Data Protection Impact Assessment (DPIA) (NY) - New York
NEW YORK DATA PROTECTION IMPACT ASSESSMENT
Organization: [________________________________]
Assessment ID and version: [________________________________]
Processing activity or product: [________________________________]
Owner, assessment date and proposed launch: [________________________________]
1. Decision and scope
Reason for assessment: [NEW PROCESSING / MATERIAL CHANGE / SCHEDULED REVIEW / INCIDENT LEARNING / OTHER: ______]
Decision sought: [APPROVE / REVISE / STOP / OTHER: ______]
Entities, systems and locations in scope: [________________________________]
Individuals affected and relationship to organization: [________________________________]
New York resident data and other jurisdictions involved: [________________________________]
2. Data processing and flow
| Stage | Data categories and source | Purpose and recipient | System, location and retention |
|---|---|---|---|
| Collection | [________________] | [________________] | [________________] |
| Analysis or profiling | [________________] | [________________] | [________________] |
| Sharing or transfer | [________________] | [________________] | [________________] |
| Storage and deletion | [________________] | [________________] | [________________] |
Scale, frequency and data-flow diagram reference: [________________________________]
Health, financial, biometric, location, credential or minors' data involved: [________________________________]
Service providers, contracts and onward recipients: [________________________________]
3. Purpose and alternatives
Purpose and expected benefits for the organization and individuals: [________________________________]
Data and processing necessary for each purpose: [________________________________]
Individual expectations, notices and choices: [________________________________]
Less intrusive alternatives, including reduced data, shorter retention or deidentification: [________________________________]
Reason for rejecting any alternative: [________________________________]
4. Legal applicability record
For each potentially applicable rule, record the current official source, trigger facts, reviewer, decision and action. Do not treat this assessment as a substitute for a separate incident response or legal review.
| Rule or issue | Trigger facts and current official URL | Decision and action | Reviewer/date |
|---|---|---|---|
| New York private-information and data-security duty | [________________] | [________________] | [________________] |
| Breach notification and owner/licensee route | [________________] | [________________] | [________________] |
| Consumer notice, choice or assessment under other applicable law | [________________] | [________________] | [________________] |
| Financial, health, education, employment or other sector rule | [________________] | [________________] | [________________] |
| Federal and other-jurisdiction requirements | [________________] | [________________] | [________________] |
5. Risks and safeguards
Assess unauthorized access, excessive collection, inaccurate inference, unexpected disclosure, long retention, transfer and vendor failure. Identify affected people and evidence for each rating.
| Risk and affected people | Likelihood and impact | Safeguard, owner and evidence | Residual risk |
|---|---|---|---|
| [________________] | [____________] | [________________] | [____________] |
| [________________] | [____________] | [________________] | [____________] |
| [________________] | [____________] | [________________] | [____________] |
Access, authentication, encryption and logging design: [________________________________]
Retention, deletion, backup and restore controls: [________________________________]
Service-provider selection, contracts and oversight: [________________________________]
Testing, monitoring and incident escalation: [________________________________]
New York General Business Law § 899-bb(2)(a) requires a person or business owning or licensing computerized data containing a New York resident's private information to maintain reasonable safeguards for security, confidentiality, integrity and disposal. Record the data and role before applying the duty.
6. Incident readiness
Person responsible for investigating a suspected breach: [________________________________]
Evidence preservation and affected-data assessment: [________________________________]
Notice decision owner and discovery date: [________________________________]
If notice to residents under § 899-aa(2) is required, the statute calls for notice in the most expedient time possible without unreasonable delay and within 30 days after discovery, subject to its law-enforcement exception. A maintainer of covered data it does not own has a separate immediate owner/licensee-notice duty with a 30-day outside limit under § 899-aa(3). Record any regulator, consumer-reporting-agency, sector-specific or other-state notice routes with their current official sources.
Notice and escalation plan, if triggered: [________________________________]
7. Decision and approval
Benefits compared with residual risks to individuals: [________________________________]
Decision: ☐ Approve ☐ Approve with conditions ☐ Revise and reassess ☐ Stop processing
Conditions, owners, deadlines and validation evidence: [________________________________]
Reassessment event and next review date: [________________________________]
Privacy reviewer and date: [________________________________]
Security reviewer and date: [________________________________]
Legal reviewer and date: [________________________________]
Decision maker and date: [________________________________]
Sources and references
New York Senate, General Business Law § 899-aa and § 899-bb, accessed September 27, 2026.
About this template
- Last updated
- September 27, 2026
- Citations checked
- September 27, 2026
- Jurisdiction
- New York
- Category
- Compliance & Regulatory
Legal authority
- N.Y. Gen. Bus. Law § 899-aa
- N.Y. Gen. Bus. Law § 899-bb
Compliance documents are what regulated businesses use to prove they follow the rules that apply to their industry, whether that is privacy, anti-money-laundering, consumer protection, or sector-specific requirements. Regulators look for consistent policies, up-to-date records, and clear evidence of employee training. The cost of getting compliance paperwork right is almost always smaller than the cost of an enforcement action, fine, or public disclosure.
Not legal advice
This template is provided for informational purposes. We recommend having an attorney review any legal document before signing, especially for high-value or complex matters.
Checked against the law it cites
A reviewer verified this template's legal citations against the official source on September 27, 2026.
N.Y. Gen. Bus. Law § 899-aa(2) (checked September 27, 2026): "The disclosure shall be made in the most expedient time possible and without unreasonable delay, provided that such notification shall be made within thirty days after the breach has been discovered, except for the legitimate needs of law enforcement, as provided in subdivision four of this section."
N.Y. Gen. Bus. Law § 899-aa(3) (checked September 27, 2026): "Any person or business which maintains computerized data which includes private information which such person or business does not own shall notify the owner or licensee of the information of any breach of the security of the system immediately, provided that such notification shall be made within thirty days following discovery, if the private information was, or is reasonably believed to have been, accessed or acquired by a person without valid authorization."
N.Y. Gen. Bus. Law § 899-bb(2)(a) (checked September 27, 2026): "Any person or business that owns or licenses computerized data which includes private information of a resident of New York shall develop, implement and maintain reasonable safeguards to protect the security, confidentiality and integrity of the private information including, but not limited to, disposal of data."
Draft your Data Protection Impact Assessment (DPIA) (NY) in the editor
Answer a few questions, let the AI editor draft each section from your answers, review it, and download Word and PDF. $99 one time, or $249 per month for every document and every Ezel app.