EnglishEspañol
New York flag

New York

New York Data Privacy Laws: SHIELD Act & Consumer Rights (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 25 primary sources cited on this page. How we verify our legal content

New York Data Privacy Laws: SHIELD Act & Consumer Rights (2026)

Frequently Asked Questions

Does the SHIELD Act give New York residents the right to delete their data?

No. The SHIELD Act focuses on security safeguards and breach notification. It does not give residents the right to access, correct, or delete data held about them. Those rights would come from a future comprehensive privacy law like the pending NY Privacy Act.

When did the SHIELD Act's 30-day breach notification deadline take effect?

The 30-day deadline took effect immediately when Governor Hochul signed the December 2024 amendments on December 21, 2024. Prior law required notification 'in the most expedient time possible' without a specific deadline.

What new categories of private information does the SHIELD Act cover as of 2025?

Effective March 21, 2025, 'private information' under the SHIELD Act includes medical information (medical history, conditions, treatments, diagnoses) and health insurance information (policy numbers, subscriber IDs, claims and appeals history). These were added by the December 2024 amendment to N.Y. Gen. Bus. Law section 899-aa.

Does the New York City Biometric Law apply to offices outside New York City?

No. NYC Administrative Code Title 22, chapter 12 applies only to commercial establishments operating within New York City. The statewide NY Biometric Privacy Act (S1422A) would extend similar rules across all of New York. The Senate passed S1422A 41-20 on June 3, 2026, and it is now pending in the Assembly; it is not yet law.

What is the DFS cybersecurity regulation and who does it cover?

23 NYCRR Part 500 is the Department of Financial Services cybersecurity rule, covering banks, insurers, mortgage lenders, and other entities licensed under New York's Banking Law, Insurance Law, or Financial Services Law. It requires 72-hour breach reporting to DFS, multi-factor authentication, encryption of nonpublic information, and for large 'Class A' entities, annual independent cybersecurity audits.

Has New York passed a comprehensive consumer privacy law?

Not as of May 2026. Multiple versions of the New York Privacy Act have been introduced since 2019, most recently S3044 and A8158 in the 2025-2026 session. None has passed either chamber. New York does not have CCPA-style consumer rights under state law.

Can a New York employer monitor employee emails and texts without notice?

No. Civil Rights Law section 52-c (effective May 7, 2022) requires private employers with a New York place of business to provide prior written notice to employees before monitoring telephone conversations, email, or internet use. The notice must be acknowledged in writing. The law does not prohibit monitoring; it only requires disclosure.

What is the TAKE IT DOWN Act and how does it affect New York?

The TAKE IT DOWN Act (Pub. L. 119-12) was signed by President Trump on May 19, 2025. It criminalizes publishing nonconsensual intimate imagery including AI-generated deepfakes. As of May 19, 2026, covered online platforms must take down confirmed NCII within 48 hours of a valid request. The FTC enforces the platform takedown obligations. This is federal law and applies to New York residents and businesses.

How do I report a data breach as a New York business?

If a breach of New York residents' private information occurs, notify affected residents within 30 days. If more than 500 residents are affected, provide written notice to the AG, Department of State, and State Police. Report to the AG at ag.ny.gov. If your business is a covered entity under 23 NYCRR Part 500, also file a cybersecurity incident notice through the DFS portal within 72 hours of determining a reportable incident occurred.

Are there penalties for violating the NYC Biometric Identifier Information Law?

Yes. Failure to post required signage carries a $500 penalty with a 30-day cure period. Negligent sale or sharing of biometric data: $500 per violation. Intentional or reckless sale or sharing: $5,000 per violation. The prevailing plaintiff recovers attorney fees in all cases. DCWP also has enforcement authority.

Updates

Corrected the SHIELD Act penalty section (the civil penalty for a notification failure applies only on a knowing or reckless finding, and is the greater of $5,000 or up to $20 per instance capped at $250,000), corrected the employee electronic-monitoring notice law from Labor Law to Civil Rights Law section 52-c, and corrected the Public Health Law section 18 deadlines so the 10-day clock is attached to inspecting records rather than receiving copies.

