Senate Bill S7786

Signed By Governor
2021-2022 Legislative Session

Relates to the notification of certain state agencies of a breach of the security system or a breach of the security network

download bill text pdf

Sponsored By

Archive: Last Bill Status - Signed by Governor


  • Introduced
    • In Committee Assembly
    • In Committee Senate
    • On Floor Calendar Assembly
    • On Floor Calendar Senate
    • Passed Assembly
    • Passed Senate
  • Delivered to Governor
  • Signed By Governor

Do you support this bill?

Please enter your contact information

Home address is used to determine the senate district in which you reside. Your support or opposition to this bill is then shared immediately with the senator who represents you.

Optional services from the NY State Senate:

Create an account. An account allows you to officially support or oppose key legislation, sign petitions with a single click, and follow issues, committees, and bills that matter to you. When you create an account, you agree to this platform's terms of participation.

Include a custom message for your Senator? (Optional)

Enter a message to your senator. Many New Yorkers use this to share the reasoning behind their support or opposition to the bill. Others might share a personal anecdote about how the bill would affect them or people they care about.
Actions
Votes

2021-S7786 (ACTIVE) - Details

See Assembly Version of this Bill:
A8793
Law Section:
State Technology Law
Laws Affected:
Amd §209, St Tech L (as proposed in S.7019 & A.7612)

2021-S7786 (ACTIVE) - Summary

Relates to the notification of certain state agencies of a breach of the security system or a breach of the security network.

2021-S7786 (ACTIVE) - Sponsor Memo

2021-S7786 (ACTIVE) - Bill Text download pdf

                             
                     S T A T E   O F   N E W   Y O R K
 ________________________________________________________________________
 
                                   7786
 
                             I N  S E N A T E
 
                             January 11, 2022
                                ___________
 
 Introduced  by  Sen. KRUEGER -- read twice and ordered printed, and when
   printed to be committed to the Committee on Rules
 
 AN ACT to amend the state technology law, in relation to  the  notifica-
   tion  of  certain  agencies  of  a  breach of the security system or a
   breach of the security network
 
   THE PEOPLE OF THE STATE OF NEW YORK, REPRESENTED IN SENATE AND  ASSEM-
 BLY, DO ENACT AS FOLLOWS:
 
   Section  1.  Section  209  of  the state technology law, as added by a
 chapter of the laws of 2021 amending the state technology  law  relating
 to  the  notification  of  certain  state  agencies  of a data breach or
 network security breach, as proposed in  legislative  bills  numbers  S.
 7019 and A.  7612, is amended to read as follows:
   § 209. Notification of [data] A breach [or network] OF THE security OF
 THE  SYSTEM  OR A breach OF NETWORK SECURITY; shared data. 1. The office
 shall, within twenty-four hours  [following  the  discovery  of  a  data
 breach  or  network security breach or receiving notice of a data breach
 or network security breach] OF EITHER BEING  NOTIFIED  OF  OR  RECEIVING
 EVIDENCE  OF  A  BREACH  OF  THE  SECURITY OF THE SYSTEM, OR A BREACH OF
 NETWORK SECURITY, AS DEFINED IN PARAGRAPHS (A) AND  (B)  OF  SUBDIVISION
 THREE  OF THIS SECTION, notify the chief information officer, [and where
 appropriate,] the chief information security officer, AND  WHERE  APPRO-
 PRIATE, THE CYBER SECURITY COORDINATOR of any state entity with which it
 shares  data, provides networked services or shares a network connection
 whose data, services or connection is [or may have been the subject  of]
 REASONABLY  SUSPECTED  TO BE AFFECTED BY ANY such breach [whether or not
 such data was, or is reasonably believed to have been, acquired or  used
 by an unauthorized person].
   2. The office shall[, in addition to the provisions of subdivision one
 of  this  section,  notify]  PROVIDE the chief information officer, [and
 where appropriate,] the chief information security  officer,  AND  WHERE
 APPROPRIATE, THE CYBER RISK COORDINATOR of [such] ANY state entity [with
 which  it  shares  data, provides networked services or shares a network
 connection and whose data is or  may  have  been  the  subject  of  such
 breach,  of],  WHO HAS BEEN NOTIFIED PURSUANT TO SUBDIVISION ONE OF THIS
 
  EXPLANATION--Matter in ITALICS (underscored) is new; matter in brackets
                       [ ] is old law to be omitted.
              

Comments

Open Legislation is a forum for New York State legislation. All comments are subject to review and community moderation is encouraged.

Comments deemed off-topic, commercial, campaign-related, self-promotional; or that contain profanity, hate or toxic speech; or that link to sites outside of the nysenate.gov domain are not permitted, and will not be published. Attempts to intimidate and silence contributors or deliberately deceive the public, including excessive or extraneous posting/posts, or coordinated activity, are prohibited and may result in the temporary or permanent banning of the user. Comment moderation is generally performed Monday through Friday. By contributing or voting you agree to the Terms of Participation and verify you are over 13.

Create an account. An account allows you to sign petitions with a single click, officially support or oppose key legislation, and follow issues, committees, and bills that matter to you. When you create an account, you agree to this platform's terms of participation.