{
 "jurisdiction_id": "US-NY",
 "jurisdiction": "United States – New York",
 "url": "https://dataprotection.gi/jurisdictions/united-states-new-york/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 40,
  "sub_modules": 57,
  "source_register": 21
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "amber",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-new-york/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "A robust sectoral/breach-security framework exists (SHIELD, NYDFS) but there is no omnibus statute defining lawful bases, controller obligations broadly, or a general registration duty.",
   "claims": [
    {
     "statement": "The New York State Attorney General is the primary enforcer of data security and privacy statutes in New York, including the SHIELD Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "NYS Office of the Attorney General / DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/factsheet_for_business-_nys_information_security_breach_and_notification_act_20_august_2014.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The SHIELD Act regulates data breach and data security matters in New York and expanded enforcement capabilities of the Attorney General.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/new-york",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "New York has not adopted a comprehensive data protection law and does not recognize a constitutional or common law right of privacy; privacy is instead regulated statutorily through Article 5 of the Civil Rights Law.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/new-york",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The security requirements of the SHIELD Act apply to any business that collects or maintains private information of a New York resident, giving the law broad extraterritorial reach.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/new-yorks-shield-act-has-taken-effect-what-does-this-mean-for-your-business",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "NYDFS Covered Entities must annually validate and submit a certificate of compliance with the Cybersecurity Regulation, signed by the board of directors or a senior officer.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://corporate.dataguidance.com/usa-ny-dfs-final-cybersecurity-regulation-sea-change-covered-entities-2/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Senate Bill 9088, introduced January 30, 2026, would require data brokers to register annually with the Attorney General, pay a fee, and disclose extensive information about their operations.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/new-york-bill-data-brokers-registration-and-data",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "red",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-new-york/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "No general lawful-bases or special-category regime exists; coverage is fragmented and purpose-specific (children's data only).",
   "claims": [
    {
     "statement": "The New York Child Data Protection Act mandates that consent requests be clear, separate from other transactions, and easily revocable, with the most prominent option being to refuse consent.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/new-york-bill-establishing-new-york-child-data",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A state-wide biometric privacy bill (Assembly Bill 27) has been under consideration in the New York legislature, containing more onerous requirements than the existing NYC local biometric law and including a private right of action, but has not been enacted state-wide.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/nyc-biometric-law-enters-into-force",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "red",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-new-york/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "No comprehensive data-subject-rights statute exists; only sector-specific access/correction rights (education) were identified.",
   "claims": [
    {
     "statement": "Under New York education-sector data agreements, an LEA must establish reasonable procedures for a parent, legal guardian, or eligible student to review Education Records and correct erroneous information held by a service provider.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/new-york-safe-kids-act-signed-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Providers must respond to student-data record requests in a reasonably timely manner, no later than forty-five days from the date of request or the timeframe required under state law, whichever is sooner.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/new-york-safe-kids-act-signed-law",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-new-york/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Strong security/breach regime (SHIELD + NYDFS) but no DPIA/DPO/ROPA/joint-controller framework generally applicable.",
   "claims": [
    {
     "statement": "NYDFS Covered Entities under 23 NYCRR Part 500 must identify reasonably foreseeable internal and external risks and assess the sufficiency of safeguards controlling those risks.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://corporate.dataguidance.com/usa-ny-dfs-final-cybersecurity-regulation-sea-change-covered-entities-2/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "NYDFS regulations require regulated entities to designate a qualified individual (CISO) responsible for overseeing and implementing the entity's cybersecurity program.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://corporate.dataguidance.com/usa-ny-dfs-final-cybersecurity-regulation-sea-change-covered-entities-2/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The SHIELD Act requires businesses that own or license New York residents' private information to develop, implement and maintain reasonable safeguards including administrative, technical and physical safeguards.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/new-yorks-shield-act-has-taken-effect-what-does-this-mean-for-your-business",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The NYDFS Cybersecurity Regulation requires banks, insurance companies and other financial services institutions to establish and maintain a comprehensive cybersecurity programme covering governance, data management, incident planning, system testing, and data-incident reporting.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://corporate.dataguidance.com/usa-ny-dfs-final-cybersecurity-regulation-sea-change-covered-entities-2/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "There is an exception to the SHIELD Act breach notification obligation if notification is already made pursuant to GLBA, HIPAA, NYDFS Cybersecurity Regulation, or another official government agency's regulations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/new-yorks-shield-act-has-taken-effect-what-does-this-mean-for-your-business",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A business may use substitute notice for a data breach if it demonstrates to the New York Attorney General that the cost of providing notice would exceed $250,000 or that the affected class exceeds 500,000 persons.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "NYS Office of the Attorney General / DataGuidance",
     "source_url": "https://www.dataguidance.com/sites/default/files/factsheet_for_business-_nys_information_security_breach_and_notification_act_20_august_2014.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The SHIELD Act requires disposing of private information within a reasonable amount of time after it is no longer needed for business purposes by erasing electronic media so that the information cannot be read or reconstructed.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/new-yorks-shield-act-has-taken-effect-what-does-this-mean-for-your-business",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "red",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-new-york/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "No transfer-mechanism, adequacy, SCC/BCR, TIA, or localisation regime exists under NY state law; module reflects a genuine regulatory gap for this JID rather than incomplete research.",
   "claims": []
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-new-york/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Financial and employment sectors have mature, in-force overlays; health (non-HIPAA) and credit-scoring overlays remain largely proposed or federally-anchored.",
   "claims": [
    {
