Cat chases dog, cheese eats mouse, ISO sues FTC: strange times in payments
Notwithstanding the DOJ’s abandonment of Operation Chokepoint in 2017, the Federal Trade Commission (“FTC”) has continued to treat ISOs as gatekeepers to the payments system, threatening them with liability where they fail to adequately police their merchants—while denying this policy publically. Yet earlier this month, one ISO took the offensive and, in a groundbreaking move, initiated a preemptive strike against the FTC rather than simply allowing itself to fall victim to these tactics.
On December 5, 2019, Complete Merchant Solutions LLC (“CMS”) filed suit against FTC in the federal district court of Utah—Case No. 2:19-cv-00963-CMR. The Complaint seeks a declaration and injunction to stop the FTC from engaging in conduct that CMS alleges “is not only unfair and harassing but also far beyond the express limitations of its jurisdiction and enforcement powers.”
One Of The Good Guys
CMS is an ISO for acquirers Commercial Bank of California, Chesapeake Bank, Deutsche Bank, Merrick Bank, and Wells Fargo. From soon after its founding in 2008, CMS focused on serving e-commerce businesses and other start-up technology companies. Over the past decade, CMC has grown from a tiny start-up to a highly successful company. CMS has won several awards, been recognized nationally and regionally, has attracted investment from blue-chip equity funds, and provides work for nearly 300 employees and independent contractors, while serving more than 5,500 merchant accounts that together produce over $3 billion in payments annually.
According to its Complaint, since 2013, CMS has maintained a chargeback rate well below the 1% mark. In 2018, CMS’ chargeback rates were just .58% by dollar and .23% by count. CMS employs rigorous underwriting practices, which have led it to decline approximately 16% of merchant applications since 2013. CMS also subscribes to costly merchant-monitoring tools, including G2 and TSYS Fraud, to identify suspicious payment activity, fraud, and other red flags; and also monitors the Mastercard Merchant Online Status Tracking (MOST) system.
A “Barrage” Of CIDs
Nonetheless, CMS alleges that, for the past two years, FTC has directed numerous Civil Investigative Demands (CIDs) to CMS “seeking vast amounts of information relating almost entirely to a handful of business which CMS and its sponsoring banks ceased working with years ago.” In response, CMS has produced over 45,000 documents—totaling over 475,000 pages—responded to numerous interrogatories, and produced multiple employees for depositions.
CMS contends that the evidence produced to FTC shows that: CMS declined applications for 21 merchants responsive to the CID (“responsive merchants”); responsive merchants were 3% of CMS’ total merchants in 2011, declining to only 0.5% in 2016 and 0.08% in 2017; by 2016 and 2017, less than 0.1% of CMS’ processing volume was for responsive merchants; the overwhelming majority of responsive merchants were terminated by CMS before any regulator filed a complaint or subpoenaed CMS; and, of the 37 responsive merchants later involved in FTC enforcement actions, CMS had terminated 34 prior to the time of suit.
Nonetheless, FTC was not satisfied.
FTC Threatens Suit
CMS alleges that, on February 4, 2019, FTC staff informed CMS that they planned to recommend enforcement action and sent CMS’ lawyers a proposed complaint and consent order. The proposed complaint’s theory is that CMS “failed to adequately screen and monitor its merchant-clients,” and thereby misled its sponsoring banks.
According to CMS, the FTC’s proposed consent order directed CMS to:
- Terminate all businesses that use telephones to induce the purchase of goods or services;
- Terminate all businesses that represented that their goods or services would help consumers earn income from home, obtain training or education on how to establish a business or make money from a business, obtain employment for an upfront fee, or obtain government grants or government income, benefits, or scholarships;
- Terminate all businesses that involve a subscription model where consumers have to tell the business to cancel their subscription (that is, every subscription product); and
- Engage in heightened screening of “High Risk Client[s],” a category defined as covering any merchant with more than 15% card-not-present transactions, more than $200,000 in card-not-present transactions a year, or any merchant that sells:
- Discount buying clubs;
- Foreclosure protection or guarantees;
- Lottery sales or sweepstakes;
- Medical discount benefits packages;
- Multi-level marketing distribution;
- Nutraceuticals (a category that includes vitamins);
- Payment aggregators;
- Cryptocurrency;
- Third party payment processors;
- Penny auctions;
- Real estate seminars and training programs; and
- Computer technical support services.
