Insights
Compliance

The NY SHIELD Act and your firm’s IT

New York’s data security statute is shorter and more specific than its reputation suggests. It names the safeguards it expects, it treats encrypted data differently from unencrypted data, and it applies a lighter standard to smaller organizations. All three points change what a firm should actually build.

Share

What the statute asks for

The operative provision is General Business Law section 899-bb. It says that any person or business owning or licensing computerized data that includes private information of a New York resident shall “develop, implement and maintain reasonable safeguards to protect the security, confidentiality and integrity of the private information including, but not limited to, disposal of data.” [1] New York General Business Law Section 899-BB: Data security protections View source ↗

Two features of that sentence do most of the work. The standard is reasonable safeguards, not a fixed control list, so the answer depends on the organization. And disposal is called out specifically, which is the obligation firms most often have no plan for.

The statute then gives two ways to satisfy it. A firm already subject to and in compliance with another data security regime counts as a “compliant regulated entity” — the statute names the Gramm-Leach-Bliley Act Title V regulations, the HIPAA and HITECH implementing regulations, and New York’s own 23 NYCRR part 500. [1] New York General Business Law Section 899-BB: Data security protections View source ↗ Otherwise, a firm implements a data security program containing the safeguards the statute enumerates.

Encryption changes what is in scope

This is the part worth reading closely, because it is the one with the largest practical consequence and it sits in the definitions rather than in the security provision.

“Private information” is defined in section 899-aa as personal information combined with one of several listed data elements — Social Security number, driver’s license number, financial account credentials, biometric data, medical information, health insurance information — and the definition applies “when either the data element or the combination of personal information plus the data element is not encrypted, or is encrypted with an encryption key that has also been accessed or acquired.” [2] New York General Business Law Section 899-AA: Notification; person without valid authorization has acquired private information View source ↗

What that means in practice

Properly encrypted data, where the key was not also taken, falls outside the definition. Encryption at rest is therefore not one control among many for this statute. It is the control that determines how much of a firm’s data the statute is concerned with at all, and it is the reason we treat full-disk and mailbox encryption as a baseline rather than an upgrade.

The qualifier matters as much as the rule. An encrypted laptop whose password is on a note in the bag is not protected by this language, and neither is a backup encrypted with a key stored beside it. The carve-out rewards key management, not the purchase of encryption.

The three categories, and what sits in each

Where a firm implements its own program, the statute lists reasonable administrative, technical and physical safeguards. [1] New York General Business Law Section 899-BB: Data security protections View source ↗ The list is worth reading as written, because much of it is not about technology.

Administrative

Designating one or more employees to coordinate the security program; identifying reasonably foreseeable internal and external risks; assessing whether the safeguards in place control those risks; training and managing staff in the program; selecting service providers capable of maintaining appropriate safeguards and requiring those safeguards by contract; and adjusting the program as the business changes. [1] New York General Business Law Section 899-BB: Data security protections View source ↗

Technical

Assessing risks in network and software design; assessing risks in information processing, transmission and storage; detecting, preventing and responding to attacks or system failures; and regularly testing and monitoring the effectiveness of key controls, systems and procedures. [1] New York General Business Law Section 899-BB: Data security protections View source ↗

Physical

Assessing risks of information storage and disposal; detecting, preventing and responding to intrusions; protecting against unauthorized access during and after collection, transportation and disposal; and disposing of private information within a reasonable time once it is no longer needed, by erasing media so the information cannot be read or reconstructed. [1] New York General Business Law Section 899-BB: Data security protections View source ↗

The contract clause is the one firms miss

Selecting service providers capable of maintaining appropriate safeguards and requiring those safeguards by contract is an enumerated administrative safeguard. [1] New York General Business Law Section 899-BB: Data security protections View source ↗ A firm can run excellent internal controls and still have nothing in writing from the vendors holding its data. We would rather raise that during onboarding than have a firm discover it while answering a client questionnaire.

Most firms fall under the smaller-organization standard

The statute defines a “small business” as any person or business with fewer than fifty employees, or less than three million dollars in gross annual revenue in each of the last three fiscal years, or less than five million dollars in year-end total assets. [1] New York General Business Law Section 899-BB: Data security protections View source ↗ Those branches are disjunctive in the text, so meeting any one of them is enough.

An organization in that category satisfies the program requirement where its safeguards are “appropriate for the size and complexity of the small business, the nature and scope of the small business’s activities, and the sensitivity of the personal information the small business collects.” [1] New York General Business Law Section 899-BB: Data security protections View source ↗

For a six-attorney firm that is a meaningful difference. The expectation is proportionality rather than an enterprise control set. It is also not a pass: sensitivity of information is one of the three factors, and a firm holding medical records in a personal injury practice is handling more sensitive data than its headcount alone would suggest.

How it is enforced

A failure to comply is deemed a violation of General Business Law section 349, and the Attorney General may bring an action to enjoin the violation and obtain civil penalties under section 350-d. [1] New York General Business Law Section 899-BB: Data security protections View source ↗ The statute also states that nothing in the section creates a private right of action. [1] New York General Business Law Section 899-BB: Data security protections View source ↗

So the exposure here runs through the Attorney General rather than through suits by affected individuals under this section. That is a narrower channel than the one firms usually picture, and it is a reason to read the statute rather than rely on an impression of it.

What we build against it

The technical and physical lists map onto work that is ordinary for us: encryption at rest on every endpoint and mailbox with keys held centrally, endpoint detection and response for the detect-and-respond language, documented access control and review for the risk assessment items, logging with a stated retention period so monitoring can be evidenced rather than asserted, and a retention and disposal policy that someone has actually decided on instead of letting data accumulate.

The administrative list is where we are a participant rather than the owner. A firm has to name the person coordinating the program, and the vendor contract language is the firm’s to execute. We can tell you what we maintain and put it in writing, which is the part of that safeguard we control.

What this page is not

We describe what the statute says and what we implement. Whether this statute applies to your firm, and whether any particular set of controls satisfies it, are legal questions for your own counsel. We do not make those determinations, and a provider telling you a configuration makes you compliant is telling you something it is not in a position to know.

References and Standards

  1. [1] New York State Senate, Section 899-BB: Data security protections, NYS Open Legislation. Accessed October 6, 2026. https://www.nysenate.gov/legislation/laws/GBS/899-BB
  2. [2] New York State Senate, Section 899-AA: Notification; person without valid authorization has acquired private information, NYS Open Legislation. Accessed October 6, 2026. https://www.nysenate.gov/legislation/laws/GBS/899-AA

Want this reviewed against your own setup?

Thirty minutes on what your firm holds, where it sits, and which of these safeguards are already in place. Email [email protected] or book a consultation.

Schedule a Consultation