Not publishable as-is. 1 of 5 publication_gate checks fail. The renderer displays the gate rather than suppressing it. Legal review and sub-brief approval are informational and are not part of this test.
Based mainly on secondary sources. Only 2 of the sources retrieved for this jurisdiction are official or direct reporting of official material (tier 1 or 2), against the 3 we look for. No finding on this page is shown with confidence above “Uncertain” until stronger sources are retrieved.
United States — New York
US-NYschema gdpri-v2trajectory: not yet assessedregulated (sectoral)overlaps: FIM, WPM, AIC, Advennt
Last updated · 10 categories · 40
claims · 24 sources in the cumulative register
10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
40Claimsbaseline..claims[]
2Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix(sums to 10 rendered categories; click to filter)
Jurisdiction brief
Standing brief, as of 28 September 2026.
Lead Signal
New York's algorithmic and biometric governance landscape advanced this cycle with the state Senate's passage of the statewide Biometric Privacy Act (S1422A) by a vote of 41-20 on June 3, 2026. The bill is now pending in the Assembly. If enacted, it would extend statewide biometric-consent obligations beyond the scope of New York City's existing Local Law 3, which currently governs biometric data collection only within the city.
Other Developments
Children and vulnerable groups exposure. The same S1422A reform, if enacted, would extend biometric-consent obligations to cover populations and contexts beyond NYC's Local Law 3, which is understood to bear directly on protections for minors and other vulnerable groups whose biometric data is collected outside a narrowly municipal frame. No separate, distinct children-specific statutory development beyond this biometric-reform vector was identified this cycle.
Cross-Monitor Connections
Biometric identity-verification requirements are also live in the gambling-regulatory space this cycle, where the advennt monitor is tracking a New York State Gaming Commission draft rule that would mandate biometric verification at registration and per wagering session; that is a separate, sector-specific instrument from S1422A and is not analysed further here. No world-payments or financial-integrity connection was identified for this cycle's data-protection developments in New York.
Outlook
S1422A's progress through the Assembly is the item to watch; its current status beyond the June 3, 2026 Senate vote requires confirmation against primary legislative-tracking records rather than the single secondary source available this cycle. If enacted, the statewide biometric-consent framework would represent the most significant expansion of New York's algorithmic and biometric governance regime since the SHIELD Act's standing security requirements, and would be the first statewide (rather than New York City-specific) biometric statute in the state.
trust tier: ai_unverified
Standing brief, as of 28 September 2026.
Regulatory Status
New York's data-protection regulatory status this cycle is defined by a single material development: the statewide Biometric Privacy Act (S1422A) passed the state Senate 41-20 on June 3, 2026 and is pending in the Assembly. If enacted, this would be New York's first statewide biometric-consent statute, extending obligations beyond New York City's Local Law 3. The state's core security and breach-notification statute, the SHIELD Act, remains the operative baseline instrument and was not itself subject to change this cycle.
Outlook
The Assembly's handling of S1422A following the June 3, 2026 Senate vote is the primary item to watch for New York's data-protection posture. Its resolution, in either direction, would materially affect the state's algorithmic, biometric and surveillance governance regime and the protections available to minors and vulnerable groups outside New York City.
10 of 10 categories
Signal
Density
Selections OR within a group, AND across groups. Press / to search.
A robust sectoral/breach-security framework exists (SHIELD, NYDFS) but there is no omnibus statute defining lawful bases, controller obligations broadly, or a general registration duty.
Traffic-light rationale — AmberA robust sectoral/breach-security framework exists (SHIELD, NYDFS) but there is no omnibus statute defining lawful bases, controller obligations broadly, or a general registration duty.
Sub-modules (5)
Regulator And AuthorityGreen
The NY AG is the primary regulator; NYDFS is the sectoral financial-services cybersecurity regulator with independent enforcement powers.
Claims (1):
The New York State Attorney General is the primary enforcer of data security and privacy statutes in New York, including the SHIELD Act.
Act And InstrumentsAmber
Core instruments are the SHIELD Act, Civil Rights Law Art. 5, NYDFS 23 NYCRR Part 500, the Child Data Protection Act, and the SAFE for Kids Act.
Claims (1):
The SHIELD Act regulates data breach and data security matters in New York and expanded enforcement capabilities of the Attorney General.
Material ScopeAmber
Scope centers on 'private information' (SSNs, driver's license numbers, financial account data, and biometric data after SHIELD amendments) rather than a general personal-data definition.
Claims (1):
New York has not adopted a comprehensive data protection law and does not recognize a constitutional or common law right of privacy; privacy is instead regulated statutorily through Article 5 of the Civil Rights Law.
Territorial ScopeGreen
SHIELD Act security and breach obligations apply to any person or business that owns or licenses computerized private information of a NY resident, regardless of whether the business operates in New York.
Claims (1):
The security requirements of the SHIELD Act apply to any business that collects or maintains private information of a New York resident, giving the law broad extraterritorial reach.