Unacceptable Consequences
Thus, CMS argues that, under the FTC’s first proposal, CMS would not be able to solicit Amazon as a merchant, because it sells books by Princeton Review about how to get scholarships for college. CMS would not be able to solicit Brigham Young University as a merchant because it has a business school that represents that its services can assist students in starting or running a business. CMS would have to subject CVS or Walmart to heightened scrutiny, because they sell multivitamins. And, CMS would have to subject Best Buy or Apple to heightened scrutiny, because the Geek Squad and the Genius Bar provide computer technical support services.
CMS further alleges that, while the FTC narrowed some of the categories in response to comments from CMS’ attorneys, the FTC indicated that it would insist on a ban on serving businesses that fall into certain categories, including any company (like Amazon) who sells nutraceuticals with an option to purchase via subscription (like Amazon’s “Subscribe and Save” program). The FTC also kept the list of suspect categories requiring heightened scrutiny and monitoring virtually identical apart from moving subscriptions (for all products other than nutraceuticals, which would still be subject to the outright ban), the business-related education and grants categories, and businesses that use telephones to induce sales from the categories subject to an outright ban to one requiring heightened scrutiny. The FTC rejected any further proposal to narrow these categories.
And the FTC sought to set the threshold for chargebacks (which would trigger a duty to “immediately” investigate) at just 55 chargebacks per month, a level well below even the “early warning” thresholds set by the card brand guidelines. What’s more, the FTC’s various draft orders all sought to impose a “strict liability” standard— meaning that CMS could be in violation of the terms of the order without any knowledge of the facts giving rise to that liability.
FTC Overstepping Its Authority
CMS argues that this is not what the law intends and is far beyond any reasonable bounds of the FTC’s authority.
The FTC Act empowers the FTC to police unfair business practices. According to CMS, however, the vague term “unfair” does not confer upon the FTC the power to make banks’ ISOs vicariously liable for failing to prevent merchants from committing fraud. And, the FTC has no authority to eject thousands of law-abiding merchants— which themselves are not the subject of any legal action—from the payment systems on which they depend based on nothing more than the FTC staff’s biases against particular industries.
CMS also points out that the FTC is expressly prohibited from regulating banks, whose relationships with ISOs are regulated by the FDIC and other banking regulators. Thus, CMS argues that FTC is seeking an end-run around this limitation of its authority by going after the ISOs—who act as a sales arm for the acquiring banks, and are there to simply facilitate the connections between merchants and banks, the entities responsible for the processing of merchant transactions.
Accordingly, the Complaint asks the Court to put an end to the FTC’s overreach and threatened legal claims by granting CMS’ request for declaratory relief, and issuing an injunction prohibiting the FTC from bringing (or threatening to bring) any action against CMS in connection with the provision of its ISO services as described herein, premised on a violation of 15 U.S.C. § 45(a) or § 53(b), as such statutes give the FTC no authority to bring such actions.
Why It Matters
This is a bold move by CMS. By filing suit against the FTC rather than waiting for FTC to commence an enforcement action, CMS has taken the initiative and framed the argument on its own terms as a champion of ISOs throughout the payments industry. This challenge is also set against the backdrop of a split among the federal circuit courts as to whether 15 U.S.C. § 53(b)—which codifies section 13(b) of the FTC Act—empowers the FTC to seek monetary relief, including restitution—an issue that has recently put the FTC on its heels in enforcement actions. This lawsuit may represent a blow to FTC’s ability to police ISOs and hold them liable for their merchants’ actions absent strong evidence of complicity.
The industry should also take note that—as evidenced by FTC’s proposed consent order to CMS—all nutraceutical, tech support, and negative continuity merchants, along with the ISOs that extend services to them, remain very much within the FTC’s crosshairs.
Bradley O. Cebeci is a Senior Attorney with Rome & Associates, APC. Brad focuses on Payments Law, Digital Marketing and FTC Issues.
COPPA compliance for advertisers, websites, mobile apps and other online services
Whether you are an advertiser or online service provider, you must adapt to survive in an increasingly regulated and rapidly changing digital media environment. With an estimated 175,000 kids going online globally for the first time everyday, one of the key challenges your business may face is complying with a host of differing laws designed to protect the privacy of these young users—including the Children’s Online Privacy Protection Act (COPPA), which is specifically designed to protect children, and the California Consumer Privacy Act (CCPA) and European General Data Protection Regulation (GDPR), which contain provisions affording special protection to kids.
