Skip to content
2026

Now taking on 4 new clients this year — white-glove onboarding, month to month.

Book a call

NY SHIELD Act for Small Business: 8 Questions Owners Ask

Glowing digital security shield with a padlock hovering over the Manhattan skyline at dusk, illustrating NY SHIELD Act data protection for New York businesses.

The New York SHIELD Act sets data-security and breach-notification rules for almost any business that holds the private information of New York residents, and there is no full exemption for small companies. If you have customer or employee data on New Yorkers, these are the questions we hear most from owners, answered plainly.

What is the NY SHIELD Act?

The Stop Hacks and Improve Electronic Data Security (SHIELD) Act is a New York law that requires businesses to protect New York residents' private information with reasonable safeguards and to notify people when that data is breached. It broadened both what counts as a breach and who has to comply, well beyond the state's older, narrower data-breach law.

Does it apply to my business if I'm not located in New York?

Yes. The law covers any person or business that owns or licenses computerized data containing the private information of a New York resident, regardless of where the business itself operates. A company in New Jersey, Florida, or anywhere else that serves even a handful of New York customers is on the hook.

Is my small business exempt from the SHIELD Act?

Not exempt, but scaled. A "small business" (fewer than 50 employees, under $3 million in gross revenue for each of the last three years, or under $5 million in total year-end assets) may implement safeguards appropriate to its size and complexity. The breach-notification requirement, though, applies to everyone with no small-business carve-out.

What "reasonable safeguards" do I actually have to put in place?

The law names three categories rather than a checklist: administrative, technical, and physical. In practice that means designating someone responsible for security, running risk assessments, training staff, holding vendors to security terms by contract, encrypting and controlling access to data, disposing of records securely, and testing that your key controls work. It maps closely to the core controls that actually stop attacks.

What counts as a data breach under the law?

The SHIELD Act expanded a breach to include unauthorized access to private information, not only its acquisition. It also widened "private information" to cover things like biometric data and an email address paired with a password or security question answer. So an incident that exposes login credentials can trigger obligations even if you cannot prove data was copied.

What are the penalties for violations?

For a knowing or reckless notification failure, a court may impose the greater of $5,000 or up to $20 per instance, capped at $250,000. For failing to maintain reasonable safeguards, penalties run up to $5,000 per violation. The New York Attorney General enforces the law; there is no private right of action, but investigations and fines are real.

What do I have to do if we have a breach?

Notify affected New York residents in the most expedient time possible, and, above set thresholds, notify the state Attorney General and other agencies, including the template of the notice you plan to send. Moving quickly and correctly matters, which is why every business should have an incident response plan written before an incident, not during one.

How do I get compliant, and where should I start?

Start with a data inventory: know what New York-resident private information you hold, where it lives, and who can reach it. Then run a risk assessment against the three safeguard categories and close the gaps, prioritizing encryption, access control, vendor terms, and a tested response plan. Strong data loss prevention and current cyber insurance both support the effort.

Where can I get help?

The NetSys Group runs security assessments and delivers the ongoing cybersecurity services that keep SHIELD Act safeguards in place year-round for businesses across New York and the surrounding region. Contact us for a complimentary risk assessment, and we will show you where your data protection stands against the law's requirements.

Reading is free. So is knowing where you stand.

Turn insight into action.

Take a free cybersecurity or AI readiness assessment, or book a call with a NetSys engineer — no obligation, no runaround.