Data Privacy Compliance for Small Businesses
Data privacy compliance for a small business starts with the FTC's data security expectations under Section 5 of the FTC Act: collect only the data you need, secure it with reasonable safeguards, and dispose of it properly. Beyond that baseline, every state plus the District of Columbia, Puerto Rico and the Virgin Islands requires notifying affected people after a data breach, and a growing number of state privacy laws add further obligations once a business crosses a revenue or data-volume threshold.
By LLC Register · Last reviewed October 1, 2026
Comprehensive Guide
The Baseline Every Business Has to Meet
Even a small business with no customers in a state covered by a specific privacy law still has to meet the FTC's general data security expectation. Under Section 5 of the FTC Act, the FTC treats a business's failure to maintain reasonable safeguards for personal information as a potentially unfair or deceptive practice, which the FTC can act on regardless of the business's size or industry. The FTC's guidance describes this as building an information security program with administrative, technical and physical safeguards appropriate to the data you actually hold.
Three Practices the FTC Points To
Per FTC guidance, the recurring themes across its data security cases and guidance are:
- Collect only what you need. Limiting what personal information you gather in the first place reduces what you have to protect and what's exposed if something goes wrong.
- Secure what you keep. This covers everything from password practices and access controls to vendor contracts covering anyone else who handles your data on your behalf.
- Dispose of it properly. Data you no longer need for a legitimate business purpose should be securely deleted or destroyed, not left sitting in old files or systems.
Every State Requires Breach Notification
All states, the District of Columbia, Puerto Rico and the Virgin Islands have enacted laws requiring notification of security breaches involving personal information, according to the FTC. What counts as a reportable breach, how quickly you must notify affected people, and whether you also have to notify a state agency or the credit bureaus all vary by jurisdiction. If you experience a breach, the FTC recommends securing your systems immediately, assembling a response team that includes legal counsel, and checking the specific state and federal requirements that apply to your business before you notify anyone, since acting too fast without legal guidance can create its own problems.
State Privacy Laws Add Obligations Above a Threshold
Separately from breach notification, a growing number of states, starting with California, have passed comprehensive privacy laws that give consumers rights over their data, such as the right to know what's collected, request deletion, or opt out of having it sold. These laws generally apply only once a business crosses a specific threshold, commonly tied to annual revenue or the number of residents whose data the business handles. A small business below every applicable state's threshold isn't covered by that state's comprehensive privacy law, though it's still subject to the FTC baseline and to breach notification requirements.
Some Federal Laws Apply Regardless of Size
A handful of federal laws apply to specific kinds of data no matter how small the business is. The Gramm-Leach-Bliley Act's Safeguards Rule applies to businesses that handle consumer financial information, including many that wouldn't think of themselves as financial institutions, such as retailers offering financing or tax preparers. The Children's Online Privacy Protection Act applies to any site or service directed at children under 13, or where the operator has actual knowledge it's collecting data from children under 13, and requires verifiable parental consent before collecting their personal information.
Writing a Privacy Policy
Most businesses that collect any personal information through a website benefit from a basic privacy policy describing what you collect, why, and how people can contact you with questions, even where no specific law requires it. Where a state privacy law does apply to your business, its specific disclosure requirements, such as listing consumer rights and how to exercise them, generally have to be reflected in that policy directly.
Practical Considerations
Figure Out Which Laws Actually Apply to You First
It's easy to over-build a compliance program aimed at laws that don't apply to your business yet, or to under-build one aimed only at the FTC baseline while ignoring an industry-specific law like GLBA that does apply. Map your actual data practices, industry and footprint against the specific laws before choosing what to implement.
A Breach Response Plan Is Worth Having Before You Need It
Because breach notification deadlines can be short and vary by state, deciding who's on your response team, including legal counsel, and what your notification process looks like, is easier to do in advance than during an actual incident.
Vendor Contracts Are Part of Your Own Compliance
If a payroll processor, cloud host, or marketing platform handles personal information on your behalf, their security failure can still become your compliance problem. Review what data-protection commitments your vendor contracts actually include.
This Is Not Legal Advice
Which specific state and federal privacy and security laws apply to your business depends on your industry, your data practices, and your footprint, and these laws change frequently. Talk to an attorney experienced in privacy law to confirm your specific obligations, especially before or after a breach.
Sources
The official sources used for this article.
FTC: Data security guidance for business | ftc.gov/business-guidance/privacy-security/data-security |
|---|---|
FTC: Data Breach Response: A Guide for Business | ftc.gov/business-guidance/resources/data-breach-response-guide-business |
FTC: Gramm-Leach-Bliley Act Safeguards Rule | ftc.gov/business-guidance/privacy-security/gramm-leach-bliley-act |
FTC: Children's Online Privacy Protection Rule (COPPA) | ftc.gov/business-guidance/privacy-security/childrens-privacy |
California Privacy Protection Agency: CCPA FAQ | cppa.ca.gov/faq.html |
Created by: LLC RegisterLast reviewed October 1, 2026
Updated: October 1, 2026
Frequently Asked Questions
What's the FTC's basic data security expectation for a small business?
Under Section 5 of the FTC Act, the FTC expects a business to maintain reasonable administrative, technical and physical safeguards for personal information it collects, regardless of its size or industry, and can treat inadequate security as an unfair or deceptive practice.
Does every state require notifying customers after a data breach?
Yes. All states, the District of Columbia, Puerto Rico and the Virgin Islands have laws requiring notification after a security breach involving personal information, though the specific triggers, deadlines and notice requirements vary by jurisdiction, per the FTC.
Do small businesses need to comply with state privacy laws like the CCPA?
Only if they cross that state's applicability threshold, such as a revenue or data-volume amount. A small business below every applicable state's threshold isn't covered by that state's comprehensive privacy law, though it still has to meet the FTC's general security expectation and any breach notification law.
What should a small business do first after discovering a data breach?
The FTC recommends securing your systems immediately to stop further exposure, assembling a response team that includes legal counsel, and checking the specific state and federal notification requirements that apply before notifying anyone, since the right notification process depends on your jurisdiction and what data was exposed.
Form your business with LLC Register
$99 a year for a registered agent, with LLC formation in year one and annual report filing included. State fees are passed through at cost.
