Telemarketing Sales Rule

Federal RegisterDec 14, 2015

Ask Donna

What actually matters in this document.

Text

FEDERAL TRADE COMMISSION

16 CFR Part 310

RIN 3084-AB19

Telemarketing Sales Rule

AGENCY:

Federal Trade Commission.

ACTION:

Final rule.

SUMMARY:

In this document, the Commission adopts amendments to the Telemarketing Sales Rule (“TSR” or “Rule”). These amendments define and prohibit the use of certain payment methods in all telemarketing transactions; expand the scope of the advance fee ban for recovery services; and clarify certain provisions of the Rule. The amendments are necessary to protect consumers from deceptive or abusive practices in telemarketing.

DATES:

Effective on February 12, 2016, except for amendatory instructions 4.b., 4.c., 4.d., and 6, which are effective on June 13, 2016.

ADDRESSES:

This document is available on the Internet at the Commission's Web site at

www.ftc.gov

. The complete record of this proceeding, including the final amendments to the TSR and the Statement of Basis and Purpose (“SBP”), is available at

www.ftc.gov

.

FOR FURTHER INFORMATION CONTACT:

Karen S. Hobbs or Craig Tregillus, Attorneys, Division of Marketing Practices, Bureau of Consumer Protection, Federal Trade Commission, 600 Pennsylvania Avenue NW., Room CC-8528, Washington, DC 20580, (202) 326-3587 or 2970.

SUPPLEMENTARY INFORMATION:

This document states the basis and purpose for the Commission's decision to adopt amendments to the TSR that were proposed and published for public comment in the

Federal Register

on July 9, 2013.

1

After careful review and consideration of the entire record on the issues presented in this rulemaking proceeding, including 43 public comments submitted by a variety of interested parties,

2

the Commission has decided to adopt, with several modifications, the proposed amendments to the TSR intended to curb deceptive or abusive practices in telemarketing and improve the effectiveness of the Rule.

1

Telemarketing Sales Rule Notice of Proposed Rulemaking,

78 FR 41200 (July 9, 2013) (hereinafter

NPRM

). The text of the TSR is set forth at 16 CFR part 310. Unless stated otherwise, references to specific provisions of the TSR refer to the current version of the Rule published in the Code of Federal Regulations, revised as of January 1, 2015.

2

All of the public comments are available at

http://ftc.gov/os/comments/tsrantifraudnprm/index.shtm

. In addition, a list of commenters cited in this SBP, along with their short citation names or acronyms used throughout the SBP, is attached as Appendix A. Where a commenter submitted more than one comment, the comment is identified separately.

Beginning on February 12, 2016, sellers and telemarketers will be required to comply with the amended TSR requirements, except for § 310.4(a)(9) and (10), the prohibitions against accepting remotely created payment orders, cash-to-cash money transfers, and cash reload mechanisms, which will be effective on June 13, 2016.

I. Background

A. Overview of the TSR

Enacted in 1994, the Telemarketing and Consumer Fraud and Abuse Prevention Act (“Telemarketing Act” or “Act”)

3

targets deceptive or abusive telemarketing practices.

4

The Act specifically directed the Commission to issue a rule defining and prohibiting deceptive and abusive telemarketing practices.

5

In addition, the Act mandated that the rule address some specified practices, which the Act designated as “abusive.”

6

The Act also authorized state attorneys general or other appropriate state officials, as well as private persons who meet stringent jurisdictional requirements, to bring civil enforcement actions in federal district court.

7

3

15 U.S.C. 6101-6108. Subsequently, the USA PATRIOT Act, Public Law 107-56, 115 Stat. 272 (Oct. 26, 2001), expanded the Telemarketing Act's definition of “telemarketing” to encompass calls soliciting charitable contributions, donations, or gifts of money or any other thing of value.

4

Other statutes enacted by Congress to address telemarketing fraud during the early 1990's include the Telephone Consumer Protection Act of 1991, 47 U.S.C. 227

et seq.,

which restricts the use of automated dialers, bans the sending of unsolicited commercial facsimile transmissions, and directs the Federal Communications Commission (“FCC”) to explore ways to protect residential telephone subscribers' privacy rights; and the Senior Citizens Against Marketing Scams Act of 1994, 18 U.S.C. 2325

et seq.,

which provides for enhanced prison sentences for certain telemarketing-related crimes.

5

15 U.S.C. 6102(a).

6

15 U.S.C. 6102(a)(3).

7

15 U.S.C. 6103, 6104.

Pursuant to the Act's directive, the Commission promulgated the original TSR in 1995 and subsequently amended it in 2003 and again in 2008 and 2010 to add, among other things, provisions establishing the National Do Not Call Registry and addressing the use of pre-recorded messages and debt relief offers.

8

The TSR applies to virtually all “telemarketing,” defined to mean “a plan, program, or campaign which is conducted to induce the purchase of goods or services or a charitable contribution, by use of one or more telephones and which involves more than one interstate telephone call.”

9

The Telemarketing Act, however, explicitly states that the jurisdiction of the Commission in enforcing the Rule is coextensive with its jurisdiction under Section 5 of the Federal Trade Commission Act (“FTC Act”).

10

As a result, some entities and products fall outside the jurisdiction of the TSR.

11

Further, the Rule wholly or partially exempts from its coverage several types of calls.

12

8

Telemarketing Sales Rule Statement of Basis and Purpose and Final Rule,

60 FR 43842 (Aug. 23, 1995) (hereinafter

TSR Final Rule 1995

);

Amended Telemarketing Sales Rule Statement of Basis and Purpose,

68 FR 4580 (Jan. 29, 2003) (hereinafter

TSR Amended Rule 2003

);

Amended Telemarketing Sales Rule Statement of Basis and Purpose,

73 FR 51164 (Aug. 29, 2008) (hereinafter

TSR Amended Rule 2008

);

Amended Telemarketing Sales Rule Statement of Basis and Purpose,

75 FR 48458 (Aug. 10, 2010) (hereinafter

TSR Amended Rule 2010

).

9

16 CFR 310.2(cc) (using the same definition as the Telemarketing Act, 15 U.S.C. 6106).

10

15 U.S.C. 6105(b).

11

15 U.S.C. 45(a)(2) (setting forth certain limitations to the Commission's jurisdiction with regard to its authority to prohibit unfair or deceptive acts or practices). These entities include banks, savings and loan institutions, and certain federal credit unions. It should be noted, however, that although the Commission's jurisdiction is limited with respect to the entities exempted by the FTC Act, the Commission has made clear that the Rule does apply to any third-party telemarketers those entities might use to conduct telemarketing activities on their behalf.

See TSR Proposed Rule,

67 FR 4492, 4497 (Jan. 30, 2002) (citing

TSR Final Rule 1995,

60 FR 43843) (“As the Commission stated when it promulgated the Rule, `[t]he Final Rule does not include special provisions regarding exemptions of parties acting on behalf of exempt organizations; where such a company would be subject to the FTC Act, it would be subject to the Final Rule as well.'”).

12

For example, § 310.6(a) exempts telemarketing calls to induce charitable contributions from the Do Not Call Registry provisions of the Rule, but not from the Rule's other requirements. In addition, there are exceptions to some exemptions that limit their reach.

See, e.g.,

16 CFR 310.6(b)(5)-(6).

The TSR is fundamentally an anti-fraud rule that protects consumers from deceptive and abusive telemarketing practices. First, the Rule requires telemarketers to make certain disclosures to consumers, and it prohibits material misrepresentations.

13

Second, the TSR requires telemarketers

to obtain consumers' “express informed consent” to be charged on a particular account before billing or collecting payment and, through a specified process, to obtain consumers' “express verifiable authorization” to be billed through any payment system other than a credit or debit card.

14

Third, the Rule prohibits telemarketers and sellers from requesting or receiving payment in advance of obtaining: credit repair services;

15

recovery services;

16

offers of a loan or other extension of credit, the granting of which is represented as “guaranteed” or having a high likelihood of success;

17

and debt relief services.

18

Fourth, the Rule prohibits credit card laundering

19

and other forms of assisting and facilitating sellers or telemarketers engaged in violations of the TSR.

20

13

The TSR requires that telemarketers soliciting sales of goods or services promptly disclose several key pieces of information: (1) The identity of the seller; (2) the fact that the purpose of the call is to sell goods or services; (3) the nature of the goods or services being offered; and (4) in the case of prize promotions, that no purchase or payment is necessary to win. 16 CFR 310.4(d). Telemarketers also must disclose, in any telephone sales call, the cost of the goods or services and certain other material information. 16 CFR 310.3(a)(1).

In addition, the TSR prohibits misrepresentations about, among other things, the cost and quantity of the offered goods or services. 16 CFR 310.3(a)(2). It also prohibits making false or misleading statements to induce any person to pay for goods or services or to induce charitable contributions. 16 CFR 310.3(a)(4).

14

16 CFR 310.4(a)(7); 16 CFR 310.3(a)(3).

15

16 CFR 310.4(a)(2).

16

16 CFR 310.4(a)(3).

17

16 CFR 310.4(a)(4).

18

16 CFR 310.4(a)(5).

19

16 CFR 310.3(c).

20

16 CFR 310.3(b).

The TSR also protects consumers from unwanted telephone calls. With narrow exceptions, it prohibits telemarketers from calling consumers whose numbers are on the National Do Not Call Registry or who have specifically requested not to receive calls from a particular entity.

21

Finally, the TSR requires that telemarketers transmit to consumers' telephones accurate Caller ID information

22

and places restrictions on calls made by predictive dialers

23

and those delivering pre-recorded messages.

24

21

16 CFR 310.4(b).

22

16 CFR 310.4(a)(8).

23

16 CFR 310.4(b)(1)(iv).

24

16 CFR 310.4(b)(1)(v).

B. Overview of the Proposal To Amend the TSR

On July 9, 2013, the Commission proposed to amend the TSR to enhance its anti-fraud protections, as well as to clarify amendments that apply primarily, though not exclusively, to the provisions restricting unwanted calls. The Commission's Notice of Proposed Rulemaking (“NPRM”) detailed the proposed amendments to the TSR (“proposed Rule”). The subsections I.B.1 and I.B.2 below describe the Commission's proposal with respect to its anti-fraud amendments, which would:

1. Define and prohibit the use of four types of payment methods by telemarketers and sellers: “remotely created check,” “remotely created payment order,” “cash-to-cash money transfer,” and “cash reload mechanism.”

2. Expand the prohibition against advanced fees for recovery services (now limited to recovery of losses sustained in prior telemarketing transactions) to include recovery of losses in any previous transaction.

Section II sets forth the Commission's analysis of the comments received on the proposal, any modifications to the proposed language, and reasons for adopting the provisions of the Final Rule.

The clarifying amendments, discussed in Section III, serve three main functions. First, they specify that a description of the goods or services purchased must be included in the verification recording of a consumer's agreement to purchase them. Second, they clarify that the business-to-business exemption extends only to calls to induce a sale to or contribution from a business entity, and not to calls to induce sales to or contributions from individuals employed by the business. Finally, these amendments address the TSR's Do Not Call requirements to:

• State expressly that a seller or telemarketer bears the burden of demonstrating that the seller has an existing business relationship with, or has obtained an express written agreement from, a person whose number is listed on the Do Not Call Registry;

• Illustrate the types of impermissible burdens that deny or interfere with a consumer's right to be placed on a seller's or telemarketer's entity-specific do-not-call list;

• Specify that a seller's or telemarketer's failure to obtain the information necessary to honor a consumer's request to be placed on a seller's entity-specific do-not-call list pursuant to § 310.4(b)(1)(ii) disqualifies it from relying on the safe harbor for isolated or inadvertent violations in § 310.4(b)(3); and

• Emphasize that the prohibition against sellers sharing the cost of Do Not Call Registry fees, which are non-transferrable, is absolute.

1. Proposed Prohibition on Novel Payment Methods in Telemarketing

The NPRM proposed to prohibit the use of four types of “novel payment methods” in telemarketing, namely: Remotely created checks, remotely created payment orders, cash-to-cash money transfers, and cash reload mechanisms.

25

The Commission distinguishes these four payment methods from “conventional payment methods,” such as credit cards, and electronic fund transfers, such as debit cards. The conventional payment methods are processed or cleared electronically through networks that can be monitored systematically for fraud. Further enhancing the security of conventional payment methods is the fact that they are subject to federal laws that provide statutory limitations on a consumer's liability for unauthorized transactions and standard procedures for resolving errors. The NPRM contrasted and compared the features and vulnerabilities of the four types of novel payment methods, especially when used in telemarketing.

26

25

NPRM, supra

note 1, at 41200.

26

Id.

at 41202-07.

a. Remotely Created Checks and Remotely Created Payment Orders

Traditional checks require the signature of the account holder and instruct a financial institution to pay money from the account of the check writer (“payor”) to the check recipient (“payee”). As originally defined in the NPRM, a remotely created check (“RCC”) is a type of check which is created by the payee (typically a merchant, seller, or telemarketer) using the consumer's personal and financial account information and which is not actually signed by the payor.

27

In place of the payor's actual signature, the remotely created check usually bears a statement indicating that the account holder authorized the check, such as “Authorized by Account Holder” or “Signature Not Required.” A remotely created check is deposited into the check clearing system like any other check. As defined in the NPRM, a remotely created payment order (“RCPO”) is an electronic version of a remotely created check. The electronic image looks and functions like a remotely created check, but it never exists in paper form. Using remote deposit capture—a system that allows a depositor to scan checks remotely and transmit the check images to a bank for deposit—a merchant, seller, or telemarketer can deposit a remotely created payment order into the check clearing system in the same way as

traditional paper checks and remotely created checks.

27

For the reasons raised by certain commenters, and discussed in detail in Section II.A.4 below, the Final Rule adopts a revised definition of “remotely created payment order” that deletes the reference to the absence of the payor's signature and eliminates the need for a separate definition of “remotely created check.” The revised definition of “remotely created payment order” includes any payment instruction or order drawn on a person's account that is created by the payee and deposited into or cleared through the check clearing system. The definition is broad enough to include a “remotely created check,” as defined in Regulation CC.

Electronic payment alternatives to remotely created checks and remotely created payment orders include conventional payment methods, such as Automated Clearinghouse (“ACH”)

28

debits and traditional debit card transactions—both of which involve consumer bank accounts—as well as credit card transactions.

29

These alternatives are processed through different payment networks. Payment methods cleared through the ACH network are subject to regular oversight and scrutiny by NACHA—The Electronic Payments Association (“NACHA”), a private self-regulatory trade association that enforces a system of rules, monitoring, and penalties for noncompliance. Among other things, NACHA monitors the levels at which all ACH debits are returned (or rejected) by consumers or consumers' banks because high rates of returned transactions (“return rates”) can be indicative of unlawful practices, such as unauthorized debiting of consumer accounts. NACHA also monitors and categorizes specific types of returned transactions, based on the reason for the return, such as “unauthorized,” “non-sufficient funds,” or “invalid account numbers.” For many years, NACHA's rules have required banks to report and investigate any merchant with a monthly return rate of 1 percent or more for returns categorized as unauthorized,

30

a threshold that NACHA recently reduced to 0.5 percent.

31

28

ACH transactions are electronic payment instructions to either credit or debit a bank account. ACH credit transactions push funds into an account, while ACH debit transactions pull funds from an account. NACHA,

What is ACH?: Quick Facts About the Automated Clearing House (ACH) Network

(Jul. 1, 2013),

available at https://www.nacha.org/news/what-ach-quick-facts-about-automated-clearing-house-ach-network

. ACH credits include payroll direct deposits, Social Security benefits, and interest payments. Examples of ACH debit transactions include mortgage, loan, and insurance premium payments. FFIEC,

Bank Secrecy Act/Anti-Money Laundering Examination Manual, Automated Clearing House Transactions—Overview

217 (Feb. 27, 2015),

available at http://www.ffiec.gov/bsa_aml_infobase/pages_manual/olm_059.htm

.

29

Unlike most general-purpose reloadable cards and other prepaid cards, traditional debit cards (also referred to as “check cards”) are linked to consumer checking accounts at a financial institution.

See infra

notes 176-178; Electronic Funds Transfer Act (“EFTA”), 15 U.S.C. 1693; Regulation E, 12 CFR part 1005.

30

NACHA, 2013 Operating Rules, Art. 2, Subsection 2.17.2.1, Additional ODFI Action and Reporting When the Return Threshold is Exceeded (Mar. 15, 2013) (describing the actions that originating financial institutions (“ODFIs”) must take when an originator's unauthorized return rate exceeds 1 percent).

31

In September 2015, amendments to NACHA's Operating Rules will take effect. Among other things, these amendments reduce the threshold for unauthorized returns from one percent to 0.5 percent. Press Release, NACHA,

NACHA Membership Approves New Rules to Further Improve ACH Network Quality

(Aug. 26, 2014),

available at https://www.nacha.org/rules/updates

. NACHA also adopted new monthly return rate thresholds for other types of ACH debit returns, including a three percent threshold for returns based on “account data issues” (

i.e.,

debits returned for invalid account numbers or an inability to locate the account) and a total return rate of 15 percent.

