New York’s SHIELD Act requires almost every business holding a New York resident’s personal data to run a written data security program. A company with around 20 employees still counts as a “small business” under the law, which lowers the bar to “reasonable” safeguards instead of a detailed checklist.
This comes up constantly. An owner reads a headline about the SHIELD Act, assumes it’s some enterprise-only regulation, and moves on. Wrong assumption. If you’ve got customer names, employee Social Security numbers, or even just email addresses paired with passwords sitting in a spreadsheet somewhere, this law already applies to you. Has for a while now.
What Actually Counts as “Private Information” Here
The SHIELD Act covers more than most owners expect. Social Security numbers and driver’s license numbers, the obvious ones everybody assumes. But the law also covers biometric data. Since a March 2025 update, medical history and health insurance details too. Policy numbers. Claims history. It covers something else that trips up almost everybody: a username or email address paired with a password or security question answer, sitting behind nearly every customer login portal and employee inbox anyone actually runs day to day. Nobody’s exempt just because they don’t process credit cards.
And here’s the part that surprises people most. The law doesn’t care where your business is headquartered. It applies based on where the affected person lives. A 20-person shop headquartered in Bergen County, New Jersey, with a handful of New York clients still has SHIELD Act obligations toward those clients, even though the business itself never sets foot in New York. This is the kind of gap most generic cybersecurity advice glosses over entirely, since it’s written for a national audience instead of the Tri-State reality VJNetworks’ clients actually operate in.

The 20-Person Business Question
This part actually works in your favor, size-wise. Fewer than 50 employees qualifies. So does under 3 million dollars in gross annual revenue across each of the last three fiscal years, or under 5 million in year-end total assets. New York calls that combination a “small business,” and meeting any one of the three is enough. Not all three.
A 20-person company clears that bar easily. Easily. What that buys you is a data security program built around “reasonable” safeguards, sized to your actual business, not a 40-page policy manual written for a company with a dedicated compliance department. Reasonable still means something, though. It’s not a pass to do nothing.
I partnered up to start VJNetworks out of Congers, NY in 2004, and I’ve watched this exact confusion play out for years. Owners either think the law doesn’t touch them at all, or they think it demands the same program a hospital system needs. Neither is right. The real answer sits in the middle, and it’s a lot more manageable than most owners assume once somebody actually walks them through it.
What “Reasonable Safeguards” Actually Means
The New York Attorney General’s office breaks it into three buckets, and none of them require a law degree to understand.
| Safeguard type | What it actually looks like |
|---|---|
| Administrative | Someone named as responsible for security, risks identified, staff trained, vendors vetted |
| Technical | Network and software risks assessed, controls tested on a regular basis |
| Physical | Secure storage, secure disposal, records not just sitting in an unlocked drawer |
Notice what’s missing. No mention of a specific software product, no minimum spend, no vendor name anywhere in any of it. The law is written around outcomes, not tools, which is exactly why “reasonable” sounds vague right up until someone actually puts real, working practices next to it and the whole thing suddenly makes sense.
One more thing worth knowing. Already compliant with HIPAA, the Gramm-Leach-Bliley Act, or New York’s own financial services cybersecurity rule? You’re covered here too, automatically, without building a second program from scratch on top of one you’re already running and paying for. Healthcare practices juggling this alongside what HIPAA actually requires get this overlap question a lot, and the short answer is usually good news.

If Something Actually Goes Wrong
This is the part owners really want to know, so I’ll give it straight. New York tightened this rule in December 2024. Thirty days. That’s the new hard cap. Notification has to go out “without unreasonable delay,” and no later than 30 days after you discover the breach. The old grace period, the one IT teams used to lean on to assess the damage before saying anything, is gone. Three state agencies get notified too: the Attorney General, the Department of State, and the State Police.
Only the Attorney General can bring an enforcement action here. There’s no private right of action, meaning a customer whose data leaked can’t personally sue your business under this specific law, no matter how badly that relationship ends up damaged on the trust side of things. Small comfort in the moment, but worth knowing before you assume every breach turns straight into a lawsuit.
The dollar numbers are real, though. Failing to maintain the required safeguards can run up to $5,000 per violation. Botched notification, if it’s found to be knowing or reckless, adds up to $20 per failed notice, capped at $250,000. The Attorney General’s own guidance lays out what her office actually looks for when deciding whether a program was reasonable, based on real cases her office has handled.

What a 20-Person Business Should Actually Do
Here’s the short list I give clients who are starting from zero.
- Put one person’s name on the security program, even if it’s you. “Everyone’s responsible” means nobody is.
- Write down what private information you actually hold and where it lives, since most owners genuinely don’t know until they look.
- Require real passwords and multi-factor authentication on anything touching customer or employee data.
- Have an actual answer ready for “what do we do if this leaks,” before you need it, not while it’s happening.
- Check whether your current vendors are contractually required to protect data too, not just your own systems.
None of that requires a big budget, or some consultant showing up with a binder full of jargon nobody in the room can actually follow. What it requires is someone to actually own it and follow through, which is where most 20-person businesses fall short. Not from a lack of caring. From a lack of time.
Straight Answers From an Owner Who’s Been Through This
We’re only 20 people. Does this law even apply to us?
What actually counts as “private information” here? Just Social Security numbers?
If a client’s data leaks and it genuinely wasn’t our fault, are we still on the hook?
Can a customer sue us directly if we get this wrong?
Do we need a lawyer to write our data security policy, or can our IT provider handle it?
The SHIELD Act isn’t the enterprise-only regulation most business owners assume it is, and it isn’t a demand for a compliance department you can’t afford either. VJNetworks has helped small businesses across the Tri-State area build the reasonable, actually-followed version of this program for over 20 years, folded into VJNetworks’ managed IT services. It starts with what you’re actually required to do, not a sales pitch about what you could buy. If you want a straight read on where your own business stands, a free assessment covers exactly that, the same way it has for businesses across Rockland County and beyond.
Further reading: the Attorney General’s SHIELD Act page covers the full legal text and requirements directly.
Quick disclaimer: Everything above is general information, not legal advice. Your specific setup, vendors, and risk can change the answer, so if you want an actual assessment of where your business stands or just have questions this post didn’t answer, reach out — happy to walk through it.
A free assessment checks your current setup against what the SHIELD Act actually requires at your size, no compliance jargon, no upsell. No obligation, no sales pitch.
