New York's SHIELD Act: The Section 899-bb Security Requirement and the Breach Law Changes Since 2019
Key Takeaways
- Chapter 117 of the Laws of 2019 was signed on July 25, 2019; its notification changes took effect on the 90th day and section 899-bb on the 240th day, March 21, 2020
- Section 899-bb reaches any person or business that owns or licenses computerized private information of a New York resident, and deems compliant those subject to and in compliance with GLBA, HIPAA or 23 NYCRR Part 500 rules
- A small business is one with fewer than 50 employees, under $3 million in gross annual revenue in each of the last three fiscal years, or under $5 million in year-end total assets
- A violation of section 899-bb is deemed a violation of GBL section 349, enforced by the Attorney General, and the section creates no private right of action
- Chapter 647 of 2024 imposed a 30-day outer limit on breach notice, chapter 613 of 2024 added medical and health insurance information, and chapter 91 of 2025 confined DFS notice to Part 500 covered entities
What Chapter 117 of 2019 Changed
Senate Bill S5575-B, the Stop Hacks and Improve Electronic Data Security Act, passed both houses on June 17, 2019 and was signed as chapter 117 of the Laws of 2019 on July 25, 2019. The Attorney General's office, which described the bill as an agency program bill it had submitted, said in its statement at passage that the bill expanded the information covered by the notification law, broadened the breach definition to include unauthorized access, applied the notice requirement to any person or entity with a New York resident's private information rather than only those conducting business in the state, and created "reasonable data security requirements tailored to the size of a business."
In the enacted text, section 3 rewrote most of General Business Law section 899-aa, section 4 added a new section 899-bb, and section 5 made parallel changes to section 208 of the State Technology Law, which governs state entities. Section 6 set the timing: the act took effect "on the ninetieth day after it shall have become a law," except that section 4 took effect "on the two hundred fortieth day." Counted from July 25, 2019, that is October 23, 2019 for the notification changes and March 21, 2020 for the security requirement.
The Reasonable Safeguards Requirement
The core duty is a single sentence in section 899-bb(2)(a). Any person or business "that owns or licenses computerized data which includes private information of a resident of New York shall develop, implement and maintain reasonable safeguards to protect the security, confidentiality and integrity of the private information including, but not limited to, disposal of data." The trigger in that text is the resident whose data is held, not where the business operates. Section 899-bb(1)(b) gives "private information" the same meaning as in section 899-aa, a definition that has itself been amended since 2020.
Section 899-bb(2)(b) then offers two ways for a person or business to be "deemed to be in compliance." One is to be a compliant regulated entity. The other is to implement a data security program that includes the administrative, technical and physical safeguards the section describes.
Compliant Regulated Entities
Section 899-bb(1)(a) defines a compliant regulated entity as any person or business "that is subject to, and in compliance with," any of four sets of data security requirements:
- regulations promulgated under Title V of the Gramm-Leach-Bliley Act, 15 U.S.C. 6801 to 6809
- the regulations implementing HIPAA at 45 CFR parts 160 and 164, and the HITECH Act
- Part 500 of Title 23 of the New York Codes, Rules and Regulations, the Department of Financial Services cybersecurity regulation
- "any other data security rules and regulations of, and the statutes administered by, any official department, division, commission or agency of the federal or New York state government," as interpreted by that agency or by the federal or New York courts
Both conditions appear in the definition. On the statute's terms, being subject to one of those regimes does not by itself make an entity a compliant regulated entity; the text also requires that it be in compliance with the regime.
