Scarinci Hollenbeck, LLC, LLCScarinci Hollenbeck, LLC, LLC

Firm Insights

What Businesses Should Know About New York’s New Privacy Laws

Author: Scarinci Hollenbeck, LLC

Date: August 21, 2019

Key Contacts

Back

How Will Two New Privacy Laws Impact Your New York Business?

In late July, New York Governor Andrew Cuomo signed two bills into law that will impose new privacy requirements on New York businesses. The “Stop Hacks and Improve Electronic Data Security” (SHIELD) Act imposes new obligations regarding how businesses handle private customer data and provide data breach notifications. The second bill (A.2374/S.3582) requires consumer credit reporting agencies to offer identity theft prevention and mitigation services in the case of a breach.

What Businesses Need to Know About New York’s New Privacy Laws

Requirements Under SHIELD Act

Key points of the SHIELD Act include: (a) broadening the scope of information covered under breach notification law, (b) broadening the definition of a data breach to include unauthorized access to information (not just the unauthorized acquisition of information), and (c) requiring businesses to provide reasonable data security.

The SHIELD requirements apply to “any person or business that owns or licenses computerized data which includes private information of a resident of New York.”   Such people/businesses are required to “develop, implement and maintain reasonable safeguards to protect the security, confidentiality and integrity of the private information including, but not limited to, disposal of data.” SHIELD will take effect in March 2020.

Two carve-outs for certain businesses:

  1. Small businesses (those with less than 50 employees and under $3 million in gross revenue, or less than $5 million in assets) will be compliant if they “implement and maintain reasonable safeguards that are appropriate to the size and complexity of the small business to protect the security, confidentiality and integrity of the private information.”
  2. There is also a carve-out exemption for certain other businesses that are already regulated by, and compliant with, data breach requirements under other applicable state/federal cybersecurity laws (e.g., Gramm-Leach-Bliley Act; HIPAA). 

SHIELD broadens the scope of information covered under New York’s existing data breach notification law, and updates notification requirements when there has been a breach of data. Three key changes include:

  • The scope of information subject to the current data breach notification law will expand to include (a) biometric information, (b) email addresses and their corresponding passwords or security questions and answers, and (c) protected health information as defined under HIPAA.
  • The definition of a data breach will expand to include unauthorized access to private information. Currently, the state’s data breach law only covers unauthorized acquisition. Under the SHIELD Act, in determining whether information “has been accessed, or is reasonably believed to have been accessed, by an unauthorized person or a person without valid authorization, such business may consider, among other factors, indications that the information was viewed, communicated with, used, or altered by a person without valid authorization or by an unauthorized person.”
  • Data breach notification requirements would apply to any person or entity with private information of a New York resident, not just to those that conduct business in New York State.

Failure to provide required reasonable data security would be a violation of section 349 of the General Business Law, and the attorney general could bring suit for noncompliance. Businesses could be fined $5,000 for each violation or up to $20 per instance of failed notification, with an aggregate maximum of $250,000. However, the SHIELD Act does not create a private right of action.

Requirements for Credit Reporting Agencies

The second bill impacts credit reporting agencies and establishes the minimal amount of long-term protections that must be given to affected consumers. For any credit reporting agency that suffers a breach of information containing consumer Social Security numbers, that agency must then provide to affected consumers five years of identity theft prevention services and, if applicable, identity theft mitigation services. Credit reporting agencies must also inform consumers on credit freezes of a breach of data involving a Social Security number, and provide consumers with the right to freeze their credit at no cost.  This law will take effect in September 2019 and applies to any breach of the security of a consumer credit reporting agency that occurred in the prior three years.

If you have questions, please contact us

If you have any questions or if you would like to discuss the matter further, please contact me, Kristin Garris, or the Scarinci Hollenbeck attorney with whom you work, at 201-806-3364.

No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.

