A11127 amends New York’s General Business Law section 899-aa, which governs notice to consumers after a security breach. The bill requires breach notices to include, in addition to existing contact and agency information, a description of the categories of information accessed or believed to have been accessed without authorization. It also adds a new requirement that if the person or business providing the notice was the source of the breach, the notice must include an offer of identity theft prevention and mitigation services at no cost to affected individuals for at least 12 months, along with the information needed to use that offer, when the breach exposed or may have exposed personal information.
The measure is aimed at strengthening consumer protections after data breaches by making sure affected people receive both clearer information and practical remediation services. It would apply to businesses and other entities that must provide breach notifications under New York law, especially where the notifying party is responsible for the breach. The bill takes effect immediately if enacted.
Because the bill was only introduced and referred to committee, there is no recorded vote or committee transcript showing broader legislative reaction. Based on the text, the bill appears consumer-protective and likely intended to improve identity theft prevention and breach response, with no explicit opposition reflected in the available record.
The main point of potential contention is the added compliance burden on businesses that suffer or cause a breach, particularly the cost of providing at least 12 months of free identity theft protection services. Supporters would likely emphasize stronger consumer notice and remediation, while critics may focus on the financial and administrative impact on covered entities and the ambiguity of when a breach "may have exposed" personal information.
Impact
The bill would amend General Business Law section 899-aa, expanding the required contents of data breach notices and imposing a new obligation to offer free identity theft prevention and mitigation services for at least 12 months when the notifying entity was the source of the breach and personal information was or may have been exposed. It would affect businesses and other entities subject to New York’s breach notification law, and would likely increase compliance and remediation costs while giving consumers additional post-breach protections.
Sentiment
The available record suggests a generally consumer-protective and favorable policy direction, but there is no committee transcript or vote history to show formal support or opposition. The bill’s purpose appears to be strengthening breach response and identity theft protection, which typically draws support from consumer advocates, while the added service requirement could prompt concern from businesses and compliance stakeholders.
Contention
The likely point of contention is whether requiring at least 12 months of free identity theft prevention and mitigation services is an appropriate and necessary consumer safeguard or an undue burden on businesses that are already dealing with a breach. Another possible issue is the scope of the trigger language—especially the standard that services must be offered when personal information was "or may have been" exposed—which could be viewed as broad or uncertain by regulated entities.
Same As
Provides that if the person or business providing the notification was the source of the breach, an offer to provide appropriate identity theft prevention and mitigation services, shall be provided at no cost to the affected person for not less than 12 months, along with all information necessary to take advantage of the offer to any person whose information was or may have been breached if the breach exposed or may have exposed personal information.
Requires providers of residential services to developmentally disabled children to have electronic monitoring devices in the common areas of their residential facilities.
Authorizes a member to obtain up to three years of service credit for prior paid police service within the United States with an accredited police agency outside of the state of New York; requires a member to have at least five years of credited service to be eligible to receive such credit.
Authorizes a member to obtain up to three years of service credit for prior paid police service within the United States with an accredited police agency outside of the state of New York; requires a member to have at least five years of credited service to be eligible to receive such credit.
Relates to bans from online dating services based on content; requires retention of records where necessary to maintain enforcement of fraud bans or content bans; makes related provisions.
Relates to bans from online dating services based on content; requires retention of records where necessary to maintain enforcement of fraud bans or content bans; makes related provisions.
Establishes a pilot program to implement a unified administrative platform for the authorization, coordination, monitoring, and payment of non-emergency medical transportation services.
Provides that a member with credited service in excess of twenty-five years shall receive an additional retirement allowance equal to one-sixtieth of such member's final average salary for each year of creditable service in excess of twenty-five years; makes related provisions.