Likewise, the payment card networks, such as American Express, Discover, MasterCard, and Visa, impose on participants (

e.g.,

merchants, banks, and third party payment processors) a system of rules, monitoring, and penalties for noncompliance. Transactions processed through the payment card networks, including certain types of debit and general-purpose reloadable debit card (“GPR card”) transactions, are subject to systemic monitoring to identify unusual activity associated with fraud.

32

Among other things, payment card networks monitor whether a merchant's monthly number of chargebacks

33

and chargeback rate (

i.e.,

the percentage of transactions that are “charged back” out of the total number of sales transactions submitted by a specific merchant) exceed certain parameters—for example, 100 chargebacks and a 1 percent chargeback rate in a given month.

34

32

Network-branded debit cards and GPR cards can be used like credit cards to make purchases at a variety of stores, online, or over the telephone. These so-called “signature” debit card purchases (

i.e.,

without the use of a PIN) are processed through and, thus, subject to the operating rules and anti-fraud monitoring of the payment card networks.

33

“Chargeback” is a payments industry term used to describe the process through which a disputed charge to a consumer's credit card is refunded to the consumer and charged back to the entity, often a merchant, that placed the charge on the consumer's account.

See NPRM, supra

note 1, at 41203 & nn.47-48.

34

For example, Visa's operating rules state:

Visa monitors the total volume of US Domestic Interchange, International Interchange, and Chargebacks for a single Merchant Outlet and identifies US Merchants that experience all of the following activity levels during any month:

• 100 or more interchange transactions

• 100 or more Chargebacks

• A 1% or higher ratio of overall Chargeback-to-Interchange volume

Visa, U.S.A,

Visa Core Rules and Visa Product Service Rules,

500 (Apr. 15, 2015),

available at https://usa.visa.com/dam/VCOM/download/about-visa/15-April-2015-Visa-Rules-Public.pdf

. MasterCard maintains similar, but not identical, thresholds for its excessive chargeback monitoring programs (at least 100 chargebacks and a chargeback ratio of 1.5 percent). MasterCard,

Security Rules and Procedures—Merchant Edition,

54 (Feb. 5, 2015),

available at http://www.mastercard.com/us/merchant/pdf/SPME-Entire_Manual_public.pdf

.

In contrast to the transactions processed by the ACH and payment card networks, remotely created checks and remotely created payment orders are not subject to such centralized and systemic monitoring. This is due to the decentralized nature of the check clearing system and the inability of banks to distinguish these items from other checks deposited for clearing.

35

35

NPRM, supra

note 1, at 41206-07.

In addition to these operational differences between conventional and novel payment mechanisms, different laws govern each type of payment. As described in detail in section II.A.3.a(3) below, electronic fund transfers such as ACH debits and traditional debit card transactions are governed by Regulation E and the EFTA, which provide consumers with specific rights, including liability limits for unauthorized transactions, the right to a prompt re-credit of funds, specified deadlines for completing investigations of unauthorized transactions, and the right to notification of the results of such investigations.

36

Under Regulation E and the EFTA, the financial institution has the burden of proof for showing the transaction was “authorized” or “unauthorized.”

37

For ACH transactions, consumers also benefit from NACHA's systemic oversight and enforcement of operating rules governing participants in the ACH Network.

38

36

See infra

notes 176-178; EFTA, 15 U.S.C. 1693; Regulation E, 12 CFR part 1005. With certain exceptions, most GPR cards are not subject to the EFTA or Regulation E. However, payment card networks voluntarily extend their same zero liability protection to GPR purchases as they apply to credit and traditional debit cards processed through their networks. Federal Reserve Bank of Atlanta, Retail Payments Risk Forum,

Dispelling prepaid card myths: Not all cards are created equal

(July 5, 2011),

available at http://portalsandrails.frbatlanta.org/2011/07/dispelling-prepaid-card-myths-not-all-cards-created-equal.html; see also infra

note 178. The CFPB recently published a proposed rule that would extend to “prepaid accounts,” including GPR cards, the protections of Regulation E and the EFTA, with certain important modifications.

Notice of Proposed Rulemaking Prepaid Accounts Under the Electronic Fund Transfer Act (Regulation E) and the Truth in Lending Act (Regulation Z)

(hereinafter “Prepaid Account Rule”), 79 FR 77102 (Dec. 23, 2014). At this time, the CFPB has not taken further action on the proposal.

37

15 U.S.C. 1693g.

38

See supra

notes 30-31.

Credit card transactions also are governed by federal law—Regulation Z and the Truth in Lending Act (“TILA”).

39

This regulation provides protections for consumers using credit cards that are similar to, but more robust than, those for ACH debits under EFTA

and Regulation E. These rights include error and dispute resolution rights, as well as limited liability for unauthorized transactions. In addition, consumers are protected by the operators of the payment card networks that enforce compliance with operating rules designed to detect and deter fraud.

40

39

See infra

notes 172-173 and accompanying text; TILA, 15 U.S.C. 1601

et seq.;

Regulation Z, 12 CFR part 1026.

40

See supra

notes 32-34 and accompanying text.

In contrast, remotely created checks are governed principally by Articles 3 and 4 of the Uniform Commercial Code (“UCC”), a series of state laws applicable to negotiable instruments and commercial contracts.

41

As described in section II.A.3.a(3) below, the UCC provides that consumers are not liable for a check unless it is “properly payable.”

42

Unlike the defined rights of consumers under Regulation E and the EFTA, however, provisions of the UCC applicable to unauthorized checks (including remotely created checks) do not set forth specific timeframes for investigations and provide no right to the re-credit of funds during a bank's investigation. Moreover, the permissible timeframe for consumers to report unauthorized checks, and many other provisions of the UCC, can be varied by agreement or contract. These variations often appear in the fine print of take-it-or-leave-it bank deposit agreements.

43

Technically, the UCC does not cover remotely created payment orders. As a practical matter, however, banks process remotely created payment orders the same as remotely created checks because they cannot distinguish between the two during the check clearing process.

41

Currently, the UCC (in whole or in part) has been enacted, with some local variation, in all 50 states, the District of Columbia, Puerto Rico, and the Virgin Islands.

42

UCC 4-401 cmt. 1 (“An item is properly payable from a customer's account if the customer has authorized the payment and the payment does not violate any agreement that may exist between the bank and its customer.”).

43

See infra

note 189 (citing bank deposit agreements shortening timeframe to 14 days).

Unscrupulous telemarketers use remotely created checks and remotely created payment orders to exploit vulnerabilities in the check clearing system, enabling them to siphon “hundreds of millions of dollars” in telemarketing transactions from consumers' bank accounts.

44

In past TSR rulemaking proceedings, the Commission was concerned with providing protection in telemarketing transactions “when consumers are unaware that they may be billed via a particular method, when that method lacks legal protection against unlimited unauthorized charges, and when the method fails to provide dispute resolution rights,” as with novel payment methods like remotely created checks and payment orders.

45

In response to the original TSR rulemaking proceedings in which the Commission proposed to prohibit remotely created checks by requiring written authorization, the Commission received numerous, detailed comments from representatives of the automated payments industry and businesses demonstrating the widespread use of remotely created checks by legitimate telemarketers and sellers, as well as the lack of effective payment alternatives.

46

Based on the 1995 rulemaking record, the Commission revised its proposal and adopted the basic “express verifiable authorization” requirement for transactions involving such payment methods in § 310.3(a)(3).

47

In the most recent NPRM, however, the Commission amassed evidence from its own enforcement actions, and those of other federal and state agencies, demonstrating that the express verifiable authorization requirement is manifestly ineffective at preventing massive consumer losses in fraudulent telemarketing transactions involving remotely created checks and remotely created payment orders. The NPRM accordingly proposed to prohibit the use of these payment methods in telemarketing transactions.

44

NPRM, supra

note 1, at 41202 (citing injury estimates from law enforcement cases).

45

TSR Final Rule 2003, supra

note 8, at 4606.

46

TSR Final Rule 1995, supra

note 8, at 43850 & n.80 (noting examples of businesses, such as “two of the baby Bells, GEICO, Citicorp, Telecheck, Equifax, Bank of America, Discovery Card, Dunn and Bradstreet, and First of America Bank.”);

see also TSR Revised Notice of Proposed Rulemaking,

60 FR 30406, 30413 (June 8, 1995) (hereinafter

TSR RNPRM

).

47

TSR Final Rule 1995, supra

note 8, at 43850-51. Under § 310.3(a)(3), a consumer's authorization is considered verifiable if it is obtained in one of three ways: Advance written authorization signed by the consumer; an audio recording of the consumer giving express oral authorization; or written confirmation of the transaction mailed to the consumer before submitting the charge for payment.

b. Cash-to-Cash Money Transfers and Cash Reload Mechanisms

Money transfer providers enable individuals to send (or “remit”) money quickly and conveniently to distant friends and family, using a network of agents in various locations in the U.S. and abroad. As used in the NPRM and this Statement of Basis and Purpose (“SBP”), the term “cash-to-cash money transfer” describes a specific type of money transfer in which a consumer brings cash or currency to a money transfer provider that transfers the value to another person who can pick up cash in person.

As the NPRM described, the perpetrators of telemarketing scams frequently instruct consumers to use cash-to-cash money transfers because this method of payment is a fast way to anonymously and irrevocably extract money from the victims of fraud. Once a cash-to-cash money transfer is picked up, there is no recourse for the consumer to obtain a refund after the fraud is discovered. Cash-to-cash transfers to locations outside of the U.S. are governed by the Remittance Transfer Rule (“Remittance Rule”), part of the EFTA and Regulation E. Among other things, the Remittance Rule mandates disclosures to customers of money transfer providers, error resolution for mistakes, limited cancellation rights, and other protections.

48

However, the Remittance Rule provides no similar rights for consumers using other types of cash-to-cash transfers.

48

15 U.S.C. 1693

o

-1; 12 CFR part 1005, subpart B (effective October 28, 2013);

NPRM, supra

note 1, at 41211 & n.129.

Cash reload mechanisms are similarly problematic. Cash reload mechanisms act as a virtual deposit slip for consumers to load funds onto a GPR card without a bank intermediary. A consumer simply pays cash, plus a small fee, to a retailer that sells cash reload mechanisms, such as MoneyPaks, Vanilla Reloads, or Reloadit packs. In exchange, the consumer receives a unique access or personal identification number (“PIN”) authorization code. The consumer can use the PIN code over the telephone or Internet to transfer the funds onto any existing GPR card within the same prepaid network, apply the funds to a “digital wallet” with a payment intermediary (

e.g.,

PayPal), or pay a utility or other bill owed to an approved partner of the cash reload mechanism provider.

49

Perpetrators of telemarketing scams increasingly are instructing consumers to pay with a cash reload mechanism that the perpetrator can quickly use to offload the funds onto their own prepaid cards and thereby anonymously and irrevocably extract money from victims. As with a cash-to-cash money transfer,

once a cash reload mechanism is transmitted to an anonymous con artist, the money is gone and cannot be recovered. In response to concerns about the misuse of its cash reload mechanism by perpetrators of fraud, Green Dot Corporation (“Green Dot”) announced it would discontinue its MoneyPak cash reload mechanism in favor of a swipe-reload process—where a consumer presents her existing GPR card at the register and loads funds directly to the card.

50

The providers of two other cash reload mechanisms, Vanilla Reload Network and Reloadit, have made similar announcements.

51

49

For reasons discussed in section II.B.3.c below, legitimate merchants and billers typically do not accept cash reload mechanisms directly from consumers. Instead, merchants and most billers accept as payment the GPR card itself. In the past, Green Dot Corporation permitted certain approved billing partners to accept its MoneyPak cash reload mechanisms directly from customers. Unlike perpetrators of telemarketing fraud, however, these approved billers did not use the PIN-based cash reload mechanisms to add the funds onto existing GPR cards.

See infra

note 414 and accompanying text (describing the operation of MoneyPak and other cash reload mechanisms).

50

Written Statement of Green Dot Corporation For U.S. Senate Special Committee on Aging Hearing “Hanging Up on Phone Scams: Progress and Potential Solutions to this Scourge,” 2 (July 16, 2014) (hereinafter “Written Statement of Green Dot”),

available at http://www.aging.senate.gov/imo/media/doc/Green_Dot_7_16_14.pdf. See infra

section II.B for a detailed discussion.

51

Press Release, InComm,

InComm Expands Vanilla Reload Network, Plans to Add Swipe Reload at Over 15,000 More Retail Locations: InComm removes reload packs from stores to help prevent victim assisted fraud

(Oct. 24, 2014) (hereinafter “InComm Press Release”),

available at http://www.incomm.com/news-events/Pages/Press%20Releases/InComm-Expands-Vanilla-Reload-Network-Plans-to-Add-Swipe-Reload-to-Over-15000-More-Retail-Locations.aspx

; Testimony of William Tauscher Chairman and Chief Executive Officer Blackhawk Network Holdings, Inc. Before United States Senate Special Committee on Aging Hearing “Private Industry's Role in Stemming the Tide of Phone Scams,” at 3 (Nov. 19, 2014) (hereinafter “Testimony of Blackhawk Network”),

available at http://www.aging.senate.gov/imo/media/doc/Tauscher_11_19_14.pdf

(describing Blackhawk's “elimination of quick load with the scratch-off PIN” for its Reloadit Pack product).

Like remotely created checks and payment orders, cash-to-cash money transfers and cash reload mechanisms are categorized herein as “novel” telemarketing payment methods because they lack the same error resolution rights and liability limits provided by the TILA and Regulation Z (for credit card payments) or the EFTA and Regulation E (for electronic fund transfers, ACH debits, and traditional debit card transactions). Thus, the use of cash-to-cash money transfers and cash reload mechanisms expose consumers to the risk of unrecoverable losses from telemarketing fraud. Because it appeared from the Commission's law enforcement experience that all these novel payment methods are used almost exclusively by perpetrators of telemarketing fraud, who typically ignore the TSR's “express verifiable authorization” requirement, the NPRM proposed to prohibit their use in all telemarketing transactions.

2. Proposed Expansion of Prohibition on Telemarketing Recovery Services

Telemarketers pitching “recovery services” contact victims of prior scams promising to recover the money they lost or the prize or merchandise they never received, in exchange for a fee paid in advance. Once the fee is paid, consumers rarely receive any benefit from the promised recovery services. To protect consumers from this abusive practice, § 310.4(a)(3) of the TSR prohibits any telemarketer or seller from requesting or receiving payment for recovery services for losses in a previous telemarketing transaction “until seven (7) business days after such money or other item is delivered to that person.” The Commission is eliminating the requirement that the prior loss was the result of a telemarketing transaction. This will ensure that consumers who have incurred fraud losses in non-telemarketing transactions receive the same protection against recovery services fraud.

3. Other Proposed Clarifying Amendments

The NPRM also proposed a number of technical amendments to the TSR that are designed to clarify existing provisions, as noted in the introduction. They are discussed fully in section III.

C. Overview of Comments Received in Response to the NPRM

In response to the NPRM, the Commission received more than 40 comments representing the views of state and federal agencies,

52

consumer groups,

53

consumers,

54

industry trade associations,

55

businesses,

56

a U.S. Senator;

57

and an academic.

58

The commenters generally supported the Commission's efforts to combat telemarketing fraud and enforce the existing provisions of the TSR. The vast majority of commenters discussed the amendments to prohibit the use of novel payment methods in telemarketing transactions. Most financial services industry and business commenters opposed all or part of the amendments curtailing novel payment methods. Law enforcement and regulators, consumer advocates, and individual consumers expressed support for the amendments, with some commenters urging the Commission to expand the prohibitions to other industries and marketing methods. Several commenters expressed their views on the amendments to the recovery services, express verifiable consent, or Do Not Call related provisions of the Rule. The comments and the basis for the Commission's adoption or rejection of the commenters' suggested modifications to the proposed amendments are analyzed in detail in sections II and III below.

52

N.J. Acting Att'y Gen. and Vt. Att'y Gen.'s Office (on behalf of 24 states and the District of Columbia) (collectively, “AGO”); Consumer Fin. Prot. Bureau (“CFPB”); Consumer Prot. Branch, U.S. Dep't of Justice (“DOJ-CPB”); Criminal Div., U.S. Dep't of Justice (“DOJ-Criminal”); and Fed. Reserve Bank of Atlanta (“FRBA”).

53

AARP; Ams. for Fin. Reform (“AFR”) (on behalf of itself and Arkansans against Abusive Payday Lending; Chicago Consumer Coal.; Consumer Action; Consumer Fed'n of Am.; Consumers Union, the Advocacy and Policy Arm of Consumer Reports; Maryland Consumer Rights Coal.; Nat'l Consumer Law Ctr.; National Ass'n of Consumer Advocates; Pub. Citizen; Pub. Justice Ctr.; Florida Consumer Action Network; U.S. PIRG; and Utah Coal. of Religious Cmtys.); and the Nat'l Consumer Law Ctr. (“NCLC”) (on behalf of its low-income clients and the Ctr. For Responsible Lending; Consumer Action; Consumer Fed'n of Am.; Consumers Union, the Advocacy and Policy Arm of Consumer Reports; Nat'l Ass'n of Consumer Advocates; the Nat'l Consumers League; and U.S. PIRG).

