Skip to main content

Data Protection

How to Protect Customer Information

Practical steps small businesses can take to protect customer data: what you hold, who can reach it, how it is stored, and what to do if something goes wrong.

7 min readPublished

Protecting customer information is often presented as a technology problem. It is mostly a decision problem: what you choose to collect, how long you choose to keep it, and who you allow to reach it. The technology follows from those answers.

This guide covers the controls that matter most for a business without a dedicated security team, roughly in the order we would tackle them.

Educational guidance, not legal advice

This article explains widely recommended practices. It is not legal advice and it is not a compliance determination. Requirements vary by state, industry, and contract — confirm what applies to your business with a qualified professional.

Know what you hold

You cannot protect data you have forgotten about, and forgotten data is where breaches tend to originate. Before buying anything, spend an hour answering: what customer information do we have, where does it live, and who can reach it?

Look in the places people overlook:

  • Email — inboxes and sent folders often hold years of attachments.
  • Spreadsheets on individual computers and in shared drives.
  • Cloud storage, including personal accounts used for work.
  • Your booking, invoicing, accounting, and CRM systems.
  • Paper files, and the scanner or printer that stores copies.
  • Old laptops and drives in a cupboard.
  • Backups, which contain everything the originals did.

Sorting it simply

Formal data classification schemes are overkill here. Three tiers are enough:

  • Public — information already published.
  • Internal — ordinary business information that should not be public but would cause limited harm if exposed.
  • Sensitive — anything that could harm a customer or your business if disclosed: identification numbers, financial and payment details, health information, credentials, and detailed personal records.

Spend your effort on the third tier. Treating everything as critical is a reliable way to protect nothing well.

Collect and keep less

Every piece of sensitive data you hold is something you must protect, store, back up, and eventually dispose of. The FTC’s longstanding business guidance opens on exactly this point: take stock, then scale down.

Practically:

  • Review your intake forms and remove fields you do not actually use. Date of birth and identification numbers are frequently collected out of habit.
  • Do not store full payment card numbers. Your payment processor is equipped to handle them; you almost certainly are not. See what is PCI DSS? for why this matters.
  • Set a retention period for customer records and actually apply it. Deleting data you no longer need is a genuine security control, not housekeeping.
  • Dispose of things properly — securely wipe drives before disposal, shred paper, and clear out old email attachments.

Control who can reach it

Least privilege means each person has access to what their job requires and nothing more. It is not about distrust; it limits the damage when an account is compromised, which is the realistic threat.

  • Give every person their own account. Shared logins make it impossible to know who did what and impossible to remove one person’s access.
  • Use administrator accounts only for administrative work. Day-to-day use should be a standard account.
  • Review access periodically — twice a year is reasonable — and remove what is no longer needed.
  • Remove access the day someone leaves. This is the most commonly missed step, and it applies to contractors too.

Secure the accounts

Multi-factor authentication

If you do only one thing from this article, do this. Multi-factor authentication means a stolen password alone is not enough to get in. Enable it on email first — email is the recovery route for nearly every other account you own, which makes it the highest-value target — then on banking, payment, accounting, and any system holding customer data.

Prefer an authenticator app or a hardware security key over text messages where the option exists. Text-message codes are meaningfully better than nothing and worth using if that is all a service supports.

Passwords

Current guidance has moved away from forced frequent changes and complexity rules, which tend to produce predictable passwords. What actually helps: long and unique passwords for every account, a password manager so that is realistic, and immediate changes when a password may have been exposed. Never reuse a password between a personal service and a business system.

Secure the devices

  • Turn on full-disk encryption — BitLocker on Windows, FileVault on macOS. A stolen encrypted laptop is a hardware loss; a stolen unencrypted one may be a data breach.
  • Require a screen lock with a short timeout on computers and phones.
  • Keep software updated. See why small businesses need patch management.
  • Run reputable security software and confirm it is actually reporting, not silently disabled.
  • Know which devices exist. Personal phones and home computers with access to business email are part of your footprint whether or not you manage them.

