What is ISBNA?
The New York Information Security Breach and Notification Act (ISBNA) protects New York residents from misuse of their personal information. The Act mandates the protection of such information by businesses operating in the state and outlines an organization’s obligations to its customers in the event of a security breach.
ISBNA also empowers the Attorney General to bring an action against any business that fails to comply with the Act, and describes the penalties which may be administered by the courts.
Who is affected by ISBNA?
The Act applies to all businesses operating in New York state and those maintaining records containing the personal information of New York residents. The Act requires businesses to “disclose any breach of the security of the system following discovery or notification of the breach… to any resident… whose private information was, or is reasonably believed to have been, acquired by a person without valid authorization.” Under the Act, personal information is defined as any non-public name or number that may be used to identify a specific individual, including:
- a social security number
- a driver’s license number or non-driver identification card number
- a financial account number
- a credit card or debit card number accompanied by applicable passwords or security codes
Disclosure must be made in the most expedient time possible and without unreasonable delay. Failure to abide by the Act can result in court-awarded damages for actual costs or losses incurred by an individual, as well as sanctions of up to $150,000 for intentional or reckless violation of the ISBNA.
Your Partner in Regulatory Compliance
By purging outdated files or placing one of our locked security consoles in your office, PROSHRED® can assist your company in maintaining a document destruction program that meets ISBNA regulations. Using state-of-the-art technology, our highly trained and certified security professionals efficiently shred all documents right on your premises. We give you the option to watch the shredding process, and also provide you with a Certificate of Destruction that records each shred. Trust PROSHRED® as your partner in compliance for maintaining your document security program.
For more information on the New York Information Security Branch and Notification Act, please visit: