New York SHIELD Act - Compliance Guide
· About New York SHIELD Act
Key Takeaways
- The New York SHIELD Act applies to any person or business that owns or licenses computerized private information of a New York resident, and it requires “reasonable safeguards” for that data and prompt breach notification.
- The Attorney General enforces the statute, and courts can impose civil penalties of up to $5,000 per violation for safeguard failures and up to $20 per instance for notice failures, capped at $250,000.
- The law’s security-safeguard requirements took effect on 21 March 2020, while the breach-notification amendments took effect on 23 October 2019.
- A 2024 amendment changed the breach-notification deadline to 30 days and expanded private information to include medical information and health insurance information, effective 21 December 2024.
- The law has no private right of action; enforcement is by the New York Attorney General and, for certain notification failures, by civil penalty in court.
- Businesses that meet the SHIELD Act definition of a covered entity should map their controls to ISO 27001, NIST CSF 2.0, and, where AI or automated processing is in scope, ISO 42001 as a governance overlay, not as a substitute for statutory compliance.
What It Is
The Stop Hacks and Improve Electronic Data Security Act (SHIELD Act) amended New York’s breach-notification statute in General Business Law Article 39-F, sections 899-aa and 899-bb, to require reasonable data security protections and updated breach notice rules for covered personal information. The New York Attorney General’s SHIELD Act guidance states that the law was signed on 25 July 2019, with the notification changes effective 23 October 2019 and the security-safeguard requirements effective 21 March 2020.[3][9]
The Attorney General is the principal enforcement body for the statute.[3] A later amendment adopted in 2024 took effect on 21 December 2024, tightening the notification deadline to 30 days and expanding the definition of private information to include medical and health insurance data.[11][13]
There is no known 2025–2026 delay to the SHIELD Act itself in the sources reviewed; the 2025–2026 materials found relate to New York’s separate “Shield Law” for reproductive and gender-affirming care, which is unrelated to the data-security SHIELD Act.[2][7][12]
Who Must Comply
The statute applies broadly to any person or business that owns or licenses computerized private information of a New York resident, regardless of where the organization is located, if it stores that information in electronic form. Secondary summaries consistently describe the reach as extraterritorial because the trigger is the presence of covered New York resident information, not New York incorporation or headquarters.[9][15]
The law’s breach-notification provisions also apply to entities that conduct business in New York and maintain computerized data that includes private information, with notice obligations triggered when unauthorized acquisition of private information occurs.[3][9] The 2024 amendment added a special notice layer for certain DFS-regulated entities, requiring notice to the Department of Financial Services, the Attorney General, the Department of State, and the State Police for qualifying breaches.[13]
The statute contains limited exceptions built into the definition of breach and the notice scheme, including situations where the information is encrypted and there is no reason to believe the encryption key was compromised.[3] Publicly available guidance does not indicate a broad sectoral exemption from the security-safeguard requirement; rather, the law is intentionally general and applies across industries.[3][9]
Core Requirements
- Maintain reasonable safeguards. Covered businesses must implement, maintain, and monitor “reasonable safeguards” to protect the security, confidentiality, and integrity of private information, including administrative, technical, and physical controls.[3][9]
- Design a written security program. The safeguards program should include designated personnel, risk assessment, training, vendor oversight, and incident response planning consistent with the statute’s examples of reasonable protections.[3]
- Limit access and disposition. Businesses must restrict access to private information to people who need it for legitimate business purposes and must properly dispose of data when it is no longer needed.[3][9]
- Notify affected persons promptly. If a breach of private information occurs, notice must be sent without unreasonable delay and, under the 2024 amendment, no later than 30 days after discovery, unless law enforcement requests delay.[11][13]
- Provide required regulator notice. Certain breaches require notice to New York State officials, and the 2024 amendment added DFS-specific notice obligations for regulated entities.[13]
- Use the expanded data definition. Since 21 December 2024, “private information” includes medical information and health insurance information in addition to prior identifiers such as Social Security numbers and account credentials.[11][13]
Deadlines and Penalties
| milestone | date | what applies | |---|---:|---| | SHIELD Act signed | 25 July 2019 | New York enacts amended breach-notification and safeguard framework.[3] | | Breach-notice amendments effective | 23 October 2019 | Updated notification rules apply, including response timing and notice content changes.[3][9] | | Security-safeguard requirements effective | 21 March 2020 | Covered businesses must maintain reasonable administrative, technical, and physical safeguards.[3][9] | | 2024 amendment effective | 21 December 2024 | 30-day notice deadline, expanded “private information,” and additional DFS-related notice duties.[11][13] |
The statute authorizes civil penalties of up to $5,000 per violation for failure to maintain reasonable safeguards, and up to $20 per instance for failure to provide timely notice, with notice penalties capped at $250,000.[14][15] The Attorney General may also seek injunctive relief and restitution, and there is no private right of action under the statute.[14][15]
How to Comply
- Map data and scope. Identify every system, vendor, and process that stores computerized private information of New York residents, including the 2024-expanded categories of medical and health insurance data.[11][13]
- Run a risk assessment. Use a documented risk assessment to prioritize controls, and refresh it at least annually and after material changes; this aligns well with ISO 27001 risk-based control selection and NIST CSF 2.0 Identify/Protect functions.
