Know what personal data you actually hold
Most businesses underestimate how much personal data is scattered across forms, spreadsheets, marketing tools and support tickets. A basic data inventory is the necessary first step before any compliance work is meaningful.
Collect consent deliberately, not by default
Pre-checked consent boxes and vague blanket permissions are increasingly poor practice. Be explicit about what data is collected, why, and give users a genuine way to withdraw consent.
Have a breach response plan before you need one
A documented, rehearsed response plan — who is notified, what is disclosed, and by when — turns a data incident from a crisis into a manageable, contained event.
Frequently asked questions
Do small businesses need to worry about data privacy compliance?
Yes. Obligations generally scale with the sensitivity and volume of personal data handled, not company size alone, so even a small business collecting customer data should have basic consent and security practices in place.
What is the minimum first step toward compliance?
Start with a data inventory: what personal data you collect, where it's stored, who can access it, and how long it's retained. Most other compliance work follows naturally once that picture is clear.