State Breach Law

New York Data Breach Notification Law

N.Y. Gen. Bus. Law § 899-aa, § 899-bb • Effective 2005-12-07

If you have data on New York residents, you must notify them "in the most expedient time possible" after a breach. The SHIELD Act also requires you to have a security program protecting their data - this applies even if your business isn't based in NY. Fines can reach $5,000 per violation.

Notification deadline: Most expedient time possible

Enforcement: New York Attorney General

Overview

The New York SHIELD Act (Stop Hacks and Improve Electronic Data Security) significantly expanded breach notification requirements and added mandatory security program requirements for businesses handling New York residents' private information.

Who Must Be Notified

  • Affected New York residents
  • New York Attorney General
  • Department of State
  • State Police (if over 5,000 residents affected)

Covered Data Types

Social Security number, Driver's license number, Financial account number with access code, Credit/debit card number with security code, Biometric information, Username with password or security questions, HIPAA-covered health information

Notification Requirements

  • Timing: Most expedient time possible
  • Content must include: description of incident, types of data exposed, contact information
  • Offer identity theft protection services for SSN breaches
  • Submit copy of notification to AG, State Police (if 5,000+ affected)
  • Alternative notice (media) allowed if cost exceeds $250,000 or 500,000+ affected

Is your business exposed?

Exemptions

  • Encrypted data (if key not compromised)
  • Publicly available information
  • Information subject to GLBA, HIPAA (but notification still required)

Penalties

Civil penalties up to $5,000 per violation or $20 per failed notification (up to $250,000). Additional penalties for knowing/reckless violations.

If You Experience a Breach

  1. 1.

    Implement a "reasonable" security program as required by SHIELD Act

  2. 2.

    Conduct risk assessment for NY resident data

  3. 3.

    Designate employee(s) to coordinate security program

  4. 4.

    Know how to contact NY AG office for breach reporting

    NY AG Data Security Portal

  5. 5.

    Review vendor contracts for security requirements

  6. 6.

    Prepare breach response plan and notification templates

Official Source

https://ag.ny.gov/internet/data-breach

Other State Breach Laws

New York, Texas, Florida

Is your business exposed?

Check if your company data is circulating on the dark web

Free scan • No credit card required