New York
New York Data Breach Notification Laws: Reporting Rules & Timelines (2026)
Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 13 primary sources cited on this page. How we verify our legal content

New York requires businesses to notify affected residents within 30 days of discovering a data breach under N.Y. Gen. Bus. Law 899-aa, as amended by the SHIELD Act. Unauthorized access to computerized private information triggers the obligation, and businesses must also alert the NY Attorney General, Department of State, State Police, and major credit bureaus.
New York's data breach notification law is one of the most demanding in the country. The combination of GBL Section 899-aa and the SHIELD Act (GBL Section 899-bb) creates a two-part framework: you must notify promptly when breaches happen, and you must maintain reasonable security to prevent them in the first place. A December 2024 amendment tightened the rules further by adding a firm 30-day notification deadline and eliminating delays for scope investigation.
This guide covers every obligation under New York's breach notification and data security laws, including the 2024 and 2025 amendments, who must comply, what triggers notification, required safeguards, penalties, and how the law interacts with the NYDFS cybersecurity regulation.
What Triggers a Data Breach Notification in New York
Under GBL Section 899-aa, notification is required when there has been unauthorized access to or acquisition of computerized data that compromises the security, confidentiality, or integrity of private information maintained by a business.
The SHIELD Act broadened this trigger significantly in 2019. Before the SHIELD Act, a "breach" required actual acquisition of data. Now, mere unauthorized access is enough to trigger notification obligations, even if the data was not physically taken.
What Counts as Private Information
New York's definition is broader than the first-initial-plus-last-name formula most states use. GBL 899-aa(1)(b) builds on "personal information," which subdivision 1(a) defines as any information concerning a natural person that, because of "name, number, personal mark, or other identifier," can be used to identify that person. "Private information" is that personal information in combination with any one or more of the following data elements, where the data element or the combination is unencrypted, or is encrypted with a key that was also compromised:
- Social Security number
- Driver's license number or non-driver ID card number
- Account number, credit card number, or debit card number in combination with a required security code, access code, password, or other information that would permit access to the financial account
- Account number, credit card number, or debit card number standing alone, but only if circumstances exist where that number could be used to access the individual's financial account without additional identifying information, security code, access code, or password
- Biometric information (fingerprint, voiceprint, retina image, or other unique physical representation)
- Username or email address combined with a password or security question and answer
As of March 21, 2025, the definition also includes:
- Medical information (medical history, mental or physical condition, or treatment/diagnosis by a healthcare professional)
- Health insurance information (policy number, subscriber ID, unique insurer identifier, or application/claims history)
Because the definition keys off "personal information" rather than a name, a record that identifies a person by number or other identifier can qualify even when no name was exposed. A Social Security number or a customer account identifier that singles out an individual can trigger the duty on its own. Publicly available information that is lawfully made available to the general public from federal, state, or local government records is excluded.
The 30-Day Notification Deadline

The December 2024 amendment (S2659B) made two critical changes to notification timing.
First, it established a firm 30-day deadline. Businesses must notify affected New York residents "in the most expedient time possible and without unreasonable delay," but in no event later than 30 days after discovering the breach. This replaced the prior standard of "most expedient time possible," which had no hard deadline.
Second, the amendment eliminated the ability to delay notification while assessing the scope of a breach or restoring system integrity. Under the old law, businesses could take additional time to determine how many people were affected or to fix the vulnerability before notifying anyone. That flexibility is gone. The only remaining exception is for legitimate law enforcement needs, where authorities may request a brief delay to preserve evidence.
These changes took effect immediately upon the governor's signature on December 21, 2024.
Vendor and Service Provider Deadlines
The 30-day clock also applies to vendors and service providers. If a business processes or maintains private information on behalf of another company, it must notify the data owner within 30 days of discovering the breach. The data owner then has its own 30-day window to notify affected individuals.
Who Must Be Notified
New York requires notification to multiple parties. Most of these obligations apply regardless of how many individuals are affected; notifying the three major credit reporting agencies is the exception, required only when more than 5,000 New York residents are notified at one time.
Affected Individuals
Any New York resident whose private information was compromised must receive direct notification. Acceptable methods include:
- Written notice (mail)
- Electronic notice (if the person consented to electronic communications)
- Telephone notification
Substitute Notice
Substitute notice is available when direct notification costs exceed $250,000, the breach affects more than 500,000 people, or the business lacks sufficient contact information. Substitute notice requires all three of the following:
- Email notice to all available addresses
- Conspicuous posting on the company's website
- Notification to major statewide media
Government Agencies
Businesses must notify the following state agencies about the timing, content, and distribution of breach notices, plus the approximate number of affected individuals:
- New York Attorney General (online reporting form)
- New York Department of State, Division of Consumer Protection
- New York State Police
Credit Reporting Agencies
If more than 5,000 New York residents must be notified at one time, the business must also notify the three major consumer reporting agencies (Equifax, Experian, and TransUnion), regardless of which data elements were involved in the breach. This notice covers the timing, content, and distribution of the resident notices, plus the approximate number of affected people.
