Relates to social media open application programming; requires social media platforms to implement and maintain a standards-based application programming interface that permits third-party applications to retrieve data at no cost to be used for the user's benefit and to provide certain information to users; requires social media companies to submit a report to the attorney general.
S10416 would add a new article to the General Business Law requiring certain social media platforms to provide open, standards-based API access for third-party applications acting on behalf of users or their authorized representatives. Covered platforms would have to allow third parties to retrieve a broad set of user-related data at no cost, including profile information, follower/following data, recommendations, settings, notifications, and other platform-produced or user-generated content available to the user. The bill also requires platforms to support write/update actions through the API for user data and safety or preference controls such as blocking, muting, reporting, hiding comments, and accepting requests.
The bill further imposes technical and transparency obligations. Platforms must test and maintain the API, provide status dashboards, support pagination and other data retrieval functions, publish detailed developer documentation, and may deny access only under objective, consistently applied security criteria. Social media companies would also have to file semiannual API access reports with the Attorney General describing API features, changes, access decisions, and denials, and those reports would be made publicly available in a searchable online repository. Enforcement would be limited to actions by the Attorney General or a city corporation counsel, with injunctive relief available for violations.
If enacted, the bill would create a new regulatory framework in New York governing large social media companies and their interfaces with third-party tools. It would require qualifying platforms to expose user data and certain platform functions through open APIs, likely affecting product design, data governance, security practices, and developer access policies. The bill would also add new reporting duties to the Attorney General and authorize state or local enforcement actions for noncompliance. It expressly excludes platforms with less than $100 million in annual gross revenue and services limited to direct messaging, commercial transactions, or consumer reviews.
Based on the bill text and the absence of recorded committee debate or votes in the provided materials, the overall sentiment appears to be policy-driven and reform-oriented rather than partisan or procedurally contentious in the available record. The measure is framed as a consumer-access and interoperability bill, emphasizing user control, transparency, and third-party development access. No formal vote history or transcript comments are provided, so there is no documented opposition or support to assess beyond the bill’s structure and stated requirements.
The main points of contention likely involve the scope of required data access, the burden on platforms to maintain open APIs, and the privacy and security implications of allowing third-party applications to retrieve and act on user data. Social media companies may object to mandatory access at no cost, the breadth of covered data, and the reporting obligations, while supporters would likely argue that users should be able to move, manage, and use their data through interoperable tools. Another likely issue is the bill’s security exception, which allows denial of access only under objective and consistent criteria, potentially limiting platform discretion over API access decisions.