STATE OF NEW YORK
        ________________________________________________________________________
                                          72--A
                               2017-2018 Regular Sessions
                    IN SENATE
                                       (Prefiled)
                                     January 4, 2017
                                       ___________
        Introduced  by  Sen. HOYLMAN -- read twice and ordered printed, and when
          printed to be committed to the Committee  on  Consumer  Protection  --
          recommitted to the Committee on Consumer Protection in accordance with
          Senate  Rule  6, sec. 8 -- committee discharged, bill amended, ordered
          reprinted as amended and recommitted to said committee
        AN ACT to amend the general business law, in relation to restricting the
          disclosure of personal information by businesses
          The People of the State of New York, represented in Senate and  Assem-
        bly, do enact as follows:
     1    Section  1.  This act shall be known and may be cited as the "right to
     2  know act of 2018".
     3    § 2. The legislature hereby finds  and  declares  that  the  right  to
     4  privacy  is  a  personal  and  fundamental right protected by the United
     5  States Constitution. All individuals have a right of privacy in informa-
     6  tion pertaining to them.
     7    This state recognizes the importance of providing consumers with tran-
     8  sparency about how their personal information has been shared  by  busi-
     9  nesses.  For  free  market  forces to have a role in shaping the privacy
    10  practices and for "opt-in"  and  "opt-out"  remedies  to  be  effective,
    11  consumers must be more than vaguely informed that a business might share
    12  personal  information  with  third  parties.  Consumers  must  be better
    13  informed about what kinds of personal information are purchased by busi-
    14  nesses for direct marketing purposes. With  these  specifics,  consumers
    15  can knowledgeably choose to opt-in or opt-out or choose among businesses
    16  that disclose information to third parties for direct marketing purposes
    17  on the basis of how protective the business is of consumers' privacy.
    18    Businesses  are  now  collecting  personal information and sharing and
    19  selling it in ways not contemplated or properly covered by  the  current
    20  law. Some web sites are installing up to one hundred tracking tools when
    21  consumers  visit web pages and sending very personal information such as
         EXPLANATION--Matter in italics (underscored) is new; matter in brackets
                              [ ] is old law to be omitted.
                                                                   LBD03601-06-8

        S. 72--A                            2
     1  age, gender, race, income, health  concerns,  and  recent  purchases  to
     2  third-party advertising and marketing companies. Third-party data broker
     3  companies are buying, selling, and trading personal information obtained
     4  from  mobile  phones,  financial  institutions,  social media sites, and
     5  other online and brick and mortar companies.
     6    Some mobile applications are sharing  personal  information,  such  as
     7  location  information,  unique  phone  identification  numbers, and age,
     8  gender, and other personal details with third-party companies.
     9    Consumers need to know the ways that  their  personal  information  is
    10  being collected by companies and then shared or sold to third parties in
    11  order  to properly protect their privacy, personal safety, and financial
    12  security.
    13    § 3. The article heading of article 39-F of the general business  law,
    14  as  added  by  chapter  442  of  the laws of 2005, is amended to read as
    15  follows:
    16             [NOTIFICATION OF UNAUTHORIZED] ACQUISITION AND USE
    17                           OF PRIVATE INFORMATION
    18    § 4. The general business law is amended by adding a new section  899-
    19  bb to read as follows:
    20    §  899-bb.  Disclosure of a customer's personal information to a third
    21  party. 1. (a) A business that retains a customer's personal  information
    22  shall make available to the customer free of charge access to, or copies
    23  of, all of the customer's personal information retained by the business.
    24    (b)  A  business that discloses a customer's personal information to a
    25  third party shall  make  the  following  information  available  to  the
    26  customer free of charge:
    27    (1)  All  categories  of the customer's personal information that were
    28  disclosed, including the categories set forth in paragraph (b) of subdi-
    29  vision four of this section.
    30    (2) The names and contact information of all of the third parties that
    31  received the customer's personal information from the business,  includ-
    32  ing  the third party's designated request address or addresses if avail-
    33  able.
    34    2. A business required to comply with subdivision one of this  section
    35  shall  make  the  required  information  available by one or more of the
    36  following means:
    37    (a) By providing a designated request address and, upon receipt  of  a
    38  request  under this section to the designated request address, providing
    39  the customer within thirty days with the required  information  for  all
    40  disclosures occurring in the prior twelve months, provided that:
    41    (1) if the business has an online privacy policy, that policy includes
    42  a  description  of a customer's rights pursuant to this section accompa-
    43  nied by one or more designated request addresses; provided that a  busi-
    44  ness with multiple online privacy policies must include this information
    45  in the policy of each product or service that collects personal informa-
    46  tion that may be disclosed to a third party;
    47    (2)  the  business  ensures  that all persons responsible for handling
    48  customer inquiries about the business' privacy practices  or  the  busi-
    49  ness'  compliance  with  this  section  are  informed  of all designated
    50  request addresses; and
    51    (3) the business  provides  information  pertaining  to  the  specific
    52  customer  if  that  information is reasonably available to the business,
    53  and provides information in standardized format if information  pertain-
    54  ing to the specific customer is not reasonably available.
    55    (b) For information required to be provided by paragraph (b) of subdi-
    56  vision  one  of  this  section,  by  providing  the customer with notice

        S. 72--A                            3
     1  including the required information prior to or immediately  following  a
     2  disclosure.
     3    (c)  By providing the customer the disclosure required by Section 6803
     4  of Title 15 of the United States Code, but only if the  disclosure  also
     5  complies with this section.
     6    3.  (a)  A  business  is not obligated to provide more than one notice
     7  under paragraph (b) of subdivision two  of  this  section  to  the  same
     8  customer  in  a  twelve-month  period  about  the disclosure of the same
     9  personal information to the same third party and is not obligated  under
    10  paragraph (a) of subdivision two of this section to respond to a request
    11  by the same customer more than once within a given twelve-month period.
    12    (b) A business is not obligated to provide information to the customer
    13  pursuant  to  subdivision  one  of  this  section if the business cannot
    14  reasonably verify that the individual making the request is the  custom-
    15  er.
    16    4.  For purposes of this section, the following terms have the follow-
    17  ing meanings:
    18    (a) "Business" means any person,  proprietorship,  firm,  partnership,
    19  association,  cooperative,  nonprofit organization or corporation organ-
    20  ized or existing under the laws of this state or any  other  state,  and
    21  doing  business  in  this  state,  exclusive  of  public corporations as
    22  defined pursuant to article two-A of the general construction law.
    23    (b) "Categories of personal information" includes, but is not  limited
    24  to, the following:
    25    (1)  Identity  information  including,  but not limited to, real name,
    26  alias, nickname, and user name.
    27    (2) Address information, including, but not limited to, postal address
    28  or e-mail.
    29    (3) Telephone number.
    30    (4) Account name.
    31    (5) Social security number or other  government-issued  identification
    32  number,  including, but not limited to, social security number, driver's
    33  license number, identification card number, and passport number.
    34    (6) Birthdate or age.
    35    (7) Physical characteristic information, including,  but  not  limited
    36  to, height and weight.
    37    (8)  Sexual  information, including, but not limited to, sexual orien-
    38  tation, sex, gender status, gender identity, and gender expression.
    39    (9) Race or ethnicity.
    40    (10) Religious affiliation or activity.
    41    (11) Political affiliation or activity.
    42    (12) Professional or employment-related information.
    43    (13) Educational information.
    44    (14) Medical information,  including,  but  not  limited  to,  medical
    45  conditions  or  drugs,  therapies, mental health, or medical products or
    46  equipment used.
    47    (15) Financial information, including, but  not  limited  to,  credit,
    48  debit,  or account numbers, account balances, payment history, or infor-
    49  mation related to assets, liabilities, or general creditworthiness.
    50    (16) Commercial information, including, but not limited to, records of
    51  property, products or services provided,  obtained,  or  considered,  or
    52  other purchasing or consumer histories or tendencies.
    53    (17) Location information.
    54    (18)  Internet  or  mobile  activity  information,  including, but not
    55  limited to, Internet protocol addresses or  information  concerning  the
    56  access or use of any Internet or mobile-based site or service.

        S. 72--A                            4
     1    (19)  Content, including text, photographs, audio or video recordings,
     2  or other material generated by or provided by the customer.
     3    (20) Any of the above categories of information as they pertain to the
     4  children of the customer.
     5    (c)  (1)  "Customer" means an individual who is a resident of New York
     6  state who provides personal information to a business, with  or  without
     7  an  exchange  of  consideration,  in  the course of purchasing, viewing,
     8  accessing, renting, leasing, or otherwise using real or personal proper-
     9  ty, or any interest therein, or obtaining a product or service from  the
    10  business including advertising or any other content.
    11    (2)  An individual is also the customer of a business if that business
    12  obtained the personal information of  that  individual  from  any  other
    13  business.