NYDFS Notification (Financial Services Entities)
The December 2024 amendment initially added the New York Department of Financial Services to the notification list for all businesses. A February 2025 correction (S804) clarified that NYDFS notification is required only for entities that qualify as "covered entities" under 23 NYCRR Part 500. Those entities must comply with the separate 72-hour notification requirement under the NYDFS cybersecurity regulation.
Encryption Safe Harbor

New York provides a safe harbor for encrypted data. If the private information was encrypted and the encryption key was not compromised during the breach, notification is not required.
However, if the unauthorized person also obtained the encryption key, or if there is reason to believe the key was accessed, the full notification obligations apply. This means businesses should store encryption keys separately from the data they protect.
The safe harbor also covers data that has been rendered unreadable or unusable through other security methods, as long as the method used to protect the data was not also compromised.
SHIELD Act Data Security Requirements

The SHIELD Act (GBL Section 899-bb) goes beyond notification. It requires any person or business that owns or licenses private information of New York residents to "develop, implement, and maintain reasonable safeguards to protect the security, confidentiality, and integrity of the private information."
This obligation applies to businesses nationwide, not just those located in New York. If you hold private information of any New York resident, you must comply.
Administrative Safeguards
The SHIELD Act requires administrative measures including:
- Designating one or more employees to coordinate the security program
- Identifying reasonably foreseeable internal and external risks
- Assessing whether existing safeguards control the identified risks
- Training and managing employees in security practices and procedures
- Selecting service providers capable of maintaining appropriate safeguards and requiring those protections by contract
- Adjusting the security program in light of business changes or new circumstances
Technical Safeguards
Required technical measures include:
- Assessing risks in network and software design
- Assessing risks in information processing, transmission, and storage
- Detecting, preventing, and responding to attacks or system failures
- Regularly testing and monitoring the effectiveness of key controls, systems, and procedures
Physical Safeguards
Required physical measures include:
- Assessing risks of information storage and disposal
- Detecting, preventing, and responding to intrusions
- Protecting against unauthorized access during or after collection, transportation, and destruction of information
- Disposing of private information within a reasonable time after it is no longer needed, by erasing electronic media so the information cannot be read or reconstructed
Small Business Compliance
The SHIELD Act includes a scaled compliance option for small businesses, defined as having fewer than 50 employees, less than $3 million in gross annual revenue for the last three fiscal years, or less than $5 million in year-end total assets. A small business satisfies the safeguard requirements if its security program is appropriate for the size and complexity of the business, the nature and scope of its activities, and the sensitivity of the information it collects.
Deemed Compliance
Businesses already subject to and in compliance with certain federal regulations are deemed compliant with the SHIELD Act's safeguard requirements. This includes entities regulated under HIPAA, the Gramm-Leach-Bliley Act, or the NYDFS cybersecurity regulation (23 NYCRR Part 500).
NYDFS Cybersecurity Regulation: Additional Layer for Financial Services
Financial services entities regulated by the New York Department of Financial Services face additional obligations under 23 NYCRR Part 500. Key differences from the SHIELD Act include:
- A stricter 72-hour notification deadline to DFS (compared to 30 days under GBL 899-aa)
- Mandatory written cybersecurity policies
- Required annual penetration testing and bi-annual vulnerability assessments
- Appointment of a Chief Information Security Officer (CISO)
- Annual compliance certification to DFS
The November 2023 amendment to Part 500 further strengthened these requirements. Covered entities must comply with both the SHIELD Act and Part 500, with the stricter standard applying in any area of overlap.
Penalties and Enforcement

The New York Attorney General has exclusive authority to enforce both the breach notification law and the SHIELD Act safeguard requirements.
Notification Violations
Courts may award the affected person's actual costs or losses for a failure to provide timely notification, through the Attorney General's enforcement action. If the court finds the violation was knowing or reckless, it may also impose a civil penalty of the greater of $5,000 or $20 per instance of failed notification, capped at $250,000. Absent a knowing or reckless finding, there is no separate civil penalty tier; recovering actual costs or losses through the AG's action is the only monetary remedy.
Safeguard Violations
For failure to maintain reasonable safeguards under the SHIELD Act, courts may impose penalties of up to $5,000 per violation. There is no statutory cap on the total amount.
Statute of Limitations
The Attorney General must bring an enforcement action within three years of either the date the Attorney General became aware of the violation or the date of the notice sent to the state agencies under GBL 899-aa(8)(a), whichever occurs first. Where a breach notice was filed, that filing date is ordinarily what starts the clock. In no event may an action be brought more than six years from the date the company discovered the breach of private information, unless the company took steps to hide the breach.
