Senate Bill 1216 (2025) — Cybersecurity of mortgage brokers and lenders and money services businesses

SB 1216

Florida Bills

Florida Senate - 2025 SB 1216 By Senator DiCeglie 18-01808-25 20251216__ Page 1 of 19 CODING: Words stricken are deletions; words underlined are additions. A bill to be entitled 1

An act relating to cybersecurity of mortgage brokers 2 and lenders and money services businesses; creating 3 ss. 494.00170 and 560.1215, F.S.; defining terms; 4 requiring licensees to develop and maintain a 5 specified information security program; requiring that 6 such program meet certain criteria; requiring 7 licensees to establish a specified incident response 8 plan; providing requirements for such plan; providing 9 applicability; specifying that a licensee has a 10 specified timeframe to comply with certain provisions; 11 requiring the licensee to maintain a copy of the 12 information security program for a specified period of 13 time; requiring such program to be available upon 14 request or examination; requiring licensees to make a 15 prompt investigation of a cybersecurity event that has 16 occurred or may occur; specifying requirements for 17 such investigation; requiring licensees to complete an 18 investigation or confirm and document that a third-19 party service provider has completed an investigation 20 under certain circumstances; requiring the licensee to 21 maintain specified records and documentation for a 22 specified period of time; requiring the licensee to 23 produce such records and documentation to be available 24 upon request; requiring licensees to provide a 25 specified notice to the Office of Financial 26 Regulation; requiring the licensee to provide a 27 quarterly update of the investigation under certain 28 circumstances; providing construction; authorizing the 29

Florida Senate - 2025 SB 1216 18-01808-25 20251216__ Page 2 of 19 CODING: Words stricken are deletions; words underlined are additions. Financial Services Commission to adopt rules; amending 30 ss. 494.00255 and 560.114, F.S.; revising the actions 31 that constitute grounds for disciplinary actions for 32 mortgage brokers and lenders and grounds for the 33 issuance of a cease and desist order or removal order 34 or the denial, suspension, or revocation of a license 35 of a money service business, respectively; providing 36 an effective date. 37 38 Be It Enacted by the Legislature of the State of Florida: 39 40

Section

Section 494.00170, Florida Statutes, is created 41 to read: 42 494.00170 Cybersecurity.— 43

(1) As used in this section, the term: 44 (a) “Customer” means a person who seeks to obtain, obtains, 45 or has obtained a financial product or service from a licensee 46 covered under this chapter. 47 (b) “Customer information” means any record containing 48 nonpublic personal information about a customer of a financial 49 transaction, whether in paper, electronic, or other form, which 50 is handled or maintained by or on behalf of the licensee or its 51 affiliates. 52 (c) “Cybersecurity event” means an event resulting in 53 unauthorized access to, or disruption or misuse of, an 54 information system, information stored on such information 55 system, or customer information held in physical form. 56 (d) “Financial product or service” means any product or 57 service offered by a licensee under this chapter. 58

Florida Senate - 2025 SB 1216 18-01808-25 20251216__ Page 3 of 19 CODING: Words stricken are deletions; words underlined are additions. (e) “Information security program” means the 59 administrative, technical, or physical safeguards used to 60 access, collect, distribute, process, protect, store, use, 61 transmit, dispose of, or otherwise handle customer information. 62 (f) “Information system” means a discrete set of electronic 63 information resources organized for the collection, processing, 64 maintenance, use, sharing, dissemination, or disposition of 65 electronic information, as well as any specialized system such 66 as an industrial or process control system, telephone switching 67 and private branch exchange system, or environmental control 68 system which contains customer information or is connected to a 69 system that contains customer information. 70 (g)1. “Nonpublic personal information” includes all of the 71 following: 72 a.

Personally identifiable financial information. 73 b. Any list, description, or grouping of customers derived 74 from personally identifiable financial information that is not 75 publicly available. The term includes lists of customers’ names 76 and street addresses which are derived, in whole or in part, 77 from personally identifiable information, such as account 78 numbers. 79 2. The term does not include any of the following: 80 a. Publicly available information, unless it is part of a 81 list described in sub-subparagraph 1.b. 82 b.

Any list, description, or grouping of customers, along 83 with their publicly available information, if the list was 84 created without using any personally identifiable financial 85 information that is not publicly available. A list of customers’ 86 names and addresses is not considered nonpublic personal 87

Florida Senate - 2025 SB 1216 18-01808-25 20251216__ Page 4 of 19 CODING: Words stricken are deletions; words underlined are additions. information if it contains only publicly available information, 88 is not derived in whole or in part from nonpublic personally 89 identifiable financial information, and is not disclosed in a 90 way that indicates any of the customers on the list are 91 customers of the licensee. 92 (h)1. “Personally identifiable financial information” means 93 any information that: 94 a.

