Requires e-mail service providers to implement a procedure to authenticate an individual's identity when such individual creates a new e-mail account.
Summary
This bill would amend New York’s General Business Law to require e-mail service providers doing business in the state to create and use a procedure to authenticate a person’s identity when that person opens a new e-mail account. The bill defines an e-mail service provider broadly to include any person, business, or organization qualified to do business in New York that offers the ability to send e-mail messages.
The measure does not specify the exact authentication method, leaving providers discretion to design a process that verifies identity before account creation. If enacted, it would take effect 90 days after becoming law and would establish a new compliance obligation for e-mail platforms operating in New York.
Impact
The bill would add a new section 390-f to the General Business Law, creating a state-level identity verification requirement for new e-mail account creation. It would affect e-mail service providers operating in New York by requiring them to develop and implement authentication procedures, potentially changing account onboarding practices and compliance policies. The bill does not amend criminal, privacy, or consumer protection statutes beyond this new requirement, but it could have practical implications for user access, data collection, and platform operations.
Sentiment
No committee transcript or vote record is available, so there is no documented legislative debate or recorded support/opposition in the provided materials. Based on the text alone, the bill appears to reflect a policy interest in identity verification and fraud prevention, but the public or legislative sentiment cannot be determined from the available record.
Contention
The main point of contention likely would be the breadth and ambiguity of the required authentication procedure, since the bill does not define what counts as adequate identity verification. Potential concerns could include privacy, data security, administrative burden on providers, and barriers for users who prefer anonymity or lack standard identification. Supporters would likely emphasize fraud reduction, accountability, and abuse prevention, while critics may argue that the mandate is overbroad and could be difficult to implement consistently.
Same As
Requires e-mail service providers to implement a procedure to authenticate an individual's identity when such individual creates a new e-mail account.
Directs every peer-to-peer mobile service to require users to create a personal identification code associated with the user's account that is required to be used when certain actions are taken and to require users to set a monetary amount for intended transfers above which the use of a personal identification number will be required to authenticate the user's identity.
Individualized service plans; legislative intent; prepared and maintained written individualized service plan; timing requirements; standards; disputed evidence; implementation; disposition; approval; tailoring; language governs; modification; standardization; review hearings; Oklahoma Department of Mental Health and Substance Abuse Services; report; effective date.
Individualized service plans; legislative intent; prepared and maintained written individualized service plan; timing requirements; standards; disputed evidence; implementation; disposition; approval; tailoring; language governs; modification; standardization; review hearings; Oklahoma Department of Mental Health and Substance Abuse Services; report; effective date.
Requires voice service providers to display the level of STIR/SHAKEN authentication on incoming calls in an way understandable by the general public; requires voice service providers to file annual reports with the public service commission.