I’m thrilled to announce that Frost Echols is the new sponsor for the Compliance Digest. Frost Echols reputation has been built on aggressively protecting the rights of businesses throughout our local jurisdictions. Founding partners, Mike Frost and Chad Echols, developed a deep understanding of regulatory compliance, commercial litigation and business operations through years of advising executives in the collection industry. We are committed to a strategic, economic, and aggressive approach to your legal representation.

Every week, AccountsRecovery.net brings you the most important news in the industry. But, with compliance-related articles, context is king. That’s why the brightest and most knowledgable compliance experts are sought to offer their perspectives and insights into the most important news of the day. Read on to hear what the experts have to say this week.
Did the Letter Get Sent? Court Orders Discovery in FCRA Mailing Case
A District Court judge in Ohio has denied a defendant’s motion to dismiss claims it violated the Fair Credit Reporting Act in a he-said, she-said case over whether the defendant mailed a copy of the plaintiff’s consumer file after she requested it. The decision is notable for how it handles a recurring operational question for consumer reporting agencies and furnishers alike: is proof of mailing enough to satisfy FCRA disclosure obligations, even if the consumer says they never received anything? The court said yes on the legal question. But on the facts, it said it is simply too early to decide. More details here.
WHAT THIS MEANS, FROM CHAD ECHOLS OF FROST ECHOLS: The key takeaway for creditors, CRAs, and collection agency furnishers is that this decision provides a favorable legal framework by confirming that under §1681g, proof of proper mailing of a disclosure satisfies the statutory obligation even absent proof of actual receipt, but it underscores that legal correctness does not necessarily equate to early case dismissal. Despite agreeing with the defense position on the law, the Court denied dispositive relief because of a narrow factual dispute over whether the disclosure was mailed. Denying the motion allows limited discovery to proceed. Discovery and the procedural requirement to win via a motion for summary judgment is the real exposure point for the industry. When plaintiffs can survive early motions simply by disputing receipt, it opens the door to document requests, depositions on mailing practices, and internal procedures, all of which impose cost, disruption, and risk.
In practical terms, discovery and the associated costs often create settlement leverage for consumers even in cases where liability is ultimately unlikely. Accordingly, industry participants should view this ruling as both a doctrinal win and an operational warning that robust, well-documented mailing procedures (including audit trails, logs, or ideally some provable verification) are essential not just for ultimate liability defenses, but to position cases for early resolution and avoid being forced into cost-driven settlements due to the burdens of discovery.
THE COMPLIANCE DIGEST IS SPONSORED BY:
How ChatGPT Is Quietly Reshaping Consumer Complaints and Outcomes
This report is from last year and I don’t think I’ve written about it yet, and The Wall Street Journal last week ran an article from one of the report’s authors that resurfaced it, so I wanted to either write about it again or write about for the first time because it’s interesting that artificial intelligence may help consumers get better results when complaining, especially with regulators like the Consumer Financial Protection Bureau. More details here.
WHAT THIS MEANS, FROM STEFANIE JACKMAN OF TROUTMAN PEPPER LOCKE: As consumers increasingly use AI tools to draft more precise complaints, companies that deploy AI on their end are better positioned to identify legitimate grievances and respond with appropriate resolutions. However, automating complaint responses also risks stripping away the human judgment needed to recognize nuanced or vulnerable consumer situations. As a result, a company may believe it is being appropriately responsive and sensitive to a consumer’s situation, only to discover that it is not delivering the level of meaningful relief it intended. To ensure AI is used fairly and transparently, companies should establish clear human review protocols for complaints flagged as complex or high-stakes, and regularly audit their AI systems for patterns of denial or deflection that may signal bias or systemic unfairness. Companies should also be transparent with consumers about when and how AI is being used in the complaint process, and maintain accessible pathways to human representatives for those who request them. Ultimately, AI should be deployed as a tool to enhance fairness and efficiency, but not to replace the accountability that consumers and regulators increasingly expect.
In addition, if employees use open-access AI tools to research legal requirements in connection with evaluating consumer complaints and disputes, any analysis or conclusions generated may not be protected by the attorney-client privilege or the work-product doctrine, creating a significant risk that such communications and outputs could be discoverable in subsequent litigation or regulatory proceedings. Companies should establish clear protocols requiring that any AI-assisted legal research and analysis performed in the complaint management context be conducted under the direct supervision and direction of counsel, ensuring that the privileged nature of the inquiry is established and preserved from the outset.