54

Three supported all or part of the proposed amendments: Michalik, Cordero, and Frankfield. Five did not specifically address the proposed amendments: Burden, Bailey-Waddell, Manness, Seaman, and Farrington.

55

Amer. Bankers Ass'n (“ABA”); The Clearing House and Fin. Servs. Roundtable (“The Associations”); Credit Union Nat'l Ass'n. (“CUNA”); Elec. Check Clearing House Org. (“ECCHO”); Elec. Transactions Ass'n. (“ETA”); NACHA—The Elec. Payments Ass'n. (“NACHA”); The Money Servs. Roundtable (“TMSRT”); and Nat'l Ass'n. of Fed. Credit Unions (“NAFCU”).

56

Blue Diamond Remodeling, Inc. (“Blue Diamond”); DCS Holdings Group, LLC (“DCS Holdings”); G3 Assocs.; Green Dot Corp. (“Green Dot”); InfoCision Mgmt. Corp. (“InfoCision”); Interactive Commc'ns Int'l, Inc. (“InComm”); Michael; NetSpend; PPA—Biondi; PPA—Frank; Samuel (“First Data”); Thayer Gate Advisors (“Thayer”); and Transp. FCU.

57

The Hon. Bill Nelson.

58

Prof. Sarah Jane Hughes (“Hughes”).

II. Final Amended Rule Pertaining to the Anti-Fraud Amendments

The Commission has carefully reviewed and analyzed the entire record developed in this proceeding.

59

The record, as well as the Commission's own law enforcement experience and that of its state and federal counterparts, supports the Commission's view that the anti-fraud amendments to the TSR are necessary and appropriate to protect consumers from significant financial harm.

60

In some instances, the Commission has made modifications to its original proposal. The Final Rule

addresses deceptive and abusive practices in telemarketing by:

59

The record includes the NPRM, and the law enforcement cases and experience referenced therein, which are hereby incorporated by reference.

60

The Commission's decision to amend the Rule is made pursuant to the rulemaking authority granted by the Telemarketing Act to protect consumers from deceptive and abusive practices. 15 U.S.C. 6102(a)(1) and (a)(3).

• Prohibiting the use of remotely created payment orders in outbound and inbound telemarketing transactions;

○ Adopting a modified definition of the term “remotely created payment order” that broadly includes checks (including “remotely created checks”) and payments that are: (1) Created by the payee; and (2) sent through the check clearing system;

○ Eliminating the proposed definition of the term “remotely created check;”

• Prohibiting the use of cash-to-cash money transfers and cash reload mechanisms in outbound and inbound telemarketing transactions;

○ Adopting the proposed definition of “cash-to-cash money transfer;”

○ Adopting a revised definition of the term “cash reload mechanism” to clarify the exclusion of swipe reload methods of loading funds to GPR cards; and

• Expanding the advance fee ban on recovery services to include recovery of losses incurred in previous telemarketing and non-telemarketing transactions.

A. Final Rule and Comments Received on Remotely Created Checks and Remotely Created Payment Orders

Based on its review of the entire record, the Commission concludes that the use of remotely created checks and remotely created payment orders in telemarketing is an abusive practice. In reaching this conclusion, the Commission has applied the unfairness analysis set forth in Section 5(n) of the FTC Act,

61

finding that this practice causes or is likely to cause substantial injury to consumers that is not outweighed by countervailing benefits to consumers or competition and is not reasonably avoidable.

62

In the following sections, the Commission separately: (1) Reviews comments supporting the prohibition against each of the two novel payment methods, (2) reviews comments opposing the prohibition against each of them, (3) sets forth its legal analysis, and (4) describes the operation of the amended provisions, and related definitions, in the Final Rule.

61

The Telemarketing Act authorizes the Commission to promulgate Rules “prohibiting deceptive telemarketing acts or practices and other abusive telemarketing acts or practices.” 15 U.S.C. 6102(a)(1). In determining whether a practice is “abusive,” the Commission has used the Section 5(n) unfairness standard where appropriate.

See TSR Amended Rule 2003, supra

note 8, at 4614.

62

See

15 U.S.C. 45(n) (codifying the Commission's unfairness analysis, set forth in a letter from the FTC to Hon. Wendell Ford and Hon. John Danforth, Committee on Commerce, Science and Transportation, United States Senate, Commission Statement of Policy on the Scope of Consumer Unfairness Jurisdiction,

reprinted in In re Int'l Harvester Co.,

104 F.T.C. 949, 95-101 (1984)) (hereinafter “Unfairness Policy Statement”).

1. Comments Supporting the Prohibition on Remotely Created Checks and Remotely Created Payment Orders

Numerous commenters, including members of the financial services industry, a federal credit union, small businesses, an academic, consumer advocacy groups, individual consumers, staff from federal agencies, and Offices of Attorneys General in 24 states and the District of Columbia supported the prohibition on the use of remotely created checks and remotely created payment orders in telemarketing transactions.

63

Commenters expressed support for every aspect of the Commission's proposal, specifically described reasons why it is necessary and appropriate, and some suggested that the Commission's proposal should be applied to non-telemarketing transactions.

63

The states are: Arizona, Arkansas, Delaware, Hawaii, Illinois, Iowa, Kentucky, Louisiana, Maine, Maryland, Massachusetts, Minnesota, Mississippi, Nevada, New Hampshire, New Jersey (joined via separate comment letter), New Mexico, Oregon, Pennsylvania, Rhode Island, Tennessee, Utah, Vermont, and Washington. AGO at 1.

In general, commenters in support of the prohibition argued that these payment methods are highly susceptible to fraud in telemarketing and cause significant harm to consumers in the form of unauthorized and fraudulent withdrawals from their financial accounts.

64

Commenters agreed that perpetrators of fraud frequently use remotely created checks and remotely created payment orders to extract money from consumer victims and inflict significant harm.

65

One small business owner suggested that businesses should never receive direct access to a consumer's account, describing it as “a perfect scenario for fraud and other deceitful actions to occur.”

66

The DOJ-CPB stated that a prohibition on remotely created checks and remotely created payment orders and other novel payment methods “would prevent hundreds of millions of dollars in consumer loss each year while, at the same time, leaving open safer mechanisms for legitimate marketers to accept consumer payments.”

67

In addition, the DOJ-CPB noted, “[t]he serious risks posed by RCCs are well documented in and outside of the FTC's [NPRM],” including in guidance documents published by bank regulators and public comments filed in other rulemaking proceedings.

68

64

DOJ-CPB at 2; AFR at 1; AARP at 3; AGO at 11; CFPB at 1; NCLC at 2-3; DOJ-Criminal at 3; Transp. FCU.

65

AARP at 3; AGO at 11 (reaffirming the views expressed by the Attorneys General of 34 states, the District of Columbia, and American Samoa in 2005 comment letter filed by National Association of Attorneys General, Proposed Amendment to Regulation CC Remotely Created Checks, FRB Docket No. R-1226 (May 9, 2005),

available at http://www.federalreserve.gov/SECRS/2005/May/20050512/R-1226/R-1226_264_1.pdf

); NACHA at 1; NCLC at 1, 5; Michael; DOJ-CPB at 1-2; DOJ-Criminal at 1& 3.

66

Michael.

67

DOJ-CPB at 1.

68

Id.

at 2 (citing Financial Crimes Enforcement Network, Advisory FIN-2012-A010, Risk Associated with Third-Party Payment Processors (Oct. 22, 2012); NACHA, Remotely Created Checks and ACH Transactions: Analyzing the Differentiators (March 2010); FFIEC, Bank Secrecy Act Anti-Money Laundering Examination Manual: Third-Party Payment Processors B Overview (2010); Federal Reserve Bank of Atlanta, 2008 Risk & Fraud in Retail Payments: Detection & Mitigation Conference Summary (Oct. 6-7, 2008); Public Comment filed with the Federal Reserve by the National Association of Attorneys General, the National Consumer Law Center, Consumer Federation of America, Consumers Union, the National Association of Consumer Advocates, and U.S. Public Interest Research Group in Docket No. R-1226 (May 9, 2005)).

Several commenters emphasized that consumers who provide their account numbers to a telemarketer have no effective control over how that payment is processed, little understanding of the different levels of protection afforded different types of payments, and no realization that the information they provide can be used to initiate additional unauthorized debits.

69

Many commenters pointed out how the consumer protections for remotely created checks and remotely created payment orders are less robust and more burdensome for consumers than those provided for credit cards and ACH debits.

70

Commenters also explained how protections for consumers whose accounts are debited via remotely created checks and remotely created payment orders are further diminished due to the lack of a systemic, centralized monitoring and identification of these payment types in the check clearing system.

71

Many commenters described

how a telemarketer's choice to use a consumer's bank account information to create a remotely created check, instead of originating an ACH debit or accepting a payment card, determines the level of scrutiny and monitoring applied to the transaction and the telemarketer or seller.

72

These commenters pointed out that telemarketers and sellers using remotely created checks and remotely created payment orders are often deliberately exploiting these regulatory and operational weaknesses to escape the heightened scrutiny and monitoring of the ACH and payment card networks.

69

AGO at 11 (citing a “lack of consumer awareness of how strangers can debit their bank accounts without authorization”); Trans. FCU (noting that consumers do not realize their account information “can easily be used to generate additional unauthorized payments”); NCLC at 6 (“Consumers cannot protect themselves from the dangers of RCCs and RCPOs”); Michael.

70

AGO at 11 (noting “the hurdles that consumers often encounter in trying to obtain a recredit to their bank account when—if at all—they discover an unauthorized debit”); NCLC at 4-5 (noting that “the use of RCCs and RCPOs is popular for scammers because the consumer protections are weak and poorly enforced . . .” and explaining how RCCs and RCPOs can make it difficult for consumers to initiate stop payment orders).

71

AGO at 11 (highlighting “the difficulty, if not impossibility, of tracking remotely created checks”);

NACHA at 3 (“RCCs are difficult, if not impossible, for individual financial institutions to monitor as a class”); NCLC at 9 (“a systemic monitoring system is lacking for the check system.”).

72

AFR at 1 (“RCCs and RCPOs are heavily used by scammers and others who wish to avoid the consumer protections and fraud prevention mechanisms associated with modern electronic payment devices”); DOJ-CPB at 2 (“we have seen third party payment processors that promote their use of RCCs as a means to process transactions for merchants that have been blacklisted from credit card and ACH transactions”); Trans. FCU (“[w]e have seen these types of payment mechanisms used by scammers, often targeting elderly or financially distressed members”); NACHA at 3 (“Because RCCs are not monitored systemically . . . fraudsters are able to use RCCs to evade the authorization requirements and strong protections that NACHA has implemented through the ACH system”); NCLC at 6 (“RCCs and RCPOs are also used by entities who wish to escape scrutiny by the systems used to detect fraud in other payment systems.”).

Virtually all of the commenters in support of the prohibition focused on the harm inflicted on consumers when unauthorized and fraudulent debits are withdrawn using remotely created checks and remotely created payment orders.

73

Commenters opined that the legitimate use of remotely created checks and payment orders in telemarketing transactions, if any, is significantly outweighed by the considerable evidence of harm inflicted on consumers.

74

Citing the existence of safer modern alternatives to remotely created checks and remotely created payment orders in telemarketing transactions, such as debit cards and ACH debits, commenters argued that the reasons to prohibit their use are even more compelling today than in the past.

75

As a result, they maintained, the proposed Rule would not adversely affect legitimate telemarketers, who already accept more conventional payment methods.

73

One commenter from the financial services industry, NetSpend, described the significant adverse impact that remotely created checks have on its prepaid Visa and MasterCard debit card business and the banks that issue its cards. Netspend at 1. NetSpend explained that its debit cards do not have checking account functionality, so any remotely created checks drawn on the card account number are automatically returned unpaid by the issuing bank. NetSpend states that “some financial institutions and their third-party vendors choose to ignore the 100% return-rate” and continue to submit remotely created checks each month against its prepaid debit cards that lack checking privileges. As a result, NetSpend reports, it pays about $75,000 per year in bank fees to just one of its card issuing banks for processing thousands of remotely created check images before the bank can automatically reject them.

Id.

NetSpend also stated that it suffered significant losses from remotely created checks originated by First Bank of Delaware—a bank that the Department of Justice sued for processing remotely created payments for “fraudulent merchants and telemarketers wishing to skirt the rules of the electronic funds transfers networks.”

Id.; see also U.S.

v.

First Bank of Delaware,

Civ. No. 12-6500 (E.D. Pa. Nov. 19, 2012).

74

AARP at 3 (concluding that “the benefit to consumers of the proposed rule outweighs the burden to businesses in complying with this rule”); Hughes at 1 (“I find the cost-benefit analysis articulated in the [NPRM] to be persuasive”); NACHA at 3 (explaining that “[i]n 2010, NACHA adopted rules (that became effective in 2011) allowing for recurring payments to be authorized over the telephone” thereby eliminating the few advantages for legitimate businesses of remotely created checks over ACH).

75

AARP at 3 (concluding that “legitimate businesses have access to a variety of other payment methods”); AFR at 1 (noting that remotely created checks and remotely created payment orders “have few legitimate uses for which other payment systems could not substitute”); DOJ-CPB at 3 (“The FTC's proposed rule change will not adversely affect legitimate telemarketers” that can “use a variety of other payment means”); NCLC at 7 (“With the availability of modern electronic payment methods, there are no longer any legitimate reasons to use either payment mechanism that can justify their risks.”).

Two commenters responded to the Commission's specific request for comment regarding the proposed definitions of remotely created check and remotely created payment order by proposing discrete changes that would eliminate the requirement that the check or payment order be “unsigned.”

76

These commenters explained that the definition proposed in the NPRM was too narrow and technical to be fully effective, because a telemarketer engaged in fraud could instead insert “a graphical image of a signature into the signature block of each check or remotely created payment order” to circumvent the prohibition.

77

Instead, the commenters suggested that the Commission revise the definitions of remotely created check and remotely created payment order to make clear that both are a payment order or instruction: (1) Created or initiated by the payee and (2) deposited into or cleared through the check clearing system.

76

CFPB at 2 (“The Bureau believes that the RCC and RCPO definitions ultimately adopted by the Commission should not hinge on the presence or absence of the consumer's signature”); FRBA-2 at 2 (stating that “this broader prohibition will better serve the Commission's purposes”).

77

FRBA-2 at 2.

Several commenters supporting the proposed Rule urged the Commission to expand the prohibition on remotely created checks and remotely created payment orders to non-telemarketing transactions.

78

These commenters argued for a complete prohibition on these payment methods in all consumer transactions, noting the existence of abuse of remotely created checks and payment orders in connection with scams perpetrated via email and other media.

79

Two of these commenters urged the Commission to work closely with the CFPB, Federal Reserve Bank, and other regulators to implement such a prohibition.

80

78

AFR at 1; NCLC at 2;

see also

NACHA at 4 (noting that “it seems likely that bad actors would attempt to move activity online, as e-commerce is not covered by the telemarketing sales rule.”). In addition, two individuals went so far as to suggest either banning all telemarketing or requiring “everything in writing.” Seaman (adding, “[i]f consumers want something, they will call the company themselves”); G3 Assocs. (“It's real simple . . . make them put it in writing (either snail mail or email) . . . if they are legit they will if they won't, hang up!”).

79

AFR at 1 (urging the Commission to apply the proposed ban to “sales initiated by email or other methods that do not use a telephone”); NCLC at 4 (noting the use of these payments by internet payday lenders that provide loans to consumer in states where payday lending is illegal or where they are not licensed).

80

AFR at 1; NCLC at 7.

Some commenters also emphasized the essential assistance provided by payment processors and merchant banks to telemarketers and sellers that use remotely created checks and remotely created payment orders to debit consumer accounts without authorization.

81

NCLC expressed the view that the Rule's existing knowledge standard for assisting and facilitating is too burdensome, and would insulate payment processors from liability for processing prohibited payments for telemarketers.

82

NCLC and AFR urged the Commission to adopt a strict liability standard that would incentivize payment processors to develop robust mechanisms to ensure they are not processing these prohibited payments.

83

81

DOJ-CPB at 2 (noting that payment processors market the use of remotely created checks to process transactions for merchants that have been kicked out of payment card networks and ACH network); NCLC at 8 (“Payment processors and ODFIs play critical roles in the misuse of RCCs and RCPOs.”).

82

NCLC at 8.

83

AFR at 1 (“Payment processors and the banks that originate RCCs and RCPOs should be strictly liable for processing unlawful payments”); NCLC at 7-8 (“The best way to stop RCCs and RCPOs from entering into the system and reaching consumers' accounts is to . . . hold payment processors and ODFIs strictly liable for accepting RCCs or RCPOs that violate the TSR.”).

2. Comments Opposing the Prohibition on Remotely Created Checks and Remotely Created Payment Orders

In stark contrast to the 1995 rulemaking proceedings in which a

number of specific entities described in detail their legitimate use of and dependence on remotely created checks, in response to the current NPRM, the Commission received only one comment from a telemarketing firm covered by the amended Rule—InfoCision. InfoCision asserted generally that the amended Rule would increase the burdens on legitimate businesses and charities that rely on novel payment methods.

