Law / United States / New York

New York

United States law applies in New York New York is a state of the United States, whose 32 researched instruments are listed on the United States page, not here. The law of New York, described on this page below, applies here too.
New York has 1 local jurisdiction That local jurisdiction has law of its own, on a page of its own, listed below.

20 of 23 named instruments researched to a stage, across five of the six areas of law we track: 14 in force, 2 enacted but not yet in force and 4 proposed. As of 20 September 2026.

When they take effect14 of 20 carry a date, 6 do not.
2019: 2 instruments (2 in force) ’19 2020: 1 instrument (1 in force) 2021: 1 instrument (1 in force) 2022: 0 instruments 2023: 2 instruments (2 in force) 2024: 2 instruments (2 in force) 2025: 3 instruments (3 in force) ’25 2026: 2 instruments (2 in force) 2027: 1 instrument (1 enacted but not yet in force) ’27 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 11
  2. Privacy law 2
  3. Scraping law 2
  4. Cybersecurity law 2
  5. Age gating law 3
  6. News aggregation law none researched

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law11 instruments, 7 in force, 4 proposed

Research summary (266 words)

New York diverges sharply from the federal ai baseline of two proposed-only measures, with one enacted frontier-model safety statute and a cluster of enacted and pending synthetic-media disclosure laws.

The Responsible AI Safety and Education Act (RAISE Act), signed December 19, 2025 and in force since March 19, 2026, requires developers of large frontier AI models to publish safety and security protocols, undergo independent audits, and report safety incidents to the Attorney General within 72 hours, with no private right of action.

A family of disclosure statutes reaches synthetic and AI-altered media in different contexts: intimate-image and digital-replica deepfakes are reached by criminal and civil-liability provisions of the Penal Law and Civil Rights Law, materially deceptive AI media in political communications must be disclosed under the Election Law, advertisements using a synthetic performer must be disclosed under the General Business Law, and an AI companion operator must disclose that a user is talking to a machine and screen for self-harm risk.

New York City's own automated employment decision tool bias-audit law is researched separately at the city jurisdiction level and is not restated here. Several additional measures have passed one or both houses of the Legislature but await further action: an AI training-data transparency act, a content-provenance and anti-deepfake act, a prohibition on unsafe AI companion features for minors, and a broader automated-decision-system disclosure act.

New York's Legislative Oversight of Automated Decision-making in Government (LOADinG) Act, State Technology Law article 4 (signed December 21, 2024), binds only state agencies' own use of automated decision-making systems and is not catalogued here as an instrument for that reason.

AI governance

Responsible AI Safety and Education Act (RAISE Act)

N.Y. Gen. Bus. Law art. 44-B (§§ 1420-1425), ch. 699 of 2025New York State Senate, bill text and enactment history for S6953-B (2025)

In force 6 months, effective 19 March 2026. Binds private bodies.

What this law does

A large developer of a frontier AI model must implement a written safety and security protocol before deploying the model, retain an unredacted copy of it for as long as the model is deployed plus five years, conspicuously publish a redacted copy and transmit that copy to the Attorney General and the Division of Homeland Security and Emergency Services, and grant either of them access to the protocol on request.

It must record the specific tests and test results behind any assessment the section or its own protocol requires, in enough detail for a third party to replicate the testing procedure, and retain those for the same period.

It must not deploy a frontier model that would create an unreasonable risk of critical harm, must review its protocol annually and republish it if that review makes a material modification, must disclose each safety incident to the Attorney General and the Division within 72 hours, and must not knowingly make false or materially misleading statements in the documents the section produces.

The Attorney General may bring a civil action for a civil penalty of up to $10,000,000 for a first violation and $30,000,000 for any subsequent violation, or for injunctive or declaratory relief; the act creates no private right of action. Signed December 19, 2025 as chapter 699 of the Laws of 2025, and in force since March 19, 2026, the ninetieth day after enactment.

Note that the enacted print, S6953-B, carries no third-party audit: the annual independent audit of compliance, its report contents and its publication duty appeared in the original print and in S6953-A and were dropped before passage, and the word audit does not appear in the chaptered text.

