🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US-NY · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 21 sources retrieved model claude-sonnet-5 ·

United States – New York

US-NY schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 40 claims · 21 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
40Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

A robust sectoral/breach-security framework exists (SHIELD, NYDFS) but there is no omnibus statute defining lawful bases, controller obligations broadly, or a general registration duty.

Primary frameworkSHIELD Act (GBL Art. 39-F) / NYDFS 23 NYCRR Part 500
Traffic-light rationale — AmberA robust sectoral/breach-security framework exists (SHIELD, NYDFS) but there is no omnibus statute defining lawful bases, controller obligations broadly, or a general registration duty.

Sub-modules (5)

Regulator And AuthorityGreen

The NY AG is the primary regulator; NYDFS is the sectoral financial-services cybersecurity regulator with independent enforcement powers.

Claims: CLM-US-NY-a1b2c3d4

Act And InstrumentsAmber

Core instruments are the SHIELD Act, Civil Rights Law Art. 5, NYDFS 23 NYCRR Part 500, the Child Data Protection Act, and the SAFE for Kids Act.

Claims: CLM-US-NY-b2c3d4e5

Material ScopeAmber

Scope centers on 'private information' (SSNs, driver's license numbers, financial account data, and biometric data after SHIELD amendments) rather than a general personal-data definition.

Claims: CLM-US-NY-c3d4e5f6

Territorial ScopeGreen

SHIELD Act security and breach obligations apply to any person or business that owns or licenses computerized private information of a NY resident, regardless of whether the business operates in New York.

Claims: CLM-US-NY-d4e5f6a7

Regulator Registration And FilingAmber

No general controller registration exists; NYDFS requires an annual Certification of Compliance from covered entities. A pending Senate Bill 9088 would create a data-broker registration/deletion regime but is not yet enacted.

Claims: CLM-US-NY-e5f6a7b8, CLM-US-NY-f6a7b8c9

Category narrative96 words

New York has no single comprehensive data-protection statute. The New York Attorney General (Bureau of Internet & Technology) is the primary consumer-privacy enforcer, operating under the Stop Hacks and Improve Electronic Data Security Act (SHIELD Act, GBL Art. 39-F, §§899-aa/bb) and the Civil Rights Law Art. 5. The New York State Department of Financial Services (NYDFS) is the sectoral regulator for financial-services cybersecurity under 23 NYCRR Part 500. Material and territorial scope are defined breach-by-breach (private information of NY residents) rather than by a general 'personal data' concept, and there is no comprehensive controller/processor registration regime.

Sources and claims (6)
  1. ConfirmedNYS Office of the Attorney General / DataGuidanceThe New York State Attorney General is the primary enforcer of data security and privacy statutes in New York, including the SHIELD Act.
  2. ConfirmedDataGuidanceThe SHIELD Act regulates data breach and data security matters in New York and expanded enforcement capabilities of the Attorney General.
  3. ConfirmedDataGuidanceNew York has not adopted a comprehensive data protection law and does not recognize a constitutional or common law right of privacy; privacy is instead regulated statutorily through Article 5 of the Civil Rights Law.
  4. ConfirmedIAPPThe security requirements of the SHIELD Act apply to any business that collects or maintains private information of a New York resident, giving the law broad extraterritorial reach.
  5. ConfirmedDataGuidanceNYDFS Covered Entities must annually validate and submit a certificate of compliance with the Cybersecurity Regulation, signed by the board of directors or a senior officer.
  6. UncertainDataGuidanceSenate Bill 9088, introduced January 30, 2026, would require data brokers to register annually with the Attorney General, pay a fee, and disclose extensive information about their operations.

#

No general lawful-bases or special-category regime exists; coverage is fragmented and purpose-specific (children's data only).

Primary frameworkChild Data Protection Act / SAFE for Kids Act (purpose-specific only)
Supervisory authorityNew York State Attorney General
Traffic-light rationale — RedNo general lawful-bases or special-category regime exists; coverage is fragmented and purpose-specific (children's data only).

Sub-modules (4)

Lawful BasesRed

No enumerated lawful-bases regime exists in New York law outside of sector statutes.

Absence provenance: not recorded. Searched: New York general lawful basis processing statute, NY comprehensive privacy law lawful bases.

Special CategoriesRed

No general 'special category' data definition exists in NY statute akin to GDPR Art. 9; biometric identifier data receives distinct treatment only via the NYC local Biometric Identifier Information Law and pending state biometric bills.

