New York · verified through August 25, 2026

New York: law status and evidence context.

Law status, direct attached-library attribution, and public enforcement context are shown separately. A zero direct total does not mean no enforcement exists.

NY · 6 requirements mapped / control outcomes supported

Law status

No verified general comprehensive law

No comprehensive consumer privacy law verified (the New York Privacy Act bills S365/A4947 remain pending)

Official name / citation
n.a.
Status / effective date
Bills only
Principal enforcer
New York Attorney General (with the Department of Financial Services for regulated entities)

Direct attached-library attribution

0 cases · $0

These totals are assigned solely by the attachment’s state heading. Shared multistate totals are not allocated in full to every state.

The attached library does not enumerate participant-level allocations for every multistate matter; shared settlement totals are presented once at the national level and are not duplicated into state totals.

Official law sources

Other generally applicable PII law

N.Y. Gen. Bus. Law § 899-aa (Information Security Breach and Notification Act) - https://www.nysenate.gov/legislation/laws/GBS/899-AA

Public enforcement context

Tier 1

Eight auto insurers (American Family/Midvale, Farmers, Hagerty, The Hartford, Infinity, Liberty Mutual, Metromile, State Auto)

$14.2 million · n.a. (date not stated on page)

The AG and DFS obtained $14.2 million from insurers over data-security failures that exposed consumers' personal information in online quoting tools.

Legal basis: New York consumer protection and data-security authority (statutes not named on the page); joint action with DFS

Official case source (opens in a new tab)

Mapped control outcomes

1 personal data inventory/data map; 2 sensitive-data discovery; 3 downstream copy tracking; 8 breach blast-radius analysis; 9 retention/minimization; 10 regulator audit evidence

Kestryl can evidence where regulated personal data actually resides across structured stores and unstructured attachments/images, produce audit rows and evidence packs showing when each location was discovered and reviewed, and apply structured-data remediation modes (mask, vault, strip) to reduce exposure. It does not alter source attachments or documents, and its output is technical evidence supporting controls, not proof of legal compliance.