A customer provides to a licensee to obtain a financial 95 product or service, such as information submitted on an 96 application for a loan or other financial product or service; 97 b. A licensee receives about a customer during or as a 98 result of any transaction involving a financial product or 99 service, including information collected through an Internet 100 cookie or from a web server; or 101 c.

A licensee otherwise obtains about a customer in 102 connection with providing a financial product or service, such 103 as records indicating that a customer has previously engaged 104 with the licensee or obtained a financial product or service. 105 2. Personally identifiable financial information does not 106 include any of the following: 107 a. A list of names and addresses of customers of an entity 108 that is not a mortgage broker or lender. 109 b.

Information that does not identify a customer, such as 110 aggregate information or anonymized data that does not contain 111 personal identifiers such as account numbers, names, or 112 addresses. 113 (i)1. “Publicly available information” means any 114 information that a licensee has a reasonable basis to believe is 115 lawfully made available to the general public from any of the 116

Florida Senate - 2025 SB 1216 18-01808-25 20251216__ Page 5 of 19 CODING: Words stricken are deletions; words underlined are additions. following: 117 a. Federal, state, or local government records, such as 118 real estate records or security interest filings. 119 b. Widely distributed media, including telephone 120 directories, television or radio programs, newspapers, or 121 websites that are available to the general public on an 122 unrestricted basis.

A website is not restricted merely because 123 an Internet service provider or a site operator requires a fee 124 or a password, so long as access is available to the general 125 public. 126 c. Disclosures to the general public that are required to 127 be made by federal, state, or local law. 128 2. For the purpose of this paragraph, the term “reasonable 129 basis to believe is lawfully made available to the general 130 public” means that the licensee has taken steps to determine all 131 of the following: 132 a.

That the information is of the type that is available to 133 the general public, such as information included on the public 134 record in the jurisdiction where the mortgage would be recorded. 135 b.

Whether an individual can direct that the information 136 not be made available to the general public and, if so, whether 137 the customer to whom the information relates has so directed. 138 (j) “Third-party service provider” means a person, other 139 than a licensee, that contracts with a licensee to maintain, 140 process, or store nonpublic personal information or that is 141 otherwise permitted access to nonpublic personal information 142 through its provision of services to a licensee. 143 (2)(

a) Each licensee shall develop, implement, and maintain 144 a comprehensive written information security program that 145

Florida Senate - 2025 SB 1216 18-01808-25 20251216__ Page 6 of 19 CODING: Words stricken are deletions; words underlined are additions. contains administrative, technical, and physical safeguards for 146 the protection of the licensee’s information system and 147 nonpublic personal information. 148 (

b) A licensee must ensure the information security program 149 meets all of the following criteria: 150 1. Is commensurate with the following measures: 151 a. The size and complexity of the licensee. 152 b. The nature and scope of the licensee’s activities, 153 including its use of third-party service providers. 154 c. The sensitivity of the nonpublic personal information 155 used by the licensee or in the possession, custody, or control 156 of the licensee. 157 2. Is designed to: 158 a.

Protect the security and confidentiality of nonpublic 159 personal information and the security of the licensee’s 160 information system; 161 b. Protect against threats or hazards to the security or 162 integrity of nonpublic personal information and the licensee’s 163 information system; and 164 c. Protect against unauthorized access to or use of 165 nonpublic personal information and minimize the likelihood of 166 harm to any customer. 167 3. Defines and periodically reevaluates the retention 168

schedule and the mechanism for the destruction of nonpublic 169 personal information if retention is no longer necessary for the 170 licensee’s business operations or required by applicable law. 171 4. Regularly tests and monitors systems and procedures for 172 the detection of actual and attempted attacks on, or intrusions 173 into, the information system. 174

Florida Senate - 2025 SB 1216 18-01808-25 20251216__ Page 7 of 19 CODING: Words stricken are deletions; words underlined are additions. 5. Monitors, evaluates, and adjusts, as necessary, the 175 licensee’s information security program to: 176 a. Ensure the program remains consistent with relevant 177 changes in technology; 178 b. Confirm that the program accounts for the sensitivity of 179 nonpublic personal information; 180 c. Identify and address changes that may be necessary to 181 the licensee’s information system; 182 d.

