Skip to content
Privacy Regulations

New York SHIELD Act

Overview

The New York Stop Hacks and Improve Electronic Data Security (SHIELD) Act is a state-level data security law that strengthens consumer data protection and breach notification requirements for businesses handling data of New York residents. Enacted in 2019, the law became fully enforceable on March 21, 2020.

Unlike broad consumer privacy laws like California’s CPRA or Colorado’s CPA, the SHIELD Act primarily focuses on data security obligations and breach prevention measures.

Who Must Comply?

The SHIELD Act applies to any business that collects, processes, or stores the private data of New York residents, regardless of whether they operate in New York.

πŸ“Œ No revenue or data processing thresholds – Unlike most state privacy laws, the SHIELD Act applies to all companies handling New York residents’ data, including small businesses.

Exemptions:

The law does not apply to:
🚫 Government agencies
🚫 Entities compliant with industry-specific security standards (e.g., HIPAA or GLBA)

Key Consumer Protections Under SHIELD

βœ” Expanded Definition of Private Information – The law defines private information broadly, including:

  • Social Security numbers
  • Driver’s license numbers
  • Credit and debit card numbers
  • Biometric data (fingerprints, retina scans, voiceprints)
  • Email addresses with passwords/security questions

βœ” Mandatory Breach Notification – Companies must notify affected individuals and state authorities if private information is exposed in a data breach.

βœ” Reasonable Data Security Program – Businesses must implement data security safeguards, including:

  • Administrative safeguards (employee training, risk assessments)
  • Technical safeguards (firewalls, encryption, access controls)
  • Physical safeguards (secure disposal of records, restricted access to sensitive data)

Business Compliance Requirements

βœ” Breach Notification Rules – If a company suffers a data breach, it must:
πŸ“Œ Notify New York consumers whose data was exposed
πŸ“Œ Inform the New York Attorney General, the State Police, and the Department of State
πŸ“Œ Notify credit reporting agencies if 5,000+ residents are affected

βœ” No Consumer Opt-Out Rights – Unlike CPRA or GDPR, the SHIELD Act does not provide consumers with opt-out rights or data access rights.

βœ” No Universal Opt-Out Requirement – Businesses do not need to recognize Global Privacy Control (GPC) signals.

Real-World Enforcement Cases

The New York Attorney General enforces the SHIELD Act, with penalties of up to $250,000 per violation.

πŸ“Œ Recent Enforcement Actions:

  • EyeMed Vision Care (2022) – Fined $4.5 million for failing to secure email accounts that exposed customer data.
  • T-Mobile (2022) – Investigated after a data breach affecting 53 million U.S. residents, including millions of New Yorkers.

πŸ“Œ Comparison with Other State Privacy Laws
The New York SHIELD Act differs from traditional consumer privacy laws:
βœ… Stronger Data Security Rules – Requires reasonable safeguards for businesses handling private information.
βœ… Strict Breach Notification Obligations – Companies must notify affected individuals and state authorities.
βœ… No Consumer Opt-Out Rights – Unlike California (CPRA) and Colorado (CPA), consumers cannot opt out of data collection.

Future of SHIELD Act Regulation

πŸ“Œ Increased enforcement actions against companies failing to implement strong security.
πŸ“Œ Potential amendments to include broader consumer privacy rights.
πŸ“Œ Possible alignment with a federal data security law if enacted.

The SHIELD Act is one of the strongest U.S. data security laws, focusing on preventing breaches and protecting consumer data rather than consumer opt-out rights.

NEW GEN AI

Get answers to even the most complex questions about your data and explore the complexities of your data landscape using Generative AI chat.