Court Finds Continued Texts After Opt-Out Violated FDCPA, Rejects BFE Defense
A District Court judge in Pennsylvania has granted a plaintiff’s motion for summary judgment in a Fair Debt Collection Practices Act class-action lawsuit that accused the defendant of failing to stop sending text messages after the plaintiff opted out of receiving messages. More details here.
WHAT THIS MEANS, FROM LAUREN BURNETTE OF MESSER STRICKLER BURNETTE: A couple things to keep in mind as you digest this opinion: first, remember that this is largely the Plaintiff’s version of the facts, since Plaintiff’s facts were deemed unopposed. Put another way, this opinion might not tell the whole evidentiary story. Second, the only arguments considered were the ones Plaintiff presented to the Court, with no counter-argument from the Defendant. So fear not as you see the outcome of the case—nobody likes to lose, but the opinion only tells one party’s story. All that said, there are other, more helpful lessons to take from this opinion. This is a good reminder that outsourcing a business practice like texting doesn’t mean you are likewise outsourcing your text-related compliance obligations. It’s also not enough to write a policy requiring ongoing due diligence with the texting vendor if you never put that policy into practice. If you want to use the bona fide error defense to excuse liability, you have to be prepared to show the judge that your procedures don’t just exist on paper.
FDCPA Exposure in Foreclosure Action Gets Fresh Look from Eighth Circuit
The Court of Appeals for the Eighth Circuit has vacated a lower court’s dismissal of a Fair Debt Collection Practices Act claim against a collection law firm because it allegedly never sent the plaintiff the payoff request that she provided. The decision sends the case back for further proceedings and highlights a nuanced and unresolved issue for collection attorneys and servicers: when a failure to comply with state foreclosure requirements may also trigger liability under the FDCPA. More details here.
WHAT THIS MEANS, FROM XERXES MARTIN OF MARTIN GOLDEN LYONS WATTS MORGAN: In Fiecke-Stifter v. MidCountry Bank, the Eighth Circuit reviewed two dismissed claims arising from a mortgage foreclosure, a Truth in Lending Act Claim (“TILA”) against the bank, and a Fair Debt Collection Practices Act (“FDCPA”) claim against the bank’s law firm. The Court affirmed the dismissal of the TILA claim stating plaintiff was trying to add restrictions to the TILA that did not exist. However , the Court reversed the FDCPA dismissal finding that the plaintiff plausibly alleged the law firm may have foreclosed on the property without a “present right to possession” under Minnesota law because it failed to provide a requested payoff/reinstatement amount before the foreclosure sale.
FDCPA section 1692f(6)(A) prohibits a security-interest enforcer from taking “any nonjudicial action” to dispossess property without a “present right to possession” of the property claimed as collateral through an enforceable security interest, but then you have to look to state specific law to determine the right to foreclose.
The Eighth Circuit churned through Minnesota foreclosure law and specifically looked at whether violation of a specific Minnesota statute affected the “present right to possession”, which is an unsettled issue. Since the district court did not analyze whether Minnesota’s reinstatement and timely notice statute’s application to a “present right to possession” and the FDCPA, it vacated the dismissal and remanded for more thorough briefing and analysis. The case highlights importance of making sure all statutory requirements are performed and recorded when conducting collection or foreclosure activity.
Illinois Appeals Court Rejects FDCPA Claims Over ‘Blank’ Summons in Collection Case
An Illinois Appeals Court has upheld a ruling in favor of a bank and a collection law firm that were accused in class-action counterclaims of violating the Fair Debt Collection Practices Act by serving the plaintiff with a blank summons in an underlying collection lawsuit. More details here.
WHAT THIS MEANS, FROM JESSICA KLANDER OF BASSFORD REMELE: TD Bank USA v. Dandridge is a helpful reminder that minor technical or formatting issues don’t create liability when the key information is still clearly provided. The court made clear that under the unsophisticated consumer standard, FDCPA claims require something actually misleading or contradictory—not just missing or repeated information across pages. It also reinforces the value of relying on court–approved or regulator-generated forms to guard against unsupported claims. Just as importantly, it shows how effective early dispositive motions can be in knocking out both individual claims and potential class exposure at the pleading stage.
Oklahoma Enacts Comprehensive Data Privacy Law
Oklahoma has joined the growing list of states passing comprehensive consumer data privacy legislation, creating new compliance considerations for companies that collect, process, or rely on consumer data as part of their operations. The newly enacted law establishes a framework that grants consumers expanded control over their personal data while placing new obligations on businesses that meet certain thresholds. More details here.
WHAT THIS MEANS, FROM LESLIE BENDER OF EVERSHEDS SUTHERLAND: Oklahoma is the 21st state to enact a comprehensive consumer data privacy law. Its law, a business-friendly version like Virginia’s, takes effect on January 1, 2027, giving businesses time to prepare. It gives Oklahoma residents new rights over their personal information and imposes clear obligations on companies that collect and use it.
