NY AG Proposes Stricter Data Security Laws Citing Equifax Breach
Attorney General Eric Schneiderman is proposing comprehensive legislation to tighten state data security laws and expand data protections for New York residents in the aftermath of the Equifax breach that compromised 8 million New Yorkers among 145.5 million Americans.
November 02, 2017 at 04:13 PM
5 minute read
Following on the Equifax Inc. breach that compromised personal information of 145.5 million Americans including more than 8 million New Yorkers, Attorney General Eric Schneiderman is proposing comprehensive legislation to tighten data security laws and expand protections.
The Stop Hacks and Improve Electronic Data Security Act, introduced this week in the Legislature, would require companies that handle New Yorkers' sensitive data to adopt “reasonable administrative, technical and physical protections for data” regardless of where the company is headquartered, Schneiderman's office said in a news release Thursday. It would cover credit reporting agencies such as Equifax as well as many other types of companies that collect personally identifiable information on individuals.
The Attorney General's Office said it received a record 1,300 data breach notifications in 2016, a 60 percent increase over the previous year.
Business officials, speaking on background, said they wondered how such a proposal would be enforced considering the proposal extends to entities operating outside the state. The bill would apply the notice requirement to anyone holding private information of New Yorkers, a change from the current requirement that they “conduct business” in the state.
Under the legislation, reporting requirement triggers would include username and password combinations, biometric data and health data covered by the federal Health Insurance Portability and Accountability Act of 1996. Current New York state law requires that companies meet data security requirements only if the identifiable information contains a Social Security number, according to the Attorney General's Office.
“It's clear that New York's data security laws are weak and outdated. The SHIELD Act would help ensure these hacks never happen in the first place. It's time for Albany to act, so that no more New Yorkers are needlessly victimized by weak data security measures and criminal hackers who are constantly on the prowl,” Schneiderman said in the release.
Schneiderman's program bill, introduced by state Sen. David Carlucci and Assemblyman Brian Kavanagh, both Democrats who lead their respective chambers' consumer protection bureaus, would allow the Attorney General's Office to seek civil penalties and injunctions if companies don't provide adequate security for their data.
The civil penalty would be $5,000 for each violation or up to $20 per instance of failed notification, provided that the latter's aggregate amount doesn't exceed $250,000. The legislation would also require that companies who handle sensitive user data to provide consumers with broader information when a data breach is attempted or occurs, Schneiderman's office said.
The legislation provides flexibility for small businesses with fewer than 50 employees, who have gross revenue under $3 million for the last three fiscal years or less than $5 million in year-end total assets. According to the legislation, small businesses would be deemed compliant if they “implement and maintain reasonable safeguards that are appropriate to the size and complexity of the small business to protect the security, confidentiality and integrity of the private information.”
Also under the bill, companies that obtain independent certification that their data security measures meet the highest standard would receive safe harbor from state enforcement action.
David Zetoony, leader of Bryan Cave's global data privacy and security practice, praised the provision in the AG's news release, saying it is “providing a safe harbor for companies that go above-and-beyond to certify good data security is innovative, unique and friendly to business”.
The Business Council of New York State Inc., an association of more than 2,400 private sector employers, is still in discussion with Schneiderman's office over the legislation, a spokesman for the organization told the New York Law Journal.
“Businesses are not the bad actors in the scenario,” said spokesman Zack Hutchins. “They're interested in securing their customer data.”
The legislation comes roughly two months after the massive breach of the major consumer credit reporting agency Equifax. Schneiderman's office opened up an investigation into Equifax in September. The state's Department of Financial Services, which regulates the banking insurance and other financial institutions, is also investigating the Equifax breach.
Following the Equifax breach, New York Gov. Andrew Cuomo proposed new regulations that would subject consumer credit reporting agencies to the same groundbreaking cybersecurity rules that the state recently enacted for bank and insurance companies. Under the proposed rules, credit reporting agencies such as Equifax, TransUnion and Experian would have to register with the state Department of Financial Services beginning in February and every year thereafter. Credit reporting agencies, under Cuomo's proposal, would have to have state-approved cybersecurity plans.
A spokeswoman for the Consumer Data Industry Association, the trade group representing credit reporting agencies, said in an email that the organization is reviewing Schneiderman's proposal. In a hearing last week before a state Senate panel, Eric Ellman, the senior vice president of public policy and legal affairs at the Consumer Data Industry Association, based in Washington, D.C., said further laws weren't necessary and lawmakers should be focusing on mitigating cybersecurity threats.
