New York

Who Is Covered?

Any person or business which owns or licenses computerized data which includes private information. N.Y. Gen. Bus. Law § 899-aa(2).

 

What Information Is Protected?

“Private information” means either:

A. Personal information consisting of any information in combination with any one or more of the following data elements, when either the data element or the combination of personal information plus the data element is not encrypted, or is encrypted with an encryption key that has also been accessed or acquired:

 

  1. Social security number;
  2. Driver’s license number or non-driver identification card number;
  3. Account number, credit or debit card number, in combination with any required security code, access code, password or other information that would permit access to an individual’s financial account;
  4. Account number, credit or debit card number, if circumstances exist wherein such number could be used to access an individual’s financial account without additional identifying information, security code, access code, or password; or
  5. Biometric information, meaning data generated by electronic measurements of an individual’s unique physical characteristics, such as a fingerprint, voice print, retina or iris image, or other unique physical representation or digital representation of biometric data which are used to authenticate or ascertain the individual’s identity; or

B. A user name or email address in combination with a password or security question and answer that would permit access to an online account. N.Y. Gen. Bus. Law § 899-aa(1)(b).

 

What Is A “Breach”?

“Breach of the security of the system” shall mean unauthorized access to or acquisition of, or access to or acquisition without valid authorization, of computerized data that compromises the security, confidentiality, or integrity of private information maintained by a business. 

In determining whether information has been accessed, or is reasonably believed to have been accessed, by an unauthorized person or a person without valid authorization, such business may consider, among other factors, indications that the information was viewed, communicated with, used, or altered by a person without valid authorization or by an unauthorized person. In determining whether information has been acquired, or is reasonably believed to have been acquired, by an unauthorized person or a person without valid authorization, such business may consider the following factors, among others:

 

  1. Indications that the information is in the physical possession and control of an unauthorized person, such as a lost or stolen computer or other device containing information; or
  2. Indications that the information has been downloaded or copied; or
  3. Indications that the information was used by an unauthorized person, such as fraudulent accounts opened or instances of identity theft reported. N.Y. Gen. Bus. Law § 899-aa(1)(c).

 

What Triggers Notification?

Discovery or notification of the breach in the security of the system involving the private information of any resident of New York state whose private information was, or is reasonably believed to have been, accessed or acquired by a person without valid authorization. N.Y. Gen. Bus. Law § 899-aa(2).

Likelihood of Harm Exception: Notice to affected persons is not required if the exposure of private information was an inadvertent disclosure by persons authorized to access private information, and the person or business reasonably determines such exposure will not likely result in misuse of such information, or financial harm to the affected persons or emotional harm in the case of unknown disclosure of online credentials. N.Y. Gen. Bus. Law § 899-aa(2)(a).

 

How Is Notice Provided To Individuals?

Timing: In the most expedient time possible and without unreasonable delay, provided that such notification is made within 30 days after the breach is discovered, except for the legitimate needs of law enforcement. N.Y. Gen. Bus. Law § 899-aa(2).

Delivery: Notice may be provided by:

 

  1. Written notice;
  2. Electronic notice, provided that the person to whom notice is required has expressly consented to receiving said notice in electronic form and a log of each such notification is kept by the person or business who notifies affected persons in such form; provided further, however, that in no case shall any person or business require a person to consent to accepting said notice in said form as a condition of establishing any business relationship or engaging in any transaction.
  3. Telephone notification provided that a log of each such notification is kept by the person or business who notifies affected persons; or
  4. Substitute notice, if a business demonstrates to the state attorney general that the cost of providing notice would exceed two hundred fifty thousand dollars, or that the affected class of subject persons to be notified exceeds five hundred thousand, or such business does not have sufficient contact information. Substitute notice shall consist of all of the following: (a) email notice when such business has an email address for the subject persons, except if the breached information includes an email address in combination with a password or security question and answer that would permit access to the online account, in which case the person or business shall instead provide clear and conspicuous notice delivered to the consumer online when the consumer is connected to the online account from an internet protocol address or from an online location which the person or business knows the consumer customarily uses to access the online account; (b) conspicuous posting of the notice on such business’s website page, if such business maintains one; and (c) notification to major statewide media. N.Y. Gen. Bus. Law § 899-aa(5).

Content: Notice must include:

 

  1. Contact information for the person or business making the notification;
  2. The telephone numbers and websites of the relevant state and federal agencies that provide information regarding security breach response and identity theft prevention and protection information; and
  3. A description of the categories of information that were, or are reasonably believed to have been, accessed or acquired by a person without valid authorization, including specification of which of the elements of personal information and private information were, or are reasonably believed to have been, so accessed or acquired. N.Y. Gen. Bus. Law § 899-aa(7).

