2018

Following closely on the heels of the EU’s General Data Protection Regulation (GDPR), California recently enacted its own consumer privacy law called the California Consumer Privacy Act of 2018 (CCPA).

The law, which requires protection of personal information of California residents, was passed in June and then amended in late September. Merchants and payment processors will be affected by the CCPA, even those that are not based in California. Businesses will need to think closely about what types of data they collect and how they store and transmit such data. They will also need to establish processes for dealing with consumer requests.

In March 2017, the United States Supreme Court issued its opinion in Expressions Hair Design v. Schneiderman, on a challenge to New York’s law prohibiting credit card surcharges. The Supreme Court held that the law restricts merchants’ speech by banning surcharges while allowing cash discounts—two similar business models that differ only by how a merchant’s pricing can be communicated to customers—and then sent the case back down for the lower court to determine whether this particular speech restriction is lawful or not. This case remains pending (the New York state court was consulted to interpret the state statute, and we are still awaiting its response), but other federal courts have already relied on this decision to invalidate equivalent laws in other states.

It’s hard to be a cash-only business, especially when businesses are expected as a matter of course to accept credit and debit cards. But processing fees can make merchants hesitant to sign up for transaction processing services, and many payment processors want to offer merchants the ability to pass processing costs through to the customer. There are several ways these programs can be structured, each subject to a different regulatory framework.

On December 13, 2017, the United States Court of Appeals for the Eleventh Circuit held that an independent sales organization can be held liable for all damages suffered by consumers as a result of a merchant’s violation of the Telemarketing Sales Rule (“TSR”).  The court rejected the ISO’s argument that its liability should be limited to the fees it received from the merchants as a result of the merchants’ processing activities.

On January 4, 2018, U.S. Attorney General Sessions formally rescinded guidance issued by the Department of Justice (DOJ) during the Obama administration related to the DOJ’s approach to the enforcement of state-legalized marijuana activity.   Sessions replaced the former guidance by issuing a memo (“Sessions Memo”) that instructs U.S. Attorneys to “follow the well-established principles that govern all federal prosecutions” when determining which marijuana activities to prosecute.