84

The remaining comments were submitted primarily by financial services industry members and associations.

85

Comments from the financial services industry contended that prohibiting telemarketers and sellers from using remotely created checks and remotely created payment orders would be a direct and impermissible regulation of banks, an action that exceeds the Commission's jurisdiction.

86

Overall, commenters opposed to the prohibition raised similar concerns. As described in detail below, commenters challenged the FTC's unfairness analysis, including the significance of the injury to consumers and the relative burdens on consumers and businesses; argued that the reach of the proposal was too broad; and suggested alternative courses of action.

84

InfoCision at 2.

85

See generally,

ABA; The Associations; CUNA; ECCHO; ETA; First Data; FRBA; NAFCU; PPA—Biondi; PPA—Frank.

86

ABA at 7 (stating the prohibition exceeds “the FTC's mission, jurisdiction, and authority”);

see also

ECCHO at 3; The Associations at 2. Other comments acknowledged the amended Rule would not apply to financial institutions, but raised concerns about potential negative effects on the broader payment system. ABA at 7; CUNA at 1; FRBA-1 at 2; The Associations at 10. To minimize these effects, commenters encouraged the Commission to coordinate closely with the Federal Reserve Board, CFPB, bank regulators, and other stakeholders. CUNA at 1; FRBA-1 at 4; NAFCU at 1.

While many commenters challenged the FTC's assertion that the use of these payment methods in telemarketing causes or is likely to cause substantial harm to consumers,

87

no commenter specified how or to what extent remotely created checks and remotely created payment orders are used in lawful telemarketing of legitimate products and services. For example, InfoCision claimed that novel payment methods are “extremely important” to legitimate businesses and charities that “need to offer customers multiple means of accepting payments or charitable donations” and that the amended Rule would increase the cost of collecting payments and donations but did not provide support for these claims.

88

Commenters from the financial services industry also did not provide specific support or evidence.

89

87

ABA at 2; ETA at 2; The Associations at 2; ECCHO at 13.

88

InfoCision at 2.

89

ABA at 1 (“we do not speak extensively in this comment letter of all of the potential legitimate uses of RCCs by telemarketing and other merchants”); DCS Holdings (“we do not have quantifiable data concerning how many businesses depend on one or more of these [payment] methods”); ECCHO at 12-13 (estimating the total number of remotely created checks cleared and returned as unauthorized in 2010 without identifying the number related to telemarketing); First Data at 7 (estimating that “thousands” of small businesses in its system accept RCCs and RCPOs, “some” of which “may be used via telemarketing transactions”); Thayer (“[the prohibition] will make business far more difficult for legitimate telemarketing firms”). Furthermore, First Data, itself a credit card payment processor, described its use of remotely created checks to withdraw money from the bank accounts of start-up merchants that have yet to obtain corporate credit or debit cards. First Data at 7. First Data did not provide estimates of the number of such transactions.

Id.

The commenters in opposition took issue with other aspects of the unfairness analysis the Commission articulated in the NPRM.

90

According to some commenters, the Commission failed to demonstrate that the regulatory framework applicable to remotely created checks and remotely created payment orders is a source of significant harm to consumers or a sufficient justification for the amendment.

91

To buttress that argument, commenters favorably compared the consumer protections that the UCC affords consumers who use remotely created checks and remotely created payment orders with those afforded by the EFTA (for ACH debits and traditional debit cards) and the TILA (for credit cards).

92

Further, many argued that the Commission overstated the operational weaknesses of the check clearing system in detecting and deterring fraudulent telemarketers and unauthorized transactions.

93

90

ABA at 1, 3; ECCHO at 4; The Associations at 5.

91

ECCHO suggested that the Commission “should undertake additional primary research to validate the statements in the Proposal regarding the relative burdens associated with a consumer obtaining a credit of funds to his/her account when making a claim of an unauthorized payment of any type (card, ACH or check).” ECCHO at 7.

92

ABA at 8-9 (noting that, despite differences in “details and the technical legal process,” the protections for consumers “are, as a practical matter, comparable”); ECCHO at 6 (“the UCC and other check law protections against unauthorized RCCs are arguably better for consumers than Regulation E and Regulation Z.”); The Associations at 4-5 (expressing disagreement that consumer protections for unauthorized remotely created checks and remotely created payment orders are inadequate); PPA—Biondi (same); PPA—Frank (same).

93

PPA—Biondi; PPA—Frank.

At least one commenter argued that the Commission failed to demonstrate that remotely created payment orders, themselves, caused unavoidable harm to consumers.

94

Indeed, some commenters asserted that the prohibition would do little to protect consumers when unscrupulous telemarketers thwart the Rule's existing express verifiable authorization requirements, regardless of the payment method used.

95

94

ABA at 6 (opining that the unavoidability must be connected to the cause of the harm, which is the telemarketer's initial deception, not the choice of payment system routing);

see also

ECCHO at 5 (suggesting the Commission should focus “on the actions of the telemarketer that give rise to unfair or abusive practices and not on the use of a particular payment instrument.”); ETA at 1 (“it is not the payment methods themselves that are fraudulent, but rather the actors that are attempting to sell goods and services in a fraudulent manner that constitute the problem”); PPA—Frank (“The change here is just like blaming the gun and not the person who pulls the trigger . . .”).

95

ABA at 5 (stating that fraudulent telemarketers will shift to other payment mechanisms); CUNA at 2 (same); PPA—Biondi (same);

see also

ECCHO at 4 (opining that the proposed Rule will have no deterrent effect on a “telemarketer who is already violating the TSR by not obtaining customer authorization for a debit transaction of any type—ACH, card, or RCC.”).

Most commenters, however, aimed their critique at the final cost-benefit prong of the Commission's unfairness analysis. These commenters expressed the view that the harm, if any, inflicted on consumers is outweighed by the benefits of using remotely created checks and remotely created payment orders in telemarketing transactions.

96

Because of the inability of banks to distinguish remotely created checks and remotely created payment orders from traditional checks, some argued that the prohibition would have a “

per se

application beyond telemarketing” that would cause banks to refuse to accept any remotely created checks and remotely created payment orders.

97

As a result, commenters emphasized, the amended Rule would cause substantial harm to all consumers and businesses that rely on these payment methods in non-telemarketing transactions (

e.g.,

last minute payments of credit card bills, insurance premiums, and mortgages).

98

As evidence of the responsible use of remotely created checks and remotely created payment orders by legitimate businesses, ECCHO provided estimates that they asserted showed relatively low overall rates of unauthorized remotely

created check adjustment claims, compared with the overall volume of such transactions.

99

In addition to their concern over curtailing currently accepted payment mechanisms, several commenters opined that any action to restrict remotely created checks and, more importantly, remotely created payment orders would stifle future innovation in payments.

100

96

ABA at 7 (noting that not all consumers have or are eligible for the conventional payment methods described in the NPRM); First Data at 3 (stating that the prohibition will result in delayed receipt of goods or services purchased over the telephone); PPA—Biondi (stating that RCCs and RCPOs benefit consumers because “there is more space available for providing information about the transaction to the consumer”); PPA—Frank (same).

97

ABA at 6;

see also

DCS Holdings; ECCHO at 3; FRBA-1 at 2; PPA—Frank; The Associations at 2.

98

ABA at 2; ECCHO at 4; ETA at 2; PPA—Biondi The Associations at 9.

99

ECCHO estimated that banks processed approximately 2.04 million remotely created checks per day in 2009. ECCHO at 13-14. Based on a survey of three large financial institutions, ECCHO estimated the percentages and numbers of the unauthorized RCC adjustment claims to be .01264% or approximately “258 unauthorized RCCs per day industry wide.”

Id.

100

CUNA at 1; ECCHO at 3-4; FRBA-1 at 2; NAFCU at 1.

Some commenters opposing the prohibition offered alternatives to the Commission's proposal. These suggestions included voluntary or mandatory reporting of remotely created check and remotely created payment order return rates to the Commission by telemarketers or their non-depository payment processors;

101

requiring financial institutions to disclose to bank regulators each instance of “abnormal” or “significant” remotely created check and remotely created payment order transaction or returns activity by their customers;

102

mandating that all banks and payment processors only do business with telemarketers on a registry of telemarketers;”

103

and implementing a magnetic ink character recognition (“MICR”) line

104

identifier for remotely created checks and remotely created payment orders.

105

101

The Associations at 2, 10-11 (“Rather than prohibiting the use of RCCs and RCPOs by telemarketers altogether, we believe the FTC should impose return reporting requirements on telemarketers and their [non-depository] processors that use RCCs and RCPOs”);

compare

DCS Holdings (proposing that the Commission “require monitoring and quantifying all payment types processed for returns, volumes, velocity patterns etc.”).

102

FRBA-1 at 4.

103

PPA—Frank (“How about requiring alk (sic) telemarketers to register providing all product and fulfillment details for what they are selling”); DCS Holdings (“Require all banks and third party processors only do business with `Registered' telemarketers . . .”).

104

The MICR information appears at the bottom of each check, and contains numbers that identify the bank branch, bank routing number, check number, and account number at the payor bank.

105

ECCHO at 10; First Data at 8.

3. The Commission Concludes That the Use of Remotely Created Checks and Remotely Created Payment Orders in Telemarketing Meets the Test for Unfairness

In the context of TSR rulemaking proceedings, the Commission has determined to apply the unfairness test to evaluate whether certain acts and practices qualify as “other abusive telemarketing acts or practices”

106

under the Telemarketing Act.

107

As set forth in Section 5(n) of the FTC Act, an act or practice is unfair if: (a) It causes or is likely to cause

108

substantial injury to consumers, (b) the injury is not reasonably avoidable by consumers, and (c) the injury is not outweighed by countervailing benefits to consumers or competition. Based on the entire record in this proceeding, the Commission concludes that the use of remotely created checks and remotely created payment orders in telemarketing transactions meets the unfairness test and, thus, is an abusive practice.

106

15 U.S.C. 6102(a)(1) (“The Commission shall prescribe rules prohibiting deceptive telemarketing acts or practices and other abusive telemarketing acts or practices.”).

107

TSR Amended Rule 2003, supra

note 8, at 4614.

108

Thus, the Commission need not demonstrate

actual

consumer injury, but only the

likelihood

of substantial injury. In this proceeding, however, there is sufficient evidence that the use of remotely created checks and remotely created payment orders in telemarketing causes actual injury.

a. The Use of Remotely Created Checks and Remotely Created Payment Orders in Telemarketing Causes Substantial Harm to Consumers

(1) Law Enforcement Record

The rulemaking record demonstrates the persistent, ongoing, and substantial harm caused by the use of remotely created checks and remotely created payment orders in telemarketing transactions. For nearly two decades, the Commission and its state and federal law enforcement partners have used every available tool at their disposal to combat the abuse of remotely created checks in unlawful telemarketing transactions. In many of these cases, the Commission has sought and courts have granted extraordinary equitable and monetary relief, including

ex parte

temporary restraining orders and asset freezes aimed at immediately halting the perpetrators of widespread telemarketing fraud.

109

These fraudulent schemes have victimized consumers nationwide with pitches for a variety of products, such as phony medical discount products, advance fee loans, credit card interest rate reduction services, and magazine subscriptions. Despite aggressive and active law enforcement actions, telemarketers and sellers continue to abuse remotely created checks and, increasingly, remotely created payment orders, to defraud consumers, as exemplified by recent cases filed by the Commission.

109

Since 1995, the Commission has filed more than 300 cases involving violations of the TSR, many of which have included fraudulent or unauthorized remotely created checks.

See, e.g., FTC

v.

Sun Bright Ventures, LLC,

Civ. No. 14-02153-JDW-EAJ (M.D. Fla. July 20, 2015) (Stip. Perm. Inj.);

FTC

v.

First Consumers, LLC,

Civ. No. 14-1608 (E.D. Pa. Feb. 19, 2015) (Summ. J.);

FTC

v.

AFD Advisors,

Civ. No. 13-6420 (N.D. Ill. Aug. 26, 2014) (Stip. Perm. Inj.);

FTC

v.

Ideal Financial Solutions, Inc.,

Civ. No. 13-00143-MMD-GFW (D. Nev. June 30, 2015) (Partial Summ. J.);

FTC

v.

Group One Networks, Inc.,

Civ. No. 09-0352 (M.D. Fla. Mar. 19, 2010) (Stip. Perm. Inj.);

FTC

v.

FTN Promotions, Inc.,

Civ. No. 07-1279-T-30TGW (M.D. Fla. Dec. 30, 2008) (Stip. Perm. Inj.);

FTC

v.

3d Union,

Civ. No. 04-0712-RCJ-RJJ (D. Nev. July 19, 2005) (default judgment);

FTC

v.

4086465 Canada, Inc. d/b/a International Protection Center,

Civ. No. 04-1351 (N.D. Ohio Nov. 14, 2005) (Stip. Perm. Inj.);

FTC

v.

Win USA Services, Ltd.,

Civ No. 98-1614Z (W.D. Wash. Apr. 13, 2000) (Summ. J.);

FTC

v.

Consumer Money Markets, Inc.,

Civ. No. 00-1071-PMP-RJJ (Sept. 6, 2000) (Stip. Perm. Inj.);

FTC

v.

National Credit Management Group,

Civ. No. 98-936(ALJ) (D.N.J. May 4, 1999) (Stip. Perm. Inj.);

FTC

v.

SureCheK Systems, Inc.,

No. 1-97-CV-2015 (JTC) (N.D. Ga. June 11, 1998) (Stip. Perm. Inj.);

FTC

v.

National Credit Foundation, Inc.,

Civ. No. 96-2374-PHX-ROS (Apr. 10, 1997) (Stip. Perm. Inj.);

FTC

v.

Universal Credit Corporation,

Civ. No. 96-0114-LHM(EEx) (C.D. Cal. Dec. 6, 1996) (Stip. Perm. Inj.);

FTC

v.

Diversified Marketing Service Corp.,

Civ. No. 96-0388M (Oct. 18, 1996) (Stip. Perm. Inj.);

FTC

v.

Windward Marketing, Ltd,

Civ. No. 96-0615-FMH (N.D. Ga. Oct. 10, 1996).

States have brought additional cases against telemarketers and sellers that used remotely created checks to withdraw money from consumer bank accounts without authorization.

See e.g., State of Ohio ex rel.

v.

Simplistic Advertising, Inc.,

Civ. No. 08-7232 (Franklin County, OH Ct. Com. Pl. filed May 16, 2008);

State of Ohio ex rel.

v.

6450903 Canada, Inc.,

Civ. No. 05CVH7233 (Franklin County, OH Ct. Com. Pl. May 8, 2009) (default judgment).

In the past two years alone, the Commission halted three separate telemarketing operations that were charged with using remotely created checks or remotely created payment orders to defraud thousands of consumers out of tens of millions of dollars.

110

In September 2014, the Commission sued Sun Bright Ventures, LLC, its principals, and related entities for operating a telemarketing scheme that allegedly deceived consumers into divulging their bank account information by pretending to be part of Medicare. Using consumer bank account information, the defendants allegedly used remotely created checks (and remotely created payment orders) to extract money from thousands of seniors and used tape-recorded “authorizations” to defeat consumers' disputes with their banks.

111

The Commission alleged these tape recordings were faulty, as they failed to show that the defendants obtained

consumers' authorization to be debited.

112

The rates at which consumers and banks returned these transactions were grossly outside comparable industry norms for debits from consumer bank accounts.

113

For example, the defendants allegedly generated overall return rates of approximately 68 percent and an unauthorized return rate of 28 percent.

114

By comparison, in 2013 NACHA reported that overall return rates for ACH debit transactions averaged just 1.42 percent, while unauthorized return rates averaged .03 percent.

115

110

See FTC

v.

Sun Bright Ventures, supra

note 109 (entry of stipulated monetary judgment order for $1,418,981);

FTC

v.

First Consumers, supra

note 109 (entry of $10,734,255.81 monetary judgment);

FTC

v.

AFD Advisors, supra

note 109 (entry of stipulated monetary judgment of $1,091,450.68).

111

Pl.'s Mot. and Memo. In Supp. of TRO at 8-9,

Sun Bright Ventures,

Civ. No. 14-02153.

112

Compl. ¶ 23,

Sun Bright Ventures, supra

note 109. On June 5, 2015, an FBI Special Agent filed a criminal complaint and arrest warrant charging Glenn Erikson with wire fraud in connection with his part in the

SunBright Ventures

telemarketing scheme.

U.S.

v.

Glenn Erikson,

Cr. No. 15-0520-MPK (W.D. Pa. June 5, 2015).

113

Due to the decentralized nature of the check clearing system and the inability to track remotely created checks and remotely created payment orders, neither the banking industry nor the Federal Reserve maintain data on average industry return rates. Therefore, the Commission's cases have referenced NACHA return rate statistics for ACH debits as a benchmark for return rates of remotely created check and remotely created payment order transactions.

