Don’t do SECURITY. Do business SECURELY.

US Red Flag Program Clarification Act signed into law

A new US law narrows the definition of “creditor” under the Identity Theft Red Flags Rule, ending uncertainty for professional service firms.

The Red Flag Program Clarification Act of 2010 has today been signed into law in the United States, narrowing which businesses must comply with the Identity Theft Red Flags Rule under the Fair Credit Reporting Act.

Key points

  • A “creditor” is now limited to those that obtain or use consumer reports, report to credit bureaus, or advance funds.
  • Professionals such as lawyers, doctors and accountants that simply bill for services after they are provided are generally excluded.
  • Covered financial institutions and creditors must still maintain a written identity theft prevention programme.
  • The FTC is expected to begin enforcing the Rule shortly after years of delay.

UK organisations offering credit or accounts to US customers should confirm whether they are covered and, if so, that their programme detects and responds to identity theft warning signs.

Source: Red Flag Program Clarification Act of 2010, S.3987 (congress.gov)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

More insights