In 2019, New York expanded its data protection framework significantly with the enactment of the Stop Hacks and Improve Electronic Data Security Act — better known as the NY SHIELD Act. For businesses that collect information about New York residents, NY SHIELD Act compliance for businesses and data protection is now a legal obligation, not a best practice. The law broadened the state’s data breach notification requirements and, crucially, imposed affirmative data security obligations on covered businesses for the first time. One of those obligations directly involves the secure destruction of sensitive documents.
Whether your business is a Manhattan law firm, a Long Island real estate brokerage, a healthcare network serving Westchester County, or an e-commerce company based in Brooklyn that ships products nationwide, if you collect or maintain private information about New York residents, the SHIELD Act applies to you. This guide explains the law’s key requirements, how they intersect with document shredding obligations, and what steps your business should take to achieve NY SHIELD Act compliance.

What Is the NY SHIELD Act?
The NY SHIELD Act amended New York’s General Business Law to expand data breach notification requirements and impose data security requirements on businesses that own or license computerized private information about New York residents. Key provisions include:
- Expanded definition of private information: The law broadened what counts as “private information” beyond Social Security numbers to include username/password combinations, biometric information, account numbers with access codes, and more.
- Expanded definition of breach: A “breach” now includes unauthorized access to private information, not just unauthorized acquisition — a critical distinction that makes more incidents reportable.
- Affirmative data security obligations: Most significantly, the SHIELD Act requires businesses to implement a “reasonable data security program.” This is a first for New York law — previously, data security was addressed only reactively through breach notification.
- Applicability: The law applies to any person or business that owns or licenses computerized data including private information about a New York resident — regardless of where the business is located.
What Is a “Reasonable Data Security Program” Under the SHIELD Act?
New York SHIELD Act shredding and broader data security obligations center on the requirement to implement a reasonable data security program. The law identifies specific safeguards that such a program should include:
Administrative Safeguards:
- Designate one or more employees to coordinate the security program
- Identify reasonably foreseeable internal and external risks
- Assess the sufficiency of existing safeguards to control those risks
- Train and manage employees in security practices
- Select service providers capable of maintaining appropriate safeguards (and require them to maintain safeguards by contract)
Technical Safeguards:
- Assess network and software design risks
- Detect, prevent, and respond to attacks or intrusions
- Protect against unauthorized access during or after collection, transportation, and destruction of data
Physical Safeguards:
- Assess risks of information storage and disposal
- Detect, prevent, and respond to intrusions on physical systems
- Protect against unauthorized access to or use of private information during or after the collection, transportation, and destruction of such information
- Dispose of private information within a reasonable amount of time after it is no longer needed for business purposes by erasing electronic media and shredding, destroying, or otherwise modifying the personal information in those records to make it unreadable or undecipherable
That final physical safeguard point is critical: the SHIELD Act explicitly requires destruction of private information by shredding or equivalent means once it is no longer needed. This is a statutory obligation, not merely a recommendation. Visit our compliance resources to learn more about building a SHIELD Act-compliant data security program.
What Documents Trigger NY Data Protection Law Document Disposal Requirements?
NY data protection law document disposal obligations under the SHIELD Act apply to records containing “private information” about New York residents, including:
- Social Security numbers
- Driver’s license numbers and state ID card numbers
- Account numbers, credit card numbers, or debit card numbers (in combination with access codes or passwords)
- Financial account information sufficient to access an account
- Biometric information
- Username and email address in combination with password or security questions and answers
In practice, this covers a wide range of common business documents: employee records, customer files, credit applications, invoices with account information, HR onboarding documents, and more. Any document containing this information must be disposed of through secure destruction — not simply discarded in recycling or ordinary trash. Learn how our shredding process handles document destruction securely from collection through certified disposal.
SHIELD Act Compliance Business New York: Who Is Exempt?
The SHIELD Act provides a scaled compliance approach for small businesses. A small business — generally defined as a business with fewer than 50 employees, less than $3 million in gross annual revenue in each of the last three fiscal years, or less than $5 million in year-end total assets — may implement a reasonable data security program by implementing “reasonable administrative, technical, and physical safeguards” appropriate to its size and complexity.
This does not mean small businesses are exempt from document destruction requirements. It means they may have flexibility in how they structure their program relative to a large corporation. Even a small business with a few employees that collects New York residents’ Social Security numbers must securely destroy those documents when they are no longer needed. A professional shredding service provides an efficient, affordable way for small businesses to satisfy this obligation without building out complex internal infrastructure.
Consequences of SHIELD Act Non-Compliance
The New York Attorney General enforces the SHIELD Act and can seek:
- Penalties of up to $5,000 per violation for failures to notify after a breach
- Up to $20 per failed notification, with a maximum of $250,000 in aggregate penalties for notification failures
- Civil penalties for violations of data security program requirements
- Injunctive relief requiring corrective action
Beyond enforcement penalties, a publicized data breach in New York — especially one involving documents that should have been destroyed — carries substantial reputational and commercial consequences. Clients and partners increasingly conduct privacy due diligence, and evidence of inadequate document disposal practices can disqualify a business from contracts or vendor relationships.
Contact New York Shredding to discuss how our certified destruction services support your SHIELD Act compliance program and help you maintain documentation of your data security practices.
Integrating SHIELD Act Shredding Requirements into Your Compliance Program
For most New York businesses, the SHIELD Act’s shredding requirement fits naturally into a broader compliance program that may already include HIPAA, GLBA, FACTA, or other obligations. A unified approach — using the same locked consoles, certified destruction process, and Certificate of Destruction documentation for all sensitive document categories — is more efficient and easier to audit than managing separate processes for each law.
Our shredding services are designed to support multi-law compliance for New York businesses, with scalable service options that work for sole proprietors and enterprise organizations alike. We serve all five boroughs, Long Island, Westchester, and the Hudson Valley — providing local service with the documentation standards required for compliance audits.
Why New York Businesses Choose New York Shredding
For over a decade, New York Shredding Document Destruction, Inc. has helped businesses across New York City, Long Island, Westchester, and the Hudson Valley protect their sensitive information through certified, HIPAA-compliant shredding services. Our industrial-grade shredding equipment, locked on-site consoles, and Certificate of Destruction give your business the proof it needs for any compliance audit.
Whether you need scheduled shredding, a one-time purge, or hard drive destruction, we serve all five boroughs and surrounding areas with fast, reliable service. Request a free quote today and get your office on a shredding schedule that keeps you protected year-round.
Ready to get started? Contact New York Shredding for a free quote, or explore our full range of shredding services.

