Skip to content

The NY SHIELD Act for Tax Preparers: Reasonable Safeguards, the Small-Business Test, and the GLBA Shortcut

Checked against the primary record: July 19, 2026Statute enacted: July 25, 2019 (L. 2019, ch. 117, SHIELD Act); safeguards duty effective March 21, 2020

Dolev Arama, Founder/Last updated July 20, 2026/Every figure primary-sourced

The short answer

New York's SHIELD Act requires any person or business holding a New York resident's private information to maintain reasonable safeguards, wherever the firm sits. For a tax practice there is a shortcut: a firm subject to, and in compliance with, the federal Safeguards Rule is deemed compliant with that duty. The shortcut only works if the federal program actually exists.

This page explains the New York SHIELD Act's data-security duty and how it interacts with the federal Safeguards Rule for tax and accounting firms. It is general information, not legal advice for your specific situation. For that, consult a qualified professional.

What does the SHIELD Act actually require?

The SHIELD Act (the Stop Hacks and Improve Electronic Data Security Act) is New York's data-security law, signed July 25, 2019 as Chapter 117 of that year's laws. It did two things: it widened the state's breach-notification statute, and it created a standing safeguards duty, codified at N.Y. Gen. Bus. Law section 899-bb under the heading "Data security protections." By the act's own effective-date clause, the safeguards duty has applied since March 21, 2020 (S5575B).

The duty itself is one sentence: "Any person or business that owns or licenses computerized data which includes private information of a resident of New York shall develop, implement and maintain reasonable safeguards to protect the security, confidentiality and integrity of the private information including, but not limited to, disposal of data." Read the subject of that sentence carefully. It keys the duty to the resident whose data you hold, not to where your office is. A preparer in New Jersey or Texas with one New York client's file is inside it, and "private information" reaches the exact things a tax file is made of: Social Security numbers, driver's license numbers, and financial account numbers held with identifying information.

What counts as "reasonable safeguards"? The statute does not hand you a checklist. It offers two routes to compliance, and the second is the one most coverage skips: either you implement a data security program with administrative, technical, and physical safeguards along the lines the statute sketches, or you are already regulated under a listed federal or state data-security regime and actually comply with it, in which case New York deems you compliant. That second route is this page's subject, because tax preparers are on the federal list.

First, the part that makes this a duty worth taking seriously. New York's safeguards requirement stands on its own: it does not wait for federal enforcement moods, and the office that enforces it brings data-security cases. In October 2025, Attorney General Letitia James announced a settlement with a public accounting firm over exactly this ground. The record is worth reading closely, because it is the closest thing the niche has to a picture of what a state data-security action against an accounting practice looks like.

At a glance

NY Attorney General settlement: Wojeski & Company (October 2025)

Firm
Wojeski & Company, described in the announcement as "a public accounting firm"
Announced
October 20, 2025, by New York Attorney General Letitia James
The incidents
A ransomware intrusion discovered July 28, 2023, which began with a phishing email, and a second exposure Wojeski was notified of on May 31, 2024, when an employee of a firm hired to help with the investigation sent data to unauthorized addresses. 4,726 New York residents affected in the first incident, 267 in the second
Data involved
Names, dates of birth, Social Security and driver's license numbers, financial account numbers, email addresses, phone numbers, and medical benefits and entitlement information
What the investigation found
Customers' Social Security numbers were not encrypted in parts of the company's network, and Wojeski did not notify customers of either breach until November 2024, a year and a half after client data was first put at risk
Outcome
A settlement requiring the firm, among other terms, to maintain "a comprehensive information security program," encrypt personal data, inventory where that data lives, and keep an incident response plan that gets notice out on time. The announcement also includes a payment to the state; the amount is in the linked record
Prepared by Safeguards Monitor from the Attorney General's October 20, 2025 announcement, checked July 19, 2026.

What the record teaches is plain, and it is not ridicule; Wojeski was attacked by criminals, and its second exposure came through a firm hired to help with the cleanup. Read the settlement's required terms as a list: a security program, encryption, a data inventory, a response plan that gets notice out on time. What New York required of one firm going forward is a picture of what the office enforcing the safeguards duty expects of every firm up front. "As an accounting firm, Wojeski should have taken stronger measures to protect New Yorkers' personal data and prevent data breaches that could lead to identity theft and other types of fraud," the announcement reads. That sentence is addressed to a profession, not one firm.

