New York 2025-2026 Regular Session

New York Senate Bill S00804

Introduced
1/8/25  
Refer
1/8/25  
Engrossed
1/28/25  
Refer
1/28/25  
Engrossed
1/28/25  
Enrolled
2/12/25  
Chaptered
2/14/25  

Caption

Relates to when and how notification of a data breach is to be provided to the department of financial services.

Summary

Bill S00804 amends the general business law in New York to specify the requirements for notifying the Department of Financial Services (DFS) in the event of a data breach. The bill stipulates that notification to the DFS is only required if the entity involved is classified as a 'covered entity' under existing regulations. Furthermore, it mandates that such notifications must not delay the communication of information to affected New York residents. This change aims to streamline the notification process and ensure timely communication in the event of data breaches affecting residents.

Impact

The bill modifies existing provisions regarding data breach notifications, particularly focusing on the obligations of covered entities. By clarifying when notification to the DFS is necessary, it aims to reduce confusion among businesses and enhance compliance with state laws. This could lead to improved data breach response protocols and potentially better protection for consumers by ensuring they are informed promptly about breaches that may affect their personal information.

Sentiment

The sentiment surrounding Bill S00804 appears to be overwhelmingly positive, as indicated by the unanimous votes in both the Senate and Assembly. The support from various stakeholders suggests a consensus on the importance of timely notifications in the event of data breaches, reflecting a proactive approach to consumer protection in New York.

Contention

While the bill has received broad support, some concerns have been raised regarding the definition of 'covered entity' and whether it adequately encompasses all businesses that handle sensitive consumer data. Critics argue that the criteria could leave out smaller businesses that may not be classified as covered entities but still pose risks to consumer data security. However, these concerns did not significantly hinder the bill's passage.

Companion Bills

NY A00913

Same As Relates to when and how notification of a data breach is to be provided to the department of financial services.

Previously Filed As

NY A00913

Relates to when and how notification of a data breach is to be provided to the department of financial services.

NY A11127

Provides that if the person or business providing the notification was the source of the breach, an offer to provide appropriate identity theft prevention and mitigation services, shall be provided at no cost to the affected person for not less than 12 months, along with all information necessary to take advantage of the offer to any person whose information was or may have been breached if the breach exposed or may have exposed personal information.

NY S02659

Provides that a business must provide notification of a data breach within 30 days of such breach; includes the department of financial services to the list of entities that must be notified of a data breach that affects any New York resident.

NY S1452

Department of Financial Services

NY H1221

Department of Financial Services

NY H1281

Department of Financial Services

NY HB1281

Department of Financial Services:

NY S1572

Department of Financial Services

NY SB626

Security Breach Notification Act; requiring notice of security breach of certain information; modifying provisions. Effective date.

NY SB626

Security Breach Notification Act; requiring notice of security breach of certain information; modifying provisions. Effective date.

Similar Bills

No similar bills found.