US Privacy Law New York, USA

New York SHIELD Act: Data Security Requirements

The SHIELD Act's reasonable-safeguards program, expanded breach notification, AG enforcement with real settlements, and how it fits New York's wider privacy stack.

Regulation

Stop Hacks and Improve Electronic Data Security Act (2019), N.Y. Gen. Bus. Law 899-aa, 899-bb

Max Penalty

Up to $5,000 per violation for safeguards failures; breach-notification failures up to $20 per failed notification (capped at $250,000)

Enforcing Authority

New York Attorney General

Official Source

ag.ny.gov

Executive Summary

  • The SHIELD Act (fully effective March 2020) is a data-security law, not a consumer-rights law: any person or business holding private information of New York residents must implement a reasonable-safeguards program, regardless of where the business operates.
  • It expanded breach notification: 'breach' includes unauthorized access (not just acquisition), and 'private information' covers biometrics, email-plus-credentials, and account numbers usable without a code.
  • The safeguards requirement is programmatic: designated coordinators, risk assessments, employee training, vendor oversight, and disposal, small businesses scale it to their size.
  • The AG enforces actively and settles publicly: Zoetop/SHEIN ($1.9M, 2022), Wegmans ($400,000, 2022), Marymount Manhattan College ($3.5M investment order), a $700,000 sports-retailer settlement (2023), and repeated credential-stuffing actions.
  • New York has no comprehensive consumer privacy law yet, so SHIELD plus NYDFS Part 500 (for financial services) plus the AG's UDAP authority are the operative New York privacy regime.

New York regulates privacy through security. Without a comprehensive consumer-rights statute, the SHIELD Act does the state’s heavy lifting: an extraterritorial safeguards mandate with no size threshold, one of the broadest breach definitions in the country, and an Attorney General who converts breach filings into settlements that read like security-engineering specifications. Companies mapping their state obligations by consumer-rights laws alone miss that New York already regulates them.

LawSHIELD Act, N.Y. Gen. Bus. Law 899-aa, 899-bb
EffectiveBreach rules Oct 2019; safeguards March 2020
Penalties$5,000/violation (safeguards); up to $250,000 (notification)
RegulatorNew York AG
StatuteGBS 899-bb

Building the SHIELD program

Assign and document. A named security coordinator, a written program, and an annual risk assessment are the artifacts the AG asks for first. Deemed compliance via GLBA, HIPAA, or NYDFS Part 500 covers regulated entities; affiliates and non-regulated lines still need their own program.

Engineer to the settlement baseline. The AG’s consent orders converge on: MFA for remote and privileged access, encryption of private information at rest and in transit, centralized logging with monitoring, penetration testing, credential-stuffing defenses (rate limiting, compromised-password screening), and incident-response plans with honest notification drafting. Building to this list is cheaper than negotiating it under investigation.

Manage vendors as required elements. Selection diligence, contractual safeguards, and oversight are statutory components, align them with your CCPA service-provider terms and the state assessment framework so one vendor program serves all regimes.

Rehearse notification. Access-based triggers mean more incidents are notifiable than under acquisition-only statutes; the multi-agency filing set (AG, DOS, State Police) and the anti-minimization lesson from SHEIN belong in your incident-response runbook alongside the other states’ clocks.

Track the New York stack. NYDFS Part 500 for financial services (with its annual certification and third-party rules), the AG’s UDAP authority for dark patterns and misrepresentations, and the perennial New York Privacy Act proposals that would add consumer rights, watch each session.

Exposed trackers, forms, and third-party flows are the reconnaissance layer attackers and regulators both read; audit yours with a free scan.

Frequently Asked Questions

Who does the SHIELD Act apply to?

Any person or business, anywhere, that owns or licenses computerized private information of a New York resident. There is no revenue or volume threshold and no requirement of doing business in New York. Small businesses (under 50 employees, under $3M revenue, or under $5M assets) may scale safeguards to their size and complexity but are not exempt. If your customer table contains New Yorkers, the act applies.

What counts as 'private information'?

Personal information combined with: SSN; driver's license or ID number; account, credit, or debit card number (with any code needed for access, or without one if usable alone); biometric information; or a username/email plus password or security Q&A. This is broader than most breach statutes, notably including biometrics and bare credentials, so credential-stuffing incidents and biometric leaks are notifiable New York breaches.

What does a 'reasonable safeguards' program require?

899-bb enumerates elements across three domains. Administrative: a designated security coordinator, risk assessments, workforce training, vendor selection and contractual safeguards. Technical: network and software risk assessment, access controls, monitoring, and testing. Physical: storage, disposal, and intrusion protections. Compliance with GLBA, HIPAA, or NYDFS Part 500 deems you compliant; everyone else needs a documented program mapped to these elements.

What triggers breach notification, and how fast?

Unauthorized access to or acquisition of private information: access alone qualifies (New York looks at indications the data was viewed, not just exfiltrated). Notify affected residents in the most expedient time possible without unreasonable delay, plus the AG, the Department of State, and State Police; 5,000+ residents adds consumer-reporting-agency notice. The AG's cases repeatedly punish slow or minimizing notifications, SHEIN's $1.9M settlement centered on downplaying a 39-million-account breach.

What does SHIELD enforcement actually look like?

AG investigations triggered by breach filings, credential-stuffing reports, or media coverage, resolved by settlements imposing penalties and multi-year security programs: Zoetop/SHEIN $1.9M (misrepresented breach scope), Wegmans $400,000 (exposed cloud storage), a college's $3.5M security-investment order, and a 2023 sports retailer paying $700,000 over credential stuffing. Settlements consistently require MFA, logging, encryption, penetration testing, and vendor management, the de facto New York security baseline.

Regulatory Crosswalk

NYDFS 23 NYCRR 500Massachusetts 201 CMR 17FTC Safeguards Rule

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.