Shown verbatim: the complete text as captured from the official page posted by the Mississippi Legislature, fetched 2026-08-29. This is the enrolled version. The official bill page.
MISSISSIPPI LEGISLATURE 2026 Regular Session To: Banking and Financial Services By: Representative Aguirre House Bill 1596 (As Sent to Governor) AN ACT TO REQUIRE A MONEY TRANSMITTER LICENSED UNDER THE MONEY TRANSMISSION MODERNIZATION ACT TO IMPLEMENT SAFEGUARDS TO PROTECT CUSTOMER INFORMATION AND INCREASE DATA SECURITY; TO REQUIRE A LICENSEE TO DESIGNATE A QUALIFIED INDIVIDUAL TO BE RESPONSIBLE FOR OVERSEEING, IMPLEMENTING AND ENFORCING AN INFORMATION SECURITY PROGRAM; TO PROVIDE THE MINIMUM STANDARDS AND REQUIREMENTS FOR THE INFORMATION SECURITY PROGRAM AND TO REQUIRE RISK ASSESSMENTS; TO REQUIRE NOTIFICATION TO THE COMMISSIONER OF BANKING AND CONSUMER FINANCE WHEN UNENCRYPTED CUSTOMER INFORMATION IS ACQUIRED WITHOUT THE AUTHORIZATION OF THE AFFECTED INDIVIDUAL; TO PROVIDE CERTAIN EXCEPTIONS; TO AMEND SECTION 75-16-11, MISSISSIPPI CODE OF 1972, TO PROVIDE THAT FUNDS COMING INTO THE POSSESSION OF THE COMMISSIONER AS A RESULT OF THE MONEY TRANSMISSION MODERNIZATION ACT SHALL BE DEPOSITED INTO THE CONSUMER FINANCE FUND; TO AMEND SECTIONS 75-16-25, 75-16-31 AND 75-16-43, MISSISSIPPI CODE OF 1972, TO REGULATE VIRTUAL CURRENCY KIOSKS UNDER THE PROVISIONS OF THE MONEY TRANSMISSION MODERNIZATION ACT; TO AMEND SECTION 75-16-51, MISSISSIPPI CODE OF 1972, TO REQUIRE A LICENSEE TO PROVIDE TRAINING MATERIALS TO HELP AUTHORIZED DELEGATES RECOGNIZE FINANCIAL ABUSE AND FINANCIAL EXPLOITATION OF AN ELDER ADULT AND RESPOND APPROPRIATELY IN SUCH SITUATIONS; TO AMEND SECTION 75-16-65, MISSISSIPPI CODE OF 1972, TO INCLUDE THE WORD "INVESTMENTS"; TO CREATE NEW SECTION 75-16-89, MISSISSIPPI CODE OF 1972, TO REQUIRE A LICENSEE TO PROVIDE CERTAIN INFORMATION TO THE PURCHASER IN CONNECTION WITH EACH MONEY TRANSMISSION OR KIOSK TRANSACTION CONDUCTED BY THE LICENSEE DIRECTLY OR THROUGH AN AUTHORIZED DELEGATE; AND FOR RELATED PURPOSES. BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF MISSISSIPPI: SECTION 1. Short title. Sections 1 through 7 of this act shall be known and may be cited as the "Data Security for Money Transmitters Act". SECTION 2. Definitions. The definitions provided in Section 75-16-5 shall also apply to the terms used in Sections 1 through 7 of this act, and the following terms as used in Sections 1 through 7 of this act have the meanings as defined in this section, unless the context clearly indicates otherwise: (a) "Authorized user" means an employee, contractor, agent or other person that participates in a licensee's business operations and is authorized to access and use a licensee's information systems and data. (b) "Consumer" means an individual who obtains or has obtained a financial product or service from a licensee that is to be used primarily for personal, family or household purposes, or that individual's legal representative. (c) "Customer" means a consumer who has a customer relationship with a licensee. (d) "Customer information" means a record containing nonpublic personal information about a customer of a licensee, whether in paper, electronic or other form, that is handled or maintained by or on behalf of a licensee or the licensee's affiliates. (e) "Customer relationship" means a continuing relationship between a consumer and a licensee under which the licensee provides to the consumer one or more financial products or services that are used primarily for personal, family or household purposes. (f) "Encryption" means the transformation of data into a form that results in a low probability of assigning meaning without the use of a protective process or key, consistent with current cryptographic standards and accompanied by appropriate safeguards for cryptographic key material. (g) "Financial product or service" means a product or service that a financial holding company could offer by engaging in a financial activity under Section 4(k) of the Bank Holding Company Act of 1956, 12 USC Section 1843(k), as it existed on January 1, 2025. The term "financial product or service" includes a licensee's evaluation or brokerage of information that a licensee collects in connection with a request or an application from a consumer for a financial product or service. (h) "Information security program" means the administrative, technical or physical safeguards a licensee uses to access, collect, distribute, process, protect, store, use, transmit, dispose of or otherwise handle customer information. (i) "Information system" means a discrete set of electronic information resources organized for the collection, processing, maintenance, use, sharing, dissemination or disposition of electronic information, including any specialized system such as industrial controls systems or process controls systems, telephone switching and private branch exchange systems, and environmental controls systems, that contains customer information or that is connected to a system that contains customer information. (j) "Licensee" means a money transmitter or virtual currency kiosk licensed under the Money Transmission Modernization Act, Section 75-16-1 et seq. (k) "Multi-factor authentication" means authentication through verification of at least two (2) of the following types of authentication factors: (i) Knowledge factors, including, but not limited to, a password; (ii) Possession factors, including, but not limited to, a token; or (iii) Inherence factors, including, but not limited to, biometric characteristics. (l) (i) "Nonpublic personal