COPPA extends broadly to online services (advertisers, websites and mobile apps) whose audience includes children under 13, and prohibits them from collecting personal information (including persistent identifiers) from those users without first obtaining verifiable parental consent. While COPPA has been around for nearly 20 years, the Federal Trade Commission (FTC) has recently made COPPA compliance a key priority and stepped up the pace of COPPA enforcement actions.
Among those impacted by the trend are YouTube creators, who face a new dilemma to start the New Year. If their content is “made for kids,” they must immediately label it as such. By doing so, they may lose the ability to monetize their content. By failing to do so, they may expose themselves to crippling fines.
The Backstory
In September 2019, Google LLC and its subsidiary YouTube LLC agreed to pay $170 million to settle a civil action by the FTC and the New York Attorney General for alleged COPPA violations. YouTube allegedly violated COPPA by collecting cookies from viewers of child-directed channels, without first notifying parents and getting their consent, and then using those cookies to deliver targeted ads.
In addition to paying a $136 million penalty to the FTC and $34 million to New York, YouTube has developed a new system for identifying child-directed content on its platform as part of the settlement.
A New Year, A New Policy
Effective January 1, 2020, YouTube creators are responsible for determining whether their content is directed to children and then designating such content as “made for kids” as appropriate. That label may apply to individual videos (new and previously uploaded), or an entire channel.
In turn, YouTube will no longer collect cookies to deliver targeted ads to viewers of “for kids” videos and channels. Instead, YouTube will deliver “contextualized ads” based strictly on the video’s content. YouTube will also disable comments, info screens, the “donate” button, channel branding watermarks, “save to playlist” or “watch later” features, and cards and end screens for “for kids” videos, and eliminate community tabs, notification bells and stories from “for kids” channels.
Again, if a video’s intended audience is 13 and under, the creator is subject to COPPA.
Is It Child-Directed?
But, as YouTube and the FTC both acknowledge, the determination of whether content is “child-directed” may not be clear in many cases. In such cases, the FTC identifies a number of additional factors one must consider to make that determination, including:
- The subject matter,
- Visual content,
- The use of animated characters or child-oriented activities and incentives,
- The kind of music or other audio content,
- The age of the models,
- The presence of child celebrities or celebrities who appeal to children,
- Language or other characteristics of the site,
- Whether advertising that promotes or appears on the site is directed to children, and
- Competent and reliable empirical evidence about the age of the audience.
Other Considerations
FTC also suggests that, unless a video is affirmatively targeting kids, there are many subject matter categories that do not implicate COPPA. For example, videos about traditionally adult activities like employment, finances, politics, home ownership, home improvement, or travel are probably not covered by COPPA unless the content is geared toward kids. The same would be true for videos aimed at high school or college students. On the other hand, if content includes traditional children’s pastimes or activities, it may be child-directed. For example, the FTC recently determined that an online dress-up game was child-directed.
Second, a video is not automatically covered by COPPA just because it has bright colors or animated characters. While many animated shows are directed to kids, the FTC recognizes that some animated programming appeals to everyone.
Where questions still remain, the FTC suggests considering how others view your content and content similar to yours. Has your channel been reviewed on sites that evaluate content for kids? Is your channel – or channels like yours – mentioned in blogs for parents of young children or in media articles about child-directed content? Have you surveyed your users or is there other empirical evidence about the age of your audience?
Conclusion
Okay. But what about channels built around gaming content like Minecraft and Fortnite? In such cases, application of the foregoing factors may still fail to offer a clear answer, and may provide little comfort to creators. Particularly when the Rule authorizes civil penalties of up to $42,530 per violation.
Website operators, mobile app services, and advertisers (both upstream and downstream) should be equally concerned about these questions.Indeed, digital services that classify themselves as general audience services are subject to increasing challenge by regulators to prove their audience composition.
If you are unsure about whether your content or your website is subject to COPPA, you should consult with an attorney experienced in FTC matters and COPPA compliance. We regularly review media, data collection practices, and privacy policies for compliance with COPPA, the CCPA, the GDPR and the FTC Act.
Bradley O. Cebeci is a Senior Attorney with Rome & Associates, APC. Brad focuses on Payments Law, Digital Marketing and FTC Issues.
