Law / United States / New York

Stop Hacks and Improve Electronic Data Security (SHIELD) Act, breach notification duty

N.Y. Gen. Bus. Law § 899-aa

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 23 October 2019.

A breach notification rule binding private bodies.

As of 27 August 2026.

What it requires

  • Disclose a breach of the security of your system to each affected New York resident in the most expedient time possible and without unreasonable delay, and no later than 30 days after discovering the breach.
  • Notify the New York Attorney General, the Department of State, and the Division of State Police of the breach, and notify each nationwide consumer reporting agency if you are notifying more than 5,000 New York residents at once.
  • Do not assume New York law clears a faceprint or voiceprint you extract from a recording to authenticate or ascertain identity. SHIELD's biometric-information trigger carries no recording-derived exclusion, so an extracted identifier plausibly falls within it if a later breach exposes it, though this reading is untested in New York case law or Attorney General guidance.
  • Do not treat a New York City ordinance as displaced by this section's preemption clause. SHIELD's preemption is scoped to breach notification; the separate NYC Biometric Identifier Information Law regulates capture consent and retention, a different subject.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Any person or business that owns or licenses computerized data including private information must disclose a breach of the security of the system to each affected New York resident in the most expedient time possible and without unreasonable delay, and no later than 30 days after the breach is discovered.

Notice to the Attorney General, the Department of State, and the Division of State Police is required for every disclosure, and notice to nationwide consumer reporting agencies is required when more than 5,000 New York residents are notified at once.

'Private information' is personal information combined with an unencrypted data element such as a Social Security number, driver's license number, financial account number, biometric information, or medical or health insurance information; biometric information here carries no exclusion for data derived from a photograph, video, or audio recording, unlike a comprehensive-regime state's biometric definition, though this plain-text reading has not been tested in New York case law or Attorney General guidance.

This section's local-law preemption clause is scoped to breach notification and does not displace New York City's separate biometric-privacy ordinance, which regulates capture consent and retention, a different subject.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • processes_biometrics
  • processes_voice

Read the law

official New York statute text, N.Y. General Business Law, New York State Senate

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app