What it requires

AI prohibited practices

Private right of action for unlawful dissemination or publication of a sexually explicit depiction (digital replica)

N.Y. Civ. Rights Law § 52-cNew York Consolidated Laws, Civil Rights Law, as published by the New York State Senate

In force since 3 May 2024. Binds public and private bodies.

What this law does

A depicted individual has a civil cause of action against a person who discloses, disseminates or publishes sexually explicit material showing them that was created or altered through digitization (defined to include software, machine learning, artificial intelligence, or other computer-generated or technological means) without their consent, where the defendant knew or should have known that consent was lacking.

A disclaimer stating the depiction is unauthorized or fabricated is not a defense, and the finder of fact may award injunctive relief, punitive damages, compensatory damages, and attorney's fees.

What it requires

Prohibition on Unsafe AI Companion Features for Minors

N.Y. Gen. Bus. Law art. 48 (proposed §§ 1800-1805), S9051-BNew York State Senate, bill text and status for S9051-B (2025)

Proposed: draft date not recorded. Finalized, with one agreed text, dated 5 June 2026, as of 12 September 2026. Binds private bodies.

What this law does

This measure is proposed and binds nobody yet.

As passed by both houses, it would bar an operator from providing an AI companion with unsafe features to a covered minor, including outputs that facilitate suicide, self-harm, disordered eating or sexually explicit conduct, outputs that encourage secrecy or self-isolation, features deceptive as to the companion's non-human, non-sentient nature, and engagement-optimizing outputs that override the companion's own safety guardrails, unless the operator uses a permitted age-assurance method to confirm the user is not a minor.

The Attorney General enforces the act, which the active print would take effect January 1, 2027. Passed the Senate and Assembly in June 2026; not yet delivered to or acted on by the Governor as of this review.

What it requires

Right of publicity, digital replica of a deceased performer

N.Y. Civ. Rights Law § 50-fNew York Consolidated Laws, Civil Rights Law, as published by the New York State Senate

In force 9 months, effective 19 December 2025. Binds public and private bodies.

What this law does

A person who uses a deceased performer's digital replica, a newly created, computer-generated, highly realistic electronic representation of their voice or visual likeness, in an audiovisual work, sound recording, or live musical performance, knowing the use was unauthorized by the applicable right holder, is liable for the greater of $2,000 or the injured party's compensatory damages, plus disgorgement of the defendant's profits and, in the court's discretion, punitive damages.

The section exempts parody, satire, commentary, documentaries and similar works, and news, public affairs and political-campaign uses. The digital replica provisions were first enacted effective 23 December 2022 and were further revised, per the consolidated law page's own revision history, effective 19 December 2025.

What it requires

Unlawful dissemination or publication of an intimate image (digitization amendment)

N.Y. Penal Law § 245.15New York Consolidated Laws, Penal Law, as published by the New York State Senate

In force since 1 December 2023. Binds public and private bodies.

What this law does

It is a class A misdemeanor to intentionally disseminate or publish an intimate image of another person without consent and with intent to cause emotional, financial or physical harm, including an image created or altered by digitization; the statute defines digitization to mean altering an image in a realistic manner using images of a person other than the person depicted, or computer-generated images.

The offense applies regardless of the actor's role in creating the original image, so a person who disseminates an AI-generated or AI-altered intimate depiction is exposed on the same terms as one who disseminates an unaltered photograph.

What it requires

AI risk obligations

New York Artificial Intelligence Act

N.Y. Civ. Rights Law art. 10-A (proposed §§ 105-115); amd. Exec. Law § 296, S1169-B, pending in the AssemblyNew York State Senate, bill text and status for S1169-A/B (2025)

Proposed: draft date not recorded. Before the second chamber, dated 3 June 2026, as of 12 September 2026. Binds private bodies.

What this law does

This measure is proposed and binds nobody yet.

As passed by the Senate, it would add a new Civil Rights Law article 10-A requiring a company (a deployer) using a high-risk AI system for a consequential decision (covering, among other categories, employment, education, housing and essential utilities) to disclose that use to the affected individual at least five business days in advance, conduct regular fairness and non-discrimination impact assessments, and preserve the individual's option to request human review.

