Everything you need to know about NYPA compliance, data security requirements, and secure data disposal.
The New York Privacy Act is one of the longest-running attempts at comprehensive state-level privacy legislation in the United States. First introduced in 2019 and reintroduced in multiple legislative sessions since, it aims to give New York residents GDPR-style control over their personal data. As of 2026, the bill remains under legislative consideration and has not yet been signed into law, but its repeated reintroduction signals sustained momentum and makes it worth tracking closely for any business operating in or serving customers in New York State.
Legislative History
The Act was first introduced in the New York State Senate and Assembly in 2019 and has been reintroduced in nearly every legislative session since, most recently carrying forward into the 2025–2026 session. It has passed one chamber at various points but has not completed the full legislative process required to become law. New York has separately advanced narrower privacy legislation, including health-data-specific bills, while the broader, comprehensive New York Privacy Act continues to be debated.
What the Bill Proposes
If enacted in its current form, the New York Privacy Act would:
- Require companies to act as data fiduciaries, owing a duty of care, loyalty, and confidentiality to consumers whose data they process — a stricter standard than most existing US state privacy laws
- Mandate disclosure of the methods companies use to de-identify personal information
- Require special safeguards around data sharing with third parties
- Give consumers the right to request the names of all entities with whom their data has been shared
- Grant consumers rights to access, correct, delete, and port their personal data
- Restrict the sale of personal data without opt-in consent for certain categories
Who Would Be Covered
The proposed law would apply broadly to legal entities that conduct business in New York State or produce products or services targeted at New York residents and that control or process personal data, without the revenue or data-volume thresholds seen in some other state privacy laws — making its potential scope wider than laws like the CCPA.
Why the Fiduciary Standard Matters
Most US state privacy laws to date follow a "notice and choice" model — companies must disclose what they collect and give consumers a way to opt out. The New York Privacy Act's data fiduciary approach goes further, placing an affirmative legal duty on companies to act in the best interests of the individuals whose data they hold, similar to how a financial advisor owes a duty to a client. This would be a significant departure from the norm and, if passed, could influence how other states approach privacy legislation.
Preparing for Potential Enactment
Given the bill's staying power across multiple legislative sessions, businesses that operate in New York or handle New York residents' data should consider getting ahead of it rather than waiting for final passage:
- Map what personal data is collected from New York residents and why
- Document data sharing relationships with third parties and vendors
- Build data minimization and secure retention/disposal practices into existing workflows
- Establish processes to honor access, correction, deletion, and portability requests
- Monitor legislative developments, since amendments between sessions have changed scope and enforcement mechanisms
Data Disposal Implications
Regardless of whether the bill becomes law, permanently and verifiably erasing personal data once it is no longer needed is a foundational privacy practice that supports compliance with nearly every version of the proposed Act, as well as with existing frameworks like the CCPA and GDPR. Simple file deletion is not sufficient; data should be destroyed using standards-based erasure methods that produce an auditable record, particularly for decommissioned laptops, servers, and mobile devices that once held customer data.
Official Regulatory Reference
For the most accurate, authentic, and up-to-date legal text, we highly recommend consulting the official legislative documentation provided by the respective regional government or data protection authority. Relying on the official source of truth is the best way to ensure full compliance.
Streamlining Compliance with D-Secure Solutions
Meeting strict data sanitization requirements doesn't have to be a manual, error-prone process. Our enterprise data sanitization solutions are purpose-built to help organizations seamlessly meet these strict regulatory mandates.
By utilizing D-Secure Drive Eraser, your organization can permanently wipe sensitive data and automatically generate tamper-evident erasure certificates. This creates a rigorous, verifiable audit trail that satisfies regulatory bodies and eliminates the risk of data leaks.
Conclusion
The New York Privacy Act has not yet passed, but its recurring presence in the legislature, combined with New York's economic significance, means businesses should treat it as a "when," not "if," proposition. Building strong data governance and secure data lifecycle practices now will make eventual compliance far less disruptive.
No comments yet. Be the first to comment.