S T A T E O F N E W Y O R K
________________________________________________________________________
5239
2025-2026 Regular Sessions
I N A S S E M B L Y
February 12, 2025
___________
Introduced by M. of A. K. BROWN -- read once and referred to the Commit-
tee on Governmental Operations
AN ACT to amend the state technology law, in relation to increasing
security on digital submissions to the state
THE PEOPLE OF THE STATE OF NEW YORK, REPRESENTED IN SENATE AND ASSEM-
BLY, DO ENACT AS FOLLOWS:
Section 1. The state technology law is amended by adding a new section
106-c to read as follows:
§ 106-C. DIGITAL SUBMISSIONS TO THE STATE. ANY STATE AGENCY, BOARD,
BUREAU, AUTHORITY, COMMISSION, DIVISION, OR OTHER GOVERNMENTAL ENTITY
PERFORMING A GOVERNMENTAL OR PROPRIETARY FUNCTION FOR THE STATE THAT
ALLOWS FOR THE DIGITAL SUBMISSION OF INFORMATION TO SUCH GOVERNMENTAL
ENTITY SHALL REQUIRE A PERSON TO CREATE AN ACCOUNT WITH THE GOVERNMENTAL
ENTITY THROUGH WHICH THE DIGITAL SUBMISSION CAN BE MADE. SUCH ACCOUNT
SHALL HAVE THE FOLLOWING SECURITY FEATURES:
1. VERIFIED ACCOUNT. (A) TO CREATE AN ACCOUNT, A USER SHALL PROVIDE
AND CONFIRM THE FOLLOWING INFORMATION:
(I) THE USER'S FULL NAME;
(II) THE USER'S PHYSICAL RESIDENTIAL ADDRESS;
(III) THE USER'S DATE OF BIRTH;
(IV) AT LEAST TWO OF THE FOLLOWING:
(A) THE USER'S SOCIAL SECURITY NUMBER;
(B) THE USER'S DRIVER'S LICENSE NUMBER;
(C) THE USER'S UNITED STATES PASSPORT NUMBER;
(D) THE USER'S TAXPAYER IDENTIFICATION NUMBER; OR
(E) ANY OTHER FORM OF IDENTIFICATION ISSUED BY A GOVERNMENTAL ENTITY
APPROVED BY THE OFFICE; AND
(V) THE USER'S EMAIL ADDRESS OR TELEPHONE NUMBER.
(B) THE USER'S ACCOUNT SHALL HAVE A UNIQUE USERNAME CHOSEN BY THE USER
USING RULES APPROVED BY THE OFFICE.
EXPLANATION--Matter in ITALICS (underscored) is new; matter in brackets
[ ] is old law to be omitted.
LBD08052-01-5
A. 5239 2
(C) THE GOVERNMENTAL ENTITY SHALL VALIDATE THE INFORMATION PROVIDED BY
THE USER TO CREATE SUCH ACCOUNT IS ACCURATE.
2. MULTI-FACTOR AUTHORIZATION. TO ACCESS AN ACCOUNT MADE UNDER SUBDI-
VISION ONE OF THIS SECTION, A USER SHALL BE REQUIRED TO USE THE USER'S
USERNAME AND TWO OF THE FOLLOWING METHODS OF AUTHENTICATION TO VERIFY
SUCH USER'S IDENTITY:
(A) A PASSWORD;
(B) ANSWERS TO PREVIOUSLY PROVIDED SECURITY QUESTIONS;
(C) BIOMETRIC DATA, INCLUDING FINGERPRINT, FACIAL OR VOICE RECOGNI-
TION;
(D) AN AUTHORIZATION CODE SENT BY PHONE CALL, TEXT MESSAGE OR EMAIL TO
THE APPROPRIATE CONTACT INFORMATION PROVIDED; OR
(E) ANY OTHER AUTHORIZATION TYPES APPROVED BY THE OFFICE.
§ 2. This act shall take effect one year after it shall have become a
law. Effective immediately, the addition, amendment and/or repeal of any
rule or regulation necessary for the implementation of this act on its
effective date are authorized to be made and completed on or before such
effective date.