Data Privacy in New York: A Practical Guide to the SHIELD Act

Understand which businesses the SHIELD Act covers, what counts as private information, and how to build compliant security and breach response programs.

By Sneha Tete, Integrated MA, Certified Relationship Coach
Created on

New York’s Stop Hacks and Improve Electronic Data Security Act (SHIELD Act) is one of the most significant state-level data privacy laws in the United States. It modernizes New York’s breach notification regime and creates concrete expectations for how businesses safeguard the private information of New York residents.

This guide explains what the SHIELD Act is, who it covers, what counts as private information, and how to build a compliant security and breach response program. It is written for business leaders, compliance officers, and legal teams that need a clear, practical overview rather than dense statutory language.

1. What Is the SHIELD Act and Why Was It Enacted?

The SHIELD Act is a state law that amends New York’s 2005 Information Security Breach and Notification Act to address modern cyber risks, such as large-scale hacks, credential theft, and misuse of biometric data. It was signed into law in 2019, with breach notification changes effective in October 2019 and security safeguard requirements effective in March 2020.

In simple terms, the SHIELD Act does two main things:

  • Expands breach notification rules to cover more kinds of data and more types of incidents.
  • Requires “reasonable safeguards” – administrative, technical, and physical – to protect private information from unauthorized access, use, or disclosure.

New York’s legislature introduced these changes to respond to the increasing frequency and severity of data breaches, and to encourage organizations to proactively improve their security programs rather than simply react after an incident.

2. Who Must Comply with the SHIELD Act?

The SHIELD Act has a broad territorial reach. It applies to any person or business that owns or licenses computerized data containing the private information of a New York resident, whether or not the organization is physically located in New York.

2.1 Covered Entities

Under the Act, covered entities include:

  • New York-based companies of any size that hold private information about state residents.
  • Out-of-state or foreign companies that store, process, or have access to private information of New York residents.
  • Non-profit organizations if they own or license computerized data containing private information.
  • Individuals operating a business, including sole proprietors, if they handle computerized private information.

Importantly, many businesses fall under the Act even if data processing is outsourced to vendors or cloud providers. If you determine how and why private information of New York residents is processed, the SHIELD Act likely treats you as responsible for that data.

2.2 Vendors and Service Providers

The law also has implications for third-party vendors. If a business shares private information about New York residents with a service provider, it must ensure that the vendor implements reasonable security safeguards. This reflects the reality that many breaches originate in the supply chain rather than inside the organization itself.

  • Vendor contracts are expected to include security obligations.
  • Businesses should assess vendor security practices and monitor ongoing compliance.

3. What Counts as “Private Information” Under the Act?

A central feature of the SHIELD Act is its expanded definition of private information. Earlier New York law focused on traditional identifiers such as Social Security numbers and financial account numbers. The SHIELD Act broadens this to reflect new forms of sensitive data and attack vectors.

3.1 Core Identifiers

Private information still includes well-known high-risk data elements:

  • Social Security numbers.
  • Driver’s license or non-driver identification numbers.
  • Financial account, credit card, or debit card numbers combined with codes or passwords that allow access to the account.

3.2 Modern and Emerging Data Types

The SHIELD Act extends coverage to additional categories, such as:

  • Biometric information used to authenticate identity (for example, fingerprints, voice prints, retinal or iris scans).
  • Email addresses or usernames plus credentials (passwords, security questions and answers) that enable access to online accounts.

These expansions reflect the reality that account takeover and biometric spoofing can cause significant harm even when traditional identifiers are not compromised.

3.3 The Role of Context

Not all data is equally sensitive in every context. Under the Act, private information generally involves a data element that, together with a name or identifier, could allow identity theft, account compromise, or other harm if accessed without authorization. Organizations should consider how data is used and what risk it poses, not just whether it fits neatly into a single category.

4. What Is a “Breach” Under New York Law?

The SHIELD Act expands the definition of a breach. Under prior law, a breach often focused on acquisition of data. The SHIELD Act treats a breach as any event involving access to computerized data that compromises the confidentiality, security, or integrity of private information.

In practice, this means that even if you cannot prove that data was copied or exfiltrated, unauthorized access may still trigger breach obligations when private information is involved.

Examples of Incidents That May Constitute a Breach
Scenario Potential Breach Status
Hacker gains remote access to a database with customer credentials. Likely a breach due to unauthorized access to private information.
Employee views records without a business need to know. May be a breach if access compromises confidentiality or integrity.
Lost laptop containing unencrypted biometric data and account numbers. Typically treated as a breach because devices and data are exposed.

