Skip to main content

Nixon Peabody LLP

  • People
  • Capabilities
  • Insights
  • About
Trending Topics
    • People
    • Capabilities
    • Insights
    • About
    • Locations
    • Events
    • Careers
    • Alumni
    Practices

    View All

    • Affordable Housing
    • Community Development Finance
    • Corporate & Finance
    • Cybersecurity & Privacy
    • Entertainment & Media
    • Environmental
    • Franchising & Distribution
    • Government Investigations & White Collar Defense
    • Healthcare
    • Intellectual Property
    • International Services
    • Labor, Employment, and Benefits
    • Litigation
    • Private Wealth & Advisory
    • Project Finance
    • Public Finance
    • Real Estate
    • Regulatory & Government Relations
    Industries

    View All

    • Aviation
    • Cannabis
    • Consumer
    • Energy
    • Financial Services
    • Healthcare
    • Higher Education
    • Infrastructure
    • Manufacturing
    • Nonprofit Organizations
    • Real Estate
    • Sports & Stadiums
    • Technology
    Value-Added Services

    View All

    • Alternative Fee Arrangements

      Developing innovative pricing structures and alternative fee agreement models that deliver additional value for our clients.

    • Continuing Education

      Advancing professional knowledge and offering credits for attorneys, staff and other professionals.

    • Crisis Advisory

      Helping clients respond correctly when a crisis occurs.

    • DEI Strategic Services

      Providing our clients with legal, strategic, and practical advice to make transformational changes in their organizations.

    • eDiscovery

      Leveraging law and technology to deliver sound solutions.

    • Environmental, Social, and Governance (ESG)

      We help clients create positive return on investments in people, products, and the planet.

    • Global Services

      Delivering seamless service through partnerships across the globe.

    • Innovation

      Leveraging leading-edge technology to guide change and create seamless, collaborative experiences for clients and attorneys.

    • IPED

      Industry-leading conferences focused on affordable housing, tax credits, and more.

    • Legal Project Management

      Providing actionable information to support strategic decision-making.

    • Legally Green

      Teaming with clients to advance sustainable projects, mitigate the effects of climate change, and protect our planet.

    • Nixon Peabody Trust Company

      Offering a range of investment management and fiduciary services.

    • NP Capital Connector

      Bringing together companies and investors for tomorrow’s new deals.

    • NP Second Opinion

      Offering fresh insights on cases that are delayed, over budget, or off-target from the desired resolution.

    • NP Trial

      Courtroom-ready lawyers who can resolve disputes early on clients’ terms or prevail at trial before a judge or jury.

    • Social Impact

      Creating positive impact in our communities through increasing equity, access, and opportunity.

    • Women in Dealmaking

      We provide strategic counsel on complex corporate transactions and unite dynamic women in the dealmaking arena.

    1. Home
    2. Insights
    3. Alerts
    4. State Senate Committee introduces the New York Privacy Act

      Alerts

    Alert / Cybersecurity & Privacy

    State Senate Committee introduces the New York Privacy Act

    May 15, 2024

    LinkedInX (Twitter)EmailCopy URL

    By Timothy Sini and Jenny HolmesJared Kaiman (Legal Intern–Government Investigations and White Collar Defense Group) assisted with the preparation of this alert.

    What’s the impact?

    • The Act applies to legal persons and entities that conduct business in New York or produce products or services targeted to residents of New York.
    • Consumer data and sensitive personal data require different levels of protection under the Act.
    • Businesses must provide clear mechanisms for consumers to opt-out of certain data use activities.

    DOWNLOAD

    New York Privacy Act (PDF)

    We’ve watched state after state follow in California’s footsteps and pass comprehensive privacy laws, but New York has remained noticeably quiet. Instead, New York’s legal data privacy landscape is unclear and often lacks transparency, making it difficult for both New York businesses and individuals to navigate.

    New Yorkers cannot evaluate the risks of sharing their personal data with businesses and compare privacy-related protections across services and at the same time, New York businesses are faced with increasing consumer demands for transparency. With a substantial increase in the amount and categories of personal data being generated, collected, stored, analyzed, and potentially shared, it is increasingly clear that New York’s legal landscape needs to evolve to address the uncertainties.

    What is the New York Privacy Act?

    Senate Bill S365B, also known as The New York Privacy Act (the Act), is currently in Senate Committee and aims to create a level playing field between New Yorkers who provide data through interactions with businesses (consumers) and businesses. The Act applies to legal persons that conduct business in New York or produce products or services targeted to residents of New York and that meet one of the following three thresholds:

    • Have annual gross revenue of $25 million dollars or more,
    • Controls or processes personal data of 50,000 consumers or more, or
    • Derives over 50% of gross revenue from the sale of personal data.

