Definitions

Miss. Code Ann. § 75-14-3, under Data Security for Money Transmitters Act.

Miss. Code Ann. § 75-14-3

(a) The definitions provided in Section 75-16-5 shall also apply to the terms used in this article, and the following terms as used in this article have the meanings as defined in this section, unless the context clearly indicates otherwise:(a) “Authorized user” means an employee, contractor, agent or other person that participates in a licensee’s business operations and is authorized to access and use a licensee’s information systems and data.(b) “Consumer” means an individual who obtains or has obtained a financial product or service from a licensee that is to be used primarily for personal, family or household purposes, or that individual’s legal representative.(c) “Customer” means a consumer who has a customer relationship with a licensee.(d) “Customer information” means a record containing nonpublic personal information about a customer of a licensee, whether in paper, electronic or other form, that is handled or maintained by or on behalf of a licensee or the licensee’s affiliates.(e) “Customer relationship” means a continuing relationship between a consumer and a licensee under which the licensee provides to the consumer one or more financial products or services that are used primarily for personal, family or household purposes.(f) “Encryption” means the transformation of data into a form that results in a low probability of assigning meaning without the use of a protective process or key, consistent with current cryptographic standards and accompanied by appropriate safeguards for cryptographic key material.(g) “Financial product or service” means a product or service that a financial holding company could offer by engaging in a financial activity under Section 4(k) of the Bank Holding Company Act of 1956, 12 USC Section 1843(k), as it existed on January 1, 2025. The term “financial product or service” includes a licensee’s evaluation or brokerage of information that a licensee collects in connection with a request or an application from a consumer for a financial product or service.(h) “Information security program” means the administrative, technical or physical safeguards a licensee uses to access, collect, distribute, process, protect, store, use, transmit, dispose of or otherwise handle customer information.(i) “Information system” means a discrete set of electronic information resources organized for the collection, processing, maintenance, use, sharing, dissemination or disposition of electronic information, including any specialized system such as industrial controls systems or process controls systems, telephone switching and private branch exchange systems, and environmental controls systems, that contains customer information or that is connected to a system that contains customer information.(j) “Licensee” means a money transmitter or virtual currency kiosk licensed under the Money Transmission Modernization Act, Section 75-16-1 et seq.(k) “Multi-factor authentication” means authentication through verification of at least two (2) of the following types of authentication factors:(i) Knowledge factors, including, but not limited to, a password;(ii) Possession factors, including, but not limited to, a token; or(iii) Inherence factors, including, but not limited to, biometric characteristics.(l) (i) “Nonpublic personal information” means:1. Personally identifiable financial information; and2. A list, description or other grouping of consumers, and publicly available information pertaining to a consumer, that is derived using personally identifiable financial information that is not publicly available.(ii) The term “nonpublic personal information” includes, but is not limited to, a list of individuals’ names and street addresses that is derived, in whole or in part, using personally identifiable financial information that is not publicly available. The term “nonpublic personal information” does not include:1. Publicly available information except as included on a list described in subparagraph (i)2 of this paragraph (l);2. A list, description or other grouping of consumers, and publicly available information pertaining to the list, description or other grouping of consumers, that is derived without using personally identifiable financial information that is not publicly available; or3. A list of individuals’ names and addresses that contains only publicly available information and is not:a. Derived, in whole or in part, using personally identifiable financial information that is not publicly available; andb. Disclosed in a manner that indicates that any of the individuals on the list is a consumer of a licensee.(m) “Notification event” means acquisition of unencrypted customer information without the authorization of the affected individual. For purposes of this paragraph (m):(i) Customer information is considered unencrypted if the encryption key was accessed by an unauthorized person; and(ii) Unauthorized acquisition will be presumed to include unauthorized access to unencrypted customer information unless a licensee has reliable evidence showing that there has not been, or could not reasonably have been, unauthorized acquisition of the customer information.(n) “Penetration testing” means a test methodology in which assessors attempt to circumvent or defeat the security features of an information system by attempting penetration of databases or controls from outside or inside a licensee’s information systems.(o) (i) “Personally identifiable financial information” means information:1. A consumer provides to a licensee to obtain a financial product or service from a licensee;2. About a consumer resulting from a transaction involving a financial product or service between a licensee and a consumer; or3. A licensee otherwise obtains about a consumer in connection with providing a financial product or service to that consumer.(ii) The term “personally identifiable financial information” includes:1. Information a consumer provides to a licensee on an application to obtain a loan, credit card or other financial product or service;2. Account balance information, payment history, overdraft history and credit or debit card purchase information;3. The fact that an individual is or has been a licensee’s customer or has obtained a financial product or service from a licensee;4. Information about a licensee’s consumer if the information is disclosed in a manner that indicates that the individual is or has been the licensee’s consumer;5. Information that a consumer provides to a licensee or that a licensee or a licensee’s agent otherwise obtains in connection with collecting on, or servicing, a credit account;6. Information a licensee collects through an Internet cookie or the information collecting device from a computer server; and7. Information from a consumer report.(iii) The term “personally identifiable financial information” does not include:1. A list of names and addresses of customers of an entity that is not a licensee; and2. Information that does not identify a consumer, including aggregate information or blind data that does not contain personal identifiers such as account numbers, names or addresses.(p) “Publicly available information” means information that a licensee has a reasonable basis to believe is lawfully made available to the public from federal, state or local government records; widely distributed media; or disclosures to the public that are required to be made by federal, state or local law.The term “publicly available information” includes, but is not limited to:(i) Information in government records, including information in government real estate records and security interest filings; and(ii) Information from widely distributed media, including information from a telephone book, a television or radio program, a newspaper or a website that is available to the public on an unrestricted basis. A website is not considered to be restricted under this subparagraph (ii) merely because an Internet service provider or a site operator requires a fee or a password, so long as access is available to the public.For purposes of this paragraph (p), a licensee has a reasonable basis to believe that information is lawfully made available to the public if the licensee has taken steps to determine that the information is of the type that is available to the public, whether an individual can direct that the information not be made available to the public and, if so, that the licensee’s consumer has not directed that the information not be made available to the public.For purposes of this paragraph (p), mortgage information is lawfully made available to the public if the licensee determines that the information is of the type included on the public record in the jurisdiction where the mortgage would be recorded.For purposes of this paragraph (p), an individual’s telephone number is lawfully made available to the public if the licensee has located the telephone number in a telephone directory or the consumer has informed the licensee that the telephone number is not unlisted.(q) “Qualified individual” means an individual designated by a licensee to oversee, implement and enforce the licensee’s information security program.(r) “Security event” means an event resulting in unauthorized access to, or disruption or misuse of:(i) An information system or information stored on the information system; or(ii) Customer information held in physical form.(s) “Service provider” means a person or entity that receives, maintains, processes or otherwise is permitted access to customer information through its provision of services directly to a licensee that is subject to this article.

