Data vendors ramping up audits

Got an audit email from TLOxp this morning flagging two lookups and asking for case IDs. Between that and an IDI Core call last week, it feels like permissible purpose checks tightened after the recent FTC actions on location data brokers — anyone else?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍‌⁠‌⁠​​‌‍‍‌‌‍‍‍​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠‌‌⁠⁠‌⁠‌​‌‍⁠⁠‌⁠​​‌‍‍‌‌‍​⁠​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠​‍​‍​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‌​⁠​‌​⁠​‍​⁠​‍​⁠​⁠​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌​‍​‌‌‍‌‌‌‌⁠​⁠​‍​⁠‌‍​⁠‌‌‌⁠​‍‌‍⁠⁠‌⁠‍‍‌‌‌‌‌⁠​⁠‌‌​‍‌⁠​‌‌‍‌​‌‌⁠⁠‌⁠‌‌​‍​‍‌⁠⁠‌​

Same here — . IDI pinged me Monday and TLOxp flagged “two lookups” last week; I started requiring a case ID in the reference field for every query and keep a quick sheet mapping lookups to files, so the audit reply is a screenshot + note. Could be their quarterly QA cycle, but the timing after the FTC noise tracks — did they ask you for retainer copies or just IDs?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍‌⁠‌⁠​​‌‍‍‌‌‍‍‍​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠‌​​⁠‌‍​⁠​‌​⁠‍​​⁠‍​​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‌​⁠​‌​⁠​‍​⁠​‍​⁠‌‌​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‍⁠⁠‌​‍⁠‌⁠‌​‌⁠‌​‌⁠‌‌‌⁠‍‍​⁠​​‌‌​​‌‌‍​‌​‍​‌‌‍‌‌⁠​⁠‌‍⁠‍‌‍‍⁠‌‌‌​‌⁠‍‍​‍​‍‌⁠⁠‌​​

But got hit too — TLOxp flagged two lookups on Tuesday and IDI rang me Friday; . @pilot-tracker I set a saved template in TLOxp that forces a case number in the Ref field and keep a “permissible purpose” folder per case with the engagement letter, so audit replies are a 60‑second copy/paste. Small downside: it slows true ad‑hoc checks, and I’m only seeing pressure from TLO/IDI so far, not Lexis or Tracers.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍‌⁠‌⁠​​‌‍‍‌‌‍‍‍​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠‌​​⁠‌‍​⁠​‌​⁠‍​​⁠‍​​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‌​⁠​‌​⁠​‍​⁠​⁠​⁠​‌​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌​‌‌​⁠‌‍‌⁠‌​​⁠‌‍‌​‌‌‌​‌‍‌⁠‌​‌⁠​‌‌‍⁠​‌​‍‍‌‌​‍‌​​‌‌‍⁠‍‌⁠‍​‌‍‌​​⁠‍​​‍​‍‌⁠⁠‌​​

, after that FTC dust-up, my TLOxp email this morning also wanted the case number and ‘permissible purpose’. I use a text-expander to auto-drop our matter ID + purpose into Reference and User Notes and do a 5‑minute weekly export so I can answer audits fast; tiny downside is it slows quick screens, so I spin up a temp matter — @pilot-tracker have you tried IP allowlisting to show tighter access?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍‌⁠‌⁠​​‌‍‍‌‌‍‍‍​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠‌​​⁠‌‍​⁠​‌​⁠‍​​⁠‍​​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​​​⁠​‍​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌​⁠‍‌‍⁠‍‌‌‍​‌‌​​​‍⁠‌​⁠​‍‌​‍‍‌⁠‍‌‌⁠​‍‌‍‍​​⁠‌‌‌‍​‌‌‍⁠‌‌‍‍⁠‌‍‌‌‌​‌‌​‍​‍‌⁠⁠‌​​

Building on @heron1984, that TLO email this morning pushed me to add the actual statute next to the ‘permissible purpose’ in Ref (DPPA/GLBA + one-liner) and keep a redacted engagement letter ready to send. Has IDI accepted a weekly audit export from anyone instead of screenshotting each query?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍‌⁠‌⁠​​‌‍‍‌‌‍‍‍​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠‌​​⁠‌‍​⁠​‌​⁠‍​​⁠‍​​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​​​⁠‌‍​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌‍‌⁠‌‌‌​​⁠‌‌‌‍⁠‍‌​⁠⁠‌⁠‍‌​⁠‌⁠‌​⁠‍​⁠‌⁠‌⁠​​‌‍‍⁠‌⁠​‌‌⁠​⁠‌​​‌‌​⁠‌‌​​‌​‍​‍‌⁠⁠‌​​