Does the small-business rule exempt my firm?

No. There is no small-business exemption in the SHIELD Act's safeguards duty; there is a small-business calibration, and the difference matters. Start with who qualifies. A "small business" under the statute is any person or business with:

  • "(i) fewer than fifty employees;"
  • "(ii) less than three million dollars in gross annual revenue in each of the last three fiscal years; or"
  • "(iii) less than five million dollars in year-end total assets, calculated in accordance with generally accepted accounting principles."

The connector is "or." Meeting any one of the three prongs makes a firm a small business under the statute; a solo preparer qualifies on the first prong alone, whatever the other two say. We flag this because guides in the field state the test as if a firm had to satisfy all three conditions together. The statute's own word, at section 899-bb(1)(c), is "or," and a test you misread as a conjunction is a test you may wrongly think you failed.

Now what qualifying actually changes. A second error class in the field presents the small-business clause as an exception, as if small firms were excused. The clause says something narrower: a small business complies with the statute's own program path "if the small business's security program contains reasonable administrative, technical and physical safeguards that are appropriate for the size and complexity of the small business, the nature and scope of the small business's activities, and the sensitivity of the personal information the small business collects from or about consumers." That is scaling, not release. The duty sentence in the previous section applies to a small business exactly as it applies to a national chain; the yardstick for "reasonable" adjusts to the firm. And note the clause's cross-reference: the calibration attaches to the statute's build-your-own-program route. A firm taking the deemed-compliance route in the next section is measured against its federal program instead.

You're covered by GLBA. Are you already SHIELD-compliant?

Here is the clause the rest of this page has been walking toward. A tax practice is a "financial institution" under the federal Safeguards Rule; the rule's scope section lists "tax preparation firms" by name, and its definitions carry an example holding that an accountant or other tax preparation service in the business of completing income tax returns is one (16 CFR part 314; the coverage chain is walked in full in our federal Safeguards Rule pillar). The Safeguards Rule is a regulation promulgated under Title V of the Gramm-Leach-Bliley Act. New York's legislature looked at firms in exactly that position and wrote this:

Primary record

N.Y. Gen. Bus. Law § 899-bb · Data security protections

"Compliant regulated entity" shall mean any person or business that is subject to, and in compliance with, any of the following data security requirements: (i) regulations promulgated pursuant to Title V of the federal Gramm-Leach-Bliley Act (15 U.S.C. 6801 to 6809), as amended from time to time; [...] A person or business shall be deemed to be in compliance with paragraph (a) of this subdivision if it either: (i) is a compliant regulated entity as defined in subdivision one of this section; or [...]
Prepared by Safeguards Monitor from GBS § 899-bb, subdivisions 1(a) and 2(b) (nysenate.gov), two passages joined and trailed at the bracketed breaks, current as of July 2026.
L. 2019, ch. 117 (SHIELD Act), eff. March 21, 2020 · Verified July 19, 2026

Put the two passages together and the chain is short. Your firm is subject to GLBA data-security regulations because the Safeguards Rule covers tax preparation firms. If it is also in compliance with them, it is a "compliant regulated entity," and New York deems it in compliance with the reasonable-safeguards duty. One program, two jurisdictions. That is the double duty a federal Written Information Security Plan performs for a practice with New York clients, and no equivalent sentence exists in the federal rule pointing the other way.

Now read the highlighted words the way a regulator would. The entry condition has two parts, joined by "and": subject to, and in compliance with. Being covered by the federal rule is the easy half; every paid preparer clears it. The second half is a present-tense fact about your firm. A Written Information Security Plan that exists as a downloaded template with blank fields is not a program you are "in compliance with," and a firm in that position has not earned the deeming; it is simply out of compliance in two jurisdictions at once. The shortcut never excuses the federal program. It rewards it.

Two more edges, stated plainly. First, the deeming reaches the safeguards duty and nothing else: New York's breach-notification law is a separate section with its own machinery, covered below. Second, deemed compliance is a status you hold only while its conditions hold, not a certificate anyone issues. If the federal program lapses, the New York shortcut lapses with it, and nothing on this page is a compliance verdict about your firm.

