|
Assembly Actions -
Lowercase Senate Actions - UPPERCASE |
|
|---|---|
| Jun 01, 2018 |
print number 6933b |
| Jun 01, 2018 |
amend and recommit to finance |
| Feb 12, 2018 |
reported and committed to finance |
| Feb 02, 2018 |
print number 6933a |
| Feb 02, 2018 |
amend and recommit to consumer protection |
| Jan 03, 2018 |
referred to consumer protection |
| Nov 01, 2017 |
referred to rules |
Senate Bill S6933B
2017-2018 Legislative Session
Sponsored By
(D) Senate District
Archive: Last Bill Status - In Senate Committee Finance Committee
- Introduced
-
- In Committee Assembly
- In Committee Senate
-
- On Floor Calendar Assembly
- On Floor Calendar Senate
-
- Passed Assembly
- Passed Senate
- Delivered to Governor
- Signed By Governor
Actions
Votes
Bill Amendments
2017-S6933 - Details
- See Assembly Version of this Bill:
- A8884
- Current Committee:
- Senate Finance
- Law Section:
- General Business Law
- Laws Affected:
- Amd Art 39-F Art Head, §899-aa, add §899-bb, Gen Bus L; amd §208, St Tech L
- Versions Introduced in 2019-2020 Legislative Session:
-
S133, S5575
2017-S6933 - Sponsor Memo
BILL NUMBER: S6933
SPONSOR: CARLUCCI
TITLE OF BILL: An act to amend the general business law and the state
technology law, in relation to notification of a security breach
PURPOSE:
New York's data breach notification law needs to be updated keep pace
with current technology. This bill broadens the scope of information
covered under the notification law and updates the notification require-
ments when there has been a breach of data. It also broadens the defi-
nition of a data breach to include an unauthorized person gaining access
to information. It also requires reasonable data security, provides
standards tailored to the size of a business, and provides protections
from liability for certain entities.
SUMMARY OF SPECIFIC PROVISIONS:
Section 1 of the bill names the act.
2017-S6933 - Bill Text download pdf
S T A T E O F N E W Y O R K
________________________________________________________________________
6933
2017-2018 Regular Sessions
I N S E N A T E
November 1, 2017
___________
Introduced by Sen. CARLUCCI -- read twice and ordered printed, and when
printed to be committed to the Committee on Rules
AN ACT to amend the general business law and the state technology law,
in relation to notification of a security breach
THE PEOPLE OF THE STATE OF NEW YORK, REPRESENTED IN SENATE AND ASSEM-
BLY, DO ENACT AS FOLLOWS:
Section 1. This act shall be known and may be cited as the "New York
Data Security Act".
§ 2. The article heading of article 39-F of the general business law,
as added by chapter 442 of the laws of 2005, is amended to read as
follows:
NOTIFICATION OF UNAUTHORIZED ACQUISITION OF PRIVATE
INFORMATION; DATA SECURITY PROTECTIONS
§ 3. Subdivisions 1, 2, 3, 5, 6, 7 and 8 of section 899-aa of the
general business law, as added by chapter 442 of the laws of 2005, para-
graph (c) of subdivision 1, paragraph (a) of subdivision 6 and subdivi-
sion 8 as amended by chapter 491 of the laws of 2005 and paragraph (a)
of subdivision 8 as amended by section 6 of part N of chapter 55 of the
laws of 2013, are amended and a new subdivision 5-a is added to read as
follows:
1. As used in this section, the following terms shall have the follow-
ing meanings:
(a) "Personal information" shall mean any information concerning a
natural person which, because of name, number, personal mark, or other
identifier, can be used to identify such natural person;
(b) "Private information" shall mean EITHER: (I) personal information
consisting of any information in combination with any one or more of the
following data elements, when either the personal information or the
data element is not encrypted, or encrypted with an encryption key that
has also been ACCESSED OR acquired:
(1) social security number;
EXPLANATION--Matter in ITALICS (underscored) is new; matter in brackets
[ ] is old law to be omitted.
co-Sponsors
(D) Senate District
2017-S6933A - Details
- See Assembly Version of this Bill:
- A8884
- Current Committee:
- Senate Finance
- Law Section:
- General Business Law
- Laws Affected:
- Amd Art 39-F Art Head, §899-aa, add §899-bb, Gen Bus L; amd §208, St Tech L
- Versions Introduced in 2019-2020 Legislative Session:
-
S133, S5575
2017-S6933A - Sponsor Memo
BILL NUMBER: S6933A
SPONSOR: CARLUCCI
TITLE OF BILL:
An act to amend the general business law and the state technology law,
in relation to notification of a security breach
PURPOSE:
New York's data breach notification law needs to be updated keep pace
with current technology. This bill broadens the scope of information
covered under the notification law and updates the notification require-
ments when there has been a breach of data. It also broadens the defi-
nition of a data breach to include an unauthorized person gaining access
to information. It also requires reasonable data security, provides
standards tailored to the size of a business, and provides protections
from liability for certain entities.
SUMMARY OF SPECIFIC PROVISIONS:
2017-S6933A - Bill Text download pdf
S T A T E O F N E W Y O R K
________________________________________________________________________
6933--A
2017-2018 Regular Sessions
I N S E N A T E
November 1, 2017
___________
Introduced by Sen. CARLUCCI -- read twice and ordered printed, and when
printed to be committed to the Committee on Rules -- recommitted to
the Committee on Consumer Protection in accordance with Senate Rule 6,
sec. 8 -- committee discharged, bill amended, ordered reprinted as
amended and recommitted to said committee
AN ACT to amend the general business law and the state technology law,
in relation to notification of a security breach
THE PEOPLE OF THE STATE OF NEW YORK, REPRESENTED IN SENATE AND ASSEM-
BLY, DO ENACT AS FOLLOWS:
Section 1. This act shall be known and may be cited as the "New York
Data Security Act".
