ARTICLE
9 August 2019

New York State Governor Signs Bills Expanding Data Breach Notification Requirements

CW
Cadwalader, Wickersham & Taft LLP

Contributor

Cadwalader, established in 1792, serves a diverse client base, including many of the world's leading financial institutions, funds and corporations. With offices in the United States and Europe, Cadwalader offers legal representation in antitrust, banking, corporate finance, corporate governance, executive compensation, financial restructuring, intellectual property, litigation, mergers and acquisitions, private equity, private wealth, real estate, regulation, securitization, structured finance, tax and white collar defense.
On Friday, July 26, 2019, New York Governor Andrew Cuomo signed two bills into law designed to enhance cybersecurity protections for New York residents. The legislation updates New York's
United States Privacy
To print this article, all you need is to be registered or login on Mondaq.com.

On Friday, July 26, 2019, New York Governor Andrew Cuomo signed two bills into law designed to enhance cybersecurity protections for New York residents. The legislation updates New York's data breach notification law.

The "Stop Hacks and Improve Electronic Data Security Act" (the "SHIELD Act") was created to enhance cybersecurity protections for New York residents by expanding the state's existing data breach notification requirements. Specifically, the legislation:

  • widens the definition of "private information" to include biometric data, a username or email address and a password, or security questions and answers that would permit access to an online account;
  • expands the definition of "data breach" to include unauthorized access to private information on a data system, even if such private information is not stolen;
  • extends the breach notification requirement to include any person or entity that owns or licenses computerized data that includes private information concerning any New York State resident, even in the absence of a New York business enterprise;
  • tightens the notification procedures following a data breach; and
  • imposes data security safeguard requirements, including the designation of cybersecurity personnel, sufficient data protection controls, and employee training on cybersecurity practices and procedures.

The "Identity Theft Prevention and Mitigating Services Act" will require credit reporting agencies to provide "reasonable identity theft prevention services [and] identity theft mitigation services" to any customers affected by a data breach involving their social security numbers.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More