An earlier print passed the Senate in June 2025 and died in the Assembly in January 2026; the Senate repassed a new print, S1169-B, on June 3, 2026, which as of this review is pending before the Assembly Ways and Means Committee.

What it requires

AI training data

Artificial Intelligence Training Data Transparency Act

N.Y. Gen. Bus. Law art. 44-C (proposed §§ 1430-1432), A6578-B / S6955New York State Senate, bill text and status for A6578-B (2025)

Proposed: draft date not recorded. Finalized, with one agreed text, dated 4 June 2026, as of 12 September 2026. Binds private bodies.

What this law does

This measure is proposed and binds nobody yet. As passed by both houses, it would require a developer of a generative AI model or service made available to New York users to publicly post documentation describing the training data used, including its sources, whether it includes copyrighted, personal or aggregate consumer information, the collection time period, and whether synthetic data generation was used, with exemptions for aviation-safety and federal defense systems.

Passed the Assembly and was delivered to the Senate on May 5, 2026, and passed the Senate on June 4, 2026; not yet delivered to or acted on by the Governor as of this review.

What it requires

AI transparency

AI Content Provenance and Stop Deepfakes Act

N.Y. Gen. Bus. Law art. 45-A (proposed §§ 1510-1513), S6954-B / A6540New York State Senate, bill text and status for S6954-A (2025)

Proposed: draft date not recorded. Finalized, with one agreed text, dated 4 June 2026, as of 12 September 2026. Binds private bodies.

What this law does

This measure is proposed and binds nobody yet. As passed by both houses, it would require providers of generative AI content-creation systems to embed machine-readable provenance data identifying content they create or modify as synthetic, and would bar social media platforms from stripping that provenance data from user-uploaded content.

A grossly negligent or intentional violation exposes the AI provider or hosting platform, or the social media platform's operator, to an Attorney General penalty of up to $100,000 per violation ($50,000 if unintentional), and a court may impose a further civil penalty of up to $25,000 per violation in a private consumer-protection action. Passed the Senate and Assembly in June 2026; not yet delivered to or acted on by the Governor as of this review.

What it requires

Artificial Intelligence Companion Models safeguards

N.Y. Gen. Bus. Law art. 47 (§§ 1700-1704)New York Consolidated Laws, General Business Law article 47, as published by the New York State Senate

In force 11 months, effective 7 November 2025. Binds private bodies.

What this law does

An operator of an AI companion, a system using artificial intelligence, generative AI or emotional-recognition algorithms to simulate a sustained human-like relationship with a user, must provide a clear and conspicuous notification at the start of an interaction and at least every three hours that the user is not communicating with a human, and must implement a protocol reasonably designed to detect and respond to a user's expressions of suicidal ideation or self-harm by referring them to crisis services such as the 9-8-8 hotline.

The Attorney General may enjoin a violation and seek civil penalties of up to $15,000 per day per violation of the notification or self-harm-detection duties. The article defines the operator bound by these duties as any person, partnership, association, firm or business entity that operates for or provides an AI companion to a user.

What it requires

Disclosure of materially deceptive AI-generated media in political communications

N.Y. Election Law § 14-106(5)New York Consolidated Laws, Election Law, as published by the New York State Senate

In force since 3 May 2024. Binds public and private bodies.

What this law does

A person, firm, association, corporation, campaign, committee or organization that distributes or publishes a political communication produced by or including materially deceptive media, defined to include content created by software, machine learning, artificial intelligence or other computer-generated or technological means that is not distinguishable from reality to a reasonable person and depicts a scenario that did not occur, must disclose that use when it has actual knowledge the media is materially deceptive.

The disclosure must read "This (image, video, or audio) has been manipulated" in a specified legible format, subject to exemptions for satire, parody and bona fide news reporting. A depicted candidate may seek expedited injunctive relief, court costs and attorney's fees.

What it requires

Synthetic Performer Advertising Disclosure Law

N.Y. Gen. Bus. Law § 396-b, ch. 617 of 2025New York State Senate, bill text and enactment history for S8420-A (2025)

In force 3 months, effective 9 June 2026. Binds public and private bodies.

