Compliance

NY SHIELD Act: What Businesses Must Do to Comply

In brief

The NY SHIELD Act requires any business holding a New Yorker's private information to protect it with reasonable administrative, technical, and physical safeguards, and to report a breach fast. It applies no matter where your business sits, penalties run to 5,000 dollars per violation, and only the Attorney General enforces it.

To comply with the NY SHIELD Act, a business must protect the private information of every New York resident it holds with reasonable administrative, technical, and physical safeguards, and it must notify people quickly when that data is breached. The law does not hand you a rigid checklist. It sets a standard, reasonable security, and expects you to build a documented program that meets it. That flexibility is a trap for the unprepared, because "reasonable" is judged after an incident, by the New York Attorney General, against what a careful business would have done.

The SHIELD Act, formally the Stop Hacks and Improve Electronic Data Security Act, reshaped New York data protection in two stages. Its breach notification changes took effect on October 23, 2019, and its data security requirements took effect on March 21, 2020, according to an analysis by law firm Jackson Lewis. This guide explains who the Act covers, what "private information" means, the safeguards you have to put in place, how breach notification works, the penalties for getting it wrong, and a practical path to compliance.

Who has to comply with the SHIELD Act?

Any person or business that owns or licenses computerized private information of a New York resident has to comply, whether or not the business operates in New York. The trigger is the residency of the data subject, not the location of the company. A firm in Texas, Ohio, or anywhere else falls under the Act the moment it holds a single New Yorker's Social Security number, financial account, or account credentials, as the IAPP notes in its overview. For most companies with customers, patients, or employees in the state, that means the Act already applies.

The reach is deliberately broad. Before the SHIELD Act, New York's data law only bit when a business "conducted business" in the state. The Act removed that limit, so geography no longer shields anyone who handles New Yorkers' data. If you run a medical practice, a professional services firm, an online store, or a franchise that touches New York residents, plan to comply.

Does the SHIELD Act apply to small businesses?

Yes, small businesses must comply, but their safeguards only have to be appropriate to their size, complexity, and the sensitivity of the data they hold. The Act defines a small business as one with fewer than 50 employees, less than 3 million dollars in gross annual revenue in each of the last three fiscal years, or less than 5 million dollars in year-end total assets, per Jackson Lewis. A qualifying small business does not need enterprise-grade controls, but it still needs a real, documented program that fits its risk.

The important nuance is where the flexibility stops. Small businesses get room to scale their security program, but they get no relief at all on breach notification. If a small firm is breached, it owes the same notices, on the same timeline, as a large one. So the "small business" label lowers the bar on prevention, not on what you must do after an incident.

What counts as private information under the SHIELD Act

Private information under the SHIELD Act is a New York resident's name or identifier combined with a sensitive data element, and the Act widened that list. Covered elements include a Social Security number, a driver's license or non-driver ID number, a financial account or payment card number, and biometric data such as a fingerprint or iris image, as the IAPP summarizes. The Act also treats an account number or card number as private on its own when it could be used to access an account without any additional code.

The most consequential addition is a standalone category with no name attached. A username or email address paired with a password, or with a security question and answer that would grant access to an online account, is now private information in its own right. That change pulls ordinary login credentials into scope, which is exactly the data attackers steal most often through phishing. If your systems store customer or employee logins, you hold private information the Act protects.

The reasonable safeguards you must implement

To meet the SHIELD Act's security standard, you implement a data security program with reasonable safeguards in three categories: administrative, technical, and physical. The Act lists example measures under each, and a business is deemed compliant when its program reasonably addresses them, according to the IAPP. Treat the list below as the backbone of your program and document what you do for each.

Administrative safeguards are the governance layer. They include designating one or more employees to coordinate the security program, identifying reasonably foreseeable internal and external risks, assessing whether existing safeguards control those risks, training staff in your security practices, and selecting service providers capable of maintaining appropriate safeguards. The provider point matters, because a vendor's weak security becomes your exposure.

Technical safeguards are the controls in your systems. They include assessing risks in network and software design, assessing risks in information processing, transmission, and storage, detecting and responding to attacks or system failures, and regularly testing and monitoring the effectiveness of key controls. In plain terms, this is where multi-factor authentication, encryption, patching, logging, and endpoint protection live.

