Establishes a commission to study the European Union's general protection data regulation and the current state of cyber security in the state.
This bill would direct the Office of Information Technology Services, working with data collected by the State Board of Elections, to create an 11-member commission to study the European Union’s General Data Protection Regulation (GDPR) and New York’s current cybersecurity posture. The commission would be tasked with examining how GDPR-like protections could inform new state legislation aimed at protecting personal online information and strengthening cybersecurity defenses across both public and private sectors.
The commission’s review would focus on a broad set of critical systems and sectors, including critical infrastructure, financial systems, telecommunications, electrical grids, security systems, first responder systems, physical infrastructure, transportation, and other areas the commission deems necessary. Within one year of enactment, ITS would have to submit a report to the Governor and Legislature summarizing its findings and recommendations. The bill also authorizes the commission to request state resources and data needed to complete its work, and it contemplates consultation with experts in cybersecurity, cybercrime, hacking, voter fraud, and related fields.
The bill does not directly change existing cybersecurity, privacy, or election laws; instead, it creates a study commission and reporting requirement that could lead to future legislation. Its immediate legal effect would be to assign new duties to the Office of Information Technology Services and to authorize a commission to access state resources and data as needed. If enacted, the measure could influence later statutory changes affecting data privacy, cybersecurity standards, and protections for critical infrastructure and online personal information.
Based on the bill text and the absence of recorded committee debate or votes, the measure appears to be framed as a proactive, policy-development bill rather than a controversial regulatory overhaul. Its stated goal of improving personal data protection and cybersecurity suggests generally favorable policy intent, especially among supporters of stronger digital privacy and infrastructure security. However, because there is no recorded vote or transcript, there is no documented public sentiment in the available materials beyond the bill’s own emphasis on modernization and risk prevention.
The main potential points of contention are likely to be the scope of the commission’s mandate, the breadth of sectors it may study, and the inclusion of voter fraud among the areas of expertise to be consulted. Some stakeholders may question whether a study commission is the best use of state resources, whether the bill could lead to GDPR-style rules that are too burdensome for businesses or agencies, and how much access to state data the commission should have. Others may support the bill as a necessary first step toward stronger privacy protections and more resilient cybersecurity policy.