Law note · New York
Stop Hacks and Improve Electronic Data Security (SHIELD) Act, data security program duty
Any person or business that owns or licenses computerized data including a New York resident's private information must develop, implement, and maintain reasonable administrative, technical, and physical safeguards to protect its security, confidentiality, and integrity.
A business is deemed compliant either by being a regulated entity under an existing federal or state data-security regime such as GLBA, HIPAA and HITECH, or 23 NYCRR 500, or by implementing the safeguards program the section itself describes, and a small business under 50 employees, under $3 million in revenue, or under $5 million in year-end assets gets a version of the same duty scaled to its size and complexity.
This is a genuinely separate obligation from the breach-notification duty in section 899-aa: it is a preventive duty to safeguard data, not a duty to notify after exposure, and the statute expressly bars a private right of action for this section.
What it asks of an app
- Develop, implement, and maintain reasonable administrative, technical, and physical safeguards to protect the security, confidentiality, and integrity of New York residents' private information.
- Treat yourself as compliant if you are already a regulated entity under GLBA, HIPAA and HITECH, or 23 NYCRR 500, or otherwise implement the administrative, technical, and physical safeguards program this section describes.
- Scale your safeguards program to your size and complexity if you are a small business under 50 employees, under $3 million in revenue, or under $5 million in year-end assets.
- Do not expect a private plaintiff to sue over this safeguards duty. The statute expressly bars a private right of action for this section.
When LexLint raises it
Declared activities: crawls_web, trains_models, deploys_chatbot, automated_outreach
Primary source: official New York statute text, N.Y. General Business Law, New York State Senate