The Admin
Information about other people is a responsibility that arrives with the work
Almost every small business ends up holding details about customers and sometimes about their customers too, and the obligations attached to that are neither optional nor obvious.
By Nikhil Bose3 min read

You are holding more than you think
The mental picture of a business that handles personal information is a large one with a database. In practice a one-person business accumulates a surprising amount: contact details, addresses, correspondence, photographs, payment details, notes about people’s circumstances, and occasionally information about somebody else’s customers that arrived as part of a job.
It is spread across a phone, an email account, a laptop, a couple of services and a notebook, and almost none of it was collected deliberately. That diffusion is precisely why it is worth thinking about once, since obligations attach to the information rather than to whether you meant to gather it.
The rules vary and their shape does not
Most countries now have rules about handling information relating to identifiable people, and while the detail differs, the shape is broadly similar. There is usually an expectation that you have a legitimate reason for holding it, that you collect no more than you need, that you keep it securely, that you do not keep it indefinitely, and that the people it concerns have some rights over it.
What those rules require of a specific business in a specific country is not something to infer from a general description, and the consequences of ignoring them can be more than nominal. This is a topic for local guidance or a qualified adviser rather than for assumption, particularly if you handle anything sensitive.
Being small is not usually an exemption
A common belief is that these obligations apply only to organisations of a certain size. In most systems that is not how it works — the rules generally follow the activity rather than the headcount, though there may be lighter requirements for smaller operations in some places.
The practical risk for a very small business is rarely a formal investigation. It is a client asking what your arrangements are and receiving no coherent answer, which increasingly costs work, and it is the mess that follows an incident where nobody knew what was held or where.
The practical minimum
Four things go a long way. Know what you hold and roughly where it is. Keep it somewhere access-controlled rather than scattered across devices anybody could pick up. Delete what you no longer need, on some kind of schedule rather than never. And do not send personal information around by casual means because it is quicker.
None of that requires a system or a policy document. It requires an afternoon once, and a habit afterwards. The single most useful action is usually the deletion, because information you no longer hold can’t be lost, misused or asked about.
Clients are starting to ask
Larger customers increasingly pass their own obligations down the chain. That can arrive as a questionnaire, a clause in their terms, or a requirement to handle their data in a particular way and to tell them promptly if something goes wrong.
Those requirements are usually reasonable and occasionally disproportionate for a one-person supplier, and they are negotiable more often than people assume. What is not negotiable is having an answer, because a supplier who cannot describe how they handle information is a risk the client’s own rules may not permit them to accept.
If something does go wrong
Losing a device, sending an email to the wrong recipient, or having an account accessed by somebody else are ordinary occurrences rather than exotic ones. In many systems certain incidents must be reported, sometimes quickly, and sometimes the people affected must be told.
Because the thresholds and timescales differ by country, the useful preparation is knowing in advance who you would ask rather than working it out during the event. The instinct to keep quiet is understandable and usually the worst available option, both because reporting may be required and because the people affected generally find out anyway.
The preparation that helps most is the dull kind. Knowing what is on the device that went missing, being able to lock or wipe it remotely, having the accounts protected by something more than a password reused elsewhere, and keeping a note of who would need to be told. None of that prevents an incident. It changes it from a situation nobody can describe into one with a known extent, and the extent is what determines almost everything that follows.
Consumer editor, Biz Wealth Focus
Nikhil joined to cover starting out, pricing, cash flow and stayed for the awkward questions and would rather show the working than assert the conclusion.





