Alston & Bird Consumer Finance Blog

Mergers & Acquisitions

NYDFS Issues Guidance on Managing Risks Related to Third-Party Service Providers

On October 21, 2025, the New York Department of Financial Services (“NYDFS”) published an Industry Letter (the “Letter”) outlining guidance on managing risks related to third-party service providers (“TPSPs”). NYDFS recognizes that as covered entities become more reliant on TPSPs, managing TPSPs “remains a crucial element of a Covered Entity’s cybersecurity program.” The Letter outlines the actions and advice Covered Entities should take while progressing through the lifecycle of a TPSP relationship: (1) Identification, Due Diligence, and Selection; (2) Contracting; (3) Ongoing Monitoring and Oversight; and (4) Termination. While the Letter expressly states it does not impose new requirements or obligations on Covered Entities, but rather, intended to clarify Part 500 (specifically 500.11) and recommend best practices, the prescriptive guidance may in practice be considered the operative benchmark for certain (or many) Covered Entities.

Identification, Due Diligence, and Selection

Due to the increased risks associated with TPSP relationships, Covered Entities may wish to exercise caution and diligence before entering into any arrangement with a TPSP. Accordingly, the Letter outlines a non-exhaustive list of considerations for conducting due diligence on TPSPs. A few of those considerations include:

  • The type and extent of the TPSPs access to information systems and nonpublic information (“NPI”);
  • The TPSPs reputation within the industry, including its cybersecurity history and financial stability;
  • The controls the TPSP has implemented for its own systems and data, particularly if the Covered Entity’s systems are not fully segregated;
  • Whether the TPSP undergoes external audits and independent assessments;
  • The TPSPs practices for selecting, monitoring, and contracting with downstream service providers; and
  • Whether the TPSP, its affiliates, or vendors operate in or from jurisdictions considered high-risk due to geopolitical, legal, socio-economic, operational, or regulatory factors.

In addition to the above considerations, the Letter emphasizes that Covered Entities should consider how to best obtain, review, and validate information provided by prospective TPSPs. Although standardized questionnaires may facilitate the process of gathering the required information from the TPSPs, Covered Entities must ensure that those questionnaires are interpreted by qualified personnel to allow for proper risk-informed decisions to be made. In other words, vendor due diligence questionnaires are not a “check-the-box” requirement; the completed questionnaires must be carefully evaluated by qualified personnel and actioned appropriately. Additionally, if there are limited vendor options, Covered Entities should make risk-informed decisions, document the relevant risks, and take steps to implement compensating controls.

Contracting

Covered Entities that utilize TPSPs are required to develop and implement written policies and procedures that address due diligence and contractual protections. In the Letter, NYDFS provides a few examples of “baseline contract[al] provisions” that Covered Entities should consider incorporating into agreements with a TPSP. Some of the provisions include:

  • Develop and implement policies and procedures addressing access controls;
  • Develop and implement policies and procedures addressing encryption in transit and at rest;
  • Provide immediate or timely notice to the Covered Entity upon occurrence of a Cybersecurity Event directly impacting the Covered Entity’s information;
  • Require TPSPs to disclose where data may be stored, processed, or accessed; and
  • Require TPSPs to disclose the use of subcontractors and allow the Covered Entity to reject the use of certain subcontractors, which essentially allows Covered Entities the ability to control the use of Fourth Parties, somewhat akin to GDPR.

In addition to the above provisions, the Letter reinforces similar guidance that NYDFS provided in 2024, which we previously covered, in regard to inserting provisions in TPSP agreements that relate to the acceptable use of Artificial Intelligence (“AI”) products.

NYDFS clarified that the list provided in the Letter is neither exhaustive nor appropriate in all situations, but Covered Entities should continue to seek “reasonable protections, such as breach notification clauses, data use, and assurances regarding access controls and data handling.” Further, Covered entities should develop medium- to- long-term strategies to reduce its overall dependency on TPSPs.

Ongoing Monitoring and Oversight

A Covered Entity that utilizes a TPSP must have policies in place addressing the periodic assessment of TPSPs based on the risk that each “TPSP presents and the continued adequacy of [the TPSPs] cybersecurity practices.” The assessments conducted by Covered Entities may include obtaining security attestations from the TPSPs (e.g., SOC2, ISO 27001) and requiring penetration testing summaries, policy updates, evidence of security awareness training and proof of compliance audits.

In addition to the periodic assessments, Covered Entities should request updates on a TPSPs vulnerability management, assess patching practices, and confirm remediation of previously identified deficiencies. Although it may be an extensive exercise for Covered Entities, the Letter indicates that Covered Entities should document material or unresolved risks identified and escalate the risks as appropriate.