Administrative, Technical and Physical Elements
For everyone else, section 899-bb(2)(b)(ii) describes the program by example. Each category is introduced with the words "such as the following," and the Attorney General's SHIELD Act guidance page states that the act "lists some safeguards, but is not meant to be an exhaustive list."
| Category | Safeguards listed in section 899-bb(2)(b)(ii) |
|---|---|
| Administrative | Designating one or more employees to coordinate the security program; identifying reasonably foreseeable internal and external risks; assessing the sufficiency of safeguards in place; training and managing employees in the program's practices; selecting service providers capable of maintaining appropriate safeguards and requiring those safeguards by contract; adjusting the program in light of business changes or new circumstances |
| Technical | Assessing risks in network and software design; assessing risks in information processing, transmission and storage; detecting, preventing and responding to attacks or system failures; regularly testing and monitoring the effectiveness of key controls, systems and procedures |
| Physical | Assessing risks of information storage and disposal; detecting, preventing and responding to intrusions; protecting against unauthorized access to or use of private information during or after collection, transportation and destruction or disposal; disposing of private information within a reasonable time after it is no longer needed for business purposes, by erasing electronic media so it cannot be read or reconstructed |
The list names no particular technology. Encryption, multi-factor authentication and penetration testing do not appear in the section's text. The listed safeguards are framed as processes of assessing, detecting, testing and adjusting.
The Small Business Accommodation
Section 899-bb(1)(c) defines a small business as any person or business with "(i) fewer than fifty employees; (ii) less than three million dollars in gross annual revenue in each of the last three fiscal years; or (iii) less than five million dollars in year-end total assets, calculated in accordance with generally accepted accounting principles." The three tests are joined by "or," so any one of them is sufficient.
The accommodation is not an exemption from the security duty. Under section 899-bb(2)(c), a small business satisfies the program route if its security program "contains reasonable administrative, technical and physical safeguards that are appropriate for the size and complexity of the small business, the nature and scope of the small business's activities, and the sensitivity of the personal information the small business collects from or about consumers." The three categories remain; the measure of what is reasonable is scaled to the business.
Enforcement Belongs to the Attorney General
Section 899-bb(2)(d) provides that a person or business that fails to comply "shall be deemed to have violated section three hundred forty-nine of this chapter," and authorizes the Attorney General to bring an action to enjoin violations and obtain civil penalties under General Business Law section 350-d. Section 899-bb(2)(e) is one sentence: "Nothing in this section shall create a private right of action."
The notification statute carries separate remedies. Under section 899-aa(6), the Attorney General may seek an injunction, and the court may award damages for actual costs or losses incurred by a person who was not notified. Where a violation was knowing or reckless, the court may impose a civil penalty of "the greater of five thousand dollars or up to twenty dollars per instance of failed notification," with the per-instance amount capped at $250,000. An action must be commenced within three years after the Attorney General became aware of the violation or the date of the notice sent to the state under subdivision 8, whichever occurs first, and no later than six years after discovery of the breach unless the company took steps to hide it.
The Breach Definition SHIELD Widened
The Attorney General's guidance page summarizes the notification changes chapter 117 made. Under the 2005 law, it says, a breach was "an unauthorized acquisition of computerized data" compromising private information; the SHIELD Act extended that "to any 'access' to computerized data," and expanded the data elements "to include biometric information, username or email address, and password credentials."
Section 899-aa(1)(c) now defines a breach as "unauthorized access to or acquisition of, or access to or acquisition without valid authorization, of computerized data that compromises the security, confidentiality, or integrity of private information." The statute supplies separate factors for each limb. For access, a business may consider indications that information was "viewed, communicated with, used, or altered" without authorization. For acquisition, it may consider physical possession of a lost or stolen device, indications of downloading or copying, and use such as fraudulent accounts opened or identity theft reported.
The section as it now reads also shapes who is told and when. Notice to individuals is not required for an inadvertent disclosure by persons authorized to access the information where the business reasonably determines misuse or harm is unlikely, but that determination must be documented in writing, kept for at least five years and, if more than 500 New York residents are affected, provided to the Attorney General within ten days. A business that notifies individuals under GLBA, HIPAA or Part 500 rules need not notify them again, but still notifies the state agencies and, where required, the consumer reporting agencies, which are notified when more than 5,000 residents are notified at one time. A HIPAA covered entity that reports a breach to the HHS Secretary must notify the Attorney General within five business days, including for a breach of information that is not private information under the section.
The 2024 and 2025 Amendments
Section 899-bb has not been amended since it took effect; the Senate's statute page shows its most recent revision as March 27, 2020. Section 899-aa has been amended by two chapters of 2024 and one of 2025, and its page lists revisions dated December 27, 2024, February 21, 2025 and March 28, 2025.
