Sector security regimes
Law No. 40 of 2006 on Electronic Payment Systems and Financial and Banking Operations, Secure-Services and Banking-Confidentiality Duty
Law No. 40 of 2006 Regarding Electronic Payment Systems and Financial and Banking Operations, art. 27Official Arabic-language PDF of Law No. 40 of 2006 Regarding Electronic Payment Systems and Financial and Banking Operations
In force since 28 December 2006. Binds private bodies.
What this law does
Article 27 of Law No. 40 of 2006 Regarding Electronic Payment Systems and Financial and Banking Operations binds every financial institution practicing electronic funds transfer under the Law to two duties: comply with the Bank Law, the Banks Law, and the related laws, regulations, and instructions issued under them, and take the measures necessary to provide secure services to customers and preserve banking confidentiality.
The Law defines a financial institution as any body authorized to deal in financial transfers under the laws in force, a class that reaches a payments or funds-transfer platform operating as, or through, a licensed Yemeni financial institution.
Article 30 separately empowers the Central Bank of Yemen to issue the instructions needed to organize electronic funds transfer business, including approving electronic payment methods and the disclosure of information banks and financial institutions must provide; Article 44 further directs the Bank's Governor to establish payment-system infrastructure, organize authentication-certificate issuance with confidentiality safeguards for an electronic-signature code, and set technical specifications for devices and machines used in financial and banking technology, but no implementing regulation issued under either article was located, so no specific technical standard is described here.
No provision of this Law's Chapter Eight (Articles 37 to 41) names a penalty for a breach of Article 27 itself; that chapter's penalties instead attach to authentication-certificate fraud and a licensed authentication provider's own violations, and are this jurisdiction's scraping-topic computer-misuse and fraud findings rather than a security-topic one.
What it requires