Assembly Bill A7612

Signed By Governor
2021-2022 Legislative Session

Relates to the notification of certain state agencies of a data breach or network security breach

download bill text pdf

Sponsored By

Archive: Last Bill Status Via S7019 - Signed by Governor


  • Introduced
    • In Committee Assembly
    • In Committee Senate
    • On Floor Calendar Assembly
    • On Floor Calendar Senate
    • Passed Assembly
    • Passed Senate
  • Delivered to Governor
  • Signed By Governor

Do you support this bill?

Please enter your contact information

Home address is used to determine the senate district in which you reside. Your support or opposition to this bill is then shared immediately with the senator who represents you.

Optional services from the NY State Senate:

Create an account. An account allows you to officially support or oppose key legislation, sign petitions with a single click, and follow issues, committees, and bills that matter to you. When you create an account, you agree to this platform's terms of participation.

Include a custom message for your Senator? (Optional)

Enter a message to your senator. Many New Yorkers use this to share the reasoning behind their support or opposition to the bill. Others might share a personal anecdote about how the bill would affect them or people they care about.
Actions
Votes

co-Sponsors

2021-A7612 (ACTIVE) - Details

See Senate Version of this Bill:
S7019
Law Section:
State Technology Law
Laws Affected:
Add §209, St Tech L

2021-A7612 (ACTIVE) - Summary

Relates to the notification of certain state agencies within twenty-four hours of a discovery of a data breach or network security breach.

2021-A7612 (ACTIVE) - Bill Text download pdf

                            
 
                     S T A T E   O F   N E W   Y O R K
 ________________________________________________________________________
 
                                   7612
 
                        2021-2022 Regular Sessions
 
                           I N  A S S E M B L Y
 
                               May 19, 2021
                                ___________
 
 Introduced by M. of A. OTIS, ZEBROWSKI -- (at request of the State Comp-
   troller)  --  read  once and referred to the Committee on Governmental
   Operations
 
 AN ACT to amend the state technology law, in relation to  the  notifica-
   tion  of  certain  state agencies of a data breach or network security
   breach

   THE PEOPLE OF THE STATE OF NEW YORK, REPRESENTED IN SENATE AND  ASSEM-
 BLY, DO ENACT AS FOLLOWS:
 
   Section 1. The state technology law is amended by adding a new section
 209 to read as follows:
   §  209. NOTIFICATION OF DATA BREACH OR NETWORK SECURITY BREACH; SHARED
 DATA. 1. THE  OFFICE  SHALL,  WITHIN  TWENTY-FOUR  HOURS  FOLLOWING  THE
 DISCOVERY  OF  A  DATA  BREACH  OR  NETWORK SECURITY BREACH OR RECEIVING
 NOTICE OF A DATA BREACH OR NETWORK SECURITY  BREACH,  NOTIFY  THE  CHIEF
 INFORMATION  OFFICER, AND WHERE APPROPRIATE, THE CHIEF INFORMATION SECU-
 RITY OFFICER, OF ANY STATE ENTITY WITH WHICH IT  SHARES  DATA,  PROVIDES
 NETWORKED  SERVICES  OR SHARES A NETWORK CONNECTION WHOSE DATA, SERVICES
 OR CONNECTION IS OR MAY HAVE BEEN THE SUBJECT OF SUCH BREACH WHETHER  OR
 NOT  SUCH  DATA WAS, OR IS REASONABLY BELIEVED TO HAVE BEEN, ACQUIRED OR
 USED BY AN UNAUTHORIZED PERSON.
    2. THE OFFICE SHALL, IN ADDITION TO THE PROVISIONS OF SUBDIVISION ONE
 OF THIS SECTION, NOTIFY THE CHIEF INFORMATION OFFICER, AND WHERE  APPRO-
 PRIATE,  THE  CHIEF  INFORMATION  SECURITY OFFICER, OF SUCH STATE ENTITY
 WITH WHICH IT SHARES DATA,  PROVIDES  NETWORKED  SERVICES  OR  SHARES  A
 NETWORK  CONNECTION  AND  WHOSE  DATA IS OR MAY HAVE BEEN THE SUBJECT OF
 SUCH BREACH, OF ITS PLAN  FOR  REMEDIATION  OF  THE  BREACH  AND  FUTURE
 PROTECTION OF SUCH DATA AND NETWORK.
   3. FOR PURPOSES OF THIS SECTION:
   (A)  "DATA BREACH" SHALL MEAN AN INTENTIONAL OR UNINTENTIONAL INCIDENT
 WHERE DATA IS DISCLOSED, RELEASED, STOLEN, OR TAKEN  WITHOUT  THE  KNOW-
 LEDGE OR AUTHORIZATION OF THE DATA'S OWNER OR STEWARD.
 
  EXPLANATION--Matter in ITALICS (underscored) is new; matter in brackets
                       [ ] is old law to be omitted.
              

Comments

Open Legislation is a forum for New York State legislation. All comments are subject to review and community moderation is encouraged.

Comments deemed off-topic, commercial, campaign-related, self-promotional; or that contain profanity, hate or toxic speech; or that link to sites outside of the nysenate.gov domain are not permitted, and will not be published. Attempts to intimidate and silence contributors or deliberately deceive the public, including excessive or extraneous posting/posts, or coordinated activity, are prohibited and may result in the temporary or permanent banning of the user. Comment moderation is generally performed Monday through Friday. By contributing or voting you agree to the Terms of Participation and verify you are over 13.

Create an account. An account allows you to sign petitions with a single click, officially support or oppose key legislation, and follow issues, committees, and bills that matter to you. When you create an account, you agree to this platform's terms of participation.