Data Protection Impact Assessment (DPIA) (NY) - New York

New York Compliance & Regulatory Updated September 27, 2026 Free Word and PDF

NEW YORK DATA PROTECTION IMPACT ASSESSMENT

Organization: [________________________________]

Assessment ID and version: [________________________________]

Processing activity or product: [________________________________]

Owner, assessment date and proposed launch: [________________________________]

1. Decision and scope

Reason for assessment: [NEW PROCESSING / MATERIAL CHANGE / SCHEDULED REVIEW / INCIDENT LEARNING / OTHER: ______]

Decision sought: [APPROVE / REVISE / STOP / OTHER: ______]

Entities, systems and locations in scope: [________________________________]

Individuals affected and relationship to organization: [________________________________]

New York resident data and other jurisdictions involved: [________________________________]

2. Data processing and flow

Stage Data categories and source Purpose and recipient System, location and retention
Collection [________________] [________________] [________________]
Analysis or profiling [________________] [________________] [________________]
Sharing or transfer [________________] [________________] [________________]
Storage and deletion [________________] [________________] [________________]

Scale, frequency and data-flow diagram reference: [________________________________]

Health, financial, biometric, location, credential or minors' data involved: [________________________________]

Service providers, contracts and onward recipients: [________________________________]

3. Purpose and alternatives

Purpose and expected benefits for the organization and individuals: [________________________________]

Data and processing necessary for each purpose: [________________________________]

Individual expectations, notices and choices: [________________________________]

Less intrusive alternatives, including reduced data, shorter retention or deidentification: [________________________________]

Reason for rejecting any alternative: [________________________________]

4. Legal applicability record

For each potentially applicable rule, record the current official source, trigger facts, reviewer, decision and action. Do not treat this assessment as a substitute for a separate incident response or legal review.

Rule or issue Trigger facts and current official URL Decision and action Reviewer/date
New York private-information and data-security duty [________________] [________________] [________________]
Breach notification and owner/licensee route [________________] [________________] [________________]
Consumer notice, choice or assessment under other applicable law [________________] [________________] [________________]
Financial, health, education, employment or other sector rule [________________] [________________] [________________]
Federal and other-jurisdiction requirements [________________] [________________] [________________]

5. Risks and safeguards

Assess unauthorized access, excessive collection, inaccurate inference, unexpected disclosure, long retention, transfer and vendor failure. Identify affected people and evidence for each rating.

Risk and affected people Likelihood and impact Safeguard, owner and evidence Residual risk
[________________] [____________] [________________] [____________]
[________________] [____________] [________________] [____________]
[________________] [____________] [________________] [____________]

Access, authentication, encryption and logging design: [________________________________]

Retention, deletion, backup and restore controls: [________________________________]

Service-provider selection, contracts and oversight: [________________________________]

Testing, monitoring and incident escalation: [________________________________]

New York General Business Law § 899-bb(2)(a) requires a person or business owning or licensing computerized data containing a New York resident's private information to maintain reasonable safeguards for security, confidentiality, integrity and disposal. Record the data and role before applying the duty.

6. Incident readiness

Person responsible for investigating a suspected breach: [________________________________]

Evidence preservation and affected-data assessment: [________________________________]

Notice decision owner and discovery date: [________________________________]

If notice to residents under § 899-aa(2) is required, the statute calls for notice in the most expedient time possible without unreasonable delay and within 30 days after discovery, subject to its law-enforcement exception. A maintainer of covered data it does not own has a separate immediate owner/licensee-notice duty with a 30-day outside limit under § 899-aa(3). Record any regulator, consumer-reporting-agency, sector-specific or other-state notice routes with their current official sources.

Notice and escalation plan, if triggered: [________________________________]

7. Decision and approval

Benefits compared with residual risks to individuals: [________________________________]

Decision: ☐ Approve ☐ Approve with conditions ☐ Revise and reassess ☐ Stop processing

Conditions, owners, deadlines and validation evidence: [________________________________]

Reassessment event and next review date: [________________________________]

Privacy reviewer and date: [________________________________]

Security reviewer and date: [________________________________]

Legal reviewer and date: [________________________________]

Decision maker and date: [________________________________]

Sources and references

New York Senate, General Business Law § 899-aa and § 899-bb, accessed September 27, 2026.

Insert Image

Insert Table

Watch Ezel in action (sample case)Choose a plan

All changes saved
Save
Export
Export as DOCX
Export as PDF
Generating PDF...
data_protection_impact_assessment_ny.pdf
Ready to export as PDF or Word
AI is editing...
Chat
Review

Draft it in the editor

The AI drafts each section from your answers and you review every word. Drafting from scratch takes hours; finish yours for $99 one time.

  • Built on this template
    Uses the New York version and the statutes it cites.
  • Formatted like the template
    Captions, numbering and layout stay intact.
  • AI editing
    Rewrite any section from your own notes.
  • Export as PDF and Word
    Yours to review, sign, or file.
Secure checkout via Stripe
Need to customize this document?

About this template

Last updated
September 27, 2026
Citations checked
September 27, 2026
Jurisdiction
New York
Category
Compliance & Regulatory

Legal authority

  • N.Y. Gen. Bus. Law § 899-aa
  • N.Y. Gen. Bus. Law § 899-bb

Compliance documents are what regulated businesses use to prove they follow the rules that apply to their industry, whether that is privacy, anti-money-laundering, consumer protection, or sector-specific requirements. Regulators look for consistent policies, up-to-date records, and clear evidence of employee training. The cost of getting compliance paperwork right is almost always smaller than the cost of an enforcement action, fine, or public disclosure.

Not legal advice

This template is provided for informational purposes. We recommend having an attorney review any legal document before signing, especially for high-value or complex matters.

Checked against the law it cites

A reviewer verified this template's legal citations against the official source on September 27, 2026.

N.Y. Gen. Bus. Law § 899-aa(2) (checked September 27, 2026): "The disclosure shall be made in the most expedient time possible and without unreasonable delay, provided that such notification shall be made within thirty days after the breach has been discovered, except for the legitimate needs of law enforcement, as provided in subdivision four of this section."

N.Y. Gen. Bus. Law § 899-aa(3) (checked September 27, 2026): "Any person or business which maintains computerized data which includes private information which such person or business does not own shall notify the owner or licensee of the information of any breach of the security of the system immediately, provided that such notification shall be made within thirty days following discovery, if the private information was, or is reasonably believed to have been, accessed or acquired by a person without valid authorization."

N.Y. Gen. Bus. Law § 899-bb(2)(a) (checked September 27, 2026): "Any person or business that owns or licenses computerized data which includes private information of a resident of New York shall develop, implement and maintain reasonable safeguards to protect the security, confidentiality and integrity of the private information including, but not limited to, disposal of data."

Draft your Data Protection Impact Assessment (DPIA) (NY) in the editor

Answer a few questions, let the AI editor draft each section from your answers, review it, and download Word and PDF. $99 one time, or $249 per month for every document and every Ezel app.