When most financial firms think about New York’s Department of Financial Services (DFS) Cybersecurity Regulation — officially 23 NYCRR 500 — they focus on firewalls, encryption, and multi-factor authentication. But the regulation’s requirements extend beyond digital assets. If your firm maintains nonpublic information (NPI) in paper format — client account statements, loan documents, insurance applications, or employee records — then NY DFS cybersecurity physical records disposal is an active compliance concern. Understanding how to properly destroy physical records under this framework is essential for New York financial institutions, insurance companies, and any other DFS-regulated entity.
New York’s DFS Cybersecurity Regulation was enacted in 2017 and significantly amended in 2023, creating some of the most comprehensive state-level cybersecurity mandates in the United States. While the regulation primarily governs digital systems and data, its broad definition of nonpublic information and its emphasis on data minimization create clear obligations around how physical records containing NPI must ultimately be destroyed. For compliance officers and risk managers at regulated financial entities across Manhattan, Brooklyn, Long Island, and Westchester, this means that your shredding program is part of your cybersecurity posture.
What Is 23 NYCRR 500 and Who Does It Apply To?
23 NYCRR 500 applies to any entity operating under a DFS license, registration, charter, certificate, permit, or accreditation — including banks, insurance companies, mortgage servicers, money transmitters, and other financial services firms doing business in New York. The regulation defines “nonpublic information” broadly to include any information about an individual that can be used to identify them, combined with financial data, health information, or certain account credentials.
Physical records that contain NPI are subject to the regulation’s data governance requirements, even if the regulation’s specific technical controls (like encryption) only explicitly reference electronic systems. The regulation requires covered entities to implement policies and procedures for the secure disposal of NPI — and regulators have made clear that this includes paper documents. Key provisions include:
- Section 500.3: Cybersecurity Policy — must address “disposal of nonpublic information”
- Section 500.13: Limitations on Data Retention — NPI must be destroyed after it is no longer needed for business or legal purposes
- Section 500.19: Maintenance of audit trails and documentation of disposal activities
- Section 500.22: Annual certification to DFS that the entity complies with the regulation’s requirements
Firms that fail to address physical records in their cybersecurity policies risk examination findings and, in more serious cases, enforcement action by DFS.
How Physical Records Fit Into Your Cybersecurity Policy
Under 23 NYCRR 500.3, every covered entity must maintain a written cybersecurity policy approved by a senior officer. That policy must address the disposal of nonpublic information in whatever form it exists — including paper. This means your firm’s compliance program needs to clearly articulate:
- What types of paper records contain NPI
- How long those records must be retained under applicable law
- What destruction method will be used at end of retention (e.g., cross-cut or micro-cut shredding)
- Who is responsible for initiating and approving record destruction
- How destruction events are documented (Certificate of Destruction)
A well-structured records management policy that integrates physical destruction into the broader cybersecurity framework will satisfy DFS examiners and reduce the risk of findings during a regulatory review. Importantly, the Certificate of Destruction provided by a certified shredding vendor serves as the audit trail documentation required under Section 500.19 of the regulation. This documentation should be retained as part of your cybersecurity compliance records.
Data Minimization and the Duty to Destroy
The 2023 amendments to 23 NYCRR 500 strengthened the data minimization requirements under Section 500.13. Covered entities are now required to track where NPI lives in their systems — and by extension, in their physical filing systems — and must implement procedures to destroy information that is no longer needed. This is not just a best practice; it is a regulatory obligation.
For New York financial firms, this means conducting a periodic review of physical records to identify documents that have passed their retention period and must be destroyed. Common categories that need attention include:
- Completed loan files and mortgage applications beyond the applicable retention window
- Insurance policy files for expired or terminated policies
- Client account opening documents superseded by updated records
- Employee personnel files for departed employees
- Printed reports from core banking or insurance systems containing customer NPI
By working with a certified shredding vendor on a scheduled shredding program, your firm can automate this process — ensuring documents are destroyed on schedule without relying on staff to remember or initiate destruction manually.