Eliminate any internal or external threats to nonpublic 183 personal information; and 184 e. Amend the licensee’s information security program for 185 any of the licensee’s changing business arrangements, including, 186 but not limited to, mergers and acquisitions, alliances and 187 joint ventures, and outsourcing arrangements. 188 (

c) As part of a licensee’s information security program, a 189 licensee shall establish a written incident response plan 190 designed to promptly respond to, and recover from, a 191 cybersecurity event that compromises the confidentiality, 192 integrity, or availability of nonpublic personal information in 193 the licensee’s possession, the licensee’s information system, or 194 the continuing functionality of any aspect of the licensee’s 195 operations. The written incident response plan must address all 196 of the following: 197 1.

The licensee’s internal process for responding to a 198 cybersecurity event. 199 2. The goals of the licensee’s incident response plan. 200 3. The assignment of clear roles, responsibilities, and 201 levels of decisionmaking authority for personnel that 202 participate in the incident response plan. 203

Florida Senate - 2025 SB 1216 18-01808-25 20251216__ Page 8 of 19 CODING: Words stricken are deletions; words underlined are additions. 4. External communications, internal communications, and 204 information sharing related to a cybersecurity event. 205 5. The identification of remediation requirements for 206 weaknesses identified in information systems and associated 207 controls. 208 6. Documentation and reporting regarding cybersecurity 209 events and related incident response activities. 210 7.

The evaluation and revision of the incident response 211 plan, as appropriate, following a cybersecurity event. 212 8. The process by which notice must be given as required 213 under subsection (4) and s. 501.171(3) and (4). 214 (

d) This subsection does not apply to a licensee that: 215 1. Has fewer than 20 persons on its workforce, including 216 employees and independent contractors; or 217 2. Has fewer than 500 customers during a calendar year. 218 (

e) A licensee has 180 calendar days from the date the 219 licensee no longer qualifies for exemption under paragraph (d) 220 to comply with this section. 221 (

f) A licensee shall maintain a copy of the information 222 security program for a minimum of 5 years and shall make it 223 available to the office upon request or as part of an 224 examination. 225 (3)(

a) If a licensee discovers that a cybersecurity event 226 has occurred, or that a cybersecurity event may have occurred, 227 the licensee, or the outside vendor or third-party service 228 provider the licensee has designated to act on its behalf, shall 229 conduct a prompt investigation of the event. 230 (

b) During the investigation, the licensee, or the outside 231 vendor or third-party service provider the licensee has 232

Florida Senate - 2025 SB 1216 18-01808-25 20251216__ Page 9 of 19 CODING: Words stricken are deletions; words underlined are additions. designated to act on its behalf, shall, at a minimum, determine 233 all of the following, to the extent possible: 234 1. Whether a cybersecurity event has occurred. 235 2. The date the cybersecurity event first occurred. 236 3. The nature and scope of the cybersecurity event. 237 4. Any nonpublic personal information that may have been 238 compromised. 239 5.

Reasonable measures to restore the security of 240 compromised information systems and prevent further unauthorized 241 access, disclosure, or use of nonpublic personal information in 242 the possession, custody, or control of the licensee, outside 243 vendor, or third-party service provider. 244 (

c) If a licensee learns that a cybersecurity event has 245 occurred, or may have occurred, in an information system 246 maintained by a third-party service provider of the licensee, 247 the licensee must complete an investigation in compliance with 248 this

section or confirm and document that the third-party 249 service provider has completed an investigation in compliance 250 with this section. 251 (

d) A licensee shall maintain all records and documentation 252 related to the licensee’s investigation of a cybersecurity event 253 for a minimum of 5 years from the date of the event and shall 254 produce the records and documentation upon the office’s request. 255 (4)(

a) A licensee shall provide notice to the office of any 256 breach of security affecting 500 or more persons in this state 257 at a time and in the manner prescribed by commission rule. 258 (

b) A licensee shall, upon request by the office, provide a 259 quarterly update of the investigation undertaken pursuant to 260 subsection (3), until conclusion of the investigation. 261

Florida Senate - 2025 SB 1216 18-01808-25 20251216__ Page 10 of 19 CODING: Words stricken are deletions; words underlined are additions.