What this law does

A person who, for the purpose of a sale or advertisement of property or a service, produces or creates an advertisement containing a synthetic performer, an audio, visual or audiovisual performance of a human performer not recognizable as any identifiable natural performer, must conspicuously disclose that a synthetic performer is in the advertisement where they have actual knowledge of that fact.

A violation carries a civil penalty of $1,000 for a first violation and $5,000 for any subsequent violation.

The law exempts advertisements for expressive works such as motion pictures, television programs, and video games, consistent with the use of the synthetic performer in the underlying work, and does not limit rights of privacy or publicity under Civil Rights Law sections 50 and 50-f. Signed December 11, 2025 as chapter 617 of the Laws of 2025, and in force since June 9, 2026, 180 days after enactment.

What it requires

Privacy law2 instruments, 2 in force

Research summary (216 words)

New York has no comprehensive consumer privacy law in force; the repeatedly reintroduced New York Privacy Act remains stuck in committee across several current bills, none of which has passed either chamber. What New York does have is the Stop Hacks and Improve Electronic Data Security (SHIELD) Act, N.Y. Gen. Bus.

Law §§ 899-aa and 899-bb, a data-security and breach-notification statute that creates no data-subject access, deletion, correction, portability, or objection rights and no lawful-basis or controller and processor allocation regime, and it must never be published as a comprehensive privacy act.

Biometric information is one of seven data elements whose combination with a name triggers SHIELD's breach-notification duty, but this is not a standalone biometric-privacy restriction: it carries no capture-consent, retention, or destruction duty of its own, and it matters only after a breach has already exposed the data. New York City's Biometric Identifier Information Law, N.Y.C. Admin.

Code §§ 22-1201 to 22-1205, is the only dedicated biometric-privacy instrument touching New York, but it is municipal law binding commercial establishments within the five boroughs and is not filed here as a New York State instrument. SHIELD's enforcement is exclusive to the Attorney General for both its breach-notification duty and its separate affirmative data-security-program duty, and it creates no private right of action for either half.

Breach notification

Stop Hacks and Improve Electronic Data Security (SHIELD) Act, breach notification duty

N.Y. Gen. Bus. Law § 899-aaofficial New York statute text, N.Y. General Business Law, New York State Senate

In force since 23 October 2019. Binds private bodies.

What this law does

Any person or business that owns or licenses computerized data including private information must disclose a breach of the security of the system to each affected New York resident in the most expedient time possible and without unreasonable delay, and no later than 30 days after the breach is discovered.

Notice to the Attorney General, the Department of State, and the Division of State Police is required for every disclosure, and notice to nationwide consumer reporting agencies is required when more than 5,000 New York residents are notified at once.

'Private information' is personal information combined with an unencrypted data element such as a Social Security number, driver's license number, financial account number, biometric information, or medical or health insurance information; biometric information here carries no exclusion for data derived from a photograph, video, or audio recording, unlike a comprehensive-regime state's biometric definition, though this plain-text reading has not been tested in New York case law or Attorney General guidance.

This section's local-law preemption clause is scoped to breach notification and does not displace New York City's separate biometric-privacy ordinance, which regulates capture consent and retention, a different subject.

What it requires

Enforcement supervision

Stop Hacks and Improve Electronic Data Security (SHIELD) Act, Attorney General enforcement

N.Y. Gen. Bus. Law §§ 899-aa(6), 899-bb(2)(d)-(2)(e)official New York statute text, N.Y. General Business Law, New York State Senate

In force since 23 October 2019. Binds private bodies.

What this law does

The Attorney General may bring an action to enjoin and restrain a violation of SHIELD's breach-notification duty, and a court may award actual costs for a failure to notify and, for a knowing or reckless violation, a civil penalty of the greater of $5,000 or up to $20 per instance of failed notification, capped at $250,000; a three-year limitations period runs from Attorney General discovery or notice, extendable to six years if the breach was concealed.

A violation of the separate data-security-program duty is deemed a violation of General Business Law section 349, letting the Attorney General bring an action to enjoin it and obtain civil penalties on that basis.

