The New York State “Stop Hacks and Improve Electronic Data Security Act” (SHIELD Act) Becomes Effective March 21, 2020: Is Your Organization Ready to Achieve Compliance?
Thursday, February 6, 2020Time is running out. The effective date of New York’s cybersecurity law mandating that organizations implement an information security program to protect “private information” of New York State residents, including employee and consumer data, is now only 45 days away. New York’s law requires the implementation of a cybersecurity program, including reasonable protective measures such as risk assessments, workforce training and incident response planning and testing. Businesses should immediately take steps to comply with the Act’s requirements effective March 21, 2020. New York’s law covers all employers, individuals or organizations, regardless of size or location, which collect private information on New York State residents.
As we first reported last year at the time of the Act’s passage, the “Stop Hacks and Improve Electronic Data Security Act” (SHIELD ACT), signed into law on July 25, 2019, requires implementation of an information security program to protect “private information” defined as:
The law broadly requires that “any person or business” that owns or licenses computerized data which includes private information of a New York State resident “shall develop, implement and maintain reasonable safeguards to protect the security, confidentiality and integrity of the private information.”
In order to achieve compliance, an organization must implement a data security program that includes:
All organizations that collect private information must independently satisfy the SHIELD Act three-part standard for protecting sensitive individual information. However, regulated organizations that are covered by and in compliance with the Gramm-Leach-Bliley Act, the Health Insurance Portability and Accountability Act (HIPAA), and/or the New York State Department of Financial Services cybersecurity regulations shall be deemed in compliance with the SHIELD Act.
Failure to implement a compliant information security program is enforced by the New York State Attorney General and may result in injunctive relief and civil penalties. We can expect vigorous enforcement because the Attorney General submitted the SHIELD Act as an agency sponsored bill to keep pace with the use and dissemination of private information. Press releases from the New York State Office of the Attorney General are here: June 17 and July 25, 2019. Any enforcement activity by the Attorney General’s office will also have other damaging consequences, such as damaging publicity and raise supply chain issues with the firm’s business partners. Private litigants bringing data breach lawsuits will almost certainly assert that any non-compliance shows a disregard of standards of due care in asserting negligence claims for failing to protect sensitive individual information. See our August 12, 2019 Client Advisory for What Businesses and Employers Should Do Now.