Law / United States /
New York
Stop Hacks and Improve Electronic Data Security (SHIELD) Act, data security program duty
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 21 March 2020.
A security baseline statutes rule binding private bodies.
As of 12 September 2026.
What it requires
- This binds any person or business that owns, licenses, or maintains computerized data including the private information of a New York resident; a business already a compliant regulated entity under Gramm-Leach-Bliley Act Title V regulations, Health Insurance Portability and Accountability Act (HIPAA) and HITECH regulations, or 23 NYCRR Part 500 (the New York Department of Financial Services cybersecurity regulation for a financial-services licensee) is deemed to comply.
- Absent that safe harbor, develop, implement, and maintain a data security program with reasonable administrative safeguards (a designated coordinator, a risk assessment, employee training, vetted service-provider contracts, and periodic adjustment), reasonable technical safeguards (assessing network and software design risk, detecting and responding to attacks, and testing controls), and reasonable physical safeguards (securing storage and disposal and limiting access during and after collection).
- A small business, fewer than 50 employees, under $3,000,000 in gross annual revenue in each of the last three fiscal years, or under $5,000,000 in year-end total assets, may scale its program's administrative, technical, and physical safeguards to its own size, complexity, and the sensitivity of the personal information it collects.
- There is no private right of action; only the Attorney General may enforce this section, as a deemed violation of General Business Law 349, seeking injunctive relief and a civil penalty of up to $5,000 per violation under General Business Law 350-d.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Penalty structure
Civil penalty under General Business Law 350-d for a violation deemed unlawful under General Business Law 349; the statute names no aggregate cap. The SHIELD Act's separate breach-notification duty (899-aa) carries its own $20-per-instance-of-failed-notification penalty capped at $250,000, filed under this jurisdiction's privacy row.
- Rule
- Per violation only
- As of
- 12 September 2026
- Currency
- USD
- Per violation unit
- Violation
- Per violation amount
- 5,000
Who enforces it
Enforcement body
General Business Law 899-bb names no dedicated regulator of its own; a violation is deemed a violation of General Business Law 349, and only the Attorney General may bring an action to enjoin it and to obtain a civil penalty under General Business Law 350-d.
What it reaches
Obligation class
Security
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Any person or business that owns or licenses computerized data including the private information of a New York resident must develop, implement, and maintain reasonable safeguards to protect the security, confidentiality, and integrity of that private information.
A business satisfies this duty either by being a compliant regulated entity under Gramm-Leach-Bliley Act Title V regulations, Health Insurance Portability and Accountability Act (HIPAA) and HITECH regulations, or 23 NYCRR Part 500, or by implementing a data security program with reasonable administrative, technical, and physical safeguards scaled to the size of the business.
Failure to comply is deemed a violation of General Business Law 349, enforceable only by the Attorney General for injunctive relief; the section creates no private right of action. General Business Law 350-d sets the civil penalty for that violation at up to $5,000 per violation.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometricsserves_minorsoperates_social_platformships_mobile_appdistributes_software_product
Read the law
Official statute text, New York Consolidated Laws, General Business Law Article 39-F
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.