How to Protect Data Privacy

A Practical Guide for Small Businesses on how to Protect Data Privacy

Introduction

Every few weeks we get the same call. A company of thirty to two hundred people has just been asked by a customer, an insurer or an auditor to prove how it handles personal data, and nobody can answer. There is a privacy policy on the website that a lawyer wrote in 2021. There is no list of where the data actually lives.

That gap is the whole problem. Privacy failures at this size are rarely caused by a missing tool. They are caused by nobody knowing what data the business holds.

This post covers what a privacy failure costs now, which controls stop which specific failures, and a sequence you can run in ninety days without hiring anyone.

What a privacy failure costs in 2026

Isometric illustration of a person standing next to a document.

IBM's 2026 Cost of a Data Breach Report puts the global average breach cost at $4.99 million, up 12 percent year over year and a record high. The United States average is $11.5 million, more than double the global figure. The number that should worry a small business more is the timeline: mean time to identify and contain a breach rose to 247 days, 183 to identify and 64 to contain, the first increase in five years.

Two hundred and forty seven days is long enough for a twenty person company to lose a contract, a renewal and a founder's weekend.

Regulators have caught up too. As of 1 March 2026, European authorities had issued 2,685 GDPR fines totalling roughly EUR 6.11 billion. Insufficient technical and organisational security measures was the third most common ground for a fine, behind lacking a legal basis for processing and breaching general processing principles. Those are documentation failures, not firewall failures.

For Canadian clients the exposure is closer to home. Under Quebec's Law 25, administrative penalties reach CAD 10 million or 2 percent of global turnover, and penal provisions for severe violations reach CAD 25 million or 4 percent of global turnover, whichever is higher. Law 25 also created a private right of action carrying punitive damages of not less than CAD 1,000 per person where the infringement is intentional or results from gross fault. A mid sized customer list turns that into a real number very quickly.

The three assumptions that get small companies breached

Across our assessments, the same three beliefs show up before almost every incident.

"We are too small to be a target." The 2026 Verizon DBIR found third party involvement in breaches jumped 60 percent year over year and now accounts for close to half of all breaches. Small companies are not being targeted for their own data. They are being targeted as the way into somebody bigger. Being a supplier is the target.

"Our vendor handles security." For the first time in the report's nineteen year history, vulnerability exploitation overtook stolen credentials as the most common route to initial access, rising to 31 percent while credential abuse fell from 22 percent to 13 percent. Only 26 percent of CISA known exploited vulnerabilities were fully remediated across organisations in the DBIR dataset, down from 38 percent, and median patch time slipped from 32 days to 43 days. Somebody has to own patching, and in a small company that somebody has to be named.

"Nobody here is putting customer data into AI tools." Shadow AI is now the third most common non malicious insider action detected in data loss prevention datasets, a fourfold increase on the prior year. If you have not written an AI use policy, you do not have one, and your staff have already made their own.

Start with a data inventory, not a tool

An image of a laptop with a padlock on it.

Do not buy anything yet. The first deliverable is a spreadsheet.

List every system that touches personal data: the CRM, the payroll provider, the shared drive, the marketing platform, the support inbox, the AI assistant somebody expensed. For each one, record four things:

  • What categories of personal data it holds

  • Who the data belongs to (customers, staff, applicants, patients)

  • Which jurisdiction those people are in

  • Who inside the business owns that system

Most companies we work with find between fifteen and forty systems. They expected eight. The systems nobody remembered are almost always where the risk sits, because nobody has reviewed their access list in years.

Once the inventory exists, classify each row as public, internal, confidential or regulated. That single column is what lets you spend money proportionately instead of buying enterprise tooling for a mailing list.

Collect less, and the rest gets easier

Every field you do not collect is a field you never have to secure, audit, encrypt, back up, produce in a subject access request or disclose in a breach notification.

Go through your forms line by line. Ask why each field exists and who has ever used it. Date of birth on a newsletter signup, a full home address on a demo request, a phone number nobody calls: delete the field, then delete the historical values.

Where you genuinely need to check something rather than keep it, use a verify and discard pattern. Age verification, identity verification and payment details can usually be handled by a third party that returns a yes or no while never handing you the underlying data to store.

Then set retention periods and actually enforce them. A retention policy that nobody automated is a document, not a control.

Transparency is a design problem, not a legal one

Consent buried in a policy page is a compliance artefact. It does not build trust and, increasingly, it does not satisfy regulators either.

Do this instead. Explain collection at the point of collection, in the interface, in one sentence. Make the choice to opt out as easy as the choice to opt in, on the same screen. Answer deletion requests in days rather than the statutory maximum, and tell people when it is done.

We have seen this convert. Prospects in regulated sectors read privacy pages before they book calls, and a page that explains plainly what you hold and for how long closes deals that a legalistic one loses.

Your 30, 60 and 90 day privacy checklist

Days 1 to 30

  • Build the system inventory and classify every row

  • Turn on multi factor authentication for every account, with no exceptions for executives

  • Write a one page AI use policy naming which tools are approved and what must never be pasted into them

  • Identify who owns patching and give them a named backup

Days 31 to 60

  • Cut unnecessary form fields and purge the historical values

  • Set and automate retention periods for each data category

  • Review access lists on the systems nobody had remembered

  • Test a restore from backup, end to end, and time it

Days 61 to 90

  • Map your data flows to the jurisdictions your customers actually live in

  • Run a breach simulation covering the first 72 hours of notification duties

  • Add privacy questions to vendor onboarding, given third parties are now involved in close to half of breaches

  • Rewrite the public privacy page in plain language

If you finish that list you will be ahead of most companies your size, and you will be able to answer the customer questionnaire that started this whole thing.

Where to get help

We run this exact sequence for clients through our data security and privacy service and, where broader compliance obligations are in play, through governance, risk and compliance. If you need the accountability without a full time hire, our virtual CISO service covers it.

If you would rather start on your own, our free assessment tools will score your current position against recognised baselines in about twenty minutes, at no cost and with no sales call attached.

Or book a call and we will tell you which of the ninety days actually apply to you.

Keep Reading

Related Articles

Our Industry Certifications

Our diverse industry experience and expertise in AI, Cybersecurity & Information Risk Management, Data Governance, Privacy and Data Protection Regulatory Compliance is endorsed by leading educational and industry certifications for the quality, value and cost-effective products and services we deliver to our clients.

Copyright © 2026 IRM Consulting & Advisory. All Rights Reserved.