Skip to content
Cybersecurity

What New York Requires When Customer Data Is Breached

Notification duties attach to any business holding data on New York residents, wherever the business is.

Feature illustration for “What New York Requires When Customer Data Is Breached”

New York's breach notification requirements, expanded by the SHIELD Act, apply to any person or business that owns or licenses computerised data including private information of a New York resident — regardless of where the business is located.

That last point is the one out-of-state businesses miss. Holding data on New Yorkers is sufficient.

What counts as private information

The definition covers combinations such as a name together with a Social Security number, a driver's license number, or a financial account number with the credentials to access it. It also covers a username or email address together with a password or security question answer.

Access, not just acquisition

The SHIELD Act broadened the trigger from unauthorised acquisition to include unauthorised access. A business that can show data was viewed but cannot show it was copied may still have a notifiable event.

Who must be told

Affected individuals must be notified in the most expedient time possible and without unreasonable delay, subject to the legitimate needs of law enforcement. Depending on the number affected, notice also goes to the Attorney General, the Department of State and the Division of State Police, and in larger incidents to consumer reporting agencies.

The security program requirement

Separately, the Act requires businesses holding New Yorkers' private information to maintain reasonable administrative, technical and physical safeguards. The requirements scale with the size and complexity of the business, but they are not optional for small companies — they are proportionate.

What to do before anything happens

Know what personal data you hold and where. Write an incident response plan naming who decides, who contacts counsel, and who talks to customers. Establish a relationship with a forensic firm and with breach counsel in advance.

In an incident, the notification clock runs while you are working out who to call. Deciding that in advance is most of the preparation.

Sources

NY Attorney General — data breach reporting