If your business collects any customer information - names, emails, phone numbers, payment details, health data, or anything else that identifies a real person - you have privacy and security duties, even if you're a one-person shop. Every state requires you to notify people (and sometimes the state) after certain kinds of data breaches. A growing number of states also have their own comprehensive privacy laws. And depending on what you handle - health records, financial account data, payment cards, or data from children - additional federal rules may apply. None of this requires a big compliance department. It requires a basic privacy policy, reasonable security habits, and a plan for the day something goes wrong.
The three layers of duty
Think of your privacy obligations in three layers, because they come from different sources and don't all apply to every business:
Data-breach notification laws (all states, but the rules vary). Every state - along with the District of Columbia - has a law requiring businesses to notify affected individuals, and sometimes the state attorney general or a consumer reporting agency, after a breach involving certain personal information. There is no single national breach-notification statute, so what counts as "personal information," how fast you must notify, who you must notify, and what the notice must say are all set at the state level and differ from state to state.
Comprehensive state privacy laws (a growing but not universal list). Separately, a number of states - more than 20 as of 2026, and the list keeps growing - have passed broader consumer privacy laws that give residents rights over their own data (to see it, delete it, opt out of certain uses) and that impose duties on businesses that collect it. These laws typically apply based on where your customers live, not where your business is located, and most exempt smaller businesses through revenue or data-volume thresholds - but those thresholds vary law to law. This area is changing quickly, so confirm which states' laws currently reach your business before relying on last year's rule.
Sector-specific federal rules. If you're in certain industries or handle certain kinds of data, additional federal privacy and security laws apply on top of general state law (more below).
Because both the state count and the specific thresholds change, don't rely on a general article (including this one) for the current list. Confirm what applies to your business using the Federal Trade Commission's business guidance and your state attorney general's consumer-protection or privacy page.
Sector rules that may apply to you
Most small businesses aren't covered by these, but check if any fit your situation:
HIPAA - applies to health care providers, health plans, and their business associates who handle protected health information. If you run a medical, dental, therapy, or similar practice, or you process health data for one under contract, HIPAA's privacy and security rules likely apply on top of state law.
GLBA (Gramm-Leach-Bliley Act) - applies to businesses "significantly engaged" in financial activities, which the FTC interprets broadly to include tax preparers, mortgage brokers, check-cashing businesses, and others handling customers' financial information, not just banks. The FTC's Safeguards Rule under GLBA sets specific security requirements for covered businesses.
PCI-DSS - not a government law, but a security standard required by the card networks and your payment processor if you accept credit or debit cards. Nearly any business that takes card payments is contractually bound to some level of PCI-DSS compliance, and most modern payment processors handle much of this for you if you use their compliant systems rather than storing card data yourself.
COPPA (Children's Online Privacy Protection Act) - applies if you operate a website, app, or online service directed at children under 13, or if you have actual knowledge you're collecting personal information from children under 13. It requires verifiable parental consent before collecting most data from kids in that age group and is enforced by the FTC.
These federal rules and their basic structure are stable - but the specific requirements and any updated rulemaking (the FTC has amended the COPPA and GLBA Safeguards rules in recent years) should be confirmed at ftc.gov or the relevant federal agency before you rely on them.
What "reasonable security" generally looks like
Neither the FTC nor most state laws demand perfect security - they generally expect security that's reasonable for the size of your business and the sensitivity of the data you hold. In practice, that usually means:
Knowing what personal data you actually collect and where it's stored - you can't protect what you haven't inventoried.
Limiting access so only people who need customer data to do their job can see it.
Using unique passwords and multi-factor authentication for accounts that touch customer data.
Keeping software, point-of-sale systems, and networking equipment updated with security patches.
Encrypting sensitive data where practical, especially on laptops and portable devices.
Not keeping data longer than you need it - especially full payment card numbers, which you generally shouldn't be storing at all if your processor offers a compliant alternative.
Vetting vendors and contractors who touch customer data, and having a contract that requires them to protect it too.
The FTC publishes free, practical small-business data security guidance at ftc.gov that walks through this in plain language - it's a genuinely useful starting checklist, not just enforcement boilerplate.
What to do: building your basics
Write a short privacy policy. Describe, in plain language, what personal information you collect, why you collect it, whether you share or sell it, and how people can contact you with questions. Post it on your website if you have one, and keep a copy even if you don't.
Take inventory of the data you hold. List what personal information flows through your business - customer contact info, payment data, employee records, health or financial details - and where each type lives (your point-of-sale system, email, a spreadsheet, a cloud vendor).
Check whether sector rules apply to you. If you're in health care, financial services, or handle children's data online, look into HIPAA, GLBA, and COPPA specifically rather than assuming general rules cover you.