Moving and sharing data safely

Data at rest is usually better protected than data in motion. The weak points are typically routine and mundane.

  • Stop emailing sensitive attachments. Email copies persist in multiple mailboxes indefinitely. Use a shared system with access controls, or a link with an expiry date.
  • Confirm your website uses HTTPS everywhere, especially on any page with a form.
  • Check recipients before sending. Misdirected email is one of the most common causes of small-business data exposure, and no security product prevents it.
  • Be deliberate about removable media. USB drives get lost. If you must use them, encrypt them.

Email is the most likely entry point

Most incidents at small businesses begin with an email: a convincing request to change payment details, a fake login page, or an attachment that installs something. Technical filtering helps. What helps more is a standing rule that any request to change bank details or send money urgently is verified by phone, using a number you already have — not one supplied in the message.

Vendors and third parties

Your data is only as protected as the least careful party holding it. For each vendor with access to customer information — software providers, bookkeepers, marketing agencies, IT support — establish what data they can reach, whether their access is still needed, whether they use individual accounts with multi-factor authentication, and what their obligation is to notify you if they suffer an incident.

Remove vendor access as soon as an engagement ends. Dormant vendor accounts are a recurring finding in breach investigations.

The human side

Awareness training has a poor reputation because it is usually delivered as an annual video nobody remembers. Short, specific, and repeated works better. Make sure everyone knows: how to recognize a suspicious message, that reporting a mistake quickly is welcomed rather than punished, why payment-change requests are always verified by phone, and who to tell when something looks wrong.

The tone matters. If people fear blame, they hide mistakes, and a concealed incident is far more expensive than a reported one.

Prepare for the bad day

Assume something will go wrong eventually. Preparation is what separates a contained problem from a prolonged one.

  • Know who to call — internally, and externally for IT and legal support. Keep that list somewhere reachable if systems are down.
  • Have working backups you have actually restored from. See backup planning for small businesses.
  • Preserve evidence. Do not wipe and rebuild immediately; you may need to establish what happened and what was reached.
  • Understand your notification obligations.Most states require notifying affected individuals when certain personal information is breached, and timelines vary. The FTC’s data breach response guide is a practical starting point, and this is a point to involve counsel.

Talking to customers

If customer data is affected, communicate clearly and early: what happened, what information was involved, what you have done, what they should do, and how to reach you. Avoid speculation before facts are established, but do not delay notification while pursuing certainty you may never reach. Businesses rarely regret communicating too plainly.

Practical checklist

Customer data protection checklist

  • Inventory where customer information lives, including email, spreadsheets, cloud storage, paper, and backups.
  • Sort it into public, internal, and sensitive — then focus effort on sensitive.
  • Remove fields from intake forms that you collect but never use.
  • Confirm you are not storing full payment card numbers anywhere.
  • Set and apply a retention period; delete records you no longer need.
  • Give every person an individual account; eliminate shared logins.
  • Turn on multi-factor authentication for email first, then financial and customer systems.
  • Use a password manager so long, unique passwords are practical.
  • Reserve administrator accounts for administrative tasks only.
  • Enable full-disk encryption and short screen-lock timeouts on all devices.
  • Keep operating systems and applications patched.
  • Replace sensitive email attachments with access-controlled sharing.
  • Adopt a standing rule: verify payment-detail changes by phone, using a known number.
  • Review who has access twice a year, and remove access the day someone leaves.
  • List vendors with access to customer data and confirm what each can reach.
  • Keep tested backups and confirm you have restored from them at least once.
  • Write down who to call during an incident and store it somewhere reachable offline.

No single item here prevents every breach, and any honest summary has to say so. Together they remove the easy paths, which is what most real-world attacks depend on.

Sources and further reading

Need help applying this to your business?

We can review your current setup, point out what actually needs attention, and recommend a practical next step — whether or not it involves working with us.