New York Privacy Law
New York has no comprehensive consumer privacy statute and nonetheless regulates data more heavily than most states that do. Three separate regimes stack on the same business: General Business Law § 899-bb imposes an affirmative security duty on anyone holding a New York resident’s private information; § 899-aa runs a fixed thirty-day breach clock and routes notice to four state bodies rather than one; and 23 NYCRR Part 500 puts anyone licensed under the Banking, Insurance or Financial Services Law on a seventy-two-hour incident clock with a signed annual filing. The Attorney General’s office has turned that structure into the most active state privacy enforcement practice outside California, and it has done so on ordinary security failures rather than novel legal theories.
Sector-Specific Privacy Laws in New York
SHIELD Act data-security duty (N.Y. Gen. Bus. Law § 899-bb)
Section 899-bb reaches any person or business that owns or licenses computerized data including the private information of a New York resident, whether or not it does business in New York, and requires reasonable administrative, technical and physical safeguards. The section spells out what those look like rather than leaving them at large: administratively, designating one or more employees to coordinate the program, identifying reasonably foreseeable internal and external risks, assessing the sufficiency of existing safeguards, training and managing employees in the program’s practices, selecting service providers capable of maintaining safeguards and requiring those safeguards by contract, and adjusting the program for business changes. Technically, assessing risks in network and software design and in information processing, transmission and storage, detecting and responding to attacks, and regularly testing and monitoring key controls. Physically, assessing storage and disposal risks, detecting and preventing intrusions, protecting against unauthorized access during collection, transportation and destruction, and erasing electronic media so information cannot be read. A “small business” — fewer than fifty employees, or under $3 million in gross annual revenue in each of the last three fiscal years, or under $5 million in year-end total assets — satisfies the section with safeguards appropriate to its size and the sensitivity of what it holds. An entity already subject to and compliant with the Gramm-Leach-Bliley Act, HIPAA or 23 NYCRR Part 500 is deemed compliant. The section states expressly that nothing in it creates a private right of action; the Attorney General enforces it through the injunction and civil-penalty machinery of § 350-d.
DFS Cybersecurity Regulation (23 NYCRR Part 500)
Part 500 applies to any individual or organization operating under, or required to operate under, a licence, registration, charter, certificate, permit, accreditation or similar authorisation under the Banking Law, the Insurance Law or the Financial Services Law — a population that includes insurance producers and mortgage servicers, not only banks. The November 2023 second amendment rewrote its core obligations. Section 500.17(a) requires electronic notice to the Superintendent as promptly as possible and in no event later than seventy-two hours after determining that a cybersecurity incident has occurred at the covered entity, an affiliate, or a third-party service provider, with a continuing duty to update the Superintendent as material information emerges. Section 500.17(c) adds a separate extortion-payment track: notice of the payment within twenty-four hours, and within thirty days a written description of why payment was necessary, the alternatives considered, and the diligence performed to comply with Office of Foreign Assets Control rules. Section 500.17(b) requires an annual April 15 filing signed by the entity’s highest-ranking executive and its chief information security officer, which is either a certification of material compliance or a written acknowledgment identifying every section not complied with and giving a remediation timeline. Section 500.12 now requires multi-factor authentication for any individual accessing any information system, narrowing to remote access, cloud third-party applications and privileged accounts only for entities inside the § 500.19(a) limited exemption — fewer than twenty employees and independent contractors, under $7.5 million in gross annual revenue in each of the last three fiscal years, or under $15 million in year-end total assets.
Child Data Protection Act (N.Y. Gen. Bus. Law art. 39-FF)
Article 39-FF regulates operators of websites, online services, applications and connected devices by reference to who is using them rather than to the operator’s size. A “covered user” is a user in New York the operator actually knows to be a minor, or any user of a platform primarily directed to minors. Processing a covered user’s personal data is barred unless the user is twelve or younger and the processing is COPPA-compliant, or the user is thirteen or older and the processing is strictly necessary for an enumerated purpose or carries informed consent. The Act’s definition of informed consent is unusually specific about the mechanics: it must be obtained separately from any other transaction, free of any mechanism whose purpose or substantial effect is to obscure, subvert or impair decision-making, accompanied by a clear statement that the processing is not strictly necessary, and presented with refusal as the most prominent option. Consent must be freely revocable at any time and at least as easy to revoke as to give. Separately, the Act bars an operator, its processor or a third-party operator from purchasing or selling a covered user’s personal data at all.
