1. When Does a Data Breach Trigger a Notice Duty?
General Business Law § 899-aa applies when a breach involves computerized data containing protected private information. A breach can involve unauthorized access or acquisition, so proof that files were stolen is not always needed. Start by identifying the data and what the incident facts show.
Which Information Receives Statutory Protection?
- Social Security numbers and qualifying driver’s license or ID numbers.
- Financial account or card information that could permit account access.
- Biometric information used to authenticate or identify a person.
- Medical and health insurance information.
- Online credentials paired with information that permits account access.
Not all personal data is “private information” under the statute. Classifying the data first can prevent needless notices and missed duties. Broader cybersecurity and data privacy duties may still matter when § 899-aa notice does not.
Unauthorized Access Can Be Enough
- Viewing, use, alteration, or communication can support an access finding.
- A lost or stolen device can support an acquisition finding.
- Downloads, copies, fraud, or identity-theft reports can support acquisition.
- Good-faith employee or agent access is excluded if the data is not misused or improperly disclosed.
Waiting for proven fraud can waste time. The legal analysis should begin when facts suggest protected information may have been compromised.
2. How the 30-Day Notification Deadline Works
After discovery of a covered breach, affected residents must receive notice in the most expedient time possible and without unreasonable delay. The statute sets a 30-day outside limit unless law enforcement permits a delay.
Who May Need to Receive Notice?
| Recipient | Timing or Trigger | Main Point |
|---|---|---|
| Affected residents | Without unreasonable delay; within 30 days | Covered data was or may have been accessed or acquired |
| Data owner or licensee | Immediately; within 30 days | Another business maintains the data |
| State authorities | When resident notice is required | AG, Department of State, and State Police receive notice |
| Consumer reporting agencies | More than 5,000 residents at one time | Notice covers timing, content, distribution, and approximate number affected |
Affected residents
- Timing or TriggerWithout unreasonable delay; within 30 days
- Main PointCovered data was or may have been accessed or acquired
Data owner or licensee
- Timing or TriggerImmediately; within 30 days
- Main PointAnother business maintains the data
State authorities
- Timing or TriggerWhen resident notice is required
- Main PointAG, Department of State, and State Police receive notice
Consumer reporting agencies
- Timing or TriggerMore than 5,000 residents at one time
- Main PointNotice covers timing, content, distribution, and approximate number affected
A covered entity under 23 NYCRR Part 500 may also have to notify the Department of Financial Services under that rule.
Permitted Methods of Resident Notice
- Written notice.
- Electronic notice with express consent and a notification log.
- Telephone notice with a notification log.
- Substitute notice when statutory conditions are met.
The notice must identify the sender, give required government contact information, and describe affected data categories. A data privacy compliance process can help teams prepare those items while the investigation continues.
3. When Consumer Notice May Not Be Required
The statute has a narrow exception for certain inadvertent disclosures between people authorized to access the information. The business must make a reasonable harm determination and keep it in writing.
The Inadvertent-Disclosure Exception
- The disclosure must involve people authorized to access the data.
- Misuse or financial harm must be unlikely.
- Unknown disclosure of online credentials also requires consideration of possible emotional harm.
- The written determination must be kept for at least five years.
If more than 500 residents are affected, the written determination must go to the Attorney General within 10 days after it is made.
Law Enforcement May Delay Notice
- An agency must find that notice would impede a criminal investigation.
- The delay cannot rest only on the company’s wish for more time.
- Notice must proceed when the agency finds it will no longer compromise the investigation.
Teams can still prepare notice drafts and recipient lists so they are ready when the delay ends.
4. How Federal Rules and SHIELD Act Duties Fit Together

Other breach rules can overlap with § 899-aa. In qualifying cases, notice under a recognized regime can satisfy resident notice, while state reports may remain due. SHIELD Act security duties under § 899-bb are separate.
Federal Notice May Not End State Reporting
- Qualifying Gramm-Leach-Bliley Act notice can avoid duplicate resident notice.
- HIPAA and HITECH notice can also satisfy resident notice.
- State-authority and consumer-reporting-agency notices may still be required.
- Certain HHS breach notices trigger Attorney General notice within five business days.
Healthcare entities should review HIPAA regulatory affairs duties with § 899-aa rather than treating one system as a complete substitute.
The SHIELD Act Also Requires Safeguards
- Administrative safeguards address risk, staff practices, and service providers.
- Technical safeguards address networks, processing, storage, attacks, and failures.
- Physical safeguards address access, storage, destruction, and disposal.
- Small-business safeguards may reflect size, complexity, activities, and data sensitivity.
These duties concern security before and after an incident. Broader consumer data protection planning can address prevention and breach response.
5. Frequently Asked Questions
Does encryption always remove the duty to give notice?
No. Encrypted data can still fall within the statute when the encryption key was also accessed or acquired.
Can a vendor finish its full investigation before telling the data owner?
Not just for convenience. A business holding covered data it does not own must notify the owner immediately and within 30 days after discovery when the statute applies.
Does HIPAA compliance remove every state reporting duty?
No. Qualifying HIPAA or HITECH notice can avoid duplicate resident notice, but state reporting may remain due. Certain HHS notices also trigger Attorney General notice within five business days.
Can email always be used for breach notice?
No. Standard electronic notice generally requires express consent and a notification log. Special rules apply when breached information includes credentials for the affected account.
6. Review the Breach Decision before the Deadline Runs Out
A sound response starts with four facts: what data was affected, who accessed it, when the breach was discovered, and which notice rules apply. Sorting those facts early leaves time to investigate without losing sight of the deadline.
SJKP’s attorneys can review breach facts, notice duties, overlapping rules, and security issues as one response. If protected data is involved or a deadline is near, contact SJKP to discuss the record and legal options.
07 Oct, 2026