     "statement": "The NYDFS Cybersecurity Regulation, codified at 23 NYCRR Part 500, requires banks, insurance companies and other financial services institutions subject to NYDFS regulation to establish a comprehensive cybersecurity programme with governance, data-management, incident-planning, testing and reporting requirements.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://corporate.dataguidance.com/usa-ny-dfs-final-cybersecurity-regulation-sea-change-covered-entities-2/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Senate Bill 9269 for the New York Health Information Privacy Act mandates strict regulations on processing health information of New York residents not otherwise subject to HIPAA.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/new-york",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "New York Civil Rights Law §52-c requires that notice be provided before any employee electronic monitoring is permitted, and Labor Law §203-c prohibits video recording employees in sensitive areas.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/new-york-employee-monitoring",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "New York's 2021 electronic monitoring law requires employers who monitor or intercept employee communications or internet usage to give prior written notice upon hiring, acknowledged by the employee, and to post the notice conspicuously.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/new-york-governor-enacts-law-notice-requirements",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "New York student-data-privacy agreements require providers to treat student data as the LEA's property, restrict onward sale, and permit parental review consistent with FERPA and Education Law 2-d.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/new-york-safe-kids-act-signed-law",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "red",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-new-york/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "No dedicated adtech/cookie/cross-context-advertising statute exists in New York; the module records a genuine sectoral gap plus emergent wiretap-based litigation risk.",
   "claims": [
    {
     "statement": "New York's decades-old anti-wiretapping/eavesdropping statutes have found new significance in privacy class-action litigation against automated tracking and transcription technologies, mirroring similar theories under the federal Electronic Communications Privacy Act.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/dressing-old-laws-in-class-action-suits-applying-anti-wiretapping-laws-to-ai-transcription-services",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Senate Bill 9088 would require data brokers to disclose, among other things, whether consumer data was shared with foreign actors, government agencies, law enforcement, or AI system developers in the previous year.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/new-york-bill-data-brokers-registration-and-data",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "New York Senate Bill 2539 would mandate that retailers post warning signs if tracking customers through electronic devices, with penalties for violations.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/new-york",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-new-york/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Meaningful AI-transparency and biometric law exists but is split between city-level ordinances (NYC) and pending/newly-effective state AI statutes; general ADM transparency and profiling restrictions remain state-law gaps.",
   "claims": [
    {
     "statement": "Proposed Senate Bill 7623 would restrict employers' use of electronic monitoring and automated employment decision tools, requiring bias audits and documentation of employee-data-driven employment decisions, but remains pending.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/new-york-bill-employee-monitoring-and-automated",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "New York, alongside Illinois and Connecticut, finalized notable AI and privacy provisions during the 2026 legislative session, including transparency laws already on the books in New York referenced as comparators for new Illinois frontier-AI legislation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/notable-ai-privacy-bills-hit-finish-line-in-illinois-connecticut-and-new-york",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Senate Bill 8828 amending the RAISE Act mandates transparency and safety requirements for AI frontier model developers in New York State, effective January 1, 2027.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/new-york",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The New York City biometric law creates a private right of action enabling aggrieved parties to collect statutory damages ranging from $500 to $5,000 per violation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/nyc-biometric-law-enters-into-force",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-new-york/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Strong, recently-enacted children's-data statutes exist and cover consent, age-assurance and profiling-adjacent restrictions; dependent-adult protections remain an identified gap.",
   "claims": [
    {
     "statement": "The SAFE for Kids Act does not apply if the provider used reasonable methods to determine the user is not a minor or obtained parental consent, requiring providers to implement age-assurance measures.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/new-york-new-laws-strict-data-requirements-children-",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The SAFE for Kids Act prohibits social media platforms from providing an addictive feed to children younger than 18 without parental consent and prohibits withholding non-addictive alternatives where consent is not obtained.",
     "regulatory_stage": "enacted_not_yet_effective",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/new-york-safe-kids-act-signed-law",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "For covered users 12 and younger, the CDPA restricts data processing unless permitted under specific regulations, while informed consent is required for users 13 and older unless necessary for certain activities.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/new-york-bill-establishing-new-york-child-data",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Child Data Protection Act restricts digital services from collecting or using personal data of users under 18 without consent and prohibits the sale or disclosure of such data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/new-york-bill-establishing-new-york-child-data",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/united-states-new-york/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Enforcement activity is demonstrably active and well-resourced (AG + NYDFS), but the absence of a general private right of action for most NY privacy statutes limits collective redress.",
   "claims": [
    {
     "statement": "Companies that fail to comply with SHIELD Act security requirements may face civil penalties of up to $5,000 per violation, while breach-notification failures are penalized at $20 per instance, capped at $250,000.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/new-yorks-shield-act-has-taken-effect-what-does-this-mean-for-your-business",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The New York Attorney General resolved allegations of privacy and cybersecurity breaches by settling with 12 companies, initiating litigation against two, and imposing financial penalties exceeding $14 million.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/a-year-in-review-privacy-data-security-enforcement-by-new-yorks-state-attorney-general",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "NYDFS fined Delta Dental $2.25 million for cybersecurity violations due to insufficient incident-response and reporting policies.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/new-york",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The SHIELD Act expressly provides that there is no private right of action; the Attorney General may pursue civil penalties for violations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/new-yorks-shield-act-has-taken-effect-what-does-this-mean-for-your-business",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "A coalition of 42 attorneys general reached a settlement with 23andMe's bankruptcy trustee over a 2023 data breach affecting 6.9 million customers.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/new-york",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "NYDFS issued cybersecurity guidance focusing on reducing attack surfaces, improving threat detection, and strengthening resilience during heightened threat environments.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/new-york",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "17 state attorneys general sued the federal administration over student data demands, citing privacy risks and legal uncertainties, and a judge temporarily blocked the data collection.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/new-york",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}