No Private Right of Action
GBL 899-aa does not let individuals sue on their own. Only the New York Attorney General may bring an enforcement action for a violation. Within that AG-brought action, a court may award the affected person's actual costs or losses, including consequential financial losses, but there is no separate lawsuit an individual can file, no statutory damages provision, and no ability to recover attorney's fees under the breach notification statute.
Recent Enforcement Actions
The Attorney General has actively enforced these laws:
- Root Insurance (2025): Paid $975,000 after a vulnerability exposed approximately 45,000 New Yorkers' driver's license numbers, which were used for fraudulent unemployment claims.
- Wojeski & Company (2025): Paid $60,000 after a ransomware attack exposed client data and the firm waited 18 months to notify victims.
- National Amusements (2024): Paid $250,000 for failing to protect employee personal information.
- Albany ENT & Allergy Services (2024): Paid $500,000 plus $2.25 million for inadequate security practices that exposed patient medical data.
These settlements demonstrate that the Attorney General pursues penalties well beyond the statutory minimums by combining notification violations with safeguard failures and seeking injunctive relief.
Exemptions and Special Cases
Several situations receive special treatment under New York law:
- Good faith employee access: An inadvertent disclosure by an authorized employee does not trigger notification, provided the private information is not expected to be misused and the business takes reasonable steps to prevent further unauthorized access.
- Law enforcement delays: Notification may be delayed at the request of law enforcement if early notice would impede a criminal investigation.
- Already regulated entities: A business that notifies affected people under HIPAA/HITECH, the Gramm-Leach-Bliley Act, 23 NYCRR Part 500, or another applicable federal or New York data security rule does not have to send those same people a second notice under GBL 899-aa. The exemption stops there. Under GBL 899-aa(2)(b), the business must still notify the Attorney General, the Department of State, and the State Police under subdivision 8(a), and the consumer reporting agencies under subdivision 8(b) when more than 5,000 New York residents are notified at one time.
- HIPAA covered entities: Subdivision 9 adds a separate duty. A covered entity that reports a breach to the U.S. Secretary of Health and Human Services under HIPAA or HITECH must provide that notification to the New York Attorney General within five business days of notifying the Secretary, including where the breach involved information that is not "private information" under GBL 899-aa.
How New York Compares to Other States
New York's 30-day notification deadline places it among the stricter states. For comparison:
- Colorado, Florida, Maine, and Washington also set a 30-day outer limit for notifying affected residents
- Alabama, Ohio, and Indiana each allow 45 days
- Texas allows 60 days to notify individuals, though its Attorney General must be told within 30 days when at least 250 residents are affected
- Some states still have no specific deadline, requiring only notification "without unreasonable delay"
New York stands out for the SHIELD Act's separate safeguard requirements, its expanded definition of private information (including biometric and now medical data), and its active enforcement history.
This article provides general legal information about New York data privacy laws and breach notification requirements. It is not legal advice, and it does not create an attorney-client relationship. Data breach response involves time-sensitive obligations. Consult a qualified attorney licensed in New York for guidance specific to your situation.
More New York Laws
Frequently Asked Questions
How quickly must a business report a data breach in New York?
As of December 21, 2024, businesses must notify affected New York residents within 30 days of discovering a breach. The previous standard of "most expedient time possible" had no hard deadline. The 30-day clock starts running at discovery, and businesses can no longer delay to assess the scope of the breach or restore system integrity. The only exception is a delay requested by law enforcement for a criminal investigation.
What information triggers New York data breach notification requirements?
New York keys the trigger to "personal information," meaning any information that can identify a person by name, number, personal mark, or other identifier, combined with one of these data elements: Social Security number, driver's license or state ID number, an account or credit/debit card number together with a required security or access code, an account or card number standing alone where circumstances exist that it could be used to reach the financial account without anything further, biometric data, or username/email with a password. As of March 21, 2025, medical information and health insurance information are also covered. Because the definition does not require a name, data that identifies a person by number alone can trigger notification.
Does the SHIELD Act apply to businesses outside New York?
Yes. The SHIELD Act applies to any person or business that owns or licenses computerized data containing private information of New York residents, regardless of where the business is located. A company in California or Texas that holds data belonging to New York residents must comply with both the notification requirements and the safeguard requirements.
What is the encryption safe harbor under New York breach notification law?
If the breached data was encrypted and the encryption key was not compromised, notification is not required. However, if the encryption key was also accessed or acquired during the breach, the safe harbor does not apply and full notification is required. Businesses should store encryption keys separately from the data they protect to preserve this defense.
What penalties can the New York Attorney General impose for breach notification violations?