See

Pl.'s Summ. J. Ex. 50, Dec. Professor Amelia Helen Boss, ¶ 16 (Oct. 21, 2014) (hereinafter “Dec. Prof. Amelia Helen Boss”), filed in

First Consumers, supra

note 109 (“The strong similarities between RCCs and ACH transactions make comparisons of system data particularly appropriate, and, as will be discussed below, such comparisons are extremely important in the analysis of returns.”).

114

Compl. ¶ 37,

Sun Bright Ventures, supra

note 109.

115

Id.

at ¶ 36;

see also

NACHA, 2013 ACH Network Return Rate Statistics (on file with the Commission);

NACHA RFC, supra

note 31, at 3-5 (citing 2012 statistics evidencing an overall ACH debit return rate of 1.5 percent and an unauthorized return rate of 0.03 percent).

In March 2014, the Commission sued the perpetrators of a similar scheme targeting senior citizens: First Consumers, LLC, its principals, and related entities. The Commission charged the defendants with cold-calling tens of thousands of seniors claiming to sell fraud protection, legal protection, and pharmaceutical benefit services. In some instances, the telemarketers who carried out the fraud impersonated government and bank officials, and enticed consumers to disclose their confidential bank account information. From 2010 through 2013, the defendants used consumers' bank account information to create and deposit $18,856,360.56 in remotely created checks at various banks—$8,122,104.75 of which were returned by consumers or their banks.

116

The defendants' rate of unauthorized returns ranged from at least 1.61 percent to 9.18 percent,

117

alarmingly high in light of the 0.03 percent average industry unauthorized return rate for ACH debits and NACHA's maximum threshold of 1 percent (currently 0.5 percent) for unauthorized returns.

118

The defendants' overall return rates were similarly excessive, ranging from at least 7.79 percent to 32.13 percent.

119

On February 19, 2015, the Court granted the Commission's motion for summary judgment, and entered a final order against the individual defendant, including a permanent injunction and monetary relief in the amount of $10,734,255.81—the total amount consumers lost.

120

116

Pl.'s Summ. J. Ex. 75, Summary of Deposits and Returns (hereinafter “Summary of Deposits and Returns”), filed in

First Consumers, supra

note 109. These return rates vastly exceed NACHA's recently established overall return rate threshold of 15 percent for ACH debit transactions.

117

Id.

To calculate return rates under NACHA's rules, NACHA divides the number of ACH debit transactions by the number of returned debit transactions. Due to incomplete information on the number of remotely created checks cleared and returned from the five banks used most heavily by the defendants, it was not possible for the FTC's expert witness, Professor Amelia Helen Boss, to calculate return rates by the number of items deposited and returned. Dec. Prof. Amelia Helen Boss,

supra

note 113, at ¶ 32 & n.1, filed in

First Consumers, supra

note 109. Instead, Professor Boss calculated the defendants' return rates using the value of the deposits and returns, yielding even higher overall return rates. When calculated by value, defendants' overall return rates ranged from 8.57 percent to 46.23 percent, with unauthorized return rates between 6 percent and 16.9 percent. Summary of Deposits and Returns,

supra

note 116.

118

See supra

notes 30-31 and accompanying text describing NACHA's return rate thresholds and network statistics.

119

Summary of Deposits and Returns,

supra

note 116.

120

The permanent injunction bans the defendants from all telemarketing and from accepting or depositing remotely created checks or remotely created payment orders. On the same date, the court entered default judgments (and a similar permanent injunction) against the corporate defendants in the case.

In September 2013, the Commission sued AFD Advisors and its principal, Fawaz Sebai, for operating a telemarketing enterprise that allegedly pitched a prescription drug discount card that, victims were told, would provide substantially discounted or even free prescription drugs.

121

According to the complaint, in less than a year, the Montreal-based defendants deposited nearly $2 million in remotely created checks from consumer victims, and caused additional harm in the form of non-sufficient funds (“NSF”) fees resulting from defendants' unexpected withdrawals. As part of the scheme, the defendants allegedly coached their elderly victims through purported recorded authorizations that the defendants used to defeat consumers' attempts to reverse the withdrawals as unauthorized.

122

In July 2014, a federal grand jury indicted Fawaz Sebai and two other Canadian citizens on eight counts of mail and wire fraud in connection with the alleged scheme.

123

Arrest warrants have been issued, and the United States Attorney for the Southern District of Illinois will seek extradition of the defendants from Canada.

124

121

Compl. ¶ 18,

AFD Advisors, supra

note 109.

122

The Commission described to the Court how the defendants would stop the recording process if the consumer did not answer “correctly,” and start a new recording. Pl.'s Mot. and Memo. In Supp. of TRO at 7,

AFD Advisors, supra

note 109. The defendants would repeat this process until they obtained a “clean” recording that purported to demonstrate the consumer's authorization.

123

Press Release, U.S. Attorney for the Southern District of Illinois,

U.S. Seniors Deceived By Foreign Scammers In Medicare Hoax

(July 24, 2014),

available at http://www.justice.gov/usao/ils/News/2014/Jul/07242014_Sebai%20Press%20Release.html

.

124

Id.

The Commission's record of law enforcement cases amply demonstrates that the harm resulting from the use of remotely created checks and remotely created payment orders in telemarketing is significant.

125

Several opponents of the proposed Rule amendment questioned the significance and prevalence of injury, noting that consumers who complain to their banks obtain reversals of unauthorized remotely created checks and remotely created payment orders.

126

Declarations from consumer victims in cases brought by the Commission, however, illustrate how banks can frustrate consumers' efforts to obtain reversals of such remotely created checks. For example, when one 74-year old victim in

FTC

v.

Sun Bright Ventures

attempted to reverse the defendants' unauthorized remotely created check, a bank teller told her the bank could not refund the money because the victim had not reported the issue within 24 hours.

127

Only after the victim reported the matter to a police officer, who instructed her to return to the bank to demand a reversal, did the bank agree to refund the $448 that the defendants withdrew from her account.

128

125

See supra

note 109 (citing FTC and state cases).

126

ABA at 8-9; ECCHO at 8-9; The Associations at 6.

127

Pl.'s TRO Ex. 15 ¶ 5, filed in

Sun Bright Ventures, supra

note 111.

128

Id.

at ¶ 7.

Other

Sun Bright Ventures

victims unsuccessfully attempted to reverse unauthorized remotely created checks drawn on their bank accounts.

129

For

example, an 86-year-old widow's bank refused to reverse the $448 remotely created check drawn on her account because she failed to dispute it within 30 days, ignoring the fact that she had been hospitalized during the 30 days before she noticed the unauthorized withdrawal.

130

An 82-year old victim filed an affidavit with his bank, contesting two remotely created checks made out to the defendants for $448.52 each.

131

Initially, the bank reversed the charges and returned the money to his account. However, a few months later, the bank revoked the credit to his account because it received a voice recording of the consumer answering the defendants' “yes” or “no” questions purportedly authorizing the debits.

132

The bank revoked the refund despite the consumer's allegations that the tape was fraudulent, noting several discrepancies including the fact that he never verified his age as between 18-75, when he was in fact 82 years old, and that the representative's voice on the recording was a woman's, instead of the man with whom he had spoken.

133

129

Pl.'s TRO Ex. 8 ¶ 3, filed in

Sun Bright Ventures, supra

note 109 (bank refused to reverse the $448 remotely created check). Other victims in the

Sun Bright Ventures

case complained that banks

made it difficult to reverse the transactions.

See, e.g.,

Pl.'s TRO Ex. 7 ¶ 6-8 (only after a consumer visited her credit union a second time, and spoke to a different representative, did the credit union reverse the $399 unauthorized remotely created check); Pl.'s TRO Ex. 13 ¶ 3 (bank was “not convinced” the remotely created check was unauthorized by declarant's mother, who was diagnosed with dementia, and refused to reverse $448 withdrawal).

130

Pl.'s TRO Ex. 1 ¶¶ 4-6, filed in

Sun Bright Ventures, supra

note 109.

131

Pl.'s TRO Ex. 18 ¶¶ 4-5, filed in

Sun Bright Ventures, supra

note 109.

132

Id.

at ¶¶ 5-6.

133

Id.

In another case,

FTC

v.

Handicapped & Disabled Workshops,

a declarant described how the defendants bilked his elderly mother-in-law out of thousands of dollars, including a remotely created check for $654.95.

134

Despite his existing legal power of attorney over his mother-in-law's financial affairs due to the fact she suffers from Alzheimer's disease, her bank refused to initiate a return, supposedly because she had “authorized” the withdrawal.

135

134

Pl.'s TRO Ex. 24 ¶ 21, filed in

FTC

v.

Handicapped & Disabled Workshops, Inc.,

Civ. No. 08-0908-PHX-DGC (D. Ariz. Dec. 9, 2008) (Stip. Perm. Inj.). Another victim similarly failed to obtain reversals for approximately $1,800 of $5,500 worth of unauthorized remotely created checks initiated by the

Handicapped & Disabled Workshops

defendants from May through November 2007. Pl.'s TRO Exs. 21 & 22.

135

Pl.'s TRO Ex. 24 ¶ 21, filed in

Handicapped & Disabled Workshops, supra

note 134.

Even when consumers can obtain reversals of the original transactions, significant consumer injury also results from collateral consequences stemming from the unauthorized bank debit, such as overdraft or NSF fees. For example, one consumer victimized by the fake IRS refund pitch used by the defendants in

FTC

v.

NHS Systems

grew suspicious shortly after he revealed his bank account number over the telephone.

136

Despite putting a hold on his bank account and warning his bank that a fraud-induced withdrawal was going to be posted to his account, the consumer's bank charged him NSF fees resulting from the unauthorized remotely created checks initiated by the defendants. After another

NHS Systems

victim reported the unauthorized remotely created checks to his bank, the bank threatened to report his overdrawn account to a credit reporting agency. The bank ultimately agreed to waive some, but not all, of the NSF fees caused by the numerous unauthorized remotely created checks posted against his account, but still required him to bring the account to a zero balance before he could close it.

137

136

Pl.'s TRO Ex. 13 ¶¶ 3-5, 9, 13, filed in

FTC

v.

NHS Systems,

Civ. No. 08-2215-JS (E.D. Pa. Mar. 28, 2013) (Stip. Perm. Inj.).

137

Pl.'s TRO Ex. 5 ¶¶ 8, 18, filed in

NHS Systems, supra

note 136.

Still other consumers simply never dispute such transactions with their bank in the first place.

138

As the FTC's expert witness observed in

FTC

v.

First Consumers,

“the victim may encounter roadblocks in attempting to achieve redress from the merchant, or simply may be embarrassed at his or her vulnerability.”

139

Evidence of such underreporting can be inferred from the overall return rates generated by perpetrators of fraud. For example, the fact that a thoroughly fraudulent telemarketing scheme generates a 68 percent overall return rate implies that 32 percent of the transactions were never challenged by consumer victims.

140

Some of these consumers overlook the unauthorized or fraudulent charge altogether, fail to notice it in time to make a claim under the terms of the account agreements with their banks, or may be unaware of their option to pursue the matter with their own bank. Other consumers frequently try in vain to pursue a refund directly from businesses on their own.

141

For example, after the defendants in

FTC

v.

Sun Bright Ventures

initiated a $448 unauthorized remotely created check charge to his account, one elderly victim tried for six months to resolve the matter with the defendants directly—he never received a refund.

142

In

FTC

v.

First Consumers,

a consumer thought she was talking to a representative of her bank, Wells Fargo, when she provided her bank account information to authorize a one-time payment of $38 for a theft protection plan from her account.

143

When she called the real Wells Fargo to inquire about the product, the representative told her that the defendants' company had no affiliation with the bank. Wells Fargo also apparently failed to advise her that, as the victim of an imposter scam, she could dispute the transaction. Instead of a $38 charge, the defendants initiated a remotely created check in the unauthorized amount of $387 against her account. The consumer tried for months to obtain a refund directly from the defendants, and never received her money back from the defendants or her bank.

138

See

Dec. Prof. Amelia Helen Boss,

supra

note 113, at ¶ 36, filed in

First Consumers, supra

note 109 (“many fraudulent debits go undetected by the consumer victim and, even if discovered, the victim may not assert its claim against the bank in time, or the bank may refuse to re-credit the account and return the check.”).

139

Id.

140

Compl. ¶ 37,

Sun Bright Ventures, supra

note 109.

141

See, e.g.,

Pl.'s TRO Ex. 8 ¶¶ 8-12, filed in

FTC

v.

Instant Response Systems,

Civ. No. 13-0976-ILG-VMS (E.D.N.Y. Apr. 14, 2015) (Summ. J.) (describing how she spent many months trying in vain to obtain a refund from defendants after being pressured and harassed into providing her bank account information to the defendant for a home medical alert device, which cost her $840).

142

Pl.'s TRO Ex. 6 ¶¶ 7-9, filed in

Sun Bright Ventures, supra

note 109.

143

Pl.'s TRO Ex. 2 ¶ 5, filed in

First Consumers, supra

note 109.

Even the most aggressive and highly coordinated law enforcement cases have not been able to make consumer victims whole.

144

Consider the series of actions taken by the Commission, federal prosecutors, and bank regulators against Wachovia Bank, N.A., two of its payment processing customers, and one

massive telemarketing enterprise.

145

In separate actions, the Office of the Comptroller of the Currency (“OCC”) and the U.S. Department of Justice alleged that Wachovia Bank maintained account relationships with certain payment processors

146

responsible for depositing more than $418 million in remotely created checks on behalf of fraudulent telemarketers,

147

including the defendants in

FTC

v.

FTN Promotions, Inc.

(“Suntasia”).

148

In 2007, the Commission charged the

Suntasia

defendants with deceptively telemarketing a variety of memberships in buyers' and travel clubs, resulting in $172 million in injury to nearly one million consumers. In settlement, the Commission and the OCC received approximately $50 million to be used for restitution; however, due to the extensive amount of injury caused by the defendants, the consumer victims were not made whole.

149

144

The most recent example includes the simultaneous criminal and civil actions initiated by DOJ-Criminal and DOJ-CPB against CommerceWest Bank, of Irvine, California, for allegedly “allow[ing] one of its clients to facilitate the theft of tens of millions of dollars from the bank accounts of unsuspecting, innocent consumers.” Compl. ¶ 2,

U.S.

v.

CommerceWest Bank,

Civ. No. 15-0379 (C.D. Cal. filed Mar. 10, 2015). Under the terms of the settlement, the bank agreed to pay $4.9 million to resolve civil and criminal complaints alleging the bank facilitated consumer telemarketing fraud schemes and violated the Bank Secrecy Act (“BSA”) while processing remotely created check transactions for V Internet Corp LLC., a third-party payment processor based in Las Vegas. Press Release, DOJ,

CommerceWest Bank Admits Bank Secrecy Act Violation and Reaches $4.9 Million Settlement with Justice Department

(Mar. 20, 2015),

available at http://www.justice.gov/opa/pr/commercewest-bank-admits-bank-secrecy-act-violation-and-reaches-49-million-settlement-justice

.

See also, U.S.

v.

CommerceWest Bank,

Civ. No. 15-0379 (C.D. Cal. Mar. 10, 2015) (No. 3-1) (consent decree for permanent injunction and civil penalty);

U.S.

v.

CommerceWest Bank,

Cr. No. 15-0025 (C.D. Cal. Mar. 10, 2015) (deferred prosecution agreement and information).

145

U.S.

v.

Wachovia, N.A.,

Cr. No. 10-20165 (S.D. Fla. Mar. 16, 2010);

In the Matter of Wachovia Bank, N.A.,

AA-EC-10-16 (Mar. 10, 2010). In 2010, Wachovia agreed to pay more than $150 million in restitution to resolve the matters, and entered into a deferred prosecution agreement with the U.S. Attorney for the Southern District of Florida.

See

Press Release, United States Department of Justice,

Wachovia Enters Into Deferred Prosecution Agreement: Bank Agrees to Pay $160 Million

(Mar. 17, 2010),

available at http://www.justice.gov/dea/divisions/hq/2010/pr031710p.html

; Press Release, OCC,

OCC, Wachovia Enter Revised Agreement to Reimburse Consumers Directly

(Dec. 11, 2008),

available at http://www.occ.gov/ftp/release/2008-143.htm

.

146

U.S.

v.

Payment Processing Ctr., LLC,

Civ. No. 06-0725 (E.D. Pa. Aug. 12, 2010) (Stip. Perm. Inj.);

FTC

v.

Your Money Access (“YMA”),

Civ. No. 07-5147-ECR (E.D. Pa. Oct. 22, 2010) (Stip. Perm. Inj.). The FTC also brought cases against many of the telemarketers that worked with the processors.

147

See, e.g., Universal Premium Servs.,

Civ. No. 06-0849 (C.D. Cal. Apr. 17, 2008) (Summ. J.);

FTC

v.

Sun Spectrum Commc'ns. Org., Inc.,

Civ. No. 03-81105 (S.D. Fla. Oct. 3, 2004) (Stip. Perm. Inj.);

FTC

v.

Xtel Marketing, Inc.,

Civ. No. 04-7238 (N.D. Ill. July 22, 2005) (Stip. Perm. Inj.);

FTC

v.

