Scarinci Hollenbeck, LLC
The Firm
201-896-4100 info@sh-law.comFirm Insights
Author: Scarinci Hollenbeck, LLC
Date: August 2, 2021
The Firm
201-896-4100 info@sh-law.comBiometric data privacy laws continue to grow at both the state and local level. New York City landlords are the latest to be impacted. Under the New York City Tenant Data Privacy Act (TDPA), owners of multi-family dwellings that utilize keyless entry systems, including but not limited to key fobs, biometric identifiers, and electronic technologies, must provide tenants with a data retention and privacy policy.
The TDPA will impact all owners/landlords of Class A multiple dwellings that use smart access systems. Under the TDPA, a “smart access” building is defined as one that uses keyless entry systems, including electronic or computerized technology, RFID cards, mobile apps, biometric information or other digital technology to grant access to the building, common areas, or individual dwelling units.
Restrictions on Data Collection and Use
The TDPA establishes restrictions on the collection and use of data collected from smart access systems. An owner of a smart access building or third party may not collect reference data from a user for use in a smart access system except where such user has expressly consented, in writing or through a mobile application, to the use of such smart access building’s smart access system. After obtaining consent, owners may collect only the minimum amount of authentication data and reference data necessary to enable the use of the smart access system, and may not collect additional biometric identifier information from any users.
The term “authentication data” means the data generated or collected at the point of authentication in connection with granting a user entry to a smart access building, common area or dwelling unit through the building’s smart access system. It does not include data generated through or collected by a video or camera system that is used to monitor entrances but not grant entry. Meanwhile, “reference data” is defined as the information against which authentication data is verified at the point of authentication by a smart access system in order to grant a user entry to a smart access building, dwelling unit of such building or a common area of such building.
The TDPA further provides that smart access system may only collect, generate or utilize the following information:
The TDPA also requires that any data collected be removed, anonymized, or destroyed within a given time, generally no later than 90 days after such data has been collected or generated, except for authentication data that is retained in an anonymized format.
The TDPA also provides that any information that an owner of a multiple dwelling collects about a tenant’s use of gas, electricity or any other utility must be limited to the tenant’s total monthly usage, unless otherwise required by law. The new law also makes it unlawful for an owner of a multiple dwelling to collect any information about a tenant’s use of internet service. When internet service is provided directly from an owner to tenants, the landlord may collect such information if it is aggregated and anonymized, or necessary for billing purposes.
The TDPA restricts the sharing of any data collected with third parties. It also makes it unlawful for an owner of a smart access building to: track the location of any user of a smart access system outside of the building; use a smart access system to deliberately collect information on or track the relationship status of tenants and their guests; utilize data collected through a smart access system for any purpose other than to grant access to and monitor entrances and exits to the smart access building, common areas, and dwelling units; use a smart access system to limit the time of entry into the building by any user except as requested by a tenant; require a tenant to use a smart access system to gain entry to such tenant’s dwelling unit; and use any information collected through a smart access system to harass or evict a tenant.
Privacy Policy Requirements
The owner of a smart access building must provide tenants with privacy policy, written in plain language, that describes, at a minimum, the following information:
Mandatory Security Safeguards
A smart access system must implement stringent security measures and safeguards to protect the security and data of tenants, guests and other individuals in smart access buildings. Under the TDPA, these security measures and safeguards must, at a minimum, include data encryption, the ability of the user to change the password if the system uses a password and firmware that is regularly updated to enable the remediation of any security or vulnerability issues.
Enforcement
The Tenant Data Privacy Act establishes a private right of action for the unlawful sale of data collected through a smart access system covered by the law. Tenants are entitled to seek compensatory damages or statutory damages ranging from $200 to $1,000, as well as attorney’s fees.
The TDPA takes effect 60 days after it was signed into law on July 29, 2021. However, owners are not liable for a violation of the law until January 1, 2023.
The TDPA is the country’s first standalone law to regulate the collection and retention of data from tenants living in “smart access” buildings. It also adds to the growing patchwork of biometric privacy regulations with which businesses must contend.
Although owners of smart access buildings in New York City have until 2023 to come into full compliance with the law, it is always advisable to be proactive. We also encourage landlords outside of New York City to monitor legal developments in this rapidly evolving area of law as it is very likely that similar laws will be enacted elsewhere.
If you have any questions or if you would like to discuss the matter further, please contact me, Thomas Herndon, Jr., or the Scarinci Hollenbeck attorney with whom you work, at 201-896-4100.
No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.
Corporate transactions can have significant implications for a corporation and its stakeholders. For deals to be successful, companies must act strategically to maximize value and minimize risk. It is also important to fully understand the legal and financial ramifications of corporate transactions, both in the near and long term. Understanding Corporate Transactions The term “corporate […]
Author: Dan Brecher
Ongoing economic uncertainty is forcing many companies to make tough decisions, which includes lowering staff levels. The legal landscape on both the state and federal level also continues to evolve, especially with significant changes to the priorities of the Equal Employment Opportunity Commission (“EEOC”) under the Trump Administration. Terminating an employee is one of the […]
Author: Angela A. Turiano
While filing annual reports may seem like a nuisance, failing to do so can have significant ramifications. These include fines, reputational harm, and interruption of your business operations. In basic terms, “admin dissolution for annual report” means that a company is dissolved by the government. This happens because it failed to submit its annual report […]
Author: Dan Brecher
Antitrust laws are designed to ensure that businesses compete fairly. There are three federal antitrust laws that businesses must navigate. These include the Sherman Act, the Federal Trade Commission Act, and the Clayton Act. States also have their own antitrust regimes. These may vary from federal regulations. Understanding antitrust litigation helps businesses navigate these complex […]
Author: Robert E. Levy
If you’re considering closing your business, it’s crucial to understand that simply shutting your doors does not end your legal obligations. Unless you formally dissolve your business, it continues to exist in the eyes of the law—leaving you exposed to ongoing liabilities such as taxes, compliance violations, and potential lawsuits. Dissolving a business can seem […]
Author: Christopher D. Warren
Contrary to what many people think, corporate restructuring isn’t all doom and gloom. Revamping a company’s organizational structure, corporate hierarchy, or operations procedures can help keep your business competitive. This is particularly true during challenging times. Corporate restructuring plays a critical role in modern business strategy. It helps companies adapt quickly to market changes. Following […]
Author: Dan Brecher
No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.
Consider subscribing to our Firm Insights mailing list by clicking the button below so you can keep up to date with the firm`s latest articles covering various legal topics.
Stay informed and inspired with the latest updates, insights, and events from Scarinci Hollenbeck. Our resource library provides valuable content across a range of categories to keep you connected and ahead of the curve.
Let`s get in touch!
Sign up to get the latest from the Scarinci Hollenbeck, LLC attorneys!