Physical safeguards govern the real-world side of data. They include assessing risks in how information is stored and disposed of, protecting against unauthorized access during collection, transport, and destruction, and disposing of private information within a reasonable time after it is no longer needed, by erasing electronic media so the data cannot be read or reconstructed. Retaining data you no longer need is a liability the Act specifically wants you to reduce.

None of these safeguards is exotic, and most overlap directly with a modern managed security program. A business that runs multi-factor authentication, encrypts sensitive data, patches promptly, monitors for intrusions, trains its people, and disposes of old records securely is doing the substance of what the Act asks. Layered cybersecurity services put those controls in place and keep them current, which is the difference between claiming a program on paper and being able to prove one.

Breach notification: what to do when data is exposed

If private information is breached, notify affected New York residents in the most expedient time possible and without unreasonable delay. New York's summary from Davis Wright Tremaine notes that notice should be given without unreasonable delay and describes the parties a business must alert. Beyond the affected individuals, you also notify the New York Attorney General, the Department of State Division of Consumer Protection, and the State Police, and if more than 5,000 residents are notified you must alert the national consumer reporting agencies as well.

The SHIELD Act also broadened what counts as a breach. A breach now includes unauthorized access to private information, not only its acquisition, as Davis Wright Tremaine explains. Under the old rule, a business could argue no one had actually taken the data. Now, if an attacker merely viewed or reached it in a way that compromised its security, confidentiality, or integrity, the notification clock can start. That lower threshold means more incidents qualify, so your incident response plan should assume access alone can be reportable.

1,876 Data breach notices New York's Attorney General received in 2022. Breaches that exposed Social Security numbers alone put the personal data of more than 3.2 million New Yorkers at risk. NY Office of the Attorney General, 2023

That volume is the backdrop for why the Act exists and why regulators take it seriously. Breach notices to the state number in the thousands each year, and a single incident can affect millions of residents. Compliance is not a box you tick once; it is the reason a breach becomes a controlled disclosure instead of a headline and an investigation.

Penalties for non-compliance

The SHIELD Act carries real financial teeth, and only the New York Attorney General can enforce it. For failing to maintain reasonable safeguards, a court can impose civil penalties of up to 5,000 dollars per violation, according to the IAPP. For a knowing or reckless failure to notify people of a breach, penalties can reach the greater of 5,000 dollars or up to 20 dollars per instance of failed notification, capped at 250,000 dollars, per Jackson Lewis. There is no private right of action, so lawsuits come from the state, not from individuals suing under the Act.

$5,000 Maximum civil penalty per violation for failing to maintain reasonable safeguards. Breach notification failures can reach up to 20 dollars per instance, capped at 250,000 dollars. Jackson Lewis, SHIELD Act FAQs

The Attorney General has moved from guidance to enforcement. In a settlement announced in December 2025, a New York orthopedics practice agreed to pay 500,000 dollars after a 2023 ransomware attack exposed the data of 656,086 individuals, and regulators found the practice had failed to implement reasonable safeguards such as multi-factor authentication for remote access, data encryption, and monitoring to detect unauthorized access, according to HIPAA Journal. The attackers used compromised login credentials to reach unencrypted records, the exact gap multi-factor authentication is meant to close.

$500K Settlement a New York medical practice paid in 2025 after a 2023 ransomware breach exposed 656,086 people's data. The Attorney General cited missing multi-factor authentication, encryption, and monitoring. HIPAA Journal, 2025

The lesson from that case is that the safeguards the Act names are the same ones enforcement actions look for. When regulators investigate, they check whether you had multi-factor authentication, encryption, monitoring, and a documented program before the breach, not scrambled together after it. A settlement, plus the cost of the incident itself, dwarfs the price of the controls that would have prevented it.

What a breach costs beyond the fine

The penalty is only part of the exposure, because the breach itself carries a far larger bill. IBM's 2025 Cost of a Data Breach Report put the global average cost of a breach at 4.44 million dollars, with the United States average reaching an all-time high of 10.22 million dollars, the highest of any country, per IBM. Most small and mid-sized businesses never absorb the full enterprise figure, but they also have far less cushion, and downtime, recovery, lost customers, and legal costs stack on top of any state penalty.

