Data privacy basics for small businesses and startups
A practical introduction to privacy law for small organisations: what personal data is, key principles, privacy notices, vendors, and handling breaches.
Almost every business now collects personal data, whether it is a customer mailing list, website analytics or employee records. Privacy laws around the world, such as the GDPR in Europe and a growing number of US state laws, set rules for how that data is handled. This guide covers the basics in plain English.
What counts as personal data
Personal data is broadly any information that relates to an identifiable person: names, email addresses, phone numbers, IP addresses, location data, purchase history and more. Some categories, such as health information, biometric data, and financial details, are treated as more sensitive and often carry stricter rules.
Core principles
While laws differ, many share common principles:
- Transparency: tell people what you collect and why.
- Purpose limitation: use data only for the reasons you stated.
- Data minimisation: collect only what you need.
- Storage limitation: do not keep data longer than necessary.
- Security: protect data with appropriate technical and organisational measures.
- Accountability: be able to show how you comply.
Privacy notices
A privacy notice explains your data practices to the people whose data you hold. It should be accurate, specific and easy to read. Start by mapping what data you collect, where it is stored, which tools and vendors process it, and how long you keep it. A notice copied from another business rarely matches what you actually do, which can create legal risk of its own.
Marketing, cookies and consent
Email marketing, text messages and online tracking often have their own rules. In some places you need consent before sending marketing messages or setting non-essential cookies; in others, an easy opt-out may be enough. Keep records of how and when people signed up, and always honour unsubscribe requests promptly.
Vendors and contracts
When another company handles data for you, such as a cloud host, payment processor or email platform, you usually remain responsible for that data. Many laws require a written data processing agreement setting out the vendor’s obligations. Check where vendors store data, as transfers across borders can trigger additional requirements.
Individual rights
Depending on the law, people may have rights to access their data, correct it, delete it, object to certain uses, or opt out of its sale or sharing. Have a simple process for receiving and answering these requests within the required time.
When things go wrong
A data breach can be anything from a hacked system to an email sent to the wrong person. Have a basic response plan: contain the problem, assess the risk, decide whether regulators or individuals must be notified, and keep a record. Notification deadlines can be short.
Preparing for a consultation
- List the personal data you collect and where it comes from.
- List the software tools and vendors that handle it.
- Note the countries where your customers and vendors are located.
- Bring your current privacy notice and any customer contracts.
- Describe any incident or complaint you are dealing with.
This is general information, not legal advice — speak to a licensed lawyer about your situation.