DPA Short Form Transfer Addendum - New York (Operational Compliance)

New York Contracts & Agreements Updated August 27, 2026 Free Word and PDF

DPA SHORT FORM TRANSFER ADDENDUM -- NEW YORK

Operational Compliance Format -- Article Numbering

Addendum Effective Date: [__/__/____]

Reference Agreement: [________________________________] dated [__/__/____] (the "Agreement")

Transferor: [________________________________] ("Transferor")

Transferee: [________________________________] ("Transferee")

This Addendum establishes the operational compliance framework for transfers of Personal Data involving New York residents under the SHIELD Act and, where applicable, 23 NYCRR Part 500.


ARTICLE I: DEFINITIONS

1.1 "Private Information" -- The categories and conditions in N.Y. Gen. Bus. Law § 899-aa(1)(b), including: covered personal information combined with a listed data element when the statutory encryption/key condition is met; a qualifying account, credit-card, or debit-card number that can provide account access without additional credentials; or a username or email address combined with credentials permitting online-account access. Complete the element-level inventory in Article IV from the current statute.

1.2 "Personal Data" -- A contractual umbrella term for information linked or reasonably linkable to an identified or identifiable individual. It includes Private Information only when the statutory definition and conditions are satisfied; it is not presented here as a separate New York statutory definition.

1.3 "Security Breach" -- The event defined in N.Y. Gen. Bus. Law § 899-aa(1)(c), including unauthorized access to or acquisition of, or access to or acquisition without valid authorization of, computerized data that compromises the security, confidentiality, or integrity of Private Information maintained by a business, subject to the statute's good-faith employee/agent exclusion and incident-specific analysis.

1.4 "Reasonable Safeguards" -- The administrative, technical, and physical safeguards applicable under N.Y. Gen. Bus. Law § 899-bb(2), after determining whether the regulated-entity or small-business routes apply.

1.5 "DFS Applicability" -- Whether either Party, the relevant system, or the transaction falls within current 23 NYCRR Part 500 must be determined from the regulation and the Party's regulator, licenses, exemptions, and filed status; this Addendum does not make that classification.


ARTICLE II: OPERATIONAL SCOPE

2.1 Regulatory Applicability Assessment:

Framework Applicable Notes
SHIELD Act (899-aa, 899-bb) ☐ Yes ☐ No Applies to all businesses with NY resident Private Info
DFS Cybersecurity (23 NYCRR 500) ☐ Yes ☐ No Financial institutions regulated by DFS
HIPAA ☐ Yes ☐ No Health data involvement
Other ☐ Yes ☐ No [________________________________]

2.2 Pre-Transfer Compliance Checklist:

☐ Written contract executed (this Addendum)
☐ Service provider safeguard requirement satisfied (899-bb(2)(b)(ii)(A)(5))
☐ Reasonable Safeguards implemented and verified
☐ Private Information elements identified
☐ Medical/health insurance information protocols updated (eff. Mar. 2025)
☐ Data inventory completed (Exhibit C)
☐ Technical measures verified (Exhibit B)
☐ Subprocessor list reviewed
☐ 30-day breach notification workflow established (eff. Dec. 2024)
☐ Multi-agency notification contacts documented (AG, Dept. of State, State Police, and DFS when the notifying person or business is a Part 500 covered entity)
☐ DFS compliance verified (if applicable)

2.3 Transfer Type: ☐ Controller-to-Processor ☐ Controller-to-Controller ☐ Processor-to-Sub-Processor

2.4 Purpose: [________________________________]

2.5 Data Categories:

☐ SSN ☐ DL/State ID ☐ Financial account + credentials ☐ Account/card number usable without additional credentials
☐ Biometric info ☐ Username/email + password/security answer ☐ Medical info
☐ Health insurance info ☐ Names/identifiers ☐ Employment data
☐ Online identifiers ☐ Commercial data ☐ Geolocation ☐ Other: [________________________________]

2.6 Data Subject Categories: ☐ Customers ☐ Employees ☐ End Users ☐ Business Contacts ☐ Patients ☐ Other: [________________________________]

2.7 Duration: Agreement term plus [____] day wind-down.


ARTICLE III: COMPLIANCE FRAMEWORK

3.1 SHIELD Act Contract Matrix (899-bb(2)(b)(ii)(A)(5)):

Requirement Reference Status
Service provider capable of maintaining safeguards Article VII ☐ Verified
Contractual safeguard requirement This Addendum ☐ Complete
Breach notification cooperation Article X ☐ Complete
Data disposal provision Article XI ☐ Complete
Audit/oversight capability Article XII ☐ Complete

