senate Bill S6933A

2017-2018 Legislative Session

Relates to a notification of a security breach

download bill text pdf

Sponsored By

Current Bill Status - In Senate Committee Finance Committee


  • Introduced
  • In Committee
  • On Floor Calendar
    • Passed Senate
    • Passed Assembly
  • Delivered to Governor
  • Signed/Vetoed by Governor

Your Voice

do you support this bill?

Please enter your contact information

Home address is used to determine the senate district in which you reside. Your support or opposition to this bill is then shared immediately with the senator who represents you.

Optional services from the NY State Senate:

Create an account. An account allows you to officially support or oppose key legislation, sign petitions with a single click, and follow issues, committees, and bills that matter to you. When you create an account, you agree to this platform's terms of participation.

Include a custom message for your Senator? (Optional)

Enter a message to your senator. Many New Yorkers use this to share the reasoning behind their support or opposition to the bill. Others might share a personal anecdote about how the bill would affect them or people they care about.

Actions

view actions (7)
Assembly Actions - Lowercase
Senate Actions - UPPERCASE
Jun 01, 2018 print number 6933b
Jun 01, 2018 amend and recommit to finance
Feb 12, 2018 reported and committed to finance
Feb 02, 2018 print number 6933a
Feb 02, 2018 amend and recommit to consumer protection
Jan 03, 2018 referred to consumer protection
Nov 01, 2017 referred to rules

Votes

view votes

Feb 12, 2018 - Consumer Protection committee Vote

S6933A
6
3
committee
6
Aye
3
Nay
1
Aye with Reservations
0
Absent
1
Excused
0
Abstained
show Consumer Protection committee vote details

Consumer Protection Committee Vote: Feb 12, 2018

aye wr (1)
excused (1)

S6933 (ACTIVE) - Details

Current Committee:
Senate Finance
Law Section:
General Business Law
Laws Affected:
Amd Art 39-F Art Head, §899-aa, add §899-bb, Gen Bus L; amd §208, St Tech L

S6933 (ACTIVE) - Summary

Relates to notification of a security breach; includes credit and debit cards; increases civil penalties.

S6933 (ACTIVE) - Sponsor Memo

S6933 (ACTIVE) - Bill Text download pdf

                    S T A T E   O F   N E W   Y O R K
________________________________________________________________________

                                  6933

                       2017-2018 Regular Sessions

                            I N  S E N A T E

                            November 1, 2017
                               ___________

Introduced  by Sen. CARLUCCI -- read twice and ordered printed, and when
  printed to be committed to the Committee on Rules

AN ACT to amend the general business law and the state  technology  law,
  in relation to notification of a security breach

  THE  PEOPLE OF THE STATE OF NEW YORK, REPRESENTED IN SENATE AND ASSEM-
BLY, DO ENACT AS FOLLOWS:

  Section 1. This act shall be known and may be cited as the  "New  York
Data Security Act".
  S  2. The article heading of article 39-F of the general business law,
as added by chapter 442 of the laws of  2005,  is  amended  to  read  as
follows:
           NOTIFICATION OF UNAUTHORIZED ACQUISITION OF PRIVATE
                 INFORMATION; DATA SECURITY PROTECTIONS
  S  3.  Subdivisions  1,  2,  3, 5, 6, 7 and 8 of section 899-aa of the
general business law, as added by chapter 442 of the laws of 2005, para-
graph (c) of subdivision 1, paragraph (a) of subdivision 6 and  subdivi-
sion  8  as amended by chapter 491 of the laws of 2005 and paragraph (a)
of subdivision 8 as amended by section 6 of part N of chapter 55 of  the
laws  of 2013, are amended and a new subdivision 5-a is added to read as
follows:
  1. As used in this section, the following terms shall have the follow-
ing meanings:
  (a) "Personal information" shall mean  any  information  concerning  a
natural  person  which, because of name, number, personal mark, or other
identifier, can be used to identify such natural person;
  (b) "Private information" shall mean EITHER: (I) personal  information
consisting of any information in combination with any one or more of the
following  data  elements,  when  either the personal information or the
data element is not encrypted, or encrypted with an encryption key  that
has also been ACCESSED OR acquired:
  (1) social security number;

 EXPLANATION--Matter in ITALICS (underscored) is new; matter in brackets
                      [ ] is old law to be omitted.
                                                           LBD13619-04-7

Co-Sponsors

S6933A (ACTIVE) - Details

Current Committee:
Senate Finance
Law Section:
General Business Law
Laws Affected:
Amd Art 39-F Art Head, §899-aa, add §899-bb, Gen Bus L; amd §208, St Tech L

S6933A (ACTIVE) - Summary

Relates to notification of a security breach; includes credit and debit cards; increases civil penalties.