information" means: 1. Personally identifiable financial information; and 2. A list, description or other grouping of consumers, and publicly available information pertaining to a consumer, that is derived using personally identifiable financial information that is not publicly available. (ii) The term "nonpublic personal information" includes, but is not limited to, a list of individuals' names and street addresses that is derived, in whole or in part, using personally identifiable financial information that is not publicly available. The term "nonpublic personal information" does not include: 1. Publicly available information except as included on a list described in subparagraph (i)2 of this paragraph (l); 2. A list, description or other grouping of consumers, and publicly available information pertaining to the list, description or other grouping of consumers, that is derived without using personally identifiable financial information that is not publicly available; or 3. A list of individuals' names and addresses that contains only publicly available information and is not: a. Derived, in whole or in part, using personally identifiable financial information that is not publicly available; and b. Disclosed in a manner that indicates that any of the individuals on the list is a consumer of a licensee. (m) "Notification event" means acquisition of unencrypted customer information without the authorization of the affected individual. For purposes of this paragraph (m): (i) Customer information is considered unencrypted if the encryption key was accessed by an unauthorized person; and (ii) Unauthorized acquisition will be presumed to include unauthorized access to unencrypted customer information unless a licensee has reliable evidence showing that there has not been, or could not reasonably have been, unauthorized acquisition of the customer information. (n) "Penetration testing" means a test methodology in which assessors attempt to circumvent or defeat the security features of an information system by attempting penetration of databases or controls from outside or inside a licensee's information systems. (o) (i) "Personally identifiable financial information" means information: 1. A consumer provides to a licensee to obtain a financial product or service from a licensee; 2. About a consumer resulting from a transaction involving a financial product or service between a licensee and a consumer; or 3. A licensee otherwise obtains about a consumer in connection with providing a financial product or service to that consumer. (ii) The term "personally identifiable financial information" includes: 1. Information a consumer provides to a licensee on an application to obtain a loan, credit card or other financial product or service; 2. Account balance information, payment history, overdraft history and credit or debit card purchase information; 3. The fact that an individual is or has been a licensee's customer or has obtained a financial product or service from a licensee; 4. Information about a licensee's consumer if the information is disclosed in a manner that indicates that the individual is or has been the licensee's consumer; 5. Information that a consumer provides to a licensee or that a licensee or a licensee's agent otherwise obtains in connection with collecting on, or servicing, a credit account; 6. Information a licensee collects through an Internet cookie or the information collecting device from a computer server; and 7. Information from a consumer report. (iii) The term "personally identifiable financial information" does not include: 1. A list of names and addresses of customers of an entity that is not a licensee; and 2. Information that does not identify a consumer, including aggregate information or blind data that does not contain personal identifiers such as account numbers, names or addresses. (p) "Publicly available information" means information that a licensee has a reasonable basis to believe is lawfully made available to the public from federal, state or local government records; widely distributed media; or disclosures to the public that are required to be made by federal, state or local law. The term "publicly available information" includes, but is not limited to: (i) Information in government records, including information in government real estate records and security interest filings; and (ii) Information from widely distributed media, including information from a telephone book, a television or radio program, a newspaper or a website that is available to the public on an unrestricted basis. A website is not considered to be restricted under this subparagraph (ii) merely because an Internet service provider or a site operator requires a fee or a password, so long as access is available to the public. For purposes of this paragraph (p), a licensee has a reasonable basis to believe that information is lawfully made available to the public if the licensee has taken steps to determine that the information is of the type that is available to the public, whether an individual can direct that the information not be made available to the public and, if so, that the licensee's consumer has not directed that the information not be made available to the public. For purposes of this paragraph (p), mortgage information is lawfully made available to the public if the licensee determines that the information is of the type included on the public record in the jurisdiction where the mortgage would be recorded. For purposes of this paragraph (p), an individual's telephone number is