(a) “Authorized user” means an employee, contractor, agent or other person that participates in a licensee’s business operations and is authorized to access and use a licensee’s information systems and data.

(b) “Consumer” means an individual who obtains or has obtained a financial product or service from a licensee that is to be used primarily for personal, family or household purposes, or that individual’s legal representative.

(c) “Customer” means a consumer who has a customer relationship with a licensee.

(d) “Customer information” means a record containing nonpublic personal information about a customer of a licensee, whether in paper, electronic or other form, that is handled or maintained by or on behalf of a licensee or the licensee’s affiliates.

(e) “Customer relationship” means a continuing relationship between a consumer and a licensee under which the licensee provides to the consumer one or more financial products or services that are used primarily for personal, family or household purposes.

(f) “Encryption” means the transformation of data into a form that results in a low probability of assigning meaning without the use of a protective process or key, consistent with current cryptographic standards and accompanied by appropriate safeguards for cryptographic key material.

(g) “Financial product or service” means a product or service that a financial holding company could offer by engaging in a financial activity under Section 4(k) of the Bank Holding Company Act of 1956, 12 USC Section 1843(k), as it existed on January 1, 2025. The term “financial product or service” includes a licensee’s evaluation or brokerage of information that a licensee collects in connection with a request or an application from a consumer for a financial product or service.

(h) “Information security program” means the administrative, technical or physical safeguards a licensee uses to access, collect, distribute, process, protect, store, use, transmit, dispose of or otherwise handle customer information.

(i) “Information system” means a discrete set of electronic information resources organized for the collection, processing, maintenance, use, sharing, dissemination or disposition of electronic information, including any specialized system such as industrial controls systems or process controls systems, telephone switching and private branch exchange systems, and environmental controls systems, that contains customer information or that is connected to a system that contains customer information.

(j) “Licensee” means a money transmitter or virtual currency kiosk licensed under the Money Transmission Modernization Act, Section 75-16-1 et seq.

(k) “Multi-factor authentication” means authentication through verification of at least two (2) of the following types of authentication factors:(i) Knowledge factors, including, but not limited to, a password;(ii) Possession factors, including, but not limited to, a token; or(iii) Inherence factors, including, but not limited to, biometric characteristics.

(i) Knowledge factors, including, but not limited to, a password;

(ii) Possession factors, including, but not limited to, a token; or

(iii) Inherence factors, including, but not limited to, biometric characteristics.

