Privacy Policy - US Baseline (New York)
[COMPANY NAME] NEW YORK PRIVACY NOTICE
Effective Date: [__/__/____]
Last Updated: [__/__/____]
This Privacy Notice explains how [COMPANY LEGAL NAME] ("Company," "we," "us," or "our") collects, uses, retains, and discloses personal data through [LIST COVERED WEBSITES, APPLICATIONS, PRODUCTS, SERVICES, AND OFFLINE INTERACTIONS] (collectively, the "Services").
1. SCOPE AND CONTACT DETAILS
Company address: [________________________________]
Privacy email: [________________________________]
Request form: [________________________________]
Telephone: [________________________________]
This Notice applies to: [DESCRIBE COVERED INDIVIDUALS AND INTERACTIONS].
This Notice does not apply to: [IDENTIFY SEPARATELY NOTICED EMPLOYEE, APPLICANT, BUSINESS-CONTACT, OR OTHER PROCESSING].
2. PERSONAL DATA WE COLLECT
| Category | Examples actually collected | Sources | Purposes | Recipient categories | Retention period or criteria |
|---|---|---|---|---|---|
| Identifiers and contact data | [Specify] | [Specify] | [Specify] | [Specify] | [Specify] |
| Account and transaction data | [Specify] | [Specify] | [Specify] | [Specify] | [Specify] |
| Device, network, and online activity | [Specify] | [Specify] | [Specify] | [Specify] | [Specify] |
| Location data | [Specify] | [Specify] | [Specify] | [Specify] | [Specify] |
| Communications and user content | [Specify] | [Specify] | [Specify] | [Specify] | [Specify] |
| Professional or education data | [Specify] | [Specify] | [Specify] | [Specify] | [Specify] |
| Preferences and inferences | [Specify] | [Specify] | [Specify] | [Specify] | [Specify] |
| Sensitive or New York private information | [Specify] | [Specify] | [Specify] | [Specify] | [Specify] |
| Children's data | [Specify or state none] | [Specify] | [Specify] | [Specify] | [Specify] |
| Other data | [Specify] | [Specify] | [Specify] | [Specify] | [Specify] |
For incident-response purposes, New York "private information" can include specified identifiers combined with personal information, biometric information, medical or health-insurance information, and online-account credentials, subject to the statute's definitions and encryption conditions.
3. HOW WE USE PERSONAL DATA
We use personal data, as applicable, to:
- provide, maintain, personalize, and improve the Services;
- create and administer accounts and transactions;
- communicate about services, support, security, and offers;
- conduct analytics, research, advertising, and campaign measurement;
- authenticate users and detect fraud, abuse, and security incidents;
- comply with law and legal process and protect rights and safety; and
- evaluate or complete a corporate transaction.
We will provide additional notice or obtain consent before processing personal data for another purpose when applicable law requires it.
4. HOW WE DISCLOSE PERSONAL DATA
| Recipient category | Data categories disclosed | Purpose |
|---|---|---|
| Hosting, cloud, security, and IT providers | [Specify] | [Specify] |
| Payment and transaction providers | [Specify] | [Specify] |
| Analytics providers | [Specify] | [Specify] |
| Advertising and social-media partners | [Specify] | [Specify] |
| Customer-support and fulfillment providers | [Specify] | [Specify] |
| Professional advisers | [Specify] | [Specify] |
| Affiliates | [Specify] | [Specify] |
| Government authorities and litigants | [Specify] | [Specify] |
| Corporate transaction recipients | [Specify] | [Specify] |
| Other recipients you direct or authorize | [Specify] | [Specify] |
5. COOKIES AND TRACKING TECHNOLOGIES
| Purpose | Providers | Data involved | Choice method |
|---|---|---|---|
| Strictly necessary | [Specify] | [Specify] | [Not optional where necessary] |
| Functionality | [Specify] | [Specify] | [Cookie settings] |
| Analytics | [Specify] | [Specify] | [Cookie settings; provider choice] |
| Advertising | [Specify] | [Specify] | [Privacy choices link] |
Browser Do Not Track response: [________________________________]
Whether other parties collect activity over time and across different websites or services: [________________________________]
6. PRIVACY CHOICES AND REQUESTS
New York's SHIELD Act does not itself create a comprehensive consumer-rights request program. We will honor rights required by another applicable law and the following rights that we voluntarily offer, if any:
☐ access to personal data;
☐ correction of inaccurate personal data;
☐ deletion of personal data;
☐ portable copy of personal data;
☐ opt-out of sale or targeted advertising;
☐ other: [________________________________].
