TITLE 5

Banking

Other Businesses Under Jurisdiction of State Banking Department

CHAPTER 35. Delaware Payment Stablecoins Act [For application of this chapter, see 85 Del. Laws, c. 339, § 2]

Subchapter VII. Risk Management and Governance [For application of this subchapter, see 85 Del. Laws, c. 339, § 2]

§ 3535. Risk management and governance [For application of this section, see 85 Del. Laws, c. 339, § 2].

(a) The Commissioner shall promulgate regulations establishing principles-based risk management requirements for permitted payment stablecoin issuers licensed under § 3511 of this title, which must include the following:

(1) Operational risk, including technology infrastructure and cybersecurity.

(2) Liquidity risk management.

(3) Reserve asset interest rate risk and diversification.

(4) Business continuity and disaster recovery, including provisions specific to distributed ledger systems and private key management.

(5) Insider and affiliate transactions, including prohibitions on self-dealing that disadvantages payment stablecoin holders.

(6) Outsourcing of critical functions, including use of sub-custodians and third-party technology providers.

(7) Nonpublic personal information protection and data security.

(8) Asset growth prudential management, ensuring that growth in outstanding issuance value is commensurate with the issuer’s risk management capabilities, operational capacity, and staffing.

(9) Annual wind-down planning, requiring each permitted payment stablecoin issuer to prepare and file with the Commissioner an updated plan for the orderly wind-down of its payment stablecoin operations in the event of insolvency or license surrender, consistent with § 3523(a)(3) and (a)(5) of this title.

(b) Risk management requirements promulgated under this section must be tailored to the business model and risk profile of permitted payment stablecoin issuers, and must be aligned, to the extent practicable, with corresponding federal standards established under the GENIUS Act [12 U.S.C. § 5901 et seq.] and Office of the Comptroller of the Currency implementing regulations to maintain the substantial similarity required for GENIUS Act certification.

85 Del. Laws, c. 339, § 1

§ 3536. Fitness and character requirements [For application of this section, see 85 Del. Laws, c. 339, § 2].

(a) An individual who has been convicted of, or has pleaded guilty or nolo contendere to, any crime involving fraud, dishonesty, breach of trust, money laundering, or financial crimes in any jurisdiction may not serve as a director or executive officer of a permitted payment stablecoin issuer licensed under this chapter.

(b) The Commissioner may establish by regulation additional fitness and character standards applicable to executive officers, directors, and persons with control of permitted payment stablecoin issuers, consistent with the standards established for federal qualified payment stablecoin issuers under the GENIUS Act [12 U.S.C. § 5901 et seq.].

85 Del. Laws, c. 339, § 1

§ 3537. Customer data privacy and information security [For application of this section, see 85 Del. Laws, c. 339, § 2].

(a) A permitted payment stablecoin issuer licensed under § 3511 of this title shall establish, implement, and maintain a written program to protect the nonpublic personal information of its customers from unauthorized access, use, or disclosure. The program must do all of the following:

(1) Include administrative, technical, and physical safeguards appropriate to the size, complexity, and sensitivity of the customer information maintained by the issuer.

(2) Identify and assess internal and external risks to the security, confidentiality, and integrity of customer nonpublic personal information.

(3) Design and implement safeguards to control the risks identified under paragraph (a)(2) of this section.

(4) Include measures to ensure continuity of operations and recover critical functions in the face of disruptions to systems that maintain or process nonpublic personal information.

(b) A permitted payment stablecoin issuer and affiliates of permitted payment stablecoin issuers may not sell, transfer, or disclose a customer’s nonpublic personal information to a nonaffiliated third party except in any of the following circumstances:

(1) With the prior informed consent of the customer.

(2) As necessary to provide a product or service requested by the customer, subject to appropriate safeguards and contractual protections.

(3) As required by applicable federal or state law, including a lawful order.

(c) Except as otherwise provided in § 12D-103 of Title 6, a permitted payment stablecoin issuer is subject to Chapter 12D of Title 6.

(d) A permitted payment stablecoin issuer that discovers or reasonably suspects an unauthorized acquisition of or access to nonpublic personal information of its customers must do all of the following:

(1) Promptly investigate the incident and take reasonable steps to contain and mitigate any harm to affected customers.

(2) Notify the Commissioner through the Commissioner’s designated supervisory office within 72 hours of becoming aware that a breach of nonpublic personal information has occurred or is reasonably likely to have occurred.

(3) Notify affected customers as soon as reasonably practicable following the investigation described in paragraph (d)(1) of this section, in accordance with the form, timing, and content requirements established by the Commissioner by regulation under subsection (e) of this section. If the permitted payment stablecoin issuer is unable to identify which specific customers’ information has been accessed, it shall notify all customers in the group of files or accounts reasonably believed to have been accessed. Customer notice may be delayed if a federal or state law-enforcement agency determines in writing that notification will interfere with a criminal investigation; upon such determination, the issuer shall notify affected customers as soon as the law-enforcement agency advises that notification will no longer interfere with the investigation.

(e) The Commissioner shall promulgate regulations establishing detailed standards under this section, which must be principles-based and substantially similar to standards applicable to federal qualified payment stablecoin issuers under 12 C.F.R. Part 15, as amended. The Commissioner’s regulations must address, at a minimum, all of the following:

(1) Content and format requirements for the written information security program required by subsection (a) of this section.

(2) Standards for determining when a breach has occurred or is reasonably likely to have occurred for purposes of paragraph (d)(2) of this section.

(3) Form, timing, and content of customer notifications under paragraph (d)(3) of this section.

(4) Coordination with the Commissioner’s supervisory office and relevant law-enforcement agencies in the event of a material breach.

85 Del. Laws, c. 339, § 1

85 Del. Laws, c. 339, § 1