S6933A (ACTIVE) - Sponsor Memo

S6933A (ACTIVE) - Bill Text download pdf

                    S T A T E   O F   N E W   Y O R K
________________________________________________________________________

                                 6933--A

                       2017-2018 Regular Sessions

                            I N  S E N A T E

                            November 1, 2017
                               ___________

Introduced  by Sen. CARLUCCI -- read twice and ordered printed, and when
  printed to be committed to the Committee on Rules  --  recommitted  to
  the Committee on Consumer Protection in accordance with Senate Rule 6,
  sec.  8  --  committee  discharged, bill amended, ordered reprinted as
  amended and recommitted to said committee

AN ACT to amend the general business law and the state  technology  law,
  in relation to notification of a security breach

  THE  PEOPLE OF THE STATE OF NEW YORK, REPRESENTED IN SENATE AND ASSEM-
BLY, DO ENACT AS FOLLOWS:

  Section 1. This act shall be known and may be cited as the  "New  York
Data Security Act".
  S  2. The article heading of article 39-F of the general business law,
as added by chapter 442 of the laws of  2005,  is  amended  to  read  as
follows:
           NOTIFICATION OF UNAUTHORIZED ACQUISITION OF PRIVATE
                 INFORMATION; DATA SECURITY PROTECTIONS
  S  3.  Subdivisions  1,  2,  3, 5, 6, 7 and 8 of section 899-aa of the
general business law, as added by chapter 442 of the laws of 2005, para-
graph (c) of subdivision 1, paragraph (a) of subdivision 6 and  subdivi-
sion  8  as amended by chapter 491 of the laws of 2005 and paragraph (a)
of subdivision 8 as amended by section 6 of part N of chapter 55 of  the
laws  of 2013, are amended and a new subdivision 5-a is added to read as
follows:
  1. As used in this section, the following terms shall have the follow-
ing meanings:
  (a) "Personal information" shall mean  any  information  concerning  a
natural  person  which, because of name, number, personal mark, or other
identifier, can be used to identify such natural person;
  (b) "Private information" shall mean EITHER: (I) personal  information
consisting of any information in combination with any one or more of the
following  data  elements,  when  either the personal information or the

 EXPLANATION--Matter in ITALICS (underscored) is new; matter in brackets
                      [ ] is old law to be omitted.
                                                           LBD13619-05-8

Co-Sponsors

S6933B (ACTIVE) - Details

Current Committee:
Senate Finance
Law Section:
General Business Law
Laws Affected:
Amd Art 39-F Art Head, §899-aa, add §899-bb, Gen Bus L; amd §208, St Tech L

S6933B (ACTIVE) - Summary

Relates to notification of a security breach; includes credit and debit cards; increases civil penalties.

S6933B (ACTIVE) - Sponsor Memo

S6933B (ACTIVE) - Bill Text download pdf

                    S T A T E   O F   N E W   Y O R K
________________________________________________________________________

                                 6933--B

                       2017-2018 Regular Sessions

                            I N  S E N A T E

                            November 1, 2017
                               ___________

Introduced  by Sens. CARLUCCI, KAMINSKY -- read twice and ordered print-
  ed, and when printed to be committed to  the  Committee  on  Rules  --
  recommitted to the Committee on Consumer Protection in accordance with
  Senate  Rule  6, sec. 8 -- committee discharged, bill amended, ordered
  reprinted as amended and recommitted to  said  committee  --  reported
  favorably  from  said  committee  and  committed  to  the Committee on
  Finance -- committee discharged, bill amended,  ordered  reprinted  as
  amended and recommitted to said committee

AN  ACT  to amend the general business law and the state technology law,
  in relation to notification of a security breach

  THE PEOPLE OF THE STATE OF NEW YORK, REPRESENTED IN SENATE AND  ASSEM-
BLY, DO ENACT AS FOLLOWS:

  Section 1. This act shall be known and may be cited as the "Stop Hacks
and Improve Electronic Data Security Act (SHIELD Act)".
  S  2. The article heading of article 39-F of the general business law,
as added by chapter 442 of the laws of  2005,  is  amended  to  read  as
follows:
           NOTIFICATION OF UNAUTHORIZED ACQUISITION OF PRIVATE
                 INFORMATION; DATA SECURITY PROTECTIONS
  S  3.  Subdivisions  1,  2,  3, 5, 6, 7 and 8 of section 899-aa of the
general business law, as added by chapter 442 of the laws of 2005, para-
graph (c) of subdivision 1, paragraph (a) of subdivision 6 and  subdivi-
sion  8  as amended by chapter 491 of the laws of 2005 and paragraph (a)
of subdivision 8 as amended by section 6 of part N of chapter 55 of  the
laws of 2013, are amended to read as follows:
  1. As used in this section, the following terms shall have the follow-
ing meanings:
  (a)  "Personal  information"  shall  mean any information concerning a
natural person which, because of name, number, personal mark,  or  other
identifier, can be used to identify such natural person;

 EXPLANATION--Matter in ITALICS (underscored) is new; matter in brackets
                      [ ] is old law to be omitted.
                                                           LBD13619-10-8

Comments

Open Legislation comments facilitate discussion of New York State legislation. All comments are subject to moderation. Comments deemed off-topic, commercial, campaign-related, self-promotional; or that contain profanity or hate speech; or that link to sites outside of the nysenate.gov domain are not permitted, and will not be published. Comment moderation is generally performed Monday through Friday.

By contributing or voting you agree to the Terms of Participation and verify you are over 13.