lawfully made available to the public if the licensee has located the telephone number in a telephone directory or the consumer has informed the licensee that the telephone number is not unlisted. (q) "Qualified individual" means an individual designated by a licensee to oversee, implement and enforce the licensee's information security program. (r) "Security event" means an event resulting in unauthorized access to, or disruption or misuse of: (i) An information system or information stored on the information system; or (ii) Customer information held in physical form. (s) "Service provider" means a person or entity that receives, maintains, processes or otherwise is permitted access to customer information through its provision of services directly to a licensee that is subject to this act. SECTION 3. Standards for safeguarding customer information. (1) A licensee shall develop, implement and maintain a comprehensive information security program. (2) The information security program under subsection (1) of this section shall: (a) Be written in one or more readily accessible parts; and (b) Contain administrative, technical and physical safeguards that are appropriate to the licensee's size and complexity, the nature and scope of the licensee's activities, and the sensitivity of any customer information at issue. SECTION 4. Information security program required elements. (1) (a) A licensee shall designate a qualified individual to be responsible for implementing, overseeing and enforcing the licensee's information security program. (b) The qualified individual may be employed by the licensee, an affiliate or a service provider. If a licensee designates an individual employed by an affiliate or service provider to oversee the information security program, the licensee: (i) Remains responsible for compliance with this act; (ii) Must designate a senior member of the licensee's personnel to be responsible for the direction and oversight of the qualified individual; and (iii) Must require the service provider or affiliate to maintain an information security program that protects the licensee as required by this act. (2) (a) A licensee shall base the information security program on a risk assessment that: (i) Identifies reasonably foreseeable internal and external risks to the security, confidentiality and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of the information; and (ii) Assesses the sufficiency of any safeguards in place to control these risks. (b) The risk assessment shall be written and include: (i) Criteria for the evaluation and categorization of identified security risks or threats the licensee faces; (ii) Criteria for the assessment of the confidentiality, integrity and availability of the licensee's information systems and customer information, including the adequacy of the existing controls in the context of the identified risks or threats the licensee faces; and (iii) Requirements for mitigating or accepting identified risks based on the risk assessment and a description of how the information security program will address identified risks. (3) A licensee shall periodically perform additional risk assessments that: (a) Reexamine the reasonably foreseeable internal and external risks to the security, confidentiality and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of customer information; and (b) Reassess the sufficiency of any safeguards in place to control these risks. (4) A licensee shall design and implement safeguards to control the risks the financial institution identifies through the risk assessment as required under subsection (2) of this section, including, but not limited to: (a) Implementing and periodically reviewing access controls, including technical and, as appropriate, physical controls, to: (i) Authenticate and permit access only to authorized users to protect against the unauthorized acquisition of customer information; and (ii) Limit authorized users' access only to customer information that the authorized user needs to perform the authorized user's duties and functions, or in the case of customers, to access the customer's own customer information; (b) Identifying and managing the data, personnel, devices, systems and facilities that enable the licensee to achieve business purposes according to the licensee's relative importance to business objectives and the licensee's risk strategy; (c) Protecting by encryption all customer information held or transmitted by the licensee both in transit over external networks and at rest. To the extent the licensee determines that encryption of customer information, either in transit over external networks or at rest, is infeasible, the licensee may instead secure the customer information using effective alternative compensating controls reviewed and approved by the licensee's qualified individual; (d) Adopting secure development practices for in-house developed applications used by the licensee for transmitting, accessing or storing customer information and procedures for evaluating, assessing or testing the security of externally developed applications the licensee uses to transmit, access or store customer information; (e) Implementing multi-factor authentication for an individual accessing an information system, unless the licensee's qualified individual has approved in writing the use of reasonably equivalent or more secure access controls; (f) Developing, implementing and maintaining procedures for the secure disposal of customer information in any format no later than two (2) years after the last date the customer