Similar to California before it, New York could serve as the next testing grounds for the next statewide consumer data privacy law.

The Government is laying the groundwork for a robust privacy law – one that could mirror the California Consumer Privacy Act (CCPA) – by providing similar privacy rights to consumers and enacting regulations around how companies process individuals’ data.

When Governor Andrew Cuomo released the state’s 2022 budget, it included a proposal for a comprehensive data privacy bill. In his lengthy, 322-page  State of the State report, Cuomo said he’d propose a law that would enable New Yorkers to better control and protect their data from attackers.

Similar to the CCPA, the goal of this law is transparency. CCPA does afford consumers the right to know what type of data is being collected about them and for which purposes, also whether it’s being shared or sold to other businesses or third parties.

Cuomo’s law, which would establish a Consumer Data Privacy Bill of Rights, would do a lot of the same as the CCPA. This bill would protect the information of individuals like health, biometric, and location data, as well as allow any New Yorker the ability to access, control, or erase any data on them. It would also give them “the right to discrimination, and the right to equal access to services.” This means that  businesses that collect information on a large amount of New Yorkers (the CCPA applies to businesses that buy, receive or sell data of 50,000 consumers or more) would have to disclose the purpose of the data they collect and only collect data for that purpose.

As of right now it’s just a proposal, and Cuomo’s office claims the legislation will also include “strong enforcement mechanisms to hold covered entities accountable for the illegal use of consumer data.”

At the surface, the concept of a privacy bill that can give consumers better control over their data certainly sounds like Cuomo wants to bring the state’s privacy protections up to par with the CCPA or even the European Union’s General Data Protection Regulation.

This shouldn’t come as a complete surprise that things are trending in this direction because New York has passed a handful of data privacy-focused bills over the last several years.

The state’s SHIELD Act, an update to New York’s data breach notification law also known as the Stop Hacks and Improve Electronic Data Security Act, is designed to keep organizations accountable for the safe handling of data went into effect last year. This legislation was aimed around getting employers to implement and maintain safeguards to protect the security, confidentiality, and integrity of private information they may control. In order to be in compliance with the SHIELD Act, New York businesses need a data security program that can assess and identify risk, prevent intrusions, and protect against the unauthorized access of private data.

The New York State Department of Financial Services’ Cybersecurity Regulation, which imposes mandatory requirements for financials outfits like banks and insurance companies, also requires organizations to develop a cybersecurity policy.

One of the first of its kind for states, the regulation also requires financial entities to meet a series of requirements, submit cybersecurity notices to the NYDFS Superintendent, and adhere to data breach notification guidelines.

Those of course are regulations already on the books in New York; that doesn’t cover legislation that’s still working its way through the state’s legislative session, including SB 567, which bears many similarities to the CCPA but includes a private right of action, Assembly Bill A680, or the New York Privacy Act, legislation some have called even bolder than CCPA, and Assembly Bill A405, which pertains to interest-based advertising.

While it is nearly impossible to anticipate every compliance obstacle that may come your way, you should be prepared to handle as many of them as possible. Being proactive now means that you’ll enjoy peace of mind later. If you have any questions on compliance or need any assistance CB Tech Group is here for you. Like we said earlier it is better to be prepared beforehand then later.