•  Summary 
  •  
  •  Actions 
  •  
  •  Committee Votes 
  •  
  •  Floor Votes 
  •  
  •  Memo 
  •  
  •  Text 
  •  
  •  LFIN 
  •  
  •  Chamber Video/Transcript 

A01157 Summary:

BILL NOA01157
 
SAME ASNo Same As
 
SPONSORSantabarbara
 
COSPNSRSchiavoni
 
MLTSPNSR
 
Amd §899-aa, Gen Bus L
 
Relates to imposing a five-day time limit during which to disclose a breach in the security of a system.
Go to top    

A01157 Actions:

BILL NOA01157
 
01/09/2025referred to consumer affairs and protection
Go to top

A01157 Text:



 
                STATE OF NEW YORK
        ________________________________________________________________________
 
                                          1157
 
                               2025-2026 Regular Sessions
 
                   IN ASSEMBLY
 
                                     January 9, 2025
                                       ___________
 
        Introduced  by  M.  of  A. SANTABARBARA -- read once and referred to the
          Committee on Consumer Affairs and Protection
 
        AN ACT to amend the general business law, in relation to  disclosure  of
          breaches of the security of the system
 
          The  People of the State of New York, represented in Senate and Assem-
        bly, do enact as follows:
 
     1    Section 1. The opening paragraph of subdivision 2 of section 899-aa of
     2  the general business law, as amended by chapter 647 of the laws of 2024,
     3  is amended to read as follows:
     4    Any person or business which owns or licenses computerized data  which
     5  includes  private  information shall disclose any breach of the security
     6  of the system [following] within five days of the discovery or notifica-
     7  tion of the breach in the security of the system to any resident of  New
     8  York  state  whose private information was, or is reasonably believed to
     9  have been, accessed or acquired by a person without valid authorization.
    10  [The disclosure shall be made in the most expedient  time  possible  and
    11  without  unreasonable  delay,  provided  that such notification shall be
    12  made within thirty days after the breach has been discovered, except for
    13  the legitimate needs of law enforcement, as provided in subdivision four
    14  of this section.]
    15    § 2. This act shall take effect immediately.
 
 
 
 
         EXPLANATION--Matter in italics (underscored) is new; matter in brackets
                              [ ] is old law to be omitted.
                                                                   LBD03501-01-5
Go to top