Comserv Connect
← Back to Blog
Compliance

NY SHIELD Act Compliance for Small Businesses

By Comserv Connect TeamReviewed by Chris Ferrera

Most small-business owners in New York have never heard of the SHIELD Act. Then they hold onto a customer's name and Social Security number, or a card number together with its security code, or an email address and the password that goes with it, and without realizing it, they're squarely inside a law with real teeth.

The SHIELD Act isn't just for big companies. If you have private information on even one New York resident, it applies to you. What changes with your size is the standard you're measured against, not whether the law reaches you. Here's what it actually requires, minus the legalese.

What the SHIELD Act Is

The Stop Hacks and Improve Electronic Data Security (SHIELD) Act is New York's data-security law. It does two big things: it broadens what counts as a data breach you have to report, and, more importantly for day-to-day operations, it requires businesses to put "reasonable safeguards" in place to protect private information.

What Counts as Private Information

This is the part owners guess at, and the definition is narrower and more specific than most people assume (General Business Law 899-aa(1)(b)). It generally works in pairs.

A name combined with a Social Security number, a driver's license number, or a financial account number counts. A card number by itself generally does not: it counts when it comes with the security code, access code, or password that would let someone actually use the account. An email address or username by itself doesn't count either; it counts when it's paired with a password or with a security question and its answer.

One addition matters a great deal if you're a medical or dental practice. An amendment signed in December 2024, effective March 21, 2025, added medical information and health insurance information to the definition of private information. If you hold patient data, more of what sits in your systems falls under this law today than did two years ago.

What "Reasonable Safeguards" Looks Like in Practice

The three safeguard categories aren't regulator commentary or industry best practice. They are written into the statute itself, at 899-bb(2)(b)(ii), with examples attached. Translated into things you can actually implement:

  • Administrative safeguards. Designate someone to coordinate the security program, identify your reasonably foreseeable risks, assess whether your current safeguards actually control them, train your staff, and manage your vendors. That last item is the sleeper: the statute expressly expects you to select service providers capable of maintaining appropriate safeguards, and to require those safeguards by contract. It's the requirement small businesses miss most often, and it's a paperwork problem rather than a technology problem.
  • Technical safeguards. Assess risk in your network and software design and in how information is processed, transmitted, and stored; detect, prevent, and respond to attacks and system failures; and regularly test and monitor whether your key controls are working. In practice that means endpoint protection, network monitoring, access controls that limit who can reach private information, and encryption where it belongs.
  • Physical safeguards. Control who can get to the devices, protect information during collection and transport, and dispose of old data properly so a discarded laptop or drive doesn't become a breach.

None of that is exotic. It's the same foundation any serious cybersecurity program is built on, which is the point. The SHIELD Act largely codifies what "taking security seriously" already means.

The Parts Small Businesses Miss

Three things catch owners off guard.

First, the law follows the resident, not your address. A New Jersey shop with New York customers is still on the hook.

Second, there is a defined small-business tier, and it's worth knowing whether you're in it. Under 899-bb(1)(c), you qualify as a small business if you have fewer than 50 employees, or less than $3 million in gross annual revenue in each of the last three fiscal years, or less than $5 million in year-end total assets. Qualifying is not an exemption. It scales the standard: your safeguards need to be appropriate for the size and complexity of your business, the nature and scope of your activities, and the sensitivity of the information you collect. So being small is a real legal factor, not a defense. It changes what "reasonable" looks like for you; it doesn't remove the obligation to be reasonable.

Third, there is a safe harbor, and most coverage of this law skips it. Under 899-bb(2)(b)(i), a "compliant regulated entity" is deemed to be in compliance with the SHIELD Act's data-security requirement. That covers businesses subject to and in compliance with HIPAA and the HITECH Act, the Gramm-Leach-Bliley Act, or the New York Department of Financial Services cybersecurity regulation at 23 NYCRR Part 500. If you're a medical practice already running a HIPAA Security Rule program, or a financial firm already under Gramm-Leach-Bliley or Part 500, you may already satisfy this law through the framework you're on. That's a genuine shortcut, but it's conditional. The safe harbor turns on actually being in compliance with that other regime, not merely being covered by it, so it's worth confirming rather than assuming.

Outside the safe harbor, "reasonable" gets judged after the fact. You tend to find out whether your safeguards were reasonable when something goes wrong and someone reviews what you had in place.

That's why documentation matters as much as tools. A risk assessment on record, written policies, evidence of training, signed vendor agreements, and monitoring you can point to are what turn "we tried" into "we had reasonable safeguards." Without them, you're relying on nothing having gone wrong.

How Comserv Helps

The SHIELD Act rewards businesses that treat security as an ongoing system rather than a one-time purchase. The good news is that the safeguards it expects are largely the same ones that keep you from getting breached in the first place.

At Comserv Connect, our cybersecurity services cover a lot of what those statutory categories ask for: 24/7 threat monitoring and response, zero-trust endpoint control, email security, security awareness training with simulated phishing and risk assessments, and encrypted, tested backup and recovery. What we won't tell you is that buying a stack makes you compliant. Reasonableness under this law is a facts-and-circumstances judgment, not a product list, and the vendor-management and documentation pieces are yours to own. We work with businesses across New York and New Jersey, and we'd rather help you get an honest read on where you stand.

Not sure whether your safeguards would hold up? Book a free strategy call or call (347) 273-1200, and we'll walk you through it.

This post summarizes New York General Business Law sections 899-aa and 899-bb in plain English. It is general information, not legal advice, and it does not create an attorney-client relationship. How the statute applies to your business depends on your specific facts, so talk to your own counsel before relying on any of it.

Want the Checklist We Actually Use?

The same checks we run for the businesses we protect, in plain language. Free PDF, no vendor pitch.