Whether your firm can rely on deemed compliance turns on two legal reads: that the federal rule covers your practice, and that your program actually complies with it. Both are fact-specific. If you plan to lean on this clause, have a qualified professional confirm both conditions for your situation.

What does the federal WISP already cover in New York?

The statute's do-it-yourself route sketches what New York considers a data security program: administrative, technical, and physical safeguards "such as the following," a deliberately illustrative list. For a firm taking the deemed-compliance route, that list still matters, because it is the map of what the state cares about. Here is each SHIELD example safeguard beside the federal element that does its work:

New York's example safeguards beside the federal elements that perform them
SHIELD example safeguard (§ 899-bb(2)(b)(ii))Where a federal Safeguards Rule program answers it (16 CFR 314.4)
"designates one or more employees to coordinate the security program"The Qualified Individual your program must designate to oversee it, at 314.4(a).
"identifies reasonably foreseeable internal and external risks" and "assesses the sufficiency of safeguards in place to control the identified risks"The risk assessment the program is built on, at 314.4(b).
"trains and manages employees in the security program practices and procedures"Security awareness training and personnel policies at 314.4(e).
"selects service providers capable of maintaining appropriate safeguards, and requires those safeguards by contract"Service-provider selection, contract terms, and oversight at 314.4(f).
"adjusts the security program in light of business changes or new circumstances"Program evaluation and adjustment at 314.4(g).
"assesses risks in network and software design" and "in information processing, transmission and storage"The risk assessment at (b) plus the concrete safeguards at (c): access controls at (c)(1), the data and systems inventory at (c)(2), encryption at (c)(3), secure development at (c)(4), and multi-factor authentication at (c)(5).
"detects, prevents and responds to attacks or system failures"Monitoring and logging of authorized-user activity, with detection of unauthorized access by those users, at (c)(8), and the incident response plan at (h).
"regularly tests and monitors the effectiveness of key controls, systems and procedures"The testing and monitoring duty at 314.4(d).
Physical safeguards: "assesses risks of information storage and disposal" and "disposes of private information within a reasonable amount of time"Secure disposal on a defined clock at (c)(6), access controls at (c)(1), and change management at (c)(7) when systems holding the data change.
Prepared by Safeguards Monitor from GBS § 899-bb(2)(b)(ii) (nysenate.gov) and 16 CFR 314.4 (eCFR), both checked July 19, 2026. The statute's list is illustrative by its own words; the federal citations are the rule's element map.

One calibration note before the conclusion: the federal rule's own small-firm exception (16 CFR 314.6) waives four items for firms holding information on fewer than 5,000 consumers, among them the written form of the risk assessment and the written incident response plan. The deeming rides on the rule as it applies to your firm, so a lawfully exempt solo practice is not missing a layer by lacking what the rule does not ask of it.

The overlap is not a coincidence; it is why the legislature wrote the deeming clause. New York's categories are the federal program's categories at lower resolution, so a firm that can open its federal Written Information Security Plan and point to each row, as the rule applies to it, has its New York answer in hand. A covered firm with no program at all is missing both layers at once, which is the honest reason to start the document this week rather than after a letter arrives.

How do you close the New York layer?

For a covered tax practice, the New York pass is short, and every step lands inside work the federal rule already asks of you:

  1. Confirm the entry condition. If your firm prepares returns for compensation, the federal rule covers it as a financial institution. If your situation sits at an edge (bookkeeping only, payroll only, a volunteer site), the profession-by-profession coverage map settles which duties reach you before New York's shortcut is even relevant.
  2. Make the federal program real, not nominal. "In compliance with" is the deeming clause's second condition. Complete the plan, implement its safeguards, and keep the records that show both. A template with blank fields clears neither jurisdiction.
  3. Write the New York reliance down. Add one dated line to your Written Information Security Plan: the firm holds New York residents' private information and relies on the compliant-regulated-entity clause at GBS 899-bb via its GLBA-regulated status. The statute does not require this note; it is how you answer the question quickly, with the statute cite in hand, if a client or regulator ever asks.
  4. Inventory New York private information. New York defines "private information" in its notification law by data elements: Social Security numbers, driver's license numbers, financial account and card numbers, and biometric records, plus, standing on its own, a username or email address with a password or security answer that opens an online account. Your federal data inventory at 314.4(c)(2) is the natural place to note which records involve New York residents.
  5. Handle the breach side on its own track. The deeming clause does not touch New York's notification law; the next section separates the two, and your incident response plan should already name the state's offices.
  6. Recheck at the annual review. Deemed status rides on continuing federal compliance. When your program's periodic review runs, re-date the New York line along with the rest of the plan.

SHIELD vs New York's breach-notification law: which is which?

Two neighboring sections do different jobs, and conflating them is the most common New York error we see. Section 899-bb, this page's subject, is the standing safeguards duty: what your firm must maintain before anything goes wrong. Section 899-aa is the breach-notification law: when private information is accessed or acquired without authorization, the firm must disclose to the affected New York residents and notify the state's offices, including the Attorney General, the Department of State, and the State Police, on that section's own definitions and clocks. The SHIELD Act amended the notification law and created the safeguards duty in the same 2019 act, which is part of why the two blur together in coverage.

The operative point for a deemed-compliant firm: the deeming clause lives in 899-bb and reaches only the safeguards duty. Nothing in it excuses a single notification obligation. The Wojeski record above makes the cost of missing that concrete, since notice that arrived more than a year late was one of the failures the Attorney General named. When an incident happens at a tax practice, the sequence starts with the IRS and runs through the states; the full who-to-call sequence after a client-data breach walks it contact by contact, deadline by deadline.

FAQ

Does the SHIELD Act reach firms outside New York?

Yes. The safeguards duty applies to "any person or business that owns or licenses computerized data which includes private information of a resident of New York," with no requirement that the business operate in the state. Your client's residency, not your office address, is what places you inside it. A Colorado preparer with three New York clients owes New York reasonable safeguards for those three files.

Is anything actually required to be in writing?

The safeguards duty sentence does not use the word "written," and that surprises people. But look at how compliance is shown under either route. The statute's own program path is defined by functions a firm performs (designating, assessing, training, adjusting), which are demonstrated in practice through documentation. And the deemed-compliance path runs through the federal Safeguards Rule, which requires a comprehensive information security program that is, in the rule's own words, "written in one or more readily accessible parts." Massachusetts, for comparison, writes the word directly into its state rule, 201 CMR 17.00. Practically: New York does not hand you a form, and a firm with nothing on paper has no good way to demonstrate either route.

What about the NYDFS cybersecurity regulation, Part 500?

A different regime for a different population: 23 NYCRR Part 500 binds entities operating under a New York Banking Law, Insurance Law, or Financial Services Law authorization, which a tax-preparation practice typically is not. The two connect in one tidy way: Part 500 sits on the same list as GLBA in the compliant-regulated-entity definition, and the same two conditions govern it there, being subject to it and being in compliance with it.

Are there penalties for ignoring the safeguards duty?

Yes. The Attorney General enforces section 899-bb; the statute deems a violation of the safeguards duty a violation of section 349, New York's deceptive-practices law, and sends civil penalties to section 350-d, and it states plainly that "Nothing in this section shall create a private right of action." We keep penalty figures off every page of this site except our single-source penalties reference; New York's amounts are in the text of section 350-d at the link.

Does New York's tax preparer registration add data-security duties?

Not on its face. New York separately requires commercial tax return preparers to register annually with the Department of Taxation and Finance and complete continuing education, while attorneys, CPAs, and enrolled agents, among others, are excluded from that registration's definition of preparer (the DTF registration page, updated January 26, 2026). That page carries no data-security requirement; we checked it on July 19, 2026. For a New York practice, the state's data-security duty runs through the SHIELD Act, and the registration regime runs alongside it.

The bottom line

New York's safeguards duty has applied since March 21, 2020, it follows the client's residency across state lines, and the office enforcing it has already settled with a public accounting firm. For a tax practice the statute's most useful sentence is the deeming clause: hold a federal Safeguards Rule program and actually follow it, and New York counts you compliant with its safeguards duty by that fact. One document, honestly completed, carries both layers. The breach-notification side stays its own duty either way.