Skip to content

Brought to you by

Dentons logo

Dentons Data

Your trusted advisor for all things digital.

open menu close menu

Dentons Data

  • Home
  • About Us

New York Department of Financial Services Cybersecurity Regulation Requirements Applicable to Third Parties Now in Effect

By Kirsten Thompson
March 18, 2019
  • Cybersecurity
Share on Facebook Share on Twitter Share via email Share on LinkedIn

With March comes Spring – and the full force and effect of the Cybersecurity Regulation of the New York Department of Financial Services (“NYDFS”). This includes requirements relating to Third Party Service Providers (e.g., vendors, suppliers, agents – the term Third Party Service Providers is defined in the Regulations). Canadian companies and financial service providers may be caught by these and other provisions of the Regulations and should review the applicability of these recently-in-force provisions.

The Regulation was first promulgated on March 1, 2017 and required banks, insurance companies, and other financial institutions and individuals who are, or should be, licensed with NYDFS (called Covered Entities in the Regulation) to comply with what some characterized as fairly onerous cybersecurity and data security requirements. The final transitional period for the Regulation ended on March 1, 2019 – meaning all affected entities will need to be in compliance.

The Regulation had been criticized as being overly-prescriptive and unduly burdensome, resulting in the  NYDFS giving entities covered by the Regulation a two-year transitional period to address the requirements of the Third Party Service Provider provision.

With the Regulation now fully in force, Covered Entities must have written policies and procedures to address the risks associated with Third Party Service Providers’ access to Nonpublic Information or Information Systems. Among the items required are the establishment of minimum cybersecurity practices for Third Party Service Providers and the development of due diligence processes to assess these practices.

Share on Facebook Share on Twitter Share via email Share on LinkedIn
Subscribe and stay updated
Receive our latest blog posts by email.
Stay in Touch
Kirsten Thompson

About Kirsten Thompson

Kirsten Thompson is a partner and the national lead of Dentons’ Privacy and Cybersecurity group. She has both an advisory and advocacy practice, and provides privacy, data security and data management advice to clients in a wide variety of industries.

All posts Full bio

RELATED POSTS

  • Cybersecurity
  • Privacy

IPC trilogy considering encryption-based, non-extractive cyber attacks

By Jaime Cardy
  • Cybersecurity
  • Data
  • Guidance
  • Privacy
  • Technology

Considerations for de-identifying personal health information: Guidance from Ontario’s Information and Privacy Commissioner

By Kirsten Thompson and Sasha Coutu
  • Access
  • Blockchain
  • Cybersecurity
  • Data
  • FinTech
  • Privacy

The privacy paradox in blockchain: best practices for data management in crypto

By Sasha Coutu

About Dentons

Redefining possibilities. Together, everywhere. For more information visit dentons.com

Grow, Protect, Operate, Finance. Dentons, the law firm of the future is here. Copyright 2023 Dentons. Dentons is a global legal practice providing client services worldwide through its member firms and affiliates. Please see dentons.com for Legal notices.

Categories

Subscribe and stay updated

Receive our latest blog posts by email.

Stay in Touch

Dentons logo in black and white

© 2025 Dentons

  • Legal notices
  • Privacy policy
  • Terms of use
  • Cookies on this site