Relates to when and how notification of a data breach is to be provided to the department of financial services.
Summary
Bill S00804 amends the general business law in New York to specify the requirements for notifying the Department of Financial Services (DFS) in the event of a data breach. The bill stipulates that notification to the DFS is only required if the entity involved is classified as a 'covered entity' under existing regulations. Furthermore, it mandates that such notifications must not delay the communication of information to affected New York residents. This change aims to streamline the notification process and ensure timely communication in the event of data breaches affecting residents.
Impact
The bill modifies existing provisions regarding data breach notifications, particularly focusing on the obligations of covered entities. By clarifying when notification to the DFS is necessary, it aims to reduce confusion among businesses and enhance compliance with state laws. This could lead to improved data breach response protocols and potentially better protection for consumers by ensuring they are informed promptly about breaches that may affect their personal information.
Sentiment
The sentiment surrounding Bill S00804 appears to be overwhelmingly positive, as indicated by the unanimous votes in both the Senate and Assembly. The support from various stakeholders suggests a consensus on the importance of timely notifications in the event of data breaches, reflecting a proactive approach to consumer protection in New York.
Contention
While the bill has received broad support, some concerns have been raised regarding the definition of 'covered entity' and whether it adequately encompasses all businesses that handle sensitive consumer data. Critics argue that the criteria could leave out smaller businesses that may not be classified as covered entities but still pose risks to consumer data security. However, these concerns did not significantly hinder the bill's passage.
Provides that if the person or business providing the notification was the source of the breach, an offer to provide appropriate identity theft prevention and mitigation services, shall be provided at no cost to the affected person for not less than 12 months, along with all information necessary to take advantage of the offer to any person whose information was or may have been breached if the breach exposed or may have exposed personal information.
Provides that a business must provide notification of a data breach within 30 days of such breach; includes the department of financial services to the list of entities that must be notified of a data breach that affects any New York resident.