information was used in connection with the provision of a financial product or service to the customer, unless the customer information is: (i) Necessary for business operations or for other legitimate business purposes; (ii) Otherwise required to be retained by state or federal law or regulation; or (iii) Where targeted disposal is not reasonably feasible due to the manner in which the information is maintained; (g) Periodically reviewing the licensee's data retention policy to minimize the unnecessary retention of data; (h) Adopting procedures for change management; and (i) Implementing policies, procedures and controls designed to monitor and log the activity of authorized users and detect unauthorized access or use of, or tampering with, customer information by these users. (5) (a) A licensee shall regularly test or otherwise monitor the effectiveness of the safeguards' key controls, systems and procedures, including those to detect actual and attempted attacks on or intrusions into information systems. (b) For information systems, monitoring and testing shall include continuous monitoring or periodic penetration testing and vulnerability assessments. Absent effective continuous monitoring or other systems to detect, on an ongoing basis, changes in information systems that may create vulnerabilities, the licensee shall conduct: (i) Annual penetration testing of a licensee's information systems determined each given year based on relevant identified risks according to the risk assessment; and (ii) Vulnerability assessments, including a systemic scan or review of an information system reasonably designed to identify publicly known security vulnerabilities in the licensee's information systems based on the risk assessment, at least every six (6) months, and whenever there are: 1. Material changes to the licensee's operations or business arrangements; and 2. Circumstances the licensee knows or has reason to know may have a material impact on the licensee's information security program. (6) A licensee shall implement policies and procedures to ensure that personnel are able to enact the licensee's information security program by: (a) Providing the licensee's personnel with security awareness training that is updated as necessary to reflect risks identified by the risk assessment; (b) Using qualified information security personnel employed by the licensee or an affiliate or service provider sufficient to manage the licensee's information security risks and to perform or oversee the information security program; (c) Providing information security personnel with security updates and training sufficient to address relevant security risks; and (d) Verifying that key information security personnel take steps to maintain current knowledge of changing information, security threats and countermeasures. (7) (a) A licensee shall take reasonable steps to select and retain service providers that are capable of maintaining appropriate safeguards for the customer information at issue. As a provision of the contract between a licensee and a service provider, the service provider shall be required to implement and maintain such safeguards. (b) A licensee shall periodically assess its service providers based on the risk they present and the continued adequacy of their safeguards. (8) A licensee shall evaluate and adjust the licensee's information security program to reflect: (a) The results of the testing and monitoring required by subsection (5) of this section; (b) A material change to the licensee's operations or business arrangements or other circumstances; (c) The results of risk assessments performed under subsection (2) of this section; and (d) Any other circumstances that the licensee knows or has reason to know may have a material impact on the licensee's information security program. (9) A licensee shall establish a written incident response plan designed to promptly respond to, and recover from, any security event materially affecting the confidentiality, integrity or availability of customer information in the licensee's control. The incident response plan shall address: (a) The goals of the incident response plan; (b) The internal processes for responding to a security event; (c) The definition of clear roles, responsibilities and levels of decision-making authority; (d) External and internal communications and information sharing; (e) Identification of requirements for the remediation of any identified weaknesses in information systems and associated controls; (f) Documentation and reporting regarding security events and related incident response activities; and (g) The evaluation and revision as necessary of the incident response plan following a security event. (10) (a) The licensee's qualified individual shall report in writing, at least annually, to the licensee's board of directors or equivalent governing body. If a board of directors or equivalent governing body does not exist, the report required under this subsection (10) shall be timely presented to a senior officer responsible for the licensee's information security program. (b) The report shall include: (i) The overall status of the information security program and the licensee's compliance with Sections 1 through 7 of this act and associated rules; and (ii) Material matters related to the information security program, addressing issues such as risk assessment, risk management and control decisions, service provider arrangements, results of testing, security events or violations and management's responses to security events or violations, and