Updated the statewide Biometric Privacy Act's legislative status (the state Senate passed S1422A 41-20 on June 3, 2026, and it now awaits Assembly action), corrected a mislabeled bill pairing in the key takeaways, clarified that mandatory Department of Financial Services breach notification applies only to DFS-regulated "covered entities" rather than all businesses, and removed a dead duplicate citation link.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Comprehensive refresh: updated SHIELD Act breach notification deadline to 30 days (effective December 21, 2024); added medical and health insurance as new 'private information' categories (effective March 21, 2025); added DFS Part 500 Class A company obligations and all November 2025 phase-in deadlines; added Delta Dental DFS consent order (April 30, 2026, $2.25M); added Root Insurance AG settlement (March 2025, $975K); added Allstate/National General AG lawsuit (March 2025); added Wojeski accounting firm settlement (October 2025, $60K); added multistate car insurer settlement (October 2025, $14.2M); updated biometric section with S1422A committee status; updated NY Privacy Act status to pending committee; added TAKE IT DOWN Act platform obligations effective May 19, 2026; corrected GEICO/Travelers as joint DFS+AG action (November 2024); verified and removed unverifiable Charles Schwab reference.

Reviewed and approved by an editor

Sources and References

  1. SHIELD Act Overview - New York State Attorney General(ag.ny.gov).gov
  2. N.Y. General Business Law Section 899-aa - Breach Notification(nysenate.gov).gov
  3. N.Y. General Business Law Section 899-bb - Data Security Protections(nysenate.gov).gov
  4. Data Security Breach Management - NY Department of State(dos.ny.gov).gov
  5. Breach Notification and Incident Reporting - NY Office of IT Services(its.ny.gov).gov
  6. NYC Biometric Identifier Information Rules - DCWP(rules.cityofnewyork.us).gov
  7. N.Y. Civil Rights Law Section 52-c - Employee Monitoring Notification(nysenate.gov).gov
  8. NYSED Data Privacy and Security Policy - Education Law 2-d(nysed.gov).gov
  9. Parents Bill of Rights for Data Privacy and Security - NYSED(nysed.gov).gov
  10. Patient Rights and Access to Information - NY Department of Health(health.ny.gov).gov
  11. HIV/AIDS Laws and Regulations - NY Department of Health(health.ny.gov).gov
  12. N.Y. Civil Rights Law Section 79-l - Genetic Testing Privacy(nysenate.gov).gov
  13. Senate Bill S3044 - New York Privacy Act (2025)(nysenate.gov).gov
  14. AG James Secures $250,000 from National Amusements (2024)(ag.ny.gov).gov
  15. AG James Secures $975,000 from Root Insurance (2025)(ag.ny.gov).gov
  16. 23 NYCRR Part 500: DFS Cybersecurity Resource Center(dfs.ny.gov).gov
  17. DFS Cybersecurity Settlement with Delta Dental, $2.25 million (April 30, 2026)(dfs.ny.gov).gov
  18. AG James and DFS Secure $11.3 Million from GEICO and Travelers (November 25, 2024)(ag.ny.gov).gov
  19. AG James Sues National General and Allstate Insurance (March 10, 2025)(ag.ny.gov).gov
  20. AG James Secures $14.2 Million from Car Insurers Over Data Breaches (October 14, 2025)(ag.ny.gov).gov
  21. AG James Settles with Wojeski Accounting Firm, $60,000 (October 2025)(ag.ny.gov).gov
  22. AG James Announces $52 Million Multistate Settlement with Marriott (October 2024)(ag.ny.gov).gov
  23. NYC Administrative Code Title 22, Ch. 12: Biometric Identifier Information(codelibrary.amlegal.com)
  24. N.Y. Education Law § 2-d: Student Data Privacy (NY Legislature)(nysenate.gov).gov
  25. TAKE IT DOWN Act: Federal Law Prohibiting NCII (CRS, Congress.gov)(congress.gov).gov
  26. NY S1422A: Biometric Privacy Act (2025-2026 session)(nysenate.gov).gov
  27. Hunton Andrews Kurth: NY AG and NYDFS Announce $11.3M Settlement with GEICO and Travelers(hunton.com)
  28. N.Y. Public Health Law Section 18 - Access to Patient Information(nysenate.gov)
  29. N.Y. General Business Law Section 350-d - Civil Penalty for Deceptive Acts(nysenate.gov)
Share: