Privacy & Security Compliance SHIELD Act

Compliance Framework

NY SHIELD Act Compliance

The New York Stop Hacks and Improve Electronic Data Security Act imposes data security obligations on any organisation that holds private information about New York residents — regardless of where the organisation is located. AIQA helps you implement the reasonable safeguards SHIELD requires and prepare for AG enforcement.

What It Is

New York's Comprehensive Data Security Law

Signed into law in July 2019 and effective March 2020, the SHIELD Act significantly expanded New York's data breach notification requirements and — critically — added affirmative data security programme obligations. Unlike earlier breach notification laws, SHIELD requires covered businesses to implement a reasonable data security programme, not merely to notify after a breach.

The law has extraterritorial reach: any person or business, anywhere in the world, that owns or licenses private information of New York residents must comply. Enforcement authority rests with the New York Attorney General, who can seek civil penalties of up to $5,000 per violation and $250,000 in aggregate.

What Counts as Private Information

Private information under SHIELD includes Social Security numbers, driver's license numbers, account and card numbers combined with security codes, biometric information, username/password combinations, and — new under SHIELD — HIPAA-protected health information and health insurance account numbers.

Quick Facts

  • Effective March 21, 2020
  • Enforced by New York Attorney General
  • Max penalty $5,000/violation, $250K aggregate
  • Scope Any org holding NY residents' private info
  • Safeguards Administrative, Technical, Physical

Required Safeguards

Three Categories of Reasonable Security

Administrative

Designate security coordinators; identify internal/external security risks; assess the sufficiency of existing safeguards; train and manage employees; select compliant service providers; adjust the programme as your business evolves.

Technical

Assess network and software design; assess information processing, transmission, and storage safeguards; detect, prevent, and respond to attacks; test and monitor systems and procedures regularly.

Physical

Assess risks of information storage and disposal; detect, prevent, and respond to unauthorised physical access; dispose of private information securely after it is no longer needed for business purposes.

How AIQA Helps

SHIELD-Ready in 90 Days

Data Inventory & Risk Assessment

We identify all private information your organisation holds about NY residents, map where it flows and is stored, and assess current administrative, technical, and physical risks — the foundation of a defensible SHIELD programme.

Safeguard Implementation

We design and implement the specific safeguards needed across all three categories, ensuring they are proportionate to your size, complexity, and the sensitivity of the data you hold — as the statute requires.

Breach Response Planning

SHIELD's expanded breach notification requirements demand a practiced response plan. We build and test your incident response procedures, draft notification templates, and ensure your AG notification timelines are operationally achievable.

Common Challenges

Where Organisations Fall Short

Extraterritorial Blind Spot

Many non-NY organisations do not realise SHIELD applies to them. If you hold any private information about even one New York resident, you are covered — regardless of your location.

'Reasonable' Is Not Defined

SHIELD does not prescribe specific controls. 'Reasonable' is judged against your size, complexity, and data sensitivity — leaving room for AG interpretation that organisations need expert guidance to anticipate.

Expanded Definition of Private Info

SHIELD broadened what counts as private information beyond earlier NY breach law. Organisations that were previously compliant may now hold newly-covered data types they have not assessed.

Vendor Due Diligence

SHIELD explicitly requires selecting and retaining third-party service providers that also maintain appropriate safeguards — creating a contractual and oversight obligation most SMBs have not formalised.

Other Compliance Frameworks

Free Offer

Start With a Complimentary SHIELD Act Review

We will assess whether SHIELD applies to your organisation, review your current safeguards across all three categories, and identify the highest-priority gaps. No cost, no commitment.

30–60 minutes. No cost. No commitment.