Law note · New York
Stop Hacks and Improve Electronic Data Security (SHIELD) Act, Attorney General enforcement
The Attorney General may bring an action to enjoin and restrain a violation of SHIELD's breach-notification duty, and a court may award actual costs for a failure to notify and, for a knowing or reckless violation, a civil penalty of the greater of $5,000 or up to $20 per instance of failed notification, capped at $250,000; a three-year limitations period runs from Attorney General discovery or notice, extendable to six years if the breach was concealed.
A violation of the separate data-security-program duty is deemed a violation of General Business Law section 349, letting the Attorney General bring an action to enjoin it and obtain civil penalties on that basis.
Section 899-bb expressly bars a private right of action for the safeguards duty, and section 899-aa carries no comparable express bar in its own text, but its enforcement subdivision is written entirely in terms of Attorney General authority, with no private-suit provision found anywhere in that section during this research pass. Neither half of SHIELD arms a private plaintiff.
What it asks of an app
- Expect SHIELD Act violations, for both the breach notification duty and the data security program duty, to be enforced exclusively by the New York Attorney General, never by a private plaintiff.
- Expect the Attorney General to seek an injunction and, for a failure to notify, actual costs, plus for a knowing or reckless violation a civil penalty of the greater of $5,000 or $20 per instance of failed notification, capped at $250,000.
- Expect a data-security-program violation to be treated as a violation of General Business Law section 349, letting the Attorney General seek an injunction and civil penalties on that separate basis.
When LexLint raises it
Declared activities: crawls_web, trains_models, deploys_chatbot, automated_outreach
Primary source: official New York statute text, N.Y. General Business Law, New York State Senate