Scarinci Hollenbeck, LLC, LLCScarinci Hollenbeck, LLC, LLC

Firm Insights

What Businesses Should Know About New York’s New Privacy Laws

Author: Scarinci Hollenbeck, LLC

Date: August 21, 2019

Key Contacts

Back

How Will Two New Privacy Laws Impact Your New York Business?

In late July, New York Governor Andrew Cuomo signed two bills into law that will impose new privacy requirements on New York businesses. The “Stop Hacks and Improve Electronic Data Security” (SHIELD) Act imposes new obligations regarding how businesses handle private customer data and provide data breach notifications. The second bill (A.2374/S.3582) requires consumer credit reporting agencies to offer identity theft prevention and mitigation services in the case of a breach.

What Businesses Need to Know About New York’s New Privacy Laws

Requirements Under SHIELD Act

Key points of the SHIELD Act include: (a) broadening the scope of information covered under breach notification law, (b) broadening the definition of a data breach to include unauthorized access to information (not just the unauthorized acquisition of information), and (c) requiring businesses to provide reasonable data security.

The SHIELD requirements apply to “any person or business that owns or licenses computerized data which includes private information of a resident of New York.”   Such people/businesses are required to “develop, implement and maintain reasonable safeguards to protect the security, confidentiality and integrity of the private information including, but not limited to, disposal of data.” SHIELD will take effect in March 2020.

Two carve-outs for certain businesses:

  1. Small businesses (those with less than 50 employees and under $3 million in gross revenue, or less than $5 million in assets) will be compliant if they “implement and maintain reasonable safeguards that are appropriate to the size and complexity of the small business to protect the security, confidentiality and integrity of the private information.”
  2. There is also a carve-out exemption for certain other businesses that are already regulated by, and compliant with, data breach requirements under other applicable state/federal cybersecurity laws (e.g., Gramm-Leach-Bliley Act; HIPAA). 

SHIELD broadens the scope of information covered under New York’s existing data breach notification law, and updates notification requirements when there has been a breach of data. Three key changes include:

  • The scope of information subject to the current data breach notification law will expand to include (a) biometric information, (b) email addresses and their corresponding passwords or security questions and answers, and (c) protected health information as defined under HIPAA.
  • The definition of a data breach will expand to include unauthorized access to private information. Currently, the state’s data breach law only covers unauthorized acquisition. Under the SHIELD Act, in determining whether information “has been accessed, or is reasonably believed to have been accessed, by an unauthorized person or a person without valid authorization, such business may consider, among other factors, indications that the information was viewed, communicated with, used, or altered by a person without valid authorization or by an unauthorized person.”
  • Data breach notification requirements would apply to any person or entity with private information of a New York resident, not just to those that conduct business in New York State.

Failure to provide required reasonable data security would be a violation of section 349 of the General Business Law, and the attorney general could bring suit for noncompliance. Businesses could be fined $5,000 for each violation or up to $20 per instance of failed notification, with an aggregate maximum of $250,000. However, the SHIELD Act does not create a private right of action.

Requirements for Credit Reporting Agencies

The second bill impacts credit reporting agencies and establishes the minimal amount of long-term protections that must be given to affected consumers. For any credit reporting agency that suffers a breach of information containing consumer Social Security numbers, that agency must then provide to affected consumers five years of identity theft prevention services and, if applicable, identity theft mitigation services. Credit reporting agencies must also inform consumers on credit freezes of a breach of data involving a Social Security number, and provide consumers with the right to freeze their credit at no cost.  This law will take effect in September 2019 and applies to any breach of the security of a consumer credit reporting agency that occurred in the prior three years.

If you have questions, please contact us

If you have any questions or if you would like to discuss the matter further, please contact me, Kristin Garris, or the Scarinci Hollenbeck attorney with whom you work, at 201-806-3364.

No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.

Scarinci Hollenbeck, LLC, LLC

Related Posts

See all
You Just Received a Federal Grand Jury Subpoena in New Jersey: Now What? post image

You Just Received a Federal Grand Jury Subpoena in New Jersey: Now What?

