Bill

Bill > A00913


NY A00913

NY A00913
Relates to when and how notification of a data breach is to be provided to the department of financial services.


summary

Introduced
01/08/2025
In Committee
01/22/2025
Crossed Over
Passed
Dead

Introduced Session

2025-2026 General Assembly

Bill Summary

AN ACT to amend the general business law, in relation to when and how notification of a data breach is to be provided to the department of financial services

AI Summary

This bill amends the New York general business law to clarify the requirements for notifying state authorities about data breaches. Specifically, the bill modifies the existing notification process by specifying that notice to the Department of Financial Services (DFS) is only required for "covered entities" as defined in the DFS cybersecurity regulation (23 NYCRR 500.1). When a data breach occurs affecting New York residents, the organization must still notify multiple state agencies including the attorney general, department of state, and state police about the timing, content, and distribution of breach notifications, as well as provide an approximate number of affected individuals. However, the notice to DFS must now be submitted in strict compliance with 23 NYCRR 500.17, which contains specific technical requirements for cybersecurity incident reporting. Importantly, these additional notification requirements cannot delay the primary notification to affected New York residents. The bill is set to take effect simultaneously with a related legislative package concerning data breach notifications.

Committee Categories

Business and Industry, Housing and Urban Affairs

Sponsors (2)

Last Action

Companion passed 2025-02-14 (on 02/14/2025)

bill text


bill summary

Loading...

bill summary

Loading...
Loading...