New York

New York Privacy Law

New York has no comprehensive consumer privacy statute and nonetheless regulates data more heavily than most states that do. Three separate regimes stack on the same business: General Business Law § 899-bb imposes an affirmative security duty on anyone holding a New York resident’s private information; § 899-aa runs a fixed thirty-day breach clock and routes notice to four state bodies rather than one; and 23 NYCRR Part 500 puts anyone licensed under the Banking, Insurance or Financial Services Law on a seventy-two-hour incident clock with a signed annual filing. The Attorney General’s office has turned that structure into the most active state privacy enforcement practice outside California, and it has done so on ordinary security failures rather than novel legal theories.

Sector-Specific Privacy Laws in New York

SHIELD Act data-security duty (N.Y. Gen. Bus. Law § 899-bb)

Section 899-bb reaches any person or business that owns or licenses computerized data including the private information of a New York resident, whether or not it does business in New York, and requires reasonable administrative, technical and physical safeguards. The section spells out what those look like rather than leaving them at large: administratively, designating one or more employees to coordinate the program, identifying reasonably foreseeable internal and external risks, assessing the sufficiency of existing safeguards, training and managing employees in the program’s practices, selecting service providers capable of maintaining safeguards and requiring those safeguards by contract, and adjusting the program for business changes. Technically, assessing risks in network and software design and in information processing, transmission and storage, detecting and responding to attacks, and regularly testing and monitoring key controls. Physically, assessing storage and disposal risks, detecting and preventing intrusions, protecting against unauthorized access during collection, transportation and destruction, and erasing electronic media so information cannot be read. A “small business” — fewer than fifty employees, or under $3 million in gross annual revenue in each of the last three fiscal years, or under $5 million in year-end total assets — satisfies the section with safeguards appropriate to its size and the sensitivity of what it holds. An entity already subject to and compliant with the Gramm-Leach-Bliley Act, HIPAA or 23 NYCRR Part 500 is deemed compliant. The section states expressly that nothing in it creates a private right of action; the Attorney General enforces it through the injunction and civil-penalty machinery of § 350-d.

DFS Cybersecurity Regulation (23 NYCRR Part 500)

Part 500 applies to any individual or organization operating under, or required to operate under, a licence, registration, charter, certificate, permit, accreditation or similar authorisation under the Banking Law, the Insurance Law or the Financial Services Law — a population that includes insurance producers and mortgage servicers, not only banks. The November 2023 second amendment rewrote its core obligations. Section 500.17(a) requires electronic notice to the Superintendent as promptly as possible and in no event later than seventy-two hours after determining that a cybersecurity incident has occurred at the covered entity, an affiliate, or a third-party service provider, with a continuing duty to update the Superintendent as material information emerges. Section 500.17(c) adds a separate extortion-payment track: notice of the payment within twenty-four hours, and within thirty days a written description of why payment was necessary, the alternatives considered, and the diligence performed to comply with Office of Foreign Assets Control rules. Section 500.17(b) requires an annual April 15 filing signed by the entity’s highest-ranking executive and its chief information security officer, which is either a certification of material compliance or a written acknowledgment identifying every section not complied with and giving a remediation timeline. Section 500.12 now requires multi-factor authentication for any individual accessing any information system, narrowing to remote access, cloud third-party applications and privileged accounts only for entities inside the § 500.19(a) limited exemption — fewer than twenty employees and independent contractors, under $7.5 million in gross annual revenue in each of the last three fiscal years, or under $15 million in year-end total assets.

Child Data Protection Act (N.Y. Gen. Bus. Law art. 39-FF)

Article 39-FF regulates operators of websites, online services, applications and connected devices by reference to who is using them rather than to the operator’s size. A “covered user” is a user in New York the operator actually knows to be a minor, or any user of a platform primarily directed to minors. Processing a covered user’s personal data is barred unless the user is twelve or younger and the processing is COPPA-compliant, or the user is thirteen or older and the processing is strictly necessary for an enumerated purpose or carries informed consent. The Act’s definition of informed consent is unusually specific about the mechanics: it must be obtained separately from any other transaction, free of any mechanism whose purpose or substantial effect is to obscure, subvert or impair decision-making, accompanied by a clear statement that the processing is not strictly necessary, and presented with refusal as the most prominent option. Consent must be freely revocable at any time and at least as easy to revoke as to give. Separately, the Act bars an operator, its processor or a third-party operator from purchasing or selling a covered user’s personal data at all.