(l) (i) “Nonpublic personal information” means:1. Personally identifiable financial information; and2. A list, description or other grouping of consumers, and publicly available information pertaining to a consumer, that is derived using personally identifiable financial information that is not publicly available.(ii) The term “nonpublic personal information” includes, but is not limited to, a list of individuals’ names and street addresses that is derived, in whole or in part, using personally identifiable financial information that is not publicly available. The term “nonpublic personal information” does not include:1. Publicly available information except as included on a list described in subparagraph (i)2 of this paragraph (l);2. A list, description or other grouping of consumers, and publicly available information pertaining to the list, description or other grouping of consumers, that is derived without using personally identifiable financial information that is not publicly available; or3. A list of individuals’ names and addresses that contains only publicly available information and is not:a. Derived, in whole or in part, using personally identifiable financial information that is not publicly available; andb. Disclosed in a manner that indicates that any of the individuals on the list is a consumer of a licensee.

(i) “Nonpublic personal information” means:1. Personally identifiable financial information; and2. A list, description or other grouping of consumers, and publicly available information pertaining to a consumer, that is derived using personally identifiable financial information that is not publicly available.

1. Personally identifiable financial information; and

2. A list, description or other grouping of consumers, and publicly available information pertaining to a consumer, that is derived using personally identifiable financial information that is not publicly available.

(ii) The term “nonpublic personal information” includes, but is not limited to, a list of individuals’ names and street addresses that is derived, in whole or in part, using personally identifiable financial information that is not publicly available. The term “nonpublic personal information” does not include:1. Publicly available information except as included on a list described in subparagraph (i)2 of this paragraph (l);2. A list, description or other grouping of consumers, and publicly available information pertaining to the list, description or other grouping of consumers, that is derived without using personally identifiable financial information that is not publicly available; or3. A list of individuals’ names and addresses that contains only publicly available information and is not:a. Derived, in whole or in part, using personally identifiable financial information that is not publicly available; andb. Disclosed in a manner that indicates that any of the individuals on the list is a consumer of a licensee.

1. Publicly available information except as included on a list described in subparagraph (i)2 of this paragraph (l);

2. A list, description or other grouping of consumers, and publicly available information pertaining to the list, description or other grouping of consumers, that is derived without using personally identifiable financial information that is not publicly available; or

3. A list of individuals’ names and addresses that contains only publicly available information and is not:a. Derived, in whole or in part, using personally identifiable financial information that is not publicly available; andb. Disclosed in a manner that indicates that any of the individuals on the list is a consumer of a licensee.

a. Derived, in whole or in part, using personally identifiable financial information that is not publicly available; and

b. Disclosed in a manner that indicates that any of the individuals on the list is a consumer of a licensee.

(m) “Notification event” means acquisition of unencrypted customer information without the authorization of the affected individual. For purposes of this paragraph (m):(i) Customer information is considered unencrypted if the encryption key was accessed by an unauthorized person; and(ii) Unauthorized acquisition will be presumed to include unauthorized access to unencrypted customer information unless a licensee has reliable evidence showing that there has not been, or could not reasonably have been, unauthorized acquisition of the customer information.

(i) Customer information is considered unencrypted if the encryption key was accessed by an unauthorized person; and

(ii) Unauthorized acquisition will be presumed to include unauthorized access to unencrypted customer information unless a licensee has reliable evidence showing that there has not been, or could not reasonably have been, unauthorized acquisition of the customer information.

(n) “Penetration testing” means a test methodology in which assessors attempt to circumvent or defeat the security features of an information system by attempting penetration of databases or controls from outside or inside a licensee’s information systems.

(o) (i) “Personally identifiable financial information” means information:1. A consumer provides to a licensee to obtain a financial product or service from a licensee;2. About a consumer resulting from a transaction involving a financial product or service between a licensee and a consumer; or3. A licensee otherwise obtains about a consumer in connection with providing a financial product or service to that consumer.(ii) The term “personally identifiable financial information” includes:1. Information a consumer provides to a licensee on an application to obtain a loan, credit card or other financial product or service;2. Account balance information, payment history, overdraft history and credit or debit card purchase information;3. The fact that an individual is or has been a licensee’s customer or has obtained a financial product or service from a licensee;4. Information about a licensee’s consumer if the information is disclosed in a manner that indicates that the individual is or has been the licensee’s consumer;5. Information that a consumer provides to a licensee or that a licensee or a licensee’s agent otherwise obtains in connection with collecting on, or servicing, a credit account;6. Information a licensee collects through an Internet cookie or the information collecting device from a computer server; and7. Information from a consumer report.(iii) The term “personally identifiable financial information” does not include:1. A list of names and addresses of customers of an entity that is not a licensee; and2. Information that does not identify a consumer, including aggregate information or blind data that does not contain personal identifiers such as account numbers, names or addresses.

