Skip to content

New York Takes on Big Tech with Tougher Data Protection Rules

Businesswoman in office interacting with digital cybersecurity shield hologram by laptop at desk

New York is tightening a screw that has corporations such as Google, Meta & Co. worried – while giving local users substantially stronger protection.

For several years, the US metropolis has been building a dense framework of laws, authorities and technical requirements. The aim is greater control over data, infrastructure and digital services, alongside less dependence on Big Tech. What may look like dry bureaucracy from the outside could become a model for other cities and permanently reshape the United States' digital landscape.

Why New York has become a frontline city in the data battle

New York depends on global corporations, financial institutions, start-ups and tourists. It is precisely here that the interests of Big Tech and politicians clash particularly fiercely. The city administration is no longer responding with symbolic measures alone; it is now introducing tough rules that directly affect platform business models.

Officially, there is no major programme called “digital sovereignty”. In practice, however, that is exactly what is taking shape: a local shield against overwhelmingly powerful IT corporations, many of which are headquartered on the US West Coast. The measures affect not only US businesses, but every provider trading in New York, including companies from Europe and Asia.

New York is forcing international corporations to respect its own data protection and security rules – or face a high cost.

At the heart of this offensive is a series of new state and city-level laws focused on three major areas: governance, data protection and critical infrastructure.

New York Privacy Act: tougher data protection for all users

The New York Privacy Act, which is currently progressing through the legislative process, is regarded as one of the most ambitious proposals anywhere in the United States. It applies to every company offering goods or services in New York, regardless of where it is based.

The law would impose several obligations likely to prove painful for many technology corporations:

  • Personal data may only be processed with prior explicit consent.
  • Companies must clearly explain which data they collect, how they use it and whether they sell it.
  • Users have the right to have their data corrected or erased completely.
  • The requirements also apply to companies with no physical presence in New York.

This brings New York somewhat closer to the European approach, without simply copying it. Companies will need to make specific changes to their products and processes if they want to remain active in the New York market.

Technology procurement with conditions: no free pass for risky hardware

Alongside its data protection plans, the city is restricting public authorities' procurement of sensitive technology. Local government bodies may only purchase certain computers, components and IT systems if they present no identifiable cybersecurity risks.

Put plainly, products regarded as insecure or open to manipulation will be excluded. New York is therefore targeting both public and private suppliers whose devices or software contain vulnerabilities, or are suspected of being usable as spying tools.

Manufacturers now face a new test. Anyone seeking public contracts in New York must be able to demonstrate security standards credibly.

New office for digital assets and blockchain

To prevent its strategy from getting lost amid the confusion of multiple authorities, New York has created a city office for digital assets and blockchain. This unit coordinates innovative projects intended to use blockchain technology in public administration and city operations.

The office has two functions:

  • Internal coordination of pilot projects, such as transparent procurement procedures, document tracking or municipal token solutions.
  • Setting guidelines to ensure new technologies are used responsibly and in line with data protection and security rules.

The city wants to avoid blockchain projects becoming mere public-relations stunts or drifting into regulatory grey areas.

Stronger online protection for children and young people

New York goes particularly far in protecting minors. Through the New York Child Data Protection Act (NYCDPA), which takes effect at the end of 2025, the state is tightening the rules for platforms aimed at younger users.

Among other provisions, the NYCDPA states:

  • No personalised advertising targeting users under 18.
  • A ban on manipulative design tactics (“Dark Patterns”) that push children towards more interaction.
  • Privacy settings for minors must be as restrictive as possible by default (“Privacy by default”).
  • Penalties of up to $5,000 per violation, enforced by the Attorney General.

New York is therefore placing obligations on social media apps, gaming platforms and streaming services. For corporations, this means developing separate product logic for young and adult users rather than putting everyone through the same algorithm.

Health data: an end to selling sensitive information

Another element is the New York Health Information Privacy Act. The law came into force in 2024, with stronger effects from 2025. It specifically concerns health information: highly sensitive data that has increasingly been digitised and, in some cases, monetised in recent years.

The Act introduces two central changes:

Aspect Rule
Right to erasure Individuals can demand that their health data be removed.
Sale Selling or sharing data for advertising purposes without explicit consent is prohibited.

New York is thereby challenging business models that combine health data into profiles and sell them to third parties. In an environment where fitness apps, insurers and wearables collect ever more information, this represents a noticeable intervention.

New DIGIT super-agency is intended to bring everything together

In the political programme “State of the State 2026”, Governor Kathy Hochul proposes creating a new authority: the Office of Digital Innovation, Governance, Integrity & Trust, or DIGIT for short.

This body would be responsible for:

  • Coordinating cybersecurity at state level.
  • Developing and monitoring data protection policies.
  • Setting technology-policy guidelines for authorities and public projects.

With DIGIT, New York is establishing an institution that operates like a combination of an IT ministry, data protection authority and cybersecurity centre. For corporations, that means fewer back doors and clearer accountability when something goes wrong.

Political change increases pressure on Big Tech

The foundations for this shift were laid under former Republican mayor Eric Adams. However, the momentum is likely to accelerate: Democrat Zohran Mamdani has led the city since 1 January 2026.

One signal immediately attracted attention in the technology sector: Mamdani appointed lawyer Lina Khan to lead the City Hall transition team. Khan has long been considered one of the most outspoken critics of major platform corporations and has built a reputation in the United States as a firm antitrust hardliner.

By bringing Lina Khan on board, New York is enlisting the very woman who has kept Big Tech under sustained legal fire for years.

The message to corporations is unambiguous: do not come with minimum standards, or politicians will step in – with further legislation if necessary.

Could other cities follow New York's example?

The key question is now whether New York will remain an exception or whether this marks the beginning of a broader trend. US states have traditionally had considerable scope to make their own data protection and consumer protection laws. California led the way with its own frameworks, and New York is now following with an approach more strongly shaped by the city itself.

Major cities including Chicago, Los Angeles and Boston are watching closely to see what happens in the East Coast market. If stricter data protection and security rules prove neither to ruin the local economy nor to stifle innovation, a wave of similar initiatives could follow.

What terms such as “Privacy by default” and “Dark Patterns” mean

Some terms from New York's laws are now appearing in debates around the world, yet remain unfamiliar to many users. “Privacy by default” means that a service's standard settings collect as little data as possible, rather than requiring users to work their way through menus to switch off tracking.

“Dark Patterns” refers to design tricks in apps or websites used by providers to steer users, for example through hidden reject buttons, confusing wording or visually highlighted buttons for the “wrong” choice. Such practices are no longer meant to be permitted for minors.

What this means in practice for users and companies

For people in New York, this development means more rights, but also greater responsibility. Anyone wishing to have their data erased or restrict tracking must actively request it. Users should therefore pay closer attention to the options platforms offer in the state and make use of them.

Companies face a balancing act. On one hand, they must comply with complex rules; on the other, they still need to grow and deliver innovation. Smaller providers in particular may initially find it difficult to implement every requirement technically and organisationally. At the same time, this creates a market for services that build data protection and security into their products from the outset.

Overall, New York demonstrates that a city does not have to accept being merely a pawn of global platforms. By framing and enforcing its own rules intelligently, it can shift the balance of power at least to some extent – and that is precisely what technology giants currently respect more than some major political stage.

Comments

No comments yet. Be the first to comment!

Leave a Comment