The NY SHIELD Act requires any business holding a New Yorker's private information to protect it with reasonable administrative, technical, and physical safeguards, and to report a breach fast. It applies no matter where your business sits, penalties run to 5,000 dollars per violation, and only the Attorney General enforces it.
To comply with the NY SHIELD Act, a business must protect the private information of every New York resident it holds with reasonable administrative, technical, and physical safeguards, and it must notify people quickly when that data is breached. The law does not hand you a rigid checklist. It sets a standard, reasonable security, and expects you to build a documented program that meets it. That flexibility is a trap for the unprepared, because "reasonable" is judged after an incident, by the New York Attorney General, against what a careful business would have done.
The SHIELD Act, formally the Stop Hacks and Improve Electronic Data Security Act, reshaped New York data protection in two stages. Its breach notification changes took effect on October 23, 2019, and its data security requirements took effect on March 21, 2020, according to an analysis by law firm Jackson Lewis. This guide explains who the Act covers, what "private information" means, the safeguards you have to put in place, how breach notification works, the penalties for getting it wrong, and a practical path to compliance.
Any person or business that owns or licenses computerized private information of a New York resident has to comply, whether or not the business operates in New York. The trigger is the residency of the data subject, not the location of the company. A firm in Texas, Ohio, or anywhere else falls under the Act the moment it holds a single New Yorker's Social Security number, financial account, or account credentials, as the IAPP notes in its overview. For most companies with customers, patients, or employees in the state, that means the Act already applies.
The reach is deliberately broad. Before the SHIELD Act, New York's data law only bit when a business "conducted business" in the state. The Act removed that limit, so geography no longer shields anyone who handles New Yorkers' data. If you run a medical practice, a professional services firm, an online store, or a franchise that touches New York residents, plan to comply.
Yes, small businesses must comply, but their safeguards only have to be appropriate to their size, complexity, and the sensitivity of the data they hold. The Act defines a small business as one with fewer than 50 employees, less than 3 million dollars in gross annual revenue in each of the last three fiscal years, or less than 5 million dollars in year-end total assets, per Jackson Lewis. A qualifying small business does not need enterprise-grade controls, but it still needs a real, documented program that fits its risk.
The important nuance is where the flexibility stops. Small businesses get room to scale their security program, but they get no relief at all on breach notification. If a small firm is breached, it owes the same notices, on the same timeline, as a large one. So the "small business" label lowers the bar on prevention, not on what you must do after an incident.
Private information under the SHIELD Act is a New York resident's name or identifier combined with a sensitive data element, and the Act widened that list. Covered elements include a Social Security number, a driver's license or non-driver ID number, a financial account or payment card number, and biometric data such as a fingerprint or iris image, as the IAPP summarizes. The Act also treats an account number or card number as private on its own when it could be used to access an account without any additional code.
The most consequential addition is a standalone category with no name attached. A username or email address paired with a password, or with a security question and answer that would grant access to an online account, is now private information in its own right. That change pulls ordinary login credentials into scope, which is exactly the data attackers steal most often through phishing. If your systems store customer or employee logins, you hold private information the Act protects.
To meet the SHIELD Act's security standard, you implement a data security program with reasonable safeguards in three categories: administrative, technical, and physical. The Act lists example measures under each, and a business is deemed compliant when its program reasonably addresses them, according to the IAPP. Treat the list below as the backbone of your program and document what you do for each.
Administrative safeguards are the governance layer. They include designating one or more employees to coordinate the security program, identifying reasonably foreseeable internal and external risks, assessing whether existing safeguards control those risks, training staff in your security practices, and selecting service providers capable of maintaining appropriate safeguards. The provider point matters, because a vendor's weak security becomes your exposure.
Technical safeguards are the controls in your systems. They include assessing risks in network and software design, assessing risks in information processing, transmission, and storage, detecting and responding to attacks or system failures, and regularly testing and monitoring the effectiveness of key controls. In plain terms, this is where multi-factor authentication, encryption, patching, logging, and endpoint protection live.
Physical safeguards govern the real-world side of data. They include assessing risks in how information is stored and disposed of, protecting against unauthorized access during collection, transport, and destruction, and disposing of private information within a reasonable time after it is no longer needed, by erasing electronic media so the data cannot be read or reconstructed. Retaining data you no longer need is a liability the Act specifically wants you to reduce.
None of these safeguards is exotic, and most overlap directly with a modern managed security program. A business that runs multi-factor authentication, encrypts sensitive data, patches promptly, monitors for intrusions, trains its people, and disposes of old records securely is doing the substance of what the Act asks. Layered cybersecurity services put those controls in place and keep them current, which is the difference between claiming a program on paper and being able to prove one.
If private information is breached, notify affected New York residents in the most expedient time possible and without unreasonable delay. New York's summary from Davis Wright Tremaine notes that notice should be given without unreasonable delay and describes the parties a business must alert. Beyond the affected individuals, you also notify the New York Attorney General, the Department of State Division of Consumer Protection, and the State Police, and if more than 5,000 residents are notified you must alert the national consumer reporting agencies as well.
