California is positioning itself to fill the regulatory space left by Washington’s retreat from consumer financial oversight, with former Consumer Financial Protection Bureau Director Rohit Chopra bringing his enforcement philosophy to the nation’s largest state economy.
Nearly two months into Chopra’s leadership of California’s Business and Consumer Services Agency, the implications for banks, FinTechs, lenders and payments companies are becoming clearer. Reduced federal scrutiny does not necessarily mean reduced compliance risk.
A Thursday (Aug. 27) analysis by Troutman Pepper Locke described an emerging approach centered on challenging fee structures, scrutinizing algorithmic decisions, protecting financial data and imposing consequences that companies cannot simply absorb as business expenses. The opening period has produced more signals than a fully developed enforcement program, but the direction is clear.
Gov. Gavin Newsom appointed Chopra May 12, and the agency launched July 1. Created through a 2025 government reorganization, it brings consumer protection departments under a cabinet-level umbrella. Newsom’s office framed the launch as a response to weakening federal enforcement.
The agency does not expand the Department of Financial Protection and Innovation’s statutory authority under the California Consumer Financial Protection Law. Chopra’s influence instead comes through setting priorities, coordinating agencies and shaping supervision using existing powers, the analysis said.
Chopra served as the CFPB’s first student loan ombudsman, a Federal Trade Commission commissioner, and CFPB director from 2021 to 2025. Across those positions, he treated systemic misconduct as requiring changes to business practices, with escalating consequences for repeat offenders, according to the analysis.
At the CFPB, that approach was particularly visible in his campaign against fees, per the analysis. Rather than viewing problematic charges solely as disclosure failures, Chopra challenged the underlying product designs through federal prohibitions on unfair, deceptive or abusive acts or practices.
We’d love to be your preferred source for news.
Please add us to your preferred sources list so our news, data and interviews show up in your feed. Thanks!
For California firms, the analysis said scrutiny of overdraft and nonsufficient funds charges, late and convenience fees, subscription cancellation obstacles, and pricing based on personal or behavioral data can be expected. Clear disclosure may not satisfy regulators if charges allegedly cannot be anticipated or are disproportionate to the service provided.
Early DFPI activity illustrated the shifting environment, although the analysis said cases were already underway before Chopra arrived. Orders on July 1 required five broker-dealers to return more than $1.3 million for excessive commissions on small transactions. A July 7 announcement involved more than $7 million in restitution for victims of a land investment scam.
Artificial intelligence presents another likely enforcement priority, the analysis said. Chopra’s federal record reflects the position that algorithmic complexity does not excuse compliance with fair lending, anti-discrimination or consumer protection requirements.
There will also probably be scrutiny of advertising that steers vulnerable consumers toward expensive products, underwriting that uses social media or device data, and credit scoring systems that are unable to explain adverse decisions, per the analysis. For banks and FinTechs, these priorities point to a need to test model outcomes and explanations, not merely documenting that an AI governance policy exists.
Financial data handling is another focus. At the CFPB, Chopra investigated major technology companies’ payment services and advanced open banking rules intended to strengthen consumers’ control of their financial information. California’s agency signaled continuity with that approach in July by urging the FTC to retain social platform X’s privacy and data security order, the analysis said.
Separately, DFPI levied a fine of $825,000 against Academy Mortgage for alleged cybersecurity failures affecting more than 284,000 people. The case reinforces the importance of operational safeguards alongside consent and data sharing controls.
The greatest exposure could fall on repeat offenders, per the Troutman Pepper analysis. Chopra has favored product restrictions, business model changes and individual accountability over penalties alone. The agency has warned that serious violations can jeopardize California operating licenses.
For financial providers, the practical message is to reassess fees, audit algorithms, strengthen data governance and address recurring complaints. Federal retrenchment is creating room for state enforcement, not a dependable compliance reprieve. California’s approach could also foreshadow priorities elsewhere, making Chopra’s early tenure consequential beyond the state’s borders.