Vendors need to be held to a higher standard on privacy

Vendors need to be held to a higher standard on privacy
Advisory firms should perform due diligence on how all their providers safeguard clients' personal information, including custodians, software and back-office services.
JUL 25, 2019

Not that long ago, keeping clients' data secure was easy. It merely required a lock and key. Now, with third-party providers, remote access and the use of internet platforms, keeping clients' personally identifiable information private is much more complicated — and vulnerable. As cyber breaches occur on a regular basis (for example, Equifax, Yahoo, Marriott and Redtail), the risk to client data is increasing. (More: Redtail isn't the only firm with cybersecurity issues) Beyond data theft, we must determine how personal and financial data is used by third-party vendors. Are those third parties sharing information with their affiliated companies or profiting by selling it to others? As advisers, we must be informed about the policies, procedures and culture of every person and entity that has access to client data. In fact, I believe it is our fiduciary duty. A recent New York Times series on privacy noted that "platforms are under no obligation to protect user privacy. They are free to directly monetize the information they gather by selling it to the highest bidder." (More: Ask these cybersecurity questions) Data privacy is described in vendors' privacy policies. Yet how many of us actually read them? Some are very straightforward, while others are not. Envestnet Tamarac, one of the industry's leading providers, will not only share aggregated data with outside companies, it will also share your contact information and sell client results through its aggregator entity to others. Here's an example: Envestnet Tamarac "collects information about you ... information included on your Client Profile and related forms — such as name, address, Social Security number, date of birth, assets and income — along with personal information about your account activity, including your transactions, balances, positions and history. For financial professionals utilizing our technology platform, [the firm] may make available your business contact information and information regarding the use of their investment strategies to third-party investment managers and exchange-traded funds, mutual funds, and similar investment vehicles." So is your client data truly private and secure? Does it matter to you? To your clients? At what point will you discontinue doing business with a provider? Is sharing information with affiliated companies for marketing purposes OK? How about for joint marketing with non-related financial companies? Is it OK for your provider to distribute or sell "aggregated data?" I believe advisers need to update internal policies about what we consider to be permissible use of our clients' data. For me, the line stops at anything beyond sharing information with corporate affiliates for marketing purposes. It is up to us to collectively take a stand to bring the changes our clients and our businesses deserve. (More: 10 trends in cybersecurity you need to know)​ We should perform due diligence on all providers, including custodians, software and back-office services. I suggest utilizing a checklist addressing business continuity plans, compliance documentation, privacy policies, cybersecurity protections, background checks on employees and more. Finally, clients are hearing about — and experiencing — cybercrime, data breaches and invasions of privacy. One thing is universally true: Clients are concerned. Telling your clients how you protect their data is not only important, it can help build trust and enhance client relationships So please take this approach — you'll be glad you did. (More: 4 top surprises from the new tax law) Sheryl Rowling is head of rebalancing solutions at Morningstar Inc. and principal at Rowling & Associates.

Latest News

SEC kills 'gag rule' that silenced thousands of settling defendants for over 50 years
SEC kills 'gag rule' that silenced thousands of settling defendants for over 50 years

ASA reacts as regulator drops no-deny policy, freeing firms and individuals to publicly dispute allegations after reaching settlements.

Washington state regulators claim advisor was running Ponzi-like fund
Washington state regulators claim advisor was running Ponzi-like fund

Joel Frank allegedly sold more than $39 million worth of investments in the Equilus Funds to more than 90 investors,

Bipartisan bill aims to take down 401(k) charitable giving hurdle
Bipartisan bill aims to take down 401(k) charitable giving hurdle

The Charity Parity Act would eliminate a costly IRA rollover requirement that blocks direct charitable transfers from workplace retirement plans.

Trump drops $10 billion IRS lawsuit as $1.7B settlement fund takes shape
Trump drops $10 billion IRS lawsuit as $1.7B settlement fund takes shape

A last-minute court filing ends a case against the federal tax-collecting agency that had drawn unprecedented conflict-of-interest questions from Democratic critics.

You Can’t Spell Advisor without AI
You Can’t Spell Advisor without AI

Advisors discuss their use of AI now and how it will change going forward

SPONSORED Beyond wealth management: Why the future of advice is becoming more human

As technical expertise becomes increasingly commoditized, advisors who can integrate strategy, relationships, and specialized expertise into a cohesive client experience will define the next era of wealth management

SPONSORED Durability over scale: What actually defines a great advisory firm

Growth may get the headlines, but in my experience, longevity is earned through structure, culture, and discipline