Enacts the "digital fairness act"; requires any entity that conducts business in New York and maintains the personal information of 500 or more individuals to provide meaningful notice about their use of personal information; establishes unlawful discriminatory practices relating to targeted advertising.
S04276, the “Digital Fairness Act,” would create a broad new privacy and algorithmic accountability framework for entities doing business in New York that maintain personal information on 500 or more individuals. The bill requires covered entities to provide a short-form privacy notice, obtain affirmative opt-in consent before processing personal information except in specified circumstances, and give individuals access to, portability of, and deletion rights over their data. It also imposes affirmative duties on covered entities to protect data, limit processing to what is necessary, restrict sharing with third parties and data processors through contracts and audits, and prohibit certain uses of device identifiers and biometric information.
The bill also reaches government use of technology. It would require state and local agencies, and public benefit corporations, to conduct and publish automated decision system impact assessments before acquiring or using such systems, adopt public use policies, provide notice and human review for decisions affecting rights or benefits, and publish annual metrics on human review requests. In addition, it would bar payment for certain automated decision systems unless they use open source software, comply with the bill’s assessment and policy requirements, do not contain nondisclosure provisions that interfere with transparency, do not discriminate, and do not make final rights-affecting decisions without human intervention or deploy weapons.
Beyond privacy and AI governance, the bill amends New York’s human rights and consumer protection laws to prohibit discriminatory targeted advertising and related data practices. It would make it unlawful to use personal information, proxies, or targeted ads to discriminate in employment, housing, credit, health care, insurance, education, and public accommodations on the basis of protected characteristics. The bill also requires advertisers to certify compliance with the state’s anti-discrimination law when placing certain targeted ads. Finally, it expands school internet-safety instruction into a required K-12 digital literacy and digital privacy curriculum, with model curricula, training resources, and compliance tracking.
The bill’s impact on state law would be substantial. It would add a new article to the General Business Law, create new discriminatory-practices provisions in the Executive Law, add procurement and transparency requirements in the State Finance Law, and revise the Education Law to mandate digital privacy education. It would also create private rights of action, attorney general enforcement, civil penalties, rebuttable presumptions of harm, and restrictions on contractual waivers, making the measure one of the more expansive privacy and algorithmic accountability proposals in New York.
Because there are no committee transcripts or recorded votes in the provided materials, there is no documented debate or formal vote history to gauge sentiment. Based on the bill text alone, the measure is clearly framed as a consumer- and civil-rights-protective proposal, with strong emphasis on privacy, transparency, anti-discrimination, and limits on surveillance and automated decision-making. The main likely points of contention are the breadth of the opt-in consent regime, the compliance burden on businesses and government agencies, the open-source and human-review requirements for public-sector AI, and the bill’s expansive enforcement and damages provisions.
The bill would significantly expand New York’s privacy, anti-discrimination, procurement, and education laws. It creates new obligations for covered private entities to provide concise privacy notices, obtain opt-in consent for most personal-data processing, limit retention and disclosure, and implement special protections for biometric information and device identifiers. It also adds new unlawful discriminatory practice provisions targeting discriminatory advertising and data-driven access to employment, housing, credit, health care, education, insurance, and public accommodations. On the public-sector side, it imposes automated decision system impact assessments, notice, human review, and transparency requirements, and restricts state payments for certain AI systems. The Education Law amendment would make digital literacy and digital privacy instruction mandatory statewide in K-12 schools.
No committee discussion or vote record was provided, so there is no direct evidence of legislative support or opposition in the available materials. The bill’s findings and structure indicate a strong pro-privacy, pro-civil-rights orientation, with an emphasis on consumer control, transparency, and anti-discrimination. Overall, the measure appears designed to appeal to privacy advocates, civil rights groups, and supporters of AI oversight, while likely drawing concern from businesses, technology vendors, and public agencies that would face new compliance and procurement obligations.
The most likely points of contention are the bill’s broad scope and strict compliance requirements. Covered entities would need affirmative opt-in consent for many forms of data processing, and the bill limits the use of targeted advertising, third-party data sharing, biometric collection, and surreptitious device surveillance. Businesses may object to the short-form notice mandate, audit requirements, civil penalties, and private right of action. Government agencies and vendors may also resist the open-source preference, public disclosure of automated decision system details, mandatory human review, and restrictions on using AI for rights- or benefits-related decisions. Supporters are likely to emphasize privacy, transparency, and anti-discrimination protections, while critics are likely to focus on operational burden, cost, and possible limits on data-driven services and public-sector technology adoption.