Data privacy basics for your business
A plain-English introduction to data privacy — what data your business likely holds, your responsibilities, and how to handle it well.
- Difficulty
- Intermediate
Data privacy is about how you collect, store, use, and protect information about your customers, staff, and visitors. It matters for legal reasons — most countries have privacy laws with real penalties — and for trust reasons: people expect their information to be handled responsibly.
You don't need to become a lawyer. You do need to understand the basics.
Quick summary
Your business probably collects personal data through your website (contact forms, analytics, cookies), your customer database, and your email list. You are responsible for protecting that data, being transparent about how you use it, and allowing people to request its deletion. A privacy policy on your site, a clear opt-out on every marketing email (plus opt-in consent where the law requires it), and basic data security are the minimum for most businesses.
What counts as personal data?
Personal data (also called personally identifiable information, or PII) is any information that can be used to identify a specific person. This includes:
- Names, email addresses, phone numbers
- Physical addresses
- IP addresses (which your website likely collects automatically)
- Payment information
- Photos or videos of individuals
- Any combination of details that identifies someone
If your website has a contact form, an email list, or any kind of account system — you are holding personal data.
Data privacy laws: the landscape
| Law | Who it applies to | What it requires |
|---|---|---|
| GDPR (EU) | Businesses in the EU, plus businesses anywhere else that offer goods or services to people in the EU or monitor their behavior there | A lawful basis for processing (consent is one), right of access, right to deletion, data protection measures |
| CCPA (California) | For-profit businesses doing business in California that meet any one threshold: gross annual revenue above the CCPA's inflation-adjusted figure (the California Privacy Protection Agency raised it to $26,625,000 effective 1 January 2025), or buying, selling or sharing the personal information of 100,000 or more California residents or households, or deriving 50% or more of annual revenue from selling California residents' personal information | Right to know, right to delete, right to opt out of sale or sharing, right to correct, right to limit use of sensitive data, and no discrimination for exercising those rights |
| PIPEDA (Canada) | Private-sector organizations that collect, use, or disclose personal information in the course of commercial activity in Canada | Consent, accuracy, safeguards, individual access |
| Other state/national laws | Varies | Most follow similar principles, but the details and deadlines differ |
This is not legal advice
Data privacy law is complex and jurisdiction-specific. This guide gives you a foundation — but if you collect significant amounts of personal data, sell products in multiple countries, or have questions about compliance, consult a lawyer or a privacy professional.
The data your business likely holds
Think through each of these:
- Contact form submissions — names, emails, messages
- Email marketing list — names, emails, possibly purchase history or preferences
- Customer records — order history, shipping addresses, payment history
- Website analytics — Google Analytics collects cookies, device and browser details, and visitors' IP addresses, and uses the IP address to work out roughly where in the world a visitor is. Google says that when collecting data it does not log or store IP addresses, and that for EU, Swiss and UK visitors the address is discarded as soon as the location has been derived. Other analytics tools handle this differently, so check yours.
- Cookies — can identify returning visitors
- Staff information — if you have employees, you hold their personal data too
- Social media interactions — if you run ads or competitions
Your responsibilities
Have a privacy policy
Your website needs a privacy policy that explains:
- What data you collect
- Why you collect it
- How long you keep it
- Who you share it with
- How people can access or delete their data
- How to contact you with privacy requests
A privacy policy generator (like Iubenda or Termly) can give you a starting draft. It won't know your business, so read it against what you actually do — and get a lawyer to review it if you handle significant amounts of data.
Get consent for marketing emails
The rules differ by country, so check the ones that apply to you.
Under GDPR, where you rely on consent it has to be a clear affirmative act: "Silence, pre-ticked boxes or inactivity should not therefore constitute consent." So:
- A pre-ticked checkbox does not count
- People need to actively opt in
- You need to keep a record of when and how they consented
In the US, the CAN-SPAM Act — which the FTC enforces — works the other way round: it does not require you to get consent first, but every marketing email must include your valid physical postal address and a clear, working way to opt out, and you must honor an opt-out request within 10 business days.
Getting a clear opt-in anyway is the stronger standard, and it keeps you covered either way. This is sometimes called permission-based marketing or opt-in marketing.
Display a cookie banner
If your site uses cookies beyond strictly necessary ones (analytics, advertising, personalization), you need to inform visitors and get consent in many jurisdictions. A cookie consent tool handles this automatically.
Respond to data requests
If someone asks to:
- See what data you hold about them
- Correct inaccurate data
- Delete their data ("right to be forgotten")
You are generally legally required to respond, and the deadline depends on the law. GDPR gives you one month from receiving the request, extendable by two further months where the request is complex. California's CCPA gives 45 calendar days, extendable by another 45 if you tell the person. Keep records of these requests.
Protect the data you hold
Holding personal data creates a responsibility to protect it:
- Use strong passwords and 2FA on systems that hold customer data
- Don't send unencrypted personal data in plain-text emails when avoidable
- Limit who in your team has access to customer data
- Delete data you no longer need
What to do after a data breach
If you believe personal data has been accessed without authorization:
- Assess what data was involved and how many people
- Secure the breach — stop any ongoing access
- Check your legal obligations for reporting. GDPR says to notify your supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach, unless it is unlikely to risk people's rights and freedoms. US state breach-notification laws set their own rules.
- Consider whether to notify affected individuals
- Consult a lawyer
See also What to do if your site is hacked.
Common questions
Do I need a privacy policy if I only have a contact form?
Yes. A contact form collects personal data (name, email, message). You should have a privacy policy explaining how that data is used and stored, linked to from your contact form and your footer.
Does GDPR apply to me if I'm a US business?
It can. GDPR reaches a business outside the EU when what it does relates to offering goods or services to people in the EU, or to monitoring their behavior while they are in the EU. So a stray EU visitor to a site aimed squarely at US customers is not the test; selling to people in the EU, or tracking them, is. In practice, most small US businesses serving primarily US customers focus on the US state laws that apply to them and adopt GDPR-aligned practices as a good standard.
How long can I keep customer data?
You should keep data only as long as necessary for the purpose you collected it for. For records that back up a US tax return, the IRS says keep them 3 years in most cases — but 6 years if you under-reported income by more than 25%, 7 years for a worthless-securities or bad-debt claim, at least 4 years for employment tax records, and indefinitely if you never filed. Ask your accountant which applies to you, and check other rules before you delete anything: insurers and creditors may require longer. For email marketing, keep the data as long as the person remains subscribed. For contact form messages, as long as needed to respond to the inquiry.
What do I do if someone asks me to delete their data?
Respond to the request, confirm what data you hold about them, delete it from your systems (CRM, email list, any databases), and confirm to them that it's been done. Keep a log of the request and your response.
Related guides
- Why security matters for your business
- Your business security checklist
- What to do if your site is hacked
- SSL & HTTPS, explained
- Tracking, cookies & privacy
Need a hand?
Learn more
- European Commission: data protection information for business and organisations
- EUR-Lex: the full text of the GDPR
- CCPA: California Attorney General guidance
- California Privacy Protection Agency: updated monetary thresholds in the CCPA
- FTC: Privacy and security guidance for businesses
- ICO (UK): UK GDPR guidance and resources
- IRS: How long should I keep records?
Last updated
Securing your social media accounts
How to protect your Facebook, Instagram, LinkedIn, and other social media accounts from hackers and unauthorized access.
Security steps when someone leaves
The security checklist to run every time a team member, contractor, or employee moves on — to protect your business and remove unnecessary access.