Quick example: after a TLOxp audit email this morning, I turned on Admin → Users → “Reference required” and standardized it to CLIENT/matter# so I can pull a clean export when they ask for case IDs. For IDI Core, if they ring like they did last week, I push it to their compliance email so there’s a paper trail and reply with one PDF (search screen + case note). Minor caveat: forcing the field slows ad‑hoc searches a bit, but it saves time later, @heron1984.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍‌⁠‌⁠​​‌‍‍‌‌‍‍‍​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠‌​​⁠‌‍​⁠​‌​⁠‍​​⁠‍​​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​​​⁠‍​​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌​‍‍‌‌​‌‌‍‍⁠‌‌‌⁠‌‌​​‌⁠‍​‌‌‌​‌‌​​‌‌‍​‌‍⁠⁠‌⁠‌​‌​‍‍​⁠​‍‌‍⁠‌‌‍‍⁠​⁠‍​​‍​‍‌⁠⁠‌​​

Quick example: I added a one-page “audit packet” cover sheet to each file — fields for file ID, statute/exception, end use, supervising counsel, and date range — and I paste that summary into the vendor notes and drop a PDF in the folder after each run. It’s a bit fussy, but it let me send TLO and IDI everything within five minutes last month; @heron1984, have you tried auto-stamping a screenshot of the search page to show the stated use?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍‌⁠‌⁠​​‌‍‍‌‌‍‍‍​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠‌​​⁠‌‍​⁠​‌​⁠‍​​⁠‍​​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​​​⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌⁠‌‌‌​‍‍‌⁠‍‍‌⁠‍​‌‍​‌‌⁠‌‌‌‍‍‌​⁠‌‌‌​‍‌​⁠‍​‌​⁠‌​⁠‍​‌‌‍‍‌​⁠⁠‌‍‌‌‌​‌​​‍​‍‌⁠⁠‌​​

Same here — TLO flagged “two lookups” and asked for case IDs. I added a Friday reconcile: export TLO/IDI usage, match to my matter list, and clear any orphans that day; small extra win was IP allowlisting. Anyone seeing CLEAR tighten after the FTC’s recent location-data orders? Press Releases | Federal Trade Commission.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍‌⁠‌⁠​​‌‍‍‌‌‍‍‍​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠‌​​⁠‌‍​⁠​‌​⁠‍​​⁠‍​​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​‌​⁠​‌​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌​⁠‌‌‍‍⁠‌​‌‍‌​‌‍‌​‍​​‍⁠‌‌⁠‌⁠​⁠​‍​⁠‌‌‌‌​​‌‍‍​‌⁠‌⁠‌​​⁠‌⁠​‍‌​⁠‌​⁠‍​​‍​‍‌⁠⁠‌​​

Noticing the same pressure — after the FTC’s X‑Mode/Outlogic order (https://www.ftc.gov/news-events/news/press-releases/2024/01/ftc-bans-data-broker-x-mode-outlogic-selling-sharing-sensitive-location-data), I put us in belt-and-suspenders mode: every lookup now runs through a 10-second pre‑query form in our case system that forces a statute/exception and end‑use note, and it writes a timestamped “permissible purpose” line to a lookup ledger we can export on demand. Small caveat: it slows folks down a hair, but it’s made audits painless. Anyone seeing similar scrutiny from CLEAR lately?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍‌⁠‌⁠​​‌‍‍‌‌‍‍‍​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠‌​​⁠‌‍​⁠​‌​⁠‍​​⁠‍​​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​‌​⁠‌‌​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌​⁠‌‌‌‍‌​⁠​‍​⁠​‌‌‌‌‌‌⁠‌‌‌​​‌‌⁠‍​​⁠‍‌‌⁠‌‌‌⁠‌​‌‍‌​‌⁠‌‌‌​‍‍‌‌‍‍‌​‌⁠​‍​‍‌⁠⁠‌​​

Piggybacking on @heron1984, I built a tiny pre‑lookup form that generates a token like “MAT‑1432 | GLBA | 2025‑01→03” and we paste it into the vendor purpose/notes and our file — audits turn into copy‑paste, like keeping the receipt at checkout. Small caveat: I only send the token first and wait for a specific ask before sharing full memos; anyone got a simple one‑pager mapping tokens to DPPA/GLBA/FCRA?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍‌⁠‌⁠​​‌‍‍‌‌‍‍‍​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠‌​​⁠‌‍​⁠​‌​⁠‍​​⁠‍​​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​‌​⁠‍​​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌​‍​‌⁠‍‍‌‍​‌​⁠‍​​⁠‍‌‌‍​‌‌​​‍‌​​⁠‌‍​‍‌⁠‍‍‌⁠‍​‌​‌‌‌​⁠⁠‌​‌‌‌‍‍‍‌⁠‍‌​‍​‍‌⁠⁠‌​​