The NY SHIELD Act: What It Actually Requires, in Plain English
September 3, 2026
0
min read
New York's SHIELD Act applies to nearly every business handling New York resident data, not just tech companies. Here's what it actually requires and where businesses most often fall short.
The New York SHIELD Act has been in effect since 2020, but a surprising number of businesses still don't realize it applies to them, or don't know what it actually requires. If your business handles the private information of any New York resident, employees, customers, patients, clients, this law applies to you regardless of where your business is physically located.
Here's what it means in practice.
Who it covers. The SHIELD Act applies to any business, of any size, that owns or licenses private information of a New York resident. There's no small business exemption. A five-person accounting firm in Great Neck and a national retailer are held to the same core requirements if either handles New York resident data.
What counts as private information. Social Security numbers, driver's license numbers, financial account numbers combined with access codes, and biometric information all qualify. So does a combination of a name with certain other identifiers. Basic contact information alone typically doesn't trigger the law, but most businesses hold more than they realize once you look closely at HR files, client intake forms, and billing records.
What the law actually requires. The Act mandates a data security program with three components:
- Administrative safeguards: designating an employee to coordinate security, assessing risks in how the business handles data, and training staff.
- Technical safeguards: assessing network and software risks, and having a process to detect, prevent, and respond to intrusions.
- Physical safeguards: controlling physical access to areas storing private information, and properly disposing of it when no longer needed.
Where businesses most often fall short. In our experience, it's rarely the technical side that trips businesses up, most have basic firewalls and antivirus in place. The gaps are almost always administrative: no designated point person for security, no documented risk assessment, and no evidence of employee training beyond a one-time mention during onboarding.
What happens if you don't comply. The New York Attorney General can bring enforcement actions, and penalties scale with the size and duration of the violation. Beyond formal penalties, a breach involving non-compliant data handling significantly increases both legal exposure and reputational damage.
Where to start. A genuine risk assessment is the foundation everything else depends on. Without it, technical controls get implemented without addressing your actual exposure, and administrative policies exist on paper without matching reality. If you're not sure where your business stands, that assessment is exactly what we walk through in our free network security assessment, and it's usually the fastest way to find out whether you're actually covered or just assume you are.
Free Network Security Assessment
Fill out the form below to get a free network security assessment and find out how we can make your technology hassle-free!