A civil penalty of $20 per person not notified (capped at $250,000) or $5,000 per violation, whichever is greater, is available only if a court finds the notification failure was knowing or reckless. Otherwise, the only monetary remedy for a late or missed notification is the affected person's actual costs or losses, recovered through the Attorney General's action. For failure to maintain reasonable safeguards under the SHIELD Act, penalties are $5,000 per violation with no statutory cap. In practice, settlements have been much larger. The AG secured $975,000 from Root Insurance and $2.75 million from Albany ENT & Allergy Services by combining notification failures with safeguard violations.
Affected by a data breach or biometric privacy violation?
If your personal data was exposed in a breach, or your fingerprint or face scan was collected without your consent, you may be eligible to join a claim for compensation. Find out for free, with no obligation.
Updates
Corrected the definition of "private information" (New York keys the trigger to identifying information generally, not to a name plus a data element), fixed the Alabama comparison to 45 days and removed an inaccurate "strictest state" claim, restated the enforcement statute of limitations to run from the earlier of the Attorney General’s awareness or the agency notice date with the six-year outer limit measured from the company’s discovery, and added the state-agency and five-business-day HIPAA notices that entities regulated under HIPAA, GLBA or NYDFS still owe.
Corrected this page's description of enforcement under New York's breach notification law: only the state Attorney General can bring an action (there is no private right of action for individuals), the civil penalty of $5,000-or-$20-per-instance (capped at $250,000) applies only where a court finds the violation knowing or reckless, and notice to the three major credit reporting agencies is required whenever more than 5,000 New York residents are notified at once, not only when Social Security numbers are involved.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
New York General Business Law
§ 899-aaNotification; person without valid authorization has acquired private informationIn forcecited in 3 of our articles
Notification; person without valid authorization has acquired private information. 1. As used in this section, the following terms shall have the following meanings: (a) "Personal information" shall mean any information concerning a natural person which, because of name, number, personal mark, or other identifier, can be used to identify such natural person; (b) "Private information" shall mean either: (i) personal information consisting of any information in combination with any one or more of the following data elements, when either the data element or the combination of personal information plus the data element is not encrypted, or is encrypted with an encryption key that has also been accessed or acquired: (1) social security number; (2) driver's license number or non-driver identification card number; (3) account number, credit or debit card number, in combination with any required security code, access code, password or other information that would permit access to an individual's financial account; (4) account number, credit or debit card number, if circumstances exist wherein such number could be used to access an individual's financial account without additional…
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at legislation.nysenate.gov
Also relied on in: New York Data Privacy Laws: SHIELD Act & Consumer Rights (2026), New York Biometric Privacy Laws: Collection, Consent & Penalties (2026)
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- GBL Section 899-aa - NY Breach Notification Statute(nysenate.gov).gov
- GBL Section 899-bb - SHIELD Act Data Security Requirements(nysenate.gov).gov
- NY Attorney General - SHIELD Act Guidance(ag.ny.gov).gov
- NY AG Data Breach Reporting Form(formsnym.ag.ny.gov).gov
- S2659B - December 2024 Amendment (30-Day Deadline)(nysenate.gov).gov
- S804 - February 2025 NYDFS Notification Clarification(nysenate.gov).gov
- NY Dept of State - Data Security Breach Management(dos.ny.gov).gov
- NYDFS 23 NYCRR Part 500 - Cybersecurity Regulation(dfs.ny.gov).gov
- NY OIT - Breach Notification and Incident Reporting(its.ny.gov).gov
- AG James - Root Insurance $975K Settlement(ag.ny.gov).gov
- AG James - Wojeski & Company $60K Settlement(ag.ny.gov).gov
- AG James - National Amusements $250K Settlement(ag.ny.gov).gov
- NY AG press release: $2.25M Albany ENT & Allergy Services settlement(ag.ny.gov).gov
- Ala. Code 8-38-5 - Notice of Security Breach, Individuals Affected (45 days)(alison.legislature.state.al.us)
- 10 M.R.S. 1348 - Maine Notice of Risk to Personal Data (30 days)(legislature.maine.gov)
- Fla. Stat. 501.171 - Security of Confidential Personal Information (30 days)(leg.state.fl.us)
- RCW 19.255.010 - Washington Notice of Security Breaches (30 days)(app.leg.wa.gov)
- Ohio Rev. Code 1349.19 - Private Disclosure of Security Breach (45 days)(codes.ohio.gov)
- Ind. Code 24-4.9-3-3 - Time of Disclosure or Notification (45 days)(iga.in.gov)
- Tex. Bus. & Com. Code 521.053 - Notification Required Following Breach (60 days)(statutes.capitol.texas.gov)
- Colo. Rev. Stat. 6-1-716 - Notification of Security Breach (30 days)(olls.info)