New York 2025-2026 Regular Session

New York Senate Bill S09088

Introduced
1/30/26  

Caption

Requires the registration of data brokers; imposes regulations upon data brokers; establishes a data deletion mechanism for consumers; imposes penalties upon data brokers for violations of the law.

Summary

This bill would create a new Article 42-A in the General Business Law regulating “data brokers” in New York. It defines data brokers broadly as businesses that collect and sell consumer personal information to third parties without a direct relationship with the consumer, and it sets out detailed definitions for personal information, sensitive personal information, biometric data, precise geolocation, reproductive health care data, cross-context behavioral advertising, dark patterns, and related privacy terms. The bill also establishes who is covered, including certain large businesses, affiliated entities, joint ventures, and some voluntarily certified businesses. The bill requires data brokers to register with the Attorney General within 60 days of becoming subject to the law, pay a registration fee, and disclose extensive information about their data practices, including categories of data collected, whether they sell or share data to governments, law enforcement, foreign actors, or AI developers, and how consumers can exercise privacy rights. It also requires the Attorney General to create a public webpage listing registered data brokers and a centralized data deletion mechanism through which consumers can submit a single verifiable request to delete their personal information from all registered data brokers, subject to specified exemptions. Data brokers must process deletion requests, stop processing the affected data, direct service providers and contractors to delete it, and provide accessible deletion methods and website disclosures. The bill would also impose ongoing compliance obligations, including independent third-party audits every three years, annual website disclosures of deletion-request metrics, and a documented comprehensive information security program with administrative, technical, and physical safeguards. It authorizes the Attorney General to adopt implementing regulations and to enforce the law through civil penalties and injunctions. The bill includes exemptions for entities and data covered by HIPAA, the Fair Credit Reporting Act, the Gramm-Leach-Bliley Act, certain research activities, health information networks, and election-related data processing. Because there are no committee transcripts or recorded votes provided, the overall sentiment cannot be measured from formal debate or roll call history. Based on the bill text, the measure appears strongly privacy-protective and consumer-oriented, with a clear emphasis on transparency, deletion rights, and security controls. The main likely points of contention are the breadth of the definition of data broker, the operational burden of centralized deletion and recurring audits, the scope of required disclosures, and the potential compliance costs for affected businesses, especially those handling sensitive data or operating across multiple platforms. If enacted, the bill would significantly expand state oversight of data brokerage activity and create new consumer rights to identify, delete, and limit the use of personal information held by data brokers. It would also give the Attorney General a central regulatory and enforcement role, while carving out several industry and subject-matter exemptions to avoid overlap with existing federal and state privacy regimes.

Impact

The bill would add a new data broker regulatory framework to New York’s General Business Law, imposing registration, disclosure, deletion, audit, and cybersecurity obligations on covered data brokers. It would create new duties for businesses that buy, sell, or share consumer personal information, and it would establish a centralized state-run deletion mechanism administered by the Attorney General. The bill also authorizes civil penalties for noncompliance and requires public-facing transparency about data collection and deletion practices, while exempting certain health, financial, research, and election-related data activities.

Sentiment

No committee transcript or vote record is provided, so there is no documented legislative debate or recorded chamber sentiment to summarize. On its face, the bill reflects a strong pro-privacy, consumer-protection approach, suggesting support from lawmakers concerned about data broker practices, consumer tracking, and the handling of sensitive personal information. The structure of the bill indicates an intent to create robust consumer rights and stronger state oversight rather than a light-touch regulatory approach.

Contention

The most likely areas of contention are the bill’s broad definition of “data broker,” the administrative burden of registration, audits, and detailed reporting, and the feasibility of a statewide deletion mechanism that requires brokers to process requests every 45 days. Businesses may object to the compliance costs, the scope of information that must be disclosed, and the requirement to delete or stop processing data across service providers, contractors, and subsidiaries. Privacy advocates, by contrast, would likely support the bill’s strong deletion rights, restrictions on dark patterns, and protections for sensitive categories such as biometric, reproductive health, and geolocation data.

Companion Bills

NY A09642

Same As Requires the registration of data brokers; imposes regulations upon data brokers; establishes a data deletion mechanism for consumers; imposes penalties upon data brokers for violations of the law.

Similar Bills

No similar bills found.