New York 2025-2026 Regular Session

New York Assembly Bill A08158

Introduced
5/2/25  
Refer
5/2/25  

Caption

Enacts the New York privacy act to require companies to disclose their methods of de-identifying personal information, to place special safeguards around data sharing and to allow consumers to obtain the names of all entities with whom their information is shared.

Summary

This bill would enact the “New York privacy act” and add a new Article 42-A to the General Business Law establishing a broad consumer privacy framework for businesses operating in New York or targeting New York residents. It creates new rights for consumers to receive clear notice about data practices, opt out of targeted advertising, the sale of personal data, and certain profiling, and to access, correct, port, and delete their personal data. The bill also requires special opt-in consent for processing sensitive data, including biometric, genetic, precise geolocation, and certain financial or government-identification data. The bill imposes extensive obligations on controllers, processors, and third parties that handle personal data. Covered businesses must conduct regular data protection assessments for higher-risk processing, maintain reasonable security safeguards, limit retention to what is necessary, and use written contracts governing disclosures to processors and third parties. It also creates a registration regime for data brokers, requiring annual registration with the Attorney General, disclosure of business information and consumer-rights procedures, and a public registry of registered data brokers. The Attorney General is given broad enforcement authority, including subpoenas, civil penalties, restitution, disgorgement, and injunctive relief. In practical terms, the bill would significantly expand state privacy law by regulating how personal data is collected, used, shared, sold, and retained, while also carving out numerous exceptions for areas already governed by federal or state law, such as HIPAA, GLBA, FERPA, FCRA, employment records, and certain public health and research activities. It would also limit local governments from adopting conflicting or weaker privacy rules, while preserving stronger local protections that do not conflict with the act. The bill would take effect immediately, but most operative privacy provisions would begin one year after enactment. The overall sentiment reflected in the bill text is strongly pro-privacy and consumer-protective, emphasizing privacy as a fundamental right and portraying current data practices as opaque and harmful. Although there are no committee transcripts or recorded votes provided, the structure and findings suggest the bill is intended to give consumers more control and transparency rather than to loosen regulation. The bill’s detailed exceptions and business-facing compliance rules indicate an effort to balance consumer rights with operational and legal necessities. The main points of contention likely center on the bill’s breadth and compliance burden, especially for large businesses, data brokers, advertisers, and companies that rely on profiling or data sharing. Potential friction points include the opt-in consent standard for sensitive data, the broad definition of sale, the requirement to disclose downstream recipients, the data broker registry, and the Attorney General’s enforcement powers. Businesses may also object to the limits on targeted advertising, the restrictions on loyalty programs and pricing practices, and the possibility that the law could overlap with or exceed existing federal privacy regimes.

Impact

The bill would amend the General Business Law by adding a new Article 42-A, creating a comprehensive statewide privacy regime for covered businesses, data brokers, processors, and third parties. It would establish consumer rights to notice, opt out, access, portability, correction, and deletion; require data protection assessments and security safeguards; regulate targeted advertising, sale of personal data, and sensitive data processing; and create a public data broker registry enforced by the Attorney General. It would also preempt conflicting local privacy requirements while preserving stronger nonconflicting local laws, and it would exempt or defer to several existing federal and state privacy frameworks such as HIPAA, GLBA, FERPA, and FCRA.

Sentiment

The bill is framed in strongly favorable terms toward consumer privacy and data control, with legislative findings describing privacy as a fundamental right and criticizing opaque data practices, behavioral advertising, and algorithmic decision-making. No committee debate or votes are provided, so there is no recorded opposition or support in the supplied history, but the bill’s design suggests a clear pro-consumer, regulatory approach. The tone of the text indicates an intent to strengthen protections rather than compromise them, while still including numerous carve-outs for regulated sectors and lawful uses.

Contention

Likely areas of contention are the bill’s compliance costs and operational restrictions on businesses that collect or monetize personal data, especially those engaged in targeted advertising, profiling, or data brokerage. The most debated provisions would likely include the opt-in consent requirement for sensitive data, the broad definition of “sale,” the obligation to disclose categories of third parties and retention periods, the requirement to honor browser or device privacy signals, and the Attorney General’s broad enforcement and subpoena powers. Data brokers and large online platforms would likely be the most affected parties, while consumer advocates would likely support the bill’s stronger transparency, deletion, and opt-out rights.

Companion Bills

NY S03044

Same As Enacts the New York privacy act to require companies to disclose their methods of de-identifying personal information, to place special safeguards around data sharing and to allow consumers to obtain the names of all entities with whom their information is shared.

Previously Filed As

NY S08524

Enacts the New York privacy act to require companies to disclose their methods of de-identifying personal information, to place special safeguards around data sharing and to allow consumers to obtain the names of all entities with whom their information is shared.

NY S00365

Enacts the New York privacy act to require companies to disclose their methods of de-identifying personal information, to place special safeguards around data sharing and to allow consumers to obtain the names of all entities with whom their information is shared.

NY A00974

Enacts the New York privacy act to require companies to disclose their methods of de-identifying personal information, to place special safeguards around data sharing and to allow consumers to obtain the names of all entities with whom their information is shared.

NY S03044

Enacts the New York privacy act to require companies to disclose their methods of de-identifying personal information, to place special safeguards around data sharing and to allow consumers to obtain the names of all entities with whom their information is shared.

NY A04947

Enacts the NY privacy act to require companies to disclose their methods of de-identifying personal information, to place special safeguards around data sharing and to allow consumers to obtain the names of all entities with whom their information is shared.

NY A08906

Requires entities that access a consumer's consumer credit report to notify such consumer of their right to obtain a security freeze, in addition to other information necessary to place, temporarily lift or permanently lift such security freeze; prohibits notices to consumers of their right to obtain a security freeze from containing advertising for paid services.

NY S09658

Establishes a private right of action for any person whose personally identifying information was intentionally disclosed by another individual, without consent, for the purpose of harassing, threatening, intimidating, or causing harm to such person, or with reckless disregard as to whether such disclosure would cause such harm; defines personal information.

NY A10091

Establishes a private right of action for any person whose personally identifying information was intentionally disclosed by another individual, without consent, for the purpose of harassing, threatening, intimidating, or causing harm to such person, or with reckless disregard as to whether such disclosure would cause such harm; defines personal information.

NY A08101

Establishes the New York Data Protection Act; requires government entities and contractors to disclose certain personal information collected about individuals.

NY S09672

Restricts the disclosure of personal information by businesses; provides that a business that retains a customer's personal information shall make available to the customer free of charge access to, or copies of, all of the customer's personal information retained by the business.

Similar Bills

No similar bills found.