Termination

When a Covered Entity terminates its relationship with a TPSP, there are actions the Covered Entity should take to mitigate any potential risks from arising. Some of the actions the Letter outlines are prescriptive, including:

  • Revoking identity federation tools, API integrations, and external storage access;
  • Requiring certification of destruction of NPI, secure return of data, or migration of data to another TPSP or internal environment;
  • Confirming that any remaining snapshots, backups, or cached datasets are deleted and access to any shared resources is revoked;
  • Giving special attention to residual or unmonitored access points that fall outside routine access provisioning systems; and
  • Engaging keys take holders, including IT, legal, compliance, procurement, and business units to identify strategies to mitigate potential risks when planning to terminate.

Notably, in addition to the above actions a Covered Entity should take during the termination period, Covered Entities should ensure the offboarding process is properly documented and all relevant audit logs are retained to support accountability and future verifications.

NYDFS made it clear that it will continue to “consider the absence of appropriate TPSP risk management practices by Covered Entities in its examinations, investigations, and enforcement actions.” As such, although the Letter does not formally impose any new requirements for Covered Entities, Covered Entities are strongly encouraged to review the Letter and implement the practices identified by NYDFS to strengthen their cybersecurity posture.


This post was originally published on Alston & Bird’s Privacy, Cyber & Data Strategy Blog on October 27, 2025.


Labor & Employment Advisory | Employment Laws Coming to California in 2026

Originally published November 11, 2025 on the Alston & Bird website.

Executive Summary

As the end of 2025 approaches, our Labor & Employment Group highlights and summarizes new employment laws taking effect in California beginning in 2026.

  • Notice and reporting requirements for workers’ rights, Cal-WARN notices, and data breaches will be updated
  • The state labor board will step in when the National Labor Relations Board “expressly or impliedly ceded jurisdiction,” though litigation may derail the state law
  • Rehire and retention protections for workers stemming from the COVID-19 pandemic have been extended to 2027

The new year will bring new employment laws to California’s books. Employers should be aware of these new laws to ensure compliance in the coming year and beyond.

Pay Equity

Equal Pay Act Reforms – SB 642

An amendment to California’s Equal Pay Act, SB 642 expands the definition of wages to include benefits and non-salary compensation, extends the statute of limitations and recovery period for pay equity violations, and adds protections for nonbinary employees. Taking effect January 1, 2026, the law also imposes stricter pay scale requirements in job postings to promote greater pay transparency and prevent employers from undercutting the requirement with speculative pay ranges.

For a more in-depth analysis on changes to California’s pay equity protections, see here.

New Pay Data Reporting Requirements and Mandatory Penalties – SB 464

Starting January 1, 2027, employers with 100 or more employees and are required to submit annual demographic pay data reports to the Civil Rights Department (CRD) will now have to do so for 23 specified job categories—up from 10.

Current law allows courts to impose civil penalties on employers that fail to comply with pay data reporting requirements. Under the new law, these penalties are mandatory upon request by the CRD.

Notice and Reporting Requirements

Know Your Rights Act for California Workplaces – SB 294

Under the new Workplace Know Your Rights Act, on or before February 1, 2026, and annually thereafter, employers must provide written notice to all employees of various labor rights, including rights to workers’ compensation benefits, constitutional rights when interacting with law enforcement in the workplace, and protection against unfair immigration-related practices such as notice of immigration inspections. The labor commissioner is tasked with publishing a compliant notice on or before the first of the year.

Employers must also notify an employee’s designated emergency contact if the employee is arrested or detained on the worksite or while performing job duties.

Penalties include up to $500 per employee for failing to provide Workplace Know Your Rights notices and a daily $500 penalty, capped at $10,000, for not notifying emergency contacts of an arrest or detainment.

Updated Cal-WARN Notice Requirements – SB 617

California’s Worker Adjustment and Retraining Notification (Cal-WARN) notices for mass layoffs, terminations, or relocations must also include information on CalFresh food assistance programs and any workforce development boards or entities the employer will coordinate services through, starting January 1, 2026.

For a more in-depth analysis on the new Cal-WARN notice requirements, see here.

New 30-Day Data Breach Disclosure – SB 446

Starting January 1, 2026, businesses must notify consumers of data breaches within 30 days of discovery or notification of the breach and disclose large data breaches affecting more than 500 California residents to the state attorney general within 15 days. While SB 446 replaces the current flexible timelines with a strict 30-day breach notification rule, exceptions apply for legitimate law enforcement needs or as necessary to determine the scope of the breach and restore the reasonable integrity of the data system.

Signed into law this October, businesses have only a few months to review and update incident response and notification procedures to comply with the new statutory timeframe.

Wage and Labor Disputes

Expanding the Jurisdiction of California’s Labor Board – AB 288*

As the National Labor Relations Board (NLRB) continues without quorum to decide labor cases before it after President Trump’s firing of Chair Gwynne Wilcox, AB 288 expands the jurisdiction of California’s Public Employment Relations Board (PERB) to covered private sector employees who petition to enforce their rights under the National Labor Relations Act (NLRA).