The SHIELD Act also broadened what counts as a breach. A breach now includes unauthorized access to private information, not only its acquisition, as Davis Wright Tremaine explains. Under the old rule, a business could argue no one had actually taken the data. Now, if an attacker merely viewed or reached it in a way that compromised its security, confidentiality, or integrity, the notification clock can start. That lower threshold means more incidents qualify, so your incident response plan should assume access alone can be reportable.
That volume is the backdrop for why the Act exists and why regulators take it seriously. Breach notices to the state number in the thousands each year, and a single incident can affect millions of residents. Compliance is not a box you tick once; it is the reason a breach becomes a controlled disclosure instead of a headline and an investigation.
The SHIELD Act carries real financial teeth, and only the New York Attorney General can enforce it. For failing to maintain reasonable safeguards, a court can impose civil penalties of up to 5,000 dollars per violation, according to the IAPP. For a knowing or reckless failure to notify people of a breach, penalties can reach the greater of 5,000 dollars or up to 20 dollars per instance of failed notification, capped at 250,000 dollars, per Jackson Lewis. There is no private right of action, so lawsuits come from the state, not from individuals suing under the Act.
The Attorney General has moved from guidance to enforcement. In a settlement announced in December 2025, a New York orthopedics practice agreed to pay 500,000 dollars after a 2023 ransomware attack exposed the data of 656,086 individuals, and regulators found the practice had failed to implement reasonable safeguards such as multi-factor authentication for remote access, data encryption, and monitoring to detect unauthorized access, according to HIPAA Journal. The attackers used compromised login credentials to reach unencrypted records, the exact gap multi-factor authentication is meant to close.
The lesson from that case is that the safeguards the Act names are the same ones enforcement actions look for. When regulators investigate, they check whether you had multi-factor authentication, encryption, monitoring, and a documented program before the breach, not scrambled together after it. A settlement, plus the cost of the incident itself, dwarfs the price of the controls that would have prevented it.
The penalty is only part of the exposure, because the breach itself carries a far larger bill. IBM's 2025 Cost of a Data Breach Report put the global average cost of a breach at 4.44 million dollars, with the United States average reaching an all-time high of 10.22 million dollars, the highest of any country, per IBM. Most small and mid-sized businesses never absorb the full enterprise figure, but they also have far less cushion, and downtime, recovery, lost customers, and legal costs stack on top of any state penalty.
The threats behind those costs are the ones the Act's safeguards target. Verizon's 2026 Data Breach Investigations Report found that the human element was involved in 62% of breaches and that small organizations made up 96% of ransomware victims, according to Verizon. Reasonable safeguards are not bureaucratic overhead. They are the specific controls that stop the credential theft, phishing, and unpatched-system attacks that current data shows actually cause breaches.
To comply with the SHIELD Act, build a documented security program that maps to the three safeguard categories and covers breach response, then keep it current. The steps below turn the standard into a working plan you can put in place this quarter and defend later.
Most small and mid-sized businesses cannot staff this internally, which is where a managed provider earns its place. Compeint builds and runs the reasonable-safeguards program the SHIELD Act expects, from multi-factor authentication and encryption to monitoring and a tested incident response plan, so compliance is something you can demonstrate rather than hope for. The Act is a standard, and a standard is far easier to meet when the controls behind it run every day.
If your business already complies with certain federal or New York data security frameworks, the SHIELD Act deems its reasonable-safeguards obligation met without a second program. The Act calls these businesses "compliant regulated entities" and names the qualifying frameworks: the Gramm-Leach-Bliley Act (GLBA), HIPAA together with the HITECH Act, and the New York Department of Financial Services cybersecurity regulation, 23 NYCRR Part 500, plus any other data security rule of the federal or New York government, as Jackson Lewis explains. A HIPAA-covered medical practice or a GLBA-regulated financial firm that actually meets its own rules is treated as meeting the SHIELD Act's data security standard.
Two limits keep this from being a free pass. You must genuinely be in compliance with the applicable provisions of that framework, not merely subject to it, and the safe harbor covers only the reasonable-security requirement. Your breach notification duties to affected residents and to the state agencies still apply. For a business with no such framework, the answer is a written information security program built to the three safeguard categories.
New York tightened its breach rules after the SHIELD Act, so the law in force today is stricter than the 2020 version. A December 2024 amendment set a firm deadline of 30 days from discovery of a breach to notify affected New York residents, replacing the open-ended "without unreasonable delay" standard, and it added the New York Department of Financial Services to the Attorney General, Department of State, and State Police as agencies you must notify, according to Covington's Inside Privacy analysis.
A further change took effect in March 2025. It expanded the definition of "private information" to include medical information, such as a person's medical history, diagnosis, or treatment, and health insurance information, such as a policy or subscriber number, per Recording Law. That pulls healthcare data held by businesses that are not HIPAA-covered entities squarely into the SHIELD Act. If you hold health data on New Yorkers, treat it as private information now.
