Senate Bill S7019

Signed By Governor
2021-2022 Legislative Session

Relates to the notification of certain state agencies of a data breach or network security breach

download bill text pdf

Sponsored By

Archive: Last Bill Status - Signed by Governor


  • Introduced
    • In Committee Assembly
    • In Committee Senate
    • On Floor Calendar Assembly
    • On Floor Calendar Senate
    • Passed Assembly
    • Passed Senate
  • Delivered to Governor
  • Signed By Governor

Do you support this bill?

Please enter your contact information

Home address is used to determine the senate district in which you reside. Your support or opposition to this bill is then shared immediately with the senator who represents you.

Optional services from the NY State Senate:

Create an account. An account allows you to officially support or oppose key legislation, sign petitions with a single click, and follow issues, committees, and bills that matter to you. When you create an account, you agree to this platform's terms of participation.

Include a custom message for your Senator? (Optional)

Enter a message to your senator. Many New Yorkers use this to share the reasoning behind their support or opposition to the bill. Others might share a personal anecdote about how the bill would affect them or people they care about.
Actions
Votes

co-Sponsors

2021-S7019 (ACTIVE) - Details

See Assembly Version of this Bill:
A7612
Law Section:
State Technology Law
Laws Affected:
Add §209, St Tech L

2021-S7019 (ACTIVE) - Summary

Relates to the notification of certain state agencies within twenty-four hours of a discovery of a data breach or network security breach.

2021-S7019 (ACTIVE) - Sponsor Memo

2021-S7019 (ACTIVE) - Bill Text download pdf

                            
 
                     S T A T E   O F   N E W   Y O R K
 ________________________________________________________________________
 
                                   7019
 
                        2021-2022 Regular Sessions
 
                             I N  S E N A T E
 
                               May 24, 2021
                                ___________
 
 Introduced  by  Sen. KRUEGER -- (at request of the State Comptroller) --
   read twice and ordered printed, and when printed to  be  committed  to
   the Committee on Internet and Technology
 
 AN  ACT  to amend the state technology law, in relation to the notifica-
   tion of certain state agencies of a data breach  or  network  security
   breach

   THE  PEOPLE OF THE STATE OF NEW YORK, REPRESENTED IN SENATE AND ASSEM-
 BLY, DO ENACT AS FOLLOWS:
 
   Section 1. The state technology law is amended by adding a new section
 209 to read as follows:
   § 209. NOTIFICATION OF DATA BREACH OR NETWORK SECURITY BREACH;  SHARED
 DATA.  1.  THE  OFFICE  SHALL,  WITHIN  TWENTY-FOUR  HOURS FOLLOWING THE
 DISCOVERY OF A DATA BREACH  OR  NETWORK  SECURITY  BREACH  OR  RECEIVING
 NOTICE  OF  A  DATA  BREACH OR NETWORK SECURITY BREACH, NOTIFY THE CHIEF
 INFORMATION OFFICER, AND WHERE APPROPRIATE, THE CHIEF INFORMATION  SECU-
 RITY  OFFICER,  OF  ANY STATE ENTITY WITH WHICH IT SHARES DATA, PROVIDES
 NETWORKED SERVICES OR SHARES A NETWORK CONNECTION WHOSE  DATA,  SERVICES
 OR  CONNECTION IS OR MAY HAVE BEEN THE SUBJECT OF SUCH BREACH WHETHER OR
 NOT SUCH DATA WAS, OR IS REASONABLY BELIEVED TO HAVE BEEN,  ACQUIRED  OR
 USED BY AN UNAUTHORIZED PERSON.
    2. THE OFFICE SHALL, IN ADDITION TO THE PROVISIONS OF SUBDIVISION ONE
 OF  THIS SECTION, NOTIFY THE CHIEF INFORMATION OFFICER, AND WHERE APPRO-
 PRIATE, THE CHIEF INFORMATION SECURITY OFFICER,  OF  SUCH  STATE  ENTITY
 WITH  WHICH  IT  SHARES  DATA,  PROVIDES  NETWORKED SERVICES OR SHARES A
 NETWORK CONNECTION AND WHOSE DATA IS OR MAY HAVE  BEEN  THE  SUBJECT  OF
 SUCH  BREACH,  OF  ITS  PLAN  FOR  REMEDIATION  OF THE BREACH AND FUTURE
 PROTECTION OF SUCH DATA AND NETWORK.
   3. FOR PURPOSES OF THIS SECTION:
   (A) "DATA BREACH" SHALL MEAN AN INTENTIONAL OR UNINTENTIONAL  INCIDENT
 WHERE  DATA  IS  DISCLOSED, RELEASED, STOLEN, OR TAKEN WITHOUT THE KNOW-
 LEDGE OR AUTHORIZATION OF THE DATA'S OWNER OR STEWARD.
 
  EXPLANATION--Matter in ITALICS (underscored) is new; matter in brackets
                       [ ] is old law to be omitted.
              

Comments

Open Legislation is a forum for New York State legislation. All comments are subject to review and community moderation is encouraged.

Comments deemed off-topic, commercial, campaign-related, self-promotional; or that contain profanity, hate or toxic speech; or that link to sites outside of the nysenate.gov domain are not permitted, and will not be published. Attempts to intimidate and silence contributors or deliberately deceive the public, including excessive or extraneous posting/posts, or coordinated activity, are prohibited and may result in the temporary or permanent banning of the user. Comment moderation is generally performed Monday through Friday. By contributing or voting you agree to the Terms of Participation and verify you are over 13.

Create an account. An account allows you to sign petitions with a single click, officially support or oppose key legislation, and follow issues, committees, and bills that matter to you. When you create an account, you agree to this platform's terms of participation.