing of Medical Information in the Financial System, Financial Literacy and Education Improvement, Protecting Employee Misconduct Investigations, and Relation to State Laws.[4]
This title of the act contains provisions that deal mainly with the prevention of identity theft. In particular, it establishes new regulations concerning 'fraud alerts' and 'active duty alerts', establishes new limitations on the printing of customers' credit card numbers on receipts, and prescribes that new regulations be established by certain government agencies regarding the detection of identity theft by financial institutions and creditors.
The title requires that consumer reporting agencies, upon the request of a consumer who believes he is or about to be a victim of fraud or any other related crime, must place a fraud alert on that consumer's file for at least 90 days, and notify all other consumer reporting agencies of the fraud alert.[5]
Consumers may request an extended fraud alert, in which case requires the reporting agency to disclose this fraud alert in any credit score that it issues for the consumer during a seven-year period. An extended alert also requires the reporting agency to exclude the consumer from any list distributed to third parties for the purpose of extending credit or offering insurance to that consumer.[5]
The title also provides for any active duty member to request an active duty alert, which requires the reporting agency to disclose such alert with any credit report issued within 12 months of the request and to exclude the active duty member from any list distributed to third parties for the purpose of extending credit or offering insurance for two years from the request.[5]
The act also prohibits businesses from printing more than five digits of any customer's card number or card expiration date on any receipt provided to the cardholder at the point of sale or transaction. This provision is enforced with statutory damages ranging from $100 to $1000 per violation, and when claims are aggregated in a class action (brought by all the customers of a retailer that failed to truncate credit card numbers) the amount of damages can be massive.[6] The provision excludes receipts that are handwritten or imprinted, where the only method of recording the credit card number is by such means. The act did not become effective for three years after its enactment for any cash register manufactured before January 1, 2005, and did not become effective for one year after its enactment for any cash register manufactured after January 1, 2005.[7]
The act established the Red Flags Rule, which required the federal banking agencies, the National Credit Union Administration, and the Federal Trade Commission to jointly create regulations regarding identity theft prevention applicable to financial institutions and creditors. The Red Flags Rule also addresses how card issuers must respond to changes of address.[8] Regulations that were established as a result include:[9]
Another key item was the requirement that mortgage lenders provide consumers with a Credit Disclosure Notice that included their credit scores, range of scores, credit bureaus, scoring models, and factors affecting their scores. This form is typically available from credit reporting agencies, and many will send this directly to the consumer on the lenders' behalf.
