The data security requirements of New York’s Stop Hacks and Improve Electronic Data Security (SHIELD) Act take effect today.
Key points
- Any person or business owning or licensing New York residents’ private information must implement a data security programme.
- Safeguards include a designated employee, risk assessments, training, vendor oversight, and detection and response.
- Compliance with GLBA, HIPAA or NYDFS Part 500 is treated as compliance.
- Small businesses may scale safeguards to their size and complexity.
The Act applies regardless of where the organisation is located. UK businesses with New York customers or employees should check that their security programme meets these requirements.
Source: New York SHIELD Act, Senate Bill S5575B (NY Senate)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.