(5) This

section may not be construed to relieve a covered 262 entity from complying with s. 501.171. To the extent a licensee 263 is a covered entity, as that term is defined in s. 264 501.171(1)(b), such covered entity remains subject to s. 265 501.171. 266

(6) The commission may adopt rules to administer this 267 section, including rules that allow a licensee that is in full 268 compliance with 16 C.F.R

part 314, Standards for Safeguarding 269 Customer Information, by the Federal Trade Commission, to be 270 deemed in compliance with this section. 271

Section 2. Paragraph (

z) is added to subsection (1) of 272

section 494.00255, Florida Statutes, to read: 273 494.00255 Administrative penalties and fines; license 274 violations.— 275

(1) Each of the following acts constitutes a ground for 276 which the disciplinary actions specified in subsection (2) may 277 be taken against a person licensed or required to be licensed 278 under

part II or

part III of this chapter: 279 (

z) Failure to comply with the notification requirements in 280 s. 494.00170(4). 281

Section

Section 560.1215, Florida Statutes, is created 282 to read: 283 560.1215 Cybersecurity.— 284

(1) As used in this section, the term: 285 (a) “Customer” means a person who seeks to obtain, obtains, 286 or has obtained a financial product or service from a licensee 287 covered under this chapter. 288 (b) “Customer information” means any record containing 289 nonpublic personal information about a customer of a financial 290

Florida Senate - 2025 SB 1216 18-01808-25 20251216__ Page 11 of 19 CODING: Words stricken are deletions; words underlined are additions. transaction, whether in paper, electronic, or other form, which 291 is handled or maintained by or on behalf of the licensee or its 292 affiliates. 293 (c) “Cybersecurity event” means an event resulting in 294 unauthorized access to, or disruption or misuse of, an 295 information system, information stored on such information 296 system, or customer information held in physical form. 297 (d) “Financial product or service” means any product or 298 service offered by a licensee under this chapter. 299 (e) “Information security program” means the 300 administrative, technical, or physical safeguards used to 301 access, collect, distribute, process, protect, store, use, 302 transmit, dispose of, or otherwise handle customer information. 303 (f) “Information system” means a discrete set of electronic 304 information resources organized for the collection, processing, 305 maintenance, use, sharing, dissemination, or disposition of 306 electronic information, as well as any specialized system, such 307 as an industrial or process control system, telephone switching 308 and private branch exchange system, or environmental control 309 system, which contains customer information or which is 310 connected to a system that contains customer information. 311 (g)1. “Nonpublic personal information” includes all of the 312 following: 313 a.

Personally identifiable financial information. 314 b. Any list, description, or grouping of customers derived 315 from personally identifiable financial information that is not 316 publicly available. The term includes lists of customers’ names 317 and street addresses which are derived, in whole or in part, 318 from personally identifiable information, such as account 319

Florida Senate - 2025 SB 1216 18-01808-25 20251216__ Page 12 of 19 CODING: Words stricken are deletions; words underlined are additions. numbers. 320 2. The term does not include any of the following: 321 a. Publicly available information, unless it is part of a 322 list described in sub-subparagraph 1.b. 323 b. Any list, description, or grouping of customers, along 324 with their publicly available information, if the list was 325 created without using any personally identifiable financial 326 information that is not publicly available.

A list of customers’ 327 names and addresses is not considered nonpublic personal 328 information if it contains only publicly available information, 329 is not derived in whole or in part from nonpublic personally 330 identifiable financial information, and is not disclosed in a 331 way that indicates any of the customers on the list are 332 customers of the licensee. 333 (h)1. “Personally identifiable financial information” means 334 any information that: 335 a.

A customer provides to a licensee to obtain a financial 336 product or service, such as information submitted on an 337 application for a loan or other financial product or service; 338 b. A licensee receives about a customer during or as a 339 result of any transaction involving a financial product or 340 service, including information collected through an internet 341 cookie or from a web server; or 342 c.

A licensee otherwise obtains about a customer in 343 connection with providing a financial product or service, such 344 as records indicating that a customer has previously engaged 345 with the licensee or obtained a financial product or service. 346 2. Personally identifiable financial information does not 347 include any of the following: 348

Florida Senate - 2025 SB 1216 18-01808-25 20251216__ Page 13 of 19 CODING: Words stricken are deletions; words underlined are additions. a. A list of names and addresses of customers of an entity 349 that is not a money service business. 350 b.

Information that does not identify a customer, such as 351 aggregate information or anonymized data that does not contain 352 personal identifiers such as account numbers, names, or 353 addresses. 354 (i)1. “Publicly available information” means any 355 information that a licensee has a reasonable basis to believe is 356 lawfully made available to the general public from any of the 357 following: 358 a. Federal, state, or local government records, such as 359 real estate records or security interest filings. 360 b.

