S 1139 NY Passed One Chamber
Relates to requiring governmental entities to implement multifactor authentication for local and remote network access
A state bill is a proposed law in a state legislature — separate from the U.S. Congress. Learn more →
Summary
Requires governmental entities to, whenever possible and feasible, consider implementing multifactor authentication for local and remote network access; requires public websites to encrypt all exchanges and to comply with privacy standards.
Sponsor (1)
- Kristen Gonzalez Democratic · primary
Action history (16)
- Jan 8, 2025 REFERRED TO INTERNET AND TECHNOLOGY · upper
- Feb 10, 2025 REPORTED AND COMMITTED TO FINANCE · upper
- May 28, 2025 1ST REPORT CAL.1343 · upper
- May 29, 2025 2ND REPORT CAL. · upper
- Jun 4, 2025 ADVANCED TO THIRD READING · upper
- Jun 11, 2025 PASSED SENATE · upper
- Jun 11, 2025 DELIVERED TO ASSEMBLY · upper
- Jun 11, 2025 REFERRED TO WAYS AND MEANS · lower
- Jan 7, 2026 DIED IN ASSEMBLY · lower
- Jan 7, 2026 RETURNED TO SENATE · lower
- Jan 7, 2026 REFERRED TO INTERNET AND TECHNOLOGY · upper
- Feb 25, 2026 REPORTED AND COMMITTED TO FINANCE · upper
- May 19, 2026 1ST REPORT CAL.1194 · upper
- May 20, 2026 2ND REPORT CAL. · upper
- May 21, 2026 ADVANCED TO THIRD READING · upper
- May 29, 2026 SUBSTITUTED BY A6347 · upper
Text versions (2)
Full text
Full text imported from assembly.state.ny.us
Skip to main content
New York State Assembly Speaker Carl E. Heastie
--> --> -->
Assembly Members
Legislative Info
Public Hearings
Speaker's Press
Assembly Reports
Committees & More
Bill Search Home Laws Legislative Calendar Public Hearing Schedule Assembly Calendars Assembly Committee Agenda Javascript must be enabled to properly view this page.
Bill No.: Summary Actions Committee Votes Floor Votes Memo Text LFIN Chamber Video/Transcript S01139 Summary: BILL NO S01139   SAME AS SAME AS A06347
  SPONSOR GONZALEZ   COSPNSR   MLTSPNSR   Amd §202, add §§210 - 212, St Tech L   Requires governmental entities to, whenever possible and feasible, consider implementing multifactor authentication for local and remote network access; requires public websites to encrypt all exchanges and to comply with privacy standards.
Go to top S01139 Text:
STATE OF NEW YORK ________________________________________________________________________
1139
2025-2026 Regular Sessions
IN SENATE
January 8, 2025 ___________
Introduced by Sen. GONZALEZ -- read twice and ordered printed, and when printed to be committed to the Committee on Internet and Technology
AN ACT to amend the state technology law, in relation to requiring governmental entities to implement multifactor authentication for local and remote network access
The People of the State of New York, represented in Senate and Assem- bly, do enact as follows:
1 Section 1. Section 202 of the state technology law is amended by 2 adding two new subdivisions 9 and 10 to read as follows: 3 9. "Governmental entity" shall mean any state or local department, 4 board, bureau, division, commission, committee, school district, public 5 authority, public benefit corporation, council or office, including all 6 entities defined pursuant to section two of the public authorities law. 7 Such term shall include the state university of New York and the city 8 university of New York. Further, such term shall include any county, 9 city, town or village but shall not include the judiciary or state and 10 local legislatures. 11 10. "Multifactor authentication" shall mean using two or more differ- 12 ent types of identification credentials to achieve authentication. The 13 types of identification credentials shall include: 14 (a) knowledge-based credentials, which is a knowledge-based authenti- 15 cation that requires the user to provide information that they know such 16 as passwords or PINs; 17 (b) possession-based credentials, which is authentication that 18 requires individuals to have something specific in their possession, 19 such as security tokens, key fobs, SIM cards or smartphone applications; 20 and 21 (c) biometric information, which is any measurable physical, physio- 22 logical or behavioral characteristics that are attributable to a person, 23 including but not limited to facial characteristics, fingerprint charac- 24 teristics, hand characteristics, eye characteristics, vocal character-
