Law / New York

New York

age

New York has enacted three child online safety laws and no adult content age verification law. The SAFE for Kids Act (2024), restricting algorithmic feeds for minors, is not yet operative; it takes effect 180 days after the Attorney General finalizes implementing regulations, which remained in proposed-rule stage as of mid-2026. The Child Data Protection Act (2024) took effect June 20, 2025.

The Safe by Design Act, enacted in May 2026 through the FY2027 state budget, adds default privacy and safety design requirements protecting minors on online platforms and takes effect January 1, 2027.

privacy

New York has no comprehensive consumer privacy law in force; the repeatedly reintroduced New York Privacy Act remains stuck in committee across several current bills, none of which has passed either chamber. What New York does have is the Stop Hacks and Improve Electronic Data Security (SHIELD) Act, N.Y. Gen. Bus.

Law §§ 899-aa and 899-bb, a data-security and breach-notification statute that creates no data-subject access, deletion, correction, portability, or objection rights and no lawful-basis or controller and processor allocation regime, and it must never be published as a comprehensive privacy act.

Biometric information is one of seven data elements whose combination with a name triggers SHIELD's breach-notification duty, but this is not a standalone biometric-privacy restriction: it carries no capture-consent, retention, or destruction duty of its own, and it matters only after a breach has already exposed the data. New York City's Biometric Identifier Information Law, N.Y.C. Admin.

Code §§ 22-1201 to 22-1205, is the only dedicated biometric-privacy instrument touching New York, but it is municipal law binding commercial establishments within the five boroughs and is not filed here as a New York State instrument. SHIELD's enforcement is exclusive to the Attorney General for both its breach-notification duty and its separate affirmative data-security-program duty, and it creates no private right of action for either half.

19 instruments named 6 researched in detail As of 2026-08-27

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Age-appropriate design code

S4609A/A6549A Stop Online Predators Act, enacted as the Safe by Design Act (FY2027 budget, S9008-C part Y)

cite N.Y. Gen. Bus. Law art. 45-B, sections 1539-1547 (2026 N.Y. Laws ch. 58, part Y) stage IMMINENT in force in 125 days effective 2027-01-01 source official codified statute text (New York Senate legislation site)

Covered online platforms, including social media, gaming, and digital messaging services, must apply privacy-protective default settings for users they know are minors, including restricting contact and profile recommendations from unknown adults, limiting financial transactions, requiring parental approvals for weaker settings, and turning AI companion features off by default.

The act relies on commercially reasonable age assurance, with standards to be set through Attorney General rulemaking, and was enacted in May 2026 as part Y of the state's FY2027 transportation and economic development budget bill.

Note and primary source

S7695B, New York Child Data Protection Act

cite N.Y. Gen. Bus. Law art. 39-FF, sections 899-EE to 899-MM (2024 N.Y. Laws ch. 121) stage IN FORCE in force since 2025-06-20 source official Senate bill text and session law

Operators of websites, online services, apps, and connected products may not process, sell, or share the personal data of a user under 18 for targeted advertising, profiling, or other non-essential purposes without informed consent, and must honor browser or device signals indicating a user is a minor. The Attorney General has said it will exercise enforcement discretion for good-faith compliance efforts while final implementing rules remain pending.

Note and primary source

Breach notification

Stop Hacks and Improve Electronic Data Security (SHIELD) Act, breach notification duty

cite N.Y. Gen. Bus. Law § 899-aa stage IN FORCE in force since 2019-10-23 source official New York statute text, N.Y. General Business Law, New York State Senate

Any person or business that owns or licenses computerized data including private information must disclose a breach of the security of the system to each affected New York resident in the most expedient time possible and without unreasonable delay, and no later than 30 days after the breach is discovered.

Notice to the Attorney General, the Department of State, and the Division of State Police is required for every disclosure, and notice to nationwide consumer reporting agencies is required when more than 5,000 New York residents are notified at once.

'Private information' is personal information combined with an unencrypted data element such as a Social Security number, driver's license number, financial account number, biometric information, or medical or health insurance information; biometric information here carries no exclusion for data derived from a photograph, video, or audio recording, unlike a comprehensive-regime state's biometric definition, though this plain-text reading has not been tested in New York case law or Attorney General guidance.

This section's local-law preemption clause is scoped to breach notification and does not displace New York City's separate biometric-privacy ordinance, which regulates capture consent and retention, a different subject.

What it asks of an app

Stop Hacks and Improve Electronic Data Security (SHIELD) Act, data security program duty

cite N.Y. Gen. Bus. Law § 899-bb stage IN FORCE in force since 2020-03-21 source official New York statute text, N.Y. General Business Law, New York State Senate

Any person or business that owns or licenses computerized data including a New York resident's private information must develop, implement, and maintain reasonable administrative, technical, and physical safeguards to protect its security, confidentiality, and integrity.

A business is deemed compliant either by being a regulated entity under an existing federal or state data-security regime such as GLBA, HIPAA and HITECH, or 23 NYCRR 500, or by implementing the safeguards program the section itself describes, and a small business under 50 employees, under $3 million in revenue, or under $5 million in year-end assets gets a version of the same duty scaled to its size and complexity.

This is a genuinely separate obligation from the breach-notification duty in section 899-aa: it is a preventive duty to safeguard data, not a duty to notify after exposure, and the statute expressly bars a private right of action for this section.

What it asks of an app

Enforcement supervision

Stop Hacks and Improve Electronic Data Security (SHIELD) Act, Attorney General enforcement

cite N.Y. Gen. Bus. Law §§ 899-aa(6), 899-bb(2)(d)-(2)(e) stage IN FORCE in force since 2019-10-23 source official New York statute text, N.Y. General Business Law, New York State Senate

The Attorney General may bring an action to enjoin and restrain a violation of SHIELD's breach-notification duty, and a court may award actual costs for a failure to notify and, for a knowing or reckless violation, a civil penalty of the greater of $5,000 or up to $20 per instance of failed notification, capped at $250,000; a three-year limitations period runs from Attorney General discovery or notice, extendable to six years if the breach was concealed.

A violation of the separate data-security-program duty is deemed a violation of General Business Law section 349, letting the Attorney General bring an action to enjoin it and obtain civil penalties on that basis.

Section 899-bb expressly bars a private right of action for the safeguards duty, and section 899-aa carries no comparable express bar in its own text, but its enforcement subdivision is written entirely in terms of Attorney General authority, with no private-suit provision found anywhere in that section during this research pass. Neither half of SHIELD arms a private plaintiff.

What it asks of an app

Social media and minors

S7694A/A8148A, Stop Addictive Feeds Exploitation (SAFE) for Kids Act

cite N.Y. Gen. Bus. Law art. 45, sections 1500-1508 (2024 N.Y. Laws ch. 120) stage IMMINENT commencement not set source official Senate bill text and session law

Social media platforms must obtain parental consent before providing an addictive, algorithmically personalized feed to a user they know is a minor, and may not send notifications to minors between midnight and 6 a.m. without parental consent.

The act does not take effect until 180 days after the Attorney General finalizes rules identifying acceptable age-determination and parental-consent methods; a notice of proposed rulemaking was published September 15, 2025, the public comment period closed December 1, 2025, and final rules had not been adopted as of mid-2026.

Note and primary source

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.