Restricts the disclosure of personal information by businesses; provides that a business that retains a customer's personal information shall make available to the customer free of charge access to, or copies of, all of the customer's personal information retained by the business.
S06922, the “Right to Know Act,” would amend New York’s General Business Law to give consumers stronger rights to learn what personal information businesses retain about them and what information is shared with third parties. A business that stores a customer’s personal information would have to provide, free of charge, access to or copies of that information upon request. If the business discloses personal information to third parties, it would also have to disclose the categories of information shared and identify the third parties that received it, including contact information when available.
The bill sets out a request-and-response process requiring businesses to provide the information within 30 days for disclosures made in the prior 12 months, and it allows businesses to satisfy the requirement through privacy policies, designated request addresses, or certain notices. It also limits repeat requests to once per 12-month period and excuses compliance when the requester cannot reasonably be verified. The bill defines “personal information” broadly to include identifiers, location data, internet and mobile activity, financial and medical information, demographic characteristics, content created by the customer, and information about children.
The bill would create a new section 899-cc in the General Business Law and expand the state’s privacy and consumer disclosure obligations for businesses operating in New York. It would apply to a broad range of entities, including for-profit businesses and nonprofits, but not public corporations, and would establish a private and public enforcement mechanism allowing customers, the Attorney General, district attorneys, city attorneys, and city prosecutors to bring civil actions for violations. The bill also amends the article heading for existing data-security law to reflect broader protections related to acquisition and use of private information. In practice, it would require businesses to maintain systems for tracking disclosures, responding to consumer requests, and identifying third-party recipients of customer data, while preserving exceptions for service providers, legal compliance, fraud/security needs, and publicly available information.
Based on the bill text and the absence of recorded committee debate or votes in the provided materials, the measure appears to be framed as a consumer-privacy and transparency bill with a pro-consumer policy rationale. Its findings emphasize privacy rights, informed choice, and the need for consumers to understand how businesses collect, share, and sell personal information. The overall tone of the legislation is protective of consumers and skeptical of current data-sharing practices, especially those involving tracking tools, data brokers, and mobile applications.
The main points of potential contention are the breadth of the disclosure obligations and the operational burden on businesses. Businesses would need to identify categories of data shared, maintain records of third-party disclosures, and provide customer-specific information when reasonably available, which could be costly or difficult for companies with complex data ecosystems. Another likely area of dispute is the bill’s broad definition of personal information and its inclusion of sensitive categories such as health, race, religion, political activity, and children’s data. Supporters would likely focus on transparency and privacy rights, while opponents may argue that the bill is overinclusive, burdensome, or difficult to implement consistently across different business models.