Section 899-bb expressly bars a private right of action for the safeguards duty, and section 899-aa carries no comparable express bar in its own text, but its enforcement subdivision is written entirely in terms of Attorney General authority, with no private-suit provision found anywhere in that section. Neither half of SHIELD arms a private plaintiff.

What it requires

Scraping law2 instruments, 2 in force

Research summary (335 words)

New York is the most developed jurisdiction on scraping-adjacent doctrine, though it still has no scraping-specific statute. Its Penal Law computer-trespass provisions define without authorization with unusual precision, including an express notice-based revocation rule and a statutory presumption that circumventing a security measure is evidence of unauthorized access, both more explicit than a bare authorization test.

The leading circuit-level case on ToS-based scraping liability, Register.com v. Verio (356 F.3d 393, 2d Cir. 2004), held that repeated exposure to terms of use posted on every response to an automated query can support a trespass-to-chattels claim even without a signed agreement, and the leading hot-news misappropriation case, NBA v. Motorola (105 F.3d 841, 2d Cir. 1997), lets a New York hot-news claim survive Copyright Act preemption only narrowly, against free-riding on a plaintiff's own costly, time-sensitive gathering rather than against independently gathered facts; neither case has its own statute to anchor an instrument to, so both are recorded here in prose rather than as separate instruments.

Unlike several peer states, New York has no comprehensive consumer data privacy act in force (the New York Privacy Act, S1169A, passed the Senate but stalled in the Assembly and remains proposed); what New York has instead at the state level is the SHIELD Act, N.Y. Gen. Bus.

Law section 899-aa et seq., a data-security statute requiring reasonable safeguards for private information (including biometric information since a 2019 amendment) once held, with no publicly-available-information exemption at all because it does not regulate collection or use, only security; that Act is already covered under this engine's privacy topic and is not repeated as its own instrument here.

New York City's own Biometric Identifier Information Law, however, does carry a private right of action, a genuine finding worth flagging: it is a municipal law, narrower than a statewide biometric statute, but its existence and remedy are both confirmed directly from the code text. Copyright, text-and-data-mining, and database rights add nothing beyond the federal position. robots.txt carries no independent legal weight in New York.

Computer misuse

New York Computer Trespass, notice-based revocation and circumvention presumption

N.Y. Penal Law §§ 156.00, 156.05, 156.10official text, New York State Senate (nysenate.gov)

In force. Binds public and private bodies.

What this law does

Section 156.00(8) defines without authorization to mean using or accessing a computer, computer service, or computer network without the permission of the owner or lessor, or someone licensed or privileged by the owner or lessor, where such person knew that his or her use or access was without permission or after actual notice to such person that such use or access was without permission, an express, textual revocation rule under which a communicated notice, including a cease-and-desist letter, that access is unwanted converts continued access into without authorization access, without needing a technical block at all.

The same subsection also provides that the knowing use of a set of instructions, code, or computer program that bypasses, defrauds, or otherwise circumvents a security measure installed or used with the user's authorization shall be presumptive evidence that such person used or accessed such computer without authorization, giving circumvention its own statutory evidentiary weight.

Section 156.05 (unauthorized use of a computer, a class A misdemeanor) and section 156.10 (computer trespass, a class E felony, requiring either intent to commit a felony or knowing access to computer material) build on the same authorization definition.

Register.com, Inc. v. Verio, Inc. (356 F.3d 393, 2d Cir. 2004), a New York-originated dispute, affirmed a preliminary injunction on a trespass-to-chattels theory where an automated WHOIS-query tool kept accessing a database after repeated exposure to posted terms of use prohibiting that use, even though the defendant never signed an agreement, holding repeated notice sufficient.

National Basketball Association v. Motorola, Inc. (105 F.3d 841, 2d Cir. 1997), applying New York's hot-news misappropriation tort, held the tort survives Copyright Act preemption only narrowly (the plaintiff generates time-sensitive information at a cost, the defendant free-rides on it, the parties are direct competitors, and free-riding would substantially threaten the product's existence or quality), and on the facts found no violation because Motorola independently gathered its own underlying facts rather than copying the NBA's compiled product; a scraper that copies a compiled output rather than independently gathering facts could still fall within the surviving tort.

