On July 25, New York Governor Andrew Cuomo signed into law a pair of bills establishing new requirements for businesses that process certain personal information related to New York residents. The changes include expanding the scope of information covered by New York’s data breach notification law; defining breaches to include incidents involving unauthorized access to covered information, even where the information is not acquired; and requiring consumer reporting agencies who suffer breaches of social security numbers to offer up to 5 years of identity theft services. Businesses maintaining the private information of New York residents also will now be required to proactively develop “reasonable safeguards” within their organization as part of a new “reasonable security requirement.”
The “Stop Hacks and Improve Electronic Data Security Act” (SHIELD Act) expands the types of information covered by New York’s data breach notification law by adding:
- Account numbers and credit or debit card numbers if compromised in circumstances where the numbers could be used to access the associated accounts without additional information;
- Biometric information, defined as unique physical or digital representations of biometric data “used to authenticate or ascertain” a person’s identity; and
- Online account credentials (username or e-mail address in combination with password or security question and answer).