Deceptive acts and false advertising (N.Y. Gen. Bus. Law §§ 349, 350-d)
Article 22-A is New York’s unfair-practices statute and the enforcement engine behind the SHIELD Act. Section 350-d sets a civil penalty of not more than $5,000 for each violation, accruing to the State of New York and recoverable in a civil action brought by the Attorney General, rising to not more than $15,000 per violation or three times the actual restitution needed, whichever is greater, for violations connected to an abnormal market disruption. Section 899-bb(2)(c) makes a failure of the data-security duty enforceable under § 350-d, which is why the office’s security settlements are pleaded as deceptive-practice cases rather than under a standalone security penalty.
Data Breach Notification in New York
General Business Law § 899-aa separates “personal information” from “private information” and only the latter triggers the statute. Personal information is any information concerning a natural person which, because of name, number, personal mark or other identifier, can be used to identify that person. Private information is that information in combination with a Social Security number, a driver’s licence or non-driver identification number, an account, credit-card or debit-card number together with any required security code, a card number usable without additional authentication, biometric information meaning data generated by electronic measurements of physical characteristics, medical information meaning any information regarding an individual’s medical history, condition or treatment, or health-insurance information meaning a policy or subscriber number. It separately reaches a user name or e-mail address in combination with a password or security question and answer permitting access to an online account, with no name required at all. The triggering event is unauthorized access to or acquisition of computerized data that compromises the security, confidentiality or integrity of private information — access alone suffices, which is broader than the acquisition standard most states use. Notice to affected residents must be made without unreasonable delay and, since the 2024 amendment, within thirty days after the breach has been discovered. Notice runs to three state bodies for every breach regardless of headcount — the Attorney General, the Department of State and the Division of State Police — with the Department of Financial Services added for entities it licenses. Substitute notice becomes available where the cost of direct notice would exceed $250,000 or the affected class exceeds 500,000 persons. Subdivision 6 sets the penalty for a knowing or reckless notification failure at the greater of $5,000 or up to $20 per instance of failed notification, with the per-instance figure capped at $250,000.
Residents must be notified within thirty days after discovery of the breach, and without unreasonable delay. Notify the Attorney General, the Department of State and the Division of State Police for any breach of a New York resident’s private information, with no numeric threshold; the Department of Financial Services is added where applicable. Complaints are taken by the New York Attorney General, which enforces the statute.
How New York Enforces Its Privacy Laws
Security failures are prosecuted as deceptive practices. Section 899-bb(2)(c) makes a violation of the data-security duty enforceable under § 350-d, so the Attorney General’s security cases are brought under article 22-A rather than under a standalone data-security penalty. Section 350-d sets the civil penalty at not more than $5,000 for each violation, accruing to the State of New York, in a civil action brought by the Attorney General. The notification duty in § 899-aa carries its own separate penalty at subdivision 6, applicable where the failure to notify was knowing or reckless: the greater of $5,000 or up to $20 per instance of failed notification, with the per-instance total capped at $250,000.
A single act or omission violates Part 500. Section 500.20 provides that Part 500 is enforced by the Superintendent under, and not in limitation of, the Superintendent’s authority under any applicable law, and that the commission of a single act prohibited by the Part, or a single failure to act on an obligation it imposes, constitutes a violation. That framing matters for scale: an entity that has not deployed multi-factor authentication across its information systems is not committing one violation of § 500.12 but is exposed on each obligation it has not met.
Recent Enforcement in New York
23andMe genetic data — $18 million multistate settlement, $705,000 to New York. On July 14, 2026 the Attorney General announced a settlement with the bankruptcy trustee of 23andMe, joined by a bipartisan coalition of forty-three attorneys general, over the October 2023 breach that affected 6.9 million consumers including 305,245 New Yorkers. New York’s share of the $18 million recovered was more than $705,000. The office identified the failure as an absence of safeguards against cyber-attacks using stolen credentials — the release names comparing passwords against blocklists of known breached passwords and requiring multifactor authentication as protections the company did not implement. Beyond the payment, the settlement requires TTAM Research, which reregistered as the 23andMe Research Institute, to perform appropriate risk analysis, to add an advisory board on data security, and to continue offering consumers the right to delete their information.
Eight auto insurers — $14.2 million over pre-filled driver’s licence numbers. On October 14, 2025 the Attorney General announced $14.2 million from eight car insurance companies over the exposure of more than 825,000 New Yorkers’ information: American Family Mutual and Midvale Indemnity, $2.8 million; Infinity Insurance, Liberty Mutual, Metromile and State Auto, $2 million each; Farmers Insurance and Hagerty Insurance Agency, $1.3 million each; and The Hartford Insurance Group, $815,000. The vector was the same in each case and is specific to the industry: online quoting tools carried a pre-fill function that took a name and date of birth and populated the remaining fields from data purchased from brokers, including driver’s licence numbers and household member details, which attackers then harvested. The settlements require comprehensive security programs, data inventories with protections attached, reasonable authentication procedures, logging and monitoring with alerts for suspicious activity, and enhanced threat-response procedures. The office states the running total from auto insurers on this fact pattern is $20.79 million from ten companies.