recommendations for changes in the information security program. (11) A licensee shall establish a written plan addressing business continuity and disaster recovery. SECTION 5. Notification to the commissioner. (1) A licensee shall provide notice to the commissioner about notification events. Upon discovery of a notification event, if the notification event involves the information of any consumers in this state, the licensee shall notify the commissioner as soon as possible, but in no event later than seventy-two (72) hours after discovery of the notification event. The notice shall be made in a format specified by the commissioner and include the following information: (a) The name and contact information of the reporting licensee; (b) A description of the types of information that were involved in the notification event; (c) If the information is possible to determine, the date or date range of the notification event; (d) The number of consumers affected or potentially affected by the notification event; (e) A general description of the notification event; and (f) Whether a law enforcement official has provided the licensee with a written determination that notifying the public of the notification event would impede a criminal investigation or cause damage to national security, and a means for the commissioner to contact the law enforcement official. (2) Pursuant to subsection (1)(f) of this section, a law enforcement official may request an initial delay of up to thirty (30) days following the date when notice was provided to the commissioner. The delay may be extended for an additional period of up to sixty (60) days if the law enforcement official seeks an extension in writing. Additional delay may be permitted only if the commissioner determines that public disclosure of a notification event continues to impede a criminal investigation or cause damage to national security. (3) A notification event under this section shall be treated as discovered as of the first day on which the notification event is known to the licensee. The licensee shall be deemed to have knowledge of a notification event if the notification event is known to any of the licensee's employees, officers or other agents, excluding the person committing the notification event. (4) If a licensee becomes aware of a notification event in a system maintained by a service provider, the licensee shall treat such event as it would under subsection (1) of this section. However, the computation of the licensee's deadlines shall begin on the day after the service provider notifies the licensee of the notification event or the licensee otherwise has actual knowledge of the event, whichever is sooner. SECTION 6. Exceptions. (1) Subsections (2)(b), (5)(b), (9) and (10) of Section 4 of this act shall not apply to a licensee that maintains customer information concerning fewer than five thousand (5,000) consumers. SECTION 7. Authority of the Commissioner. (1) The commissioner shall have the power to examine and investigate the affairs of any covered licensee to determine whether the licensee has been or is engaged in any conduct in violation of Sections 1 through 7 of this act. This authority is in addition to the other powers that the commissioner has under the Money Transmission Modernization Act. (2) Whenever the commissioner has reason to believe that a licensee has been or is engaged in conduct in this state that violates Sections 1 through 7 of this act, the commissioner may take action that is necessary or appropriate to enforce the provisions of Sections 1 through 7 of this act. SECTION 8. Sections 1 through 7 of this act shall be codified in Title 75, Mississippi Code of 1972. SECTION 9. Section 75-16-25, Mississippi Code of 1972, is amended as follows: 75-16-25. Application for license. (1) Applicants for a license shall apply in a form and in a medium as prescribed by the commissioner. Each such form shall contain content as set forth by rule, regulation, instruction or procedure of the commissioner and may be changed or updated by the commissioner in accordance with applicable law in order to carry out the purposes of this chapter and maintain consistency with NMLS licensing standards and practices. The application must state or contain, as applicable: (a) The legal name and residential and business addresses of the applicant and any fictitious or trade name used by the applicant in conducting its business; (b) A list of any criminal convictions of the applicant and any material litigation in which the applicant has been involved in the ten-year period next preceding the submission of the application; (c) A description of any money transmission previously provided by the applicant and the money transmission that the applicant seeks to provide in this state; (d) A list of the applicant's proposed authorized delegates and the locations, including virtual currency kiosks, in this state where the applicant and its authorized delegates propose to engage in money transmission or provide any other money services, including, but not limited to, virtual currency kiosk transactions; (e) A list of other states in which the applicant is licensed to engage in money transmission and any license revocations, suspensions or other disciplinary action taken against the applicant in another state; (f) Information concerning any bankruptcy or receivership proceedings affecting the licensee or a person in control of a licensee; (g) A sample form of contract for authorized delegates, if applicable; (h) A sample form of payment instrument or