EXPLANATION--Matter in italics (underscored) is new; matter in brackets [ ] is old law to be omitted. LBD01038-01-5
S. 1139 2
1 istics, and any other characteristics that can be used to identify a 2 person including, but not limited to: fingerprints; handprints; retina 3 and iris patterns; DNA sequence; voice; gait; and facial geometry. 4 § 2. The state technology law is amended by adding three new sections 5 210, 211, and 212 to read as follows: 6 § 210. Multifactor authentication. 1. Multifactor authentication 7 requirement. Every governmental entity shall, whenever possible and 8 feasable, consider implementing multifactor authentication for local and 9 remote network access to any email accounts, cloud storage accounts, web 10 applications, networks, databases, or servers, maintained by such entity 11 or on behalf of such entity, for the employees and officers of such 12 entity or for any other individuals providing services to or on behalf 13 of such entity. 14 2. Technical standard. The office shall promulgate rules to establish 15 standard technical requirements for governmental entities for complying 16 with subdivision one of this section. Such rules shall include regu- 17 lations addressing biometric information including proper storage of 18 traits relating to user-specific biological traits. Such rules shall 19 additionally include provisions regarding compliance for individuals 20 with disabilities or special needs. For the purposes of this subdivi- 21 sion, the office may use and refer to the guidelines provided by the 22 National Institute of Standards and Technology, the Federal Risk and 23 Authorization Management Program (FedRAMP), the Federal Information 24 Security Management Act of 2002 (FISMA) and the Defense Federal Acquisi- 25 tion Regulation Supplement (DFARS). 26 3. Waivers. The office, upon application by a governmental entity, may 27 completely or partially waive the requirements of this section for such 28 governmental entity. Such waiver shall be valid for no longer than two 29 years and shall be reapproved after expiration. The office shall promul- 30 gate rules to establish the application process and criteria for such 31 waivers. 32 § 211. Privacy requirements. This section shall apply to the use of 33 multifactor authentication at governmental entities and to any vendors 34 and/or third-party contractors administering the multifactor authentica- 35 tion on behalf of the governmental entity. 36 1. No governmental entity shall require the use of biometric informa- 37 tion to access local and/or remote network access. 38 2. No governmental entity that facilitates the use of biometric infor- 39 mation to access local and remote network access shall sell or monetize 40 such data. 41 3. No governmental entity that facilitates the use of biometric infor- 42 mation to access local and remote network access shall share such data 43 with law enforcement without a warrant. 44 4. Any governmental entity and any applicable third-party contractors 45 that facilitate the use of biometric information shall agree to comply 46 with the standards established by the office and all statutory privacy 47 standards. 48 § 212. Public website encryption. Every website maintained by or on 49 behalf of a governmental entity shall encrypt all exchanges and trans- 50 fers between a web server, maintained by or on behalf of a governmental 51 entity, and a web browser of hypertext or of electronic information, and 52 require web browsers to request such encrypted exchange or transfer at 53 all times for such websites, provided that such encryption shall not be 54 required if such exchanges or transfers are conducted in a manner that 55 provides at least an equivalent level of confidentiality, data integrity 56 and authentication.
S. 1139 3
1 § 3. This act shall take effect one year after it shall have become a 2 law. Effective immediately, the addition, amendment, and/or repeal of 3 any rule or regulation necessary for the implementation of this act on 4 its effective date are authorized to be made and completed on or before 5 such effective date.
Go to top
Sitemap
Request Information
Directions and Maps
Comments
Data from OpenStates. View on OpenStates →
Comments