Relates to prohibiting the use of funds, financial incentives or subsidies where facilities or property are used primarily for e-commerce storage and transfers, or the facilitation thereof.
Provides that organ donation registrations through an electronic health record product do not retain or store patients' donor status information and meet standards established by the commissioner; amends the effective date.
This bill (A 428) protects New York users of paid online dating services by setting clear consumer safeguards. It limits subscription contracts to $1,000 total (with exceptions for short-term plans), bans requiring forced add-on services (like grooming), and guarantees a minimum number of matches per month for paid plans over $25. Users gain the right to cancel without penalty if matches aren't delivered for two months, receive a refund (minus a small fee), and get their personal data deleted or returned upon cancellation. The law directly affects all paid online dating platforms operating in New York, ensuring transparency and reducing deceptive practices.
This bill amends New York's penal law and related statutes to explicitly include "medical information" and "health insurance information" in the legal definition of "personal identifying information." It defines medical information as details about an individual's medical history or treatment, and health insurance information as policy numbers, subscriber IDs, or claims history. These changes mean that identity theft involving such sensitive health data will now be covered under existing identity theft laws, which previously did not explicitly include these categories. The bill also removes outdated definitions from related laws to streamline the updated framework.
Directs that state agencies require that procurement of end point devices be consistent with any relevant standards, guidelines, or guidance developed as part of the National Institute of Standards and Technology (NIST) Cybersecurity Framework.
Relates to the disclosure of automated employment decision-making tools; requires the office of information technology services to maintain an artificial intelligence inventory; provides that the use of artificial intelligence systems shall not affect the existing rights of employees pursuant to an existing collective bargaining agreement, or the existing representational relationships among employee organizations or the bargaining relationships between the employer and an employee organization.
S 804 amends New York's data breach notification law to clarify when and how financial institutions must notify the Department of Financial Services (DFS) after a breach affecting New York residents. It requires covered financial institutions (as defined by current DFS rules) to provide DFS with details about the breach - including timing, content, and number of affected people - without delaying direct notifications to consumers. The bill specifies that this notification to DFS is only mandatory for financial institutions, not all businesses, and must follow existing DFS reporting rules (23 NYCRR 500.17). The law, signed as Chapter 91 on February 14, 2025, streamlines reporting for regulated financial entities while maintaining direct consumer notification timelines.
Directs that state agencies require that procurement of end point devices be consistent with any relevant standards, guidelines, or guidance developed as part of the National Institute of Standards and Technology (NIST) Cybersecurity Framework.
This bill expands the legal definition of "personal identifying information" to explicitly include medical information and health insurance details. It directly affects individuals whose medical history, treatment records, or health insurance policy numbers could be misused, as these now count as sensitive data under identity theft laws. Key provisions add specific definitions: "medical information" covers health history and treatment, while "health insurance information" includes policy numbers and claims history. The bill modifies existing penal, business, and technology laws to incorporate these changes, removing prior related provisions through repeal. This update strengthens protections by making unauthorized use of health data prosecutable under current identity theft statutes.
S 778 regulates online dating services in New York by setting consumer protections and pricing limits. It caps two-year membership costs at $1,000 (with exceptions for one-year contracts), bans requiring ancillary services (like photo sessions) as a condition of use, and mandates a minimum number of matches per month for paid accounts over $25. If services fail to deliver the promised matches for two consecutive months, users can cancel and receive a refund (minus a small fee for services provided). The bill also grants a three-day cooling-off period for cancellations without penalty and requires dating platforms to return or destroy user data upon contract end.