Obligations that come with collecting information.
WHAT YOU PROBABLY COLLECT
Contact form submissions Order details and delivery addresses Email addresses for marketing Analytics data Account details, if you have logins
ALL OF IT IS PERSONAL DATA
Under the NDPR and comparable frameworks, that carries obligations.
PRACTICAL MEASURES
Collect only what you need. Remove form fields you do not act on.
Protect access: strong passwords, two-factor authentication, and administrator accounts only for those who need them.
Delete what you no longer need. Old form submissions and abandoned accounts accumulate. Publish a privacy notice describing what you do. Use HTTPS, always.
NEVER STORE CARD DETAILS
Use a hosted payment gateway. There is no legitimate reason for a small business website to hold card numbers.
EXPORTED DATA
A customer list downloaded as a spreadsheet must not sit in a web-reachable folder. Anyone guessing the URL can take it.
IF THERE IS A BREACH
Contain it, assess what was exposed, take advice on notification obligations, and tell affected people honestly.
THIS IS GENERAL GUIDANCE
Take proper advice on what applies to your business.