S T A T E O F N E W Y O R K
________________________________________________________________________
9540
I N S E N A T E
May 16, 2024
___________
Introduced by Sen. SKOUFIS -- read twice and ordered printed, and when
printed to be committed to the Committee on Consumer Protection
AN ACT to amend the general business law, in relation to prohibiting
data brokers from selling the personal information of current and
former military servicemembers
THE PEOPLE OF THE STATE OF NEW YORK, REPRESENTED IN SENATE AND ASSEM-
BLY, DO ENACT AS FOLLOWS:
Section 1. The general business law is amended by adding a new section
399-jj to read as follows:
§ 399-JJ. SALE OF PERSONAL INFORMATION OF SERVICEMEMBERS. 1. AS USED
IN THIS SECTION:
(A) "CONSENT" MEANS A CLEAR AFFIRMATIVE ACT SIGNIFYING A FREELY GIVEN,
SPECIFIC, INFORMED, AND UNAMBIGUOUS INDICATION OF A CONSUMER'S AGREEMENT
TO THE PROCESSING OF DATA RELATING TO THE CONSUMER. CONSENT MAY BE WITH-
DRAWN AT ANY TIME, AND A CONTROLLER MUST PROVIDE CLEAR, CONSPICUOUS, AND
CONSUMER-FRIENDLY MEANS TO WITHDRAW CONSENT. THE BURDEN OF ESTABLISHING
CONSENT IS ON THE CONTROLLER. CONSENT DOES NOT INCLUDE: (I) AN AGREEMENT
OF GENERAL TERMS OF USE OR A SIMILAR DOCUMENT THAT REFERENCES UNRELATED
INFORMATION IN ADDITION TO PERSONAL DATA PROCESSING; (II) AN AGREEMENT
OBTAINED THROUGH FRAUD, DECEIT OR DECEPTION; (III) ANY ACT THAT DOES NOT
CONSTITUTE A USER'S INTENT TO INTERACT WITH ANOTHER PARTY SUCH AS HOVER-
ING OVER, PAUSING OR CLOSING ANY CONTENT; OR (IV) A PRE-CHECKED BOX OR
SIMILAR DEFAULT.
(B) "CONSUMER" MEANS A NATURAL PERSON WHO IS A NEW YORK RESIDENT
ACTING ONLY IN AN INDIVIDUAL OR HOUSEHOLD CONTEXT. IT DOES NOT INCLUDE A
NATURAL PERSON KNOWN TO BE ACTING IN A PROFESSIONAL OR EMPLOYMENT
CONTEXT.
(C) "DATA BROKER" MEANS A PERSON, OR UNIT OR UNITS OF A LEGAL ENTITY,
SEPARATELY OR TOGETHER, THAT DOES BUSINESS IN THE STATE OF NEW YORK AND
KNOWINGLY COLLECTS, AND SELLS TO OTHER CONTROLLERS OR THIRD PARTIES, THE
PERSONAL DATA OF A CONSUMER WITH WHOM IT DOES NOT HAVE A DIRECT
RELATIONSHIP. "DATA BROKER" DOES NOT INCLUDE ANY OF THE FOLLOWING:
(I) A CONSUMER REPORTING AGENCY TO THE EXTENT THAT IT IS COVERED BY
THE FEDERAL FAIR CREDIT REPORTING ACT (15 U.S.C. SEC. 1681 ET SEQ.); OR
EXPLANATION--Matter in ITALICS (underscored) is new; matter in brackets
[ ] is old law to be omitted.
LBD13849-01-3
S. 9540 2
(II) A FINANCIAL INSTITUTION TO THE EXTENT THAT IT IS COVERED BY THE
GRAMM-LEACH-BLILEY ACT (PUBLIC LAW 106-102) AND IMPLEMENTING REGU-
LATIONS.
(D) "HOUSEHOLD" MEANS A GROUP, HOWEVER IDENTIFIED, OF CONSUMERS WHO
COHABITATE WITH ONE ANOTHER AT THE SAME RESIDENTIAL ADDRESS AND MAY
SHARE USE OF COMMON DEVICES OR SERVICES.
