Prohibits sharing or selling personal data to third parties by government entities and contractors.
Summary
This bill would create a new article in the New York Executive Law restricting how state agencies and their contractors collect, use, share, and sell personal information. It requires government entities and contractors to disclose, at or before collection, what categories of personal information they are collecting and for what purposes, and it bars them from collecting additional categories or using the information for new purposes without updated notice. The bill defines personal information broadly to include identifiers, biometric data, employment and education information, financial and tax information, and inferences drawn from such data, while excluding publicly available information and properly deidentified or aggregate data.
The bill also generally prohibits government entities and contractors from sharing personal information with third parties unless the sharing is necessary to perform a legitimate government purpose or a contractor’s services, and it prohibits selling personal information outright. It includes exceptions for disclosures required by law, subpoenas, FOIL requests, legal claims, and certain consumer reporting agency activity governed by the federal Fair Credit Reporting Act. The bill would take effect one year after becoming law.
Impact
If enacted, the bill would impose new privacy and data-governance obligations on New York state agencies, their subdivisions, and contractors that process information on their behalf. It would limit interagency and contractor data sharing to situations where the information is crucial to the relevant government function, require notice to individuals about collection and use, and restrict commercial transfer of personal data for monetary or other valuable consideration. It would also create compliance standards around deidentification, notice, and downstream use by third parties, while preserving existing legal disclosure obligations and certain credit-reporting uses.
Sentiment
Based on the bill text and the absence of recorded committee discussion or votes, the measure appears to reflect a privacy-protective policy approach focused on limiting government data monetization and secondary use. The overall framing suggests support for stronger safeguards around personal information held by public entities and their vendors. Because there is no available voting history or transcript, there is no documented public sentiment from committee debate in the provided materials.
Contention
The main points of potential contention are the breadth of the definition of personal information, the limits on sharing between government entities and contractors, and the practical compliance burden on agencies and vendors. Questions may arise over what qualifies as “crucial” to a government purpose, what constitutes “serious hardship” for obtaining data independently, and how the bill interacts with existing public-records obligations and operational needs. Contractors and agencies may also be concerned about liability boundaries, notice requirements, and whether the prohibition on selling data could affect common data-processing arrangements or future technology partnerships.