§ 2. The article heading of article 39-F of the general business law,
as added by chapter 442 of the laws of 2005, is amended to read as
follows:
NOTIFICATION OF UNAUTHORIZED ACQUISITION OF PRIVATE
INFORMATION; DATA SECURITY PROTECTIONS
§ 3. Subdivisions 1, 2, 3, 5, 6, 7 and 8 of section 899-aa of the
general business law, as added by chapter 442 of the laws of 2005, para-
graph (c) of subdivision 1, paragraph (a) of subdivision 6 and subdivi-
sion 8 as amended by chapter 491 of the laws of 2005 and paragraph (a)
of subdivision 8 as amended by section 6 of part N of chapter 55 of the
laws of 2013, are amended and a new subdivision 5-a is added to read as
follows:
1. As used in this section, the following terms shall have the follow-
ing meanings:
(a) "Personal information" shall mean any information concerning a
natural person which, because of name, number, personal mark, or other
identifier, can be used to identify such natural person;
(b) "Private information" shall mean EITHER: (I) personal information
consisting of any information in combination with any one or more of the
following data elements, when either the personal information or the
EXPLANATION--Matter in ITALICS (underscored) is new; matter in brackets
[ ] is old law to be omitted.
co-Sponsors
(D) Senate District
2017-S6933B (ACTIVE) - Details
- See Assembly Version of this Bill:
- A8884
- Current Committee:
- Senate Finance
- Law Section:
- General Business Law
- Laws Affected:
- Amd Art 39-F Art Head, §899-aa, add §899-bb, Gen Bus L; amd §208, St Tech L
- Versions Introduced in 2019-2020 Legislative Session:
-
S133, S5575
2017-S6933B (ACTIVE) - Sponsor Memo
BILL NUMBER: S6933B
SPONSOR: CARLUCCI
TITLE OF BILL: An act to amend the general business law and the state
technology law, in relation to notification of a security breach
PURPOSE:
New York's data breach notification law needs to be updated keep pace
with current technology. This bill broadens the scope of information
covered under the notification law and updates the notification require-
ments when there has been a breach of data. It also broadens the defi-
nition of a data breach to include an unauthorized person gaining access
to information. It also requires reasonable data security, provides
standards tailored to the size of a business, and provides protections
from liability for certain entities.
SUMMARY OF SPECIFIC PROVISIONS:
Section 1 of the bill names the act.
2017-S6933B (ACTIVE) - Bill Text download pdf
S T A T E O F N E W Y O R K
________________________________________________________________________
6933--B
2017-2018 Regular Sessions
I N S E N A T E
November 1, 2017
___________
Introduced by Sens. CARLUCCI, KAMINSKY -- read twice and ordered print-
ed, and when printed to be committed to the Committee on Rules --
recommitted to the Committee on Consumer Protection in accordance with
Senate Rule 6, sec. 8 -- committee discharged, bill amended, ordered
reprinted as amended and recommitted to said committee -- reported
favorably from said committee and committed to the Committee on
Finance -- committee discharged, bill amended, ordered reprinted as
amended and recommitted to said committee
AN ACT to amend the general business law and the state technology law,
in relation to notification of a security breach
THE PEOPLE OF THE STATE OF NEW YORK, REPRESENTED IN SENATE AND ASSEM-
BLY, DO ENACT AS FOLLOWS:
Section 1. This act shall be known and may be cited as the "Stop Hacks
and Improve Electronic Data Security Act (SHIELD Act)".
§ 2. The article heading of article 39-F of the general business law,
as added by chapter 442 of the laws of 2005, is amended to read as
follows:
NOTIFICATION OF UNAUTHORIZED ACQUISITION OF PRIVATE
INFORMATION; DATA SECURITY PROTECTIONS
§ 3. Subdivisions 1, 2, 3, 5, 6, 7 and 8 of section 899-aa of the
general business law, as added by chapter 442 of the laws of 2005, para-
graph (c) of subdivision 1, paragraph (a) of subdivision 6 and subdivi-
sion 8 as amended by chapter 491 of the laws of 2005 and paragraph (a)
of subdivision 8 as amended by section 6 of part N of chapter 55 of the
laws of 2013, are amended to read as follows:
1. As used in this section, the following terms shall have the follow-
ing meanings:
(a) "Personal information" shall mean any information concerning a
natural person which, because of name, number, personal mark, or other
identifier, can be used to identify such natural person;
EXPLANATION--Matter in ITALICS (underscored) is new; matter in brackets
[ ] is old law to be omitted.
LBD13619-10-8
Comments
Open Legislation is a forum for New York State legislation. All comments are subject to review and community moderation is encouraged.
Comments deemed off-topic, commercial, campaign-related, self-promotional; or that contain profanity, hate or toxic speech; or that link to sites outside of the nysenate.gov domain are not permitted, and will not be published. Attempts to intimidate and silence contributors or deliberately deceive the public, including excessive or extraneous posting/posts, or coordinated activity, are prohibited and may result in the temporary or permanent banning of the user. Comment moderation is generally performed Monday through Friday. By contributing or voting you agree to the Terms of Participation and verify you are over 13.
Create an account. An account allows you to sign petitions with a single click, officially support or oppose key legislation, and follow issues, committees, and bills that matter to you. When you create an account, you agree to this platform's terms of participation.