OrthopedicsNY — $500,000 over unencrypted patient files. On December 26, 2025 the Attorney General secured $500,000 in penalties from OrthopedicsNY, LLP, a Capital Region orthopaedic practice, after attackers used compromised login credentials to obtain remote access and downloaded unencrypted files. Approximately 656,000 patients and employees were affected, of whom roughly 110,000 had Social Security numbers, driver’s licence numbers or passport numbers exposed. The office found the practice had not used multifactor authentication for remote access, had not encrypted sensitive patient data, and had not conducted regular risk assessments. The settlement requires a comprehensive information security program, policies limiting data access, multifactor authentication for remote network access, encryption of collected and stored patient and employee data, network monitoring for suspicious activity, annual risk assessments, and one year of funded credit monitoring for those affected.
Pending Privacy Legislation
New York’s privacy output is concentrated in children’s and financial regulation rather than in a comprehensive statute. The New York Privacy Act is pending as S3044, referred to the Senate Internet and Technology Committee on January 7, 2026, and a second vehicle, S8524, was introduced on October 8, 2025 and committed to Rules; neither has passed either chamber. What has moved is the Stop Addictive Feeds Exploitation (SAFE) for Kids Act, whose final implementing rules the Attorney General and Governor released on July 28, 2026 for State Register publication the following day, giving the Act an effective date of January 25, 2027 — 180 days out. The Child Data Protection Act at article 39-FF of the General Business Law is already in force and bars the sale of a covered user’s personal data outright.
Federal Privacy Laws That Apply in New York
Federal privacy law applies in New York by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.
The state-law counterpart to section 5 is the Deceptive acts and false advertising (N.Y. Gen. Bus. Law §§ 349, 350-d), which the New York Attorney General enforces against businesses whose stated data practices differ from their actual ones.
Industry Rules That Reach New York Businesses
With no comprehensive state statute, most privacy obligations on a New York business arrive through its industry: healthcare, financial services, online services, retail, employment and education. Each is covered in its own guide.
Two of those reach New York businesses regardless of industry. A company serving residents of states that have enacted comprehensive laws can owe duties under those laws while New York itself has none, and any business holding personal information about New York residents is subject to the state’s breach-notification statute described above.
New York Privacy Law FAQ
What is the deadline for notifying New York residents after a breach?
Which New York agencies receive breach notice, and is there a headcount threshold?
Does the SHIELD Act create a private right of action?
What counts as a “small business” under the SHIELD Act?
Who is covered by the DFS cybersecurity regulation, and what does it require by April 15?
Does New York require notice when a ransom is paid?
When does the SAFE for Kids Act take effect and what does it restrict?
Is a comprehensive New York privacy law close to passing?
Sources
This guide describes what these documents say. Follow them to check the description against the source.
- N.Y. Gen. Bus. Law § 899-aa — Notification; person without valid authorization has acquired private information statute
- N.Y. Gen. Bus. Law § 899-bb — Data security protections (SHIELD Act) statute
- N.Y. Gen. Bus. Law § 350-d — Civil penalty statute
- N.Y. Gen. Bus. Law § 899-ee — Child Data Protection Act definitions statute
- N.Y. Gen. Bus. Law § 899-ff — Child Data Protection Act; processing and consent statute
- 23 NYCRR Part 500 — Cybersecurity Requirements for Financial Services Companies, second amendment text regulation
- New York Senate Bill S3044 (2025-2026) — New York Privacy Act legislation
- N.Y. Attorney General — 23andMe multistate settlement over genetic data agency
- N.Y. Attorney General — $14.2 million from car insurance companies over data breaches agency
- N.Y. Attorney General — $500,000 from Capital Region health care provider agency
- N.Y. Attorney General and Governor — final SAFE for Kids Act rules agency
- N.Y. Attorney General — report a data breach agency guidance
- 45 CFR Part 164 — HIPAA Privacy and Security Rules regulation
- 15 U.S.C. 6801 — Gramm-Leach-Bliley Act statute
- 20 U.S.C. 1232g — Family Educational Rights and Privacy Act statute
- 15 U.S.C. 1681 — Fair Credit Reporting Act statute
- 16 CFR Part 312 — Children’s Online Privacy Protection Rule regulation
- Section 5 of the FTC Act, 15 U.S.C. 45 statute
Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.