Data Breach Requirements: NY Gen. Bus. § 899-aa.
The numbering and internal citations herein are derived from the applicable state statute.
Personal Information
(a) The term “personal information” shall mean any information concerning a natural person which, because of name, number, personal mark, or other identifier, can be used to identify such natural person.
(b) The term “private information” shall mean either: (i) personal information consisting of any information in combination with any one or more of the following data elements, when either the data element or the combination of personal information plus the data element is not encrypted, or is encrypted with an encryption key that has also been accessed or acquired:
(1) Social Security number;
(2) Driver’s license number or non-driver identification card number;
(3) Account number, credit, or debit card number, in combination with any required security code, access code, password, or other information that would permit access to an individual’s financial account;
(4) Account number, credit, or debit card number, if circumstances exist wherein such number could be used to access an individual’s financial account without additional identifying information, security code, access code, or password; or
(5) Biometric information, meaning data generated by electronic measurements of an individual’s unique physical characteristics, such as a fingerprint, voice print, retina or iris image, or other unique physical representation or digital representation of biometric data that are used to authenticate or ascertain the individual’s identity; or
(ii) a Username or email address in combination with a password or security question and answer that would permit access to an online account.
Security Breach Definition
The term “breach of the security of the system” means unauthorized access to or acquisition of, or access to or acquisition without valid authorization, of computerized data that compromises the security, confidentiality, or integrity of private information maintained by a business.
Good Faith Exception
Good faith access to, or acquisition of, private information by an employee or agent of the business for the purposes of the business is not a breach of the security of the system, provided that the private information is not used or subject to unauthorized disclosure.
Risk of Harm Analysis
A breach notice to affected persons under this section is not required if the exposure of private information was an inadvertent disclosure by persons authorized to access private information, and the person or business reasonably determines such exposure will not likely result in misuse of such information, or financial harm to the affected persons or emotional harm in the case of unknown disclosure of online credentials. Such a determination must be documented in writing and maintained for at least five years. If the incident affects more than 500 residents of New York, the person or business shall provide the written determination to the state attorney general within ten days after the determination.
Notification Timeline
A breach notification shall be made in the most expedient time possible and without unreasonable delay, provided that such notification shall be made within thirty days after the breach has been discovered, except for the legitimate needs of law enforcement as set forth in law.
Security and Investigation Exceptions
The breach notification may be delayed if a law enforcement agency determines that such notification impedes a criminal investigation. The notification shall be made after such law enforcement agency determines that such notification does not compromise such investigation.
Notification Content Requirements
Regardless of the method by which notice is provided, such notice shall include contact information for the person or business making the notification, the telephone numbers and websites of the relevant state and federal agencies that provide information regarding security breach response and identity theft prevention and protection information, and a description of the categories of information that were, or are reasonably believed to have been, accessed or acquired by a person without valid authorization, including specification of which of the elements of personal information and private information were, or are reasonably believed to have been, so accessed or acquired.
Delivery Methods
A breach notice may be provided by one of the following methods:
(a) Written notice;
(b) Electronic notice, provided that the person to whom notice is required has expressly consented to receiving said notice in electronic form and a log of each such notification is kept by the person or business who notifies affected persons in such form. In no case, however, shall any person or business require a person to consent to accepting said notice in said form as a condition of establishing any business relationship or engaging in any transaction;
(c) Telephone notification, provided that a log of each such notification is kept by the person or business who notifies affected persons; or
(d) Substitute notice, if a business demonstrates to the state attorney general that the cost of providing notice would exceed $250,000, or that the affected class of subject persons to be notified exceeds 500,000, or that such business does not have sufficient contact information.
Substitute Notice
Substitute notice shall consist of all of the following:
(1) Email notice when such business has an email address for the subject persons, except if the breached information includes an email address in combination with a password or security question and answer that would permit access to the online account, in which case the person or business shall instead provide clear and conspicuous notice delivered to the consumer online when the consumer is connected to the online account from an internet protocol address or from an online location that the person or business knows the consumer customarily uses to access the online account;
(2) Conspicuous posting of the notice on such business’s website page, if such business maintains one; and
(3) Notification to major statewide media.
Notice to Government Agencies
In the event that any New York residents are to be notified, the person or business shall notify the state attorney general, the department of state, the division of state police, and the department of financial services as to the timing, content and distribution of the notices and approximate number of affected persons and shall provide a copy of the template of the notice sent to affected persons; provided, however, that notice to the department of financial services shall only be required if the person or business is a covered entity, as defined in 23 NYCRR 500.1, and provided further that such notice shall be provided to the department of financial services in compliance with 23 NYCRR 500.17. Such notice shall be made without delaying notice to affected New York residents.
Any covered entity required to provide notification of a breach, including breach of information that is not “private information” to the secretary of Health and Human Services, pursuant to the Health Insurance Portability and Accountability Act of 1996 (HIPAA) or the Health Information Technology for Economic and Clinical Health Act (HITECH), as amended from time to time, shall provide such notification to the state attorney general within five business days of notifying the secretary.
Consumer Reporting Agencies
In the event that more than 5,000 New York residents are to be notified at one time, the person or business shall also notify consumer reporting agencies as to the timing, content, and distribution of the notices and approximate number of affected persons. Such notice shall be made without delaying notice to affected New York residents.
Preemption and Compliance
If the breach notice is made to affected persons pursuant to the breach notification requirements under any of the following laws, nothing shall require any additional notice to those affected persons, but notice still shall be provided to the New York Attorney General, the Department of State, and the relevant division of New York State Police and to consumer reporting agencies:
(i) Regulations promulgated pursuant to Title V of the Gramm-Leach-Bliley Act;
(ii) Regulations implementing HIPAA and HITECH;
(iii) Part 500 of Title 23 of the official Compilation of Rules and Regulations of the State of New York, as amended from time to time; or (iv) Any other data security rules and regulations of, and the statutes administered by, any official department, division, commission, or agency of the federal or New York state government as such rules, regulations, or statutes are interpreted by such department, division, commission, or agency or by the federal or New York state courts.
Data Processor Obligations
Any person or business that maintains computerized data that includes private information that such person or business does not own shall notify the owner or licensee of the information of any breach of the security of the system immediately following discovery, provided that such notification shall be made within thirty days following discovery, if the private information was, or is reasonably believed to have been, accessed or acquired by a person without valid authorization.
Other Information
In determining whether information has been accessed, or is reasonably believed to have been accessed, by an unauthorized person or a person without valid authorization, such business may consider, among other factors, indications that the information was viewed, communicated with, used, or altered by a person without valid authorization or by an unauthorized person.
In determining whether information has been acquired, or is reasonably believed to have been acquired, by an unauthorized person or a person without valid authorization, such business may consider the following factors, among others:
(1) indications that the information is in the physical possession and control of an unauthorized person, such as a lost or stolen computer or other device containing information; or
(2) indications that the information has been downloaded or copied; or (3) indications that the information was used by an unauthorized person, such as fraudulent accounts opened or instances of identity theft reported.
Data Disposal and Security: NY Gen. Bus. §§ 399-h, 899-aa(1)(b), and § 899-bb.
The numbering and internal citations herein are derived from the applicable state statute. See statute for any applicable exceptions or exemptions.
Key Terms
The term “dispose” means to throw out or away or to get rid of and shall not include a sale of a record or the transfer of a record for value.
The term “personal information” means any information concerning a natural person which, because of name, number, personal mark, or other identifier, can be used to identify such natural person.
The term “personal identifying information” means personal information consisting of any information in combination with any one or more of the following data elements, when either the personal information or the data element is not encrypted, or encrypted with an encryption key that is included in the same record as the encrypted personal information or data element:
(i) Social Security number;
(ii) Driver’s license number or non-driver identification card number; or
(iii) Mother’s maiden name, financial services account number or code, savings account number or code, checking account number or code, debit card number or code, automated teller machine number or code, electronic serial number, or personal identification number;
The term “personal identification number” means any number or code that may be used alone or in conjunction with any other information to assume the identity of another person or access financial resources or credit of another person.
Data Disposal
No person, business, firm, partnership, association, or corporation, not including the state or its political subdivisions, shall dispose of a record containing personal identifying information unless the person, business, firm, partnership, association, or corporation, or other person under contract with the business, firm, partnership, association, or corporation does any of the following:
a. Shreds the record before the disposal of the record;
b. Destroys the personal identifying information contained in the record;
c. Modifies the record to make the personal identifying information unreadable; or
d. Takes actions consistent with commonly accepted industry practices that it reasonably believes will ensure that no unauthorized person will have access to the personal identifying information contained in the record.
