Regulations › US states › New York

SHIELD Act

New York SHIELD Act

In force security breach notification
WhenIn effect since 21 March 2020
Who enforces itNew York Attorney General
Who it applies toAny business holding private information of New York residents, wherever it is located.

Broadened New York's breach notification law and requires reasonable administrative, technical and physical safeguards.

The law in brief

The SHIELD Act (Stop Hacks and Improve Electronic Data Security) did two things. It broadened New York's breach notification law, so more kinds of information and more kinds of incidents trigger notice, and it created a duty for any business holding New York residents' private information to keep reasonable safeguards.

It reaches businesses anywhere, not only those operating in New York, if they hold private information about New York residents.

Who it applies to

  • Any person or business that owns or licenses computerized private information of a New York resident, wherever located.
  • Private information includes the traditional identifiers (Social Security number, driver's license number, account or card number with its code) and adds biometric information, an account or card number that can be used without a code, and a username or email address with the password or security question needed to access the account.
  • A breach includes unauthorized access, not only acquisition.
  • Small businesses (below set employee, revenue or asset levels) must still keep safeguards, scaled to their size and the sensitivity of the data.

What it requires

Reasonable safeguards

Develop, implement and maintain reasonable administrative, technical and physical safeguards to protect the security, confidentiality and integrity of private information, such as a designated coordinator, risk assessments, employee training, vendor selection and oversight, and secure disposal.

Notify affected residents within 30 days

Notify affected New York residents of a breach in the most expedient time possible and within 30 days of discovery, subject to law enforcement needs.

Notify the state

Notify the Attorney General, the Department of State and the Division of State Police of the timing, content and distribution of notices, and the Department of Financial Services where it regulates you. Notify the consumer reporting agencies if more than 5,000 residents are notified.

Credit for existing compliance

A business in compliance with GLBA, HIPAA or NYDFS Part 500 is deemed compliant with the safeguards requirement.

People's rights

Affected New York residents must be notified of a breach. There is no private right of action; the Attorney General enforces.

Enforcement and penalties

The Attorney General can seek injunctions and civil penalties. For failures to notify, penalties are set per failed notification up to a statutory cap; for failures to keep reasonable safeguards, the Attorney General can seek civil penalties per violation under 899-bb.

What's changing

Amended in December 2024. Notice to affected residents must now be made within 30 days of discovery, and covered financial entities must also notify the Department of Financial Services. Check the current text for the list of state agencies to notify.

What to do first

  1. Find where you hold New York residents' private information, including account credentials.
  2. Document your safeguards against the administrative, technical and physical examples in 899-bb.
  3. Designate an employee to coordinate the security program.
  4. Add the 30-day limit and the New York regulator notices to your breach playbook.
  5. If you are regulated under GLBA, HIPAA or NYDFS Part 500, keep evidence of that compliance; it counts as compliance with the safeguards requirement.

Checked against the official text on 28 September 2026. Quotations are the operative words of the law, linked to the article they come from; the official text is the authority. This brief is written by the Association for practitioners and is not legal advice.

Recent developments

  • 17 Sep 2026 Regulatory Guidance announced Moderate 57 US-NY New York Attorney General's Office

    NY Attorney General urges workers to file whistleblower complaints on unsafe AI development

    The guidance signals heightened enforcement focus on AI safety and data security in New York, prompting insider reporting. New York Attorney General Letitia James issued an alert encouraging employees with knowledge of unsafe or illegal AI development to submit confidential whistleblower complaints. The alert references the Responsible AI Safety and Education (RAISE) Act, which will take effect on January 1, 2027, requiring large AI developers to disclose safety measures and report incidents. The AG also cites authority under the SHIELD Act and other laws to pursue violations.

    Effective: 1 January 2027.

    Source: New York Attorney General press releases. SHIELD Act in the regulations library.

Sources