Receiving a federal grand jury subpoena is not something most businesses or individuals anticipate. While it can be concerning, a federal grand jury subpoena does not necessarily mean that you are being accused of wrongdoing. It does, however, mean that a federal criminal investigation is underway and that federal prosecutors believe you may possess information […]

Author: George McGowan

Link to post with title - "You Just Received a Federal Grand Jury Subpoena in New Jersey: Now What?"
Why Every Business Should Conduct an Annual Insurance Coverage Review post image

Why Every Business Should Conduct an Annual Insurance Coverage Review

Most New Jersey business owners purchase insurance policies, file them away, and assume they are protected if a claim arises. Without a regular insurance coverage review, many companies discover gaps only after a lawsuit, cyberattack, property loss, or other significant event occurs. An annual insurance coverage review can help businesses identify potential risks, ensure their […]

Author: George McGowan

Link to post with title - "Why Every Business Should Conduct an Annual Insurance Coverage Review"
Demand Letters & Cease and Desist Letters: When to Send One (and When Not To) post image

Demand Letters & Cease and Desist Letters: When to Send One (and When Not To)

Businesses and individuals often encounter situations where another party breaches a contract, fails to pay a debt, or continues harmful conduct. In many such disputes, a precisely drafted demand letter or cease-and-desist letter serves as a powerful legal tool. It can frequently resolve the dispute and avoid litigation. While demand or cease-and-desist letters can resolve […]

Author: George McGowan

Link to post with title - "Demand Letters & Cease and Desist Letters: When to Send One (and When Not To)"
How to Effectively Use Contracts to Manage Risk post image

How to Effectively Use Contracts to Manage Risk

Key provisions in your contracts, including those relating to indemnification, insurance, and defense, are essential to contract risk management. While sometimes considered “boilerplate,” these provisions play a pivotal role when determining which party is responsible for certain costs and liabilities. They must always be negotiated and drafted carefully. Indemnification Clauses Businesses should never overlook the […]

Author: George McGowan

Link to post with title - "How to Effectively Use Contracts to Manage Risk"
Understanding Portability for Estate and Gift Tax post image

Understanding Portability for Estate and Gift Tax

Portability of estate and gift tax enables a surviving spouse to inherit any unused portion of their deceased spouse’s federal estate and gift tax exemption. So, if one spouse doesn’t utilize their full exemption, the surviving spouse can effectively double their exemption amount with regard to estate tax liability. For married couples, portability offers a […]

Author: Marc J. Comer

Link to post with title - "Understanding Portability for Estate and Gift Tax"
Pet Trusts in New Jersey and New York: A Practical Estate Planning Tool post image

Pet Trusts in New Jersey and New York: A Practical Estate Planning Tool

For many of us, pets are more than companions—they are members of the family. Yet they are often overlooked or inadequately provided for when it comes to estate planning. A pet trust offers a legally enforceable way to ensure that your animal continues to receive proper care if you become incapacitated or pass away. As […]

Author: Marc J. Comer

Link to post with title - "Pet Trusts in New Jersey and New York: A Practical Estate Planning Tool"

No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.

Sign up to get the latest from our attorneys!

Explore What Matters Most to You.

Consider subscribing to our Firm Insights mailing list by clicking the button below so you can keep up to date with the firm`s latest articles covering various legal topics.

Stay informed and inspired with the latest updates, insights, and events from Scarinci Hollenbeck. Our resource library provides valuable content across a range of categories to keep you connected and ahead of the curve.

Let`s get in touch!

* The use of the Internet or this form for communication with the firm or any individual member of the firm does not establish an attorney-client relationship. Confidential or time-sensitive information should not be sent through this form. By providing a telephone number and submitting this form you are consenting to be contacted by SMS text message. Message & data rates may apply. Message frequency may vary. You can reply STOP to opt-out of further messaging.
“If you would like to submit a file, please email it directly to info@sh-law.com.

Sign up to get the latest from the Scarinci Hollenbeck, LLC attorneys!