In December 2024, New York Governor Kathy Hochul signed two bills amending the state’s current data breach notification law. Senate Bill S2659B and Assembly Bill A8872A aim to strengthen data breach notification requirements, enhance transparency, safeguard consumer data, and hold businesses accountable for breaches. These amendments apply to New York’s previous data breach notification law, expanding the defined qualifications of what is considered a notifiable data breach and establishing more specific guidelines for notifying consumers and government agencies of these breaches.
S2376B is in effect as of March 21, 2025. It focuses on broadening the categories of qualified private information that businesses are required to address if a data breach occurs.
To read the full details of the amendments to New York’s data breach notification law, take a closer look here.
Previously, businesses had no specific timeframe other than being required to notify affected individuals “in the most expedient time possible and without unreasonable delay.” A8872A adds a timeframe and reporting process businesses are obligated to follow in case of a data breach.
Take a closer look here to see the full text and amendments regarding reporting requirements and timelines.
The Attorney General is tasked with making sure organizations follow the notification requirements. Meanwhile, the DFS will monitor financial institutions and related entities to ensure they meet the new notification standards. Entities that fail to comply with the updated reporting requirements are subject to facing legal action, including fines and penalties, as outlined in New York's General Business Law.
All states currently have pre-existing laws requiring businesses to notify consumers in the case of a data breach, but they vary substantially. New York’s amendments to their existing focus on consumer protections, expanding the definition of what qualifies as private information and setting a stricter timeline for notifying consumers and government agencies of a data breach, could potentially set a precedent for other states to reconsider their existing consumer data restrictions and breach reporting policies. As laws that dictate consumer laws, privacy, and reporting continue to evolve, Verified Credentials will try to provide updates as they become available.
This article is for informational purposes only and does not constitute legal advice or official predictions of future laws and regulations. Hiring professionals, HR professionals, and administrators should consult their legal counsel to ensure all actions comply with the law.