Item 4. CONTROLS AND PROCEDURES

6K characters. Original on sec.gov · Markdown

Item 4. CONTROLS AND PROCEDURES

As of the end of the period covered by this report, an evaluation was carried out by the Company’s management, with the participation of our Chief Executive Officer and Chief Financial Officer, of the effectiveness of our disclosure controls and procedures (as defined in Rule 13a-15(e) under the Securities Exchange Act of 1934). Based upon that evaluation, our Chief Executive Officer and Chief Financial Officer concluded that these disclosure controls and procedures were effective as of the end of the period covered by this report. In addition, no change in our internal control over financial reporting (as defined in Rule 13a-15(f) under the Securities Exchange Act of 1934) occurred during our most recent fiscal quarter that has materially affected, or is reasonably likely to materially affect, our internal control over financial reporting.

PART II. OTHER INFORMATION

ITEM 1. LEGAL PROCEEDINGS

Remaining Matters Related to 2017 Cybersecurity Incident

Canadian Class Actions. In 2017, we experienced a cybersecurity incident following a criminal attack on our systems that involved the theft of personal information of consumers. Five putative Canadian class actions, four of which are on behalf of a national class of approximately 19,000 Canadian consumers, are pending against us in Ontario, British Columbia and Alberta. Each of the proposed Canadian class actions asserts a number of common law and statutory claims seeking monetary damages and other related relief in connection with the 2017 cybersecurity incident. In addition to seeking class certification on behalf of Canadian consumers whose personal information was allegedly impacted by the 2017 cybersecurity incident, in some cases, plaintiffs also seek class certification on behalf of a larger group of Canadian consumers who had contracts for subscription products with Equifax around the time of the incident or earlier and were not impacted by the incident.

On December 13, 2019, the court in Ontario granted certification of a nationwide class that includes all impacted Canadians as well as Canadians who had subscription products with Equifax between March 7, 2017 and July 30, 2017 who were not impacted by the incident. We appealed one of the claims on which a class was certified and on June 9, 2021, our appeal was granted by the Ontario Divisional Court. The plaintiff filed a notice of further appeal with the Ontario Court of Appeal, and on November 25, 2022, the Ontario Court of Appeal dismissed the plaintiff’s appeal and upheld the Divisional Court’s ruling in our favor. On January 24, 2023, the plaintiff appealed this decision to the Supreme Court of Canada, and on July 13, 2023, the Supreme Court of Canada dismissed the appeal. All remaining purported class actions are at preliminary stages or stayed.

FCA Investigation. The U.K.’s Financial Conduct Authority (“FCA”) opened an enforcement investigation against our U.K. subsidiary, Equifax Limited, in October 2017 in connection with the 2017 cybersecurity incident. The investigation by the FCA has involved a number of information requirements and interviews. We have responded to the information requirements and continue to cooperate with the investigation. We have been advised by the FCA that it intends to send us a notice with the FCA's findings and proposed penalty, which we anticipate will result in the initiation of settlement discussions. At this time, we are unable to predict the outcome of this FCA investigation, including whether the investigation will result in any settlement, action or proceeding against us.

CFPB Matters

In December 2021, we received a Civil Investigative Demand (a “CID”) from the CFPB as part of its investigation into our consumer disputes process in order to determine whether we have followed the FCRA's requirements for the proper handling of consumer disputes. The CID requests the production of documents and answers to written questions. We are cooperating with the CFPB in its investigation and are in discussions with the CFPB regarding our response to the CID.

In January 2023, the CFPB informed us that its enforcement division will be investigating our previously-disclosed coding issue identified within a legacy server environment in the U.S. slated to be migrated to the new Equifax cloud infrastructure which impacted how some credit scores were calculated during a three-week period in 2022. We are cooperating with the CFPB in its investigation.

In July 2023, we received a CID from the CFPB as part of its investigation into data accuracy and dispute handling at our Workforce Solutions business unit in order to determine whether we have followed the FCRA's requirements. The CID requests the production of documents and answers to written questions. We are cooperating with the CFPB in its investigation and are in discussions with the CFPB regarding our response to the CID.

At this time, we are unable to predict the outcome of these CFPB investigations, including whether the investigations will result in any actions or proceedings against us.

Other

Equifax has been named as a defendant in various other legal actions, including administrative claims, regulatory matters, government investigations, class actions and other litigation arising in connection with our business. Some of the legal actions include claims for substantial compensatory or punitive damages or claims for indeterminate amounts of damages. We believe we have defenses to and, where appropriate, will contest many of these matters. Given the number of these matters,

some are likely to result in adverse judgments, penalties, injunctions, fines or other relief. We may explore potential settlements before a case is taken through trial because of the uncertainty and risks inherent in the litigation process.

For information regarding our accounting for legal contingencies, see Note 6 of the Notes to Consolidated Financial Statements in this Form 10-Q.

Previous: Item 3. QUANTITATIVE AND QUALITATIVE DISCLOSURES ABOUT MARKET RISK · Next: Item 1A. RISK FACTORS