3.2 DFS Vendor Management Matrix (23 NYCRR 500.11, if applicable):

Requirement Reference Status
Written policy for third-party service providers This Addendum ☐ Complete
Minimum cybersecurity practices required Article VII ☐ Complete
Due diligence process Article XII ☐ Complete
Periodic assessment Article XII, 12.3 ☐ Complete

3.3 Legal Basis: ☐ Contractual ☐ Legitimate interests ☐ Consent ☐ Legal obligation

3.4 International Transfer: ☐ DPF ☐ SCCs Module [____] ☐ UK Addendum ☐ N/A


ARTICLE IV: DATA CLASSIFICATION

4.1 SHIELD Act Private Information Inventory:

Element Included Enhanced Safeguards Verified
SSN ☐ Yes ☐ No ☐ Applied [__/__/____]
DL/State ID ☐ Yes ☐ No ☐ Applied [__/__/____]
Financial acct + credentials ☐ Yes ☐ No ☐ Applied [__/__/____]
Account/card number usable without additional credentials ☐ Yes ☐ No ☐ Applied [__/__/____]
Biometric info ☐ Yes ☐ No ☐ Applied [__/__/____]
Username/email + password ☐ Yes ☐ No ☐ Applied [__/__/____]
Medical information ☐ Yes ☐ No ☐ Applied [__/__/____]
Health insurance information ☐ Yes ☐ No ☐ Applied [__/__/____]

Definition gate: For each checked element, record the linked personal information, encryption and key status, statutory subparagraph, and source review date: [________________________________]

4.2 Additional Data:

Element Included Purpose Retention
Name ☐ Yes ☐ No [________________________________] [____]
Email ☐ Yes ☐ No [________________________________] [____]
Phone ☐ Yes ☐ No [________________________________] [____]
Address ☐ Yes ☐ No [________________________________] [____]
IP/device IDs ☐ Yes ☐ No [________________________________] [____]
Employment data ☐ Yes ☐ No [________________________________] [____]
Purchase history ☐ Yes ☐ No [________________________________] [____]

4.3 DFS Nonpublic Information (23 NYCRR 500.01, if applicable):

☐ NPI as defined in DFS regulations
☐ N/A (not DFS-regulated)


ARTICLE V: TRANSFEROR OPERATIONS

5.1 SHIELD Act Data Security Program Checklist (899-bb):

Administrative Safeguards (899-bb(2)(b)(ii)(A)):
☐ Security coordinator designated: [________________________________]
☐ Internal/external risks identified
☐ Safeguard sufficiency assessed
☐ Employee training conducted: Last date [__/__/____]
☐ Service providers (including Transferee) contractually required to maintain safeguards

Technical Safeguards (899-bb(2)(b)(ii)(B)):
☐ Network/software risk assessed
☐ Processing/transmission risk assessed
☐ Attack detection/prevention/response implemented
☐ Key controls regularly tested

Physical Safeguards (899-bb(2)(b)(ii)(C)):
☐ Storage/disposal risk assessed
☐ Intrusion detection/prevention implemented
☐ Unauthorized access protection implemented
☐ Disposal procedures established

5.2 Small Business Status (899-bb(2)(c)):

☐ Fewer than 50 employees ☐ Less than $3M gross revenue (3 years) ☐ Less than $5M total assets
☐ Qualifies as small business ☐ Does not qualify ☐ TBD

5.3 Monitoring Schedule:

Activity Frequency Last Done Next Due
Security program review Annually [__/__/____] [__/__/____]
Risk assessment update Annually [__/__/____] [__/__/____]
Service provider review Annually [__/__/____] [__/__/____]
Employee training Annually [__/__/____] [__/__/____]
Breach drill Annually [__/__/____] [__/__/____]
DFS assessment (if applicable) Annually [__/__/____] [__/__/____]

ARTICLE VI: TRANSFEREE OPERATIONS

6.1 Required Actions:

☐ Process only per documented instructions
☐ Maintain Reasonable Safeguards (899-bb)
☐ Ensure personnel confidentiality
☐ Cooperate with breach notification (30-day deadline)
☐ Cooperate with audits and assessments
☐ Delete/return data on termination
☐ DFS cybersecurity program (if applicable)
☐ Notify Transferor if unable to meet obligations

6.2 Prohibited Actions:

☐ NOT sell Personal Data
☐ NOT share for advertising without authorization
☐ NOT process for unauthorized purposes
☐ NOT disclose to unauthorized parties
☐ NOT engage in deceptive data practices (GBL 349/350)

