Requires all municipal corporations to report cybersecurity incidents and demands of ransom payments to the division of homeland security and emergency services; defines terms; requires cybersecurity incident reviews; requires cybersecurity awareness training, cybersecurity protection and data protection standards for state maintained information systems.
Requires all municipal corporations to report cybersecurity incidents and demands of ransom payments to the division of homeland security and emergency services; defines terms; requires cybersecurity incident reviews; requires cybersecurity awareness training, cybersecurity protection and data protection standards for state maintained information systems.
This bill (A 428) protects New York users of paid online dating services by setting clear consumer safeguards. It limits subscription contracts to $1,000 total (with exceptions for short-term plans), bans requiring forced add-on services (like grooming), and guarantees a minimum number of matches per month for paid plans over $25. Users gain the right to cancel without penalty if matches aren't delivered for two months, receive a refund (minus a small fee), and get their personal data deleted or returned upon cancellation. The law directly affects all paid online dating platforms operating in New York, ensuring transparency and reducing deceptive practices.
This bill amends New York's penal law and related statutes to explicitly include "medical information" and "health insurance information" in the legal definition of "personal identifying information." It defines medical information as details about an individual's medical history or treatment, and health insurance information as policy numbers, subscriber IDs, or claims history. These changes mean that identity theft involving such sensitive health data will now be covered under existing identity theft laws, which previously did not explicitly include these categories. The bill also removes outdated definitions from related laws to streamline the updated framework.
Directs that state agencies require that procurement of end point devices be consistent with any relevant standards, guidelines, or guidance developed as part of the National Institute of Standards and Technology (NIST) Cybersecurity Framework.
Relates to the disclosure of automated employment decision-making tools; requires the office of information technology services to maintain an artificial intelligence inventory; provides that the use of artificial intelligence systems shall not affect the existing rights of employees pursuant to an existing collective bargaining agreement, or the existing representational relationships among employee organizations or the bargaining relationships between the employer and an employee organization.
S 804 amends New York's data breach notification law to clarify when and how financial institutions must notify the Department of Financial Services (DFS) after a breach affecting New York residents. It requires covered financial institutions (as defined by current DFS rules) to provide DFS with details about the breach - including timing, content, and number of affected people - without delaying direct notifications to consumers. The bill specifies that this notification to DFS is only mandatory for financial institutions, not all businesses, and must follow existing DFS reporting rules (23 NYCRR 500.17). The law, signed as Chapter 91 on February 14, 2025, streamlines reporting for regulated financial entities while maintaining direct consumer notification timelines.