Photo of Jon Sriro

Jon Sriro

Jon is a member of Taft’s Privacy and Data Security and Paytech and Payment Systems practices and is a CIPP/US-certified attorney. He advises clients on technology transactions, data privacy and cybersecurity, and AI governance, with experience spanning SaaS and cloud agreements, regulatory compliance (including GDPR and CCPA), and complex data issues across a range of industries.

Many companies negotiate contracts containing merchant of record designations without fully appreciating the significance of that designation from a privacy and data security perspective.

For purposes of this article, the merchant of record is the party that both contracts directly with the payment processor and holds the direct consumer relationship for the transaction. The MoR is the business the consumer knows, interacts with, and sees on the cardholder billing statement. This is the traditional direct-merchant model, distinct from platform arrangements
Continue Reading The Merchant of Record (MoR) Designation Has Significant Privacy and Data Security Implications

On October 22, 2024, the Consumer Financial Protection Bureau (CFPB) finalized its long-awaited rule on Personal Financial Data Rights (referred to herein as the “Open Banking Rule”).

The Open Banking Rule requires banks, credit unions, and other financial service providers to make available consumers’ data upon request to those consumers or other third parties designated by such consumers. The rule is issued to implement the personal financial data rights established by the Consumer Financial Protection Act of 2010 (“CFPA”).  In
Continue Reading Open Banking: Final Personal Financial Data Rights Rule