SlideShare uma empresa Scribd logo
1 de 3
Baixar para ler offline
What to expect from the
New York Privacy Act
In the recently proposed bill of the New York Privacy Act in the House and Senate, businesses may soon
have to gear up for this new data privacy law. If enforced, the law may severely impact businesses,
restricting their operations in the way how they collect, use and share consumer’s personal information
throughout the State.
Earlier to this, a similar bill was introduced in the last legislative session but had failed to pass in the
assembly. However, with New York Privacy Act now re-introduce in a more refined version. This bill
should be closely watched by the industry as it moves through the legislative process. The New York
Privacy Act is very similar to California’s Consumer Privacy Act (CCPA) but is more expansive in its
approach and requirements. The regulation if enforced will provide consumers with much greater control
over their personal information, and make businesses more accountable for their operations and
business processes.
In today’s article, we have covered details on the proposed New York Privacy Act bill and its possible
impact on businesses. So, before summarizing the proposed bill let us first understand what the
Regulation is all about.
What is the New York Privacy Act?
The proposed New York Privacy Act is a law which if enforced will apply to a wide range of businesses. It
is an Act that may apply to entities that conduct business in New York pertaining to personal information
of residents of New York State. While there are exceptions for the state and local governments, but the
law may apply to all private entities (including non-profits) subject to the requirements.
The proposed NY Privacy Law mirrors various other Privacy regulations like the California Consumer
Privacy Act (“CCPA”) and the EU’s General Data Privacy Regulation (“GDPR”). This would be in line with
consumer’s right to request for businesses to correct any inaccurate personal information or delete the
personal information held with them.
What does the proposed New York Privacy Act say about Consumer Rights, Consent, & Business
obligations?
Data Subjects
Data subjects or consumers are defined as “a natural person who is a New York resident.” Employees
and contractors are specifically excluded from the definition of consumer. Job applicants are not explicitly
excluded from the definition of consumer, however, “data sets maintained for employment records
purposes” are excluded. Again there is no “business-to-business” exemption.
Personal Information-
The New York Privacy Act broadly defines personal data and excludes only de-identified or publicly
available data from this law.
Business in Scope
Similar to the GDPR and CCPA Regulation, the scope of NYPA is quite broad. It would apply to any legal
entity that conducted business in the New York States or Businesses that produce or provide services
that are intentionally targeted to residents of New York State. However, there are no thresh holds set on
revenue or minimum amounts of personal data a company processes to be subject to the law. Further, it
is important to note that there is no exemption for individuals or non-profit organizations but purely
household activities are exempted from the law.
Business Obligation
The NYPA law creates a fiduciary obligation on the businesses to abide by the law and act in a way that
benefits data subjects of whom they collect store or process personal data. This would simply mean that
businesses will be held to a higher standard of compliance for the data collected and used of data
subjects. It would also mean that businesses must act in the best interest of their consumers irrespective
of it not being in the best interest of their business.
Consumer Consent-
Speaking about consumer consent, the Act clearly states that businesses will require consumers to
provide “specific, informed and unambiguous” consent before they process or use their personal data.
Businesses will have to obtain consumer’s consent specific to each intended use of their data. They
would further require consumer-specific consent for each intended third-party receiving the data. Again
for businesses in the marketing space will require separate checkboxes for each of their respective
marketing partners.
Consumer Rights-
The proposed privacy act which is very similar to the CCPA and the GDPR provides consumers the right
to access, rectification/correction, deletion, restriction of processing, and portability. Businesses are
expected to act upon the request of the consumers without any undue delay. They are also expected to
take “reasonable steps” to inform third parties about the consumer’s request.
Violation & Fines–
The NYPA law specifies that a consumer who suffers a loss may recover statutory damages of $1,000 or
more or actual damages, and $3,000 or actual damages for an intentional violation. However, the law
limits the scope of recovery to violations of the Act in the form of injunctive relief and actual
damages. This means that the consumer must prove that they suffered a loss due to the failure of
© VISTA InfoSec ®
© VISTA InfoSec ®
© VISTA InfoSec ®
business to comply with the NYPA to be able to recover. Further, any person who is aware, based on
non-public information, that a person or business has violated this section may file a civil action for civil
penalties. This provision would allow for suits to be filed by competitors, vendors, and consumer groups
based on violations of the law.
What Should Businesses Do?
The New York Privacy Act is still a proposed bill and not a legislation in effect that has passed the
assembly. Further, as the law moves through the legislative process, businesses can expect
amendments in the law. Businesses should have a close watch over the legislative process to see how
and when the law comes into effect. But, this brings us to a very common question asked by most
businesses as to how should they approach the data privacy law going forward.
Ideally, an organization should initially start with conducting the basic assessment of their operations to
identify the kind of data collected and classify them based on their level of sensitivity. Understanding
what data is collected, processed, and identify the law that impacts the data is the key to your compliance
journey.
Once your business gains a basic understanding, the road ahead will be much easier for establishing a
privacy program that fits with your organizational blueprint. Waiting for the legislation to come into effect
isn’t really an option. For your business to stay ahead of the curve and gain a better business stand-point
preparation for the law is what is advisable.
After all, be it the GDPR Regulation CCPA or the proposed New York Privacy Act all of the regulations
are more or less similar and are established with the common agenda of protecting the rights and privacy
of consumer’s personal data. So, the faster and earlier your organization takes steps towards initiating a
data privacy program, the better it is for them at the later stage for achieving compliance. Your business
will be in a far better position to deal with any such data privacy regulation that comes into effect in the
future.
facebook.com/vistainfosec/ in.linkedin.com/company/vistainfosec twitter.com/VISTAINFOSEC
Dowritetousyourfeedback,commentsandqueriesor,ifyouhaveanyrequirements:
info@vistainfosec.com
You can reach us on:
USA
+1-415-513 5261
INDIA
+91 73045 57744
SINGAPORE
+65-3129-0397

