Bill
Bill > S0603
RI S0603
RI S0603Provides standards for developing, implementing, and maintaining reasonable administrative, technical, and physical safeguards to protect the security, confidentiality, and integrity of customer information.
summary
Introduced
03/06/2025
03/06/2025
In Committee
06/17/2025
06/17/2025
Crossed Over
06/20/2025
06/20/2025
Passed
07/02/2025
07/02/2025
Dead
Signed/Enacted/Adopted
07/02/2025
07/02/2025
Introduced Session
2025 Regular Session
Bill Summary
This act would provide standards for developing, implementing, and maintaining reasonable administrative, technical, and physical safeguards to protect the security, confidentiality, and integrity of customer information held by entities licensed under chapter 14 of title 19 relating to licensed activities of financial institutions. This act would take effect upon passage.
AI Summary
This bill provides comprehensive standards for financial institutions to protect customer information through robust cybersecurity practices. The bill requires licensed entities to develop and maintain a written information security program that includes administrative, technical, and physical safeguards tailored to the organization's size, complexity, and the sensitivity of customer data. Key provisions include: designating a qualified individual to oversee the security program; conducting regular risk assessments to identify potential security threats; implementing encryption and multi-factor authentication; establishing access controls; developing secure data retention and disposal procedures; performing ongoing testing and monitoring of information systems, including annual penetration testing and vulnerability assessments; providing security awareness training for personnel; carefully vetting and monitoring third-party service providers; creating a written incident response plan; and requiring annual reporting to the organization's leadership about the status and effectiveness of the information security program. The bill also mandates that licensees promptly notify the director within three business days of a security event that could materially harm consumers or the organization's operations, providing detailed information about the breach, its potential impact, and remediation efforts. Notably, the bill does not apply to regulated financial institutions already subject to federal banking regulations.
Committee Categories
Business and Industry
Sponsors (8)
Bob Britto (D)*,
Jacob Bissaillon (D),
Lou DiPalma (D),
Walter Felag (D),
Victoria Gu (D),
Matt LaMountain (D),
Mark McKenney (D),
Sue Sosnowski (D),
Last Action
Signed by Governor (on 07/02/2025)
Official Document
bill text
bill summary
Loading...
bill summary
Loading...
bill summary
Document Type | Source Location |
---|---|
State Bill Page | https://status.rilegislature.gov/ |
BillText | https://webserver.rilegislature.gov/BillText25/SenateText25/S0603A.pdf |
BillText | https://webserver.rilegislature.gov/BillText25/SenateText25/S0603.pdf |
Loading...