Legal · Resource

Privacy: what you hold obligates you

Privacy law stopped being a big company problem: a widening set of US state laws, and international rules the moment you serve customers abroad, attach obligations to data most small companies did not realize they held. The work starts not with policies but with an inventory, because you cannot protect, disclose or delete what you have not mapped.

Map what you actually hold

One afternoon, one spreadsheet: what personal data enters the business, customers, prospects, employees, site visitors; where it lives, which systems and vendors; why you hold it; and who can touch it. Most SMBs discover the same surprises: marketing lists nobody owns, ex-employee data kept forever, and customer information copied across five tools because integration was easier than discipline.

The map drives everything after: the privacy policy that tells the truth, the deletion you can actually perform when a request arrives, and the breach response that knows what was exposed. It also usually shrinks the problem, because the cheapest data to protect is the data you stop collecting.

The legal patchwork, in operator terms

In the US, a growing roster of state laws grants consumers rights, to know, delete and opt out of the sale or sharing of their data, with thresholds that exempt many small firms from the comprehensive statutes but not from sector rules or from basic honesty duties enforced as unfair practice. Internationally, serving European or UK customers brings GDPR-style obligations regardless of your size: a lawful basis for processing, honored subject rights, and disclosure duties.

The operator’s posture that survives the patchwork: tell the truth about what you collect and why, honor deletion and opt-out requests promptly wherever the requester lives, and collect less. Compliance by minimalism scales better than compliance by paperwork.

Vendors and the bad day

Your privacy promises travel through your vendors: the email platform, the analytics, the CRM all process your customers’ data on your behalf, and their failures are your headlines. Keep the vendor list from your data map current, prefer vendors who sign processing terms, and delete the tools you stopped using, which are pure liability with no offsetting value.

Write the breach plan before you need it: who declares an incident, who calls counsel and insurance, how affected people and authorities get notified within the clocks that apply, and where the contact list lives. Notification deadlines are short in most regimes, and companies that improvise them in panic miss them.

How this runs on VelorStrategy

The map, the policy and the plan, on the desk

The Legal Desk holds the privacy program at operator scale: the data map and vendor register in the compliance registry, policy templates that state what you actually do, request handling tracked as matters with their clocks, and the breach plan filed where the bad day can find it.

Velora drafts the first data map from your description of the business and flags the obligations your footprint suggests, with counsel review for the regimes that bind you. From the Plus membership.

This guide is operational education for business owners, not legal advice. Laws vary by state and country; have licensed counsel review anything material before you rely on it.

Frequently asked questions

Do small businesses have to comply with privacy laws?

Increasingly yes: state law thresholds exempt many from the comprehensive statutes, but sector rules, honesty duties and international reach apply regardless of size the moment you hold personal data.

What is the first step in privacy compliance?

A data map: what personal data you hold, where, why, and who touches it. Every policy, request and breach response depends on it, and it usually shrinks the problem by ending needless collection.

What should a breach response plan include?

Roles and declaration authority, counsel and insurer contacts, the notification clocks for your regimes, and templates for telling affected people. Written before the incident, because the deadlines are short.

Run it on the workspace built for execution

VelorStrategy is the strategy and execution workspace for startups and small and midsize companies, in the US and globally: eight desks, one login, and Velora AI across all of it. Join free, no card and no time limit.

Create your free membership ›See memberships

More Legal resources