- Adopt a written security program. Build policies for access control, encryption, secure disposal, endpoint protection, logging, and incident response, with management approval and assignment of responsibility; this matches the governance expectations in ISO 27001 and the operating model in NIST CSF 2.0.
- Harden third-party oversight. Require vendor due diligence, contractual security terms, and breach-notification commitments for processors and service providers, because the statute’s safeguard concept includes oversight of service providers.[3]
- Train staff and test response. Run periodic training, phishing awareness, tabletop exercises, and breach drills so the organization can meet the 30-day notice clock and preserve evidence for regulators.
- Set a legal hold and notice workflow. Create decision trees for whether an incident is a notifiable breach, which regulators must be notified, and when law-enforcement delay applies; automate deadlines where possible.
- Use ISO 42001 where AI is involved. If AI systems touch covered personal data, use ISO 42001 to control governance, risk, and lifecycle management, but keep SHIELD Act obligations as the legal baseline because the statute is technology-neutral.
- Document everything. Keep assessment records, policy versions, incident timelines, and remediation evidence so you can prove the “reasonable safeguards” program if the Attorney General investigates.[3][14]
Related Regulations
- New York breach-notification law generally overlaps with the SHIELD Act because SHIELD is the amendment that modernized the state’s existing breach-response rules and notice thresholds.[3]
- NYDFS Cybersecurity Regulation (23 NYCRR 500) can conflict operationally with SHIELD for financial institutions because both require security programs and incident handling, but DFS-regulated entities must satisfy both regimes independently.
- California Consumer Privacy Act / CPRA overlaps on security and breach exposure, but California adds consumer rights and private litigation pathways that SHIELD does not provide.
- Massachusetts 201 CMR 17.00 overlaps on written security-program expectations and can be used as a control benchmark, though it is a separate state regime.
- Federal HIPAA may overlap when protected health information is involved, but SHIELD’s expanded private-information definition is broader than HIPAA’s covered-entity scope and can apply outside healthcare.
FAQ
Does the New York SHIELD Act apply to companies outside New York?
Yes. The statute is commonly read to apply to businesses outside New York if they own or license computerized private information of New York residents.[9][15] Headquarters location is not the main trigger; the covered data is.
What counts as “private information” under the SHIELD Act?
The definition includes traditional identifiers such as Social Security numbers and financial account data, and, after the 2024 amendment, medical information and health insurance information too.[11][13] The exact trigger is whether the data is computerized private information of a New York resident.
Is there a 30-day breach-notification deadline now?
Yes. The 2024 amendment made the outside deadline 30 days from discovery, unless a law-enforcement agency requests delay.[11][13] Earlier SHIELD-era guidance still appears online, so organizations should not rely on pre-2024 summaries alone.
Does the SHIELD Act have a private right of action?
No. Enforcement is by the New York Attorney General, with civil penalties available through the statute’s enforcement framework.[14][15] That does not eliminate litigation risk from other laws or common-law claims after a breach.
Do encrypted incidents still have to be reported?
Not always. New York’s breach framework includes an exception where the data was encrypted and there is no reason to believe the encryption key was compromised.[3] That exception is fact-specific, so organizations should document the encryption state and key-management status before deciding not to notify.
Does SHIELD replace NYDFS cybersecurity rules?
No. The SHIELD Act is a general state data-security and breach-notification law, while NYDFS cybersecurity rules apply to covered financial entities and impose separate obligations.[3][13] Some organizations must comply with both.
Sources
- New York Attorney General — SHIELD Act
- New York Assembly bill record for S5575 / SHIELD Act
- BPS Law — Three Key Changes to Breach Notification Law
- Spirion — New York SHIELD Act overview
- BreachRx — New York SHIELD Act Incident Response Guidelines
- New York Courts PDF on SHIELD Act penalties
- BSK article on New York’s amended Shield Law for health care
Put it into practice
- Generate the policy: NY SHIELD Act policy generator (generatepolicy.com)
- Buy the policy pack: State Privacy Law Checklist (cyberpolicy.shop)
- Build it yourself: 2026 US Privacy Program Workbook (ciso.diy)