New York regulates privacy through security. Without a comprehensive consumer-rights statute, the SHIELD Act does the state’s heavy lifting: an extraterritorial safeguards mandate with no size threshold, one of the broadest breach definitions in the country, and an Attorney General who converts breach filings into settlements that read like security-engineering specifications. Companies mapping their state obligations by consumer-rights laws alone miss that New York already regulates them.
| Law | SHIELD Act, N.Y. Gen. Bus. Law 899-aa, 899-bb |
|---|---|
| Effective | Breach rules Oct 2019; safeguards March 2020 |
| Penalties | $5,000/violation (safeguards); up to $250,000 (notification) |
| Regulator | New York AG |
| Statute | GBS 899-bb |
Building the SHIELD program
Assign and document. A named security coordinator, a written program, and an annual risk assessment are the artifacts the AG asks for first. Deemed compliance via GLBA, HIPAA, or NYDFS Part 500 covers regulated entities; affiliates and non-regulated lines still need their own program.
Engineer to the settlement baseline. The AG’s consent orders converge on: MFA for remote and privileged access, encryption of private information at rest and in transit, centralized logging with monitoring, penetration testing, credential-stuffing defenses (rate limiting, compromised-password screening), and incident-response plans with honest notification drafting. Building to this list is cheaper than negotiating it under investigation.
Manage vendors as required elements. Selection diligence, contractual safeguards, and oversight are statutory components, align them with your CCPA service-provider terms and the state assessment framework so one vendor program serves all regimes.
Rehearse notification. Access-based triggers mean more incidents are notifiable than under acquisition-only statutes; the multi-agency filing set (AG, DOS, State Police) and the anti-minimization lesson from SHEIN belong in your incident-response runbook alongside the other states’ clocks.
Track the New York stack. NYDFS Part 500 for financial services (with its annual certification and third-party rules), the AG’s UDAP authority for dark patterns and misrepresentations, and the perennial New York Privacy Act proposals that would add consumer rights, watch each session.
Exposed trackers, forms, and third-party flows are the reconnaissance layer attackers and regulators both read; audit yours with a free scan.