Regulator Registration And FilingAmber
No general controller registration exists; NYDFS requires an annual Certification of Compliance from covered entities. A pending Senate Bill 9088 would create a data-broker registration/deletion regime but is not yet enacted.
Claims (2):
NYDFS Covered Entities must annually validate and submit a certificate of compliance with the Cybersecurity Regulation, signed by the board of directors or a senior officer.
Senate Bill 9088, introduced January 30, 2026, would require data brokers to register annually with the Attorney General, pay a fee, and disclose extensive information about their operations.
Category narrative96 words
New York has no single comprehensive data-protection statute. The New York Attorney General (Bureau of Internet & Technology) is the primary consumer-privacy enforcer, operating under the Stop Hacks and Improve Electronic Data Security Act (SHIELD Act, GBL Art. 39-F, §§899-aa/bb) and the Civil Rights Law Art. 5. The New York State Department of Financial Services (NYDFS) is the sectoral regulator for financial-services cybersecurity under 23 NYCRR Part 500. Material and territorial scope are defined breach-by-breach (private information of NY residents) rather than by a general 'personal data' concept, and there is no comprehensive controller/processor registration regime.
Sources and claims (6)
UncertainNYS Office of the Attorney General / DataGuidance — The New York State Attorney General is the primary enforcer of data security and privacy statutes in New York, including the SHIELD Act.observed
UncertainDataGuidance — The SHIELD Act regulates data breach and data security matters in New York and expanded enforcement capabilities of the Attorney General.observed
UncertainDataGuidance — New York has not adopted a comprehensive data protection law and does not recognize a constitutional or common law right of privacy; privacy is instead regulated statutorily through Article 5 of the Civil Rights Law.observed
UncertainIAPP — The security requirements of the SHIELD Act apply to any business that collects or maintains private information of a New York resident, giving the law broad extraterritorial reach.observed
UncertainDataGuidance — NYDFS Covered Entities must annually validate and submit a certificate of compliance with the Cybersecurity Regulation, signed by the board of directors or a senior officer.observed
UncertainDataGuidance — Senate Bill 9088, introduced January 30, 2026, would require data brokers to register annually with the Attorney General, pay a fee, and disclose extensive information about their operations.observed
Traffic-light rationale — RedNo general lawful-bases or special-category regime exists; coverage is fragmented and purpose-specific (children's data only).
Sub-modules (4)
Lawful BasesRed
No enumerated lawful-bases regime exists in New York law outside of sector statutes.
Absence provenance: unavailable. Searched: New York general lawful basis processing statute, NY comprehensive privacy law lawful bases.
Consent ThresholdsAmber
The CDPA requires clear, separate, easily revocable consent requests, with the most prominent option being to refuse consent, for covered users aged 13-17; users 12 and under face default processing restrictions absent a permitted purpose.
Claims (1):
The New York Child Data Protection Act mandates that consent requests be clear, separate from other transactions, and easily revocable, with the most prominent option being to refuse consent.
Special CategoriesRed
No general 'special category' data definition exists in NY statute akin to GDPR Art. 9; biometric identifier data receives distinct treatment only via the NYC local Biometric Identifier Information Law and pending state biometric bills.
Claims (1):
A state-wide biometric privacy bill (Assembly Bill 27) has been under consideration in the New York legislature, containing more onerous requirements than the existing NYC local biometric law and including a private right of action, but has not been enacted state-wide.
Pseudonymisation And AnonymisationRed
No NY state statutory definition of pseudonymisation/anonymisation was identified; education-sector contractual templates reference FERPA de-identification standards only.
Absence provenance: unavailable. Searched: New York pseudonymisation anonymisation statute, NY state law de-identification safe harbour.
Category narrative72 words
New York has no general lawful-basis framework analogous to GDPR Art. 6, nor a codified 'special category' regime. Consent standards appear only in narrow, purpose-specific statutes: the Child Data Protection Act (CDPA) requires informed, revocable consent for processing minors' data, and the SAFE for Kids Act requires parental consent for 'addictive feeds.' No statutory pseudonymisation/anonymisation safe-harbour exists at state level outside of education-sector guidance (Student Data Privacy Consortium templates referencing FERPA de-identification).
Sources and claims (2)
UncertainDataGuidance — The New York Child Data Protection Act mandates that consent requests be clear, separate from other transactions, and easily revocable, with the most prominent option being to refuse consent.observed
UncertainIAPP — A state-wide biometric privacy bill (Assembly Bill 27) has been under consideration in the New York legislature, containing more onerous requirements than the existing NYC local biometric law and including a private right of action, but has not been enacted state-wide.observed
Traffic-light rationale — RedNo comprehensive data-subject-rights statute exists; only sector-specific access/correction rights (education) were identified.
Sub-modules (5)
Access RightAmber
No general consumer access right exists; Education Law 2-d/FERPA gives parents/eligible students the right to review education records held by providers.
Claims (1):
Under New York education-sector data agreements, an LEA must establish reasonable procedures for a parent, legal guardian, or eligible student to review Education Records and correct erroneous information held by a service provider.
Rectification And ErasureAmber
No general erasure/rectification right exists outside the education sector, where parents may request correction of erroneous student data.
