Bank agrees to cease performing credit checks on individuals who are no longer clients

Early resolved case summary #2017-003

July 5, 2017


Lessons Learned

  • Organizations seeking to collect and use personal information after the termination of a business relationship with an individual should engage in a careful analysis of the purposes for such continued collection and use, the form of consent required and the sensitivity of the personal information continuing to be collected and used.
  • Organizations should make reasonable efforts to provide complete and accurate information to individuals inquiring about the organization’s personal information handling practices to ensure that accurate and complete information is provided to the individual in response to their inquiries.

Complaint

An individual alleged that a bank performed several credit checks on her without her consent over several years. She accessed her credit report from a credit reporting agency and noticed that the bank had performed close to 15 credit inquiries on her file. The individual was shocked because she had not been a customer of the bank for many years. She asked the bank to explain the reason the checks were performed and to identify the consent relied upon to do so. The bank responded that the inquiries originated from its marketing group and informed the complainant that they were not visible to organizations requesting her credit report, but only appeared on the report she requested personally. Unsatisfied with the response from the bank, the individual filed a complaint with our office, seeking answers to her questions, an apology and reassurance that the credit checks would no longer continue.

Summary of Investigation

Our office communicated with the bank in the context of its early resolution process. The bank’s internal investigation revealed that the marketing department was not the source of the credit inquiries. In fact, the individual had applied for a credit card and an online investment account with the bank in 2013, but the services were never activated and were subsequently closed. Still, the bank continued to perform soft credit inquiries on the complainant’s credit file at different points in time.

The bank pointed out that its privacy policy indicated that a credit check will be done upon registering for a credit product to determine the credit worthiness of the individual, and that upon the service ending, the bank retained the ability to perform credit inquiries. The policy also noted that should the customer wish for this activity to stop, they could withdraw their consent at any point in time, as long as reasonable notice was provided. The bank also advised that the credit inquiries were ‘soft hits’, meaning that they had no impact on the customer’s credit rating. In addition, the bank indicated that once the customer requested the credit inquiries stop, the credit inquiries stopped.

Outcome

Generally, once a relationship between an individual and an organization ends, an organization must carefully analyze its continuing need to collect and use the individual’s personal information, for example, based on legal requirements to do so. In the specific circumstances of this complaint, our office expressed concerns over the fact that the bank engaged in the collection of the customer’s sensitive credit-related information, even after the termination of a business relationship with a customer and where there was no legal requirement to do so.

Once our office outlined these concerns and in an effort to resolve this complaint, the bank agreed to end this practice and update its privacy policy accordingly. The individual was satisfied with the measures being taken by the bank in response to her complaint and considered the matter early resolved.

Update: As a result of this commitment from the bank, our office followed up and has confirmed that the practice has ended and its privacy policy has been updated to reflect this.

Report a problem or mistake on this page
Please select all that apply (required): Error 1: This field is required.

Note

Date modified: