The Stop Hacks and Improve Electronic Data Security (SHIELD) Act is designed to protect the personal data of all New York residents. Compliance with the New York SHIELD Act is expected of every business collecting personal data from a New York resident - regardless of whether the entire collecting data is located in New York State. This includes third-party service providers, which means your Third-Party Risk Management program should be adjusted to address the information security standards of the NY SHIELD Act.

Include NY SHIELD Act Data Breach Notification Protocols in your Incident Response Plan

Following a data breach, the NY SHIELD Act expects businesses to alert the following parties as quickly as possible: Impacted individuals.

Related Articles