6.3 Confidentiality. All personnel bound by confidentiality obligations.

6.4 DFS Third-Party Requirements (500.11, if applicable):

☐ Cybersecurity program implemented
☐ MFA for system access
☐ Encryption for NPI in transit and at rest
☐ Cybersecurity event notification protocols


ARTICLE VII: TECHNICAL MEASURES

7.1 SHIELD Act Three-Pillar Verification:

Administrative Safeguards:

Control Status Verified Next Review
Security coordinator ☐ Active [__/__/____] [__/__/____]
Risk identification ☐ Complete [__/__/____] [__/__/____]
Safeguard assessment ☐ Complete [__/__/____] [__/__/____]
Employee training ☐ Current [__/__/____] [__/__/____]
Service provider oversight ☐ Active [__/__/____] [__/__/____]

Technical Safeguards:

Control Status Verified Next Review
TLS 1.2+ transit encryption ☐ Active ☐ Pending [__/__/____] [__/__/____]
AES-256 at-rest encryption ☐ Active ☐ Pending [__/__/____] [__/__/____]
MFA ☐ Active ☐ Pending [__/__/____] [__/__/____]
RBAC ☐ Active ☐ Pending [__/__/____] [__/__/____]
IDS/IPS ☐ Active ☐ Pending [__/__/____] [__/__/____]
Vulnerability scanning ☐ Active ☐ Pending [__/__/____] [__/__/____]
Penetration testing ☐ Active ☐ Pending [__/__/____] [__/__/____]
SIEM/monitoring ☐ Active ☐ Pending [__/__/____] [__/__/____]
Incident response plan ☐ Active ☐ Pending [__/__/____] [__/__/____]

Physical Safeguards:

Control Status Verified Next Review
Facility access controls ☐ Active ☐ Pending [__/__/____] [__/__/____]
Intrusion detection ☐ Active ☐ Pending [__/__/____] [__/__/____]
Secure disposal (NIST 800-88) ☐ Active ☐ Pending [__/__/____] [__/__/____]

7.2 Enhanced Private Information Measures. Field-level encryption; data masking in non-prod; real-time alerts; segregated storage.

7.3 Medical/Health Data Measures (eff. Mar. 2025). Encryption, access controls, and logging specifically applied to medical and health insurance information now included in Private Information definition.


ARTICLE VIII: DATA SUBJECT RIGHTS OPERATIONS

8.1 NY Landscape Note. New York lacks comprehensive consumer privacy rights (access, delete, correct, port, opt-out). The SHIELD Act focuses on security and breach notification. However, operational readiness for consumer rights is recommended.

8.2 Multi-State Rights Support. Where other state laws apply to NY residents:

Right Supported Response Time
Access/Know ☐ Yes ☐ Prep [____] days
Delete ☐ Yes ☐ Prep [____] days
Correct ☐ Yes ☐ Prep [____] days
Portability ☐ Yes ☐ Prep [____] days
Opt-Out (sale/share) ☐ Yes ☐ Prep [____] days

8.3 Future Readiness Checklist:

☐ Data mapping system capable of individual-level queries
☐ Deletion capability across all data stores
☐ Correction/update capability
☐ Export in machine-readable format
☐ Opt-out mechanism infrastructure
☐ Consumer request intake and tracking system

8.4 DFS Consumer Complaint Cooperation (if applicable). Transferee cooperates with DFS-directed consumer complaints.


ARTICLE IX: SUBPROCESSOR MANAGEMENT

9.1 SHIELD Act Requirement. Where Transferee owns or licenses covered computerized data, its reasonable administrative safeguards include selecting capable subprocessors and requiring safeguards by contract (899-bb(2)(b)(ii)(A)(5)).

9.2 Authorization: ☐ Specific ☐ General (with [____] days' notice)

9.3 Subprocessor Tracker:

Subprocessor Location Activity Private Info DFS Data Approved Date
[________________________________] [____] [________________________________] [__/__/____]
[________________________________] [____] [________________________________] [__/__/____]
[________________________________] [____] [________________________________] [__/__/____]

9.4 Flow-Down Checklist:

☐ Reasonable Safeguards (admin, tech, physical)
☐ Confidentiality ☐ Purpose limitation ☐ Breach notification
☐ Audit cooperation ☐ Deletion/return ☐ DFS compliance (if applicable)

9.5 Liability. Transferee fully liable.


ARTICLE X: DATA BREACH RESPONSE

10.1 Critical: 30-Day Notification Deadline (eff. Dec. 21, 2024).

Step Action Deadline
1 Breach detected/suspected Trigger
2 Transferee notifies Transferor Within [____] hours
3 Details provided With notification
4 Updates Every [____] hours
5 Individual notice (NY residents) Within 30 days of discovery
6 AG notification With individual notice
7 DFS notification Within 72 hours (if DFS-regulated)
8 Dept. of State notification With individual notice
9 State Police notification With individual notice