    14    (d)  "Designated  request  address"  means  a  mailing address, e-mail
    15  address, web page,  toll-free  telephone  number,  or  other  applicable
    16  contact  information, whereby customers may request or obtain the infor-
    17  mation required to be provided under subdivision one of this section.
    18    (e) (1)  "Disclose"  means  to  disclose,  release,  share,  transfer,
    19  disseminate,  make  available, or otherwise communicate orally, in writ-
    20  ing, or by electronic or any other means to any third party  as  defined
    21  in this section.
    22    (2) "Disclose" does not include:
    23    (A)  Disclosure of personal information by a business to a third party
    24  pursuant to a written contract authorizing the third  party  to  utilize
    25  the  personal information to perform services on behalf of the business,
    26  including maintaining or servicing accounts, providing customer service,
    27  processing or fulfilling orders  and  transactions,  verifying  customer
    28  information,   processing  payments,  providing  financing,  or  similar
    29  services, but only if (I) the contract prohibits the  third  party  from
    30  using  the personal information for any reason other than performing the
    31  specified service or  services  on  behalf  of  the  business  and  from
    32  disclosing any such personal information to additional third parties and
    33  (II) the business effectively enforces these prohibitions.
    34    (B)  Disclosure of personal information by a business to a third party
    35  based on a good-faith belief that disclosure is required to comply  with
    36  applicable law, regulation, legal process, or court order.
    37    (C)  Disclosure of personal information by a business to a third party
    38  that is reasonably necessary to address fraud,  security,  or  technical
    39  issues;  to  protect  the disclosing business' rights or property; or to
    40  protect customers or the public from illegal activities as  required  or
    41  permitted by law.
    42    (D)  Disclosure of personal information by a business to a third party
    43  that is otherwise lawfully available to  the  general  public,  provided
    44  that  the business did not direct the third party to the personal infor-
    45  mation.
    46    (f) "Personal information" means:
    47    (1) Any information that identifies or references a  particular  indi-
    48  vidual or electronic device, including, but not limited to, a real name,
    49  alias, postal address, telephone number, electronic mail address, Inter-
    50  net  protocol  address,  account  name, social security number, driver's
    51  license number, passport number, or any  other  identifier  intended  or
    52  able to be uniquely associated with a particular individual or device.
    53    (2) Any information that relates to or describes an individual if such
    54  information is disclosed in connection with any identifying or referenc-
    55  ing information as defined in subparagraph one of this paragraph.

        S. 72--A                            5
     1    (g) (1) "Retains" means to store or otherwise hold information, wheth-
     2  er the information is collected or obtained directly from the subject of
     3  the information or from any third party.
     4    (2) "Retains" does not include information that is stored or otherwise
     5  held  solely  for  one or more of the following purposes, so long as the
     6  information is deleted as soon as it  is  no  longer  needed  for  those
     7  purposes:
     8    (A)  To perform a service or complete a transaction initiated by or on
     9  behalf of the customer, including  maintaining  or  servicing  accounts,
    10  providing  customer  service, processing or fulfilling orders and trans-
    11  actions, verifying customer information, processing payments,  providing
    12  financing, or similar services.
    13    (B)  To  address  fraud, security, or technical issues; to protect the
    14  disclosing business' rights or property; or to protect customers or  the
    15  public from illegal activities as required or permitted by law.
    16    (C)  To comply with applicable law or regulation or with a court order
    17  or other legal process where the business has a good-faith  belief  that
    18  the law, regulation, court order, or legal process requires the informa-
    19  tion to be stored or held.
    20    (h)  "Third party" or "third parties" means one or more of the follow-
    21  ing:
    22    (1) A business that is a separate legal entity from the business  that
    23  has disclosed personal information.
    24    (2)  A  business that does not share common ownership or common corpo-
    25  rate control with the business that has disclosed personal information.
    26    (3) A business that does not share a brand  name  or  common  branding
    27  with  the business that has disclosed personal information such that the
    28  affiliate relationship is clear to the customer.
    29    5. The provisions of this section are severable. If any  provision  of
    30  this  section  or its application is held invalid, that invalidity shall
    31  not affect other provisions or applications that  can  be  given  effect
    32  without the invalid provision or application.
    33    6. A violation of this section constitutes an injury to a customer.  A
    34  civil  action  to  recover  penalties  may be brought by a customer, the
    35  attorney general, a district attorney, a city attorney, or a city prose-
    36  cutor, in a court of competent jurisdiction.
    37    § 5. This act shall take effect immediately.