New York Doesn't Have a Comprehensive Privacy Law — But Don't Relax Yet
If you've been comparing New York to California, Virginia, or Colorado, it's worth stopping that comparison entirely. New York has never passed a comprehensive consumer privacy law of that kind. What it has instead is the SHIELD Act, a data security statute, and it asks something completely different of your business.
What SHIELD Actually Requires
The Stop Hacks and Improve Electronic Data Security Act applies to any business holding the private information of a New York resident, regardless of where that business itself is located. It doesn't grant consumers a right to access their data, correct it, or opt out of anything. Instead, it requires businesses to develop, implement, and maintain reasonable administrative, technical, and physical safeguards to protect that data.
Reasonable administrative safeguards include designating someone to coordinate your security program and identifying foreseeable risks. Technical safeguards include things like encrypting data in transit and monitoring your network. Physical safeguards cover how you store and eventually dispose of records containing private information.
Small Business Flexibility
If your store has fewer than 50 employees, less than $3 million in gross annual revenue in each of the prior three years, or less than $5 million in year-end total assets, the law lets you scale your security program to match your actual size and complexity, rather than requiring the same infrastructure a large enterprise would need. It's still a real requirement, just a proportionate one.
What Counts as Protected Data Just Got Bigger
As of March 21, 2025, the definition of protected "private information" under SHIELD expanded to include medical history, diagnoses, and health insurance policy and claims data. If your store sells anything health-adjacent, supplements, wellness products, medical devices, this expansion is worth knowing about specifically, since it widens what you're responsible for protecting.
Penalties
The New York Attorney General enforces SHIELD exclusively; there's no private right of action. Failing to maintain reasonable safeguards carries a civil penalty of up to $5,000 per violation. Separately, failing to properly notify affected New York residents after a data breach carries its own penalty of $20 per instance of failed notification, capped at $250,000.
The Real Risk Isn't a Missing Policy — It's a Missing Program
This is the detail that trips up sellers who assume having a privacy policy is enough. SHIELD isn't primarily about what your policy says. It's about whether you actually have a documented security program behind it, something you could produce and describe if ever asked, not just a page of text on your website.
Check Your New York Exposure
All information in this article is sourced from New York General Business Law §§ 899-aa and 899-bb, and guidance published by the New York Attorney General's office. Regulens is informational only and this article is not legal advice. Speak to a licensed privacy attorney about your specific compliance situation.
Regulens tracks New York as part of its ongoing state-by-state privacy coverage. Your store's readiness is calculated based on your actual inputs and current policy documents.
Free to check, takes three minutes, no credit card needed. Not legal advice. Informational only.
Check your store's New York privacy readiness at getregulens.com
Further Reading
Tennessee's Privacy Law Has an Escape Hatch No Other State Offers
Tennessee lets businesses build a legal defense into their compliance program itself. Here's how TIPA's threshold works, and the one framework that can protect you even if something goes wrong.
Minnesota's Privacy Law Gives Consumers a Right No Other State Grants
Minnesota lets consumers ask exactly which companies you sold their data to, by name. Most state privacy laws only require a general disclosure. Here's what that actually means for a Shopify store.