AMENDED IN ASSEMBLY JUNE 22, 2026
AMENDED IN ASSEMBLY MAY 26, 2026
AMENDED IN SENATE JANUARY 5, 2026
AMENDED IN SENATE MARCH 24, 2025
CALIFORNIA LEGISLATURE— 2025–2026 REGULAR SESSION
95
Introduced by Senator Richardson
February 19, 2025
An act to add Chapter 10 (commencing with Section 2180) to Division 1.2 of the Financial Code, relating to financial protection.
Vote: majority Appropriation: no Fiscal committee: yes Local program: yes
LEGISLATIVE COUNSEL’S DIGEST
The Money Transmission Act (MTA) prohibits a person from engaging in the business of money transmission in the state, or from advertising, soliciting, or holding itself out as providing money transmission in the state, unless the person is licensed by the Department of Financial Protection and Innovation under the act. The MTA defines “money transmission” to mean, among other things, selling or issuing stored value to a person located in the state and defines “stored value” to mean monetary value representing a claim against the issuer that is stored on an electronic or digital medium and evidenced by an electronic or digital record and that is intended and accepted for use as a means of redemption for money or monetary value or payment for goods or services. The MTA punishes noncompliance with, among other things, a civil penalty, license revocation, and, for certain violations, as a felony, as prescribed.
This bill would prohibit a licensee under the MTA from allowing a user login without using unless the licensee has implemented specified processes, including 2-factor authentication, multifactor authentication, or other reasonably equivalent or more secure access control, as specified. The bill would prohibit a licensee from allowing a user login without implementing an automatic logout requirement, a session timeout requirement, and a reauthentication requirement, as
specified. The bill would provide that its provisions become operative January 1, 2028. By expanding the scope of a crime, this bill would impose a state-mandated local program.
The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement.
This bill would provide that no reimbursement is required by this act for a specified reason.
The people of the State of California do enact as follows:
SECTION 1.
It is the intent of the Legislature that implementation of this act is consistent with evolving security standards while maintaining strong consumer protections.
SEC. 2.
Chapter 10 (commencing with Section 2180) is added to Division 1.2 of the Financial Code, to read:
Chapter 10. Authentication
For purposes of this chapter:
(a) “Multifactor authentication” means an authentication process that requires two or more forms of verification.
(b) “Two-factor authentication” means a security process that requires two distinct forms of verification.
(c) “User login” means an action by which a user accesses an account or platform for the purpose of initiating, receiving, or managing money transmission services. services for
the first time or after a logout.
(a) A licensee shall not allow a user login without using two-factor implementing all of the following:
(1) Two-factor authentication, multifactor authentication, or other reasonably equivalent or more secure access control.
(2) A process for reverifying the identity of the user, device, or system using two-factor authentication, multifactor authentication, or other reasonably equivalent or more secure access control.
(3) The ability for a user to report an error or suspected fraud using the same platform through which the user accessed the money transmission service or through a reasonably accessible alternative.
(b) A secure access control method described in paragraph (1) of subdivision (a) shall be approved in writing by an individual employed or contracted by the licensee who is responsible for overseeing, implementing, and enforcing the licensee’s information security program.
(c) In implementing paragraph (2) of subdivision (a), both of the following apply:
(1) The licensee shall use a risk-based approach that balances consumer protection with reasonable user access.
(2) The licensee may consider any relevant factor, including, but not limited to, any of the following, provided that the consideration does not compromise security or protections against unauthorized access:
(A) The level of risk presented by the activity.
(B) Indicators of anomalous behavior.
(C) The sensitivity of the transaction.
(a) A licensee shall not allow a user login without implementing all of the following:
(1) An automatic logout requirement.
(2) A session timeout requirement.
(3) A reauthentication requirement.
(b) In implementing the requirements described in subdivision (a), the licensee shall use a risk-based approach that balances consumer protection with reasonable user access.
(c) In implementing the requirements described in subdivision (a), the licensee may consider any of the following factors, provided that the consideration does not compromise security or protections against unauthorized access:
(1) The level of risk presented by the activity.
(2) Indicators of anomalous behavior.
(3) The sensitivity of the transaction.
2183.2182.
This chapter shall become operative January 1, 2028.
SEC. 3.
No reimbursement is required by this act pursuant to Section 6 of Article XIIIB of the California Constitution because the only costs that may be incurred by a local agency or school district will be incurred because this act creates a new crime or infraction, eliminates a crime or infraction, or changes the penalty for a crime or infraction, within the meaning of Section 17556 of the Government Code, or changes the definition of a crime within the meaning of Section 6 of Article XIIIB of the California Constitution.