No reported New York case squarely applies section 156.00 to a plain scraping fact pattern with no notice and no technical barrier.

What it requires

Personal data

New York City Biometric Identifier Information Law

N.Y.C. Admin. Code §§ 22-1201 to 22-1205 (Local Law 2021/003)official municipal code, American Legal Publishing code library (codelibrary.amlegal.com)

In force since 9 July 2021. Binds private bodies.

What this law does

The ordinance applies only to a commercial establishment, a place of entertainment, retail store, or food and drink establishment. Section 22-1202(a) requires clear, conspicuous signage disclosing the collection, retention, conversion, storage, or sharing of biometric identifier information, defined to include a retina or iris scan, fingerprint, voiceprint, or hand or face geometry scan, or other identifying characteristic.

Section 22-1202(b) flatly bans selling, leasing, trading, sharing in exchange for anything of value, or otherwise profiting from biometric identifier information.

Section 22-1203 creates a private right of action: an aggrieved person may sue, with a 30-day notice-and-cure period required before suing over a signage violation but no notice-and-cure required for a sale or profit violation under section 22-1202(b), and a prevailing party may recover statutory damages, attorneys' fees and costs, and injunctive relief.

It is a municipal law, narrower in scope than a statewide biometric statute because it is limited to commercial establishments' customer-facing collection and does not apply outside New York City, and its private right of action is stated in the code text. Section 22-1204 exempts government agencies entirely, and exempts financial institutions and non-analyzed photo or video capture from the disclosure duty specifically.

What it requires

Cybersecurity law2 instruments, 2 in force

Research summary (809 words)

New York's product-security and cyber-resilience posture rests on one enacted state statute, the Stop Hacks and Improve Electronic Data Security (SHIELD) Act's data security program duty, General Business Law 899-bb (Article 39-F, added by L. 2019, ch. 117 (S5575-B/A5635-B), signed July 25, 2019 and effective March 21, 2020), which requires any person or business that owns or licenses computerized data including the private information of a New York resident to develop, implement, and maintain reasonable administrative, technical, and physical safeguards appropriate to the information it holds, satisfied either by being a compliant regulated entity already regulated under Gramm-Leach-Bliley Act Title V, Health Insurance Portability and Accountability Act (HIPAA)/HITECH, or 23 NYCRR Part 500, or by running a scaled data security program of the kind the section itself describes.

No enacted New York statute sets security requirements a connected device or software product must meet before or after it reaches the market: a bill closely modeled on California's connected-device statute, adding General Business Law 390-d, has been introduced in every legislative session since 2017-2018 (S9179; S3973 and A2229; S1926 and A561; most recently S7269 in the 2025-2026 session) and has never advanced past committee, so this is a researched absence rather than a gap in coverage.

Outside the financial sector New York has no general private-sector duty to report an exploited vulnerability or a security incident to an authority; Chapter 177 of the Laws of 2025 (General Municipal Law Article 19-C, Executive Law 711-c, and State Technology Law 103-f and 210) requires municipal corporations, public authorities, and state agencies, government bodies, not a private business, to report a cybersecurity incident to the Division of Homeland Security and Emergency Services within 72 hours and a ransomware payment within 24 hours, so it belongs with this jurisdiction's government-accountability material rather than as a row in this profile's private-sector scope.

The Department of Financial Services separately administers 23 NYCRR Part 500, first promulgated March 1, 2017 as the first cybersecurity regulation of its kind, binding a Covered Entity operating under a license, registration, charter, certificate, permit, or accreditation issued under the Banking Law, the Insurance Law, or the Financial Services Law, and requiring a risk-informed cybersecurity program with a designated Chief Information Security Officer; its Second Amendment, promulgated by Superintendent Adrienne A. Harris with a Notice of Adoption published November 1, 2023, added an enhanced-obligation Class A company tier for the largest covered entities, defined in part by at least $20,000,000 in gross annual revenue in each of the last two fiscal years and more than 2,000 employees averaged over the same period, and 899-bb itself names Part 500 compliance as one of the three routes to being a compliant regulated entity.

