Skip to content

How Does the Partial Rollback of Dodd-Frank Affect Payment Facilitators and UDAAP?

The US House of Representatives voted this week to repeal parts of the Dodd-Frank Wall Street Reform and Consumer Protection Act, the 2010 legislation that brought significant changes to financial regulation in the United States after the Great Recession. Because Dodd-Frank led to the creation of the Consumer Financial Protection Bureau (CFPB), payment facilitators and processors may wonder whether changes in the law impact the way the government approaches its enforcement of unfair, deceptive, or abusive acts or practices - known as UDAAP. (Get our UDAAP guide for an in-depth explanation of these practices.)

The recent legislation, which passed 258-159, is aimed at relaxing rules for small- and medium-sized banks, which under the modified law would not have to undergo the same stress tests as banks that hold more than $250 billion in assets. These rules are intended to prevent another financial meltdown, but opponents have said the rules are too cumbersome for smaller institutions and that the new changes will help regional banks be more competitive by making it easier for them to lend money.

Absent of this recent rollback is any change to UDAAP. That means the CFPB still has the authority to go after unfair and deceptive practices, which are defined as ones that harm consumers financially and that consumers cannot reasonably avoid. The greater risk to UDAAP enforcement lies is within the bureau itself, with leader Mick Mulvaney. The CFPB Director has stated that the bureau is not particularly interested in pursuing UDAAP violations.

Does this mean payment facilitators shouldn't be concerned about merchants engaged in unfair or deceptive practices? Not so fast. Despite Mulvaney's statements, the CFPB last month slapped Wells Fargo with a whopping $1 billion UDAAP fine - 10 times bigger than the previous largest assessed in the bureau's history. The bank was found to have forcibly enrolled hundreds of thousands of borrowers in duplicative or unnecessary automobile insurance policies. The Wells Fargo fine, as well as a recent lead generation case the CFPB is aggressively pursuing, suggest that UDAAP still has teeth.

Regardless of government approaches to UDAAP enforcement, payment facilitators should remain wary of merchants offering high-risk services such as credit repair, debt collection, payday lending, lead generation sales, and extended warranties, as these merchants can still prompt steep card brand fines if they are found to be engaging in UDAAP violations. There are several steps payment processors and acquirers can take to avoid UDAAP violations and accompanying fines. These include:

    • Properly responding to consumer complaints

 

    • Performing internal policy audits

 

    • Educating staff

 

    • Practicing proper underwriting

 

    • Reviewing existing UDAAP policies

 

Most important, consistent merchant monitoring is a valuable tool for identifying and avoiding UDAAP violations.

For more information on these high-risk areas, get our UDAAP guide.

 

David Khalaf is a writing, communications, and marketing professional with specialties in media, investigations, content strategy, and writing instruction. His 20 years of writing, media, and communications work have included two top-tier universities (USC and UCLA), print and digital magazines, consulting firms, and technology companies.

His current work involves content strategy and development at LegitScript, a company that helps the world's leading search engines, payment service providers, and internet platforms and marketplaces do business with legitimate, legally operating entities in more than 80 countries and 15 languages around the world. LegitScript specializes in risk and compliance for highly regulated industries including CBD/cannabis, online gambling, cryptocurrencies, drugs, financial trading, online adult, scams and fraud, and more.

Recent Blog Articles

Where Policy Meets Performance: Winning in Healthcare Advertising Post-Certification

Why LegitScript Certification Matters for Healthcare Advertising For many healthcare providers, earning LegitScript Certification is a major milestone. It's the key that unlocks advertising on platforms like Google and Meta, two of the most powerful digital channels for reaching patients. Certificat...

Key Takeaways from the 2025 Marketplace Risk New York Conference

The 2025 Marketplace Risk New York Conference proved that marketplaces and platforms are no longer simply about connecting buyers and sellers. They are about creating safe, trusted environments where commerce can thrive. For trust and safety, compliance, legal, and product professionals, the message...

Why the Next 6 Months Will Redefine Merchant Risk Management

Two deadlines. One turning point. On October 1, 2025, enforcement begins on the Visa Acquirer Monitoring Program (VAMP). Just three months later, on January 1, 2026, Mastercard's Merchant Monitoring Program (MMP) revised standards take effect. Together, these updates mark one of the most significant...

Maverick Payments and LegitScript Weigh in on AI’s Growing Role in Payments

Artificial intelligence (AI) may be one of the hottest topics in payment processing, but industry leaders say its role in payments is an opportunity that requires a thoughtful approach and critical thinking. That was the central theme of LegitScript's recent webinar, "Maverick Payments on What AI Re...