Set to take effect January 1, 2026 with a phased rollout through January 1, 2027, the law will permit California’s public sector labor agency to investigate and decide labor disputes and alleged unfair practices cases and oversee union elections in the private sector if the NLRB has “expressly or impliedly ceded jurisdiction.”

*Subject to ongoing litigation: On October 15, 2025, just two weeks after AB 288 was signed into law, the NLRB filed a lawsuit against PERB and the State of California alleging AB 288 is unconstitutional and preempted by the NLRA. It is unclear whether AB 288 will survive the NLRB’s attempt to block the law from going into effect next year.

Increased Enforcement of Wage Laws – SB 261

In addition to expanded workplace regulations, employers will also be met with greater penalties for failing to satisfy employee wage judgments. Effective January 1, 2026, employers that fail to pay wage-related judgments within 180 days will face mandatory court costs and attorneys’ fees, penalties up to triple the outstanding judgment amount, and enforcement by public prosecutors permitted to stand in as assignees of employees with unpaid wage judgments.

Employers should audit procedures to resolve unpaid wage judgments within the 180-day satisfaction period to avoid heavy penalties under the new law.

Contracts and Employee Benefits

An End to “Stay or Pay” Contracts – AB 692

AB 692 makes “stay or pay” contracts entered into on or after January 1, 2026 illegal in California. An extension of the prohibition on noncompete contracts, this law prohibits employers from requiring employees to pay certain penalties, fees, or costs if they leave their employment before a set minimum work period. The ban applies to the common use of training-repayment agreement provisions but provides exceptions for separate agreements covering signing bonuses or tuition reimbursements.

Employers should make sure to review employment contracts before the law goes into effect. Violations allow employees to sue for the greater of actual damages or $5,000 plus attorneys’ fees and costs.

Expanded Paid Family Leave for “Designated Persons” – SB 590

Beginning July 1, 2028, workers can take up to eight weeks of paid family leave to care for a designated person, identified under penalty of perjury and attesting to the qualifying relationship.

This law expands eligibility under the existing paid family leave progam to workers who take time off to care for seriously ill “designated persons,” defined as “any care recipient related by blood or whose association with the individual is the equivalent of a family relationship.”

AI Regulation and Extended COVID Protections

Transparency in Frontier AI Act – SB 53

As the first law of its kind, SB 53 attempts to directly regulate the development of artificial intelligence (AI) by establishing mandatory safety incident reporting and requiring large developers of “frontier” AI models to publish and maintain a framework of safety protocols, risk assessment, and management practices. Noncompliance carries civil penalties of up to $1 million per violation.

The oversight and regulation of these large AI models is likely to impact the companies that use them. The law also provides whistleblower protections for employees who report violations or safety threats. Developers are prohibited from enforcing nondisclosure agreements or retaliating against employees who raise these concerns, and they must establish an internal anonymous reporting process.

For a more in-depth analysis on AI litigation and regulatory trends, see here

2027 Extension on Pandemic Worker Recall Rights – AB 858

The rehire and retention protections for certain hospitality and airport service workers laid off for COVID-19-related reasons have been extended until January 1, 2027. Two months before the pandemic worker reinstatement rights were set to expire on December 31, 2025, Governor Gavin Newsom signed this second extension into law on October 3.


If you have any questions, or would like additional information, please contact one of the attorneys on our Labor & Employment team.

You can subscribe to future advisories and other Alston & Bird publications by completing our publications subscription form.


CFPB Rescinds Registry for Covered Nonbank Entities

What Happened?

In the October 29 Federal Register, the Consumer Financial Protection Bureau issued a final rule rescinding its previous rule relating to the Registry of Nonbank Covered Persons Subject to Certain Agency and Court Orders Final Rule, which imposed obligations on nonbank entities that offer or provide a consumer financial product or service. As a result, covered nonbanks will no longer be required to registered with the Bureau or provide information about certain public Federal, State, or local written orders imposing obligations on the nonbank based on violations of certain consumer protection laws (among other obligations we discussed in a previous post).

In the same Federal Register issue, the Bureau also issued notice of its intent to rescind: (a) amendments to its rules of practice governing adjudication proceedings; and (b) a proposed rule regarding the registry of supervised nonbanks that use form contracts to impose terms and conditions that seek to waive or limit consumer legal protections.

Federal Bank Regulators Announce Rescission of Climate-Related Risk Management Principles

What Happened?

On October 16, 2025, the Federal Deposit Insurance Corporation (“FDIC”), the Federal Reserve Board (“FRB”), and the Office of the Comptroller of the Currency (“OCC”) (collectively, the “bank regulators”) announced that they intend to rescind the interagency Principles for Climate-Related Financial Risk Management for Large Financial Institutions (“Climate Principles”).

