Data Privacy Basics: Common Pitfalls and How to Guard Yourself
Why data privacy law now touches far smaller businesses than founders expect, the most common pitfalls, and concrete steps to reduce both legal and reputational risk.
Why This Applies to You, Even as a Small Business
Many founders assume data privacy law is a "big tech" problem β something for companies with millions of users and teams of lawyers. That assumption is increasingly wrong. Any business that collects customer emails, runs a website with analytics or advertising cookies, stores payment information, or keeps a customer database is handling personal data, and the legal landscape now touches far smaller businesses than most founders expect β California's law, for example, applies once a business processes the personal information of 100,000 or more residents annually, a threshold a fast-growing consumer app or e-commerce site can reach well before it reaches meaningful revenue.
Why this matters beyond just compliance: the practices that keep you compliant β collecting only what you need, being clear about what you do with it, having a plan if something goes wrong β are also just good practice for keeping customer trust and reducing your own risk, independent of which specific law technically applies to you yet.
The Legal Landscape: Framework + What Varies
How This Varies by State
A growing number of U.S. states have their own consumer privacy laws, generally built around a similar core framework: businesses meeting certain thresholds must give consumers the right to know what personal data is collected about them, the right to request deletion, and often the right to opt out of having their data sold or used for targeted advertising. California's law (the CCPA, as amended by the CPRA) is the most established and often used as the reference point β as of the 2025β2026 adjustment, it applies to for-profit businesses with over roughly $26.6 million in annual gross revenue, OR that derive 50%+ of revenue from selling/sharing personal information, OR that process the personal information of 100,000+ California residents or households annually. These three thresholds are independent β meeting any one of them brings a business into scope, even if the others don't apply.
What varies by state
- βΊWhich specific revenue or data-volume thresholds trigger applicability
- βΊWhich specific consumer rights are granted (know, delete, correct, opt-out of sale, opt-out of targeted advertising)
- βΊWhether sensitive data categories require opt-in consent rather than just an opt-out right
- βΊWhether the law includes a private right of action allowing consumers to sue directly, versus enforcement only by the state attorney general
- βΊBreach notification timelines and specific requirements
Check your state attorney general's website for your state's specific consumer privacy law, and consult a privacy attorney if you process meaningful volumes of customer data across multiple states.
Common Pitfalls
| Why it happens | What it puts at risk | |
|---|---|---|
| Collecting more data than you actually need | "Just in case it's useful later" feels harmless at the time | More data collected means more data to protect, more data exposed if there's ever a breach, and more scrutiny under privacy laws |
| A copy-pasted privacy policy that doesn't match real practice | Templates are fast and free; auditing what your business actually does with data takes more effort | A privacy policy that doesn't match reality is itself a compliance and trust risk β regulators and plaintiffs' attorneys specifically look for that mismatch |
| No breach response plan | It's easy to assume a breach won't happen to a small business specifically | Most states require notifying affected individuals within a set window after a breach β scrambling to figure out your legal obligations during an active incident makes everything worse |
| Sharing data with third-party tools without a data agreement | Signing up for a new SaaS tool feels like a product decision, not a data decision | You remain responsible for how your customers' data is handled even after it's in a vendor's hands |
| Tracking cookies or analytics without required consent | Most analytics and ad tools are enabled by default with no privacy review | Several state and international laws require affirmative consent before non-essential tracking β silent defaults can create real exposure |
How to Guard Yourself
Checklist
0/6What Happens When It Goes Wrong
The reputational cost often outweighs the legal cost for a small business
Nearly every state has a breach notification law requiring you to notify affected individuals within a defined window after discovering a breach β the specific timeline and requirements vary by state. But for most small businesses, the harder cost to recover from isn't the legal exposure β it's the trust damage with customers who find out their data wasn't handled carefully. Treating privacy as a real operational practice, not just a policy document, is what actually reduces both risks at once.
Check Your Understanding
Quick Check
A founder assumes their small e-commerce business is too small to be covered by any state privacy law. What's the risk in that assumption?
Why is a copy-pasted privacy policy template a real risk, not just a shortcut?
Key Terms
Key Terms
- Personal information (PI)
- Data that identifies or could reasonably be linked to a specific individual β names, emails, device identifiers, and more, depending on the specific law.
- Data minimization
- The practice of collecting only the personal data actually needed for a specific purpose, rather than collecting broadly "just in case."
- Data processing agreement (DPA)
- A contract with a vendor clarifying how they may use, protect, and are responsible for customer data you share with them.
- Opt-in vs. opt-out
- Opt-in requires a consumer's affirmative action before their data is used a certain way; opt-out allows the use by default until the consumer objects β which one applies varies significantly by law and data type.
- Breach notification
- A legal requirement to notify affected individuals (and sometimes regulators) within a defined window after discovering a data breach.
Previous
Business Insurance: What It Actually Covers (and Doesn't)
Next β
Contracts 101: The Agreements That Actually Run Your Business
Discussion & questions
Ask a question about this lesson or share your take.
Loadingβ¦