All posts
Guidance· 20 August 2026· 5 min

Five privacy mistakes small businesses make (and how to fix them)

Most data-protection problems in small businesses come from a handful of everyday habits rather than dramatic failures. Here are five of the most common, with practical fixes.

1. Collecting more data than you need

It is tempting to ask for everything "just in case". The Act expects you to collect only what is necessary for a clear purpose. Review your forms and intake processes and remove fields you do not genuinely use.

2. Keeping data forever

Data you no longer need is a liability, not an asset. Set documented retention periods for the main categories of records you hold, and dispose of information securely when the period ends.

3. Sharing customer lists over informal channels

Member spreadsheets forwarded by email or sent through messaging groups are a frequent source of accidental disclosure. Limit access to the people who need it, and use proper access controls rather than broad sharing.

4. No plan for rights requests

When someone asks to see the data you hold about them, an ad-hoc response risks missing the statutory deadline. A simple, written process, who receives the request, how identity is verified, how you search and respond, removes the panic.

5. Assuming a breach "won't happen here"

Lost phones, misdirected emails and compromised passwords affect careful businesses too. A short, rehearsed breach-response routine means you can assess and, if needed, notify within the required timeframe.

Legal note. This article is general information about the Data Protection Act, 2020, and is not legal advice.

Fixing most of these takes hours, not weeks. The free Compliance Health Check will tell you which to prioritise for your business.