Deceptive acts and false advertising (N.Y. Gen. Bus. Law §§ 349, 350-d)

Article 22-A is New York’s unfair-practices statute and the enforcement engine behind the SHIELD Act. Section 350-d sets a civil penalty of not more than $5,000 for each violation, accruing to the State of New York and recoverable in a civil action brought by the Attorney General, rising to not more than $15,000 per violation or three times the actual restitution needed, whichever is greater, for violations connected to an abnormal market disruption. Section 899-bb(2)(c) makes a failure of the data-security duty enforceable under § 350-d, which is why the office’s security settlements are pleaded as deceptive-practice cases rather than under a standalone security penalty.

Data Breach Notification in New York

General Business Law § 899-aa separates “personal information” from “private information” and only the latter triggers the statute. Personal information is any information concerning a natural person which, because of name, number, personal mark or other identifier, can be used to identify that person. Private information is that information in combination with a Social Security number, a driver’s licence or non-driver identification number, an account, credit-card or debit-card number together with any required security code, a card number usable without additional authentication, biometric information meaning data generated by electronic measurements of physical characteristics, medical information meaning any information regarding an individual’s medical history, condition or treatment, or health-insurance information meaning a policy or subscriber number. It separately reaches a user name or e-mail address in combination with a password or security question and answer permitting access to an online account, with no name required at all. The triggering event is unauthorized access to or acquisition of computerized data that compromises the security, confidentiality or integrity of private information — access alone suffices, which is broader than the acquisition standard most states use. Notice to affected residents must be made without unreasonable delay and, since the 2024 amendment, within thirty days after the breach has been discovered. Notice runs to three state bodies for every breach regardless of headcount — the Attorney General, the Department of State and the Division of State Police — with the Department of Financial Services added for entities it licenses. Substitute notice becomes available where the cost of direct notice would exceed $250,000 or the affected class exceeds 500,000 persons. Subdivision 6 sets the penalty for a knowing or reckless notification failure at the greater of $5,000 or up to $20 per instance of failed notification, with the per-instance figure capped at $250,000.

Residents must be notified within thirty days after discovery of the breach, and without unreasonable delay. Notify the Attorney General, the Department of State and the Division of State Police for any breach of a New York resident’s private information, with no numeric threshold; the Department of Financial Services is added where applicable. Complaints are taken by the New York Attorney General, which enforces the statute.

How New York Enforces Its Privacy Laws

Security failures are prosecuted as deceptive practices. Section 899-bb(2)(c) makes a violation of the data-security duty enforceable under § 350-d, so the Attorney General’s security cases are brought under article 22-A rather than under a standalone data-security penalty. Section 350-d sets the civil penalty at not more than $5,000 for each violation, accruing to the State of New York, in a civil action brought by the Attorney General. The notification duty in § 899-aa carries its own separate penalty at subdivision 6, applicable where the failure to notify was knowing or reckless: the greater of $5,000 or up to $20 per instance of failed notification, with the per-instance total capped at $250,000.

A single act or omission violates Part 500. Section 500.20 provides that Part 500 is enforced by the Superintendent under, and not in limitation of, the Superintendent’s authority under any applicable law, and that the commission of a single act prohibited by the Part, or a single failure to act on an obligation it imposes, constitutes a violation. That framing matters for scale: an entity that has not deployed multi-factor authentication across its information systems is not committing one violation of § 500.12 but is exposed on each obligation it has not met.

