Provides for the accessibility of consumer financial data; prohibits fees for the transfer of such data to authorized parties.
S09483 would create a new article in the New York banking law called the “New York financial data rights act.” The bill gives New York consumers and small businesses a statutory right to obtain their financial data from covered financial institutions in a secure, electronic, machine-readable format and to transfer that data to an authorized representative of their choosing. Covered data includes transaction history, balances, payment initiation information, account terms, upcoming bill information, and account/identity verification information, generally for at least the prior 24 months.
The bill also requires financial institutions to maintain a developer interface, such as a standardized API, to receive and respond to data access requests, and it bars institutions from unreasonably denying or impairing access. It prohibits financial institutions from charging fees for providing this data or for maintaining the interface, while allowing certain data to remain exempt, including proprietary algorithms, fraud- and anti-money-laundering-related information, legally confidential information, and data not retrievable in the ordinary course of business. The bill imposes obligations on authorized representatives to obtain express informed consent, provide revocation mechanisms, limit data use and retention, and maintain security programs consistent with federal standards.
If enacted, the bill would amend the Banking Law by adding article 14-C and would be enforced by the superintendent of financial services. Violations, including improper fees or unlawful restrictions on access, could result in civil penalties of up to $10,000 per violation. The act would take effect 60 days after becoming law.
The bill would significantly expand consumer and small business data portability rights under New York banking law by requiring financial institutions to furnish covered financial data on request and to support standardized electronic access mechanisms. It would apply to New York banking organizations, certain out-of-state banks serving New York residents, custodians of financial assets, and other regulated data providers, thereby affecting a broad range of institutions and third-party data access arrangements. It also creates new compliance, security, authentication, and enforcement obligations, while limiting what data must be disclosed and preserving exemptions for sensitive or proprietary information.
The available record shows no committee transcript or vote history, so there is no documented floor or committee sentiment to assess. Based on the bill text alone, the measure appears pro-consumer and pro-small-business, aimed at improving access, portability, and competition in financial services. Its structure suggests support for open banking principles, while also attempting to address privacy and security concerns through consent, authentication, and security requirements.
The main points of potential contention are likely to be the scope of mandatory data sharing, the requirement that institutions build and maintain API-based access systems, and the prohibition on fees for data access. Financial institutions may object to compliance costs, operational burdens, and the risk that broad access requirements could create security or liability concerns. By contrast, consumer and small business advocates would likely support the bill’s portability rights and fee ban, while privacy and security concerns are addressed in the bill through exemptions, consent rules, and data-use limitations for authorized representatives.