New York 2023-2024 Regular Session

New York Senate Bill S09540 Latest Draft

Bill / Introduced Version Filed 05/16/2024

   
  STATE OF NEW YORK ________________________________________________________________________ 9540  IN SENATE May 16, 2024 ___________ Introduced by Sen. SKOUFIS -- read twice and ordered printed, and when printed to be committed to the Committee on Consumer Protection AN ACT to amend the general business law, in relation to prohibiting data brokers from selling the personal information of current and former military servicemembers The People of the State of New York, represented in Senate and Assem- bly, do enact as follows: 1 Section 1. The general business law is amended by adding a new section 2 399-jj to read as follows: 3 § 399-jj. Sale of personal information of servicemembers. 1. As used 4 in this section: 5 (a) "Consent" means a clear affirmative act signifying a freely given, 6 specific, informed, and unambiguous indication of a consumer's agreement 7 to the processing of data relating to the consumer. Consent may be with- 8 drawn at any time, and a controller must provide clear, conspicuous, and 9 consumer-friendly means to withdraw consent. The burden of establishing 10 consent is on the controller. Consent does not include: (i) an agreement 11 of general terms of use or a similar document that references unrelated 12 information in addition to personal data processing; (ii) an agreement 13 obtained through fraud, deceit or deception; (iii) any act that does not 14 constitute a user's intent to interact with another party such as hover- 15 ing over, pausing or closing any content; or (iv) a pre-checked box or 16 similar default. 17 (b) "Consumer" means a natural person who is a New York resident 18 acting only in an individual or household context. It does not include a 19 natural person known to be acting in a professional or employment 20 context. 21 (c) "Data broker" means a person, or unit or units of a legal entity, 22 separately or together, that does business in the state of New York and 23 knowingly collects, and sells to other controllers or third parties, the 24 personal data of a consumer with whom it does not have a direct 25 relationship. "Data broker" does not include any of the following: 26 (i) a consumer reporting agency to the extent that it is covered by 27 the federal Fair Credit Reporting Act (15 U.S.C. Sec. 1681 et seq.); or EXPLANATION--Matter in italics (underscored) is new; matter in brackets [ ] is old law to be omitted. LBD13849-01-3 

 S. 9540 2 1 (ii) a financial institution to the extent that it is covered by the 2 Gramm-Leach-Bliley Act (Public Law 106-102) and implementing regu- 3 lations. 4 (d) "Household" means a group, however identified, of consumers who 5 cohabitate with one another at the same residential address and may 6 share use of common devices or services. 7 (e) "Military servicemember" means a person who is serving or has 8 served: 9 (i) on active duty in the army, navy, marine corps, air force, space 10 force, or coast guard of the United States; 11 (ii) in the army national guard or air national guard; 12 (iii) as a commissioned officer in the public health service or of the 13 national oceanic and atmospheric administration or environmental 14 sciences services administration; or 15 (iv) as a cadet at a United States armed forces service academy. 16 (f) "Military servicemember list" means a list that includes personal 17 information, other than public record information, about one or more 18 individuals or households which is created for the express or implied 19 purpose of compiling information about individuals who are current or 20 former servicemembers. 21 (g) "Personal data" means any data that identifies or could reasonably 22 be linked, directly or indirectly, with a specific natural person, or 23 household. Personal data does not include deidentified data, information 24 that is lawfully made publicly available from federal, state or local 25 government records, or information that a controller has a reasonable 26 basis to believe is lawfully made available to the general public by the 27 consumer or from widely distributed media. 28 (h) "Sell" means selling, reselling, disclosing, transferring, convey- 29 ing, sharing, licensing, trading, making available, processing, granting 30 of permission or authorization to process, or otherwise exchanging or 31 providing access to personal data for monetary or other valuable consid- 32 eration. "Sell" includes enabling, facilitating or providing access to 33 personal data for targeted advertising. "Sell" does not include the 34 following: 35 (i) the disclosure of data to a processor who processes the data on 36 behalf of the controller and which is contractually prohibited from 37 using it for any purpose other than as instructed by the controller; 38 (ii) the disclosure or transfer of data as an asset that is part of a 39 merger, acquisition, bankruptcy, or other transaction in which another 40 entity assumes control or ownership of all or a majority of the control- 41 ler's assets; or 42 (iii) the disclosure of personal data to a third party necessary for 43 purposes of providing a product, service, or interaction with such third 44 party, when the consumer intentionally and unambiguously requests such 45 disclosure. 46 2. It shall be unlawful for a data broker knowingly or recklessly to 47 sell a military servicemember list or personal data about any military 48 servicemember without consent from such military servicemembers. 49 3. This section applies to legal persons that conduct business in New 50 York or produce products or services that are targeted to residents of 51 New York. 52 § 2. This act shall take effect on the ninetieth day after it shall 53 have become a law.