(i) “Personally identifiable financial information” means information:1. A consumer provides to a licensee to obtain a financial product or service from a licensee;2. About a consumer resulting from a transaction involving a financial product or service between a licensee and a consumer; or3. A licensee otherwise obtains about a consumer in connection with providing a financial product or service to that consumer.

1. A consumer provides to a licensee to obtain a financial product or service from a licensee;

2. About a consumer resulting from a transaction involving a financial product or service between a licensee and a consumer; or

3. A licensee otherwise obtains about a consumer in connection with providing a financial product or service to that consumer.

(ii) The term “personally identifiable financial information” includes:1. Information a consumer provides to a licensee on an application to obtain a loan, credit card or other financial product or service;2. Account balance information, payment history, overdraft history and credit or debit card purchase information;3. The fact that an individual is or has been a licensee’s customer or has obtained a financial product or service from a licensee;4. Information about a licensee’s consumer if the information is disclosed in a manner that indicates that the individual is or has been the licensee’s consumer;5. Information that a consumer provides to a licensee or that a licensee or a licensee’s agent otherwise obtains in connection with collecting on, or servicing, a credit account;6. Information a licensee collects through an Internet cookie or the information collecting device from a computer server; and7. Information from a consumer report.

1. Information a consumer provides to a licensee on an application to obtain a loan, credit card or other financial product or service;

2. Account balance information, payment history, overdraft history and credit or debit card purchase information;

3. The fact that an individual is or has been a licensee’s customer or has obtained a financial product or service from a licensee;

4. Information about a licensee’s consumer if the information is disclosed in a manner that indicates that the individual is or has been the licensee’s consumer;

5. Information that a consumer provides to a licensee or that a licensee or a licensee’s agent otherwise obtains in connection with collecting on, or servicing, a credit account;

6. Information a licensee collects through an Internet cookie or the information collecting device from a computer server; and

7. Information from a consumer report.

(iii) The term “personally identifiable financial information” does not include:1. A list of names and addresses of customers of an entity that is not a licensee; and2. Information that does not identify a consumer, including aggregate information or blind data that does not contain personal identifiers such as account numbers, names or addresses.

1. A list of names and addresses of customers of an entity that is not a licensee; and

2. Information that does not identify a consumer, including aggregate information or blind data that does not contain personal identifiers such as account numbers, names or addresses.

(p) “Publicly available information” means information that a licensee has a reasonable basis to believe is lawfully made available to the public from federal, state or local government records; widely distributed media; or disclosures to the public that are required to be made by federal, state or local law.

(i) The term “publicly available information” includes, but is not limited to:(i) Information in government records, including information in government real estate records and security interest filings; and(ii) Information from widely distributed media, including information from a telephone book, a television or radio program, a newspaper or a website that is available to the public on an unrestricted basis. A website is not considered to be restricted under this subparagraph (ii) merely because an Internet service provider or a site operator requires a fee or a password, so long as access is available to the public.

(i) Information in government records, including information in government real estate records and security interest filings; and

(ii) Information from widely distributed media, including information from a telephone book, a television or radio program, a newspaper or a website that is available to the public on an unrestricted basis. A website is not considered to be restricted under this subparagraph (ii) merely because an Internet service provider or a site operator requires a fee or a password, so long as access is available to the public.

For purposes of this paragraph (p), a licensee has a reasonable basis to believe that information is lawfully made available to the public if the licensee has taken steps to determine that the information is of the type that is available to the public, whether an individual can direct that the information not be made available to the public and, if so, that the licensee’s consumer has not directed that the information not be made available to the public.

For purposes of this paragraph (p), mortgage information is lawfully made available to the public if the licensee determines that the information is of the type included on the public record in the jurisdiction where the mortgage would be recorded.

For purposes of this paragraph (p), an individual’s telephone number is lawfully made available to the public if the licensee has located the telephone number in a telephone directory or the consumer has informed the licensee that the telephone number is not unlisted.

(q) “Qualified individual” means an individual designated by a licensee to oversee, implement and enforce the licensee’s information security program.

(r) “Security event” means an event resulting in unauthorized access to, or disruption or misuse of:(i) An information system or information stored on the information system; or(ii) Customer information held in physical form.

(i) An information system or information stored on the information system; or

(ii) Customer information held in physical form.

(s) “Service provider” means a person or entity that receives, maintains, processes or otherwise is permitted access to customer information through its provision of services directly to a licensee that is subject to this article.