Recent Enforcement in New York

23andMe genetic data — $18 million multistate settlement, $705,000 to New York. On July 14, 2026 the Attorney General announced a settlement with the bankruptcy trustee of 23andMe, joined by a bipartisan coalition of forty-three attorneys general, over the October 2023 breach that affected 6.9 million consumers including 305,245 New Yorkers. New York’s share of the $18 million recovered was more than $705,000. The office identified the failure as an absence of safeguards against cyber-attacks using stolen credentials — the release names comparing passwords against blocklists of known breached passwords and requiring multifactor authentication as protections the company did not implement. Beyond the payment, the settlement requires TTAM Research, which reregistered as the 23andMe Research Institute, to perform appropriate risk analysis, to add an advisory board on data security, and to continue offering consumers the right to delete their information.

Eight auto insurers — $14.2 million over pre-filled driver’s licence numbers. On October 14, 2025 the Attorney General announced $14.2 million from eight car insurance companies over the exposure of more than 825,000 New Yorkers’ information: American Family Mutual and Midvale Indemnity, $2.8 million; Infinity Insurance, Liberty Mutual, Metromile and State Auto, $2 million each; Farmers Insurance and Hagerty Insurance Agency, $1.3 million each; and The Hartford Insurance Group, $815,000. The vector was the same in each case and is specific to the industry: online quoting tools carried a pre-fill function that took a name and date of birth and populated the remaining fields from data purchased from brokers, including driver’s licence numbers and household member details, which attackers then harvested. The settlements require comprehensive security programs, data inventories with protections attached, reasonable authentication procedures, logging and monitoring with alerts for suspicious activity, and enhanced threat-response procedures. The office states the running total from auto insurers on this fact pattern is $20.79 million from ten companies.

OrthopedicsNY — $500,000 over unencrypted patient files. On December 26, 2025 the Attorney General secured $500,000 in penalties from OrthopedicsNY, LLP, a Capital Region orthopaedic practice, after attackers used compromised login credentials to obtain remote access and downloaded unencrypted files. Approximately 656,000 patients and employees were affected, of whom roughly 110,000 had Social Security numbers, driver’s licence numbers or passport numbers exposed. The office found the practice had not used multifactor authentication for remote access, had not encrypted sensitive patient data, and had not conducted regular risk assessments. The settlement requires a comprehensive information security program, policies limiting data access, multifactor authentication for remote network access, encryption of collected and stored patient and employee data, network monitoring for suspicious activity, annual risk assessments, and one year of funded credit monitoring for those affected.

Pending Privacy Legislation

New York’s privacy output is concentrated in children’s and financial regulation rather than in a comprehensive statute. The New York Privacy Act is pending as S3044, referred to the Senate Internet and Technology Committee on January 7, 2026, and a second vehicle, S8524, was introduced on October 8, 2025 and committed to Rules; neither has passed either chamber. What has moved is the Stop Addictive Feeds Exploitation (SAFE) for Kids Act, whose final implementing rules the Attorney General and Governor released on July 28, 2026 for State Register publication the following day, giving the Act an effective date of January 25, 2027 — 180 days out. The Child Data Protection Act at article 39-FF of the General Business Law is already in force and bars the sale of a covered user’s personal data outright.

Federal Privacy Laws That Apply in New York

Federal privacy law applies in New York by sector, whatever the state has enacted: HIPAA to health information, the Gramm-Leach-Bliley Act to financial institutions, FERPA to student education records, the Fair Credit Reporting Act to consumer reports, COPPA to children under 13, and Section 5 of the FTC Act to privacy claims that do not match practice.

The state-law counterpart to section 5 is the Deceptive acts and false advertising (N.Y. Gen. Bus. Law §§ 349, 350-d), which the New York Attorney General enforces against businesses whose stated data practices differ from their actual ones.

Industry Rules That Reach New York Businesses

With no comprehensive state statute, most privacy obligations on a New York business arrive through its industry: healthcare, financial services, online services, retail, employment and education. Each is covered in its own guide.

Two of those reach New York businesses regardless of industry. A company serving residents of states that have enacted comprehensive laws can owe duties under those laws while New York itself has none, and any business holding personal information about New York residents is subject to the state’s breach-notification statute described above.