120194 Canada, Ltd.,

Civ. No. 1:04-07204 (N.D. Ill. Mar. 8, 2007) (Summ. J.);

FTC

v.

Oks,

Civ. No. 05-5389 (N.D. Ill. Mar. 18, 2008) (permanent injunction);

FTC

v.

Frankly Speaking, Inc.,

Civ. No. 1:05-60 (M.D. Ga. May 14, 2005) (Stip. Perm. Inj.).

148

FTC

v.

FTN Promotions, Inc. (“Suntasia”),

Civ. No. 07-1279-T30TGW (M.D. Fla. Dec. 30, 2008) (Stip. Perm. Inj.).

149

In 2008, the

Suntasia

defendants agreed to pay more than $16 million to settle Federal Trade Commission charges, and as part of its settlement with the OCC, Wachovia paid an additional $33 million to

Suntasia

victims.

Id.;

Press Release, FTC,

Suntasia Marketing Defendants Pay More Than $16 Million to Settle FTC Charges

(Jan. 13, 2009),

available at

https://www.ftc.gov/news-events/press-releases/2009/01/suntasia-marketing-defendants-pay-more-16-million-settle-ftc

. Subsequently, the court found the individual defendants in the original

Suntasia

case (Byron Wolf and Roy Eliasson) in contempt of the permanent injunction, and imposed a judgment of $14.75 million against the defendants. The judgment represented the amount they illegally took from consumers in a second scheme in which they debited consumers' accounts without their consent for membership in a continuity program.

See

Press Release, FTC,

Court Finds Telemarketers in Contempt; Imposes $14.75 Million Judgment

(Jan. 31, 2014),

available at http://www.ftc.gov/news-events/press-releases/2014/01/court-finds-telemarketers-contempt-imposes-1475-million-judgment

.

(2) Operational Weaknesses Make It Difficult To Detect and Stop Consumer Injury

Operational weaknesses in the check clearing system incentivize unscrupulous telemarketers to use remotely created checks and remotely created payment orders to initiate unauthorized and fraudulent debits to consumer accounts.

150

The check clearing system lacks the ability to distinguish remotely created checks and remotely created payment orders from other checks in the collection process. In addition, the check clearing system lacks the centralized, systemic monitoring necessary to analyze transaction trends and root out fraudulent actors. As a result, perpetrators of telemarketing fraud and unscrupulous payment processors continue to exploit these payment methods to siphon money from victims of fraud.

150

Dec. Prof. Amelia Helen Boss,

supra

note 113, at ¶ 24, filed in

First Consumers, supra

note 109 (“[a] fraudster may find that use of RCCs is both easier and subjects it to lower risks of detection than the use of ACH debits. . . . A payor bank will often have a pre-approval and underwriting process before it will begin to accept ACH transactions from a merchant, and that relationship is carefully monitored. Moreover, the monitoring of ACH activity by the system processor (NACHA) is much more elaborate. Thus, a fraudulent processor [or merchant] may choose to use the lower technology RCC to escape detection.”).

Comments from both supporters and opponents of the amendment agreed that the banking system lacks the ability to detect and distinguish remotely created checks and remotely created payment orders from other checks flowing through the check clearing system. To address this problem, some commenters opposed to the proposal advocated the use of a unique MICR identifier for remotely created checks. First Data suggested that “[b]anks can simply change the file formats used to send remotely created check transactions to the paying bank by adding an indicator field.”

151

ECCHO stated that in June 2013 the committee responsible for developing and maintaining technical standards for MICR line information started discussions on the potential for a MICR line identifier for remotely created checks.

152

151

First Data at 8.

See also

Atlanta Federal Reserve Retail Payment Office,

When It Comes to RCCs, Can We Make the Invisible Visible?

(Jan. 6, 2014),

available at

http://portalsandvrails.frbatlanta.org/2014/01/when-it-comes-to-rccs-can-we-make-invisible-visible.html

.

152

For a detailed explanation of the MICR standards committee, visit

http://x9.org/.

See also ECCHO at 10. ECCHO recently published a white paper proposing to “[d]etermine if there is industry support” for piloting a unique MICR identifier for RCCs, “with future intent for a permanent code.” ECCHO, RCC Identifier White Paper at 3 (Apr. 23, 2014),

available at http://www.eccho.org/uploads/Sec%209-1%20RCC%20Identifier%20Paper.pdf

. The paper does not outline next steps or a proposed timeline.

Such proposals for ways to separately identify remotely created checks have been debated for at least the past decade, however, and there is nothing in the record to indicate that there will be a solution to the problem in the reasonably foreseeable future. Prior efforts to modify the MICR line have failed. In 2005, the Board of Governors of the Federal Reserve (“Federal Reserve”) found that “without broad support for such a rule, and in light of the impracticalities of enforcement, the Board has determined not to pursue a MICR identifier for remotely created checks.”

153

And, according to ECCHO, even if financial institutions supported and implemented the MICR identifier for remotely created checks, it would not necessarily provide a means for banks to monitor the transaction or returns activity of individual merchants. This is because “[a] check that is passing through multiple banks in the collection process does not carry with it information that identifies the merchant depositor [but only identifies the merchant's bank or ODFI].”

154

Therefore, while the implementation of an identifier for remotely created checks would assist in monitoring remotely created checks, the future of such proposals is speculative at best, and the barriers to centralized monitoring of RCCs and the individual merchants that issue them will remain for the foreseeable future.

153

Final Rule, Regulation CC, 70 FR 71218, 71223 (Nov. 28, 2005).

154

ECCHO at 11 (“decentralized nature of forward check presentment and check return presents operational challenges for any one network or collecting bank to see the totality of volume associated with a particular merchant.”).

The decentralized nature of the check clearing system further compounds the problem of monitoring remotely created checks and remotely created payment orders.

155

Several commenters agreed

there exists no centralized, system-wide monitoring of remotely created check or remotely created payment order volume or returns activity among various financial institutions.

156

As the Federal Financial Institutions Examination Council (“FFIEC”) has summarized, “the check-clearing networks do not provide the level of technological and organizational controls of those in the ACH network. This lack of systemized monitoring of the electronically created payment orders increases the susceptibility to fraud by Web-based vendors and telemarketers.”

157

155

Some commenters argued that monitoring exists in the check clearing system, and suggested that the Federal Reserve Bank could calculate check return rates to monitor and deter unauthorized transactions. PPA—Biondi; PPA—Frank; First Data at 9. Comments filed by the FRBA and financial services industry did not confirm the existence of centralized monitoring by any intermediary parties. FRBA-1 at 4;

see generally

ABA; ECCHO; The Associations.

156

FRBA-1 at 4; ECCHO at 10; NACHA at 3; NCLC at 9.

157

FFIEC,

Retail Payment Systems Booklet—February 2010

16 (Feb. 2010),

available at

http://ithandbook.ffiec.gov/ITBooklets/FFIEC_ITBooklet_RetailPaymentSystems.pdf; see also

NACHA at 3 (“Because RCCs are not monitored systemically (indeed, RCCs are difficult, if not impossible, for individual financial institutions to monitor as a class), fraudsters are able to use RCCs to evade the authorization requirements and strong protections that NACHA has implemented through the ACH system.”); FFIEC,

Bank Secrecy Act/Anti-Money Laundering Manual, supra

note 28, at 235 (“The increased use of RCCs by processor customers also raises the risk of fraudulent payments being processed through the processor's bank account.”).

To counteract these deficiencies, some commenters suggested certain voluntary or mandatory reporting measures and regimes.

158

For a variety of reasons, the alternatives proposed by these commenters are equally, if not more, problematic. Creating a searchable national database or registry of all telemarketers would be costly to implement and unnecessarily burdensome for the many legitimate telemarketers and sellers that have never used remotely created checks and remotely created payment orders.

159

The same defects apply to the proposed mandate for telemarketers and payment processors to report to the Commission all return rates for their remotely created checks and payment orders.

160

And, because the Commission lacks jurisdiction over banks, it cannot “require every bank to collect and report to its primary federal regulator” when a merchant has “abnormal” or “significant” return rates, nor can it require banks to conduct business only with telemarketers listed in a database or registry.

161

Because none of these proposed solutions provide a near-term, effective means for centralized monitoring, and each would create unnecessary and expansive regulatory burdens, the Commission is not persuaded that they are an adequate substitute for a prohibition on the use of remotely created checks and remotely created payment orders.

158

See supra

notes 101-103 and accompanying text.

159

See

PPA-Frank; DCS Holdings.

160

See

The Associations at 2, 10-11; DCS Holdings.

161

See

FRBA-1 at 6; DCS Holdings; PPA—Frank.

The record amply demonstrates that perpetrators of telemarketing fraud exploit the weaknesses of the check clearing system to avoid detection. The Commission has sued telemarketers that relied extensively on remotely created checks and remotely created payment orders to debit the accounts of consumers. In recent cases, the defendants allegedly debited the accounts of consumers with whom they have never spoken; consumers who suffer from dementia; and consumers who felt pressured or tricked into providing their bank account information by telemarketer claims about important health care benefits, Medicare, or other products and services.

162

162

See supra

note 109 (listing FTC cases).

The record also lays bare the effect of the potential financial incentives that may encourage unscrupulous payment processors to offer perpetrators of telemarketing fraud these two payment methods that afford the least amount of oversight and transaction monitoring.

163

In many law enforcement cases, the Commission has charged that payment processors have known about or deliberately ignored underlying law violations committed by their merchant clients. Payment processors have sometimes actively helped merchant clients avoid detection and scrutiny, apparently for no reason other than to keep the transaction fees flowing. For example, the Commission alleged that certain payment processors urged fraudulent merchants to switch from ACH debits to remotely created checks and remotely created payment orders to avoid NACHA's one percent threshold for unauthorized returns

164

or used tactics to evade compliance monitoring systems designed to flag fraud.

165

In email communications and promotional materials, defendants in payment processing cases have explicitly described the systemic weaknesses of the check clearing system to detect patterns of fraud.

166

163

NCLC at 11 (“Payment processors and ODFIs rake in transaction fees from the scammers and the scammed alike”); Compl. ¶ 41,

FTC

v.

Automated Electronic Checking, Inc. (“AEC”),

Civ. No. 3:13-00056-RCJ-WGC (D. Nev. filed Feb. 5, 2013) (“AEC's pricing structure has been such that the income earned by AEC from returned transactions was significantly higher than the income earned from merely processing a transaction that ultimately cleared. The more returned transactions generated by AEC's client merchants, the higher the return fees earned by AEC and its banks”); Pl.'s Mot. and Memo. In Support of Summ. J. Ex. 2, Dec. Dennis M. Kiefer ¶ 33 (Oct. 2, 2008), filed in

YMA, supra

note 146 (expert describing how “YMA charged fees resulting from bad ACH and [remotely created check] transactions that were many multiples of the fees they otherwise would have charged.”).

164

AEC, supra

note 163, at ¶ 29 (defendants allegedly urged merchant clients to avoid NACHA's threshold by switching from ACH debits to RCPOs);

FTC

v.

Landmark Clearing Inc.,

Civ. No. 4:11-00826 (E.D. Tex. filed Dec. 15, 2011), Compl. ¶ 38 (alleging that defendants expressly advertised their RCPO processing product as a less regulated alternative to ACH transactions); Pl.'s Mot. and Memo. In Support of Summ. J. Ex. 1, Dec. Elliott C. McEntee ¶ 50 (Oct. 1, 2008), filed in

YMA, supra

note 146 (expressing his expert opinion that “YMA was moving its highest risk merchants from the ACH to demand drafts to avoid being detected by the Federal Reserve and NACHA. This enabled YMA to continue to assist merchants in defrauding consumers for a much longer period of time.”).

165

AEC, supra

note 163, at ¶ 58 (alleging defendants advised merchants to use different billing descriptors, customer service email accounts and telephone numbers, as well as corporate names or DBAs, to “fly under the bank radar”).

166

Id.

at ¶ 29 (“For example, in January 2008, AEC's principal Mark Turville notified one client merchant that `NACHA is going to a 1% threshold for unauthorized transactions starting 12-21-2007 and being enforced 3-21-2008.' Turville urged the merchant to consider switching to RCPOs: `As you know our new [RCPO] product is now being used by most of our clients and does not have a 1% restriction . . .”).

See also infra

note 198 and accompanying text (describing marketing claims of some payment processors offering remotely created check and remotely created payment order processing services).

The rulemaking record confirms the existence and harmful effect of the significant operational weaknesses within the check clearing system that incentivize perpetrators of telemarketing fraud to exploit remotely created checks and remotely created payment orders to siphon money from the bank accounts of their victims. Once deposited into the check clearing system, banks cannot distinguish remotely created checks and remotely created payment orders from traditional checks, making it impossible to monitor and halt fraudulent transaction activity. The likelihood of any future implementation of a unique MICR identifier or other method for tracking remotely created checks and remotely created payment orders is far from certain.

167

Even a unique identifier would not necessarily permit the monitoring of individual merchants, nor would it provide a centralized, system for monitoring remotely created check volumes and returns activity necessary to manage the risks posed by these payments in telemarketing transactions. These significant consumer protection

deficiencies in the check clearing system stand in stark contrast to the centralized transaction monitoring of individual merchants conducted by the payment card networks and the ACH network.

168

For these reasons, the Commission has determined that these weaknesses in the check clearing system have allowed, and are likely to continue to allow, remotely created checks and remotely created payment orders to cause significant consumer injury in telemarketing transactions.

167

ECCHO at 10 (“While ECCHO cannot unilaterally determine that an RCC identifier will be established within the check standard, ECCHO can assure the FTC that the issue of an RCC identifier will be considered at appropriate industry standards meetings.”). The Commission notes that the amended Rule will not preclude the financial services industry from adopting a unique MICR identifier or implementing other measures to increase oversight and visibility of remotely created checks and remotely created payment orders. The Commission will consider the effect of such monitoring if and when it is implemented.

168

See supra

notes 30-34 and accompanying text.

(3) Consumer Protections Available for Unauthorized and Disputed Remotely Created Check and Remotely Created Payment Order Transactions

The significant harm to consumers resulting from the operational weaknesses of the check clearing system (when used in telemarketing transactions) is exacerbated by differences in the laws and regulations governing conventional payment methods and novel payment methods.

169

Basic protections are available to consumers in credit card transactions and ACH transactions, which are subject to federal regulations. These same protections are not necessarily available in remotely created check transactions, which are subject to the UCC.

170

In particular, significant disparities exist in consumer liability for unauthorized transactions when banks disclaim liability for certain transactions or vary by agreement the timeframes in which consumers can dispute unauthorized transactions.

171

169

NACHA at 3 (“Most importantly, however, lack of Regulation E or

NACHA Operating Rule

-type protections for RCC transactions exposes RCCs to the types of heightened risks of fraud and abuse identified in the Release.”).

170

The Commission recognizes the unsettled legal landscape applicable to remotely created payment orders, including the fact that the UCC does not apply to these payments.

See NPRM, supra

note 1, at 41204. As a practical matter, however, banks fail to distinguish between remotely created checks and remotely created payment orders, and simply apply the UCC to remotely created payment orders. Industry commenters confirm this fact. ABA at 3; ECCHO at 14; FRBA-1 at 2; The Associations at 4.

171

In 1995, the Federal Reserve Bank of San Francisco described the protections consumers might have under the UCC as illusory and noted the pronounced financial disincentive to accept claims by a consumer that he or she did not authorize a particular draft because the banks must bear the loss of the amount of any draft that was unauthorized.

TSR Final Rule 1995,

60 FR at 43850.

Under Regulation Z, a consumer has no liability for unauthorized credit card transactions conducted over the telephone—so-called “card not present” transactions.

172

Consumers also have the right to dispute a credit card transaction for goods or services if there are problems with the delivery or calculation errors, among other issues, and to hold back payment while the dispute is pending.

173

Likewise, Regulation E and the EFTA provide similar, though less robust, protections against liability for unauthorized electronic fund transfers, including for traditional debit card transactions and ACH debits.

174

For instance, Regulation E imposes limited liability on a consumer for an unauthorized transfer, depending on how quickly she reports the loss.

175

Regulation E also establishes explicit timeframes and rights for consumers addressing disputes about unauthorized or incorrect electronic fund transfers from their bank accounts, including specific notice and investigation timeframes,

176

as well as the right to receive a provisional re-credit of disputed funds.

177

In addition, payment card network rules provide consumers with zero liability protection for debit and GPR card purchases in certain circumstances.

178

172

12 CFR 1026.12(b); Regulation Z Official Staff Commentary, Supplement I, 12 CFR 1026.12(b)(2)(iii)-3 (“The cardholder may not be held liable under 1026.12(b) when the card itself (or some other sufficient means of identification of the cardholder) is not presented.”). In instances involving unauthorized charges resulting from the theft or loss of the card, a consumer's liability is limited to $50. 15 U.S.C. 1643(a)(1)(B); 12 CFR 1026.12(b).

