Money Transmission Act: authentication.

SB 505

California Bills

20250SB__050595AMD INTRODUCED 2025-02-19 AMENDED_SENATE 2025-03-24 AMENDED_SENATE 2026-01-05 AMENDED_ASSEMBLY 2026-05-26 AMENDED_ASSEMBLY 2026-06-22 2025 SB AMD Introduced by Senator Richardson LEAD_AUTHOR SENATE Richardson

An act to add

Chapter 10 (commencing with

Section 2180) to Division 1.2 of the Financial Code, relating to financial protection. financial protection Money Transmission Act: authentication. The Money Transmission Act (MTA) prohibits a person from engaging in the business of money transmission in the state, or from advertising, soliciting, or holding itself out as providing money transmission in the state, unless the person is licensed by the Department of Financial Protection and Innovation under the act.

The MTA defines “money transmission” to mean, among other things, selling or issuing stored value to a person located in the state and defines “stored value” to mean monetary value representing a claim against the issuer that is stored on an electronic or digital medium and evidenced by an electronic or digital record and that is intended and accepted for use as a means of redemption for money or monetary value or payment for goods or services. The MTA punishes noncompliance with, among other things, a civil penalty, license revocation, and, for certain violations, as a felony, as prescribed.

This bill would prohibit a licensee under the MTA from allowing a user login unless the licensee has implemented specified processes, including 2-factor authentication, multifactor authentication, or other reasonably equivalent or more secure access control, as specified. The bill would provide that its provisions become operative January 1, 2028. By expanding the scope of a crime, this bill would impose a state-mandated local program. The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state.

Statutory provisions establish procedures for making that reimbursement. This bill would provide that no reimbursement is required by this act for a specified reason. MAJORITY NO YES YES NO NO NO NO NO NO NO The people of the State of California do enact as follows:

SECTION 1. It is the intent of the Legislature that implementation of this act is consistent with evolving security standards while maintaining strong consumer protections.

SEC. 2.

Chapter 10 (commencing with

Section 2180) is added to Division 1.2 of the Financial Code , to read: 10. Authentication 2180. For purposes of this chapter: (a) “Multifactor authentication” means an authentication process that requires two or more forms of verification. (b) “Two-factor authentication” means a security process that requires two distinct forms of verification. (c) “User login” means an action by which a user accesses an account or platform for the purpose of initiating, receiving, or managing money transmission services for the first time or after a logout. 2181. (

a) A licensee shall not allow a user login without implementing all of the following:

(1) Two-factor authentication, multifactor authentication, or other reasonably equivalent or more secure access control.

(2) A process for reverifying the identity of the user, device, or system using two-factor authentication, multifactor authentication, or other reasonably equivalent or more secure access control.

(3) The ability for a user to report an error or suspected fraud using the same platform through which the user accessed the money transmission service or through a reasonably accessible alternative. (

b) A secure access control method described in paragraph (1) of subdivision (

a) shall be approved in writing by an individual employed or contracted by the licensee who is responsible for overseeing, implementing, and enforcing the licensee’s information security program. (

c) In implementing paragraph (2) of subdivision (a), both of the following apply:

(1) The licensee shall use a risk-based approach that balances consumer protection with reasonable user access.

(2) The licensee may consider any relevant factor, including, but not limited to, any of the following, provided that the consideration does not compromise security or protections against unauthorized access: (

A) The level of risk presented by the activity. (

B) Indicators of anomalous behavior. (

C) The sensitivity of the transaction. <caml:Num>2182.</caml:Num><caml:LawSectionVersion id="id_02D4B4BD-842E-4AEF-A404-684F575C06D0"><caml:Content><xhtml:p>(a)<xhtml:span class="EnSpace"/>A licensee shall not allow a user login without implementing all of the following:</xhtml:p><xhtml:p>(1)<xhtml:span class="EnSpace"/>An automatic logout requirement.</xhtml:p><xhtml:p>(2)<xhtml:span class="EnSpace"/>A session timeout requirement.</xhtml:p><xhtml:p>(3)<xhtml:span class="EnSpace"/>A reauthentication requirement.</xhtml:p><xhtml:p>(b)<xhtml:span class="EnSpace"/>In implementing the requirements described in subdivision (a), the licensee shall use a risk-based approach that balances consumer protection with reasonable user access.</xhtml:p><xhtml:p>(c)<xhtml:span class="EnSpace"/>In implementing the requirements described in subdivision (a), the licensee may consider any of the following factors, provided that the consideration does not compromise security or protections against unauthorized access:</xhtml:p><xhtml:p>(1)<xhtml:span class="EnSpace"/>The level of risk presented by the activity.</xhtml:p><xhtml:p>(2)<xhtml:span class="EnSpace"/>Indicators of anomalous behavior.</xhtml:p><xhtml:p>(3)<xhtml:span class="EnSpace"/>The sensitivity of the transaction.</xhtml:p></caml:Content></caml:LawSectionVersion></caml:LawSection>"?> 2182.

This

chapter shall become operative January 1, 2028.

SEC. 3. No reimbursement is required by this act pursuant to

Section of

Article XIII B of the California Constitution because the only costs that may be incurred by a local agency or school district will be incurred because this act creates a new crime or infraction, eliminates a crime or infraction, or changes the penalty for a crime or infraction, within the meaning of

Section of the Government Code, or changes the definition of a crime within the meaning of

Section of

Article XIII B of the California Constitution.

Document details

CollectionCalifornia Bills
CitationSB 505
Date2026-06-22
Typebill
Languageen
SourceCA_BILL
Identifier20250SB50595AMD

Money Transmission Act: authentication.