Mais conteúdo relacionado

Mais procurados

EC2017 United Kingdom
EC2017  United KingdomEC2017  United Kingdom
EC2017 United Kingdom
Robert Bond
 

Mais procurados (17)

California Consumer Protection Act - Insight from Sia Partners
California Consumer Protection Act - Insight from Sia Partners California Consumer Protection Act - Insight from Sia Partners
California Consumer Protection Act - Insight from Sia Partners
 
Second Verse, Different from the First.
Second Verse, Different from the First. Second Verse, Different from the First.
Second Verse, Different from the First.
 
Silicon Valley companies will receive more freedom to disclose data requests ...
Silicon Valley companies will receive more freedom to disclose data requests ...Silicon Valley companies will receive more freedom to disclose data requests ...
Silicon Valley companies will receive more freedom to disclose data requests ...
 
California Consumer Protection Act - Insight from Sia Partners
California Consumer Protection Act - Insight from Sia Partners California Consumer Protection Act - Insight from Sia Partners
California Consumer Protection Act - Insight from Sia Partners
 
*Webinar* CCPA: Get Your Business Ready
*Webinar* CCPA: Get Your Business Ready*Webinar* CCPA: Get Your Business Ready
*Webinar* CCPA: Get Your Business Ready
 
Professional issues in IT
Professional issues in IT Professional issues in IT
Professional issues in IT
 
Legal Technology 3.0 | Oliver R. Goodenough
Legal Technology 3.0 | Oliver R. GoodenoughLegal Technology 3.0 | Oliver R. Goodenough
Legal Technology 3.0 | Oliver R. Goodenough
 
California Consumer Privacy Act (CCPA): Countdown to Compliance
California Consumer Privacy Act (CCPA): Countdown to ComplianceCalifornia Consumer Privacy Act (CCPA): Countdown to Compliance
California Consumer Privacy Act (CCPA): Countdown to Compliance
 
Data privacy presentation
Data privacy presentationData privacy presentation
Data privacy presentation
 
HIPAA Privacy, Security, Breach Overview
HIPAA Privacy, Security, Breach OverviewHIPAA Privacy, Security, Breach Overview
HIPAA Privacy, Security, Breach Overview
 
Dpl november colombia
Dpl november   colombiaDpl november   colombia
Dpl november colombia
 
GDPR Whitepaper
GDPR WhitepaperGDPR Whitepaper
GDPR Whitepaper
 
EC2017 United Kingdom
EC2017  United KingdomEC2017  United Kingdom
EC2017 United Kingdom
 
A Brave New World Of Data Protection. Ready? Counting down to GDPR.
A Brave New World Of Data Protection. Ready? Counting down to GDPR. A Brave New World Of Data Protection. Ready? Counting down to GDPR.
A Brave New World Of Data Protection. Ready? Counting down to GDPR.
 