The broadened definition increases the number of events that require careful legal and technical analysis, and it underscores the value of logging, monitoring, and incident investigation capabilities.

5. Security Program Requirements: “Reasonable Safeguards”

Beyond notification, the SHIELD Act requires covered entities to develop, implement, and maintain reasonable safeguards to protect the security, confidentiality, and integrity of private information.

The law groups these safeguards into three categories:

  • Administrative safeguards (policies, governance, training).
  • Technical safeguards (systems, controls, monitoring).
  • Physical safeguards (facility and device protections).

5.1 Administrative Safeguards

Administrative measures address the organizational side of security. Common expectations include:

  • Conducting regular risk assessments that consider threats, vulnerabilities, and business impact.
  • Designating one or more individuals responsible for overseeing the security program.
  • Training employees on security policies, acceptable use, and incident reporting.
  • Selecting vendors carefully and embedding security requirements in contracts.
  • Reviewing and updating policies as business operations, technology, or risks change.

5.2 Technical Safeguards

Technical safeguards focus on systems and technology controls that protect private information.

  • Identifying risks in network and software design.
  • Securing data during processing, transmission, and storage.
  • Implementing access controls, authentication, and encryption where appropriate.
  • Preventing, detecting, and responding to attacks and system failures.
  • Monitoring and testing the effectiveness of security controls over time.

5.3 Physical Safeguards

Physical safeguards reduce the likelihood that private information can be accessed through loss, theft, or unauthorized physical intrusion.

  • Controlling access to offices, server rooms, and storage areas.
  • Implementing procedures for securing and eventually disposing of paper records and devices.
  • Protecting data during collection, transportation, and disposal.
  • Detecting and responding to physical intrusions and environmental risks.

The specific controls a business adopts can vary based on size, complexity, and sensitivity of data. However, regulators expect documented, risk-based programs rather than ad hoc practices.

6. Data Breach Notification Obligations

When a breach involving private information occurs, the SHIELD Act requires businesses to notify affected individuals and specified government agencies.

6.1 Timeline and Individual Notices

Organizations must provide notice to affected New York residents within a defined period after discovering a breach involving their private information. Timely communication allows individuals to take steps to protect themselves, such as changing passwords, monitoring accounts, or placing fraud alerts.

Notices generally need to be clear, conspicuous, and provide enough detail for individuals to understand what happened and what they can do in response. While exact content requirements can depend on circumstances, they typically cover:

  • The nature of the incident (for example, unauthorized access or ransomware).
  • The types of private information involved.
  • The estimated time period of exposure.
  • Actions the business has taken or plans to take.
  • Recommended steps for affected individuals to protect themselves.

6.2 Notices to State Agencies and Others

In addition to notifying individuals, organizations must report certain breaches to New York authorities. Under the SHIELD Act and related guidance, reports may be required to the:

  • New York State Attorney General.
  • New York State Police.
  • New York Department of State.
  • New York Department of Financial Services, for certain cases.

Large incidents impacting thousands of residents can also trigger obligations to notify consumer reporting agencies. The goal is to ensure regulatory oversight and enable broader risk mitigation measures when many individuals are affected.

7. Enforcement and Penalties

The SHIELD Act gives the New York Attorney General authority to enforce the law through investigations and civil actions. Courts can impose penalties and injunctive relief for both security failures and improper breach notification.

7.1 Penalties for Security Failures

Knowing or reckless violations of the Act’s security requirements can result in civil penalties of up to $5,000 per violation, with no statutory cap on the total amount. For organizations with large datasets or systemic issues, these penalties can quickly become substantial.

7.2 Penalties for Notification Failures

Penalties for failing to provide timely or adequate breach notification have also increased. Courts may impose:

  • A per-instance penalty for each failed notification (for example, up to $20 per affected individual), subject to an overall cap.
  • An aggregate cap on certain notification-related penalties, which can reach significant amounts.

In addition to monetary penalties, enforcement actions can lead to long-term reputational harm, additional oversight, and obligations to improve security under court order.

7.3 Statute of Limitations

Enforcement actions for failure to provide notice are subject to statutes of limitations. For example, some actions must be brought within a defined number of years after the Attorney General or residents are notified of the breach, and there are longer limits when a company conceals a breach. This underscores the importance of transparent and timely reporting.