10.2 Breach Response Checklist:

☐ Breach contained
☐ Transferor notified within required timeframe
☐ Scope identified (number, Private Info elements)
☐ Medical/health insurance data involvement assessed (eff. Mar. 2025)
☐ Harm assessment completed (reasonably likely to result in misuse/harm)
☐ Individual notice drafted (date, description, contact info, CRA info, remedial services)
☐ AG office notified
☐ DFS notified (if applicable, within 72 hours)
☐ Dept. of State notified
☐ State Police notified
☐ Substitute notice evaluated (if >$250K cost, >500K affected, or insufficient contacts)
☐ Credit monitoring arranged
☐ Root cause analysis
☐ Remediation plan

10.3 Expanded Private Information (eff. Mar. 21, 2025). Medical information and health insurance information now trigger breach notification. Update detection and classification protocols.

10.4 Indemnification. Transferee indemnifies for breach costs attributable to its security failures.


ARTICLE XI: DATA RETENTION AND DELETION

11.1 SHIELD Act Disposal (899-bb(2)(b)(ii)(C)(4)). Dispose of Private Information within a reasonable time after it is no longer needed for business purposes by erasing electronic media so the information cannot be read or reconstructed.

11.2 Retention Schedule:

Category Period Basis Disposal Method
[________________________________] [____] [________________________________] [________________________________]
[________________________________] [____] [________________________________] [________________________________]

11.3 Deletion Checklist:

☐ Election received ☐ Primary data purged ☐ Backups scheduled (within [____] months)
☐ Subprocessors notified ☐ SHIELD-compliant disposal methods used ☐ Certification delivered

11.4 Legal Hold. Permitted if required; Transferor notified; minimum data; protections continue.


ARTICLE XII: AUDIT AND MONITORING

12.1 SHIELD Act Oversight. Transferor verifies Transferee's capability to maintain safeguards.

12.2 Evidence. SOC 2 Type II; ISO 27001; pen test summary; security questionnaire; risk assessment; training records.

12.3 Monitoring Schedule:

Activity Frequency Last Done Next Due
Safeguards assessment Annually [__/__/____] [__/__/____]
Security controls review Annually [__/__/____] [__/__/____]
Subprocessor audit Annually [__/__/____] [__/__/____]
Breach readiness drill Annually [__/__/____] [__/__/____]
DFS compliance review Annually (if applicable) [__/__/____] [__/__/____]

12.4 On-Site. [____] per year; [____] days' notice; NDA; cost per Agreement.

12.5 Regulatory Cooperation. AG, DFS, Dept. of State, State Police as applicable.

12.6 Remediation. [____] days; evidence provided.


ARTICLE XIII: CROSS-BORDER

13.1 Interstate. SHIELD Act applies to any business with NY resident Private Information regardless of location.

13.2 Location: ☐ US only ☐ US + EEA/UK ☐ Specific: [________________________________] ☐ No restriction

13.3 Relocation Notice. [____] days prior.


ARTICLE XIV: LIABILITY

14.1 Mutual indemnification.

14.2 Transferee: AG enforcement costs; DFS penalties (if applicable); notification/monitoring costs; common law negligence claims; GBL 349/350 claims; investigation costs.

14.3 Enforcement. AG (SHIELD Act -- no private right of action); DFS (23 NYCRR 500); common law (negligence, breach of implied contract); GBL 349/350 (private right of action for deceptive practices).

14.4 Cap. Agreement cap except for willful misconduct, unauthorized disclosure, notification failures.


ARTICLE XV: TERM AND TERMINATION

15.1 Term. Coterminous. 15.2 Cure. [____] days. 15.3 Survival. Articles I, VI, VII, VIII, X, XI, XII, XIV.


ARTICLE XVI: EXECUTION

TRANSFEROR:

Signature: [________________________________]
Printed Name: [________________________________]
Title: [________________________________]
Organization: [________________________________]
Date: [__/__/____]

TRANSFEREE:

Signature: [________________________________]
Printed Name: [________________________________]
Title: [________________________________]
Organization: [________________________________]
Date: [__/__/____]


EXHIBIT A: RISK ASSESSMENT

Factor Rating Notes
SHIELD Act safeguards ☐ Low ☐ Med ☐ High [________________________________]
30-day notification readiness ☐ Low ☐ Med ☐ High [________________________________]
Medical/health data (Mar. 2025) ☐ Low ☐ Med ☐ High [________________________________]
DFS compliance ☐ Low ☐ Med ☐ High ☐ N/A [________________________________]
Common law litigation risk ☐ Low ☐ Med ☐ High [________________________________]

