NYDFS Announces New Cybersecurity Requirements for Financial Services Companies

On July 29,  the New York State Department of Financial Services (NYFDS) posted a request for public comment on their proposed amendments to their cybersecurity requirements for financial services companies, the Cybersecurity Requirements for Financial Services Companies (Part 500).
Read More
Cybersecurity

New York DFS Issues New Cybersecurity Guidance

Under New York’s Cybersecurity Regulation, issued in 2017, any entity (a “Covered Entity”) regulated by the New York State Department of Financial Services (DFS) must maintain a risk-based cybersecurity program that protects its information systems and nonpublic data. For years, DFS has allowed Covered Entities to adopt the cybersecurity program of an affiliate. This has…
Read More

2020 News in Review

Week Ending December 28 ICO Warns SolarWinds Victims to Report Breaches The United Kingdom’s Information Commissioner’s Office (ICO) has issued a warning to organizations compromised by the SolarWinds breach. The breach, which was carried out by Russian hackers, affected more than 18000 organizations worldwide. ICO requires UK data controllers subject to NIS regulations to report…
Read More

ADCG Launches Data Privacy Law Comparison Tool

In 2018, the European Union launched its landmark data privacy law, the General Data Protection Regulation (GDPR). What followed can only be described as a wave of data privacy laws that swept the globe. Legislators from California to Brazil, to New Zealand have passed some form of data privacy law with the potential to impact…
Read More

COVID-19 Brings Deadline Extensions from NY Department of Financial Services

The New York State Department of Financial Services (NYDFS) has taken several steps in response to the COVID-19 pandemic. On March 12, NYDFS released a compliance order and a series of guidance letters extending certain deadlines and requesting that organizations submit their plans for managing the risks resulting from COVID-19. The announcements regarding the extension…
Read More

How Organizations Should Prepare for the New York SHIELD Act

How Organizations Should Get Ready for the New York SHIELD Act In the absence of comprehensive federal data protection privacy standards, states are taking matters into their own hands by passing legislation to protect the private information that companies acquire from individuals. In July, Governor Cuomo of New York signed the SHIELD act (Stop Hacks…
Read More
New York Privacy Act

New York Privacy Act: It Goes Beyond CCPA

The idea that consumers own their private financial information can be traced to an early 1970s California state constitutional amendment adding ‘privacy’ to guarantees of life, liberty, and other inalienable rights. While financial privacy is not explicitly mentioned in this original amendment, California courts have determined that it is included. Only relatively modest consumer protection…
Read More

Synopsis of Recently Passed New York State Laws on Cybersecurity

Two new privacy protection laws were signed into law by New York Governor Andrew Cuomo on July 25, 2019. (NY State Law S.5575B/A.5635 – or SHIELD Act – “Imposes Stronger Obligations on Businesses Handling Private Customer Data to Provide Proper Notification of Security Breaches.”). The law takes effect 240 days from the date of signing…
Read More
Back To Top