Tighten basic security. Unique passwords, multi-factor authentication, updated software, and limited access go a long way and cost little or nothing.
Write a one-page breach response plan before you need it. Include: who internally is notified first, who decides if it's a reportable breach, which attorney or IT professional you'll call, and a rough notification checklist. Deciding this during an actual breach, under pressure, is how mistakes and missed deadlines happen.
Know where to look up your state's specific rules. Bookmark your state attorney general's consumer protection or privacy page - that's typically where breach-notification and any state privacy law requirements are published for free.
If a breach happens
Data-breach notification deadlines and requirements are set state by state, and they can be short - some states require notice within a matter of days once you determine notification is required, others give more time, and the definition of what triggers the duty at all also varies. Don't guess. When you discover a possible breach:
Secure the incident first - stop ongoing data loss, but don't destroy evidence you may need for the investigation or an insurance claim.
Figure out what data was involved and whose - this determines which state or states' notification laws apply, since it's based on where the affected individuals live, not where your business is.
Get help promptly - a data-breach or privacy attorney, and your cyber-insurance carrier if you have a policy, can tell you the actual notification deadline and requirements that apply given what happened and who was affected.
Notify as required - affected individuals, and depending on the state and the scope, possibly the state attorney general, consumer reporting agencies, or your sector regulator.
The FTC's free Data Breach Response: A Guide for Business walks through this process and includes a model notification letter - it's a solid starting point regardless of which state's specific deadline applies to you.
A note on liability and your business structure
Having an LLC or corporation protects you from a lot of business risk, but it does not automatically shield you from privacy or breach-notification liability for your own negligence in handling data - regulators and affected customers can still pursue the business, and in some circumstances an owner personally, if security was clearly unreasonable. Limited liability is never absolute. If a breach becomes serious enough to threaten the business financially, our coverage of business debts and personal guarantees explains how those are handled in that situation - but the far better outcome is preventing that call from ever needing to happen.
Where to go for help
ftc.gov - small business data security guidance, the Data Breach Response Guide, and COPPA/GLBA Safeguards Rule information.
Your state attorney general's office - your state's specific breach-notification law and, if applicable, its comprehensive privacy law.
A qualified attorney - for reviewing your privacy policy, assessing whether a specific state privacy law applies to your business, or responding to an actual breach.
SBA.gov and your local Small Business Development Center - free, general small-business guidance, including on cybersecurity basics.
This is general information, not legal, tax, or financial advice.
Frequently asked questions
Do I really have to worry about this if I'm just a solo freelancer or a small local shop?
Size doesn't exempt you from breach notification duties in most states - if you hold customer names, emails, payment info, or other personal data and it's exposed, the notification duty can still apply to a business of any size. Comprehensive state privacy laws are different: most of those do carve out small businesses by revenue, customer volume, or the type of data involved, so it's worth checking whether a given state law actually reaches you rather than assuming either way.
What counts as a 'data breach' that triggers notification?
It varies by state, but generally it means unauthorized access to or acquisition of personal information that compromises its security - things like a stolen laptop with customer records, a hacked email account containing Social Security numbers, or a payment system intrusion. Many states also cover accidental disclosure, like sending a file with customer data to the wrong recipient. The exact definition and what data elements trigger it (name plus SSN, driver's license number, account number, etc.) differ by state, so check your state's statute or your attorney general's guidance.
Do I need a written privacy policy even if I don't have a website?
A privacy policy is most commonly associated with websites and apps, but if you collect any customer data - even a simple client intake form or an email list - it's good practice to have a short, honest written statement of what you collect, why, and how you protect it. If you do have a website or online store, more state privacy laws and platform requirements (like payment processors) expect a posted privacy policy.
What's the difference between a privacy law and PCI-DSS?
State and federal privacy laws are government laws enforced by regulators or through lawsuits. PCI-DSS (Payment Card Industry Data Security Standard) is a private contractual security standard set by the card networks and enforced through your merchant/payment processor agreement, not a government statute - but violating it can still mean fines, higher fees, or losing your ability to accept cards, so it matters just as much in practice.
What should I do right now if I don't have any of this in place?
Start with the two lowest-effort, highest-value steps: write a short privacy policy describing what data you collect and why, and write a one-page breach response plan (who to call, who to notify, in what order) before you need it. Then use the free FTC small-business data security guidance at ftc.gov to check your basic security practices, and search your state attorney general's website for your state's breach-notification and privacy-law requirements.
This article is general legal information, not legal advice, and may not reflect the most current law or the law in your jurisdiction. Laws vary by state and change over time. For advice about your specific situation, consult a licensed attorney.
Knowing your rights is the first step
Join thousands committing to calmly and consistently exercise their constitutional rights.