State Financial Privacy: California (CFIPA) and New York (NYDFS)
Last reviewed:
Because GLBA does not preempt states, California's CFIPA (SB-1) adds opt-in consent for sharing with nonaffiliated third parties, and New York's NYDFS cybersecurity regulation (2017) imposes stricter, NIST-aligned mandates including a CISO and incident response. CCPA/CPRA exempt only GLBA/CFIPA-covered datasets, not whole institutions.
CFIPA requires written opt-in consent before sharing personal information with nonaffiliated third parties, on a form titled "Important Privacy Choices for Consumers," and lets consumers opt out of sharing with affiliates in a different line of business. Negligent violations carry statutory damages of $2,500 per consumer up to a $500,000 cap; willful violations have no cap.
The NYDFS cybersecurity regulation (2017) was the first state regulation to go well beyond GLBA, defining nonpublic information more broadly and adding requirements GLBA lacked on personnel, reporting, documentation and third-party providers. NYDFS also regulates virtual currencies via the BitLicense (2015) and maintains a "Greenlist" of approved coins.
The CCPA/CPRA exemption applies dataset by dataset, not to the whole organization. Only data specifically covered by GLBA or CFIPA is exempt, so institutions must review data set by set.
Key terms - quick answers
What is “CFIPA”?
What is “NYDFS cybersecurity regulation”?
What is “BitLicense”?
Keep going - free
Every study note on this site is free. So are these: