Privacy Law Library

Information Security Program and Security Event Notification for Financial Services Licensees

RI Licensee Information Security Law

Data security · Breach notification · Financial

Enacted in 2025 and modeled on the FTC Safeguards Rule, this law requires non-bank financial services licensees to keep a written, risk-based information security program for customer information, including encryption, multi-factor authentication, annual penetration testing, secure disposal and an incident response plan. Licensees must report qualifying security events to the Division of Banking within three business days.

Where
Rhode Island
Citation
R.I. Gen. Laws §§ 19-14-35, 19-14-36 (P.L. 2025, chs. 424 and 425)
Status
In force
In force since
2025-07-02
Enforced by
Rhode Island Department of Business Regulation, Division of Banking (director)
People can sue
No
Penalties
The sections set no specific penalty; violations are enforceable through the director's general licensing and enforcement powers over ch. 19-14 licensees.
Applies to
  • Persons licensed by the Department of Business Regulation under R.I. Gen. Laws ch. 19-14: lenders and small loan lenders, loan brokers, currency transmitters, check cashers, debt-management service providers, mortgage-loan originators and third-party loan servicers
  • Excludes regulated institutions (banks, credit unions and similar) as defined in § 19-1-1, their subsidiaries, and bank holding companies and their subsidiaries

Security duties

  • Designate a qualified individual to oversee the program and perform written risk assessments, repeated periodically.R.I. Gen. Laws § 19-14-35(c)(1)-(2)
  • Implement access controls, encrypt customer information in transit over external networks and at rest (or use reviewed compensating controls), and require multi-factor authentication for anyone accessing information systems.R.I. Gen. Laws § 19-14-35(c)(3)
  • Develop, implement and maintain a written comprehensive information security program with administrative, technical and physical safeguards suited to the licensee's size, activities, vendors and data sensitivity.R.I. Gen. Laws § 19-14-35(a)
  • Regularly test safeguards through continuous monitoring or annual penetration testing and periodic vulnerability assessments, and oversee service providers.R.I. Gen. Laws § 19-14-35(c)(4)-(6)
  • Maintain a written incident response plan and a business continuity and disaster recovery plan, and have the qualified individual report in writing at least annually to the board or a senior officer.R.I. Gen. Laws § 19-14-35(c)(8)-(10)
  • Securely dispose of customer information no later than two years after last use unless retention is required by law or targeted disposal is not reasonably feasible.R.I. Gen. Laws § 19-14-35(c)(3)

Breach duties

  • Notify the director within three business days of determining that a security event occurred that must be reported to another government or supervisory body or is reasonably likely to materially harm a Rhode Island consumer or the licensee's operations, and keep updating the report.R.I. Gen. Laws § 19-14-36(a)-(b)

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: Characterization as modeled on the FTC Safeguards Rule (16 C.F.R. Part 314) is an inference from matching text, not stated in the act. | Specific administrative penalty amounts under ch. 19-14 were not checked.

Research reference, not legal advice.