Claims: CLM-US-NY-b8c9d0e1

Pseudonymisation And AnonymisationRed

No NY state statutory definition of pseudonymisation/anonymisation was identified; education-sector contractual templates reference FERPA de-identification standards only.

Absence provenance: not recorded. Searched: New York pseudonymisation anonymisation statute, NY state law de-identification safe harbour.

Category narrative72 words

New York has no general lawful-basis framework analogous to GDPR Art. 6, nor a codified 'special category' regime. Consent standards appear only in narrow, purpose-specific statutes: the Child Data Protection Act (CDPA) requires informed, revocable consent for processing minors' data, and the SAFE for Kids Act requires parental consent for 'addictive feeds.' No statutory pseudonymisation/anonymisation safe-harbour exists at state level outside of education-sector guidance (Student Data Privacy Consortium templates referencing FERPA de-identification).

Sources and claims (2)
  1. ConfirmedDataGuidanceThe New York Child Data Protection Act mandates that consent requests be clear, separate from other transactions, and easily revocable, with the most prominent option being to refuse consent.
  2. ProbableIAPPA state-wide biometric privacy bill (Assembly Bill 27) has been under consideration in the New York legislature, containing more onerous requirements than the existing NYC local biometric law and including a private right of action, but has not been enacted state-wide.

#

No comprehensive data-subject-rights statute exists; only sector-specific access/correction rights (education) were identified.

Supervisory authorityNew York State Attorney General
Traffic-light rationale — RedNo comprehensive data-subject-rights statute exists; only sector-specific access/correction rights (education) were identified.

Sub-modules (5)

Access RightAmber

No general consumer access right exists; Education Law 2-d/FERPA gives parents/eligible students the right to review education records held by providers.

Claims: CLM-US-NY-c9d0e1f2

Rectification And ErasureAmber

No general erasure/rectification right exists outside the education sector, where parents may request correction of erroneous student data.

Claims: CLM-US-NY-c9d0e1f2

Restriction And ObjectionRed

No general restriction/objection right identified in NY state law.

Absence provenance: not recorded. Searched: New York right to restrict processing, NY consumer objection to processing statute.

Data PortabilityRed

No data-portability right exists under New York state law.

Absence provenance: not recorded. Searched: New York data portability right statute.

Deadlines And Response WindowsAmber

Where an education-sector response duty exists, providers must typically respond within 45 days of a parent/LEA request, or the state-law timeframe if shorter.

Claims: CLM-US-NY-d0e1f2a3

Category narrative54 words

New York lacks a general consumer data-subject-rights regime (no state-wide access, rectification, erasure, restriction, objection, or portability right analogous to CPRA/GDPR). Rights that exist are narrow and sector-bound: FERPA/Education Law 2-d gives parents access/correction rights over student education records via LEAs, and NYDFS rules give regulated entities internal audit obligations rather than consumer-facing rights.

Sources and claims (2)
  1. ProbableDataGuidanceUnder New York education-sector data agreements, an LEA must establish reasonable procedures for a parent, legal guardian, or eligible student to review Education Records and correct erroneous information held by a service provider.
  2. ProbableDataGuidanceProviders must respond to student-data record requests in a reasonably timely manner, no later than forty-five days from the date of request or the timeframe required under state law, whichever is sooner.

#

Strong security/breach regime (SHIELD + NYDFS) but no DPIA/DPO/ROPA/joint-controller framework generally applicable.

Primary frameworkSHIELD Act (GBL §899-bb) / NYDFS 23 NYCRR Part 500
Traffic-light rationale — AmberStrong security/breach regime (SHIELD + NYDFS) but no DPIA/DPO/ROPA/joint-controller framework generally applicable.

Sub-modules (7)

Accountability And DpiaAmber

No general DPIA duty exists; NYDFS requires periodic risk assessments as part of its Cybersecurity Regulation.

Claims: CLM-US-NY-e1f2a3b4

Dpo RequirementsAmber

No general DPO requirement exists; NYDFS requires designation of a CISO for regulated financial entities.

Claims: CLM-US-NY-f2a3b4c5

Ropa RequirementsRed

No records-of-processing-activities obligation exists under New York state law.

Absence provenance: not recorded. Searched: New York records of processing activities requirement.

Joint Controller ArrangementsRed

No joint-controller concept exists in New York statute; education-sector DPAs define 'Provider' and 'Subprocessor' roles contractually rather than by statute.

Absence provenance: not recorded. Searched: New York joint controller law.

Security MeasuresGreen

SHIELD Act requires businesses to develop, implement and maintain reasonable administrative, technical and physical safeguards; NYDFS 23 NYCRR 500 imposes detailed technical standards for regulated financial entities.

Claims: CLM-US-NY-a3b4c5d6, CLM-US-NY-b4c5d6e7

Breach NotificationGreen

SHIELD Act requires notification to affected NY residents and the Attorney General, with substitute-notice provisions and an exception where notice is already made under GLBA, HIPAA, or NYDFS rules.

Claims: CLM-US-NY-c5d6e7f8, CLM-US-NY-d6e7f8a9

Retention And DisposalGreen

SHIELD Act requires disposal of private information within a reasonable time after it is no longer needed, by erasing electronic media so information cannot be read or reconstructed.

Claims: CLM-US-NY-e7f8a9b0

Category narrative57 words

New York imposes concrete security-program and breach-notification duties via the SHIELD Act and, for financial-services entities, the far more detailed NYDFS Cybersecurity Regulation (23 NYCRR Part 500). Neither statute mandates a formal DPIA or DPO in the GDPR sense, though NYDFS requires a CISO and periodic risk assessments. There is no general ROPA obligation or joint-controller framework.

Sources and claims (7)
  1. ConfirmedDataGuidanceNYDFS Covered Entities under 23 NYCRR Part 500 must identify reasonably foreseeable internal and external risks and assess the sufficiency of safeguards controlling those risks.
  2. ConfirmedDataGuidanceNYDFS regulations require regulated entities to designate a qualified individual (CISO) responsible for overseeing and implementing the entity's cybersecurity program.
  3. ConfirmedIAPPThe SHIELD Act requires businesses that own or license New York residents' private information to develop, implement and maintain reasonable safeguards including administrative, technical and physical safeguards.
  4. ConfirmedDataGuidanceThe NYDFS Cybersecurity Regulation requires banks, insurance companies and other financial services institutions to establish and maintain a comprehensive cybersecurity programme covering governance, data management, incident planning, system testing, and data-incident reporting.
  5. ConfirmedIAPPThere is an exception to the SHIELD Act breach notification obligation if notification is already made pursuant to GLBA, HIPAA, NYDFS Cybersecurity Regulation, or another official government agency's regulations.
  6. ConfirmedNYS Office of the Attorney General / DataGuidanceA business may use substitute notice for a data breach if it demonstrates to the New York Attorney General that the cost of providing notice would exceed $250,000 or that the affected class exceeds 500,000 persons.
  7. ConfirmedIAPPThe SHIELD Act requires disposing of private information within a reasonable amount of time after it is no longer needed for business purposes by erasing electronic media so that the information cannot be read or reconstructed.

#

No transfer-mechanism, adequacy, SCC/BCR, TIA, or localisation regime exists under NY state law; module reflects a genuine regulatory gap for this JID rather than incomplete research.

Traffic-light rationale — RedNo transfer-mechanism, adequacy, SCC/BCR, TIA, or localisation regime exists under NY state law; module reflects a genuine regulatory gap for this JID rather than incomplete research.

Sub-modules (6)

Transfer MechanismsRed

No NY state-law transfer mechanism regime exists.

Absence provenance: not recorded. Searched: New York state law cross-border data transfer mechanism.

Adequacy ReceivedRed

Not applicable; New York is a sub-national US jurisdiction and does not receive adequacy decisions.

Absence provenance: not recorded. Searched: New York adequacy decision received.

Adequacy GrantedRed

Not applicable; New York does not grant adequacy decisions.

Absence provenance: not recorded. Searched: New York adequacy decision granted.

Sccs And BcrsRed

No SCC/BCR concept exists under New York law.

Absence provenance: not recorded. Searched: New York standard contractual clauses binding corporate rules.

Transfer Impact AssessmentRed

No TIA requirement exists under New York law.

Absence provenance: not recorded. Searched: New York transfer impact assessment requirement.

Data LocalisationRed

No general data-localisation mandate was identified for New York; NYDFS requirements are security-focused rather than location-based.

Absence provenance: not recorded. Searched: New York data localisation mandate, New York data residency requirement.

Category narrative51 words

New York state law contains no adequacy-decision mechanism, no SCC/BCR concept, and no transfer-impact-assessment requirement — these are EU/GDPR-derived constructs with no US state-law analogue. No New York data-localisation mandate was identified. Cross-border data transfer questions for NY-resident data are governed by federal instruments (e.g., GLBA, HIPAA) rather than state law.

#

Financial and employment sectors have mature, in-force overlays; health (non-HIPAA) and credit-scoring overlays remain largely proposed or federally-anchored.

Primary frameworkNYDFS 23 NYCRR Part 500 (financial) / Education Law 2-d (education) / Labor Law Art. 5 (employment)
Traffic-light rationale — AmberFinancial and employment sectors have mature, in-force overlays; health (non-HIPAA) and credit-scoring overlays remain largely proposed or federally-anchored.

Sub-modules (7)

Financial Sector OverlayGreen

NYDFS's Cybersecurity Regulation requires banks, insurers and other regulated financial entities to maintain a comprehensive cybersecurity programme with governance, incident-response and third-party oversight obligations.

Claims: CLM-US-NY-f8a9b0c1

Health Sector OverlayAmber

A comprehensive health-privacy bill (Senate Bill 9269, the New York Health Information Privacy Act) targeting health information not subject to HIPAA has been introduced with adjusted penalties, but is not yet enacted.

Claims: CLM-US-NY-a9b0c1d2

Telecoms And EprivacyRed

No New York state-specific ePrivacy/telecoms overlay analogous to the EU ePrivacy Directive was identified; cookie/tracking issues are addressed instead via older wiretap/eavesdropping statutes.

Absence provenance: not recorded. Searched: New York ePrivacy telecoms data law.

Employment DataGreen

New York Civil Rights Law §52-c requires notice before employee electronic monitoring is permitted; Labor Law §201-a prohibits fingerprinting as an employment condition; Labor Law §203-c restricts video recording of employees in sensitive areas; a 2021 law (S2628) requires written notice of electronic monitoring upon hiring.

Claims: CLM-US-NY-b0c1d2e3, CLM-US-NY-c1d2e3f4

Credit And ScoringAmber

Credit-scoring privacy in New York is governed primarily by the federal Fair Credit Reporting Act; no distinct New York state credit-scoring privacy overlay was identified.

Absence provenance: not recorded. Searched: New York state credit scoring privacy law.

EducationAmber

New York Education Law 2-d and related student-data-privacy agreements (modeled on national Student Data Privacy Consortium templates) govern student data alongside federal FERPA.

Claims: CLM-US-NY-d2e3f4a5

InsuranceAmber

Insurance entities licensed by NYDFS fall within the scope of the Cybersecurity Regulation; no separate NY insurance-specific consumer-data statute beyond this was identified.

Claims: CLM-US-NY-f8a9b0c1

Category narrative67 words

New York's data-protection landscape is fundamentally sectoral. NYDFS's 23 NYCRR Part 500 governs financial-services cybersecurity; health information outside HIPAA is targeted by a pending New York Health Information Privacy Act (SB 9269); employment data is covered by a patchwork of Labor Law, Civil Rights Law, and General Business Law provisions plus the 2021 electronic-monitoring notice law; and education data is governed by Education Law 2-d alongside FERPA.

Sources and claims (5)
  1. ConfirmedDataGuidanceThe NYDFS Cybersecurity Regulation, codified at 23 NYCRR Part 500, requires banks, insurance companies and other financial services institutions subject to NYDFS regulation to establish a comprehensive cybersecurity programme with governance, data-management, incident-planning, testing and reporting requirements.
  2. UncertainDataGuidanceSenate Bill 9269 for the New York Health Information Privacy Act mandates strict regulations on processing health information of New York residents not otherwise subject to HIPAA.
  3. ConfirmedDataGuidanceNew York Civil Rights Law §52-c requires that notice be provided before any employee electronic monitoring is permitted, and Labor Law §203-c prohibits video recording employees in sensitive areas.
  4. ConfirmedDataGuidanceNew York's 2021 electronic monitoring law requires employers who monitor or intercept employee communications or internet usage to give prior written notice upon hiring, acknowledged by the employee, and to post the notice conspicuously.
  5. ProbableDataGuidanceNew York student-data-privacy agreements require providers to treat student data as the LEA's property, restrict onward sale, and permit parental review consistent with FERPA and Education Law 2-d.

#

No dedicated adtech/cookie/cross-context-advertising statute exists in New York; the module records a genuine sectoral gap plus emergent wiretap-based litigation risk.

Primary frameworkPenal Law Art. 250 (Eavesdropping) — repurposed, not adtech-specific
Supervisory authorityNew York State Attorney General
Traffic-light rationale — RedNo dedicated adtech/cookie/cross-context-advertising statute exists in New York; the module records a genuine sectoral gap plus emergent wiretap-based litigation risk.

Sub-modules (6)

Cookies And TrackersAmber

No dedicated cookie-consent statute exists; New York's eavesdropping statute has been used analogously to California's CIPA in tracking-technology class actions.

Claims: CLM-US-NY-e3f4a5b6

Dark PatternsRed

No New York state dark-pattern prohibition was identified; enforcement in this space is federal (FTC Act) only.

Absence provenance: not recorded. Searched: New York dark pattern prohibition statute.

Opt Out SignalsRed

New York law does not mandate recognition of Global Privacy Control or other universal opt-out signals.

Absence provenance: not recorded. Searched: New York Global Privacy Control recognition law.

Clean Rooms And DcrRed

No New York statute addresses data clean rooms or data-collaboration-room governance.

Absence provenance: not recorded. Searched: New York data clean room regulation.

Cross Context AdvertisingAmber

New York has no CPRA-style 'sale'/'share' definition governing cross-context behavioral advertising. A pending Senate Bill 9088 would create data-broker obligations touching cross-context data flows.

Claims: CLM-US-NY-f4a5b6c7

Direct MarketingAmber

Retail tracking notice requirements (pending Senate Bill 2539) would mandate warning signs for electronic device tracking of customers, but this is not yet enacted; direct marketing consent otherwise flows through federal CAN-SPAM.

Claims: CLM-US-NY-a5b6c7d8

Category narrative64 words

New York has no CPRA-style 'sale'/'share' framework, no state cookie-consent statute, and no codified dark-pattern prohibition or Global Privacy Control recognition requirement. Adtech-adjacent enforcement instead flows through decades-old anti-wiretapping/eavesdropping statutes (Penal Law Art. 250) being repurposed in class-action litigation against tracking technologies, mirroring the federal ECPA and California's CIPA experience. A pending 'One Fair Price Act' would prohibit surveillance pricing based on personal data.

Sources and claims (3)
  1. ProbableIAPPNew York's decades-old anti-wiretapping/eavesdropping statutes have found new significance in privacy class-action litigation against automated tracking and transcription technologies, mirroring similar theories under the federal Electronic Communications Privacy Act.
  2. UncertainDataGuidanceSenate Bill 9088 would require data brokers to disclose, among other things, whether consumer data was shared with foreign actors, government agencies, law enforcement, or AI system developers in the previous year.
  3. UncertainDataGuidanceNew York Senate Bill 2539 would mandate that retailers post warning signs if tracking customers through electronic devices, with penalties for violations.

#

Meaningful AI-transparency and biometric law exists but is split between city-level ordinances (NYC) and pending/newly-effective state AI statutes; general ADM transparency and profiling restrictions remain state-law gaps.

Primary frameworkRAISE Act (as amended, SB 8828) / NYC Biometric Identifier Information Law (local, not state-wide)
Supervisory authorityNew York State Attorney General
Traffic-light rationale — AmberMeaningful AI-transparency and biometric law exists but is split between city-level ordinances (NYC) and pending/newly-effective state AI statutes; general ADM transparency and profiling restrictions remain state-law gaps.

Sub-modules (6)

Profiling RestrictionsAmber

No general state-wide profiling restriction exists; a pending bill (S7623) would restrict employer use of automated employment decision tools and require bias audits, but has not been enacted state-wide.

Claims: CLM-US-NY-b6c7d8e9

Automated Decision Making TransparencyAmber

ADM transparency in New York is anchored at the New York City level (Local Law 144 bias-audit requirement for automated employment decision tools); no state-wide equivalent was identified.

Claims: CLM-US-NY-c7d8e9f0

Ai Risk AssessmentsAmber

Senate Bill 8828, amending the RAISE Act, mandates transparency and safety requirements for AI frontier model developers in New York State, effective January 1, 2027.

Claims: CLM-US-NY-d8e9f0a1

Biometric RegimeAmber

The New York City Biometric Identifier Information Law (Admin Code §§22-1201-1205) requires notice before commercial establishments collect, retain, convert, store or share biometric identifier information and creates a private right of action with statutory damages of $500 to $5,000 per violation; a broader state-wide biometric privacy bill remains pending.

Claims: CLM-US-NY-e9f0a1b2

Genetic DataRed

No New York state-specific genetic-data statute was identified beyond federal GINA protections.

Absence provenance: not recorded. Searched: New York genetic data privacy statute.

State Surveillance CarveoutsRed

No New York state-law national-security/surveillance carve-out provisions specific to data protection were identified in this research pass.

Absence provenance: not recorded. Searched: New York state surveillance carveout data protection law.

Category narrative65 words

New York's algorithmic/biometric governance is concentrated at the New York City level (Local Law 144 automated employment decision tool bias audits; the Biometric Identifier Information Law) rather than state-wide, though the state RAISE Act (as amended by SB 8828) introduces frontier-AI transparency obligations effective January 1, 2027. A state-wide biometric privacy bill (Assembly Bill 27) remains pending. No comprehensive state ADM-transparency or profiling-restriction statute exists.

Sources and claims (4)
  1. UncertainDataGuidanceProposed Senate Bill 7623 would restrict employers' use of electronic monitoring and automated employment decision tools, requiring bias audits and documentation of employee-data-driven employment decisions, but remains pending.
  2. ProbableIAPPNew York, alongside Illinois and Connecticut, finalized notable AI and privacy provisions during the 2026 legislative session, including transparency laws already on the books in New York referenced as comparators for new Illinois frontier-AI legislation.
  3. ProbableDataGuidanceSenate Bill 8828 amending the RAISE Act mandates transparency and safety requirements for AI frontier model developers in New York State, effective January 1, 2027.
  4. ConfirmedIAPPThe New York City biometric law creates a private right of action enabling aggrieved parties to collect statutory damages ranging from $500 to $5,000 per violation.

#

Strong, recently-enacted children's-data statutes exist and cover consent, age-assurance and profiling-adjacent restrictions; dependent-adult protections remain an identified gap.

Primary frameworkChild Data Protection Act / SAFE for Kids Act
Supervisory authorityNew York State Attorney General
Traffic-light rationale — AmberStrong, recently-enacted children's-data statutes exist and cover consent, age-assurance and profiling-adjacent restrictions; dependent-adult protections remain an identified gap.

Sub-modules (5)

Age VerificationGreen

The SAFE for Kids Act requires providers to implement appropriate measures to determine whether a user is a minor before serving an addictive feed.

Claims: CLM-US-NY-f0a1b2c3

Minor Profiling BansAmber

The CDPA restricts digital services from collecting or using personal data of users under 18 without consent and prohibits sale or disclosure of such data, indirectly constraining profiling-adjacent uses.

Claims: CLM-US-NY-c3d5e6f7

Education SettingsAmber

Education Law 2-d and related student-data-privacy agreements govern data collected in NY school settings, layered atop federal FERPA and COPPA.

Claims: CLM-US-NY-d2e3f4a5

Dependent AdultsRed

No dependent-adult-specific (elderly/incapacitated) data-protection provision was identified in New York state law during this research pass.

Absence provenance: not recorded. Searched: New York dependent adult data protection law, New York elderly privacy statute.

Category narrative49 words

New York has two dedicated children's-data statutes: the Child Data Protection Act (CDPA), restricting collection/use/sale of minors' (under-18) personal data absent consent, and the SAFE for Kids Act, restricting 'addictive feeds' for minors absent parental consent (effective January 25, 2027, per current tracking). No dependent-adult-specific data-protection provision was identified.

Sources and claims (4)
  1. ConfirmedDataGuidanceThe SAFE for Kids Act does not apply if the provider used reasonable methods to determine the user is not a minor or obtained parental consent, requiring providers to implement age-assurance measures.
  2. ConfirmedDataGuidanceThe SAFE for Kids Act prohibits social media platforms from providing an addictive feed to children younger than 18 without parental consent and prohibits withholding non-addictive alternatives where consent is not obtained.
  3. ConfirmedDataGuidanceFor covered users 12 and younger, the CDPA restricts data processing unless permitted under specific regulations, while informed consent is required for users 13 and older unless necessary for certain activities.
  4. ConfirmedDataGuidanceThe Child Data Protection Act restricts digital services from collecting or using personal data of users under 18 without consent and prohibits the sale or disclosure of such data.

#

Enforcement activity is demonstrably active and well-resourced (AG + NYDFS), but the absence of a general private right of action for most NY privacy statutes limits collective redress.

Primary frameworkSHIELD Act (GBL §899-bb) enforcement provisions
Supervisory authorityNew York State Attorney General
Traffic-light rationale — AmberEnforcement activity is demonstrably active and well-resourced (AG + NYDFS), but the absence of a general private right of action for most NY privacy statutes limits collective redress.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

SHIELD Act penalties are capped at $5,000 per violation for security-program failures and $20 per instance of failed breach notification, capped overall at $250,000; the AG may also seek injunctive relief.

Claims: CLM-US-NY-d5e6f7a8

Enforcement Activity IndexGreen

In its most recent reported year, the NY AG resolved allegations against 12 companies (litigating against two), securing over $14 million in penalties; NYDFS separately fined Delta Dental $2.25 million for cybersecurity violations.

Claims: CLM-US-NY-e6f7a8b9, CLM-US-NY-f7a8b9c0

Regulator Funding And CapacityAmber

No specific budget/headcount disclosure for the AG's Bureau of Internet & Technology or NYDFS's cybersecurity division was identified in this research pass.

Absence provenance: not recorded. Searched: New York Attorney General Bureau of Internet Technology budget headcount, NYDFS cybersecurity division staffing.

Collective Redress And Class ActionsAmber

Wiretap/eavesdropping-based class actions against tracking and AI-transcription technologies are an emergent collective-redress vector in New York, alongside the NYC biometric law's private right of action.

Claims: CLM-US-NY-e3f4a5b6, CLM-US-NY-e9f0a1b2

Private Right Of ActionAmber

The SHIELD Act expressly provides no private right of action; enforcement is AG-exclusive. By contrast, the NYC biometric ordinance does confer a private right of action with statutory damages.

Claims: CLM-US-NY-a8b9c0d1

Recent Developments 180DAmber

Within the last 180 days, New York has advanced a data-broker registration bill (SB 9088, Jan 30 2026), the Synthetic Performer Disclosure Act, the Stealth Crawler Prohibition Act, an AI-companion-features-for-minors bill (SB 9051B), a generative-AI-notice bill (SB 934A), a chatbot-impersonation-liability bill (SB 7263), the Health Information Privacy Act (SB 9269), NYDFS guidance on threat-surface reduction, a $2.25M NYDFS fine against Delta Dental, and a 42-state-AG settlement with 23andMe's bankruptcy trustee over its 2023 breach.

Claims: CLM-US-NY-b9c0d1e2, CLM-US-NY-c0d1e2f3, CLM-US-NY-d1e2f3a4

Category narrative86 words

The NY AG has robust civil-penalty and injunctive powers under the SHIELD Act ($5,000 per security violation; $20 per failed-notification instance capped at $250,000) but SHIELD expressly excludes a private right of action. The AG's Bureau of Internet & Technology has sustained an active enforcement cadence, and NYDFS separately fines regulated financial entities for cybersecurity lapses. Private rights of action exist narrowly (NYC biometric law) and via repurposed wiretap statutes in class litigation; a formal comprehensive collective-redress mechanism for general consumer privacy does not exist state-wide.

Sources and claims (7)
  1. ConfirmedIAPPCompanies that fail to comply with SHIELD Act security requirements may face civil penalties of up to $5,000 per violation, while breach-notification failures are penalized at $20 per instance, capped at $250,000.
  2. ConfirmedIAPPThe New York Attorney General resolved allegations of privacy and cybersecurity breaches by settling with 12 companies, initiating litigation against two, and imposing financial penalties exceeding $14 million.
  3. ConfirmedDataGuidanceNYDFS fined Delta Dental $2.25 million for cybersecurity violations due to insufficient incident-response and reporting policies.
  4. ConfirmedIAPPThe SHIELD Act expressly provides that there is no private right of action; the Attorney General may pursue civil penalties for violations.
  5. ProbableDataGuidanceA coalition of 42 attorneys general reached a settlement with 23andMe's bankruptcy trustee over a 2023 data breach affecting 6.9 million customers.
  6. ProbableDataGuidanceNYDFS issued cybersecurity guidance focusing on reducing attack surfaces, improving threat detection, and strengthening resilience during heightened threat environments.
  7. ProbableDataGuidance17 state attorneys general sued the federal administration over student data demands, citing privacy risks and legal uncertainties, and a judge temporarily blocked the data collection.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States – New York
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 40 claim(s), 21 source(s) in the cumulative register.