Claims (1):
Under New York education-sector data agreements, an LEA must establish reasonable procedures for a parent, legal guardian, or eligible student to review Education Records and correct erroneous information held by a service provider.
Restriction And ObjectionRed
No general restriction/objection right identified in NY state law.
Absence provenance: unavailable. Searched: New York right to restrict processing, NY consumer objection to processing statute.
Data PortabilityRed
No data-portability right exists under New York state law.
Absence provenance: unavailable. Searched: New York data portability right statute.
Deadlines And Response WindowsAmber
Where an education-sector response duty exists, providers must typically respond within 45 days of a parent/LEA request, or the state-law timeframe if shorter.
Claims (1):
Providers must respond to student-data record requests in a reasonably timely manner, no later than forty-five days from the date of request or the timeframe required under state law, whichever is sooner.
Category narrative54 words
New York lacks a general consumer data-subject-rights regime (no state-wide access, rectification, erasure, restriction, objection, or portability right analogous to CPRA/GDPR). Rights that exist are narrow and sector-bound: FERPA/Education Law 2-d gives parents access/correction rights over student education records via LEAs, and NYDFS rules give regulated entities internal audit obligations rather than consumer-facing rights.
Sources and claims (2)
UncertainDataGuidance — Under New York education-sector data agreements, an LEA must establish reasonable procedures for a parent, legal guardian, or eligible student to review Education Records and correct erroneous information held by a service provider.observed
UncertainDataGuidance — Providers must respond to student-data record requests in a reasonably timely manner, no later than forty-five days from the date of request or the timeframe required under state law, whichever is sooner.observed
Traffic-light rationale — AmberStrong security/breach regime (SHIELD + NYDFS) but no DPIA/DPO/ROPA/joint-controller framework generally applicable.
Sub-modules (7)
Accountability And DpiaAmber
No general DPIA duty exists; NYDFS requires periodic risk assessments as part of its Cybersecurity Regulation.
Claims (1):
NYDFS Covered Entities under 23 NYCRR Part 500 must identify reasonably foreseeable internal and external risks and assess the sufficiency of safeguards controlling those risks.
Dpo RequirementsAmber
No general DPO requirement exists; NYDFS requires designation of a CISO for regulated financial entities.
Claims (1):
NYDFS regulations require regulated entities to designate a qualified individual (CISO) responsible for overseeing and implementing the entity's cybersecurity program.
Ropa RequirementsRed
No records-of-processing-activities obligation exists under New York state law.
Absence provenance: unavailable. Searched: New York records of processing activities requirement.
Joint Controller ArrangementsRed
No joint-controller concept exists in New York statute; education-sector DPAs define 'Provider' and 'Subprocessor' roles contractually rather than by statute.
Absence provenance: unavailable. Searched: New York joint controller law.
Security MeasuresGreen
SHIELD Act requires businesses to develop, implement and maintain reasonable administrative, technical and physical safeguards; NYDFS 23 NYCRR 500 imposes detailed technical standards for regulated financial entities.
Claims (2):
The SHIELD Act requires businesses that own or license New York residents' private information to develop, implement and maintain reasonable safeguards including administrative, technical and physical safeguards.
The NYDFS Cybersecurity Regulation requires banks, insurance companies and other financial services institutions to establish and maintain a comprehensive cybersecurity programme covering governance, data management, incident planning, system testing, and data-incident reporting.
Breach NotificationGreen
SHIELD Act requires notification to affected NY residents and the Attorney General, with substitute-notice provisions and an exception where notice is already made under GLBA, HIPAA, or NYDFS rules.
Claims (2):
There is an exception to the SHIELD Act breach notification obligation if notification is already made pursuant to GLBA, HIPAA, NYDFS Cybersecurity Regulation, or another official government agency's regulations.
A business may use substitute notice for a data breach if it demonstrates to the New York Attorney General that the cost of providing notice would exceed $250,000 or that the affected class exceeds 500,000 persons.
Retention And DisposalGreen
SHIELD Act requires disposal of private information within a reasonable time after it is no longer needed, by erasing electronic media so information cannot be read or reconstructed.
Claims (1):
The SHIELD Act requires disposing of private information within a reasonable amount of time after it is no longer needed for business purposes by erasing electronic media so that the information cannot be read or reconstructed.
Category narrative57 words
New York imposes concrete security-program and breach-notification duties via the SHIELD Act and, for financial-services entities, the far more detailed NYDFS Cybersecurity Regulation (23 NYCRR Part 500). Neither statute mandates a formal DPIA or DPO in the GDPR sense, though NYDFS requires a CISO and periodic risk assessments. There is no general ROPA obligation or joint-controller framework.
