
The U.S. Consumer Financial Protection Bureau ordered TD Bank to pay US$7.76 million to affected consumers and a US$20 million civil penalty in September 2024. The regulator found years of inaccurate credit reporting and inadequate handling of customer disputes.
The order concerned TD’s U.S. bank
The action named TD Bank, N.A., headquartered in New Jersey and owned within the Toronto-Dominion group. The nearly US$28 million total combined consumer redress and a government penalty.
Those two amounts served different purposes and should not be conflated.
Inaccurate information reached reporting companies
The CFPB said TD supplied erroneous negative data about credit-card delinquencies, bankruptcies and closed accounts. Some voluntarily closed accounts appeared to remain in use.
A bank furnishing data has a legal duty to maintain reasonable accuracy.
Fraudulent accounts created another problem
TD had identified hundreds of thousands of deposit accounts that were confirmed or suspected to have been opened fraudulently. The regulator said information from some of those accounts was nevertheless reported as belonging to consumers.
Overdrafts could then damage a victim’s credit file.
Disputes were not handled properly
According to the order, the bank sometimes failed to conduct reasonable and timely investigations and in some cases did not investigate. It also failed to give proper notices after treating certain disputes as frivolous or irrelevant.
A correction system matters because initial data will never be perfect.
Consequences extend beyond borrowing
Credit and other consumer reports can influence mortgages, rentals, employment screening, insurance and ordinary lending terms. An incorrect derogatory record may therefore cost far more than a rejected credit card.
Delays also force consumers to repeatedly prove they were victims.
The order required direct redress
TD had to pay US$7.76 million to tens of thousands of people affected by the unlawful conduct. The US$20 million penalty was directed to the CFPB’s victims relief fund.
Compliance obligations also required the bank to correct systems, not merely write cheques.
Consumers should examine all three major files
A person notified of a reporting error should obtain reports, preserve correspondence and dispute incorrect entries with both the furnisher and reporting company. Identity-theft victims may need fraud alerts, freezes or official reports.
Records help regulators or lawyers assess unresolved harm.
Consent orders still establish enforceable obligations
Regulatory resolution avoids a full trial but does not make the findings meaningless. The public order sets out alleged violations, required payments and future conduct under statutory authority.
Coverage should use the regulator’s precise findings and the bank’s stated response where available.
Accuracy requires investment and governance
Automated reporting systems can spread one faulty field across thousands of files. Banks need testing, accountable executives, adequately staffed dispute teams and rapid correction across every reporting company that received an error.
The enforcement action showed why consumer data cannot be treated as a minor back-office matter. When lenders create records used throughout economic life, accuracy and meaningful correction are core financial services.
Independent testing after remediation would help establish that the same errors were not merely hidden or moved to a different system.