New York Privacy Law FAQ

What is the deadline for notifying New York residents after a breach?
Thirty days. General Business Law § 899-aa requires notice without unreasonable delay and provides that it “shall be made within thirty days after the breach has been discovered”. The clock runs from discovery, not from the completion of an investigation, and the amendment that added the fixed thirty-day figure took effect on December 21, 2024. Delay is permitted where a law enforcement agency determines that notice would impede a criminal investigation.
Which New York agencies receive breach notice, and is there a headcount threshold?
Three, and no. Section 899-aa routes notice to the Attorney General, the Department of State and the Division of State Police for any breach of a New York resident’s private information, with no minimum number of affected residents — unlike the 250-, 500- or 1,000-resident thresholds most states use. Entities licensed by the Department of Financial Services notify that department as well, and covered entities under 23 NYCRR Part 500 have a separate seventy-two-hour duty to the Superintendent that runs independently of the § 899-aa clock.
Does the SHIELD Act create a private right of action?
No. Section 899-bb states that nothing in the section creates a private right of action, and the Attorney General enforces the data-security duty through the injunction and civil-penalty provisions of § 350-d, which set a penalty of not more than $5,000 for each violation. The separate notification provision at § 899-aa(6) carries its own penalty for a knowing or reckless failure — the greater of $5,000 or up to $20 per failed notification instance, capped at $250,000.
What counts as a “small business” under the SHIELD Act?
Section 899-bb defines it by three alternative measures, any one of which qualifies: fewer than fifty employees; less than $3 million in gross annual revenue in each of the last three fiscal years; or less than $5 million in year-end total assets calculated under generally accepted accounting principles. A small business is not exempt from the security duty; the statute states that its safeguards are appropriate where they suit the size and complexity of the business, the nature and scope of its activities, and the sensitivity of the personal information it collects.
Who is covered by the DFS cybersecurity regulation, and what does it require by April 15?
23 NYCRR Part 500 covers any person or organisation operating under, or required to operate under, a licence, registration, charter, certificate, permit, accreditation or similar authorisation under the Banking Law, the Insurance Law or the Financial Services Law. Section 500.17(b) requires an electronic filing with the Superintendent each April 15, signed by the entity’s highest-ranking executive and its chief information security officer. It is either a certification that the entity materially complied with Part 500 during the prior calendar year, based on documentation sufficient to demonstrate that compliance, or a written acknowledgment identifying every section not materially complied with, describing the nature and extent of the non-compliance, and providing a remediation timeline.
Does New York require notice when a ransom is paid?
For entities covered by Part 500, yes, on a separate and shorter clock than the incident notice itself. Section 500.17(c) requires electronic notice to the Superintendent within twenty-four hours of an extortion payment made in connection with a cybersecurity event, and within thirty days a written description of the reasons payment was necessary, the alternatives to payment considered, the diligence performed to find those alternatives, and the diligence performed to ensure compliance with applicable rules including those of the Office of Foreign Assets Control.
When does the SAFE for Kids Act take effect and what does it restrict?
The Attorney General and Governor released the final rules on July 28, 2026; they were set for publication in the State Register on July 29, 2026, and the Act takes effect 180 days later, on January 25, 2027. The Act restricts algorithmically personalised feeds for users under eighteen without parental consent and bars notifications to those users between 12 a.m. and 6 a.m. without consent. The rules define an “Addictive Online Platform” as one displaying user-generated content whose users spend at least twenty percent of their time on its addictive feeds, and require age-assurance methods that meet accuracy benchmarks, offer at least one alternative to government identification, and delete the data used for age or consent verification immediately after use. The Act authorises civil penalties of up to $5,000 per violation.
Is a comprehensive New York privacy law close to passing?
Not on the current record. The New York Privacy Act, sponsored by Senator Kristen Gonzalez, carries bill number S3044 in the 2025-2026 session and was referred to the Senate Internet and Technology Committee on January 7, 2026. It would create rights of notice, access, correction, deletion and portability, an opt-out of targeted advertising, sale and profiling, an opt-in consent requirement for sensitive data, controller duties to conduct data-protection assessments and limit retention, annual data-broker registration with the Attorney General, and enforcement resting exclusively with the Attorney General with no private right of action. A separate bill, S8524, the New York data protection act, was introduced by Senator Gonzalez on October 8, 2025 and committed to the Committee on Rules.

Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.