LLC Register
  • Start your business

    • Start an LLC
    • Form a Business
    • File an S-Corp Election
    • Hire a Registered Agent

    Filings & compliance

    • Articles of Organization
    • Certificate of Formation
    • Operating Agreement
    • EIN & Tax ID Number
    • Foreign Qualification
    • Change Registered Agent
    • Annual Report
    • Stay Compliant

    Not sure where to start?

    Pick your state to see LLC filing fees.

    CaliforniaFiling fee $70

    Form your LLC in California →
    Help me decide →
  • Resources
  • About Us
Start my LLC
  • Start your business
    • Start an LLC
    • Form a Business
    • File an S-Corp Election
    • Hire a Registered Agent
    Filings & compliance
    • Articles of Organization
    • Certificate of Formation
    • Operating Agreement
    • EIN & Tax ID Number
    • Foreign Qualification
    • Change Registered Agent
    • Annual Report
    • Stay Compliant

    Not sure where to start?

    Pick your state to see LLC filing fees.

    CaliforniaFiling fee $70

    Form your LLC in California →
  • Resources
  • About Us
Start my LLC
LLC Register
  1. Home
  2. ›
  3. Resources
  4. ›
  5. Business Compliance

Data Privacy Compliance for Small Businesses

Data privacy compliance for a small business starts with the FTC's data security expectations under Section 5 of the FTC Act: collect only the data you need, secure it with reasonable safeguards, and dispose of it properly. Beyond that baseline, every state plus the District of Columbia, Puerto Rico and the Virgin Islands requires notifying affected people after a data breach, and a growing number of state privacy laws add further obligations once a business crosses a revenue or data-volume threshold.

By LLC Register · Last reviewed October 1, 2026

Read Comprehensive Guide
LLC Register

Key Takeaways

  • The FTC's baseline applies to every business, regardless of size

    Under Section 5 of the FTC Act, the FTC expects businesses to maintain reasonable administrative, technical and physical safeguards for personal information, and can treat inadequate security as an unfair or deceptive practice.

  • Breach notification laws cover all 50 states

    All states, the District of Columbia, Puerto Rico and the Virgin Islands have laws requiring notification after a security breach involving personal information, though the specific triggers and deadlines vary by jurisdiction, per the FTC.

  • State privacy laws apply only above a threshold

    Laws like California's CCPA apply once a business crosses a revenue or data-volume threshold, such as $26.625 million in annual revenue; a small business under every applicable threshold isn't covered by those specific laws.

  • Industry-specific federal laws can apply regardless of size

    A business handling financial data may be subject to the Gramm-Leach-Bliley Act's Safeguards Rule, and one collecting data from children under 13 is subject to COPPA, regardless of revenue.

Start Your LLC
In this article
  • Comprehensive Guide
  • Practical Considerations

Comprehensive Guide

The Baseline Every Business Has to Meet

Even a small business with no customers in a state covered by a specific privacy law still has to meet the FTC's general data security expectation. Under Section 5 of the FTC Act, the FTC treats a business's failure to maintain reasonable safeguards for personal information as a potentially unfair or deceptive practice, which the FTC can act on regardless of the business's size or industry. The FTC's guidance describes this as building an information security program with administrative, technical and physical safeguards appropriate to the data you actually hold.

Three Practices the FTC Points To

Per FTC guidance, the recurring themes across its data security cases and guidance are:

  • Collect only what you need. Limiting what personal information you gather in the first place reduces what you have to protect and what's exposed if something goes wrong.
  • Secure what you keep. This covers everything from password practices and access controls to vendor contracts covering anyone else who handles your data on your behalf.
  • Dispose of it properly. Data you no longer need for a legitimate business purpose should be securely deleted or destroyed, not left sitting in old files or systems.

Every State Requires Breach Notification

All states, the District of Columbia, Puerto Rico and the Virgin Islands have enacted laws requiring notification of security breaches involving personal information, according to the FTC. What counts as a reportable breach, how quickly you must notify affected people, and whether you also have to notify a state agency or the credit bureaus all vary by jurisdiction. If you experience a breach, the FTC recommends securing your systems immediately, assembling a response team that includes legal counsel, and checking the specific state and federal requirements that apply to your business before you notify anyone, since acting too fast without legal guidance can create its own problems.

State Privacy Laws Add Obligations Above a Threshold

Separately from breach notification, a growing number of states, starting with California, have passed comprehensive privacy laws that give consumers rights over their data, such as the right to know what's collected, request deletion, or opt out of having it sold. These laws generally apply only once a business crosses a specific threshold, commonly tied to annual revenue or the number of residents whose data the business handles. A small business below every applicable state's threshold isn't covered by that state's comprehensive privacy law, though it's still subject to the FTC baseline and to breach notification requirements.