Because Part 500's bound party, a financial-services licensee, is a role the LexLint activity vocabulary cannot yet express, it is deferred rather than flagged on a guess (#6740): no instrument for it is filed here, and it is recorded in this summary so a reader knows it exists.

General Business Law 899-bb is enforced only by the Attorney General, who may bring an action for injunctive relief and a civil penalty of up to $5,000 per violation under General Business Law 350-d after a violation is deemed unlawful under General Business Law 349; the section creates no private right of action, and no published enforcement record specific to the safeguards duty, as against the SHIELD Act's breach-notice half, was located.

New York's breach-notification duty, General Business Law 899-aa, the other half of the SHIELD Act, is already this jurisdiction's privacy row rather than repeated here: it requires notice to an affected New York resident and, where over 500 residents are affected, to the Attorney General, and carries its own civil penalty of up to $20 per instance of failed notification capped at $250,000. Section 500.17 of Part 500 is recorded below as its own row.

It requires a Covered Entity to notify the Superintendent within 72 hours of determining that a cybersecurity incident occurred, to notify within 24 hours of making an extortion payment and to describe in writing within 30 days why the payment was made and what alternatives were considered, and to file either a certification of material compliance or a written acknowledgement of non-compliance by April 15 each year.

A cybersecurity incident is the narrower of the regulation's two defined terms, an event that also requires notice to a government or supervisory body, has a reasonable likelihood of materially harming a material part of normal operations, or results in the deployment of ransomware within a material part of the information systems. None of the exemptions in section 500.19 relieves a Covered Entity of that notice duty, so a limited-exemption entity owes it in full.

A third-party service provider is not bound directly and is reached only through the Covered Entity's own section 500.11 duty to impose notice and security terms on it by contract.

Security baseline statutes

Stop Hacks and Improve Electronic Data Security (SHIELD) Act, data security program duty

N.Y. Gen. Bus. Law section 899-bb (Article 39-F, added by L. 2019, ch. 117 (S5575-B/A5635-B), section 4)Official statute text, New York Consolidated Laws, General Business Law Article 39-F

In force since 21 March 2020. Binds private bodies.

What this law does

Any person or business that owns or licenses computerized data including the private information of a New York resident must develop, implement, and maintain reasonable safeguards to protect the security, confidentiality, and integrity of that private information.

A business satisfies this duty either by being a compliant regulated entity under Gramm-Leach-Bliley Act Title V regulations, Health Insurance Portability and Accountability Act (HIPAA) and HITECH regulations, or 23 NYCRR Part 500, or by implementing a data security program with reasonable administrative, technical, and physical safeguards scaled to the size of the business.

Failure to comply is deemed a violation of General Business Law 349, enforceable only by the Attorney General for injunctive relief; the section creates no private right of action. General Business Law 350-d sets the civil penalty for that violation at up to $5,000 per violation.

What it requires

Vulnerability and incident reporting

New York Department of Financial Services Cybersecurity Regulation, Notices to the Superintendent

23 NYCRR 500.17Current text of the official compilation of codes

In force since 1 November 2023. Binds private bodies.

What this law does

Section 500.17 of 23 NYCRR Part 500 requires a Covered Entity to notify the Superintendent of Financial Services electronically as promptly as possible but no later than 72 hours after determining that a Cybersecurity Incident has occurred at the covered entity, its affiliates, or a third-party service provider.

A Cybersecurity Incident is a Cybersecurity Event, a broader term covering any attempt to gain unauthorized access to or misuse an information system, that also either requires notice to a government or supervisory body, carries a reasonable likelihood of materially harming a material part of normal operations, or results in the deployment of ransomware within a material part of the covered entity's information systems.

Each covered entity must promptly provide the Superintendent with any information the Superintendent requests about a reported incident and must continue updating the Superintendent with material changes or new information, with no separate numbered clock on either duty.

