Skip to code content (skip section selection)
Compare to:
New York City Overview
The New York City Charter
The New York City Administrative Code
The Rules of the City of New York
THE RULES OF THE CITY OF NEW YORK
Title 1: Department of Buildings
Title 2: Board of Standards and Appeals
Title 3: Fire Department
Title 6: Department of Consumer and Worker Protection
Title 9: Procurement Policy Board Rules
Title 12: Franchise and Concession Review Committee
Title 15: Department of Environmental Protection
Title 16: Department of Sanitation
Title 17: Business Integrity Commission
Title 19: Department of Finance
Title 20: Tax Appeals Tribunal
Title 21: Tax Commission
Title 22: Banking Commission
Title 24: Department of Health and Mental Hygiene
Title 25: Department of Mental Health and Retardation [Repealed]
Title 28: Housing Preservation and Development
Title 29: Loft Board
Title 30: Rent Guidelines Board
Title 31: Mayor's Office of Homelessness and Single Room Occupancy
Title 34: Department of Transportation
Title 35: Taxi and Limousine Commission
Title 38: Police Department
Title 38-A: Civilian Complaint Review Board
Title 39: Department of Correction
Title 40: Board of Correction
Title 41: Department of Juvenile Justice
Title 42: Department of Probation
Title 43: Mayor
Title 44: Comptroller
Title 45: Borough Presidents
Title 46: Law Department
Title 47: Commission on Human Rights
Title 48: Office of Administrative Trials and Hearings (OATH)
Title 49: Department of Records and Information Services
Title 50: Community Assistance Unit
Title 51: City Clerk
Title 52: Campaign Finance Board*
Title 53: Conflicts of Interest Board
Title 55: Department of Citywide Administrative Services
Title 56: Department of Parks and Recreation
Title 57: Art Commission
Title 58: Department of Cultural Affairs
Title 60: Civil Service Commission
Title 61: Office of Collective Bargaining
Title 62: City Planning
Title 63: Landmarks Preservation Commission
Title 66: Department of Small Business Services
Title 67: Department of Information Technology and Telecommunications
Title 68: Human Resources Administration
Title 69: Department of Aging
Title 70: In Rem Foreclosure Release Board
Title 71: Voter Assistance Commission
Title 72: Office of Emergency Management
Title 73: Civic Engagement Commission
§ 10-502 Agency disclosure of a breach of security.
   a.   Any city agency that owns, leases, or licenses data that includes private information shall promptly disclose to the chief privacy officer, office of cyber command and department of information technology and telecommunications any breach of security following discovery by a supervisor or manager, or following notification to a supervisor or manager, of such breach if such private information was, or is reasonably believed to have been, accessed, acquired, disclosed, or used by an unauthorized person.
   b.   Subsequent to compliance with the provisions set forth in subdivision a of this section, any city agency that owns, leases, or licenses data that includes private information shall disclose, in accordance with the procedures set forth in subdivisions d, e and f of this section, any breach of security following discovery by a supervisor or manager, or following notification to a supervisor or manager, of such breach to any individual whose private information was, or is reasonably believed to have been, accessed, acquired, disclosed, or used by an unauthorized person.
   c.   Any city agency that maintains but does not own, lease, or license data that includes private information shall disclose any breach of security following discovery by a supervisor or manager, or following notification to a supervisor or manager, of such breach to the owner, lessor or licensor of the data if the private information was, or is reasonably believed to have been, accessed, acquired, disclosed, or used by an unauthorized person.
   d.   The disclosures required by subdivisions b and c of this section shall be made as soon as practicable by a method reasonable under the circumstances, provided said method is not inconsistent with the legitimate needs of law enforcement or any other investigative or protective measures necessary to restore the integrity of the data system. Disclosures required by subdivision b of this section shall be made to each affected individual by at least one of the following means:
      1.   Written notice; or
      2.   Telephonic notification, provided that a log of each such notification is maintained by the agency that notifies the affected individuals; or
      3.   Electronic notification, provided that the affected individual has expressly consented to receiving such notification in electronic form and a log of each such notification is maintained by the agency that notifies affected individuals in such form; provided further, however, that in no case shall any city agency, individual, or business require an individual to consent to accepting notification in such form as a condition of establishing any relationship or engaging in any transaction.
   e.   Should disclosure pursuant to paragraph one, two or three of subdivision d be impracticable or inappropriate given the circumstances of the breach and the identity of the victim, such disclosure shall be made by a mechanism that is reasonably targeted to the individual in a manner that does not further compromise the integrity of the private information.
   f.   In the event that five thousand or more New York residents are to be notified at one time pursuant to this section, the agency shall also notify consumer reporting agencies as to the timing, content and distribution of the notices and approximate number of affected individuals. Such notice shall be made without delaying notice to affected New York residents.
   g.   Notice to affected individuals under this section is not required if the exposure of private information was an inadvertent disclosure by persons authorized to access private information, and the agency reasonably determines, in accordance with the protocols established pursuant to subdivision i of this section, that such exposure will not likely result in misuse of such information, or financial, personal, or reputational harm to the affected individuals. Such a determination must be documented in writing and maintained for at least five years.
   h.   If notice of a breach of security is made to affected individuals pursuant to any law or rule of the state of New York, or pursuant to a law described in paragraph b of subdivision 2 of section 208 of the state technology law, nothing in this section shall require any additional notice to those affected individuals, but notice still shall be provided pursuant to subdivision a of this section.
   i.   The office of cyber command, in consultation with the chief privacy officer and the department of information technology and telecommunications, shall issue protocols for agency coordination and recordkeeping for any breach of security and any incident that is not a breach of security but involves the good faith or inadvertent access, acquisition, disclosure, or use of any private information by an employee or agent of an agency for the legitimate purposes of the agency. Such protocols may apply to all agencies or a subset thereof.
   j.   Notifications made pursuant to this section may overlap with notifications required pursuant to chapter 12 of title 23, including the regulations, policies and protocols issued by the chief privacy officer pursuant to such chapter. Nothing in this section or such chapter shall require duplicate notifications, as long as any notice provided meets any applicable requirements of both this law and such chapter.
(Am. L.L. 2021/151, 12/11/2021, eff. 4/10/2022)
Editor's note: For related unconsolidated provisions, see Appendix A at L.L. 2005/045.