    If the thresholds look familiar, they largely track other state laws except for the number of consumers; California, for example, has a threshold of 100,000 consumers or more.

    Consumer data

    The Act categorizes businesses that handle consumers’ data into three distinct groups: controllers, processors, and third-parties, each of which has its own distinct obligations under the Act. As defined in the Act:

    • a controller is a person or legal entity who determines the purpose and means of processing personal data;
    • a processor is a person or legal entity that processes data on behalf of the controller; and
    • a third party, with respect to a particular interaction or occurrence, is a person, public authority, agency, or body other than the consumer, controller or processor, unless they also meet the criteria for a controller.

    The Act primarily focuses on controllers, which is the business that consumers are usually in direct contact with.

    Sensitive data

    The Act also follows other states’ laws in its definitions of personal data. Like California, the Act creates a category of “sensitive data,” that requires higher protections, such as health condition or diagnosis; racial or ethnic origin; precise geolocation; or social security, financial account, passport, or driver’s license number.

    Data transparency obligations

    Since the Act aims to create transparency between consumers and controllers, the obligations of the businesses are both structural and procedural in nature. Like other state privacy laws, the Act seeks to provide New York consumers with rights as it pertains to their personal data. These rights include, but are not limited to, the right to notice, the right to opt-out, the right to access, the right to portable data, the right to correct, and the right to delete. Further, a controller must obtain freely given, specific, informed, and unambiguous opt-in consent from a consumer to process their sensitive data or make changes to the existing processing or processing purpose and provide consumers with clear disclosures that are separate and apart from any contract or privacy policy.

    Opt-out mechanisms

    The Act requires that controllers allow consumers to opt out, at any time, of processing personal data for purposes of: (i) targeted advertising; (ii) the sale of personal data; and (iii) profiling in furtherance of decisions with legal or similarly significant effects concerning a consumer. Like the CCPA’s concept of “sharing” data, targeted advertising is advertising based upon profiling of a consumer’s behavior. The Act’s definition of “sale” also tracks the CCPA’s broad definition, including both monetary and other valuable consideration. However, the Act adds a new concept —profiling. The Act defines “profiling” to mean any form of automated processing on personal data to evaluate, analyze, or predict personal aspects related to an individual’s economic situation, health, personal preference, interests, reliability, behavior, location, or movements. Profiling does not include evaluation, analysis, or predictions based solely upon a person’s current search queries or activities on a controller’s website or online application. While the Act does not preclude a business from engaging in targeted advertising, selling data, or profiling, it must provide clear mechanisms for consumers to opt-out and cannot ask consumers to opt back in.

    Additional obligations for businesses

    Some other responsibilities of businesses include, but are not limited to, maintaining reasonable data security for personal data; notifying consumers of foreseeable harms arising from the use of their data and obtaining specific consent for that use; and conducting regular assessments to ensure that the data is not being used for unacceptable purposes.

    The future of the New York Privacy Act

    While many would welcome the Act, is it too late? Two US legislators recently unveiled a bipartisan plan to enact the first comprehensive federal data privacy law, the American Privacy Rights Act (APRA). However, APRA would preempt state law in most instances. So while we wait to see what the New York Senate Committee does with the Act, it could quickly become moot.

    Practices

    Cybersecurity & Privacy

    Insights And Happenings

    • Alert

      FTC amends and broadens Health Breach Notification Rule

      May 22, 2024
    • Alert

      Maryland enacts comprehensive data privacy act

      May 21, 2024
    • Alert

      BIPA Reform Bill addressing One-Time Claim Accrual and Electronic Signature passes Illinois Legislature

      May 20, 2024
    The foregoing has been prepared for the general information of clients and friends of the firm. It is not meant to provide legal advice with respect to any specific matter and should not be acted upon without professional counsel. If you have any questions or require any further information regarding these or other related matters, please contact your regular Nixon Peabody LLP representative. This material may be considered advertising under certain rules of professional conduct.

    Subscribe to stay informed of the latest legal news, alerts, and business trends.Subscribe

    • People
    • Capabilities
    • Insights
    • About
    • Locations
    • Events
    • Careers
    • Alumni
    • Cookie Preferences
    • Privacy Policy
    • Terms of Use
    • Accessibility Statement
    • Statement of Client Rights
    • Purchase Order Terms & Conditions
    • Nixon Peabody International LLC
    • PAL
    © 2025 Nixon Peabody. All rights reserved