Request methods: [________________________________]
We may authenticate a request and apply exceptions permitted by the law or voluntary program governing the request. A voluntary response does not concede that a particular law applies.
7. RETENTION AND NEW YORK SECURITY PROGRAM
We retain each category of personal data only for the period reasonably necessary and proportionate to its disclosed purpose, subject to legal, accounting, security, fraud-prevention, and dispute-resolution needs.
For computerized data that includes New York private information, we develop, implement, and maintain reasonable administrative, technical, and physical safeguards. Our security program is designed to address:
- designation of personnel responsible for the program;
- reasonably foreseeable internal and external risks;
- workforce training and management;
- service-provider capability and contractual safeguards;
- network, software, processing, transmission, and storage risks;
- attack, system-failure, and intrusion detection and response;
- testing and monitoring of key controls; and
- secure storage, transport, destruction, and disposal.
Safeguards for a statutory small business may be scaled to its size and complexity, activities, and the sensitivity of the information it handles. No security measure is guaranteed to prevent every incident.
8. DATA INCIDENTS
If an incident involves New York private information, we will investigate and provide legally required notices. Current New York law generally requires notice to affected residents in the most expedient time possible, without unreasonable delay, and within 30 days after discovery, subject to the law-enforcement exception.
A person or business maintaining covered data it does not own must notify the owner or licensee immediately and within 30 days following discovery when the statutory conditions are met.
When New York residents are notified, the incident workflow must also evaluate notice to the New York Attorney General, Department of State, Division of State Police, and, for a covered entity under 23 NYCRR Part 500, Department of Financial Services. If more than 5,000 New York residents are notified at one time, consumer-reporting-agency notice is also required.
9. CHILDREN'S PRIVACY
☐ The Services are general audience, are not directed to children under 13, and we do not knowingly collect personal information online from a child under 13.
☐ The Services are child-directed or we have actual knowledge of collection from a child under 13. Our children's notice is at [LINK], and we provide notice and obtain verifiable parental consent as required by the Children's Online Privacy Protection Act and 16 C.F.R. Part 312 unless an exception applies.
10. INTERNATIONAL PROCESSING
Personal data may be processed in [COUNTRIES OR REGIONS]. Where a transfer mechanism or additional safeguard is legally required, we use [DESCRIBE MECHANISM].
11. CHANGES AND CONTACT
The "Last Updated" date identifies the latest version. We will provide additional notice and obtain consent before a material change when required.
Questions, requests, or complaints may be sent to:
[COMPANY LEGAL NAME]
Attn: [PRIVACY TEAM OR OFFICER]
[ADDRESS]
[EMAIL]
[PHONE]
SOURCES AND REFERENCES
- 15 U.S.C. § 45
- 15 U.S.C. § 6502
- 16 C.F.R. Part 312
- N.Y. General Business Law § 899-aa
- N.Y. General Business Law § 899-bb
Conform this notice to the Company's data inventory, security program, incident-response plan, vendor contracts, advertising technologies, retention schedule, and applicable-law analysis before publication.
About This Template
Compliance documents are what regulated businesses use to prove they follow the rules that apply to their industry, whether that is privacy, anti-money-laundering, consumer protection, or sector-specific requirements. Regulators look for consistent policies, up-to-date records, and clear evidence of employee training. The cost of getting compliance paperwork right is almost always smaller than the cost of an enforcement action, fine, or public disclosure.
Important Notice
This template is provided for informational purposes. It is not legal advice. We recommend having an attorney review any legal document before signing, especially for high-value or complex matters.
Last updated: July 2026
Get your Privacy Policy - US Baseline (New York), done and ready to use
Fill it in for your situation, adjust it for your state, and download the finished Word and PDF. Let the AI do it in about 5 minutes, or finish it yourself in the editor. $99 one time, or go Pro for access to every document and every Ezel app.