Skip to content
For your business

Business path

8 min read

Protecting customer data as a tiny company

You hold data, so you are responsible for it

The moment you take a booking, save a phone number, or write down an order, you are holding data about another person. Names, numbers, addresses, what they bought, and sometimes payment details. It does not matter that you are small. A one-person studio and a large company carry the same basic duty: to look after the information people trusted you with.

This can feel heavy, but it is manageable. It comes down to three plain habits: collect less, protect what you keep, and be honest with people about it. Take them one at a time.

Minimise: collect only what you need

The safest data is the data you never collected. Before you ask a customer for a piece of information, ask yourself whether you actually need it to do the job.

Do you need a full home address to confirm a haircut appointment? Probably a phone number is enough. Every extra field you collect is one more thing you now have to protect and one more thing that could be exposed if something goes wrong.

The same goes for old data. A list of contacts from three years ago that you will never use again is not an asset, it is a liability sitting there. Deleting what you no longer need is one of the simplest security improvements you can make, and it costs nothing.

Protect: a few habits that do most of the work

You do not need enterprise security. A handful of ordinary habits protect small-business data well.

  • Strong passwords, one per account. A long, unique password on each important account. If one is exposed, the others stay safe. The lesson on passwords and multi-factor authentication (MFA) goes through this properly.
  • Turn on multi-factor authentication (MFA). This adds a second step to logging in, usually a code on your phone, so a stolen password alone is not enough to get in. Switch it on for anything holding customer data.
  • Limit who can see it. Only give access to people who genuinely need it, and remove that access when someone stops working with you.
  • Back it up. Keep a copy of important data somewhere separate, so a lost phone or a broken laptop does not erase your records.
  • Lock your devices. A phone or laptop with a PIN or fingerprint lock protects everything on it if it is lost or left unattended for a moment.

None of these are difficult. Together they close off the most common ways small businesses lose customer information.

Be honest with your customers

People are more willing to share their details when they understand what you do with them. You do not need legal language. A plain sentence is enough: "We keep your number so we can confirm your booking and let you know if the time changes." Say what you keep and why, and then actually stick to it.

Part of that honesty is letting people ask about their own data. A customer may want to know what you hold about them, or ask you to delete it. Treat that as normal and reasonable, and be ready to do it. It costs you very little and it builds real trust.

Warning

Never store more sensitive data than you can genuinely protect. Full payment card numbers are the clearest example: keeping them written in a notebook or saved in a spreadsheet puts your customers at serious risk and puts the responsibility on you. Let a proper payment provider handle card details so that sensitive information never sits with you at all. The rule is simple: if you could not protect it after a lost phone or a break-in, do not be the one holding it.

When something goes wrong

Even careful businesses have bad days. A phone is stolen, an account is broken into, a list ends up somewhere it should not. What matters then is responding calmly rather than hiding it.

If customer data is exposed, you can report the incident to the national authority responsible for cybersecurity, and the lesson on incident reporting walks through how and when to do that. The best time to prepare, though, is before anything happens. The talk-through drills elsewhere in these materials let you practise a calm response in advance, so that if a real bad day comes, you already know your first three steps instead of panicking.

Protecting customer data is not about being perfect. It is about collecting less, guarding what you keep with a few solid habits, being honest, and knowing what to do if the worst happens. Any small business can do all four.

NextAn afternoon security checklist

Found something unclear, outdated or improvable? Suggest an improvement