Enacts the New York privacy act to require companies to disclose their methods of de-identifying personal information, to place special safeguards around data sharing and to allow consumers to obtain the names of all entities with whom their information is shared.
S03044 would enact the “New York privacy act,” a comprehensive consumer privacy law governing how certain businesses collect, use, share, sell, and retain personal data of New York residents. The bill creates a broad set of consumer rights, including the right to notice, access, portability, correction, deletion, and the ability to opt out of targeted advertising, sale of personal data, and certain profiling. It also requires opt-in consent for processing sensitive data, imposes detailed disclosure requirements, and mandates that controllers provide clear, accessible privacy notices and mechanisms for consumers to exercise their rights.
The bill further requires covered businesses to conduct data protection assessments for higher-risk processing, maintain reasonable security safeguards, limit retention, and enter into written contracts with processors and third parties. It also creates a registration regime for data brokers, requiring annual registration with the Attorney General, payment of a fee, and public listing on a state registry. Enforcement authority is vested primarily in the Attorney General, who may seek injunctions, restitution, disgorgement, and civil penalties, and who may review data protection assessments during investigations. The bill would amend the General Business Law by adding a new Article 42-A and would take effect immediately, with most operative provisions delayed by one year.
The bill would significantly expand New York state consumer privacy law by adding new statutory obligations for businesses that conduct business in New York or target New York residents and meet specified revenue or data-processing thresholds. It would create new duties around notice, consent, data minimization, retention, security, and vendor management, while also establishing a state data broker registry and restrictions on selling data to unregistered brokers. The measure would also carve out numerous exceptions for existing federal regimes such as HIPAA, GLBA, FERPA, FCRA, and certain government, research, and public safety activities, while preserving local laws that provide equal or greater privacy protections.
The available legislative history suggests generally favorable committee support, with the Senate Internet and Technology Committee voting 6-1 in favor of the bill. The bill’s structure and findings reflect a strong policy preference for consumer privacy, transparency, and control over personal data, and the caption indicates an intent to impose special safeguards on data sharing and disclosure. No committee transcript is available here, but the vote indicates substantial support with at least one dissenting member.
Likely points of contention include the bill’s breadth and compliance burden on businesses, especially the extensive notice, consent, assessment, and contract requirements, as well as the new data broker registration and public disclosure obligations. Another likely area of dispute is the scope of the opt-out and opt-in rules, particularly for targeted advertising, sale of data, and profiling, which could affect advertising, analytics, and platform business models. The bill also contains many exemptions for regulated sectors and lawful processing, so debate may center on whether those carve-outs are too narrow or too broad, and on the Attorney General’s enforcement and regulatory authority.