Sources and claims (7)
UncertainDataGuidance — NYDFS Covered Entities under 23 NYCRR Part 500 must identify reasonably foreseeable internal and external risks and assess the sufficiency of safeguards controlling those risks.observed
UncertainDataGuidance — NYDFS regulations require regulated entities to designate a qualified individual (CISO) responsible for overseeing and implementing the entity's cybersecurity program.observed
UncertainIAPP — The SHIELD Act requires businesses that own or license New York residents' private information to develop, implement and maintain reasonable safeguards including administrative, technical and physical safeguards.observed
UncertainDataGuidance — The NYDFS Cybersecurity Regulation requires banks, insurance companies and other financial services institutions to establish and maintain a comprehensive cybersecurity programme covering governance, data management, incident planning, system testing, and data-incident reporting.observed
UncertainIAPP — There is an exception to the SHIELD Act breach notification obligation if notification is already made pursuant to GLBA, HIPAA, NYDFS Cybersecurity Regulation, or another official government agency's regulations.observed
UncertainNYS Office of the Attorney General / DataGuidance — A business may use substitute notice for a data breach if it demonstrates to the New York Attorney General that the cost of providing notice would exceed $250,000 or that the affected class exceeds 500,000 persons.observed
UncertainIAPP — The SHIELD Act requires disposing of private information within a reasonable amount of time after it is no longer needed for business purposes by erasing electronic media so that the information cannot be read or reconstructed.observed
No transfer-mechanism, adequacy, SCC/BCR, TIA, or localisation regime exists under NY state law; module reflects a genuine regulatory gap for this JID rather than incomplete research.
Traffic-light rationale — Not assessedNo transfer-mechanism, adequacy, SCC/BCR, TIA, or localisation regime exists under NY state law; module reflects a genuine regulatory gap for this JID rather than incomplete research.
Sub-modules (6)
Transfer MechanismsRed
No NY state-law transfer mechanism regime exists.
Absence provenance: unavailable. Searched: New York state law cross-border data transfer mechanism.
Adequacy ReceivedRed
Not applicable; New York is a sub-national US jurisdiction and does not receive adequacy decisions.
Absence provenance: unavailable. Searched: New York adequacy decision received.
Adequacy GrantedRed
Not applicable; New York does not grant adequacy decisions.
Absence provenance: unavailable. Searched: New York adequacy decision granted.
Sccs And BcrsRed
No SCC/BCR concept exists under New York law.
Absence provenance: unavailable. Searched: New York standard contractual clauses binding corporate rules.
Transfer Impact AssessmentRed
No TIA requirement exists under New York law.
Absence provenance: unavailable. Searched: New York transfer impact assessment requirement.
Data LocalisationRed
No general data-localisation mandate was identified for New York; NYDFS requirements are security-focused rather than location-based.
Absence provenance: unavailable. Searched: New York data localisation mandate, New York data residency requirement.
Category narrative51 words
New York state law contains no adequacy-decision mechanism, no SCC/BCR concept, and no transfer-impact-assessment requirement — these are EU/GDPR-derived constructs with no US state-law analogue. No New York data-localisation mandate was identified. Cross-border data transfer questions for NY-resident data are governed by federal instruments (e.g., GLBA, HIPAA) rather than state law.
Financial and employment sectors have mature, in-force overlays; health (non-HIPAA) and credit-scoring overlays remain largely proposed or federally-anchored.
Primary frameworkNYDFS 23 NYCRR Part 500 (financial) / Education Law 2-d (education) / Labor Law Art. 5 (employment)
Traffic-light rationale — AmberFinancial and employment sectors have mature, in-force overlays; health (non-HIPAA) and credit-scoring overlays remain largely proposed or federally-anchored.
Sub-modules (7)
Financial Sector OverlayGreen
NYDFS's Cybersecurity Regulation requires banks, insurers and other regulated financial entities to maintain a comprehensive cybersecurity programme with governance, incident-response and third-party oversight obligations.
Claims (1):
The NYDFS Cybersecurity Regulation, codified at 23 NYCRR Part 500, requires banks, insurance companies and other financial services institutions subject to NYDFS regulation to establish a comprehensive cybersecurity programme with governance, data-management, incident-planning, testing and reporting requirements.
Health Sector OverlayAmber
A comprehensive health-privacy bill (Senate Bill 9269, the New York Health Information Privacy Act) targeting health information not subject to HIPAA has been introduced with adjusted penalties, but is not yet enacted.
Claims (1):
Senate Bill 9269 for the New York Health Information Privacy Act mandates strict regulations on processing health information of New York residents not otherwise subject to HIPAA.
Telecoms And EprivacyRed
No New York state-specific ePrivacy/telecoms overlay analogous to the EU ePrivacy Directive was identified; cookie/tracking issues are addressed instead via older wiretap/eavesdropping statutes.
Absence provenance: unavailable. Searched: New York ePrivacy telecoms data law.
Employment DataGreen
New York Civil Rights Law §52-c requires notice before employee electronic monitoring is permitted; Labor Law §201-a prohibits fingerprinting as an employment condition; Labor Law §203-c restricts video recording of employees in sensitive areas; a 2021 law (S2628) requires written notice of electronic monitoring upon hiring.
Claims (2):
New York Civil Rights Law §52-c requires that notice be provided before any employee electronic monitoring is permitted, and Labor Law §203-c prohibits video recording employees in sensitive areas.