How to Protect Your Data
How to Protect Your DataHow to Protect Your Data
How to Protect Your Data
 
CCPA Webinar: Amendments, Proposed Regulations, New Ballot Initiative, and R...
CCPA Webinar:  Amendments, Proposed Regulations, New Ballot Initiative, and R...CCPA Webinar:  Amendments, Proposed Regulations, New Ballot Initiative, and R...
CCPA Webinar: Amendments, Proposed Regulations, New Ballot Initiative, and R...
 
Privacy and Data Protection CLE Presentation for Touro Law Center
Privacy and Data Protection CLE Presentation for Touro Law CenterPrivacy and Data Protection CLE Presentation for Touro Law Center
Privacy and Data Protection CLE Presentation for Touro Law Center
 

Semelhante a What to expect from the New York Privacy Act

Cybersecurity, Privacy and Data Security from a Business Lawyer's Perspective
Cybersecurity, Privacy and Data Security from a Business Lawyer's PerspectiveCybersecurity, Privacy and Data Security from a Business Lawyer's Perspective
Cybersecurity, Privacy and Data Security from a Business Lawyer's Perspective
Data Con LA
 

Semelhante a What to expect from the New York Privacy Act (20)

California-Privacy-Right-Act.pdf
California-Privacy-Right-Act.pdfCalifornia-Privacy-Right-Act.pdf
California-Privacy-Right-Act.pdf
 
Sia Partners_CCPA 2018_The American GDPR
Sia Partners_CCPA 2018_The American GDPRSia Partners_CCPA 2018_The American GDPR
Sia Partners_CCPA 2018_The American GDPR
 
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
Cybersecurity & Data Privacy 2020 - Introduction to US Privacy and Data Secur...
 
The principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - ukThe principles of the Data Protection Act in detail - uk
The principles of the Data Protection Act in detail - uk
 
California consumer privacy act and its impact on california employers
California consumer privacy act and its impact on california employersCalifornia consumer privacy act and its impact on california employers
California consumer privacy act and its impact on california employers
 
Horner Downey & Co Newsletter- GDPR
Horner Downey & Co Newsletter- GDPRHorner Downey & Co Newsletter- GDPR
Horner Downey & Co Newsletter- GDPR
 
CCPA Compliance Vs CPRA Compliance.pdf
CCPA Compliance Vs CPRA Compliance.pdfCCPA Compliance Vs CPRA Compliance.pdf
CCPA Compliance Vs CPRA Compliance.pdf
 
Introduction to US Privacy and Data Security Regulations and Requirements (Se...
Introduction to US Privacy and Data Security Regulations and Requirements (Se...Introduction to US Privacy and Data Security Regulations and Requirements (Se...
Introduction to US Privacy and Data Security Regulations and Requirements (Se...
 
Cybersecurity, Privacy and Data Security from a Business Lawyer's Perspective
Cybersecurity, Privacy and Data Security from a Business Lawyer's PerspectiveCybersecurity, Privacy and Data Security from a Business Lawyer's Perspective
Cybersecurity, Privacy and Data Security from a Business Lawyer's Perspective
 
Introduction to US Privacy and Data Security: Regulations and Requirements
Introduction to US Privacy and Data Security: Regulations and RequirementsIntroduction to US Privacy and Data Security: Regulations and Requirements
Introduction to US Privacy and Data Security: Regulations and Requirements
 
What are the new laws under Canada Digital Privacy Act.pdf
What are the new laws under Canada Digital Privacy Act.pdfWhat are the new laws under Canada Digital Privacy Act.pdf
What are the new laws under Canada Digital Privacy Act.pdf
 