Widely distributed media, including telephone 361 directories, television or radio programs, newspapers, or 362 websites, that are available to the general public on an 363 unrestricted basis. A website is not restricted merely because 364 an Internet service provider or a site operator requires a fee 365 or a password, so long as access is available to the general 366 public. 367 c. Disclosures to the general public that are required to 368 be made by federal, state, or local law. 369 2.

For the purpose of this paragraph, the term “reasonable 370 basis to believe is lawfully made available to the general 371 public” means that the licensee has taken steps to determine all 372 of the following: 373 a. That the information is of the type that is available to 374 the general public, such as information included on the public 375 record in the jurisdiction where the mortgage would be recorded. 376 b. Whether an individual can direct that the information 377

Florida Senate - 2025 SB 1216 18-01808-25 20251216__ Page 14 of 19 CODING: Words stricken are deletions; words underlined are additions. not be made available to the general public and, if so, the 378 customer to whom the information relates has not done so. 379 (j) “Third-party service provider” means a person, other 380 than a licensee, that contracts with a licensee to maintain, 381 process or store nonpublic personal information or that is 382 otherwise permitted access to nonpublic personal information 383 through its provision of services to a licensee. 384 (2)(

a) Each licensee shall develop, implement, and maintain 385 a comprehensive written information security program that 386 contains administrative, technical, and physical safeguards for 387 the protection of the licensee’s information system and 388 nonpublic personal information. 389 (

b) A licensee must ensure the information security program 390 meets all of the following criteria: 391 1. Is commensurate with the following measures: 392 a. The size and complexity of the licensee. 393 b. The nature and scope of the licensee’s activities, 394 including its use of third-party service providers. 395 c. The sensitivity of the nonpublic personal information 396 used by the licensee or in the possession, custody, or control 397 of the licensee. 398 2. Is designed to: 399 a.

Protect the security and confidentiality of nonpublic 400 personal information and the security of the licensee’s 401 information system; 402 b. Protect against threats or hazards to the security or 403 integrity of nonpublic personal information and the licensee’s 404 information system; and 405 c. Protect against unauthorized access to or use of 406

Florida Senate - 2025 SB 1216 18-01808-25 20251216__ Page 15 of 19 CODING: Words stricken are deletions; words underlined are additions. nonpublic personal information and minimize the likelihood of 407 harm to any customer. 408 3. Defines and periodically reevaluates the retention 409

schedule and the mechanism for the destruction of nonpublic 410 personal information if retention is no longer necessary for the 411 licensee’s business operations or required by applicable law. 412 4. Regularly tests and monitors systems and procedures for 413 the detection of actual and attempted attacks on, or intrusions 414 into, the information system. 415 5. Monitors, evaluates, and adjusts, as necessary, the 416 licensee’s information security program to: 417 a. Ensure the program remains consistent with relevant 418 changes in technology; 419 b.

Confirm that the program accounts for the sensitivity of 420 nonpublic personal information; 421 c. Identify and address changes that may be necessary to 422 the licensee’s information systems; 423 d. Eliminate any internal or external threats to nonpublic 424 personal information; and 425 e. Amend the licensee’s information security program for 426 any of the licensee’s changing business arrangements, including 427 but not limited to, mergers and acquisitions, alliances and 428 joint ventures, and outsourcing arrangements. 429 (

c) As part of a licensee’s information security program, a 430 licensee shall establish a written incident response plan 431 designed to promptly respond to, and recover from, a 432 cybersecurity event that compromises the confidentiality, 433 integrity, or availability of nonpublic personal information in 434 the licensee’s possession, the licensee’s information systems, 435

Florida Senate - 2025 SB 1216 18-01808-25 20251216__ Page 16 of 19 CODING: Words stricken are deletions; words underlined are additions. or the continuing functionality of any aspect of the licensee’s 436 operations. The written incident response plan must address all 437 of the following: 438 1. The licensee’s internal process for responding to a 439 cybersecurity event. 440 2. The goals of the licensee’s incident response plan. 441 3. The assignment of clear roles, responsibilities, and 442 levels of decisionmaking authority for personnel that 443 participate in the incident response plan. 444 4.