Who Does It Apply To?
The law applies to controllers and processors who conduct business in Oklahoma or produce a product or service targeted to Oklahoma residents, and who meet at least one of these thresholds:
- Process personal data of at least 100,000 consumers per year, or
- Process personal data of at least 25,000 consumers and derive over 50% of gross revenue from selling that data.
Under Oklahoma’s law, a controller is a company that decides why and how your data is used, and a processor is a vendor or service provider that handles the data on a controller’s behalf.
Who Is Exempt?
The law generally does not apply to state agencies, financial institutions covered by federal banking law (or data subject to Title V of the GLBA), HIPAA-covered health entities and their business associates, nonprofit organizations, institutions of higher education, personal data collected and used for purposes of federal policy under the Controlled Substances Act, or individuals acting purely in a personal or household capacity. Like other state privacy laws, this law includes certain exemptions for individuals acting in commercial and employment contexts.
Your Rights as a Consumer
A consumer may exercise their rights at any time by submitting a request to a controller specifying what rights they wish to exercise. Parents or legal guardians may act on behalf of their children. The core rights accorded consumers are:
- Access: Confirm whether a company is processing your data and access that data.
- Correction: Correct inaccuracies in your personal data.
- Deletion: Delete personal data provided by or obtained about you.
- Portability: Obtain a copy of your data in a portable, usable format so you can transfer it to another company.
- Opt-out: Opt out of targeted advertising, the sale of your personal data, or automated profiling that leads to significant decisions affecting things like loans, housing, employment, or insurance.
Importantly, any contract that waives or limits these consumer rights is void and unenforceable.
Business Obligations
- Privacy Notice: Companies must provide a clear, accessible privacy notice disclosing the categories of personal data they process (including sensitive data), the purpose of that processing, how consumers can exercise their rights, and what data is shared with third parties and who those parties are.
- Request Handling: Businesses must respond to consumer requests within 45 days, with a possible 45-day extension when reasonably necessary, provided the consumer is notified within the initial period. Responses must be provided free of charge up to twice per year per consumer. Companies cannot require a consumer to create a new account to exercise their rights.
- Appeal Process: If a business denies a request, it must offer a conspicuous and easy-to-use appeal process. The business must respond to any appeal in writing within 60 days and, if the appeal is denied, direct the consumer to the Attorney General’s complaint mechanism.
- Data Minimization and Security: Businesses must limit data collection to what is adequate, relevant, and reasonably necessary for the disclosed purpose. They must also maintain reasonable security practices appropriate to the volume and nature of the data.
- Sensitive Data Requires Consent: A company cannot process sensitive data — such as health information, biometrics, precise location, or data about children — without the consumer’s consent, or, for children’s data, without complying with COPPA. Sensitive data includes racial or ethnic origin, religious beliefs, health diagnoses, sexual orientation, genetic or biometric identifiers, and precise location.
- Data Protection Assessments: Companies must document internal risk reviews — called data protection assessments — for higher-risk activities, including targeted advertising, selling personal data, certain profiling, processing sensitive data, and any activity presenting a heightened risk of consumer harm. These assessments are only required for processing activities that begin on or after the law’s effective date — they are not retroactive.
Enforcement
The Attorney General has exclusive authority to enforce the law. There is no private right of action — individual consumers cannot sue businesses directly.
Cure Period: Before filing suit, the Attorney General must give the business 30 days’ written notice of the alleged violation. If the business cures the problem within that period and provides a written statement confirming the cure and that they are not committing any further violations, no action may be taken.
Penalties: A business that violates the law after the cure period — or breaks a written commitment made to the Attorney General — can face a civil penalty of up to $7,500 per violation. The court may also award the Attorney General’s reasonable legal fees and investigative expenses.
Key Exemptions
Beyond exempt entities, certain categories of data also fall outside the law’s reach, regardless of who holds them, including protected health information under HIPAA and health records; data regulated by the Fair Credit Reporting Act; student data covered by FERPA; and employment-related data collected and used within that employment context. A business that complies with COPPA’s verified parental consent requirements for data collected online is considered compliant with this law’s parental consent obligations.
Frost Echols reputation has been built on aggressively protecting the rights of businesses throughout our local jurisdictions. Founding partners, Mike Frost and Chad Echols, developed a deep understanding of regulatory compliance, commercial litigation and business operations through years of advising executives in the collection industry. We are committed to a strategic, economic, and aggressive approach to your legal representation.










