Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Age-appropriate design code
Covered online platforms, including social media, gaming, and digital messaging services, must apply privacy-protective default settings for users they know are minors, including restricting contact and profile recommendations from unknown adults, limiting financial transactions, requiring parental approvals for weaker settings, and turning AI companion features off by default.
The act relies on commercially reasonable age assurance, with standards to be set through Attorney General rulemaking, and was enacted in May 2026 as part Y of the state's FY2027 transportation and economic development budget bill.
Note and primary source →
Operators of websites, online services, apps, and connected products may not process, sell, or share the personal data of a user under 18 for targeted advertising, profiling, or other non-essential purposes without informed consent, and must honor browser or device signals indicating a user is a minor. The Attorney General has said it will exercise enforcement discretion for good-faith compliance efforts while final implementing rules remain pending.
Note and primary source →
Breach notification
cite N.Y. Gen. Bus. Law § 899-aa
stage IN FORCE in force since 2019-10-23
source official New York statute text, N.Y. General Business Law, New York State Senate
Any person or business that owns or licenses computerized data including private information must disclose a breach of the security of the system to each affected New York resident in the most expedient time possible and without unreasonable delay, and no later than 30 days after the breach is discovered.
Notice to the Attorney General, the Department of State, and the Division of State Police is required for every disclosure, and notice to nationwide consumer reporting agencies is required when more than 5,000 New York residents are notified at once.
'Private information' is personal information combined with an unencrypted data element such as a Social Security number, driver's license number, financial account number, biometric information, or medical or health insurance information; biometric information here carries no exclusion for data derived from a photograph, video, or audio recording, unlike a comprehensive-regime state's biometric definition, though this plain-text reading has not been tested in New York case law or Attorney General guidance.
This section's local-law preemption clause is scoped to breach notification and does not displace New York City's separate biometric-privacy ordinance, which regulates capture consent and retention, a different subject.
What it asks of an app →
cite N.Y. Gen. Bus. Law § 899-bb
stage IN FORCE in force since 2020-03-21
source official New York statute text, N.Y. General Business Law, New York State Senate
Any person or business that owns or licenses computerized data including a New York resident's private information must develop, implement, and maintain reasonable administrative, technical, and physical safeguards to protect its security, confidentiality, and integrity.
A business is deemed compliant either by being a regulated entity under an existing federal or state data-security regime such as GLBA, HIPAA and HITECH, or 23 NYCRR 500, or by implementing the safeguards program the section itself describes, and a small business under 50 employees, under $3 million in revenue, or under $5 million in year-end assets gets a version of the same duty scaled to its size and complexity.
This is a genuinely separate obligation from the breach-notification duty in section 899-aa: it is a preventive duty to safeguard data, not a duty to notify after exposure, and the statute expressly bars a private right of action for this section.
What it asks of an app →
Enforcement supervision
The Attorney General may bring an action to enjoin and restrain a violation of SHIELD's breach-notification duty, and a court may award actual costs for a failure to notify and, for a knowing or reckless violation, a civil penalty of the greater of $5,000 or up to $20 per instance of failed notification, capped at $250,000; a three-year limitations period runs from Attorney General discovery or notice, extendable to six years if the breach was concealed.
A violation of the separate data-security-program duty is deemed a violation of General Business Law section 349, letting the Attorney General bring an action to enjoin it and obtain civil penalties on that basis.
Section 899-bb expressly bars a private right of action for the safeguards duty, and section 899-aa carries no comparable express bar in its own text, but its enforcement subdivision is written entirely in terms of Attorney General authority, with no private-suit provision found anywhere in that section during this research pass. Neither half of SHIELD arms a private plaintiff.
What it asks of an app →
Social media and minors
Social media platforms must obtain parental consent before providing an addictive, algorithmically personalized feed to a user they know is a minor, and may not send notifications to minors between midnight and 6 a.m. without parental consent.
The act does not take effect until 180 days after the Attorney General finalizes rules identifying acceptable age-determination and parental-consent methods; a notice of proposed rulemaking was published September 15, 2025, the public comment period closed December 1, 2025, and final rules had not been adopted as of mid-2026.
Note and primary source →