stored value, as applicable; (i) The name and address of any federally insured depository financial institution through which the applicant plans to conduct money transmission; and (j) Any other information the commissioner or NMLS requires with respect to the applicant. (2) If an applicant is a corporation, limited liability company, partnership or other legal entity, the applicant shall also provide: (a) The date of the applicant's incorporation or formation and state or country of incorporation or formation; (b) If applicable, a certificate of good standing from the state or country in which the applicant is incorporated or formed; (c) A brief description of the structure or organization of the applicant, including any parents or subsidiaries of the applicant, and whether any parents or subsidiaries are publicly traded; (d) The legal name, any fictitious or trade name, all business and residential addresses and the employment, as applicable, in the ten-year period next preceding the submission of the application of each key individual and person in control of the applicant; (e) A list of any criminal convictions and material litigation in which a person in control of the applicant that is not an individual has been involved in the ten-year period next preceding the submission of the application; (f) A copy of audited financial statements of the applicant for the most recent fiscal year and for the two-year period next preceding the submission of the application; (g) A certified copy of unaudited financial statements of the applicant for the most recent fiscal quarter; (h) If the applicant is a publicly traded corporation, a copy of the most recent report filed with the United States Securities and Exchange Commission under Section 13 of the U.S. Securities Exchange Act of 1934, 15 USC Section 78m, as amended or recodified from time to time; (i) If the applicant is a wholly owned subsidiary of: (i) A corporation publicly traded in the United States, a copy of audited financial statements for the parent corporation for the most recent fiscal year or a copy of the parent corporation's most recent report filed under Section 13 of the U.S. Securities Exchange Act of 1934, 15 USC Section 78m, as amended or recodified from time to time; or (ii) A corporation publicly traded outside the United States, a copy of similar documentation filed with the regulator of the parent corporation's domicile outside the United States; (j) The name and address of the applicant's registered agent in this state; and (k) Any other information the commissioner requires with respect to the applicant. (3) A nonrefundable license fee of One Thousand Five Hundred Dollars ($1,500.00) must accompany an application for a license under this section. However, beginning with calendar year 2025 and for each subsequent calendar year, on or before July 1 of the following year, the Mississippi Department of Banking and Consumer Finance will issue a memo authorizing a new license fee under this section. The new amount will be calculated by applying any increase or decrease in the United States Bureau of Labor Statistics Consumer Price Index for All Urban Consumers (CPI-U) for the previous calendar year to the previous fee amount and rounding that amount upward to the nearest One-Hundred-Dollar increment. (4) The commissioner may waive one or more requirements of subsections (1) and (2) of this section or permit an applicant to submit other information in lieu of the required information. SECTION 10. Section 75-16-31, Mississippi Code of 1972, is amended as follows: 75-16-31. Renewal of license. (1) A license under this chapter shall be renewed annually. (a) An annual renewal fee of Eight Hundred Dollars ($800.00) plus One Hundred Dollars ($100.00) for each location in excess of one in Mississippi through which the licensee plans to conduct money transmission during the license year for which the fee is paid, shall be paid, provided that in no event shall the annual renewal fee exceed Five Thousand Eight Hundred Dollars ($5,800.00). Such renewal fee shall be paid no more than sixty (60) days before the license expiration. (b) The renewal term shall be for a period of one (1) year and shall begin on January 1 of each year after the initial license term and shall expire on December 31 of the year the renewal term begins. (2) A licensee shall submit a renewal report with the renewal fee, in a form and in a medium prescribed by the commissioner. The renewal report must state or contain a description of each material change in information submitted by the licensee in its original license application which has not been reported to the commissioner. The report must also contain a list of the locations in this state where the licensee or an authorized delegate of the licensee engages in virtual currency kiosk transactions. (3) The commissioner, for good cause, may grant an extension of the renewal date. (4) The commissioner is authorized and encouraged to utilize NMLS to process license renewals provided that such functionality is consistent with this section. SECTION 11. Section 75-16-43, Mississippi Code of 1972, is amended as follows: 75-16-43. Authorized delegate reporting. (1) Each licensee shall submit a report of all authorized delegates and locations in this state where the licensee or an authorized delegate of the licensee provides money services, including, but not limited to, virtual currency kiosks. Such report must be provided within forty-five (45) days of the end of the calendar quarter. The commissioner is authorized and encouraged