SB 505

California Bills

Money Transmission Act: authentication.

SB 505

California Bills

20250SB__050595AMD INTRODUCED 2025-02-19 AMENDED_SENATE 2025-03-24 AMENDED_SENATE 2026-01-05 AMENDED_ASSEMBLY 2026-05-26 AMENDED_ASSEMBLY 2026-06-22 2025 SB AMD Introduced by Senator Richardson LEAD_AUTHOR SENATE Richardson

An act to add

Chapter 10 (commencing with

Section 2180) to Division 1.2 of the Financial Code, relating to financial protection. financial protection Money Transmission Act: authentication. The Money Transmission Act (MTA) prohibits a person from engaging in the business of money transmission in the state, or from advertising, soliciting, or holding itself out as providing money transmission in the state, unless the person is licensed by the Department of Financial Protection and Innovation under the act.

The MTA defines “money transmission” to mean, among other things, selling or issuing stored value to a person located in the state and defines “stored value” to mean monetary value representing a claim against the issuer that is stored on an electronic or digital medium and evidenced by an electronic or digital record and that is intended and accepted for use as a means of redemption for money or monetary value or payment for goods or services. The MTA punishes noncompliance with, among other things, a civil penalty, license revocation, and, for certain violations, as a felony, as prescribed.

This bill would prohibit a licensee under the MTA from allowing a user login unless the licensee has implemented specified processes, including 2-factor authentication, multifactor authentication, or other reasonably equivalent or more secure access control, as specified. The bill would provide that its provisions become operative January 1, 2028. By expanding the scope of a crime, this bill would impose a state-mandated local program. The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state.

Statutory provisions establish procedures for making that reimbursement. This bill would provide that no reimbursement is required by this act for a specified reason. MAJORITY NO YES YES NO NO NO NO NO NO NO The people of the State of California do enact as follows:

SECTION 1. It is the intent of the Legislature that implementation of this act is consistent with evolving security standards while maintaining strong consumer protections.

SEC. 2.

Chapter 10 (commencing with

Section 2180) is added to Division 1.2 of the Financial Code , to read: 10. Authentication 2180. For purposes of this chapter: (a) “Multifactor authentication” means an authentication process that requires two or more forms of verification. (b) “Two-factor authentication” means a security process that requires two distinct forms of verification. (c) “User login” means an action by which a user accesses an account or platform for the purpose of initiating, receiving, or managing money transmission services for the first time or after a logout. 2181. (

a) A licensee shall not allow a user login without implementing all of the following:

(1) Two-factor authentication, multifactor authentication, or other reasonably equivalent or more secure access control.

(2) A process for reverifying the identity of the user, device, or system using two-factor authentication, multifactor authentication, or other reasonably equivalent or more secure access control.

(3) The ability for a user to report an error or suspected fraud using the same platform through which the user accessed the money transmission service or through a reasonably accessible alternative. (

b) A secure access control method described in paragraph (1) of subdivision (

a) shall be approved in writing by an individual employed or contracted by the licensee who is responsible for overseeing, implementing, and enforcing the licensee’s information security program. (

c) In implementing paragraph (2) of subdivision (a), both of the following apply:

(1) The licensee shall use a risk-based approach that balances consumer protection with reasonable user access.

(2) The licensee may consider any relevant factor, including, but not limited to, any of the following, provided that the consideration does not compromise security or protections against unauthorized access: (

A) The level of risk presented by the activity. (

B) Indicators of anomalous behavior. (

C) The sensitivity of the transaction. <caml:Num>2182.</caml:Num><caml:LawSectionVersion id="id_02D4B4BD-842E-4AEF-A404-684F575C06D0"><caml:Content><xhtml:p>(a)<xhtml:span class="EnSpace"/>A licensee shall not allow a user login without implementing all of the following:</xhtml:p><xhtml:p>(1)<xhtml:span class="EnSpace"/>An automatic logout requirement.</xhtml:p><xhtml:p>(2)<xhtml:span class="EnSpace"/>A session timeout requirement.</xhtml:p><xhtml:p>(3)<xhtml:span class="EnSpace"/>A reauthentication requirement.</xhtml:p><xhtml:p>(b)<xhtml:span class="EnSpace"/>In implementing the requirements described in subdivision (a), the licensee shall use a risk-based approach that balances consumer protection with reasonable user access.</xhtml:p><xhtml:p>(c)<xhtml:span class="EnSpace"/>In implementing the requirements described in subdivision (a), the licensee may consider any of the following factors, provided that the consideration does not compromise security or protections against unauthorized access:</xhtml:p><xhtml:p>(1)<xhtml:span class="EnSpace"/>The level of risk presented by the activity.</xhtml:p><xhtml:p>(2)<xhtml:span class="EnSpace"/>Indicators of anomalous behavior.</xhtml:p><xhtml:p>(3)<xhtml:span class="EnSpace"/>The sensitivity of the transaction.</xhtml:p></caml:Content></caml:LawSectionVersion></caml:LawSection>"?> 2182.

This

chapter shall become operative January 1, 2028.

SEC. 3. No reimbursement is required by this act pursuant to

Section of

Article XIII B of the California Constitution because the only costs that may be incurred by a local agency or school district will be incurred because this act creates a new crime or infraction, eliminates a crime or infraction, or changes the penalty for a crime or infraction, within the meaning of

Section of the Government Code, or changes the definition of a crime within the meaning of

Section of

Article XIII B of the California Constitution.

Document details

CollectionCalifornia Bills
CitationSB 505
Date2026-06-22
Typebill
Languageen
SourceCA_BILL
Identifier20250SB50595AMD
Money Transmission Act: authentication. | CaseLite