Where a covered entity makes an extortion payment in connection with a cybersecurity event, it must notify the Superintendent of the payment within 24 hours of making it and, within 30 days of the payment, provide a written description of why the payment was necessary and what alternatives and compliance diligence it performed.

By April 15 each year, a covered entity must submit either a written certification that it materially complied with this Part for the prior calendar year or a written acknowledgment identifying the sections it did not materially comply with and a remediation timeline, signed by its highest-ranking executive and its Chief Information Security Officer.

The limited exemptions in 23 NYCRR 500.19(a), (c) and (d), covering a small covered entity and an entity without its own information systems or nonpublic information, each work by naming the sections they relieve, and none of them names section 500.17, so an entity holding one of those still owes the Superintendent-notice duty in full.

Subsections 500.19(b), (e) and (g) work the other way, exempting their named classes from the requirements of the whole Part, which carries section 500.17 with it.

Section 500.11 requires a covered entity to adopt its own policies and contractual protections for a third-party service provider, including contractual notice to the covered entity of a cybersecurity event, so Part 500 reaches a third-party service provider only through the covered entity's own duties and never binds the provider directly unless the provider independently qualifies as its own covered entity.

What it requires

Age gating law3 instruments, 1 in force, 2 enacted but not yet in force

Research summary (94 words)

New York has enacted three child online safety laws and no adult content age verification law. The Shared AI Findings Exchange (SAFE) for Kids Act (2024), restricting algorithmic feeds for minors, is not yet operative; it takes effect 180 days after the Attorney General finalizes implementing regulations, which remained in proposed-rule stage as of mid-2026. The Child Data Protection Act (2024) took effect June 20, 2025.

The Safe by Design Act, enacted in May 2026 through the FY2027 state budget, adds default privacy and safety design requirements protecting minors on online platforms and takes effect January 1, 2027.

Age-appropriate design code

S4609A/A6549A Stop Online Predators Act, enacted as the Safe by Design Act (FY2027 budget, S9008-C part Y)

N.Y. Gen. Bus. Law art. 45-B, sections 1539-1547 (2026 N.Y. Laws ch. 58, part Y)official codified statute text (New York Senate legislation site)

In force in 100 days, effective 1 January 2027. Binds private bodies.

What this law does

Covered online platforms, including social media, gaming, and digital messaging services, must apply privacy-protective default settings for users they know are minors, including restricting contact and profile recommendations from unknown adults, limiting financial transactions, requiring parental approvals for weaker settings, and turning AI companion features off by default.

The act relies on commercially reasonable age assurance, with standards to be set through Attorney General rulemaking, and was enacted in May 2026 as part Y of the state's FY2027 transportation and economic development budget bill.

Note and primary source

S7695B, New York Child Data Protection Act

N.Y. Gen. Bus. Law art. 39-FF, sections 899-EE to 899-MM (2024 N.Y. Laws ch. 121)official Senate bill text and session law

In force since 20 June 2025. Binds private bodies.

What this law does

Operators of websites, online services, apps, and connected products may not process, sell, or share the personal data of a user under 18 for targeted advertising, profiling, or other non-essential purposes without informed consent, and must honor browser or device signals indicating a user is a minor. The Attorney General has said it will exercise enforcement discretion for good-faith compliance efforts while final implementing rules remain pending.

Note and primary source

Social media and minors

S7694A/A8148A, Stop Addictive Feeds Exploitation (SAFE) for Kids Act

N.Y. Gen. Bus. Law art. 45, sections 1500-1508 (2024 N.Y. Laws ch. 120)official Senate bill text and session law

Commencement not set. Binds private bodies.

What this law does

Social media platforms must obtain parental consent before providing an addictive, algorithmically personalized feed to a user they know is a minor, and may not send notifications to minors between midnight and 6 a.m. without parental consent.

The act does not take effect until 180 days after the Attorney General finalizes rules identifying acceptable age-determination and parental-consent methods; a notice of proposed rulemaking was published September 15, 2025, the public comment period closed December 1, 2025, and final rules had not been adopted as of mid-2026.

Note and primary source

Law in local jurisdictions1 with a page

Each has a page of its own; the number is how many of its instruments are researched to a stage.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.