Overall: ☐ Proceed ☐ Proceed with measures ☐ Do not proceed


EXHIBIT B: SHIELD ACT SAFEGUARDS VERIFICATION

Safeguard Category Control Status Date
Administrative Security coordinator ☐ Yes ☐ No [__/__/____]
Administrative Risk identification ☐ Yes ☐ No [__/__/____]
Administrative Employee training ☐ Yes ☐ No [__/__/____]
Technical Encryption transit ☐ Yes ☐ No [__/__/____]
Technical Encryption at rest ☐ Yes ☐ No [__/__/____]
Technical MFA ☐ Yes ☐ No [__/__/____]
Technical RBAC ☐ Yes ☐ No [__/__/____]
Technical SIEM ☐ Yes ☐ No [__/__/____]
Physical Access controls ☐ Yes ☐ No [__/__/____]
Physical Disposal procedures ☐ Yes ☐ No [__/__/____]
Certification SOC 2 ☐ Yes ☐ No Expiry: [__/__/____]
Certification ISO 27001 ☐ Yes ☐ No Expiry: [__/__/____]

EXHIBIT C: DATA INVENTORY

# Element Private Info DFS NPI Source Purpose Retention Disposal
1 [________________________________] [________] [________________________________] [____] [________]
2 [________________________________] [________] [________________________________] [____] [________]
3 [________________________________] [________] [________________________________] [____] [________]

SOURCES AND REFERENCES

Insert Image

Insert Table

Watch Ezel in action (sample case)Choose a plan

All changes saved
Save
Export
Export as DOCX
Export as PDF
Generating PDF...
dpa_short_form_transfer_addendum_ny.pdf
Ready to export as PDF or Word
AI is editing...
Chat
Review

Draft it in the editor

The AI drafts each section from your answers and you review every word. Drafting from scratch takes hours; finish yours for $99 one time.

  • Built on this template
    Uses the New York version and the statutes it cites.
  • Formatted like the template
    Captions, numbering and layout stay intact.
  • AI editing
    Rewrite any section from your own notes.
  • Export as PDF and Word
    Yours to review, sign, or file.
Secure checkout via Stripe
Need to customize this document?

About this template

Last updated
August 27, 2026
Jurisdiction
New York
Category
Contracts & Agreements

Legal authority

  • New York SHIELD Act, N.Y. Gen. Bus. Law 899-aa, 899-bb
  • N.Y. Gen. Bus. Law 899-aa (Breach Notification, as amended Dec. 2024)
  • 23 NYCRR Part 500 (DFS Cybersecurity Regulation)

A contract is a written record of what two or more parties agreed to and what happens if someone does not follow through. Clear language, defined terms, and clean signature blocks keep disputes small and enforceable. The most common mistakes in contracts come from vague promises, missing details about timing or payment, and skipping standard protective clauses like governing law and dispute resolution.

Not legal advice

This template is provided for informational purposes. We recommend having an attorney review any legal document before signing, especially for high-value or complex matters.

Checked against the law it cites

The statutes this template relies on are listed under Legal authority.

N.Y. Gen. Bus. Law § 899-aa(1)(b) (checked August 22, 2026): "Private information shall mean either: (i) personal information consisting of any information in combination with any one or more of the following data elements, when either the data element or the combination of personal information plus the data element is not encrypted, or is encrypted with an encryption key that has also been accessed or acquired."

N.Y. Gen. Bus. Law § 899-aa(1)(c) (checked August 22, 2026): "Breach of the security of the system shall mean unauthorized access to or acquisition of, or access to or acquisition without valid authorization, of computerized data that compromises the security, confidentiality, or integrity of private information maintained by a business."

N.Y. Gen. Bus. Law § 899-bb(2)(a) (checked August 22, 2026): "Any person or business that owns or licenses computerized data which includes private information of a resident of New York shall develop, implement and maintain reasonable safeguards to protect the security, confidentiality and integrity of the private information including, but not limited to, disposal of data."

N.Y. Gen. Bus. Law § 899-bb(2)(b)(ii)(A)(5) (checked August 27, 2026): "selects service providers capable of maintaining appropriate safeguards, and requires those safeguards by contract"

Draft your DPA Short Form Transfer Addendum - New York (Operational Compliance) in the editor

Answer a few questions, let the AI editor draft each section from your answers, review it, and download Word and PDF. $99 one time, or $249 per month for every document and every Ezel app.