Legislation
LegislationLegislation
Legislation
 
Driving change
Driving changeDriving change
Driving change
 
So Many States, So Many Privacy Laws: US State Privacy Law Update
So Many States, So Many Privacy Laws: US State Privacy Law UpdateSo Many States, So Many Privacy Laws: US State Privacy Law Update
So Many States, So Many Privacy Laws: US State Privacy Law Update
 
Week5 paper-susbauer
Week5 paper-susbauerWeek5 paper-susbauer
Week5 paper-susbauer
 
SECTOR-SPECIFIC-REGULATIONS-AND-A-FEW-HICCUPS-MORE-U.S.A-AND-ITS-PRIVACY-LAWS...
SECTOR-SPECIFIC-REGULATIONS-AND-A-FEW-HICCUPS-MORE-U.S.A-AND-ITS-PRIVACY-LAWS...SECTOR-SPECIFIC-REGULATIONS-AND-A-FEW-HICCUPS-MORE-U.S.A-AND-ITS-PRIVACY-LAWS...
SECTOR-SPECIFIC-REGULATIONS-AND-A-FEW-HICCUPS-MORE-U.S.A-AND-ITS-PRIVACY-LAWS...
 
Bahrain-Personal-Data-Protection-Law.pdf
Bahrain-Personal-Data-Protection-Law.pdfBahrain-Personal-Data-Protection-Law.pdf
Bahrain-Personal-Data-Protection-Law.pdf
 
I D Theft Employee Presentation2
I D Theft Employee Presentation2I D Theft Employee Presentation2
I D Theft Employee Presentation2
 
Ten Laws Internet Businesses Should Consider Part II
Ten Laws Internet Businesses Should Consider Part IITen Laws Internet Businesses Should Consider Part II
Ten Laws Internet Businesses Should Consider Part II
 
How to get your business GDPR ready
How to get your business GDPR readyHow to get your business GDPR ready
How to get your business GDPR ready
 

Mais de VISTA InfoSec

6 Amazing Key Elements To Consider The PCI DSS Card Data Discovery Process
6 Amazing Key Elements To Consider The PCI DSS Card Data Discovery Process6 Amazing Key Elements To Consider The PCI DSS Card Data Discovery Process
6 Amazing Key Elements To Consider The PCI DSS Card Data Discovery Process
VISTA InfoSec
 

Mais de VISTA InfoSec (20)

Future of Data Privacy Examining the Impact of GDPR and CPRA on Business Prac...
Future of Data Privacy Examining the Impact of GDPR and CPRA on Business Prac...Future of Data Privacy Examining the Impact of GDPR and CPRA on Business Prac...
Future of Data Privacy Examining the Impact of GDPR and CPRA on Business Prac...
 
HIPAA Compliance Checklist 2022
HIPAA Compliance Checklist 2022HIPAA Compliance Checklist 2022
HIPAA Compliance Checklist 2022
 
SOC2 Advisory and Attestation
SOC2 Advisory and AttestationSOC2 Advisory and Attestation
SOC2 Advisory and Attestation
 
What is expected from an organization under NCA ECC Compliance?
What is expected from an organization under NCA ECC Compliance?What is expected from an organization under NCA ECC Compliance?
What is expected from an organization under NCA ECC Compliance?
 
Webinar - PCI DSS Merchant Levels validations and applicable
Webinar - PCI DSS Merchant Levels validations and applicableWebinar - PCI DSS Merchant Levels validations and applicable
Webinar - PCI DSS Merchant Levels validations and applicable
 
Webinar - pci dss 4.0 updates
Webinar - pci dss 4.0 updates Webinar - pci dss 4.0 updates
Webinar - pci dss 4.0 updates
 
Webinar - PCI PIN, PCI cryptography & key management
Webinar - PCI PIN, PCI cryptography & key managementWebinar - PCI PIN, PCI cryptography & key management
Webinar - PCI PIN, PCI cryptography & key management
 
Reducing cardholder data footprint with tokenization and other techniques
Reducing cardholder data footprint with tokenization and other techniquesReducing cardholder data footprint with tokenization and other techniques
Reducing cardholder data footprint with tokenization and other techniques
 
Guide on ISO 27001 Controls
Guide on ISO 27001 ControlsGuide on ISO 27001 Controls
Guide on ISO 27001 Controls
 
Are Mobile Banking Apps Safe?
Are Mobile Banking Apps Safe?Are Mobile Banking Apps Safe?
Are Mobile Banking Apps Safe?
 