173

12 CFR 1026.13(a) and (d)(1). If a billing error appears on a consumer's monthly statement, a consumer may dispute the error within 60 days from the date the statement is mailed to the consumer. 12 CFR 1026.13(b)(1). In addition to these federal law protections, private payment card network rules have certain voluntary initiatives that may provide consumers with zero liability protection in many instances, with certain exceptions.

See infra

note 178 (describing voluntary zero liability protections).

174

See 12 CFR 1005.6.

175

If a consumer loses an “access device,” such as a debit card or ATM card, she faces tiered liability, depending upon when she notifies her bank of the theft or loss. 12 CFR 1005.6(b)(3). If the consumer reports the loss or theft of an access device within two business days from discovery of the loss or theft, the consumer's maximum liability is $50. 12 CFR 1005.6(b)(1). If the consumer notifies the bank more than two days after discovery of the theft or loss, her liability is limited to $500. 12 CFR 1005.6(b)(2). If the consumer fails to notify the bank within sixty days after her statement was mailed to her that first showed the unauthorized charges, she may be held liable for all unauthorized charges occurring after the 60-day period. 12 CFR 1005.6(b)(3). If the unauthorized transfers are made without an access device, the consumer must report them to avoid liability, within 60 calendar days of the bank's transmittal of the periodic statement that shows the unauthorized transfers. Otherwise, the consumer faces liability for any unauthorized transfers that occur after the 60-day period and potentially unlimited liability.

See

12 CFR 1005.6(b)(3)-2, Supp. 1, CFPB Regulation E Official Staff Commentary.

176

15 U.S.C. 1693(b). When a consumer provides her bank notice of an error such as an unauthorized transfer or an incorrect transfer, the bank must complete an investigation of the claim within ten business days. 12 CFR 1005.11; 15 U.S.C. 1693f(a).

177

If the bank requires a longer time to process or investigate the claim, it must provisionally credit the consumer's account for the amount disputed and can take no more than 45 days to complete its investigation, in most instances. At the conclusion of the investigation, the bank must credit the consumer's account if it determines that an error occurred. If it believes that no error occurred, the bank must send the consumer a notice explaining the findings of its investigation. 12 CFR 1005.11; 15 U.S.C. 1693f(c)-(d).

178

For so-called signature debit card purchases (

i.e.,

without the use of a PIN) that are processed through their networks, Visa and MasterCard provide consumers with the same zero liability protections extended to credit card purchases, with certain conditions. For example, Visa states that “Visa's Zero Liability Policy . . . protects you from unauthorized charges. Any funds taken from your account due to fraudulent use will be returned to your card.” Visa USA, Protections for Visa Debit cards,

available at

https://usa.visa.com/support/consumer/debit-cards.html#2

.

See also,

MasterCard, Zero Liability Protection, retrieved from

https://www.mastercard.us/en-us/about-mastercard/what-we-do/terms-of-use/zero-liability-terms-conditions.html

(last visited July 21, 2015) (providing zero liability for consumer purchases if the consumer exercised reasonable care in protecting their card from loss or theft and promptly reported to their financial institution when they knew the card was lost or stolen).

By contrast, remotely created checks and remotely created payment orders are governed by UCC protections.

179

Commenters opposed to the prohibition argued that the UCC provides similar, if not better, protections for consumers than Regulation E and the EFTA or Regulation Z and the TILA.

180

These commenters emphasized that section 4-401(a) of the UCC provides that a bank may pay a check only when it is “properly payable.”

181

Indeed, absent consumer negligence that substantially contributes to the fraud, the UCC imposes zero liability for consumers where a wrongdoer forges the consumer's signature on a check, uses a counterfeit check, forges an endorsement, or alters the amount of the check.

182

To take advantage of the UCC's limited liability for unauthorized checks, a consumer must examine her bank statement with “reasonable promptness” and provide the bank with notification “promptly” after the discovery of the fraud.

183

179

See supra

note 170 (recognizing that banks treat remotely created payment orders the same way they treat remotely created checks).

180

ABA at 8; ECCHO at 6; The Associations at 3. Commenters also emphasized that Regulation CC, Federal Reserve Operating Circular Number 3 (“Operating Circular 3”), and private clearinghouse agreements encourage paying banks to promptly re-credit their customers' accounts.

Id.

181

ABA at 8-9; ECCHO at 6; The Associations at 4-5.

182

Interbank of N.Y.

v.

Fleet Bank,

730 N.Y.S. 2d 208 (N.Y. Civ. Ct. 2001) (holding that the notation “verbally authorized by your depositor” is legally equivalent to a customer's signature and can be deemed a forged signature under the UCC).

183

UCC 4-406 (stating a general obligation of bank customers to examine their bank statements

and report unauthorized alterations and signatures on checks with “reasonable promptness”).

Unlike Regulation E, however, according to commenters who support the amendment, these provisions of the UCC provide no legally mandated error resolution procedure or specific timeframes for enforcing the limits on liability under the UCC.

184

Instead, UCC Articles 3 and 4 generally permit banks to vary the UCC requirements by agreement or contract. For example, in its deposit account agreement, a bank can disclaim its liability for fraudulent checks,

185

so long as the bank does not disclaim “ordinary care” and complies with the mandate of UCC section 1-304 to act in “good faith.”

186

Indeed, some bank-customer agreements disclaim liability for paying remotely created checks and remotely created payment orders by deeming such items as authorized, without regard to the express verifiable authorization requirements of the TSR.

187

184

As one commenter noted, to enforce compliance, the consumer may have to resort to legal action against her bank. NCLC at 4-5.

See also e.g.,

Mark E. Budnitz,

Consumer Payment Products and Systems: The Need for Uniformity and the Risk of Political Defeat,

24 Ann. Rev. Banking & Fin. L. 247, 253 (2005) (“The UCC contains no error resolution procedure, much less a recredit right. The UCC only gives the consumer the option of suing the financial institution for violating the UCC.”).

185

See, e.g., Cincinnati Insurance Co.

v.

Wachovia Bank,

72 U.C.C. Rep. Serv. 2d (West) 744 (D. Minn. 2010) (holding that a deposit account agreement can shift liability for an unauthorized check from the bank to its customer);

but cf., Kaiser Aluminum & Chem. Corp.

v.

Mellon Bank,

43 U.C.C. Rep. Serv. 2d (West) 928, 933 n.4 (W.D. Pa. 1997),

aff'd,

162 F.2d 1151 (3d Cir. 1998) (holding a fraudulent alteration discharges the liability of a bank customer unless the customer's negligence substantially contributed to the altering of the check, despite deposit account agreement shifting liability from bank to customer).

186

The UCC states this general rule for contracting out of liability for checks in Article 4 section 4-103(a), including the fact that the provisions of the UCC “may be varied by agreement” and that “the parties may determine by agreement the standards by which the bank's responsibility is to be measured if those standards are not manifestly unreasonable.”

187

See, e.g.,

Wells Fargo, Consumer Account Agreement, at 23 (Oct. 29, 2014) (“If you voluntarily disclose your account number to another person orally, electronically, or in writing, or by some other means, and the Bank determines that the context of such disclosure implies your authorization to debit your account, the Bank may treat such disclosure as your authorization to that person to issue

items

drawn against your account”) (emphasis in original); Bank of America, Deposit Agreement & Disclosures, at 23 (Feb. 6, 2015),

available at

https://www.bankofamerica.com/deposits/resources/deposit-agreements.go

(“If you voluntarily disclose your account number to another person orally, electronically, in writing or by other means, you are deemed to authorize each item, including electronic debits, which result from your disclosure”); Gorham Savings Bank, Deposit Account Agreement, at 8 (2015) (“If you give out your account number to a third person by telephone, you also agree that such act authorizes the recipient of the information to initiate debits to the account. You agree that the Bank may not be held liable for complying with such authorizations”); Associated Bank, Deposit Account Agreement, 5.13.4 (2015),

available at

https://www.associatedbank.com/forms-and-disclosures/deposit-account-agreement

(“If you voluntarily give information about your Account (such as our routing number and your Account number) to a party who is seeking to sell you goods or services, and you don't physically deliver a check to the party, any debit to your Account initiated by the party to whom you gave the information is deemed authorized”); Regions, Deposit Agreement, at 9 (Mar. 2014),

available at

http://www.regions.com/virtualdocuments/Deposit_Agreement_3_6_14.pdf

(“If we pay an item that you have not signed, but you have provided information identifying your account to a seller of property or services who created an item purportedly authorized by you, payment of the item is deemed to be authorized.”).

Unlike the dedicated timeframes under Regulation E, the UCC also permits banks to define (and significantly shorten) the standard by which “reasonable promptness” will be measured.

188

Some bank-customer agreements define “prompt” reporting to be as few as fourteen days, and similarly shorten the one-year “statute of repose” codified in section 4-406(f) of the UCC.

189

The statute of repose provides that a consumer has one year within which to assert fraud, regardless of the consumer's or the bank's care or lack thereof.

190

Courts have repeatedly upheld such variations of the reporting requirements of the UCC.

191

When banks significantly shorten the reporting period, it can have the same effect as a disclaimer.

192

188

Section 4-406(c) requires consumers to exercise “reasonable promptness” in examining the statement and notifying the bank after the discovery of the first fraudulent check in a series. “With respect to any subsequent fraudulent check perpetrated by the same wrongdoer before the bank is notified of the fraud,” section 4-406(d) requires the consumer to report the activity to the bank within a “reasonable period of time” not to exceed thirty days. Paul S. Turner,

Contracting Out of the UCC: Variation by Agreement Under Articles 3, 4, and 4A,

40 Loy. L.A. L. Rev. 443, 454-455 (Fall 2006).

189

Stephan C. Veltri and Greg Cavanagh,

Survey—Uniform Commercial Code: Payments,

68 Bus. Law. 1203, 1213 (2013) (“The [UCC] gives contracting parties wide latitude to vary the effect of the statute's terms. In the hands of some courts, the latitude seems limitless.”) (citations omitted). For example, Gorham Savings Bank requires customers to notify the bank of any errors, forgeries, or alterations within 14 days. Gorham Savings Bank, Deposit Account Agreement,

supra

note 187, at 3 (14 days).

See, e.g.,

Associated Bank,

supra

note 187, at 32 (14 days); Wilshire State Bank, Deposit Account Agreement, at 10 (July 21, 2011),

available at

https://www.wilshirebank.com/public/pdf/depagreeprivacy.pdf

(14 days);

see also Freese

v.

Regions Bank, N.A.,

644 SE.2d 549 (Ga. Ct. App. 2007) (upholding the reduction of time period in 4-406(f) to 30 days);

Peters

v.

Riggs Nat. Bank, N.A.,

942 A.2d 1163 (DC 2008) (60 days).

190

Courts have found that, unlike a statute of limitations, the UCC's statute of repose is not subject to equitable tolling.

See, e.g., Peters

v.

Riggs Nat. Bank, N.A.,

942 A.2d 1168 (“equitable tolling cannot apply to statutes of repose”);

Estate of Decker

v.

Farm Credit Servs. of Mid-America, ACA,

684 N.E.2d 1137, 1139 (Ind. 1997) (“While equitable principles may extend the time for commencing an action under statutes of limitation, nonclaim statutes impose a condition precedent to the enforcement of a right of action and are not subject to equitable exceptions”);

Brighton, Inc.

v.

Colonial First Nat'l Bank,

422 A.2d 433, 437 (App.Div.1980) (“The one-year period limitation . . . is not merely a statute of limitations, but a rule of substantive law barring absolutely a customer's untimely asserted right to make such a claim against the bank.”).

191

See, e.g., Stowell

v.

Cloquet Co-op Credit Union,

557 N.W.2d 567 (Minn. 1997) (enforcing agreement requiring account holder to examine his monthly statements and notify credit union of errors within 20 days of mailing statement);

Clemente Bros. Contracting Corp.

v.

Hafner-Milazzo,

2014 WL 1806924 (N.Y. 2014) (14 days);

Napleton

v.

Great Lakes Bank, N.A.,

945 N.E.2d 111 (Ill. App. Ct. 2011) (30 days);

Graves

v.

Wachovia Bank, Nat'l Ass'n,

607 F.Supp.2d 1277 (M.D. Ala. 2009) (40 days);

Am. Airlines Employees Fed. Credit Union

v.

Martin,

29 S.W.3d 86 (Tex. 2000) (60 days).

But see, In re Clear Advantage Title, Inc.,

438 B.R. 58 (Bkrtcy. D.N.J. 2010) (finding 60-day timeframe “manifestly unreasonable”);

Mueller

v.

Miller,

834 N.E.2d 862 (Ohio Ct. App. 2005) (holding an agreement for a 30-day notice unenforceable).

192

Turner,

Contracting Out of the UCC,

supra

note 188, at 453 (“A reporting requirement imposes an obligation on the customer to report the payment of a forged or fraudulent check within a specified period of time. The reporting requirement is not a disclaimer or waiver and does not directly vary the UCC rules on check fraud. When the time allowed for reporting is a very brief period, however, the reporting requirement can have the same effect as a disclaimer”) (citations omitted).

The ABA posits that, when combined with Regulation CC and Operating Circular 3, such “differences in the details and the technical legal process between the consumer protections for [unauthorized] check transactions and those for credit and debit cards and ACH transactions” do not result in different outcomes for consumers.

193

According to the ABA, this is because consumers indirectly benefit from the shift in warranties for remotely created checks under Regulation CC and Circular 3, which in theory incentivize paying banks to re-credit consumers' accounts for unauthorized transactions.

194

In practice, however, Regulation CC explicitly permits a bank of first deposit (the warranting bank) to defend a warranty claim in cases of unauthorized signature or alteration by showing that the consumer failed to discover and report the problem to her bank (the paying bank) with reasonable

promptness.

195

As noted above, in some cases this may be as few as 14 days.

196

193

ABA at 8.

194

Id.

at 9 (“Amendments to Regulation CC in 2006 in 12 CFR 229.34(d) require the bank of first deposit to warrant that the customer whose account is being debited . . . authorized the RCC payment. The effect is to permit bank customers to dispute such transactions and to have the item returned to the bank of first deposit”); ECCHO at 9; First Data at 7; The Associations at 5.

195

12 CFR 229.34(d)(2) (which provides that if a paying bank asserts a claim for breach of warranty under paragraph (d)(1), the warranting bank may defend by proving that the customer of the paying bank is precluded under U.C.C. 4-406, as applicable, from asserting against the paying bank the unauthorized issuance of the check.). The applicable provisions of Circular 3 do not alter this framework. Federal Reserve Operating Circular 3, Adjustments for Certain Warranty Claims; Errors, 20.10(f) (Dec. 2012) (“The sending bank agrees to deal directly with the requesting bank or another non-Reserve Bank party to resolve any claims or defenses related to the adjustment or the warranty set forth in Section 229.34(d) of Regulation CC with respect to the check.”).

196

See supra

notes 189-192.

For the reasons discussed above, the Commission finds that the regulatory framework applicable to remotely created checks, including provisions under the UCC pertaining to unauthorized and fraudulent checks, which may be varied by agreement, are more limited than those provided under Regulation E and the EFTA or Regulation Z and the TILA. This finding applies equally to remotely created payment orders, which commenters agreed are indistinguishable from remotely created checks and, therefore, are handled by banks in the same manner.

197

197

ABA at 3; ECCHO at 14; FRBA-1 at 2; The Associations at 4.

Finally, the greater burdens on consumers in recovering unauthorized and fraudulent withdrawals made by remotely created checks and remotely created payment orders are known to fraudulent merchants and create a strong incentive for them to use these payment methods. The record includes examples of payment processors actively marketing remotely created check and remotely created payment order processing services for the purpose of evading the stricter consumer protection requirements of ACH debits and credit card transactions.

198

For instance, while promoting its remotely created check product, one payment processor claims on its Web site that “[a] consumer must visit the bank and sign an affidavit” to dispute a “Check21” transaction, in contrast to an ACH debit, which “[a] consumer can dispute . . . by phone.”

199

The goal, in one processor's own words, is to avoid payment systems that “go too far with consumer protection.”

200

198

NCLC at 5-6 (citing examples of promotional materials for payment processors). One payment processor's Web site states that its remotely created payment order transactions “are governed by check laws and the Uniform Commercial Code, bypassing restrictive ACH rules and regulations.” National ACH,

Check 21 Payment Processing helps You Increase Sales

(Oct. 1, 2013),

available at http://www.nationalach.com/check-21-payment-processing-helps-businesses-increase-sales/

. The Commission's cases against payment processors confirm the use of remotely created checks and remotely created payment orders as a method of skirting additional scrutiny, regulation, and consumer protections.

See

Compl. ¶ 23,

Landmark Clearing, supra

note 164 (alleging that defendants expressly advertised their RCPO processing product as a less regulated alternative to ACH transactions); Compl. ¶ 29,

AEC, supra

note 163 (defendants allegedly urged merchant clients to avoid NACHA's threshold by switching from ACH debits to RCPOs); Dec. Dennis M. Kiefer ¶ 31,

YMA, supra

note 163 (describing YMA's efforts to migrate telemarketing clients with high ACH return rates to remotely created checks);

see also

George F. Thomas,

It's Time to Dump Demand Drafts,

Digital Transactions 39 (July 2008),

available at http://www.radixconsulting.com/TimetoDumpDemandDrafts.pdf

(noting that certain “organizations believe the check-collection system provides [them] better protections than the ACH . . . in the area of consumer chargeback. This is not sufficient justification for using this instrument.”).

