Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Industry, Business And Labor topic
No spam. Unsubscribe anytime.
Department of Financial Institutions seeks statutory updates, adds data-security authority for nonbanks in House Bill 1127
Summary
Commissioner Lisa Cruz, head of the North Dakota Department of Financial Institutions, testified in support of House Bill 1127, telling the Industry, Business and Labor Committee the measure modernizes multiple sections of state banking law and creates a new chapter to address data security for nondepository financial institutions.
Get email alerts on the Industry, Business And Labor topic
No spam. Unsubscribe anytime.
Commissioner Lisa Cruz, head of the North Dakota Department of Financial Institutions, testified in support of House Bill 1127, telling the Industry, Business and Labor Committee the measure modernizes multiple sections of state banking law and creates a new chapter to address data security for nondepository financial institutions.
The bill combines statutory updates across chapters 6 and 13 and creates chapter 1301.2 to incorporate a model data-security standard applicable to nonbanks, Cruz said. "Safeguarding customers' data is of utmost importance," she said, arguing the change would give the state the same enforcement authority the Federal Trade Commission uses under its safeguards rule for nonbank entities.
The bill would also clarify the department’s authority to issue prohibition and removal orders for officers, directors and employees of financial institutions. Cruz said the department seeks to close a procedural gap that has allowed individuals to avoid an effective prohibition after pleading to lesser charges. The proposal would remove a statutory reinstatement route after a final removal order and make clear the board or commissioner can issue a prohibition order when an individual is convicted of "any charge," including those that may have been pled down.
Why it matters: Cruz told lawmakers that banks and credit unions already face federal safeguards requirements, but nonbank licensees (money transmitters, payday lenders, some mortgage lenders and other nondepository lenders) lack clear state enforcement authority. "We may identify failures in compliance during our exams. And by adopting this model law, we are provided then with enforcement authority and the ability to address specific needs, such as data breach notifications," she said.
Committee members pressed Cruz on several points. Representative Johnson called the bill "a big bill" and asked about compliance costs for the cybersecurity model; Cruz said cybersecurity is already the industry’s largest compliance concern and that banks already meet federal requirements, but nonbank breaches have left gaps: "We don't stand there where we can do something to help our citizens," she said.
Representative Christie and others asked why the federal rule must be reproduced in state statute; Cruz replied it is a matter of enforcement jurisdiction and timeliness: "We do not have the same authority as the federal government. So if anything is affecting our North Dakota citizens, I would have to rely on the Federal Trade Commission to actually do something for our citizens. Having it in state law just helps us have that same authority here." She also said the department already conducts IT exams of banks and service providers but is constrained by staffing and would like additional dedicated IT expertise.
On removal and prohibition authority, representatives repeatedly raised concerns about the breadth of language that would permit removal for conduct described as violating "any law, regulation, board order, or written agreement" and for "unsafe or unsound practice" or breaches of fiduciary duty. Representative Schauer and Representative Casper asked whether the bill's language sets a sufficiently high bar to justify removing a person’s ability to return to banking. Cruz said the department applies the authority only in serious cases—embezzlement, fraud and theft—and that final removal has historically followed criminal or enforcement actions and law-enforcement involvement.
The bill also contains a set of technical and consistency fixes across licensing statutes cited by Cruz: adding a definition of "loan" for money brokers (nonbank lenders), aligning procedures for orders and appeals in the money-transmitter model law (including a 20-day appeal window consistent with chapter 2832), clarifying license-renewal denial authority, and adjustments for mortgage originator and servicer provisions (including a stated exemption for interim servicers).
Industry representatives spoke in support. Rick Kleberg, president and CEO of the North Dakota Bankers Association, told the committee the bankers' legislative committee reviewed the provisions affecting banks and unanimously endorsed the bill. He said bankers support the department's position that serious breaches of trust and corporate theft justify permanent exclusion from banking and that judicial and administrative review remain available.
No formal committee vote on House Bill 1127 occurred during the hearing. Cruz and committee members indicated willingness to refine language on the removal provisions; Cruz said she is open to adjustments so the bill’s other technical and data-security provisions can move forward.
The committee closed the hearing on House Bill 1127 after the testimony and questions and proceeded to take up other agenda items.
