The proposed bill seeks to establish a new chapter in the North Dakota Century Code dedicated to financial institution data security programs while amending existing regulations related to the Department of Financial Institutions. Key amendments include provisions that empower the commissioner or board to issue permanent suspension orders against current or former officers, directors, or employees of financial institutions convicted of dishonesty or breach of trust, emphasizing the immediate effectiveness of such orders. The bill also enhances the authority of the Department of Financial Institutions to issue cease and desist orders against financial institutions for unsafe practices, while clarifying definitions of critical terms such as "authorized user," "consumer," and "customer" to support the new data security regulations.
Additionally, the bill introduces new definitions and requirements for financial corporations regarding the safeguarding of customer information, mandating the establishment of comprehensive information security programs that include administrative, technical, and physical safeguards. It requires the designation of a "qualified individual" to oversee these programs and outlines essential elements such as risk assessments, access controls, and secure disposal procedures. The legislation also emphasizes the need for security awareness training for personnel, monitoring of authorized user activity, and the implementation of multifactor authentication. Furthermore, it updates the regulatory framework for mortgage loan originators and debt-settlement providers, enhancing oversight and accountability within these sectors by modifying licensing criteria and notification processes.
Statutes affected: PREFILED: 6-01-04.1, 6-01-04.2, 6-03-02, 13-04.1-01.1, 13-04.1-11.1, 13-05-07.1, 13-08-10, 13-08-11.1, 13-09.1-14, 13-09.1-17, 13-09.1-38, 13-10-05, 13-11-10, 13-12-19, 13-13-04, 13-13-18
Adopted by the House Industry, Business and Labor Committee: 6-01-04.1, 6-01-04.2, 6-03-02, 13-04.1-01.1, 13-04.1-11.1, 13-05-07.1, 13-08-10, 13-08-11.1, 13-09.1-14, 13-09.1-17, 13-09.1-38, 13-10-05, 13-11-10, 13-12-19, 13-13-04, 13-13-18
FIRST ENGROSSMENT: 6-01-04.1, 6-01-04.2, 6-03-02, 13-04.1-01.1, 13-04.1-11.1, 13-05-07.1, 13-08-10, 13-08-11.1, 13-09.1-14, 13-09.1-17, 13-09.1-38, 13-10-05, 13-11-10, 13-12-19, 13-13-04, 13-13-18
Adopted by the Senate Industry and Business Committee: 6-01-04.1, 6-01-04.2, 6-03-02, 13-04.1-01.1, 13-04.1-11.1, 13-05-07.1, 13-08-10, 13-08-11.1, 13-09.1-14, 13-09.1-17, 13-09.1-38, 13-10-05, 13-11-10, 13-12-19, 13-13-04, 13-13-18
Enrollment: 6-01-04.1, 6-01-04.2, 6-03-02, 13-04.1-01.1, 13-04.1-11.1, 13-05-07.1, 13-08-10, 13-08-11.1, 13-09.1-14, 13-09.1-17, 13-09.1-38, 13-10-05, 13-11-10, 13-12-19, 13-13-04, 13-13-18
INTRODUCED: 6-01-04.1, 6-01-04.2, 6-03-02, 13-04.1-01.1, 13-04.1-11.1, 13-05-07.1, 13-08-10, 13-08-11.1, 13-09.1-14, 13-09.1-17, 13-09.1-38, 13-10-05, 13-11-10, 13-12-19, 13-13-04, 13-13-18