New York's 2021 electronic monitoring law requires employers who monitor or intercept employee communications or internet usage to give prior written notice upon hiring, acknowledged by the employee, and to post the notice conspicuously.
Credit And ScoringAmber
Credit-scoring privacy in New York is governed primarily by the federal Fair Credit Reporting Act; no distinct New York state credit-scoring privacy overlay was identified.
Absence provenance: unavailable. Searched: New York state credit scoring privacy law.
EducationAmber
New York Education Law 2-d and related student-data-privacy agreements (modeled on national Student Data Privacy Consortium templates) govern student data alongside federal FERPA.
Claims (1):
New York student-data-privacy agreements require providers to treat student data as the LEA's property, restrict onward sale, and permit parental review consistent with FERPA and Education Law 2-d.
InsuranceAmber
Insurance entities licensed by NYDFS fall within the scope of the Cybersecurity Regulation; no separate NY insurance-specific consumer-data statute beyond this was identified.
Claims (1):
The NYDFS Cybersecurity Regulation, codified at 23 NYCRR Part 500, requires banks, insurance companies and other financial services institutions subject to NYDFS regulation to establish a comprehensive cybersecurity programme with governance, data-management, incident-planning, testing and reporting requirements.
Category narrative67 words
New York's data-protection landscape is fundamentally sectoral. NYDFS's 23 NYCRR Part 500 governs financial-services cybersecurity; health information outside HIPAA is targeted by a pending New York Health Information Privacy Act (SB 9269); employment data is covered by a patchwork of Labor Law, Civil Rights Law, and General Business Law provisions plus the 2021 electronic-monitoring notice law; and education data is governed by Education Law 2-d alongside FERPA.
Sources and claims (5)
UncertainDataGuidance — The NYDFS Cybersecurity Regulation, codified at 23 NYCRR Part 500, requires banks, insurance companies and other financial services institutions subject to NYDFS regulation to establish a comprehensive cybersecurity programme with governance, data-management, incident-planning, testing and reporting requirements.observed
UncertainDataGuidance — Senate Bill 9269 for the New York Health Information Privacy Act mandates strict regulations on processing health information of New York residents not otherwise subject to HIPAA.observed
UncertainDataGuidance — New York Civil Rights Law §52-c requires that notice be provided before any employee electronic monitoring is permitted, and Labor Law §203-c prohibits video recording employees in sensitive areas.observed
UncertainDataGuidance — New York's 2021 electronic monitoring law requires employers who monitor or intercept employee communications or internet usage to give prior written notice upon hiring, acknowledged by the employee, and to post the notice conspicuously.observed
UncertainDataGuidance — New York student-data-privacy agreements require providers to treat student data as the LEA's property, restrict onward sale, and permit parental review consistent with FERPA and Education Law 2-d.observed
No dedicated adtech/cookie/cross-context-advertising statute exists in New York; the module records a genuine sectoral gap plus emergent wiretap-based litigation risk.
Primary frameworkPenal Law Art. 250 (Eavesdropping) — repurposed, not adtech-specific
Traffic-light rationale — RedNo dedicated adtech/cookie/cross-context-advertising statute exists in New York; the module records a genuine sectoral gap plus emergent wiretap-based litigation risk.
Sub-modules (6)
Cookies And TrackersAmber
No dedicated cookie-consent statute exists; New York's eavesdropping statute has been used analogously to California's CIPA in tracking-technology class actions.
Claims (1):
New York's decades-old anti-wiretapping/eavesdropping statutes have found new significance in privacy class-action litigation against automated tracking and transcription technologies, mirroring similar theories under the federal Electronic Communications Privacy Act.
Dark PatternsRed
No New York state dark-pattern prohibition was identified; enforcement in this space is federal (FTC Act) only.
Absence provenance: unavailable. Searched: New York dark pattern prohibition statute.
Opt Out SignalsRed
New York law does not mandate recognition of Global Privacy Control or other universal opt-out signals.
Absence provenance: unavailable. Searched: New York Global Privacy Control recognition law.
Clean Rooms And DcrRed
No New York statute addresses data clean rooms or data-collaboration-room governance.
Absence provenance: unavailable. Searched: New York data clean room regulation.
Cross Context AdvertisingAmber
New York has no CPRA-style 'sale'/'share' definition governing cross-context behavioral advertising. A pending Senate Bill 9088 would create data-broker obligations touching cross-context data flows.
Claims (1):
Senate Bill 9088 would require data brokers to disclose, among other things, whether consumer data was shared with foreign actors, government agencies, law enforcement, or AI system developers in the previous year.
Direct MarketingAmber
Retail tracking notice requirements (pending Senate Bill 2539) would mandate warning signs for electronic device tracking of customers, but this is not yet enacted; direct marketing consent otherwise flows through federal CAN-SPAM.
Claims (1):
New York Senate Bill 2539 would mandate that retailers post warning signs if tracking customers through electronic devices, with penalties for violations.