 

Is Notice To The Government Required?

Yes. In the event that any New York residents are to be notified, the person or business shall notify the state attorney general, the department of state and the division of state police, and the department of financial services as to the timing, content and distribution of the notices and approximate number of affected persons and shall provide a copy of the template of the notice sent to affected persons. Such notice shall be made without delaying notice to affected New York residents. However, notice to the department of financial services shall only be required if the person or business is a covered entity, as defined in 23 NYCRR 500l1. N.Y. Gen. Bus. Law § 899-aa(8)(a).

Additionally, any covered entity required to provide notification of a breach, including breach of information that is not “private information,” to the secretary of health and human services pursuant to HIPAA shall provide such notification to the state attorney general within five business days of notifying the secretary. N.Y. Gen. Bus. Law § 899-aa(9).

 

Is Notice To Credit Reporting Agencies Required?

Yes. In the event that more than five thousand New York residents are to be notified at one time, the person or business shall also notify consumer reporting agencies as to the timing, content and distribution of the notices and approximate number of affected persons. Such notice shall be made without delaying notice to affected New York residents. N.Y. Gen. Bus. Law § 899-aa(8)(b).

 

Are There Security Measure Standards?

Yes. Any person or business that owns or licenses computerized data which includes private information of a resident of New York must develop, implement and maintain reasonable safeguards to protect the security, confidentiality and integrity of the private information including, but not limited to, disposal of data. A person or business will be deemed to be in compliance with paragraph (a) of this subdivision if it is a compliant regulated entity [N.Y. Gen. Bus. Law § 899-bb(1)], or implements a data security program that includes:

A. Reasonable administrative safeguards such as the following, in which the person or business:

 

  1. Designates one or more employees to coordinate the security program;
  2. Identifies reasonably foreseeable internal and external risks;
  3. Assesses the sufficiency of safeguards in place to control the identified risks;
  4. Trains and manages employees in the security program practices and procedures;
  5. Selects service providers capable of maintaining appropriate safeguards, and requires those safeguards by contract; and
  6. Adjusts the security program in light of business changes or new circumstances; and

B. Reasonable technical safeguards such as the following, in which the person or business:

 

  1. Assesses risks in network and software design;
  2. Assesses risks in information processing, transmission and storage;
  3. Detects, prevents and responds to attacks or system failures; and
  4. Regularly tests and monitors the effectiveness of key controls, systems and procedures; and

C. Reasonable physical safeguards such as the following, in which the person or business:

 

  1. Assesses risks of information storage and disposal;
  2. Detects, prevents and responds to intrusions;
  3. Protects against unauthorized access to or use of private information during or after the collection, transportation and destruction or disposal of the information; and
  4. Disposes of private information within a reasonable amount of time after it is no longer needed for business purposes by erasing electronic media so that the information cannot be read or reconstructed. N.Y. Gen. Bus. Law § 899-bb(2).

 

What Are The Possible Consequences Of A Violation?

The attorney general may seek injunctive relief and damages for actual costs or losses incurred by a person entitled to notice if notification was not provided to such person, including consequential financial losses.

Additionally, if a court determines that a person or business violated the article knowingly or recklessly, the court may impose a civil penalty of the greater of $5,000 or up to $20 per instance of failed notification, provided that the latter amount shall not exceed $250,000. N.Y. Gen. Bus. Law § 899-aa(6)(a).

 

Are There Any Exemptions/Exceptions?

If notice of the breach of the security of the system is made to affected persons pursuant to the breach notification requirements under any of the following laws, nothing in this section shall require any additional notice to those affected persons, but notice still shall be provided to the state attorney general, the department of state and the division of state police and to consumer reporting agencies:

 

  1. Regulations promulgated pursuant to Title V of the federal Gramm-Leach-Bliley Act;
  2. Regulations implementing the Health Insurance Portability and Accountability Act and the Health Information Technology for Economic and Clinical Health Act;
  3. Part five hundred of title twenty-three of the official compilation of codes, rules and regulations of the state of New York; or
  4. Any other data security rules and regulations of, and the statutes administered by, any official department, division, commission or agency of the federal or New York state government as such rules, regulations or statutes are interpreted by such department, division, commission or agency or by the federal or New York state courts. N.Y. Gen. Bus. Law § 899-aa(2)(b).