The SHIELD Act is a data security and breach notification law, not a consumer privacy-rights law like the California Consumer Privacy Act (CCPA) or the GDPR. It does not give New York residents a right to access, correct, or delete their data, and it carries no private right of action, so enforcement comes only from the Attorney General rather than from individuals, as Spirion notes in its comparison. Its penalties are smaller too, at up to 5,000 dollars per violation for security failures against the CCPA's 2,500 to 7,500 dollars per violation and the GDPR's up to 4 percent of global annual revenue.
The practical takeaway is that these laws do not substitute for one another. Meeting the SHIELD Act protects New Yorkers' data and satisfies New York, but it does not make you CCPA-ready or GDPR-ready, because those regimes add consumer rights and consent duties the SHIELD Act never imposes. A company serving customers in several states builds the reasonable-security program once, then layers the additional rights requirements where they apply.
The SHIELD Act makes your vendors' security your responsibility, so third-party risk is squarely in scope. Its administrative safeguards require you to select service providers capable of maintaining appropriate safeguards and to require those safeguards by contract, which means a provider's weak security becomes your exposure and, potentially, your violation. Vet vendors before you hand over data, write safeguard obligations into the agreement, and keep an inventory of every provider that touches New York residents' private information.
The Act also reaches businesses that maintain but do not own the data. If you hold private information on another company's behalf and it is breached, you must notify that owner or licensee, now within the same 30-day window that applies to notifying residents. That duty runs both ways in a vendor relationship, so contracts should spell out who notifies whom, and how fast, before an incident forces the question.
The NY SHIELD Act, short for the Stop Hacks and Improve Electronic Data Security Act, is a New York law that requires any business holding the private information of a New York resident to protect it with reasonable administrative, technical, and physical safeguards and to notify people quickly if that data is breached. Its breach notification changes took effect October 23, 2019, and its data security requirements took effect March 21, 2020.
Any person or business that owns or licenses computerized private information of a New York resident must comply, regardless of whether the business is located or operates in New York. Because the trigger is New York residents' data, a company anywhere in the country is covered the moment it holds a New Yorker's Social Security number, financial account, or login credentials.
Yes. Small businesses must comply, but their safeguards only need to be appropriate to their size and complexity. The Act defines a small business as one with fewer than 50 employees, less than 3 million dollars in gross annual revenue in each of the last three fiscal years, or less than 5 million dollars in year-end total assets. Small businesses get flexibility on the security program, but no flexibility on breach notification.
A court can impose civil penalties of up to 5,000 dollars per violation for failing to maintain reasonable safeguards. For a knowing or reckless failure to notify people of a breach, penalties can reach the greater of 5,000 dollars or up to 20 dollars per instance of failed notification, capped at 250,000 dollars. Only the New York Attorney General enforces the Act; there is no private right of action.
Private information includes a name combined with a Social Security number, a driver's license or non-driver ID number, a financial account or payment card number, or biometric data. The SHIELD Act also added a standalone category: a username or email address together with a password or security question and answer that would permit access to an online account, even without a name attached.
Notify affected New York residents in the most expedient time possible and without unreasonable delay. You must also notify the New York Attorney General, the Department of State Division of Consumer Protection, and the State Police, and if more than 5,000 residents are notified you must alert the consumer reporting agencies. A breach now includes unauthorized access to private information, not only its acquisition.
Partly. A business that is subject to and in compliance with HIPAA and HITECH, the Gramm-Leach-Bliley Act, or the New York Department of Financial Services cybersecurity regulation (23 NYCRR Part 500) is treated as a compliant regulated entity and meets the SHIELD Act's reasonable-safeguards requirement. You must actually be compliant with that framework, and you still owe the SHIELD Act's breach notification duties to affected residents and to the state agencies.
Within 30 days of discovering the breach. A December 2024 amendment replaced the open-ended without-unreasonable-delay standard with a firm 30-day deadline to notify affected New York residents, except where law enforcement asks you to delay. The same amendment added the New York Department of Financial Services to the Attorney General, Department of State, and State Police as agencies that must be notified.
Yes, as of March 2025. An amendment expanded private information to include medical information, such as a person's medical history, diagnosis, or treatment, and health insurance information, such as a policy or subscriber number. That pulls healthcare data held by businesses that are not HIPAA-covered entities into the SHIELD Act's scope.
The SHIELD Act is a data security and breach notification law, while the CCPA is a consumer privacy-rights law. The SHIELD Act does not give New York residents the right to access or delete their data and has no private right of action, so only the Attorney General enforces it. Its penalties are also smaller, up to 5,000 dollars per violation, compared with the CCPA's 2,500 to 7,500 dollars per violation.
Compliance you can prove
We review your safeguards against what the Act requires, flag the gaps regulators look for, and build the program that closes them, with no obligation.
Book Your Assessment