Support Center | ☎︎ Call us: (845) 440-5000 | info@vjnetworks.com
Back to Blog

The NY SHIELD Act: What It Actually Requires of a 20-Person Business

Cybersecurity
Last updated: July 23, 2026

New York’s SHIELD Act requires almost every business holding a New York resident’s personal data to run a written data security program. A company with around 20 employees still counts as a “small business” under the law, which lowers the bar to “reasonable” safeguards instead of a detailed checklist.

This comes up constantly. An owner reads a headline about the SHIELD Act, assumes it’s some enterprise-only regulation, and moves on. Wrong assumption. If you’ve got customer names, employee Social Security numbers, or even just email addresses paired with passwords sitting in a spreadsheet somewhere, this law already applies to you. Has for a while now.

What Actually Counts as “Private Information” Here

The SHIELD Act covers more than most owners expect. Social Security numbers and driver’s license numbers, the obvious ones everybody assumes. But the law also covers biometric data. Since a March 2025 update, medical history and health insurance details too. Policy numbers. Claims history. It covers something else that trips up almost everybody: a username or email address paired with a password or security question answer, sitting behind nearly every customer login portal and employee inbox anyone actually runs day to day. Nobody’s exempt just because they don’t process credit cards.

And here’s the part that surprises people most. The law doesn’t care where your business is headquartered. It applies based on where the affected person lives. A 20-person shop headquartered in Bergen County, New Jersey, with a handful of New York clients still has SHIELD Act obligations toward those clients, even though the business itself never sets foot in New York. This is the kind of gap most generic cybersecurity advice glosses over entirely, since it’s written for a national audience instead of the Tri-State reality VJNetworks’ clients actually operate in.

Small business team discussing data security practices around a table

The 20-Person Business Question

This part actually works in your favor, size-wise. Fewer than 50 employees qualifies. So does under 3 million dollars in gross annual revenue across each of the last three fiscal years, or under 5 million in year-end total assets. New York calls that combination a “small business,” and meeting any one of the three is enough. Not all three.

A 20-person company clears that bar easily. Easily. What that buys you is a data security program built around “reasonable” safeguards, sized to your actual business, not a 40-page policy manual written for a company with a dedicated compliance department. Reasonable still means something, though. It’s not a pass to do nothing.

I partnered up to start VJNetworks out of Congers, NY in 2004, and I’ve watched this exact confusion play out for years. Owners either think the law doesn’t touch them at all, or they think it demands the same program a hospital system needs. Neither is right. The real answer sits in the middle, and it’s a lot more manageable than most owners assume once somebody actually walks them through it.

What “Reasonable Safeguards” Actually Means

The New York Attorney General’s office breaks it into three buckets, and none of them require a law degree to understand.

Safeguard typeWhat it actually looks like
AdministrativeSomeone named as responsible for security, risks identified, staff trained, vendors vetted
TechnicalNetwork and software risks assessed, controls tested on a regular basis
PhysicalSecure storage, secure disposal, records not just sitting in an unlocked drawer

Notice what’s missing. No mention of a specific software product, no minimum spend, no vendor name anywhere in any of it. The law is written around outcomes, not tools, which is exactly why “reasonable” sounds vague right up until someone actually puts real, working practices next to it and the whole thing suddenly makes sense.

One more thing worth knowing. Already compliant with HIPAA, the Gramm-Leach-Bliley Act, or New York’s own financial services cybersecurity rule? You’re covered here too, automatically, without building a second program from scratch on top of one you’re already running and paying for. Healthcare practices juggling this alongside what HIPAA actually requires get this overlap question a lot, and the short answer is usually good news.

IT consultant and small business owner reviewing data security compliance documentation

If Something Actually Goes Wrong

This is the part owners really want to know, so I’ll give it straight. New York tightened this rule in December 2024. Thirty days. That’s the new hard cap. Notification has to go out “without unreasonable delay,” and no later than 30 days after you discover the breach. The old grace period, the one IT teams used to lean on to assess the damage before saying anything, is gone. Three state agencies get notified too: the Attorney General, the Department of State, and the State Police.

Only the Attorney General can bring an enforcement action here. There’s no private right of action, meaning a customer whose data leaked can’t personally sue your business under this specific law, no matter how badly that relationship ends up damaged on the trust side of things. Small comfort in the moment, but worth knowing before you assume every breach turns straight into a lawsuit.

The dollar numbers are real, though. Failing to maintain the required safeguards can run up to $5,000 per violation. Botched notification, if it’s found to be knowing or reckless, adds up to $20 per failed notice, capped at $250,000. The Attorney General’s own guidance lays out what her office actually looks for when deciding whether a program was reasonable, based on real cases her office has handled.

Locked filing cabinet drawer representing physical data security safeguards

What a 20-Person Business Should Actually Do

Here’s the short list I give clients who are starting from zero.

  • Put one person’s name on the security program, even if it’s you. “Everyone’s responsible” means nobody is.
  • Write down what private information you actually hold and where it lives, since most owners genuinely don’t know until they look.
  • Require real passwords and multi-factor authentication on anything touching customer or employee data.
  • Have an actual answer ready for “what do we do if this leaks,” before you need it, not while it’s happening.
  • Check whether your current vendors are contractually required to protect data too, not just your own systems.

None of that requires a big budget, or some consultant showing up with a binder full of jargon nobody in the room can actually follow. What it requires is someone to actually own it and follow through, which is where most 20-person businesses fall short. Not from a lack of caring. From a lack of time.

Straight Answers From an Owner Who’s Been Through This

We’re only 20 people. Does this law even apply to us?
It does, and that 20-person size is exactly what puts you in the “small business” category. That changes the standard you’re held to, not whether the law applies at all. Almost every business holding New York residents’ data is covered.
What actually counts as “private information” here? Just Social Security numbers?
No, it’s broader. Driver’s license numbers, financial account numbers, biometric data, medical and health insurance details since a 2025 update, and a username or email paired with a password all count. That last one catches a lot of businesses that assumed they were in the clear.
If a client’s data leaks and it genuinely wasn’t our fault, are we still on the hook?
Fault matters for how bad it gets, not for whether you’re covered by the law. A documented, reasonable program going in is what actually protects you, regardless of how the breach happened.
Can a customer sue us directly if we get this wrong?
Not under this specific law. There’s no private right of action written into the SHIELD Act, so enforcement runs through the Attorney General’s office alone. Other legal exposure can still exist, just not this particular one.
Do we need a lawyer to write our data security policy, or can our IT provider handle it?
Most of the actual implementation, the technical and physical safeguards, sits squarely in IT’s lane. A lawyer’s worth involving for the written policy language itself and for anything touching regulated industries. Most 20-person businesses need both, briefly, not a retainer.

The SHIELD Act isn’t the enterprise-only regulation most business owners assume it is, and it isn’t a demand for a compliance department you can’t afford either. VJNetworks has helped small businesses across the Tri-State area build the reasonable, actually-followed version of this program for over 20 years, folded into VJNetworks’ managed IT services. It starts with what you’re actually required to do, not a sales pitch about what you could buy. If you want a straight read on where your own business stands, a free assessment covers exactly that, the same way it has for businesses across Rockland County and beyond.

Further reading: the Attorney General’s SHIELD Act page covers the full legal text and requirements directly.

Quick disclaimer: Everything above is general information, not legal advice. Your specific setup, vendors, and risk can change the answer, so if you want an actual assessment of where your business stands or just have questions this post didn’t answer, reach out — happy to walk through it.

Find Out Where Your Business Actually Stands

A free assessment checks your current setup against what the SHIELD Act actually requires at your size, no compliance jargon, no upsell. No obligation, no sales pitch.

Get Your Free IT Assessment →

Or call (845) 440-5000