Privacy Shield Compliance: Necessary Reading For US Companies Doing Business In The EU
On December 3, 2019, the Federal Trade Commission (FTC) announced settlements with four companies related to allegations that they deceived consumers over participation in the EU-US Privacy Shield Framework. The companies include Click Labs, Inc., a website and mobile app services provider; Incentive Services, Inc., a developer of service award and incentive programs for employers; Global Data Vault, LLC, a provider of data storage and recovery services; and TDARX, Inc., an IT services provider. According to FTC’s allegations, at least two of these companies continued to claim participation in Privacy Shield after allowing their annual certifications to lapse, and failed to comply with the framework.
That brings the total to 21 enforcement actions related to Privacy Shield since its establishment in 2016. Thus, there can be little doubt that Privacy Shield compliance represents an enforcement priority for the FTC.
But what is Privacy Shield?
If you are a US company doing business in the EU, you should know.
By now, any US company doing business in the EU is certainly aware of the General Data Protection Regulation (GDPR) and the risk it presents to companies that fail to comply. Indeed, most such companies spent a lot of time and money in the early part of 2018 reworking their published Privacy Policies to comply with the GDPR. But many companies failed to fully understand the GDPR or actually bring their data practices into compliance.
Are you one of them? Let’s put it this way:
If you are a US company doing business in the EU and have not self-certified in Privacy Shield, there is a good chance that you may be transferring data from the European Economic Area (EEA) to the US in violation of the GDPR. Note that if a US company transfers EEA data to the US through a partner/processor—such as an analytics service that has its servers in the US—then the partner rather than the company is responsible for compliance; provided, however, that the company must enter a Data Processing Agreement with the partner whereby the partner confirms its compliance with GDPR requirements. In such cases, the company should confirm that its partner is Privacy Shield certified.
The GDPR prohibits the transfer of personal data outside of the EEA to a third-party country unless the recipient country provides an “adequate level of data protection,” the data exporter puts appropriate safeguards in place, or an exemption or derogation exists to justify the transfer.
From the EU’s perspective, the US does not have an adequate level of data protection. Moreover, while an exemption or derogation may justify some transfers of personal data, it does not offer the broad protection of self-certification under Privacy Shield.
Consent is the strongest category of exemption. But it requires a clear disclosure to the data subject of what you plan to do with the data, including all associated risks, and his/her explicit consent to the transfer of the data outside the EEA. Most of the other exemptions and derogations apply to government entities and public authorities, or require particular approval by the relevant Data Protection Agency.
Privacy Shield provides US companies with broader protection.
In order to self-register, a US company must confirm its eligibility to participate in Privacy Shield. That means that the company must be subject to the jurisdiction of the FTC or the Department of Transportation. That generally means that banks, federal credit unions, and savings and loan institutions are not eligible to participate in Privacy Shield.
Next, the company must develop a Privacy Policy Statement that complies with Privacy Shield requirements. That means notifying data subjects of your participation in Privacy Shield, the type of data being collected, the purposes for which the data is being used, any third parties with whom you will share the data, the data subject’s right to access the data and his/her choices and means to limit the use and disclosure of such data, and available recourse mechanisms.
As part of this Privacy Policy, the company must also confirm its commitment to Privacy Shield Principles, including Choice (“clear, conspicuous, and readily available mechanisms” to opt out), Accountability (transferred data “may only be processed for limited and specified purposes consistent with” data subject’s consent), Security (adhering to best industry practices to secure data), Data Integrity (limit data collection to “relevant” data, and ensure it is “reliable for its intended use, accurate, complete and current”), Access (data subject must have access, including ability to correct, amend or delete, personal data), and Recourse, Enforcement and Liability (official complaint handling process and detailed mechanism for dispute resolution through a third-party such as the Better Business Bureau, American Arbitration Association or JAMS).
Once this Privacy Policy is published, you may submit your company’s self-certification to the Department of Commerce. The associated fee is $1,500 or less for companies with annual revenue up to $500 million. You must re-certify your Privacy Shield compliance with the Department of Commerce on an annual basis. And, of course, you face the risk of a potential enforcement action by the FTC, along with civil penalties, in the event you fail to comply with your obligations under Privacy Shield.
But for US companies doing business in the EU, GDPR compliance and Privacy Shield certification go hand in hand.
Bradley O. Cebeci is a Senior Attorney with Rome & Associates, APC. Brad focuses on Payments Law, Digital Marketing and FTC Issues.