$10.22M Average cost of a data breach in the United States in 2025, an all-time high and the most expensive of any country. The global average was 4.44 million dollars. IBM Cost of a Data Breach Report, 2025

The threats behind those costs are the ones the Act's safeguards target. Verizon's 2026 Data Breach Investigations Report found that the human element was involved in 62% of breaches and that small organizations made up 96% of ransomware victims, according to Verizon. Reasonable safeguards are not bureaucratic overhead. They are the specific controls that stop the credential theft, phishing, and unpatched-system attacks that current data shows actually cause breaches.

How to comply with the SHIELD Act: a practical path

To comply with the SHIELD Act, build a documented security program that maps to the three safeguard categories and covers breach response, then keep it current. The steps below turn the standard into a working plan you can put in place this quarter and defend later.

  • Inventory the private information you hold, including where New York residents' data lives, who can reach it, and which third-party vendors touch it.
  • Assign a security coordinator and run a written risk assessment that names your foreseeable internal and external risks.
  • Turn on multi-factor authentication everywhere, starting with email, remote access, and any system holding private information.
  • Encrypt sensitive data at rest and in transit, and patch operating systems, applications, and edge devices promptly.
  • Deploy monitoring and logging so unauthorized access is detected and can be investigated, not discovered months later.
  • Dispose of data you no longer need by securely erasing media so private information cannot be read or reconstructed.
  • Write and rehearse an incident response plan that meets the notification duties to residents, the Attorney General, the Department of State, and the State Police.
  • Vet your vendors, requiring that any provider handling your data maintains appropriate safeguards, and document it in your contracts.

Most small and mid-sized businesses cannot staff this internally, which is where a managed provider earns its place. Compeint builds and runs the reasonable-safeguards program the SHIELD Act expects, from multi-factor authentication and encryption to monitoring and a tested incident response plan, so compliance is something you can demonstrate rather than hope for. The Act is a standard, and a standard is far easier to meet when the controls behind it run every day.

Related reading

FAQ

What is the NY SHIELD Act?

The NY SHIELD Act, short for the Stop Hacks and Improve Electronic Data Security Act, is a New York law that requires any business holding the private information of a New York resident to protect it with reasonable administrative, technical, and physical safeguards and to notify people quickly if that data is breached. Its breach notification changes took effect October 23, 2019, and its data security requirements took effect March 21, 2020.

Who has to comply with the SHIELD Act?

Any person or business that owns or licenses computerized private information of a New York resident must comply, regardless of whether the business is located or operates in New York. Because the trigger is New York residents' data, a company anywhere in the country is covered the moment it holds a New Yorker's Social Security number, financial account, or login credentials.

Does the SHIELD Act apply to small businesses?

Yes. Small businesses must comply, but their safeguards only need to be appropriate to their size and complexity. The Act defines a small business as one with fewer than 50 employees, less than 3 million dollars in gross annual revenue in each of the last three fiscal years, or less than 5 million dollars in year-end total assets. Small businesses get flexibility on the security program, but no flexibility on breach notification.

What are the penalties for violating the SHIELD Act?

A court can impose civil penalties of up to 5,000 dollars per violation for failing to maintain reasonable safeguards. For a knowing or reckless failure to notify people of a breach, penalties can reach the greater of 5,000 dollars or up to 20 dollars per instance of failed notification, capped at 250,000 dollars. Only the New York Attorney General enforces the Act; there is no private right of action.

What counts as private information under the SHIELD Act?

Private information includes a name combined with a Social Security number, a driver's license or non-driver ID number, a financial account or payment card number, or biometric data. The SHIELD Act also added a standalone category: a username or email address together with a password or security question and answer that would permit access to an online account, even without a name attached.

How do I report a data breach under the SHIELD Act?

Notify affected New York residents in the most expedient time possible and without unreasonable delay. You must also notify the New York Attorney General, the Department of State Division of Consumer Protection, and the State Police, and if more than 5,000 residents are notified you must alert the consumer reporting agencies. A breach now includes unauthorized access to private information, not only its acquisition.

Compliance you can prove

Meet the SHIELD Act's reasonable-security standard

We review your safeguards against what the Act requires, flag the gaps regulators look for, and build the program that closes them, with no obligation.

Book Your Assessment