Why should I do SOC2?
Why should I do SOC2?Why should I do SOC2?
Why should I do SOC2?
 
What is GDPR Data Flow Mapping
What is GDPR Data Flow MappingWhat is GDPR Data Flow Mapping
What is GDPR Data Flow Mapping
 
What is a Firewall Risk Assessment?
What is a Firewall Risk Assessment?What is a Firewall Risk Assessment?
What is a Firewall Risk Assessment?
 
Which SOC Report Do I need?
Which SOC Report Do I need?Which SOC Report Do I need?
Which SOC Report Do I need?
 
Key additions and amendments introduced under the CPRA
Key additions and amendments introduced under the CPRAKey additions and amendments introduced under the CPRA
Key additions and amendments introduced under the CPRA
 
6 Amazing Key Elements To Consider The PCI DSS Card Data Discovery Process
6 Amazing Key Elements To Consider The PCI DSS Card Data Discovery Process6 Amazing Key Elements To Consider The PCI DSS Card Data Discovery Process
6 Amazing Key Elements To Consider The PCI DSS Card Data Discovery Process
 
SOC 2 Type 1 Vs. Type 2: Do You Really Need It? This Will Help You Decide!
SOC 2 Type 1 Vs. Type 2: Do You Really Need It? This Will Help You Decide! SOC 2 Type 1 Vs. Type 2: Do You Really Need It? This Will Help You Decide!
SOC 2 Type 1 Vs. Type 2: Do You Really Need It? This Will Help You Decide!
 
Why is gdpr essential for small businesses with links
Why is gdpr essential for small businesses with linksWhy is gdpr essential for small businesses with links
Why is gdpr essential for small businesses with links
 
Pci dss scoping and segmentation with links converted-converted
Pci dss scoping and segmentation with links converted-convertedPci dss scoping and segmentation with links converted-converted
Pci dss scoping and segmentation with links converted-converted
 
Soc 2 vs iso 27001 certification withh links converted-converted
Soc 2 vs iso 27001 certification withh links converted-convertedSoc 2 vs iso 27001 certification withh links converted-converted
Soc 2 vs iso 27001 certification withh links converted-converted
 

Último

CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
giselly40
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
vu2urc
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
Joaquim Jorge
 

Último (20)

How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
 

What to expect from the New York Privacy Act

  • 1. What to expect from the New York Privacy Act In the recently proposed bill of the New York Privacy Act in the House and Senate, businesses may soon have to gear up for this new data privacy law. If enforced, the law may severely impact businesses, restricting their operations in the way how they collect, use and share consumer’s personal information throughout the State. Earlier to this, a similar bill was introduced in the last legislative session but had failed to pass in the assembly. However, with New York Privacy Act now re-introduce in a more refined version. This bill should be closely watched by the industry as it moves through the legislative process. The New York Privacy Act is very similar to California’s Consumer Privacy Act (CCPA) but is more expansive in its approach and requirements. The regulation if enforced will provide consumers with much greater control over their personal information, and make businesses more accountable for their operations and business processes. In today’s article, we have covered details on the proposed New York Privacy Act bill and its possible impact on businesses. So, before summarizing the proposed bill let us first understand what the Regulation is all about. What is the New York Privacy Act? The proposed New York Privacy Act is a law which if enforced will apply to a wide range of businesses. It is an Act that may apply to entities that conduct business in New York pertaining to personal information of residents of New York State. While there are exceptions for the state and local governments, but the law may apply to all private entities (including non-profits) subject to the requirements.
  • 2. The proposed NY Privacy Law mirrors various other Privacy regulations like the California Consumer Privacy Act (“CCPA”) and the EU’s General Data Privacy Regulation (“GDPR”). This would be in line with consumer’s right to request for businesses to correct any inaccurate personal information or delete the personal information held with them. What does the proposed New York Privacy Act say about Consumer Rights, Consent, & Business obligations? Data Subjects Data subjects or consumers are defined as “a natural person who is a New York resident.” Employees and contractors are specifically excluded from the definition of consumer. Job applicants are not explicitly excluded from the definition of consumer, however, “data sets maintained for employment records purposes” are excluded. Again there is no “business-to-business” exemption. Personal Information- The New York Privacy Act broadly defines personal data and excludes only de-identified or publicly available data from this law. Business in Scope Similar to the GDPR and CCPA Regulation, the scope of NYPA is quite broad. It would apply to any legal entity that conducted business in the New York States or Businesses that produce or provide services that are intentionally targeted to residents of New York State. However, there are no thresh holds set on revenue or minimum amounts of personal data a company processes to be subject to the law. Further, it is important to note that there is no exemption for individuals or non-profit organizations but purely household activities are exempted from the law. Business Obligation The NYPA law creates a fiduciary obligation on the businesses to abide by the law and act in a way that benefits data subjects of whom they collect store or process personal data. This would simply mean that businesses will be held to a higher standard of compliance for the data collected and used of data subjects. It would also mean that businesses must act in the best interest of their consumers irrespective of it not being in the best interest of their business. Consumer Consent- Speaking about consumer consent, the Act clearly states that businesses will require consumers to provide “specific, informed and unambiguous” consent before they process or use their personal data. Businesses will have to obtain consumer’s consent specific to each intended use of their data. They would further require consumer-specific consent for each intended third-party receiving the data. Again for businesses in the marketing space will require separate checkboxes for each of their respective marketing partners. Consumer Rights- The proposed privacy act which is very similar to the CCPA and the GDPR provides consumers the right to access, rectification/correction, deletion, restriction of processing, and portability. Businesses are expected to act upon the request of the consumers without any undue delay. They are also expected to take “reasonable steps” to inform third parties about the consumer’s request. Violation & Fines– The NYPA law specifies that a consumer who suffers a loss may recover statutory damages of $1,000 or more or actual damages, and $3,000 or actual damages for an intentional violation. However, the law limits the scope of recovery to violations of the Act in the form of injunctive relief and actual damages. This means that the consumer must prove that they suffered a loss due to the failure of
  • 3. © VISTA InfoSec ® © VISTA InfoSec ® © VISTA InfoSec ® business to comply with the NYPA to be able to recover. Further, any person who is aware, based on non-public information, that a person or business has violated this section may file a civil action for civil penalties. This provision would allow for suits to be filed by competitors, vendors, and consumer groups based on violations of the law. What Should Businesses Do? The New York Privacy Act is still a proposed bill and not a legislation in effect that has passed the assembly. Further, as the law moves through the legislative process, businesses can expect amendments in the law. Businesses should have a close watch over the legislative process to see how and when the law comes into effect. But, this brings us to a very common question asked by most businesses as to how should they approach the data privacy law going forward. Ideally, an organization should initially start with conducting the basic assessment of their operations to identify the kind of data collected and classify them based on their level of sensitivity. Understanding what data is collected, processed, and identify the law that impacts the data is the key to your compliance journey. Once your business gains a basic understanding, the road ahead will be much easier for establishing a privacy program that fits with your organizational blueprint. Waiting for the legislation to come into effect isn’t really an option. For your business to stay ahead of the curve and gain a better business stand-point preparation for the law is what is advisable. After all, be it the GDPR Regulation CCPA or the proposed New York Privacy Act all of the regulations are more or less similar and are established with the common agenda of protecting the rights and privacy of consumer’s personal data. So, the faster and earlier your organization takes steps towards initiating a data privacy program, the better it is for them at the later stage for achieving compliance. Your business will be in a far better position to deal with any such data privacy regulation that comes into effect in the future. facebook.com/vistainfosec/ in.linkedin.com/company/vistainfosec twitter.com/VISTAINFOSEC Dowritetousyourfeedback,commentsandqueriesor,ifyouhaveanyrequirements: info@vistainfosec.com You can reach us on: USA +1-415-513 5261 INDIA +91 73045 57744 SINGAPORE +65-3129-0397