Learn

Published August 28, 2026

SHIELD Act small business requirements

Who New York's SHIELD Act can reach, what reasonable safeguards look like for a one-office shop, and what the 30-day breach-notification rule means in practice.

The New York SHIELD Act is often described as a cybersecurity law for large companies. That is not the useful way to read it if you run a one-office business. The question is less about whether your shop looks like a technology company and more about whether you own or license computerized data containing private information about a New York resident.

That can include a local accountant, property manager, dental practice, retailer, or employer. It can also include a business based outside New York that serves New York customers or employees and keeps their covered information. A Worcester-sized or White Plains-sized shop, a team with no IT department, or a paper-heavy office does not automatically fall outside the law. The safeguards should fit the business, but the small-business label is not a blanket exemption.

Who the SHIELD Act covers

New York General Business Law § 899-bb requires any person or business that owns or licenses computerized data containing a New York resident's private information to develop, implement, and maintain reasonable safeguards. The wording is broad. It is not limited to a corporation headquartered in Albany, Manhattan, or anywhere else in the state. An out-of-state business can still need to take a closer look when it conducts business with New York residents and holds their covered records.

Section 899-bb defines a small business as one with fewer than 50 employees, less than $3 million in gross annual revenue in each of the last three fiscal years, or less than $5 million in year-end total assets. That definition helps determine how the safeguards are sized; it does not turn the security program into an optional extra. Even a business that does not fit that definition still has to consider reasonable safeguards under the law.

What private information means

“Private information” is personal information combined with certain data elements when the element or the combination is unencrypted, or the encryption key has also been accessed. The list includes a Social Security number; a driver's license or non-driver ID number; a financial account, credit-card, or debit-card number with the access code or other information needed to reach the account; and, in some circumstances, an account or card number that could be used without more identifying information.

It also includes biometric information used to authenticate identity, medical information, health-insurance information, and a username or email address paired with a password or security question and answer that would permit access to an online account. Publicly available information lawfully released from government records is excluded. A name in a customer list is not automatically private information; a name paired with one of these elements may be.

The statute is the authority for those definitions. Shieldwise keeps the citation and the related provisions together on the sources page, and you can read the published New York statute. New York DFS cybersecurity guidance is useful context for security planning, but it is guidance and not a substitute for reading the statute or getting legal advice.

Reasonable safeguards

The SHIELD Act does not prescribe one expensive stack of products. It asks for a reasonable security program with administrative, technical, and physical safeguards. For a small business, the measure is what is appropriate for its size and complexity, the nature and scope of its activities, the sensitivity of the information it collects, and its available resources. A five-person office is not expected to copy a hospital's security department; it is expected to know what it holds and protect it deliberately.

Administrative safeguards can start with naming one person to coordinate the program, identifying foreseeable internal and external risks, training the people who handle records, reviewing vendors, requiring appropriate protections in vendor contracts, and revisiting the program when the business or its systems change. Put those decisions in writing so the program can be used, reviewed, and improved rather than living in one owner's memory.

Technical safeguards might mean separate accounts instead of shared passwords, multi-factor authentication for email and financial systems, updates and supported software, encrypted laptops and backups where appropriate, access limited by job role, backups tested for recovery, and a simple way to notice and respond to suspicious activity. Physical safeguards still count: lock paper files, control keys and visitors, keep screens and printers from exposing records, and destroy paper and electronic media so information cannot be read or reconstructed when it is no longer needed.

What a one-office shop should do

Start with an inventory, not a shopping list. Write down where customer, employee, patient, tenant, or client information enters the business, where it is stored, who can access it, which vendors receive it, and how long you keep it. Include shared drives, email, payroll platforms, cloud accounting, old laptops, filing cabinets, and the copier that may retain documents.

Next, assign an owner and make a short risk register. For each important system, record the likely failure — a stolen laptop, a phished mailbox, an ex-employee's still-active account, or a misdirected spreadsheet — and the control that reduces it. Turn on the controls you already pay for. Train the team on phishing and misdirected email. Create an offboarding checklist and an incident page with vendor, insurer, counsel, and law-enforcement contacts. Review the plan at least when your systems, staff, vendors, or data change.

If you want a second official starting point for the technical side, read the New York DFS cybersecurity guidance. It can help you ask better questions; it does not change the SHIELD Act's small-business standard or decide how the law applies to your facts.

If there is a breach

A security event is not automatically a reportable breach. Under § 899-aa, the relevant event is unauthorized access to or acquisition of computerized data that compromises the security, confidentiality, or integrity of private information maintained by the business. Indicators can include someone viewing, copying, downloading, altering, possessing, or using the information. A good-faith employee access for business purposes is not a breach if the information is not misused or subject to unauthorized disclosure. Preserve evidence and get qualified help before deciding that an alert is harmless.

If affected New York residents' private information was, or is reasonably believed to have been, accessed or acquired without valid authorization, notice must go out in the most expedient time possible and without unreasonable delay. The current outside deadline is 30 days after the breach is discovered, subject to the law-enforcement exception. A law-enforcement agency can delay notice if it determines that notice would impede a criminal investigation; notice follows when the agency determines it will not compromise that investigation.

A custodian that maintains computerized data it does not own must notify the owner or licensee immediately, and in any event within 30 days after discovery, when the private information was or is reasonably believed to have been accessed or acquired. When New York residents are to be notified, the business must also notify the New York Attorney General, Department of State, and Division of State Police about the timing, content, distribution, and approximate number of affected people, without delaying consumer notice. DFS notice is required only for an applicable covered entity under 23 NYCRR 500.1, in compliance with 23 NYCRR 500.17. If more than 5,000 New York residents are notified at one time, consumer reporting agencies must also receive notice.

A practical Shieldwise close

The useful takeaway is not “buy more cybersecurity.” It is to build a small, living program: know the records, limit access, train the people, manage the vendors, protect the paper and devices, and rehearse the first call when something goes wrong. That is a manageable project for a one-office shop, and it gives your attorney or insurer something concrete to review.

Shieldwise provides document-preparation and workflow tools, not legal advice or attorney representation. This article is research, not counsel, and it cannot determine whether the SHIELD Act applies to your business or whether your safeguards satisfy the law. Confirm your facts, contracts, and response plan with a licensed New York attorney.

See what a New York starting point could look like →

When you're ready, see plan options →. The generated working document is a starting point grounded in the cited New York law; review it with counsel for your particular operations and obligations.