S T A T E O F N E W Y O R K
________________________________________________________________________
3812
2023-2024 Regular Sessions
I N A S S E M B L Y
February 8, 2023
___________
Introduced by M. of A. FAHY -- read once and referred to the Committee
on Consumer Affairs and Protection
AN ACT to amend the general business law, in relation to private infor-
mation
THE PEOPLE OF THE STATE OF NEW YORK, REPRESENTED IN SENATE AND ASSEM-
BLY, DO ENACT AS FOLLOWS:
Section 1. Paragraph (b) of subdivision 1 of section 899-aa of the
general business law, as amended by chapter 117 of the laws of 2019, is
amended to read as follows:
(b) "Private information" shall mean either: (i) personal information
consisting of any information in combination with any one or more of the
following data elements, when either the data element or the combination
of personal information plus the data element is not encrypted, or is
encrypted with an encryption key that has also been accessed or
acquired:
(1) social security number;
(2) driver's license number or non-driver identification card number;
(3) account number, credit or debit card number, in combination with
any required security code, access code, password or other information
that would permit access to an individual's financial account;
(4) account number, credit or debit card number, if circumstances
exist wherein such number could be used to access an individual's finan-
cial account without additional identifying information, security code,
access code, or password; [or]
(5) biometric information, meaning data generated by electronic meas-
urements of an individual's unique physical characteristics, such as a
fingerprint, voice print, retina or iris image, or other unique physical
representation or digital representation of biometric data which are
used to authenticate or ascertain the individual's identity; or
(6) BIRTHDATES, HOME ADDRESSES, OR PHONE NUMBERS, OR ANY COMBINATION
THEREOF; OR
EXPLANATION--Matter in ITALICS (underscored) is new; matter in brackets
[ ] is old law to be omitted.
LBD03710-01-3
A. 3812 2
(ii) a user name or e-mail address in combination with a password or
security question and answer that would permit access to an online
account.
"Private information" does not include publicly available information
which is lawfully made available to the general public from federal,
state, or local government records.
§ 2. This act shall take effect immediately.