Chapter 647 of the Laws of 2024. S2659-B, whose Assembly companion was A8872, was signed on December 21, 2024 and took effect immediately. It replaced the words "consistent with" before "the legitimate needs of law enforcement" with a proviso that notification "shall be made within thirty days after the breach has been discovered, except for" those needs, and deleted the clause that had allowed time for "any measures necessary to determine the scope of the breach and restore the integrity of the system." It added the same 30-day outer limit to the existing duty of a business that maintains data it does not own to notify the owner immediately, and, in the bill's summary, added the Department of Financial Services to the agencies notified of a breach affecting New York residents.
Chapter 91 of the Laws of 2025. S804, signed on February 14, 2025, is described in its memorandum as "a chapter amendment to L.2024, c.647." It narrowed the new notice: notice to the Department of Financial Services "shall only be required if the person or business is a covered entity, as defined in 23 NYCRR 500.1," and is to be provided "in compliance with 23 NYCRR 500.17." It takes effect on the same date and in the same manner as chapter 647.
Chapter 613 of the Laws of 2024. S2376, also signed on December 21, 2024, amended the Penal Law, the General Business Law and the State Technology Law to address medical and health insurance information. In section 899-aa it added "medical information," meaning information regarding an individual's medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional, and "health insurance information," covering a policy or subscriber identification number, any unique identifier a health insurer uses, and information in an application and claims history including appeals history. It took effect on the ninetieth day after becoming law, March 21, 2025.
None of the three chapters amended section 899-bb. Through the cross-reference in section 899-bb(1)(b), the private information its safeguards duty covers is the private information defined in section 899-aa as amended.
Where the Record Is Incomplete
No enforcement action under section 899-bb is described here. The Attorney General's office has announced data security settlements since the section took effect, including with GEICO and Travelers in 2024, with eight car insurance companies in 2025 and with the accounting firm Wojeski & Company in 2025 after a ransomware attack. The text of those press releases, as fetched for this article, does not identify section 899-bb or the SHIELD Act as the provision relied on, and the underlying settlement documents were not reviewed. None of them is counted here as a section 899-bb action.
Background
For the underlying law rather than this development: New York privacy law.
Frequently Asked Questions
When did the SHIELD Act's data security requirement take effect?
Does section 899-bb apply to businesses located outside New York?
Which entities does the SHIELD Act treat as already compliant?
Can a consumer sue a business for violating section 899-bb?
How long does New York law allow for notifying residents of a breach?
Sources
Everything above is reported from these documents. Follow them to verify.
- N.Y. Gen. Bus. Law § 899-bb, Data security protections (March 27, 2020) statute
- N.Y. Gen. Bus. Law § 899-aa, Notification; person without valid authorization has acquired private information (March 28, 2025) statute
- S5575-B (2019), Stop Hacks and Improve Electronic Data Security Act, chapter 117 of the Laws of 2019: text and actions (July 25, 2019) statute
- S2659-B (2023-2024), notification of a data breach, chapter 647 of the Laws of 2024 (December 21, 2024) statute
- A8872 (2023-2024), Assembly companion enacted as chapter 647 of the Laws of 2024 (December 21, 2024) statute
- S2376 (2023-2024), medical and health insurance information, chapter 613 of the Laws of 2024 (December 21, 2024) statute
- S804 (2025-2026), chapter amendment on notice to the Department of Financial Services, chapter 91 of the Laws of 2025 (February 14, 2025) statute
- New York Attorney General, Stop Hacks and Improve Electronic Data Security Act (SHIELD Act) agency guidance
- New York Attorney General, Attorney General James Applauds Passage of the SHIELD Act agency release
- New York Attorney General, Attorney General James and DFS Superintendent Harris Secure $11.3 Million from Auto Insurance Companies over Data Breaches agency release
- New York Attorney General, Attorney General James Secures $14.2 Million from Car Insurance Companies Over Data Breaches agency release
- New York Attorney General, Attorney General James Announces Settlement with Accounting Firm for Failing to Protect New Yorkers' Personal Data agency release
Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.