Law / United States / New York

Stop Hacks and Improve Electronic Data Security (SHIELD) Act, data security program duty

N.Y. Gen. Bus. Law section 899-bb (Article 39-F, added by L. 2019, ch. 117 (S5575-B/A5635-B), section 4)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 21 March 2020.

A security baseline statutes rule binding private bodies.

As of 12 September 2026.

What it requires

  • This binds any person or business that owns, licenses, or maintains computerized data including the private information of a New York resident; a business already a compliant regulated entity under Gramm-Leach-Bliley Act Title V regulations, Health Insurance Portability and Accountability Act (HIPAA) and HITECH regulations, or 23 NYCRR Part 500 (the New York Department of Financial Services cybersecurity regulation for a financial-services licensee) is deemed to comply.
  • Absent that safe harbor, develop, implement, and maintain a data security program with reasonable administrative safeguards (a designated coordinator, a risk assessment, employee training, vetted service-provider contracts, and periodic adjustment), reasonable technical safeguards (assessing network and software design risk, detecting and responding to attacks, and testing controls), and reasonable physical safeguards (securing storage and disposal and limiting access during and after collection).
  • A small business, fewer than 50 employees, under $3,000,000 in gross annual revenue in each of the last three fiscal years, or under $5,000,000 in year-end total assets, may scale its program's administrative, technical, and physical safeguards to its own size, complexity, and the sensitivity of the personal information it collects.
  • There is no private right of action; only the Attorney General may enforce this section, as a deemed violation of General Business Law 349, seeking injunctive relief and a civil penalty of up to $5,000 per violation under General Business Law 350-d.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Penalty structure

Civil penalty under General Business Law 350-d for a violation deemed unlawful under General Business Law 349; the statute names no aggregate cap. The SHIELD Act's separate breach-notification duty (899-aa) carries its own $20-per-instance-of-failed-notification penalty capped at $250,000, filed under this jurisdiction's privacy row.

Rule
Per violation only
As of
12 September 2026
Currency
USD
Per violation unit
Violation
Per violation amount
5,000

Who enforces it

Enforcement body

General Business Law 899-bb names no dedicated regulator of its own; a violation is deemed a violation of General Business Law 349, and only the Attorney General may bring an action to enjoin it and to obtain a civil penalty under General Business Law 350-d.

What it reaches

Obligation class

Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Any person or business that owns or licenses computerized data including the private information of a New York resident must develop, implement, and maintain reasonable safeguards to protect the security, confidentiality, and integrity of that private information.

A business satisfies this duty either by being a compliant regulated entity under Gramm-Leach-Bliley Act Title V regulations, Health Insurance Portability and Accountability Act (HIPAA) and HITECH regulations, or 23 NYCRR Part 500, or by implementing a data security program with reasonable administrative, technical, and physical safeguards scaled to the size of the business.

Failure to comply is deemed a violation of General Business Law 349, enforceable only by the Attorney General for injunctive relief; the section creates no private right of action. General Business Law 350-d sets the civil penalty for that violation at up to $5,000 per violation.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product

Read the law

Official statute text, New York Consolidated Laws, General Business Law Article 39-F

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app