Category narrative64 words
New York has no CPRA-style 'sale'/'share' framework, no state cookie-consent statute, and no codified dark-pattern prohibition or Global Privacy Control recognition requirement. Adtech-adjacent enforcement instead flows through decades-old anti-wiretapping/eavesdropping statutes (Penal Law Art. 250) being repurposed in class-action litigation against tracking technologies, mirroring the federal ECPA and California's CIPA experience. A pending 'One Fair Price Act' would prohibit surveillance pricing based on personal data.
Sources and claims (3)
UncertainIAPP — New York's decades-old anti-wiretapping/eavesdropping statutes have found new significance in privacy class-action litigation against automated tracking and transcription technologies, mirroring similar theories under the federal Electronic Communications Privacy Act.observed
UncertainDataGuidance — Senate Bill 9088 would require data brokers to disclose, among other things, whether consumer data was shared with foreign actors, government agencies, law enforcement, or AI system developers in the previous year.observed
UncertainDataGuidance — New York Senate Bill 2539 would mandate that retailers post warning signs if tracking customers through electronic devices, with penalties for violations.observed
Meaningful AI-transparency and biometric law exists but is split between city-level ordinances (NYC) and pending/newly-effective state AI statutes; general ADM transparency and profiling restrictions remain state-law gaps.
Primary frameworkRAISE Act (as amended, SB 8828) / NYC Biometric Identifier Information Law (local, not state-wide)
Traffic-light rationale — AmberMeaningful AI-transparency and biometric law exists but is split between city-level ordinances (NYC) and pending/newly-effective state AI statutes; general ADM transparency and profiling restrictions remain state-law gaps.
Sub-modules (6)
Profiling RestrictionsAmber
No general state-wide profiling restriction exists; a pending bill (S7623) would restrict employer use of automated employment decision tools and require bias audits, but has not been enacted state-wide.
Claims (1):
Proposed Senate Bill 7623 would restrict employers' use of electronic monitoring and automated employment decision tools, requiring bias audits and documentation of employee-data-driven employment decisions, but remains pending.
Automated Decision Making TransparencyAmber
ADM transparency in New York is anchored at the New York City level (Local Law 144 bias-audit requirement for automated employment decision tools); no state-wide equivalent was identified.
Claims (1):
New York, alongside Illinois and Connecticut, finalized notable AI and privacy provisions during the 2026 legislative session, including transparency laws already on the books in New York referenced as comparators for new Illinois frontier-AI legislation.
Ai Risk AssessmentsAmber
Senate Bill 8828, amending the RAISE Act, mandates transparency and safety requirements for AI frontier model developers in New York State, effective January 1, 2027.
Claims (1):
Senate Bill 8828 amending the RAISE Act mandates transparency and safety requirements for AI frontier model developers in New York State, effective January 1, 2027.
Biometric RegimeAmber
The New York City Biometric Identifier Information Law (Admin Code §§22-1201-1205) requires notice before commercial establishments collect, retain, convert, store or share biometric identifier information and creates a private right of action with statutory damages of $500 to $5,000 per violation; a broader state-wide biometric privacy bill remains pending.
Claims (1):
The New York City biometric law creates a private right of action enabling aggrieved parties to collect statutory damages ranging from $500 to $5,000 per violation.
Genetic DataRed
No New York state-specific genetic-data statute was identified beyond federal GINA protections.
Absence provenance: unavailable. Searched: New York genetic data privacy statute.
State Surveillance CarveoutsRed
No New York state-law national-security/surveillance carve-out provisions specific to data protection were identified in this research pass.
Absence provenance: unavailable. Searched: New York state surveillance carveout data protection law.
Category narrative65 words
New York's algorithmic/biometric governance is concentrated at the New York City level (Local Law 144 automated employment decision tool bias audits; the Biometric Identifier Information Law) rather than state-wide, though the state RAISE Act (as amended by SB 8828) introduces frontier-AI transparency obligations effective January 1, 2027. A state-wide biometric privacy bill (Assembly Bill 27) remains pending. No comprehensive state ADM-transparency or profiling-restriction statute exists.
no periodic updates on record for this sub-brief
Sources and claims (4)
UncertainDataGuidance — Proposed Senate Bill 7623 would restrict employers' use of electronic monitoring and automated employment decision tools, requiring bias audits and documentation of employee-data-driven employment decisions, but remains pending.observed
UncertainIAPP — New York, alongside Illinois and Connecticut, finalized notable AI and privacy provisions during the 2026 legislative session, including transparency laws already on the books in New York referenced as comparators for new Illinois frontier-AI legislation.observed
UncertainDataGuidance — Senate Bill 8828 amending the RAISE Act mandates transparency and safety requirements for AI frontier model developers in New York State, effective January 1, 2027.observed
UncertainIAPP — The New York City biometric law creates a private right of action enabling aggrieved parties to collect statutory damages ranging from $500 to $5,000 per violation.observed
Traffic-light rationale — AmberStrong, recently-enacted children's-data statutes exist and cover consent, age-assurance and profiling-adjacent restrictions; dependent-adult protections remain an identified gap.
Sub-modules (5)
Age VerificationGreen
The SAFE for Kids Act requires providers to implement appropriate measures to determine whether a user is a minor before serving an addictive feed.