Scarinci Hollenbeck, LLC, LLC

Related Posts

See all
How Understanding Bankruptcy Trends Can Benefit Your Business post image

How Understanding Bankruptcy Trends Can Benefit Your Business

The bankruptcy legal landscape presents both challenges and opportunities for businesses navigating financial distress. Understanding current bankruptcy trends can help businesses make more informed and strategic decisions. Corporate Bankruptcy Filings Trending Upwards Bankruptcy filings continued to trend upwards in 2024. According to statistics released by the Administrative Office of the U.S. Courts, personal and business […]

Author: Brian D. Spector

Link to post with title - "How Understanding Bankruptcy Trends Can Benefit Your Business"
SEC Takes Actions Against Issuers for Failure to File Form D post image

SEC Takes Actions Against Issuers for Failure to File Form D

In December, the U.S. Securities and Exchange Commission (SEC) announced charges against two privately held companies for failing to file a Form D notice, which is generally utilized for exempt securities offerings. Here, the SEC’s enforcement sends a strong message: compliance with regulatory requirements is not optional and failure to comply can have significant consequences. […]

Author: Kenneth C. Oh

Link to post with title - "SEC Takes Actions Against Issuers for Failure to File Form D"
Redefining Labor Relations: NLRB's Pivot from Abruzzo’s Memoranda post image

Redefining Labor Relations: NLRB's Pivot from Abruzzo’s Memoranda

On February 14, 2025, the Office of General Counsel (OGC) of the National Labor Relations Board (NLRB) under Acting General Counsel William B. Cowen issued Memorandum 25-05, “New Process for More Efficient, Effective, Accessible and Transparent Case handling.” The Memorandum rescinds nearly all of the Memoranda issued by his direct predecessor, Jennifer Abruzzo, setting the […]

Author: Matthew F. Mimnaugh

Link to post with title - "Redefining Labor Relations: NLRB's Pivot from Abruzzo’s Memoranda"
What Are FIRPTA Withholding Requirements? post image

What Are FIRPTA Withholding Requirements?

If you purchase real property from a foreign person or entity, you may be required to withhold taxes from your payment to the seller under the Foreign Investment in Real Property Tax Act (FIRPTA). The federal tax law is designed to ensure that foreign sellers pay any applicable capital gains tax on profits realized from […]

Author: Jesse M. Dimitro

Link to post with title - "What Are FIRPTA Withholding Requirements?"
Does Your Homeowners Insurance Provide Adequate Coverage? post image

Does Your Homeowners Insurance Provide Adequate Coverage?

Your home is likely your greatest asset, which is why it is so important to adequately protect it. Homeowners insurance protects you from the financial costs of unforeseen losses, such as theft, fire, and natural disasters, by helping you rebuild and replace possessions that were lost While the definition of “adequate” coverage depends upon a […]

Author: Jesse M. Dimitro

Link to post with title - "Does Your Homeowners Insurance Provide Adequate Coverage?"
Understanding the Importance of a Non-Contingent Offer post image

Understanding the Importance of a Non-Contingent Offer

Making a non-contingent offer can dramatically increase your chances of securing a real estate transaction, particularly in competitive markets like New York City. However, buyers should understand that waiving contingencies, including those related to financing, or appraisals, also comes with significant risks. Determining your best strategy requires careful analysis of the property, the market, and […]

Author: Jesse M. Dimitro

Link to post with title - "Understanding the Importance of a Non-Contingent Offer"

No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.

Sign up to get the latest from our attorneys!

Explore What Matters Most to You.

Consider subscribing to our Firm Insights mailing list by clicking the button below so you can keep up to date with the firm`s latest articles covering various legal topics.

Stay informed and inspired with the latest updates, insights, and events from Scarinci Hollenbeck. Our resource library provides valuable content across a range of categories to keep you connected and ahead of the curve.

Let`s get in touch!

* The use of the Internet or this form for communication with the firm or any individual member of the firm does not establish an attorney-client relationship. Confidential or time-sensitive information should not be sent through this form.

Sign up to get the latest from the Scarinci Hollenbeck, LLC attorneys!

Please select a category(s) below: