Privacy by Design for Small Businesses
Privacy by design means deciding what personal data you collect, who sees it and when it goes, before you build the form or the process. Seven practical habits for small teams.
"Privacy by design" sounds like something for large technology companies with privacy teams. It is not. It means making privacy decisions at the start, when you design a form, a process or a filing structure, rather than retrofitting them after something goes wrong. Data protection laws in many countries expect it in some form, and the details vary, so check your jurisdiction. The habits below apply everywhere and cost almost nothing when done early.
1. Collect less
For every field on every form, ask: what will we do with this? If the answer is "it might be useful", remove it. Date of birth when you only need to know someone is an adult; a full address when you only need a town; a copy of a passport when seeing it once would do. Data you never collect cannot leak, cannot be requested and does not need deleting.
2. Decide the purpose, and write it down
Each kind of personal data should have a reason attached. "We hold emergency contacts so we can reach someone if an employee is taken ill at work." A written purpose makes later decisions easy: using that list for a marketing mailing is plainly outside it.
3. Separate the sensitive from the ordinary
Health information, identity documents, financial details, anything about children, criminal records: keep these apart from general records, with narrower access. A single shared folder where everything lives together is the opposite of privacy by design.
4. Default to closed
New records should be visible to the people who need them, not to everyone. It is easy to open access later when a reason appears; it is almost impossible to know who looked while everything was open. The same goes for sharing links: expire by default.
5. Set the deletion date when you create the record
Retention is a design decision, not a clean-up job. When you define a kind of record, define how long it lives and what triggers the clock. Then build the reminder in. A retention schedule is the tool: see a records retention schedule template.
6. Choose tools with privacy in mind
Before adopting a new app, ask where the data is stored, whether it is encrypted in transit and at rest (explained here), who at the vendor can access it, whether you can restrict access per record, whether actions are logged, and whether you can export and delete everything if you leave.
7. Make rights requests easy to answer
People may ask to see, correct or delete what you hold about them. If personal data is scattered across inboxes, spreadsheets, desktops and paper, answering takes days. If it lives in structured records per person or per matter, it takes minutes. That is privacy by design paying for itself.
A quick test for any new process
- What personal data does it collect, and is every item needed?
- Who will be able to see it?
- Where will it be stored, and is that place secured?
- When will it be deleted, and who will make sure?
- How would we find it all if the person asked?
If you can answer those five questions before the process starts, you are doing privacy by design. If you cannot, the process is not ready.