Some Federal Laws Apply Regardless of Size

A handful of federal laws apply to specific kinds of data no matter how small the business is. The Gramm-Leach-Bliley Act's Safeguards Rule applies to businesses that handle consumer financial information, including many that wouldn't think of themselves as financial institutions, such as retailers offering financing or tax preparers. The Children's Online Privacy Protection Act applies to any site or service directed at children under 13, or where the operator has actual knowledge it's collecting data from children under 13, and requires verifiable parental consent before collecting their personal information.

Writing a Privacy Policy

Most businesses that collect any personal information through a website benefit from a basic privacy policy describing what you collect, why, and how people can contact you with questions, even where no specific law requires it. Where a state privacy law does apply to your business, its specific disclosure requirements, such as listing consumer rights and how to exercise them, generally have to be reflected in that policy directly.

Practical Considerations

Figure Out Which Laws Actually Apply to You First

It's easy to over-build a compliance program aimed at laws that don't apply to your business yet, or to under-build one aimed only at the FTC baseline while ignoring an industry-specific law like GLBA that does apply. Map your actual data practices, industry and footprint against the specific laws before choosing what to implement.

A Breach Response Plan Is Worth Having Before You Need It

Because breach notification deadlines can be short and vary by state, deciding who's on your response team, including legal counsel, and what your notification process looks like, is easier to do in advance than during an actual incident.

Vendor Contracts Are Part of Your Own Compliance

If a payroll processor, cloud host, or marketing platform handles personal information on your behalf, their security failure can still become your compliance problem. Review what data-protection commitments your vendor contracts actually include.

This Is Not Legal Advice

Which specific state and federal privacy and security laws apply to your business depends on your industry, your data practices, and your footprint, and these laws change frequently. Talk to an attorney experienced in privacy law to confirm your specific obligations, especially before or after a breach.

Related Resources

  • Cookie Consent Requirements Explained

    Learn cookie consent requirements under state privacy laws, including opt-out links, Global Privacy Control signals, and which businesses must comply.

  • CAN-SPAM Act Compliance Checklist

    Find out what the CAN-SPAM Act compliance checklist requires, including disclosures, opt-out rules, and the FTC's per-email penalty for violations.

  • LLC Recordkeeping Requirements

    Learn LLC recordkeeping requirements, including formation documents, financial records, and how long the IRS expects you to keep tax records.

Sources

The official sources used for this article.

FTC: Data security guidance for business

ftc.gov/business-guidance/privacy-security/data-security

FTC: Data Breach Response: A Guide for Business

ftc.gov/business-guidance/resources/data-breach-response-guide-business

FTC: Gramm-Leach-Bliley Act Safeguards Rule

ftc.gov/business-guidance/privacy-security/gramm-leach-bliley-act

FTC: Children's Online Privacy Protection Rule (COPPA)

ftc.gov/business-guidance/privacy-security/childrens-privacy

California Privacy Protection Agency: CCPA FAQ

cppa.ca.gov/faq.html

Created by: LLC RegisterLast reviewed October 1, 2026

Updated: October 1, 2026

Frequently Asked Questions

What's the FTC's basic data security expectation for a small business?

Under Section 5 of the FTC Act, the FTC expects a business to maintain reasonable administrative, technical and physical safeguards for personal information it collects, regardless of its size or industry, and can treat inadequate security as an unfair or deceptive practice.

Does every state require notifying customers after a data breach?

Yes. All states, the District of Columbia, Puerto Rico and the Virgin Islands have laws requiring notification after a security breach involving personal information, though the specific triggers, deadlines and notice requirements vary by jurisdiction, per the FTC.

Do small businesses need to comply with state privacy laws like the CCPA?

Only if they cross that state's applicability threshold, such as a revenue or data-volume amount. A small business below every applicable state's threshold isn't covered by that state's comprehensive privacy law, though it still has to meet the FTC's general security expectation and any breach notification law.

What should a small business do first after discovering a data breach?

The FTC recommends securing your systems immediately to stop further exposure, assembling a response team that includes legal counsel, and checking the specific state and federal notification requirements that apply before notifying anyone, since the right notification process depends on your jurisdiction and what data was exposed.

Form your business with LLC Register

$99 a year for a registered agent, with LLC formation in year one and annual report filing included. State fees are passed through at cost.

Start Your LLC
LLC Register

Any questions?

We're available Monday through Friday from 9am - 6pm CST

Start your business

Start an LLCForm a BusinessFile an S-Corp ElectionHire a Registered Agent

Filings & compliance

Articles of OrganizationCertificate of FormationOperating AgreementEIN & Tax ID NumberForeign QualificationChange Registered AgentAnnual ReportStay Compliant

Company

ResourcesContact UsPrivacy PolicyTerms of Service360 Legal

LLC Register helps entrepreneurs form and maintain their LLC with fast, guided filings and ongoing compliance support. This site provides general information and is not a substitute for legal or tax advice.

LLC Register is not a law firm and does not provide legal advice. Communications with LLC Register are not protected by attorney-client privilege.

Powered by 360Legal