(E) "MILITARY SERVICEMEMBER" MEANS A PERSON WHO IS SERVING OR HAS
SERVED:
(I) ON ACTIVE DUTY IN THE ARMY, NAVY, MARINE CORPS, AIR FORCE, SPACE
FORCE, OR COAST GUARD OF THE UNITED STATES;
(II) IN THE ARMY NATIONAL GUARD OR AIR NATIONAL GUARD;
(III) AS A COMMISSIONED OFFICER IN THE PUBLIC HEALTH SERVICE OR OF THE
NATIONAL OCEANIC AND ATMOSPHERIC ADMINISTRATION OR ENVIRONMENTAL
SCIENCES SERVICES ADMINISTRATION; OR
(IV) AS A CADET AT A UNITED STATES ARMED FORCES SERVICE ACADEMY.
(F) "MILITARY SERVICEMEMBER LIST" MEANS A LIST THAT INCLUDES PERSONAL
INFORMATION, OTHER THAN PUBLIC RECORD INFORMATION, ABOUT ONE OR MORE
INDIVIDUALS OR HOUSEHOLDS WHICH IS CREATED FOR THE EXPRESS OR IMPLIED
PURPOSE OF COMPILING INFORMATION ABOUT INDIVIDUALS WHO ARE CURRENT OR
FORMER SERVICEMEMBERS.
(G) "PERSONAL DATA" MEANS ANY DATA THAT IDENTIFIES OR COULD REASONABLY
BE LINKED, DIRECTLY OR INDIRECTLY, WITH A SPECIFIC NATURAL PERSON, OR
HOUSEHOLD. PERSONAL DATA DOES NOT INCLUDE DEIDENTIFIED DATA, INFORMATION
THAT IS LAWFULLY MADE PUBLICLY AVAILABLE FROM FEDERAL, STATE OR LOCAL
GOVERNMENT RECORDS, OR INFORMATION THAT A CONTROLLER HAS A REASONABLE
BASIS TO BELIEVE IS LAWFULLY MADE AVAILABLE TO THE GENERAL PUBLIC BY THE
CONSUMER OR FROM WIDELY DISTRIBUTED MEDIA.
(H) "SELL" MEANS SELLING, RESELLING, DISCLOSING, TRANSFERRING, CONVEY-
ING, SHARING, LICENSING, TRADING, MAKING AVAILABLE, PROCESSING, GRANTING
OF PERMISSION OR AUTHORIZATION TO PROCESS, OR OTHERWISE EXCHANGING OR
PROVIDING ACCESS TO PERSONAL DATA FOR MONETARY OR OTHER VALUABLE CONSID-
ERATION. "SELL" INCLUDES ENABLING, FACILITATING OR PROVIDING ACCESS TO
PERSONAL DATA FOR TARGETED ADVERTISING. "SELL" DOES NOT INCLUDE THE
FOLLOWING:
(I) THE DISCLOSURE OF DATA TO A PROCESSOR WHO PROCESSES THE DATA ON
BEHALF OF THE CONTROLLER AND WHICH IS CONTRACTUALLY PROHIBITED FROM
USING IT FOR ANY PURPOSE OTHER THAN AS INSTRUCTED BY THE CONTROLLER;
(II) THE DISCLOSURE OR TRANSFER OF DATA AS AN ASSET THAT IS PART OF A
MERGER, ACQUISITION, BANKRUPTCY, OR OTHER TRANSACTION IN WHICH ANOTHER
ENTITY ASSUMES CONTROL OR OWNERSHIP OF ALL OR A MAJORITY OF THE CONTROL-
LER'S ASSETS; OR
(III) THE DISCLOSURE OF PERSONAL DATA TO A THIRD PARTY NECESSARY FOR
PURPOSES OF PROVIDING A PRODUCT, SERVICE, OR INTERACTION WITH SUCH THIRD
PARTY, WHEN THE CONSUMER INTENTIONALLY AND UNAMBIGUOUSLY REQUESTS SUCH
DISCLOSURE.
2. IT SHALL BE UNLAWFUL FOR A DATA BROKER KNOWINGLY OR RECKLESSLY TO
SELL A MILITARY SERVICEMEMBER LIST OR PERSONAL DATA ABOUT ANY MILITARY
SERVICEMEMBER WITHOUT CONSENT FROM SUCH MILITARY SERVICEMEMBERS.
3. THIS SECTION APPLIES TO LEGAL PERSONS THAT CONDUCT BUSINESS IN NEW
YORK OR PRODUCE PRODUCTS OR SERVICES THAT ARE TARGETED TO RESIDENTS OF
NEW YORK.
§ 2. This act shall take effect on the ninetieth day after it shall
have become a law.