Law note · New York
Stop Hacks and Improve Electronic Data Security (SHIELD) Act, breach notification duty
Any person or business that owns or licenses computerized data including private information must disclose a breach of the security of the system to each affected New York resident in the most expedient time possible and without unreasonable delay, and no later than 30 days after the breach is discovered.
Notice to the Attorney General, the Department of State, and the Division of State Police is required for every disclosure, and notice to nationwide consumer reporting agencies is required when more than 5,000 New York residents are notified at once.
'Private information' is personal information combined with an unencrypted data element such as a Social Security number, driver's license number, financial account number, biometric information, or medical or health insurance information; biometric information here carries no exclusion for data derived from a photograph, video, or audio recording, unlike a comprehensive-regime state's biometric definition, though this plain-text reading has not been tested in New York case law or Attorney General guidance.
This section's local-law preemption clause is scoped to breach notification and does not displace New York City's separate biometric-privacy ordinance, which regulates capture consent and retention, a different subject.
What it asks of an app
- Disclose a breach of the security of your system to each affected New York resident in the most expedient time possible and without unreasonable delay, and no later than 30 days after discovering the breach.
- Notify the New York Attorney General, the Department of State, and the Division of State Police of the breach, and notify each nationwide consumer reporting agency if you are notifying more than 5,000 New York residents at once.
- Do not assume New York law clears a faceprint or voiceprint you extract from a recording to authenticate or ascertain identity. SHIELD's biometric-information trigger carries no recording-derived exclusion, so an extracted identifier plausibly falls within it if a later breach exposes it, though this reading is untested in New York case law or Attorney General guidance.
- Do not treat a New York City ordinance as displaced by this section's preemption clause. SHIELD's preemption is scoped to breach notification; the separate NYC Biometric Identifier Information Law regulates capture consent and retention, a different subject.
When LexLint raises it
Declared activities: crawls_web, trains_models, deploys_chatbot, automated_outreach, processes_biometrics, processes_voice
Primary source: official New York statute text, N.Y. General Business Law, New York State Senate