to utilize NMLS for the submission of the report required by this subsection provided that such functionality is consistent with the requirements of this section. Such utilization shall include the NMLS Uniform Authorized Agent Reporting (UAAR) process, or such other similar process as designated by NMLS. (2) The authorized delegate report shall include, at a minimum, each authorized delegate's: (a) Company legal name; (b) Taxpayer employer identification number; (c) Principal provider identifier; (d) Physical address; (e) Mailing address; (f) Any business conducted in other states; (g) Any fictitious or trade name; (h) Contact person name, phone number, and email; (i) Start date as licensee's authorized delegate; (j) End date acting as licensee's authorized delegate, if applicable; and (k) Any other information the commissioner requires with respect to the authorized delegate. SECTION 12. Section 75-16-51, Mississippi Code of 1972, is amended as follows: 75-16-51. Relationship between licensee and authorized delegate. (1) In this section, "remit" means to make direct payments of money to a licensee or its representative authorized to receive money or to deposit money in a bank in an account specified by the licensee. (2) Before a licensee is authorized to conduct business through an authorized delegate or allows a person to act as the licensee's authorized delegate, the licensee must: (a) Adopt, and update as necessary, written policies and procedures designed to ensure that the licensee's authorized delegates comply with applicable state and federal law; (b) Enter into a written contract, available to the commissioner upon request, that complies with subsection (4) of this section; and (c) Conduct a risk-based background investigation sufficient for the licensee to determine whether the authorized delegate has complied and will likely comply with applicable state and federal law. (3) An authorized delegate must operate in full compliance with this chapter. (4) The written contract required by subsection (2) of this section must be signed by the licensee and the authorized delegate and, at a minimum, must: (a) Appoint the person signing the contract as the licensee's authorized delegate with the authority to conduct money transmission on behalf of the licensee; (b) Set forth the nature and scope of the relationship between the licensee and the authorized delegate and the respective rights and responsibilities of the parties; (c) Require the authorized delegate to agree to fully comply with all applicable state and federal laws, rules, and regulations pertaining to money transmission, including this chapter and regulations implementing this chapter, relevant provisions of the Bank Secrecy Act and the USA PATRIOT ACT; (d) Require the authorized delegate to remit and handle money and monetary value in accordance with the terms of the contract between the licensee and the authorized delegate; (e) Impose a trust on money and monetary value net of fees received for money transmission for the benefit of the licensee; (f) Require the authorized delegate to prepare and maintain records as required by this chapter or regulations implementing this chapter, or as requested by the commissioner; (g) Acknowledge that the authorized delegate consents to examination or investigation by the commissioner; (h) State that the licensee is subject to regulation by the commissioner and that, as part of that regulation, the commissioner may suspend or revoke an authorized delegate designation or require the licensee to terminate an authorized delegate designation; and (i) Acknowledge receipt of the written policies and procedures required under subsection (2)(a) of this section. (5) If the licensee's license is suspended, revoked, surrendered or expired, the licensee must, within five (5) business days, provide documentation to the commissioner that the licensee has notified all applicable authorized delegates of the licensee whose names are in a record filed with the commissioner of the suspension, revocation, surrender or expiration of a license. Upon suspension, revocation, surrender or expiration of a license, applicable authorized delegates shall immediately cease to provide money transmission as an authorized delegate of the licensee. (6) An authorized delegate of a licensee holds in trust for the benefit of the licensee all money net of fees received from money transmission. If any authorized delegate commingles any funds received from money transmission with any other funds or property owned or controlled by the authorized delegate, all commingled funds and other property shall be considered held in trust in favor of the licensee in an amount equal to the amount of money net of fees received from money transmission. (7) An authorized delegate may not use a subdelegate to conduct money transmission on behalf of a licensee. (8) On or before April 1 of each year, a licensee shall provide to each authorized delegate through which it engages in the business of money transmission training materials on how to: (a) Recognize financial abuse and financial exploitation of an elder adult; and (b) Respond appropriately if the authorized delegate suspects that the authorized delegate is being asked to engage in the business of money transmission for a fraudulent transaction in which an elder adult is the victim of financial abuse or financial exploitation. A licensee shall provide the training materials required under this subsection (8) to each newly appointed authorized delegate within one (1) month after appointment of