Imposes a five-day time limit during which to disclose a breach in the security of a system
A 1157 (2025) requires businesses handling New York residents' personal data - such as names, Social Security numbers, or financial details - to notify affected individuals within five days of discovering a security breach, replacing a previous 30-day deadline. This applies to any breach involving "private information" stored in computerized systems. The law maintains existing exceptions for law enforcement investigations but shortens the disclosure window significantly. The bill amends New York's general business law to enforce this faster notification requirement.
Bill status
in committee
1 of 4 stages cleared
Introduction
Jan 2025
Committee Review
Floor Vote
Governor
Introduced Jan 9, 2025
Last action Jan 7, 2026
Floor votes
How they voted
No floor votes recorded yet.
Full legislative history
Actions timeline
Total actions
2
Key actions
0
Committee
2
Jan 7, 2026
Committee
REFERRED TO CONSUMER AFFAIRS AND PROTECTION
lower
Jan 9, 2025
Committee
REFERRED TO CONSUMER AFFAIRS AND PROTECTION
lower
1 primary · 6 co-sponsors
Sponsors
Ask Maddy
·
AI policy assistant
Ask Maddy about A 1157
Scope: NY
Hi! I can help you understand A 1157. What would you like to know?
Try one of these
i
Maddy answers using official bill text and legislative records. Always verify before sharing.
Sources cited inline