Labor & Employment Law Daily Wrap Up, LITIGATION NEWS, TRENDS—DOGE moves to shutter CFPB; lawsuit challenges disclosure of employee personal info, (Feb 11, 2025)
Organizations Mentioned:Consumer Financial Protection Bureau | National Treasury Employees Union
By Patricia K. Ruiz, J.D.
The lawsuit challenges the disclosure of employees’ personal information to Elon Musk, arguing that it divests union members of their privacy rights, after Musk’s DOGE team targeted the Bureau and its internal systems on February 5.
The National Treasury Employees Union (NTEU), a labor union representing federal government employees working in 37 agencies and departments, brought a lawsuit on behalf of its members, current and former employees of the Consumer Financial Protection Bureau (CFPB), seeking to stop the ongoing disclosure of employees’ personal information to Elon Musk and other members of the new Department of Government Efficiency (DOGE), divesting NTEU members of their privacy rights, in violation of federal law and regulations.
DOGE access to records. On January 20, 2025, President Donald J. Trump issued an executive order (EO) establishing DOGE and renaming the United States Digital Service the United DOGE Service (USDS). The EO also established a temporary organization to be led by a USDS administrator. The EO directs each agency head, in consultation with the USDS administrator, to establish a DOGE team and to “take all necessary steps... to ensure USDS has full and prompt access to all unclassified agency records, software systems, and IT systems. The EO also purports to displace all prior executive orders and regulations that might serve as a barrier to providing USDS access to agency records and systems.
The complaint states that the DOGE EO focuses on the administration’s efforts toward modernizing federal technology and software to maximize governmental efficiency and productivity, specifically highlighting a software modernization initiative aimed at improving the “quality and efficiency of government-wide software, network infrastructure, and information technology (IT) systems.” However, the complaint alleges that DOGE teams are seeking full access to agency records, information, and systems unrelated to DOGE’s stated mission.
CFPB targeted by DOGE. On January 31, 2025, the complaint alleges, President Trump designated Secretary of the Treasury Scott Bessent as acting director of the Consumer Financial Protection Bureau. On February 5, 2025, at least one of three DOGE “special government employees” entered CFPB, and the next day, three individuals had been added to the CFPB’s staff and email directory as “senior advisers.” The complaint alleges Bessent instructed CFPB staff to give the three senior advisers “read only” access to various internal systems.
Letter from Congressional Democrats. On Friday, February 7, Waters and 80 other Democrats sent a letter to then Acting Director Bessent demanding specific answers with regard to how the Treasury Secretary plans to address consequences consumers may face as a result of his decision to freeze many of the agency’s critical enforcement activities and delay key rules from taking effect, how the Treasury Secretary plans to address consequences consumers may face as a result of the freeze, and how he intends to hold financial institutions accountable and protect consumers moving forward.
Another new CFPB Acting Director. On February 7, President Trump replaced Bessent with Russell Vought as acting director of the CFPB. Vought immediately instructed CFPB staff to grant the DOGE team access to all non-classified CFPB systems. The same day, Musk posted “RIP CFPB” on his personal X account, preceded by repeated statements by Musk critical of the CFPB and its work. According to a statement from Congresswoman Maxine Waters (D-Calif.), “Hours later in the dead of the night, when he thought no one was looking, Musk deleted CFPB’s X account and took steps to shut down the CFPB’s website to suppress information and obstruct consumers from accessing crucial guidance on their rights and protections under the law.” Waters continued, “My Democratic colleagues and I will not stand by as a corrupt, crooked billionaire illegally takes control of an agency designed to protect working-class families from criminals like him. We will fight this every step of the way.”
Reaction to ‘non-functional’ Bureau. In reaction, a blog post from Credit Slips explained that “a non-functional CFPB is going to cause real problems for regulated financial institutions,” given that the CFPB is responsible for more than a dozen major federal laws.
On February 8, Vought announced on X that he notified the Federal Reserve that the CFPB will not be taking its next draw of unappropriated funding because it is not “reasonably necessary” to carry out its duties, stating, “The Bureau's current balance of $711.6 million is in fact excessive in the current fiscal environment. This spigot, long contributing to CFPB's unaccountability, is now being turned off.”
Another blog post by Credit Slips argued that Vought’s decisions to cease all examination and supervision activity are illegal, as the CFPB director under the Consumer Financial Protection Act (CFPA) is required to first determine what the CFPB needs to do to “administer, enforce, and otherwise implement the provisions of federal consumer financial law.” Nothing in the statute allows him to consider the current fiscal environment or what he sees as the agency’s unaccountability. The blog post states, “Vought’s illegal orders affect not just CFPB employees and vendors and consumers. They also affect regulated institutions” that want to play fair not lose market share to “cheats.”
Privacy Act allegations. The complaint argues that the CFPB has a responsibility under the Privacy Act to protect from unlawful third-party disclosure the information it collects and maintains about its employees. It argues that the CFPB has not and cannot show that disclosure of employee information to DOGE falls within a statutory exception to the Privacy Act. Because the DOGE members who accessed the CFPB are not officers or employees of the CFPB, but rather “special government employees” outside of the CFPB’s supervision; thus, the “need to know” exception under 5 U.S.C. §552a(b)(1) has not been met. The complaint further argues that the CFPB failed to demonstrate how the disclosure of employee information to DOGE members comports with the intended use of that employee information, let alone that the disclosure of employee information could be defined as a “routine use.” Thus, the CFPB was required to obtain the consent of affected employees and failed to do so.
Relief sought. NTEU seeks declarations that the CFPB’s decision to authorize members of DOGE to access CFPB systems is unlawful and that the disclosure of employee records and information to members of DOGE is unlawful. It further seeks to enjoin the CFPB from granting access and, by extension, disclosing employee records and information to DOGE, except as required by law. Finally, the seeks a court order requiring the CFPB to pay reasonable attorney’s fees and costs.
News: AgencyNews ComputerFraudPrivacy Privacy WhiteHouseNews LitigationNewsTrends LaborNews Labor