New York Will Consider Increasing Data Security Laws

Nossaman LLP
Contact

New York’s Attorney General, Eric T. Schneiderman, plans to propose new data security legislation this year which, if enacted, could result in New York having one of the strongest data breach laws in the country. 

The proposed legislation would bolster New York’s existing Information Security Breach and Notification Act, found in Section 208 of the State Technology Law and Section 899-aa of the General Business Law.  Existing law requires companies to notify customers when “private information” is compromised but does not require companies to institute preventative data security measures.

The new legislation would expand upon New York’s definition of what constitutes protected “private information” to include email addresses and passwords, security questions, medical history, health insurance information, and other categories of data.  The current definition is limited to social security numbers, driver’s license numbers and identification card numbers, and account numbers and credit or debit card numbers with any required passcode.  The bill would also require companies to institute more comprehensive data security protections, including stronger physical and technical measures and tougher administrative safeguards focused on minimizing internal risks.  As a carrot to encourage companies to comply with the legislation, the proposed bill would provide a safe harbor to companies that meet data security standards and receive required certifications.  

More information on the Attorney General’s proposal is available on the New York Attorney General’s website.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Nossaman LLP | Attorney Advertising

Written by:

Nossaman LLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Nossaman LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide