#
A robust sectoral/breach-security framework exists (SHIELD, NYDFS) but there is no omnibus statute defining lawful bases, controller obligations broadly, or a general registration duty.
Sub-modules (5)
Regulator And AuthorityGreen
The NY AG is the primary regulator; NYDFS is the sectoral financial-services cybersecurity regulator with independent enforcement powers.
Claims: CLM-US-NY-a1b2c3d4
Act And InstrumentsAmber
Core instruments are the SHIELD Act, Civil Rights Law Art. 5, NYDFS 23 NYCRR Part 500, the Child Data Protection Act, and the SAFE for Kids Act.
Claims: CLM-US-NY-b2c3d4e5
Material ScopeAmber
Scope centers on 'private information' (SSNs, driver's license numbers, financial account data, and biometric data after SHIELD amendments) rather than a general personal-data definition.
Claims: CLM-US-NY-c3d4e5f6
Territorial ScopeGreen
SHIELD Act security and breach obligations apply to any person or business that owns or licenses computerized private information of a NY resident, regardless of whether the business operates in New York.
Claims: CLM-US-NY-d4e5f6a7
Regulator Registration And FilingAmber
No general controller registration exists; NYDFS requires an annual Certification of Compliance from covered entities. A pending Senate Bill 9088 would create a data-broker registration/deletion regime but is not yet enacted.
Claims: CLM-US-NY-e5f6a7b8, CLM-US-NY-f6a7b8c9
Sources and claims (6)
- ConfirmedNYS Office of the Attorney General / DataGuidance — The New York State Attorney General is the primary enforcer of data security and privacy statutes in New York, including the SHIELD Act.
- ConfirmedDataGuidance — The SHIELD Act regulates data breach and data security matters in New York and expanded enforcement capabilities of the Attorney General.
- ConfirmedDataGuidance — New York has not adopted a comprehensive data protection law and does not recognize a constitutional or common law right of privacy; privacy is instead regulated statutorily through Article 5 of the Civil Rights Law.
- ConfirmedIAPP — The security requirements of the SHIELD Act apply to any business that collects or maintains private information of a New York resident, giving the law broad extraterritorial reach.
- ConfirmedDataGuidance — NYDFS Covered Entities must annually validate and submit a certificate of compliance with the Cybersecurity Regulation, signed by the board of directors or a senior officer.
- UncertainDataGuidance — Senate Bill 9088, introduced January 30, 2026, would require data brokers to register annually with the Attorney General, pay a fee, and disclose extensive information about their operations.