Financial institutions faced a mandatory deadline of November 1, 2008, to comply with the Red Flags Rule,[10] section 114 and 315 of the Fair and Accurate Credit Transactions (FACT) Act. However, due to widespread confusion over coverage under the act, specifically whether the term "creditor" applies to particular businesses, members of Congress repeatedly requested that FTC postpone the deadline for compliance with Section 315 until after December 31, 2010.[11]
According to a Business Alert issued by the Federal Trade Commission in June 2008,[12] the Red Flags Rule applies to a very broad list of businesses including "financial institutions" and "creditors" with "covered accounts". A "creditor" is defined to include "lenders such as banks, finance companies, automobile dealers, mortgage brokers, utility companies and telecommunications companies". However, this is not an all-inclusive list.
この規制は、「対象アカウント」を持つすべての企業に適用されます。「対象アカウント」には、個人情報盗難の予見可能なリスクがあるアカウントが含まれます。たとえば、クレジットカード、公共料金や携帯電話料金などの毎月請求されるアカウント、社会保障番号、運転免許証番号、医療保険アカウントなどです。これにより、規模に関係なく、ビジネス目的で消費者情報を維持または保有するすべての企業が含まれるように定義が大幅に拡大されます。これらの規制の定義が広範であるため、これらの要件から逃れることができる企業はほとんどありません。[ 13 ]
この章の規定では、連邦取引委員会が連邦銀行機関および全国信用組合機関と協議の上、「詐欺またはなりすましの影響を救済するための手続きに関する消費者の権利のモデル概要を作成する」ことが求められています。これらの権利の概要が作成されてから60日後から、すべての報告機関は、詐欺またはなりすましの被害者になったと思われる消費者が機関に連絡してきた場合、その消費者にこの概要のコピーを提供することが義務付けられています。[ 14 ]
また、同法は、消費者が個人情報盗難の疑いのある情報に由来すると特定した消費者ファイル内の情報について、報告機関がその報告を阻止することを義務付けている。当該機関は、証拠、個人情報盗難報告書の写し、消費者による情報の特定、および当該情報が消費者が関与した取引の結果ではないという消費者の声明を受け取ってから4日以内に、その情報を阻止しなければならない。
消費者が提供した情報に誤りがあった場合、または誤った情報に基づいてブロックが行われたことが判明した場合、あるいは消費者がブロックされた取引の結果として商品、サービス、または金銭を取得した場合には、機関はいかなる情報もブロックする義務はなく(既存のブロックも取り消すことができる)。[ 15 ]
この条項では、すべての消費者信用情報機関が、詐欺やなりすましに関する消費者の苦情、または詐欺警告やブロックの要求を相互に伝達する手段を開発することを義務付けています。さらに、この条項では、各消費者信用情報機関が、詐欺警告の要求および当該機関が受け取った詐欺またはなりすましに関する苦情について、毎年連邦取引委員会に報告書を提出することを義務付けています。最後に、この条項では、消費者がなりすましまたは詐欺に関する苦情を報告機関および債権者に連絡できる手段を連邦取引委員会が設定することを義務付けています。[ 16 ]
FACT法が施行された後、一部の消費者擁護団体は、同法がより厳格な既存の州規制を無効にし、銀行による個人情報の開示に関する同法に規定されている新たな規制に対して「寛大すぎる」例外を設けているとして、FACT法を批判した。[ 17 ]さらに、ワシントン・ポスト紙 の記事では、同法の適用対象となった一部の州で信用報告書を入手するのが難しいことを批判した。[ 18 ]
バーモント州、コロラド州、ジョージア州、メイン州、メリーランド州、マサチューセッツ州、ニュージャージー州、カリフォルニア州は、1994年までに信用情報機関に対し、要求に応じて無料の信用報告書を提供するよう義務付ける法律を制定していた。しかし、US Pirgによると、「FACT法によって、金融業界は主要な目標である、より強力な州の信用法およびプライバシー法の恒久的な先占を達成した」[ 19 ] 。具体的には、消費者レポートの内容、「情報提供者」の責任、不正確な情報に関する紛争に対する消費者信用情報機関の対応(ただし、1996年以前に施行された法律には例外がある)、およびレポートに基づいて不利な措置を取る者の義務など、特定の分野では州法が先占されている[ 20 ] 。
2005年3月13日付でワシントン・ポストに掲載された記事によると、「メリーランド州、ジョージア州、メイン州、マサチューセッツ州、ニュージャージー州、バーモント州の東海岸6州の住民は、州法により3つの機関すべてから無料のレポートを受け取る資格がある」ものの、これらのレポートを請求するために提供された電話番号は、記事で「複雑すぎて気が狂いそうで、状況がシステムのプログラムと異なると容赦がない」と評された自動システムにつながっているとのことだった。さらに、記事は、自動システムが消費者に「信用スコア(信用度評価)や個人情報盗難防止のための監視サービスなどの製品の販売促進を含む、記録された情報の迷路を通り抜けることを強いる」と批判した。[ 18 ] 2012年以降、消費者金融保護局(CFPB)は消費者信用情報機関(CRA)のリストを公開している。これにより、消費者は自分にとって重要な信用情報機関(CRA)を把握でき、リストに掲載されている各CRAの連絡先情報も入手できるため、消費者はより簡単に個人信用情報レポートを注文できます。リストに掲載されているCRAの多くは、消費者に個人信用情報レポートを無料で提供しています。2016年版のリストは、CFPBのウェブサイト(こちら)でご覧いただけます。
レッドフラッグ規則は債権者を広く定義しているため、多くの企業(公益事業会社など)[ 21 ]は、必要のない個人情報(社会保障番号や運転免許証番号など)を収集することが義務付けられています。この方針は、消費者が社会保障番号を企業に開示するのは絶対に必要な場合のみにすべきであるというFTCの消費者への助言に真っ向から反しています。 [ 22 ]レッドフラッグ規則のこの側面は、消費者の社会保障番号を保有する企業の数を増加させるという意図せざる結果をもたらし、それによって消費者はデータ窃盗による個人情報盗難のリスクにさらされることになります。
同法は、加盟店が電子的に印刷されたレシートにクレジットカードやデビットカードの有効期限を含めることを禁止している。2004年に同法が施行されたとき、裁判所には有効期限に関する訴訟が大量に寄せられ、この問題を明示的に検討したすべての連邦巡回裁判所は、関連する集団訴訟の審理を拒否している。2008年、議会はクレジットカードおよびデビットカードのレシート明確化法(明確化法)を可決し、レシートに有効期限を印刷したが、それ以外は同法を遵守していた加盟店は、2008年6月3日まで故意に不遵守したとはみなされないとした。[ 23 ]明確化法において、議会は「この分野の専門家は、有効期限の有無にかかわらず、カード番号を適切に切り捨てるだけで 、潜在的な詐欺師がなりすましやクレジットカード詐欺を行うことを防ぐことができるという点で意見が一致している」と結論付けた。[ 24 ]しかし、裁判所の判決や明確化法にもかかわらず、2008年6月3日以降の領収書の有効期限に関する同法の条文は、ほとんど変更されていない。