Choosing a Shredding Vendor That Meets DFS Standards
Not all shredding vendors are created equal. For DFS-regulated entities, it is important to work with a vendor that understands compliance requirements and can provide the documentation your cybersecurity policy requires. When evaluating a shredding vendor, look for:
- NAID AAA Certification: The National Association for Information Destruction certification verifies that the vendor’s destruction processes meet rigorous industry standards for security and chain of custody.
- Certificate of Destruction: Every shredding event should generate a Certificate of Destruction with the date, description of materials destroyed, and the vendor’s attestation — this document is your audit trail.
- Locked on-site consoles: Before destruction, documents should be stored in tamper-resistant locked containers placed at your office location, preventing unauthorized access during the collection period.
- Vendor vetting: Your cybersecurity policy may require due diligence on third-party vendors who access NPI — ask your shredding vendor for their security certifications and background check procedures.
Working with a local New York shredding company also simplifies logistics for multi-location firms operating across the five boroughs, Long Island, and Westchester County. Local providers can service all your office locations on a coordinated schedule without the inconsistencies that sometimes arise with national providers.
Integrating Shredding Into Your Annual DFS Certification
Each year, covered entities must certify to DFS that they are in compliance with 23 NYCRR 500. This certification is signed by the Chief Information Security Officer (CISO) or equivalent and carries significant personal and organizational accountability. As part of your certification preparation, your compliance team should verify that:
- The cybersecurity policy explicitly addresses physical records disposal
- A written retention and destruction schedule exists for all NPI-containing paper records
- Destruction events from the prior year are documented with Certificates of Destruction
- Your shredding vendor’s credentials have been reviewed during the year
- Any gaps identified in physical record disposal have been remediated
If your firm is undergoing a DFS examination, examiners may request evidence of your physical records disposal program as part of their cybersecurity review. Having organized documentation — including vendor agreements, destruction schedules, and Certificates of Destruction — will demonstrate that your program is mature and well-managed.
Common Compliance Gaps in Physical Records Management Under 23 NYCRR 500
During DFS examinations and internal audits, firms frequently discover gaps in how their cybersecurity program addresses physical records. Some of the most common shortfalls include failing to update the cybersecurity policy to explicitly reference paper records disposal, relying on informally trained staff to make ad hoc disposal decisions without a written procedure, and failing to maintain Certificates of Destruction as part of the firm’s audit documentation. These are not trivial oversight issues — regulators treat them as evidence of an immature or incomplete cybersecurity program.
Another common gap is the absence of a periodic review process for physical records nearing their retention expiration. In a digital-first environment, it is easy to forget that filing cabinets and archive boxes full of paper documents need to be reviewed and destroyed on a regular cycle. Implementing an annual or semiannual “records purge” as part of your cybersecurity program calendar — with specific personnel assigned to review and authorize destruction — closes this gap and ensures that end-of-retention destruction is a systematic process rather than an afterthought.
Finally, many firms do not adequately vet their shredding vendors from a DFS compliance perspective. Asking a vendor to provide their NAID certification, reviewing their chain-of-custody procedures, and including appropriate security requirements in the service contract are all steps that demonstrate the vendor oversight the regulation requires. Contact New York Shredding to learn about our credentials and the documentation we provide to regulated clients.
Why New York Businesses Choose New York Shredding
For over a decade, New York Shredding Document Destruction, Inc. has helped businesses across New York City, Long Island, Westchester, and the Hudson Valley protect their sensitive information through certified, HIPAA-compliant shredding services. Our industrial-grade shredding equipment, locked on-site consoles, and Certificate of Destruction give your business the proof it needs for any compliance audit.
Whether you need scheduled shredding, a one-time purge, or hard drive destruction, we serve all five boroughs and surrounding areas with fast, reliable service. Request a free quote today and get your office on a shredding schedule that keeps you protected year-round.
Ready to get started? Contact New York Shredding for a free quote, or explore our full range of shredding services.

