New York 2025-2026 Regular Session

New York Assembly Bill A08614

Introduced
5/22/25  
Refer
5/22/25  

Caption

Requires all state entities, including local governments, to notify affected individuals in the event of a data breach where information is compromised; defines "cybersecurity incident".

Summary

This bill amends New York’s State Technology Law to expand and clarify the state’s data-breach notification requirements for state entities. It broadens the definition of a “breach of the security of the system” to include not only unauthorized acquisition and acquisition without valid authorization, but also unauthorized utilization of computerized data. It also adds a new definition of “cybersecurity incident,” describing events on or through a computer network that jeopardize the integrity, confidentiality, or availability of systems, infrastructure, or information. The bill requires state entities that own, license, or maintain computerized data containing private information to notify affected New York residents of a breach as quickly as possible and without unreasonable delay, subject to law-enforcement needs and time needed to assess and restore the system. It also requires consultation with the Office of Information Technology Services, which must provide a report within 90 days on the scope of the breach and recommendations to improve security. For state entities holding data they do not own, the bill requires immediate notice to the owner or licensee when private information is accessed, acquired, or utilized without authorization. The bill further clarifies that the term “state entity” includes local governments and local agencies, while excluding the judiciary. The bill’s impact is to strengthen and modernize New York’s breach-notification framework by explicitly covering local governments and by recognizing unauthorized use of data and cybersecurity incidents as triggers for response and notice. It would affect a broad range of public-sector entities that handle personal information, including state agencies, public authorities, municipalities, counties, towns, villages, and other local agencies. It also increases the role of the Office of Information Technology Services in breach assessment and remediation. Overall, the bill appears to be framed as a cybersecurity and consumer-protection measure, with an emphasis on faster notification and clearer standards for public entities. No committee transcript or vote record is provided, so there is no documented floor or committee debate to indicate formal support or opposition. Based on the bill text alone, the measure is likely intended to address growing concerns about ransomware, unauthorized access, and data compromise in government systems. Notable points of contention, based on the text, could include the expanded scope of entities covered, the addition of “unauthorized utilization” and “cybersecurity incident” as triggering concepts, and the operational burden of faster notice and reporting requirements on state and local agencies. These changes may be viewed as improving transparency and security, but they could also raise concerns about compliance costs, incident-assessment timelines, and coordination with law enforcement and IT officials.

Impact

The bill amends section 208 of the State Technology Law to expand breach definitions, require prompt notice to affected individuals, require immediate notice to data owners/licensees in certain cases, and include local governments within the definition of state entity. It would affect public-sector data custodians across New York and increase the responsibilities of the Office of Information Technology Services in breach response and reporting.

Sentiment

No votes or committee transcripts are available, so there is no recorded legislative sentiment to summarize. Based on the bill’s content, it is a generally pro-disclosure, pro-cybersecurity measure aimed at improving public-sector breach response and protecting residents whose personal information is compromised.

Contention

The main potential points of contention are the bill’s expanded coverage of local governments and other public entities, the broader trigger for notification through “unauthorized utilization” and “cybersecurity incident,” and the practical burden of expedited notice, consultation with ITS, and post-breach reporting. Supporters would likely emphasize transparency, resident protection, and stronger cybersecurity standards, while critics may focus on administrative costs, implementation challenges, and the risk of premature notice before a breach is fully understood.

Companion Bills

NY S08169

Same As Requires all state entities, including local governments, to notify affected individuals in the event of a data breach where information is compromised; defines "cybersecurity incident".

Previously Filed As

NY S08169

Requires all state entities, including local governments, to notify affected individuals in the event of a data breach where information is compromised; defines "cybersecurity incident".

NY S39

Protecting sensitive personal information from breaches and other cybersecurity incidents

NY S07672

Requires all municipal corporations to report cybersecurity incidents and demands of ransom payments to the division of homeland security and emergency services; defines terms; requires cybersecurity incident reviews; requires cybersecurity awareness training, cybersecurity protection and data protection standards for state maintained information systems.

NY A06769

Requires all municipal corporations to report cybersecurity incidents and demands of ransom payments to the division of homeland security and emergency services; defines terms; requires cybersecurity incident reviews; requires cybersecurity awareness training, cybersecurity protection and data protection standards for state maintained information systems.

NY S01961

Establishes the "secure our data act"; relates to cybersecurity protection by state entities; requires the office of information technology services to develop standards for data protection of state entity-maintained information.

NY HB1220

Cybersecurity; governmental and certain commercial entities substantially complying with standards not liable for incidents relating to.

NY SB626

Security Breach Notification Act; requiring notice of security breach of certain information; modifying provisions. Effective date.

NY SB626

Security Breach Notification Act; requiring notice of security breach of certain information; modifying provisions. Effective date.

NY HB1380

Cybersecurity; governmental and certain commercial entities substantially complying with standards not liable for incidents relating to.

NY A11127

Provides that if the person or business providing the notification was the source of the breach, an offer to provide appropriate identity theft prevention and mitigation services, shall be provided at no cost to the affected person for not less than 12 months, along with all information necessary to take advantage of the offer to any person whose information was or may have been breached if the breach exposed or may have exposed personal information.

Similar Bills

No similar bills found.