8. Practical Steps to Comply with the SHIELD Act

While the SHIELD Act does not prescribe specific technologies, it expects a structured, documented approach to data protection. The following practices can help businesses build a compliance roadmap.

8.1 Map and Classify Data Related to New York Residents

Start with a clear view of where private information lives in your organization:

  • Identify systems, applications, and data repositories that hold information about New York residents.
  • Classify data based on sensitivity, including credentials, financial account details, and biometric identifiers.
  • Document data flows between your organization and vendors.

8.2 Conduct Risk Assessments

Perform regular risk assessments that consider threats, vulnerabilities, and business impact across administrative, technical, and physical controls.

  • Evaluate existing policies, procedures, and training.
  • Review infrastructure security, endpoint protection, and access controls.
  • Analyze vendor and supply chain risks.

8.3 Strengthen Incident Response and Notification Processes

Develop or refine an incident response plan that specifically addresses SHIELD Act obligations:

  • Define roles and responsibilities for legal, IT, communications, and leadership.
  • Establish criteria for determining whether an incident meets the breach definition.
  • Create templates for individual and regulatory notifications.
  • Implement logging and monitoring tools to detect and investigate suspicious activity.

8.4 Embed Security in Vendor Management

Since the Act extends accountability to vendors, organizations should integrate security expectations into the entire vendor lifecycle.

  • Include SHIELD Act–aligned security language in contracts.
  • Request evidence of vendor security controls (for example, audits, certifications, or policies).
  • Monitor vendors for changes, incidents, or non-compliance.

8.5 Document Your Security Program

Regulators place high value on documentation. Businesses should maintain written records of:

  • Policies and procedures for protecting private information.
  • Risk assessments and mitigation plans.
  • Training programs and attendance.
  • Incident investigations and breach notifications.

Good documentation can demonstrate diligence and help show that your organization took reasonable steps, even if an incident occurs.

9. Frequently Asked Questions About the SHIELD Act

9.1 Does the SHIELD Act apply to small businesses?

Yes. The Act applies to any person or business that owns or licenses computerized data containing private information of a New York resident, regardless of size. Smaller organizations may have flexibility in how they implement safeguards, but they are not exempt from the law.

9.2 What if my company is not located in New York?

Physical location is not determinative. If you process or control private information about New York residents, the SHIELD Act can apply even if your company is based in another state or country.

9.3 Do I need specific technologies to comply?

The SHIELD Act requires reasonable safeguards but does not mandate particular tools or vendors. Organizations should adopt controls that are appropriate to their size, complexity, and risk profile, following recognized security practices.

9.4 How is the SHIELD Act different from general data privacy laws?

While broader privacy frameworks focus on data collection, use, and individual rights, the SHIELD Act is primarily a security and breach notification law. It concentrates on protecting private information and managing incidents involving unauthorized access.

9.5 Can compliance with other regulations help with SHIELD Act requirements?

Yes. If your organization already complies with robust security and breach notification standards under other laws or frameworks, many controls may overlap with SHIELD Act expectations. However, you should still map your program specifically to New York requirements and adjust where needed.

References

  1. The New York SHIELD Act Explained — Pandectes. 2024-05-14. https://pandectes.io/blog/the-new-york-shield-act-explained/
  2. Understanding the New York SHIELD Act — Usercentrics. 2025-01-09. https://usercentrics.com/knowledge-hub/new-york-shield-act/
  3. New York SHIELD Act: The Definitive Guide to NY’s Privacy Law — Osano. 2023-06-06. https://www.osano.com/articles/new-york-shield-law
  4. The New York SHIELD Act — Spirion (archTIS). 2023-03-01. https://www.spirion.com/solutions/compliance/new-york-shield-act
  5. Stop Hacks and Improve Electronic Data Security Act (SHIELD Act) CLE Resources — New York State Unified Court System. 2023-02-01. https://www.nycourts.gov/LegacyPDFS/accesstojusticecommission/tc/2023/2A-Agents-of-SHIELD-CLE-Resources.pdf
  6. NY State Senate Bill 2019-S5575B — New York State Senate. 2019-07-25. https://www.nysenate.gov/legislation/bills/2019/S5575
Sneha Tete
Sneha TeteBeauty & Lifestyle Writer
Sneha is a relationships and lifestyle writer with a strong foundation in applied linguistics and certified training in relationship coaching. She brings over five years of writing experience to waytolegal,  crafting thoughtful, research-driven content that empowers readers to build healthier relationships, boost emotional well-being, and embrace holistic living.

Read full bio of Sneha Tete