Information Security Program and Security Event Notification for Financial Services Licensees
RI Licensee Information Security Law
Data security · Breach notification · Financial
Enacted in 2025 and modeled on the FTC Safeguards Rule, this law requires non-bank financial services licensees to keep a written, risk-based information security program for customer information, including encryption, multi-factor authentication, annual penetration testing, secure disposal and an incident response plan. Licensees must report qualifying security events to the Division of Banking within three business days.
- Where
- Rhode Island
- Citation
- R.I. Gen. Laws §§ 19-14-35, 19-14-36 (P.L. 2025, chs. 424 and 425)
- Status
- In force
- In force since
- 2025-07-02
- Enforced by
- Rhode Island Department of Business Regulation, Division of Banking (director)
- People can sue
- No
- Penalties
- The sections set no specific penalty; violations are enforceable through the director's general licensing and enforcement powers over ch. 19-14 licensees.
- Applies to
- Persons licensed by the Department of Business Regulation under R.I. Gen. Laws ch. 19-14: lenders and small loan lenders, loan brokers, currency transmitters, check cashers, debt-management service providers, mortgage-loan originators and third-party loan servicers
- Excludes regulated institutions (banks, credit unions and similar) as defined in § 19-1-1, their subsidiaries, and bank holding companies and their subsidiaries
Security duties
- Designate a qualified individual to oversee the program and perform written risk assessments, repeated periodically.R.I. Gen. Laws § 19-14-35(c)(1)-(2)
- Implement access controls, encrypt customer information in transit over external networks and at rest (or use reviewed compensating controls), and require multi-factor authentication for anyone accessing information systems.R.I. Gen. Laws § 19-14-35(c)(3)
- Develop, implement and maintain a written comprehensive information security program with administrative, technical and physical safeguards suited to the licensee's size, activities, vendors and data sensitivity.R.I. Gen. Laws § 19-14-35(a)
- Regularly test safeguards through continuous monitoring or annual penetration testing and periodic vulnerability assessments, and oversee service providers.R.I. Gen. Laws § 19-14-35(c)(4)-(6)
- Maintain a written incident response plan and a business continuity and disaster recovery plan, and have the qualified individual report in writing at least annually to the board or a senior officer.R.I. Gen. Laws § 19-14-35(c)(8)-(10)
- Securely dispose of customer information no later than two years after last use unless retention is required by law or targeted disposal is not reasonably feasible.R.I. Gen. Laws § 19-14-35(c)(3)
Breach duties
- Notify the director within three business days of determining that a security event occurred that must be reported to another government or supervisory body or is reasonably likely to materially harm a Rhode Island consumer or the licensee's operations, and keep updating the report.R.I. Gen. Laws § 19-14-36(a)-(b)
Sources
- Official text
- R.I. Gen. Laws § 19-14-35, Information security program
- R.I. Gen. Laws § 19-14-36, Notification of a security event
- P.L. 2025, ch. 424 (2025-S 0603 Sub A)
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Unverified: Characterization as modeled on the FTC Safeguards Rule (16 C.F.R. Part 314) is an inference from matching text, not stated in the act. | Specific administrative penalty amounts under ch. 19-14 were not checked.
Research reference, not legal advice.