Why Does it Matter?

The Climate Principles, initially issued in 2023, require large financial institutions with consolidated assets over $100 billion to consider climate-related financial risk management in line with regulator risk expectations (including for governance, compliance management, strategic planning, and risk management). The banking regulators’ move to rescind the Climate Principles follows the OCC’s withdrawal from them on March 31.

This recission signals the bank regulators’ shifting view of how climate change considerations should impact individual bank policy, which is consistent with President Trump’s rescission of the Biden Administration’s executive order on climate-related financial risk. The FRB staff noted in a memo to the Federal Reserve Board of Governors that they believe the Climate Principles “are not necessary and may be distracting large financial institutions from the management of material financial risks.” (Previously, FRB Vice Chair for Supervision Michelle W. Bowman argued in 2023, when the Climate Principles were initially issued, that they “increased compliance cost and burden without a commensurate improvement to the safety and soundness of financial institutions.” She also expressed concerns that examiners would be pressured to apply the Climate Principles’ expectations on smaller banks.)

What Do You Need to Do?

Guidance from the bank regulators emphasize that banks must continue to assess all material risks and should be resilient to a range of risks. This does not completely rule out that a bank may need to prepare for climate-related risks, but it removes the spotlight from these risks if they are not deemed “material,” such as those that are present, in the words of FRB Vice Chair Bowman, over an “indefinite time horizon.” The rescission of the Climate Principles will take effect immediately upon publication of a formal notice in the Federal Register (currently pending); the bank regulators issued a draft notice in advance of that publication.

The banking regulators’ withdrawal of the Climate Principles does not impact parallel state action to address risks associates with climate change. Shortly after the Climate Principles were issued in 2023, the New York Department of Financial Services issued its own guidance for financial institutions regarding climate change risks. This guidance remains in effect for all New York state regulated mortgage lenders and servicers, banking organizations, licensed branches, and agencies of foreign banking organizations. Thus, even when the Climate Principles are rescinded, regulated financial institutions may have cause to remain attuned to related risks.

California Focuses on Large AI Models

What Happened?

On September 29, 2025, California Governor Gavin Newsom signed Senate Bill 53, the Transparency in Frontier Artificial Intelligence Act (TFAIA), making California the first U.S. state to mandate standardized public safety disclosures for developers of sophisticated AI models that are made available to users in California. The law takes effect January 1, 2026, and it applies to:

  • Frontier Developers: Developers that train large-scale AI models using extremely high levels of computing power.
  • Developers: Frontier developers with annual revenue above $500 million (including affiliates), subject to additional reporting and governance obligations.

Key obligations of TFAIA include:

  • Safety Framework Publication: Large developers must publish (and update annually, as appropriate) a publicly-accessible safety framework describing how the company has incorporated national standards, international standards, and industry-consensus best practices into its frontier AI framework.
  • Transparency Reports: All developers must issue reports when deploying or materially modifying models, detailing model capabilities, intended/restricted uses, risks identified, and mitigation steps. Large developers must submit quarterly summaries to California Office of Emergency Services (COES).
  • Critical Incident Reporting: Developers and the public can report safety incidents directly to COES.
  • Whistleblower Protections: Employees who report substantial public-safety risks are protected from retaliation; large developers must maintain anonymous internal reporting channels.

The California Attorney General may pursue civil actions with penalties up to $1 million per violation. Developers meeting federal AI standards deemed equivalent or stricter by COES may qualify for a safe harbor. TFAIA also creates CalCompute, a public-sector computing consortium under the Government Operations Agency, to advance safe, ethical, and equitable AI research statewide. The California Department of Technology will review and recommend annual updates to the law’s definitions and thresholds.

Why Is It Important?

For the private sector, TFAIA signals that AI risk-governance expectations are maturing beyond voluntary principles. Developers, investors, and enterprises deploying advanced AI should expect heightened scrutiny of model transparency, catastrophic-risk assessment, and cybersecurity practices. Governor Newsom described TFAIA as a “blueprint for balanced AI policy” and the Act positions California as a standard-setter at a time when comprehensive federal AI regulation remains uncertain.

What to Do Now?

As a first step, companies should assess whether TFAIA applies, that is, whether an organization qualifies as a frontier or large frontier developer based on computing thresholds or revenue. In the event it does, companies should update AI safety and governance policies and procedures, including reviewing and aligning internal risk-management, cybersecurity, and third-party assessment frameworks with TFAIA’s requirements. Companies should also plan for transparency reports and establish internal protocols for producing and publishing model-specific transparency documentation. Finally, companies in scope should continue to monitor COES guidance to track additional requirements, safe-harbor determinations, and annual reviews by the Department of Technology.