Separately, on Wednesday, the AG's office announced a $700,000 settlement with Hilton Domestic Operating Co. Inc., formerly known as Hilton Worldwide Inc., after 350,000 credit card numbers were exposed in two separate breaches in 2015.
This content has been archived. It is available through our partners, LexisNexis® and Bloomberg Law.
To view this content, please continue to their sites.
Not a Lexis Subscriber?
Subscribe Now
Not a Bloomberg Law Subscriber?
Subscribe Now
NOT FOR REPRINT
© 2025 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.
You Might Like
View AllJustice 'Weaponization Working Group' Will Examine Officials Who Investigated Trump, US AG Bondi Says
Lawyers Across Political Spectrum Launch Public Interest Team to Litigate Against Antisemitism
4 minute read'Landmark' New York Commission Set to Study Overburdened, Under-Resourced Family Courts
Trending Stories
- 1Landlord Must Pay Prevailing Tenants' $21K Attorney Fees in Commercial Lease Dispute, Appellate Court Rules
- 2Compliance with EU AI Act Lags Behind As First Provisions Take Effect
- 3NJ's Pardons and Commutations A Model for the Federal System
- 4As Political Retribution Intensifies, Look to Navalny's Lawyers
- 5Family Law Practitioners Weigh In on Court System's New Joint Divorce Program
Who Got The Work
J. Brugh Lower of Gibbons has entered an appearance for industrial equipment supplier Devco Corporation in a pending trademark infringement lawsuit. The suit, accusing the defendant of selling knock-off Graco products, was filed Dec. 18 in New Jersey District Court by Rivkin Radler on behalf of Graco Inc. and Graco Minnesota. The case, assigned to U.S. District Judge Zahid N. Quraishi, is 3:24-cv-11294, Graco Inc. et al v. Devco Corporation.
Who Got The Work
Rebecca Maller-Stein and Kent A. Yalowitz of Arnold & Porter Kaye Scholer have entered their appearances for Hanaco Venture Capital and its executives, Lior Prosor and David Frankel, in a pending securities lawsuit. The action, filed on Dec. 24 in New York Southern District Court by Zell, Aron & Co. on behalf of Goldeneye Advisors, accuses the defendants of negligently and fraudulently managing the plaintiff's $1 million investment. The case, assigned to U.S. District Judge Vernon S. Broderick, is 1:24-cv-09918, Goldeneye Advisors, LLC v. Hanaco Venture Capital, Ltd. et al.
Who Got The Work
Attorneys from A&O Shearman has stepped in as defense counsel for Toronto-Dominion Bank and other defendants in a pending securities class action. The suit, filed Dec. 11 in New York Southern District Court by Bleichmar Fonti & Auld, accuses the defendants of concealing the bank's 'pervasive' deficiencies in regards to its compliance with the Bank Secrecy Act and the quality of its anti-money laundering controls. The case, assigned to U.S. District Judge Arun Subramanian, is 1:24-cv-09445, Gonzalez v. The Toronto-Dominion Bank et al.
Who Got The Work
Crown Castle International, a Pennsylvania company providing shared communications infrastructure, has turned to Luke D. Wolf of Gordon Rees Scully Mansukhani to fend off a pending breach-of-contract lawsuit. The court action, filed Nov. 25 in Michigan Eastern District Court by Hooper Hathaway PC on behalf of The Town Residences LLC, accuses Crown Castle of failing to transfer approximately $30,000 in utility payments from T-Mobile in breach of a roof-top lease and assignment agreement. The case, assigned to U.S. District Judge Susan K. Declercq, is 2:24-cv-13131, The Town Residences LLC v. T-Mobile US, Inc. et al.
Who Got The Work
Wilfred P. Coronato and Daniel M. Schwartz of McCarter & English have stepped in as defense counsel to Electrolux Home Products Inc. in a pending product liability lawsuit. The court action, filed Nov. 26 in New York Eastern District Court by Poulos Lopiccolo PC and Nagel Rice LLP on behalf of David Stern, alleges that the defendant's refrigerators’ drawers and shelving repeatedly break and fall apart within months after purchase. The case, assigned to U.S. District Judge Joan M. Azrack, is 2:24-cv-08204, Stern v. Electrolux Home Products, Inc.
Featured Firms
Law Offices of Gary Martin Hays & Associates, P.C.
(470) 294-1674
Law Offices of Mark E. Salomone
(857) 444-6468
Smith & Hassler
(713) 739-1250