Relates to when and how notification of a data breach is to be provided to the department of financial services.
Summary
Bill A00913 amends the general business law regarding the notification process for data breaches that affect New York residents. It specifies that businesses or individuals must notify the state attorney general, the department of state, the division of state police, and the department of financial services about the timing, content, and distribution of breach notifications. However, the requirement to notify the department of financial services applies only to covered entities as defined under existing regulations, and this notification must not delay informing affected residents.
Impact
The bill modifies existing laws governing data breach notifications by streamlining the process for certain entities while ensuring that affected residents are notified promptly. It clarifies the obligations of covered entities under the law, potentially reducing the administrative burden on businesses while maintaining consumer protection standards. This amendment aligns New York's data breach notification requirements with evolving regulatory standards.
Sentiment
The sentiment around Bill A00913 appears to be positive, as indicated by the unanimous support it received in committee votes. The bill has passed through multiple committees with no opposition, suggesting a consensus on the need for clearer guidelines regarding data breach notifications.
Contention
There are no notable points of contention reported in the discussions surrounding the bill. The unanimous votes in favor across various committees indicate broad support, with no significant opposition or concerns raised by stakeholders.
Provides that if the person or business providing the notification was the source of the breach, an offer to provide appropriate identity theft prevention and mitigation services, shall be provided at no cost to the affected person for not less than 12 months, along with all information necessary to take advantage of the offer to any person whose information was or may have been breached if the breach exposed or may have exposed personal information.
Provides that a business must provide notification of a data breach within 30 days of such breach; includes the department of financial services to the list of entities that must be notified of a data breach that affects any New York resident.