Bill Text: NY A06866 | 2015-2016 | General Assembly | Amended


Bill Title: Relates to the data security act.

Spectrum: Slight Partisan Bill (Democrat 6-2)

Status: (Introduced - Dead) 0000-00-00 - [A06866 Detail]

Download: New_York-2015-A06866-Amended.html


                STATE OF NEW YORK
        ________________________________________________________________________
                                          6866
                               2015-2016 Regular Sessions
                   IN ASSEMBLY
                                      April 8, 2015
                                       ___________
        Introduced by M. of A. DINOWITZ -- (at request of the Department of Law)
          --  read  once  and  referred to the Committee on Consumer Affairs and
          Protection
        AN ACT to amend the general business law and the state  technology  law,
          in relation to the data security act
          The  People of the State of New York, represented in Senate and Assem-
        bly, do enact as follows:
     1    Section 1. This act shall be known and may be cited as the "data secu-
     2  rity act".
     3    § 2. The opening paragraph and  paragraph  (b)  of  subdivision  1  of
     4  section  899-aa  of the general business law, as added by chapter 442 of
     5  the laws of 2005, are amended to read as follows:
     6    As used in this section, and section eight hundred  ninety-nine-bb  of
     7  this article, the following terms shall have the following meanings:
     8    (b)  "Private information" shall mean either: (i) personal information
     9  consisting of any information in combination with any one or more of the
    10  following data elements, when either the  personal  information  or  the
    11  data  element is not encrypted, or encrypted with an encryption key that
    12  has also been acquired:
    13    (1) social security number;
    14    (2) driver's license number or non-driver identification card  number;
    15  [or]
    16    (3)  account  number, credit or debit card number, in combination with
    17  any required security code, access code, or password that  would  permit
    18  access to an individual's financial account; or
    19    (4)  biometric  information, meaning data generated by automatic meas-
    20  urements of an individual's physical characteristics, which are used  by
    21  the owner or licensee to authenticate the individual's identity;
    22    (ii)  a  user  name or email address in combination with a password or
    23  security question and answer that  would  permit  access  to  an  online
    24  account; or
         EXPLANATION--Matter in italics (underscored) is new; matter in brackets
                              [ ] is old law to be omitted.
                                                                   LBD08145-09-5
feedback