Claims (1):
The SAFE for Kids Act does not apply if the provider used reasonable methods to determine the user is not a minor or obtained parental consent, requiring providers to implement age-assurance measures.
Parental ConsentGreen
Both the CDPA and SAFE for Kids Act condition certain minors'-data processing/addictive-feed provision on parental consent.
Claims (2):
The SAFE for Kids Act prohibits social media platforms from providing an addictive feed to children younger than 18 without parental consent and prohibits withholding non-addictive alternatives where consent is not obtained.
For covered users 12 and younger, the CDPA restricts data processing unless permitted under specific regulations, while informed consent is required for users 13 and older unless necessary for certain activities.
Minor Profiling BansAmber
The CDPA restricts digital services from collecting or using personal data of users under 18 without consent and prohibits sale or disclosure of such data, indirectly constraining profiling-adjacent uses.
Claims (1):
The Child Data Protection Act restricts digital services from collecting or using personal data of users under 18 without consent and prohibits the sale or disclosure of such data.
Education SettingsAmber
Education Law 2-d and related student-data-privacy agreements govern data collected in NY school settings, layered atop federal FERPA and COPPA.
Claims (1):
New York student-data-privacy agreements require providers to treat student data as the LEA's property, restrict onward sale, and permit parental review consistent with FERPA and Education Law 2-d.
Dependent AdultsRed
No dependent-adult-specific (elderly/incapacitated) data-protection provision was identified in New York state law during this research pass.
Absence provenance: unavailable. Searched: New York dependent adult data protection law, New York elderly privacy statute.
Category narrative49 words
New York has two dedicated children's-data statutes: the Child Data Protection Act (CDPA), restricting collection/use/sale of minors' (under-18) personal data absent consent, and the SAFE for Kids Act, restricting 'addictive feeds' for minors absent parental consent (effective January 25, 2027, per current tracking). No dependent-adult-specific data-protection provision was identified.
no periodic updates on record for this sub-brief
Sources and claims (4)
UncertainDataGuidance — The SAFE for Kids Act does not apply if the provider used reasonable methods to determine the user is not a minor or obtained parental consent, requiring providers to implement age-assurance measures.observed
UncertainDataGuidance — The SAFE for Kids Act prohibits social media platforms from providing an addictive feed to children younger than 18 without parental consent and prohibits withholding non-addictive alternatives where consent is not obtained.observed
UncertainDataGuidance — For covered users 12 and younger, the CDPA restricts data processing unless permitted under specific regulations, while informed consent is required for users 13 and older unless necessary for certain activities.observed
UncertainDataGuidance — The Child Data Protection Act restricts digital services from collecting or using personal data of users under 18 without consent and prohibits the sale or disclosure of such data.observed
Enforcement activity is demonstrably active and well-resourced (AG + NYDFS), but the absence of a general private right of action for most NY privacy statutes limits collective redress.
Traffic-light rationale — AmberEnforcement activity is demonstrably active and well-resourced (AG + NYDFS), but the absence of a general private right of action for most NY privacy statutes limits collective redress.
Sub-modules (6)
Regulator Powers And PenaltiesAmber
SHIELD Act penalties are capped at $5,000 per violation for security-program failures and $20 per instance of failed breach notification, capped overall at $250,000; the AG may also seek injunctive relief.
Claims (1):
Companies that fail to comply with SHIELD Act security requirements may face civil penalties of up to $5,000 per violation, while breach-notification failures are penalized at $20 per instance, capped at $250,000.
Enforcement Activity IndexGreen
In its most recent reported year, the NY AG resolved allegations against 12 companies (litigating against two), securing over $14 million in penalties; NYDFS separately fined Delta Dental $2.25 million for cybersecurity violations.
Claims (2):
The New York Attorney General resolved allegations of privacy and cybersecurity breaches by settling with 12 companies, initiating litigation against two, and imposing financial penalties exceeding $14 million.
NYDFS fined Delta Dental $2.25 million for cybersecurity violations due to insufficient incident-response and reporting policies.
Regulator Funding And CapacityAmber
No specific budget/headcount disclosure for the AG's Bureau of Internet & Technology or NYDFS's cybersecurity division was identified in this research pass.
Absence provenance: unavailable. Searched: New York Attorney General Bureau of Internet Technology budget headcount, NYDFS cybersecurity division staffing.
Collective Redress And Class ActionsAmber
Wiretap/eavesdropping-based class actions against tracking and AI-transcription technologies are an emergent collective-redress vector in New York, alongside the NYC biometric law's private right of action.
Claims (2):
New York's decades-old anti-wiretapping/eavesdropping statutes have found new significance in privacy class-action litigation against automated tracking and transcription technologies, mirroring similar theories under the federal Electronic Communications Privacy Act.
The New York City biometric law creates a private right of action enabling aggrieved parties to collect statutory damages ranging from $500 to $5,000 per violation.
Private Right Of ActionAmber
The SHIELD Act expressly provides no private right of action; enforcement is AG-exclusive. By contrast, the NYC biometric ordinance does confer a private right of action with statutory damages.