Other Information
An individual person shall not be required to comply with this subdivision unless he or she is conducting business for profit.
Key Terms
The term “personal information” means any information concerning a natural person which, because of name, number, personal mark, or other identifier, can be used to identify such natural person.
The term “private information” means either: (i) personal information consisting of any information in combination with any one or more of the following data elements, when either the data element or the combination of personal information plus the data element is not encrypted, or is encrypted with an encryption key that has also been accessed or acquired:
(1) Social Security number;
(2) Driver’s license number or non-driver identification card number;
(3) Account, credit, or debit card number, in combination with any required security code, access code, password, or other information that would permit access to an individual’s financial account;
(4) Account, credit, or debit card number, if circumstances exist wherein such number could be used to access an individual’s financial account without additional identifying information, security code, access code, or password; or
(5) Biometric information, meaning data generated by electronic measurements of an individual’s unique physical characteristics, such as a fingerprint, voice print, retina or iris image, or other unique physical representation, or digital representation of biometric data that are used to authenticate or ascertain the individual’s identity; or
(ii) Username or email address in combination with a password or security question and answer that would permit access to an online account.
The term “compliant regulated entity” shall mean any person or business that is subject to, and in compliance with, any of the following data security requirements:
(i) Regulations promulgated pursuant to Title V of the federal Gramm-Leach-Bliley Act;
(ii) Regulations implementing the Health Insurance Portability and Accountability Act of 1996, and the Health Information Technology for Economic and Clinical Health Act (HITECH), as amended from time to time;
(iii) Part 500 of title 23 of the official compilation of codes, rules and regulations of the state of New York, as amended from time to time; or
(iv) Any other data security rules and regulations of, and the statutes administered by, any official department, division, commission or agency of the federal or New York state government as such rules, regulations, or statutes are interpreted by such department, division, commission, or agency or by the federal or New York state courts.
The term “small business” means any person or business with (i) fewer than 50 employees; (ii) less than $3,000,000 in gross annual revenue in each of the last three fiscal years; or (iii) less than $5,000,000 in year-end total assets, calculated in accordance with generally accepted accounting principles.
Security Requirements
(a) Any person or business that owns or licenses computerized data which includes private information of a resident of New York shall develop, implement, and maintain reasonable safeguards to protect the security, confidentiality, and integrity of the private information including, but not limited to, disposal of data.
(b) A person or business shall be deemed to be in compliance with paragraph (a) of this subdivision if it either: (i) is a compliant-regulated entity as defined in subdivision one of this section; or (ii) implements a data security program that includes the following:
(A) Reasonable administrative safeguards such as the following, in which the person or business:
(1) Designates one or more employees to coordinate the security program;
(2) Identifies reasonably foreseeable internal and external risks;
(3) Assesses the sufficiency of safeguards in place to control the identified risks;
(4) Trains and manages employees in the security program practices and procedures;
(5) Selects service providers capable of maintaining appropriate safeguards, and requires those safeguards by contract; and
(6) Adjusts the security program in light of business changes or new circumstances; and
(B) Reasonable technical safeguards such as the following, in which the person or business:
(1) Assesses risks in network and software design;
(2) Assesses risks in information processing, transmission, and storage;
(3) Detects, prevents, and responds to attacks or system failures; and
(4) Regularly tests and monitors the effectiveness of key controls, systems, and procedures; and
(C) Reasonable physical safeguards such as the following, in which the person or business:
(1) Assesses risks of information storage and disposal;
(2) Detects, prevents and responds to intrusions;
(3) Protects against unauthorized access to or use of private information during or after the collection, transportation, and destruction or disposal of the information; and
(4) Disposes of private information within a reasonable amount of time after it is no longer needed for business purposes by erasing electronic media so that the information cannot be read or reconstructed.
Other Information
A small business complies with these requirements if the small business’s security program contains reasonable administrative, technical, and physical safeguards that are appropriate for the size and complexity of the small business, the nature and scope of the small business’s activities, and the sensitivity of the personal information the small business collects from or about consumers.