Money Services Act (Ark. Code § 23-55-101 et seq.), compiled, effective August 5, 2025 (Part 2 of 2)

Bitcoin Research — Law, Regulation, Markets & Origins (2026)

States

Ar

2

2025-08-05

Document text

Research, not advice. Part of the Bitcoin research archive (October 2026). Claims labelled unverified, contested or fringe are reported, not endorsed; statuses of bills and rules are as of the date checked. Government, court and patent records are public domain; the research notes are CC BY 4.0.

governing body.
      (2)    If a board of directors or equivalent governing body does not exist, the
             report required under subdivision (j)(1) shall be timely presented to a
             senior officer responsible for the financial institution's information
             security program.
      (3)    The report required under subdivision (j)(1) shall include:
             (A)     the overall status of the information security program and the
                     financial institution's compliance with this section and associated
                     rules; and
             (B)     material matters related to the information security program,
                     addressing issues such as risk assessment, risk management and
                     control decisions, service provider arrangements, results of testing,
                     security events or violations and management's responses to
                     security events or violations, and recommendations for changes in
                     the information security program.
(k)   A financial institution shall provide notice to the Securities Commissioner about
      notification events according to subdivisions (l)(1) and (2).
(l)   (1)    Upon discovery of a notification event as described in subdivision (l)(3), if
             the notification event involves the information of any consumers in this
             state, the financial institution shall notify the commissioner as soon as
             possible, and no later than 45 days after discovery of the notification
             event.
      (2)    The notice required under subdivision (l)(1) shall:
             (A)     be made in a format specified by the commissioner; and
             (B)     include the following information:
                     (i)    the name and contact information of the reporting financial
                            institution;

                                       75
            (ii)    (a)    a description of the types of information that were
                           involved in the notification event.
                    (b)    if the information is possible to determine under
                           subdivision (l)(2)(B)(ii)(a), the notice required
                           under subdivision (l)(1) shall contain the date or
                           date range of the notification event;
            (iii)   the number of consumers affected or potentially affected by
                    the notification event;
            (iv)    a general description of the notification event; and
            (v)     (a)    whether a law enforcement official has provided the
                           financial institution with a written determination
                           that notifying the public of the notification event
                           would impede a criminal investigation or cause
                           damage to national security, and a means for the
                           commissioner to contact the law enforcement
                           official.
                    (b)    A law enforcement official under subdivision
                           (l)(2)(B)(v)(a) may request an initial delay of up to
                           30 days following the date when notice was
                           provided to the commissioner.
                    (c)    The delay under subdivision (l)(2)(B)(v)(b) may be
                           extended for an additional period of up to 60 days if
                           the law enforcement official seeks an extension in
                           writing.
                    (d)    An additional delay beyond the delay under
                           subdivision (l)(2)(B)(v)(b) may be permitted only if
                           the State Securities Department determines that
                           public disclosure of a notification event continues to
                           impede a criminal investigation or cause damage to
                           national security.
(3)   (A)   A notification event under this section shall be treated as
            discovered as of the first day on which the notification event is
            known to the financial institution.
      (B)   The financial institution under subdivision (l)(3)(A) shall be
            deemed to have knowledge of a notification event if the
            notification event is known to a person, other than the person
            committing the notification event, who is the financial institution's
            employee, officer, or other agent.

                              76
       (m)     A financial institution shall establish a written plan addressing business continuity
               and disaster recovery.
History. Acts 2025, No. 557, § 11.

23-55-1104. Exceptions.
This article does not apply to a financial institution that maintains customer information
concerning fewer than 5,000 consumers.
History. Acts 2025, No. 557, § 11.

                                                77