Claims (1):
The SHIELD Act expressly provides that there is no private right of action; the Attorney General may pursue civil penalties for violations.
Recent Developments 180DAmber
Within the last 180 days, New York has advanced a data-broker registration bill (SB 9088, Jan 30 2026), the Synthetic Performer Disclosure Act, the Stealth Crawler Prohibition Act, an AI-companion-features-for-minors bill (SB 9051B), a generative-AI-notice bill (SB 934A), a chatbot-impersonation-liability bill (SB 7263), the Health Information Privacy Act (SB 9269), NYDFS guidance on threat-surface reduction, a $2.25M NYDFS fine against Delta Dental, and a 42-state-AG settlement with 23andMe's bankruptcy trustee over its 2023 breach.
Claims (3):
A coalition of 42 attorneys general reached a settlement with 23andMe's bankruptcy trustee over a 2023 data breach affecting 6.9 million customers.
NYDFS issued cybersecurity guidance focusing on reducing attack surfaces, improving threat detection, and strengthening resilience during heightened threat environments.
17 state attorneys general sued the federal administration over student data demands, citing privacy risks and legal uncertainties, and a judge temporarily blocked the data collection.
Category narrative86 words
The NY AG has robust civil-penalty and injunctive powers under the SHIELD Act ($5,000 per security violation; $20 per failed-notification instance capped at $250,000) but SHIELD expressly excludes a private right of action. The AG's Bureau of Internet & Technology has sustained an active enforcement cadence, and NYDFS separately fines regulated financial entities for cybersecurity lapses. Private rights of action exist narrowly (NYC biometric law) and via repurposed wiretap statutes in class litigation; a formal comprehensive collective-redress mechanism for general consumer privacy does not exist state-wide.
Sources and claims (7)
UncertainIAPP — Companies that fail to comply with SHIELD Act security requirements may face civil penalties of up to $5,000 per violation, while breach-notification failures are penalized at $20 per instance, capped at $250,000.observed
UncertainIAPP — The New York Attorney General resolved allegations of privacy and cybersecurity breaches by settling with 12 companies, initiating litigation against two, and imposing financial penalties exceeding $14 million.observed
UncertainDataGuidance — NYDFS fined Delta Dental $2.25 million for cybersecurity violations due to insufficient incident-response and reporting policies.observed
UncertainIAPP — The SHIELD Act expressly provides that there is no private right of action; the Attorney General may pursue civil penalties for violations.observed
UncertainDataGuidance — A coalition of 42 attorneys general reached a settlement with 23andMe's bankruptcy trustee over a 2023 data breach affecting 6.9 million customers.observed
UncertainDataGuidance — NYDFS issued cybersecurity guidance focusing on reducing attack surfaces, improving threat detection, and strengthening resilience during heightened threat environments.observed
UncertainDataGuidance — 17 state attorneys general sued the federal administration over student data demands, citing privacy risks and legal uncertainties, and a judge temporarily blocked the data collection.observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Publication gate
Blocking. 1 failing check(s).
schema_valid
pass
min_t1_per_instrument_met
n/a — no subject in this jurisdiction
min_quoted_text_present
waived — floor 0%
translation_provenance_recorded
n/a — no subject in this jurisdiction
egress_verified
pass
source_tier_integrity_ok
pass
jurisdiction_source_floor_met
FAIL
tier_a_b_national_primary_pct
9.52
aggregator_only_jurisdiction_count
0
manual_override
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for United States — New York
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
no reviewer on record
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 40 claim(s) (40 category placement(s)), 24 source(s) in the cumulative register.
regulator_and_framework, controller_processor_duties (security/breach), sectoral_watch (financial/employment), and children_and_vulnerable_groups modules rest on T1-T2 sources (SHIELD Act text/factsheet, NYDFS 23 NYCRR 500 primary analysis, signed statute announcements). lawful_processing_and_special_data, data_subject_rights, cross_border_and_adequacy, and adtech_and_commercial_privacy modules rely predominantly on T3 secondary summaries or explicit absent_field_provenance because New York has no omnibus statute covering these areas. algorithmic_biometric_and_surveillance_governance mixes T2 city-level primary analysis (NYC biometric/AEDT law) with T3 pending-bill tracking for state-wide equivalents. enforcement_and_redress draws on T2 AG/NYDFS enforcement-activity reporting supplemented by T3 recent-developments tracking.
Unresolved questions (5):
Has Senate Bill 8828 (RAISE Act amendment) been signed into law, or does it remain pending as of the run date?
Has Senate Bill 9269 (NY Health Information Privacy Act) advanced beyond introduction?
Is there a New York state-wide biometric privacy statute (Assembly Bill 27 or successor) enacted, or does NYC's local ordinance remain the only operative biometric-specific instrument?
Does New York state law contain any dependent-adult-specific data protection provision not surfaced in this research pass?
What is the current enactment status of Senate Bill 9088 (data broker registration) and Senate Bill 2539 (retail tracking notice)?