199

Check21.com,

ACH vs. Check21,

retrieved from

http://www.check21.com/Check-21-vs-ACH.html

(last visited on June 24, 2015);

see also,

National Processing,

ACH vs. Check 21—Which Is Right for You,

(Sept. 17, 2013),

available at http://nationalprocessing.com/blog/ach-vs-check-21-which-is-right-for-you/

(“If there is a dispute a customer will have only 40 days to visit the local branch of his bank and fill out the proper forms. A stark contrast to this is the way the disputes are handled with ACH. These customers can dispute a transaction over the telephone rather than person and have an additional 20 days to file a dispute.”).

200

NCLC at 6 (citing a blog posting by Ed Starrs, CEO, MyECheck, dated June 20, 2012, retrieved from

http://www.myecheck.com/merchants-are-at-a-disadvantage-in-most-e-commerce-transactions-due-to-deficiencies-in-payment-systems/#prettyPhoto

).

Thus, the Commission is persuaded that the protections available to consumers who have been defrauded by telemarketers through the use of remotely created checks are substantially less robust than the protections afforded by conventional payment systems, and that con-artists exploit these weaknesses. The UCC provides no legally mandated error resolution procedure, no recredit right, and no specific timeframes for enforcing its zero liability rule, thereby abandoning a consumer to choose between accepting an unauthorized debit or suing her bank. These deficiencies, in combination with those of the check clearing system to detect and halt fraud, create powerful incentives that attract fraudulent sellers, telemarketers and their payment processors seeking to profit from unauthorized and fraudulent debits from consumers' bank accounts that go unnoticed or unrecovered.

b. The Injury Is Not Reasonably Avoidable by Consumers

Having determined that the use of remotely created checks and remotely created payment orders in telemarketing causes substantial injury, the next inquiry is whether consumers can avoid the injury. The extent to which a consumer can reasonably avoid injury is examined, in part, by analyzing whether the consumer can make an informed choice. In this context, the Unfairness Statement articulates how certain types of sales techniques may prevent consumers from effectively making their own decisions, thus necessitating corrective action.

201

The Commission seeks, through these amendments, “to halt some form of seller behavior that unreasonably creates or takes advantage of an obstacle to the free exercise of consumer decisionmaking.”

202

201

15 U.S.C. 45(n);

see also

Unfairness Policy Statement,

supra

note 62, at 1074.

202

Unfairness Policy Statement,

supra

note 62, at 1074.;

see also FTC

v.

Neovi, Inc.,

598 F. Supp. 2d 1104 (S.D. Cal. Sept. 16, 2008),

aff'd,

604 F.3d 1150, 1158 (9th Cir. 2010) (“In determining whether consumers' injuries were reasonably avoidable, courts look to whether the consumers had a free and informed choice.”);

Am. Fin. Servs. Ass'n,

767 F.2d 957, 976 (D.C. Cir. 1985),

cert. denied,

475 U.S. 1011, 106 S.Ct. 1185, 89 L.Ed.2d 301 (1986) (“The requirement that the injury cannot be reasonably avoided by the consumers stems from the Commission's general reliance on free and informed consumer choice as the best regulator of the market.”);

see also FTC

v.

J.K. Publs., Inc.,

99 F.Supp.2d 1176, 1201 (C.D. Cal 2002);

FTC

v.

Windward Marketing, Ltd.,

1997 U.S. Dist. LEXIS 17114, * 29-30 (N.D.Ga. Sept. 30, 1997).

As described in the

Federal Register

Notice for the debt relief amendments to the TSR, consumers cannot reasonably avoid harm if they do not understand the risk of injury from an act or practice.

203

In the context of remotely created checks and remotely created payment orders in telemarketing transactions, consumers can avoid the injury only if they understand the intricacies of how the operational and regulatory frameworks of these payment methods differ from conventional alternatives. Consumers are unlikely to know that remotely created checks are not subject to the same systematic and centralized monitoring as are other payment mechanisms, or to understand the implications of such monitoring on detecting and deterring fraud. Further, consumers are not likely to know that weaker consumer protections apply when remotely created checks are used. Indeed, the various legal requirements and protections that apply to electronic transactions are not transparent to most consumers.

204

The differences between

the laws that apply to bank debits processed through the ACH system as opposed to the check clearing system do not lend themselves to easy categorization, description in consumer education pieces, or oral disclosures during telemarketing calls. Helping consumers understand their rights is even more challenging when consumers have to consult individual (and non-negotiable) contracts with their bank to learn how quickly they must act to protect themselves from unauthorized remotely created check transactions. Moreover, the comparative benefits and risks of remotely created checks and remotely created payment orders or the existence of NACHA rules prohibiting outbound telemarketers from initiating ACH debits from their bank accounts are not transparent to consumers.

205

203

TSR Amended Rule 2010, supra

note 8, at 48487 (citing Unfairness Policy Statement,

supra

note 62, at 1074);

In re Orkin Exterminating Co.,

108 F.T.C. 263, 366-67 (1986),

aff'd,

849 F.2d 1354 (11th Cir. 1988);

In re Int'l Harvester,

104 F.T.C. 949, 1066 (1984)).

204

See

Budnitz,

Consumer Payment Products and Systems, supra

note 184, at 248 (“the development of new payment systems and recent proliferation of new payment products have created a complex and

confusing marketplace in which consumers cannot adequately understand their rights and responsibilities.”).

205

Id.

(“For consumers of payment products, the current legal landscape is incomprehensible. Different payment products are subject to very different laws, or no law at all besides contract law. Consequently, consumers' rights and responsibilities vary greatly.”); NCLC at 6 (“Consumers also do not understand the different levels of protection for different types of payments.”).

Some opponents argued that consumers are in control of whether they give out their bank account information over the telephone to fraudsters.

206

As was the case in the debt relief industry, the ability of consumers to understand and avoid the risk of injury here too is compromised by the fact that they do not know that the goods or services offered by the telemarketer are a sham. The record leaves no dispute that the widespread unlawful practices employed by fraudulent telemarketers and sellers using remotely created checks cause substantial and unavoidable harm to consumers.

206

ABA at 6.

When fraudulent telemarketers deceive consumers into turning over their bank routing and account information, consumers have no knowledge, let alone choice, as to how the telemarketer will decide to initiate the withdrawal from their bank account.

207

The choice of whether to route a consumer's bank account information through the ACH Network or the check clearing system is exclusively in the hands of the telemarketer or seller, as is the threshold decision as to what payment information the telemarketer demands from the consumer.

208

Once the telemarketer has elected to create unsigned checks routed through the check clearing system, the telemarketer causes further economic harm that consumers cannot reasonably avoid. Namely, selecting that payment system creates more obstacles both to detection of any misconduct by industry or law enforcement and to recovery of consumer losses. The paucity of consumer protections available (as discussed in section II.A.3.a(3)) makes it difficult for consumers to obtain a reversal of the transaction from their bank. Further, given the difficulty of locating the telemarketing scammer, consumers typically cannot mitigate this harm by seeking a refund. In sum, the resulting harm in the form of fraudulent withdrawals from consumer bank accounts, as well as the investment of time, trouble, aggravation, and expense of attempting to obtain a reversal of such withdrawals, cannot be avoided.

209

207

NCLC at 6 (“the consumer has no way of knowing how the payment will be processed and no effective control over how the payee processes the payments.”); ABA at 5 (“Congress believes that choice of payment routing is for the merchant to decide, not the consumer.”); Dec. Prof. Amelia Helen Boss,

supra

note 113, at ¶ 16 filed

FTC

v.

First Consumers, supra

note 109 (“From the perspective of a consumer dealing with a merchant and providing banking account information, it is virtually impossible to know whether an RCC or ACH item will be created; once the necessary banking information is given to the payee, the choice between the two is within the control and discretion of the payee.”).

208

Obviously, a fraudulent telemarketer can perpetrate its misdeeds through the ACH Network, depending on its tolerance for scrutiny and detection. However, unscrupulous merchants attempting to originate ACH debits must account for the scrutiny they will receive both in underwriting and risk analysis. In addition, they must account for the systemic monitoring of their transaction activity to detect violations of operating rules and regulations.

Moreover, NACHA's “TEL Rule” (abbreviation for telephone-initiated debits) specifically prohibits the use of the ACH Network by

outbound

telemarketers that initiate calls to consumers with whom they have no existing relationship. NACHA Operating Rules, Art. II, 2.5.15 (Specific Provisions for TEL Entries) (2013). The TEL Rule recognizes the inherent risk of fraud associated with the anonymous and “unique characteristics of TEL Entries, particularly given that a TEL transaction takes place in a non face-to-face environment.” NACHA, TEL Brief

Risk Management for TEL ODFIs and RDFIs

Issue No. 3 (Dec. 2009),

available at http://www.neach.org/uploads/resources/doc/tel_brief_no_3_risk_for_odfirdfi.pdf

. Under the TEL Rule, only

inbound

telemarketers and sellers that have existing business relationships with consumers may obtain a consumer's authorization to initiate an ACH debit over the telephone. As evidence of a consumer's authorization of a TEL transaction, the telemarketer or seller must either: (1) Record the oral authorization of the consumer, or (2) provide the consumer with written notice confirming the oral authorization prior to the settlement date of the entry.

Id.

209

As the Ninth Circuit noted in

FTC

v.

Neovi, supra

note 202, at 1158, “[r]egardless of whether a bank eventually restored consumers' money, the consumer suffered unavoidable injuries that could not be fully mitigated.”

In opposing the amendment and the Commission's unfairness analysis, the ABA submits that the unavoidability of harm must be connected to the cause of that harm. Here, the ABA posits, the unavoidable harm is the telemarketer's initial deception, and not the telemarketer's choice of payment system routing.

210

The Commission agrees with the ABA's comment to the extent it observes that a seller's or telemarketer's misconduct through misrepresentation or omission undermines the consumer's decisionmaking process and is not reasonably avoidable. However, the initial deception is only one aspect of the seller's behavior that causes substantial injury and is not reasonably avoidable. The telemarketer's use of remotely created checks causes equally unavoidable harm to consumers by taking advantage of another obstacle to the free exercise of consumer decisionmaking—the fact that reasonable consumers are unlikely to know or understand the implications of the telemarketer's choice of payment routing.

210

ABA at 6.

The ABA further argues that, unless unavoidability is connected to the telemarketer's deception, the Commission will cast as unavoidable any injury resulting from a merchant's decisions about its operations—a business's choice between two competing debit card networks, for example.

211

The Commission finds this argument unpersuasive. A merchant's choice between two competing debit card networks has no effect on consumer protections against fraud because both transactions are covered by Regulation E and subject to the same centralized monitoring regime. This result is in stark contrast to the practices documented in the rulemaking record where a telemarketer deliberately chooses to route a consumer's payment through a specific payment system that affords the consumer less protection from fraud and provides the telemarketer with more ability to evade scrutiny than other payment systems and regulatory frameworks.

212

211

Id.

at 5.

212

For the same reasons, the Commission is equally unpersuaded by the ABA's other examples of business decisions in which consumers have no choice (

i.e.,

the credit reporting agency that a business may consult and the choice of telecommunications company that a business uses to call consumers).

Here, telemarketers' misrepresentations and use of remotely created checks and remotely created payment orders routed through the check clearing system undermine consumers' decisionmaking, thereby causing unavoidable substantial injury. This conclusion is amply buttressed by

the absence of reliable information in the rulemaking record to identify any legitimate uses of remotely created checks and remotely created payment orders in telemarketing transactions covered by the Rule.

c. The Benefits of Remotely Created Checks and Remotely Created Payment Orders in Telemarketing Do Not Outweigh the Harm to Consumers

The final prong of the Commission's unfairness analysis recognizes that costs and benefits attach to most business practices and requires the Commission to determine whether the harm to consumers from remotely created checks and remotely created payment orders in telemarketing is outweighed by countervailing benefits to consumers or competition.

213

Commenters opposed to the amendment have advanced numerous arguments regarding the benefits of remotely created checks and remotely created payment orders, including that there are legitimate uses of these payments in non-telemarketing transactions. The commenters also argue that fraud will continue despite the prohibition. In addition to the public comments, the Commission has considered its own rulemaking history in which the Commission proposed and ultimately declined to adopt a similar provision in 1995 because it deemed sufficient benefits to accrue to consumers from the use of remotely created checks. As a result of the development of numerous payment mechanisms available to consumers with checking accounts, the use of alternative payments by legitimate telemarketers, and the rulemaking record as a whole, the Commission is now persuaded that any historical benefits of remotely created checks in telemarketing are no longer cognizable. Today, the vast majority of consumers with checking accounts have debit cards linked to their accounts.

214

Moreover, the current rulemaking record contains no specific examples of legitimate telemarketers' and sellers' use of remotely created checks and remotely created payment orders.

215

Further, the Commission concludes that consumers and competition benefit from the bright line rule that a prohibition provides.

213

TSR Amended Rule 2010,

75 FR at 48485 (employing cost benefit analysis in determining debt settlement amendments to the TSR).

214

Federal Reserve Bank of Boston,

The 2011 and 2012 Surveys of Consumer Payment Choice,

at Table 2 (Sept. 2014) (hereinafter “2011 and 2012 Surveys of Consumer Payment Choice”),

available at http://www.bostonfed.org/economic/rdr/2014/rdr1401.pdf

(finding 85 percent of consumers have had a traditional debit card). For the small percentage of checking account holders without traditional debit cards, there exist few, if any, barriers to obtaining debit card access. It is not known whether consumers without such traditional debit cards also lack other payment cards, such as credit cards or GPR cards.

215

TSR Final Rule 1995, supra

note 8, at 43850. The Commission received only one comment from a telemarketing firm, InfoCision, but it did not provide support for its conclusory statement that novel payment methods are important to legitimate businesses and charities. InfoCision at 2. InfoCision's Web site states that it “work[s] with a roster over 200 clients across industries, including Fortune 500 companies and the nation's leading nonprofit organizations.” InfoCision, Our Clients,

available at http://www.infocision.com/CompanyInfo/Clients/Pages/default.aspx

(last visited June 10, 2015). InfoCision's Web site identifies numerous clients, including Easter Seals, March of Dimes, American Diabetes Association, and Unicef. A review of the individual donation Web sites for each listed client indicates they accept card payments directly from consumers, suggesting that the inability to employ novel payment mechanisms should not be a major problem at least when dealing with the vast majority of consumers who have payment cards.

According to some commenters, the benefits of remotely created checks and remotely created payment orders in telemarketing transactions for consumers with checking accounts include the convenience of paying for impulse purchases of goods and services sold over the telephone when the consumer does not have (or wish to use) another form of payment.

216

Other commenters argued that consumers also benefit from the ability to receive more detailed transaction information than ACH debits provide and better protection against identity theft than paper checks sent through the mail.

217

The asserted benefits for telemarketers and sellers include faster settlement times than ACH debits,

218

the ability to accept payments quickly and easily over the telephone from any consumer with a checking account,

219

and the potential savings in transaction costs over comparable payment alternatives.

220

216

ABA at 7 (“[remotely created checks] allow a customer that does not have a debit, credit, or prepaid card to purchase goods that the customer would otherwise be denied”); First Data at 3 (noting that consumers could be delayed in receiving goods or services); InfoCision at 2 (stating that legitimate businesses and charities “need to offer customers multiple means of accepting payments or charitable donations”).

217

First Data at 3 (citing increased risks of identity theft for checks sent through the mail); PPA-Biondi (“many of the alternative methods don't provide enough transaction information for the consumer”); PPA-Frank (same).

218

ABA at 6 (emphasizing the speed of settlement compared to ACH transactions in certain circumstances),

but see infra

note 225 (describing improvements to the ACH Network providing for same-day settlement).

219

ABA at 6 (highlighting the ability of businesses to accept payments from consumers that do not have other types of payment methods); First Data at 4 (describing the lost sales opportunities for sellers that “would be left without a timely and reliable payment mechanism when transacting business with a consumer that solely relies upon checks”); FRBA-1 at 3 (noting reasons why businesses may choose remotely created checks and remotely created payment orders over ACH debits); PPA-Frank (noting that merchants that do not meet credit standards necessary for ACH origination services need remotely created checks).

220

InfoCision at 2 (“Traditional methods [of payment] are more costly and time consuming”). The NPRM requested, but the Commission did not receive, specific comments detailing what additional costs, if any, would result from using payment alternatives to remotely created checks and remotely created payment orders in telemarketing transactions.

NPRM, supra

note 1, at 41223. To the extent that remotely created checks and remotely created payment orders may cost telemarketers and sellers less than comparable payments, such as ACH, a

This text is long and has been trimmed here. Open the source document for the complete record.

This is a copy of a public record, reproduced as it was published. It is not legal advice, and it may not be the version a court would rely on. Check the official source before you cite it.

A word about cookies

We need a few to keep you signed in and the library working. The rest help us see which pages people use and where they get stuck. They stay off unless you say yes.