External communications, internal communications, and 445 information sharing related to a cybersecurity event. 446 5. The identification of remediation requirements for 447 weaknesses identified in information systems and associated 448 controls. 449 6. Documentation and reporting regarding cybersecurity 450 events and related incident response activities. 451 7. The evaluation and revision of the incident response 452 plan, as appropriate, following a cybersecurity event. 453 8. The process by which notice must be given as required 454 under subsection (4) and s. 501.171(3) and (4). 455 (

d) This subsection does not apply to a licensee that: 456 1. Has fewer than 20 persons on its workforce, including 457 employees and independent contractors; or 458 2. Has fewer than 500 customers during a calendar year. 459 (

e) A licensee has 180 calendar days from the date the 460 licensee no longer qualifies for exemption under paragraph 461 (2)(

d) to comply with this section. 462 (

f) A licensee shall maintain a copy of the information 463 security program for a minimum of 5 years and shall make it 464

Florida Senate - 2025 SB 1216 18-01808-25 20251216__ Page 17 of 19 CODING: Words stricken are deletions; words underlined are additions. available to the office upon request or as part of an 465 examination. 466 (3)(

a) If a licensee discovers that a cybersecurity event 467 has occurred, or that a cybersecurity event may have occurred, 468 the licensee, or the outside vendor or third-party service 469 provider the licensee has designated to act on its behalf, shall 470 conduct a prompt investigation of the event. 471 (

b) During the investigation, the licensee, or outside 472 vendor or third-party service provider the licensee has 473 designated to act on its behalf, shall, at a minimum, determine 474 all of the following to the extent possible: 475 1. Whether a cybersecurity event has occurred. 476 2. The date the cybersecurity event first occurred. 477 3. The nature and scope of the cybersecurity event. 478 4. Any nonpublic personal information that may have been 479 compromised. 480 5.

Reasonable measures to restore the security of 481 compromised information systems and prevent further unauthorized 482 access, disclosure, or use of nonpublic personal information in 483 the possession, custody, or control of the licensee, outside 484 vendor, or third-party service provider. 485 (

c) If a licensee learns that a cybersecurity event has 486 occurred, or may have occurred, in an information system 487 maintained by a third-party service provider of the licensee, 488 the licensee must complete an investigation in compliance with 489 this

section or confirm and document that the third-party 490 service provider has completed an investigation in compliance 491 with this section. 492 (

d) A licensee shall maintain all records and documentation 493

Florida Senate - 2025 SB 1216 18-01808-25 20251216__ Page 18 of 19 CODING: Words stricken are deletions; words underlined are additions. related to the licensee’s investigation of a cybersecurity event 494 for a minimum of 5 years from the date of the event and shall 495 produce the records and documentation upon the office’s request. 496 (4)(

a) A licensee shall provide notice to the office of any 497 breach of security affecting 500 or more persons in this state 498 at a time and in the manner prescribed by commission rule. 499 (

b) A licensee, shall, upon request by the office, provide 500 a quarterly update of the investigation undertaken pursuant to 501 paragraph (3), until conclusion of the investigation. 502

(5) This

section may not be construed to relieve a covered 503 entity from complying with the provisions of s. 501.171. To the 504 extent a licensee is a covered entity, as that term is defined 505 in s. 501.171(1)(b), such covered entity remains subject to the 506 provisions of s. 501.171. 507

(6) The commission may adopt rules to administer this 508

section including rules that allow a licensee that is in full 509 compliance with 16 C.F.R.

part 314, Standards for Safeguarding 510 Customer Information, by the Federal Trade Commission, to be 511 deemed in compliance with subparagraph (2). 512

Section 4. Paragraph (dd) is added to subsection (1) of 513

section 560.114, Florida Statutes, to read: 514 560.114 Disciplinary actions; penalties.— 515

(1) The following actions by a money services business, 516 authorized vendor, or affiliated party constitute grounds for 517 the issuance of a cease and desist order; the issuance of a 518 removal order; the denial, suspension, or revocation of a 519 license; or taking any other action within the authority of the 520 office pursuant to this chapter: 521 (dd) Failure to comply with the notification requirements 522

Florida Senate - 2025 SB 1216 18-01808-25 20251216__ Page 19 of 19 CODING: Words stricken are deletions; words underlined are additions. in s. 560.1215(4). 523

Section 5. This act shall take effect July 1, 2025. 524

Document details

CollectionFlorida Bills
CitationSB 1216
Typebill
Languageen
Formatpdf
SourceFL_SENATE
Identifiera4fe8ea1a0ae7caf6fd7a945042cc6ce66b108c1

Source file is stored in the law ingest library (pdf).

Senate Bill 1216 (2025) — Cybersecurity of mortgage brokers and lenders and money services businesses

SB 1216

Florida Bills

Loading PDF viewer…