the authorized delegate. SECTION 13. Section 75-16-65, Mississippi Code of 1972, is amended as follows: 75-16-65. Maintenance of permissible investments. (1) A licensee shall maintain at all times permissible investments that have a market value computed in accordance with United States Generally Accepted Accounting Principles of not less than the aggregate amount of all of its outstanding money transmission obligations. (2) Except for permissible investments enumerated in Section 75-16-67(1), the commissioner, with respect to any licensee, may by rule, regulation or order limit the extent to which a specific investment maintained by a licensee within a class of permissible investments may be considered a permissible investment, if the specific investment represents undue risk to customers, not reflected in the market value of investments. (3) Permissible investments, even if commingled with other assets of the licensee, are held in trust for the benefit of the purchasers and holders of the licensee's outstanding money transmission obligations in the event of insolvency, the filing of a petition by or against the licensee under the United States Bankruptcy Code, 11 USC Sections 101-110, as amended or recodified from time to time, for bankruptcy or reorganization, the filing of a petition by or against the licensee for receivership, the commencement of any other judicial or administrative proceeding for its dissolution or reorganization, or in the event of an action by a creditor against the licensee who is not a beneficiary of this statutory trust. No permissible investments impressed with a trust pursuant to this subsection (3) shall be subject to attachment, levy of execution or sequestration by order of any court, except for a beneficiary of this statutory trust. (4) Upon the establishment of a statutory trust in accordance with subsection (3) of this section or when any funds are drawn on a letter of credit pursuant to Section 75-16-67(1), the commissioner shall notify the applicable regulator of each state in which the licensee is licensed to engage in money transmission, if any, of the establishment of the trust or the funds drawn on the letter of credit, as applicable. Notice shall be deemed satisfied if performed pursuant to a multistate agreement or through NMLS. Funds drawn on a letter of credit, and any other permissible investments held in trust for the benefit of the purchasers and holders of the licensee's outstanding money transmission obligations, are deemed held in trust for the benefit of such purchasers and holders on a pro rata and equitable basis in accordance with statutes pursuant to which permissible investments are required to be held in this state, and other states, as applicable. Any statutory trust established hereunder shall be terminated upon extinguishment of all of the licensee's outstanding money transmission obligations. (5) The commissioner, by rule, regulation or by order may allow other types of investments that the commissioner determines are of sufficient liquidity and quality to be a permissible investment. The commissioner is authorized to participate in efforts with other state regulators to determine that other types of investments are of sufficient liquidity and quality to be a permissible investment. SECTION 14. The following shall be codified as Section 75-16-89, Mississippi Code of 1972: 75-16-89. (1) A licensee shall provide its name and mailing address or telephone number to the purchaser in connection with each money transmission or kiosk transaction conducted by the licensee directly or through an authorized delegate. (2) An authorized delegate shall display prominently in a form and in a medium prescribed by the commissioner a notice that states or contains the following information: (a) The name, mailing address and telephone number of the authorized delegate; (b) For each licensee of the authorized delegate: (i) A statement that the authorized delegate is an agent conducting business on behalf of the licensee under this chapter; and (ii) The name, mailing address and telephone number of the licensee; and (c) A statement: (i) Directing consumers with complaints to contact the Department of Banking and Consumer Finance; and (ii) Containing the current mailing address and telephone number of the department. (3) (a) A licensee or authorized delegate shall include a clear, concise and conspicuous fraud warning that is posted in a conspicuous area or included on a transmittal form used by a consumer to send money to another individual. (b) The fraud warning required under subsection (3)(a) of this section shall: (i) Include a toll-free telephone number for consumers to call to report fraud or suspected fraud; and (ii) Be in clear, conspicuous and legible writing in English and in the language principally used by the licensee or authorized delegate to advertise, solicit or negotiate, either orally or in writing, for a transaction conducted in person, electronically or by telephone, if other than English. (c) A licensee shall monitor the activities of its authorized delegates relating to transmittals by consumers. (d) If a licensee or authorized delegate conducts money transmission activity through a website or a mobile application that is not in a physical location, the commissioner may authorize an alternative form of the fraud notice required under subsection (3)(a) of this section. SECTION 15. This act shall take effect and be in force from and after July 1, 2026.
Every fact on this page links to its source, starting with the official bill record.