Court Rules
All enforcement actions
SettlementLow Risk

FTC Settles with Ascension Data Over GLBA Vendor Oversight Violations

Ascension Data & Analytics, LLCDecember 15, 2020Federal Trade Commission

Summary

Ascension Data & Analytics, LLC, a mortgage analytics company, settled FTC allegations that it violated the Gramm-Leach-Bliley Act's Safeguards Rule by failing to ensure its vendor adequately protected consumer data. The vendor stored sensitive mortgage information in plain text on a cloud server, leading to unauthorized access. Ascension must implement a data security program, undergo biennial assessments, and report future breaches.

Remedy

Ascension must implement a comprehensive data security program, undergo biennial independent assessments of its data security program, have a senior executive certify annual compliance, and report any future data breaches to the FTC within 10 days.

Compliance ProgramAudit RequirementReporting Requirements

Contract Impact

In-house legal teams should review all vendor, data processing, and service agreements where the vendor handles sensitive consumer financial data (e.g., mortgage information). Focus on clauses requiring data security measures, vendor oversight rights, audit provisions, breach notification obligations, and indemnification for data incidents. Specific changes may include: (1) mandating compliance with the GLBA Safeguards Rule; (2) requiring vendors to implement and document an information security program; (3) granting the company explicit rights to audit vendor security practices; (4) obligating vendors to report security incidents promptly; and (5) including contractual remedies for failures to protect data, such as termination rights or liability for breach-related costs.

Contract Search Terms

vendor oversight clausedata security requirementsGLBA Safeguards Rule compliancethird-party vendor managementconsumer data protectionbreach notification requirementsinformation security programaudit rightsencryption standardsrisk assessment

Laws Cited

Gramm-Leach-Bliley Act

Violation Types

Entity Details

Entity

Ascension Data & Analytics, LLC

Also known as: Ascension Data & Analytics

Industry

Financial Services

Official Sources

Source Evidence

Entity Name
"Texas-based Ascension Data & Analytics, LLC"
Laws Cited
"Gramm-Leach-Bliley Act’s Safeguards Rule"
Violation Types
"stored the contents of the documents on a cloud-based server in plain text, without any protections to block unauthorized access"

Related Enforcement Actions

FTC

Ascension Data & Analytics, LLC

The FTC settled with Ascension Data & Analytics, LLC for violating the Gramm-Leach-Bliley Act's Safeguards Rule by failing to ensure its vendor properly protected consumer data. The company must strengthen its security safeguards and increase oversight of vendors. No monetary penalty was imposed.

FTC

Vanilla Chip LLC

$750K

The FTC finalized an order against Vanilla Chip LLC (doing business as TruHeight) and its principals for deceptively advertising height-enhancing supplements for children and teens without scientific evidence. The company also used fake reviews and incentivized 5-star ratings. The order requires a $750,000 payment and prohibits false health claims and deceptive review practices.

FTC

RentGrow Inc.

$2.3M

The FTC alleged that RentGrow, a tenant screening company, violated the Fair Credit Reporting Act (FCRA) by failing to use reasonable procedures to ensure the accuracy of its reports, including by reporting duplicate records and failing to disclose data sources. RentGrow agreed to pay a $2.25 million penalty and is prohibited from further FCRA violations and from misrepresenting dispute outcomes.

FTC

Handy Technologies

The FTC and New York Attorney General took action against Handy Technologies for deceptive earnings claims and failure to disclose fees and fines that led to millions of dollars being withheld from workers' wages. The FTC is sending over $2.7 million in refunds to 62,893 affected consumers.

FTC

Hopper Inc.

$35.0M

The FTC alleged that Hopper, a travel booking app, charged consumers hidden and pre-selected fees (Tip and VIP Support) without their consent, misrepresented the benefits of VIP Support and Price Freeze services, and failed to clearly disclose total prices. Hopper agreed to pay $35 million for consumer redress and is prohibited from misrepresenting fees under a proposed order.

FTC

Publishing.com LLC

$1.5M

The FTC finalized a settlement with Publishing.com LLC and its principals for misleading consumers about potential earnings from self-publishing products. The company will pay $1.5 million and is prohibited from making unsubstantiated earnings claims, failing to disclose refund terms, and misrepresenting endorsements and reviews.