If you asked most small or medium business owners whether they handle personal data, many would pause before answering. They might think of customer databases, online orders, or payment details. When those things are not central to the business, it can seem as though personal data is only a minor concern.
In practice, most businesses hold far more personal information than they realise. It builds up gradually through recruitment, payroll, sales, customer support, project delivery, and everyday communication. Over time, it becomes spread across inboxes, cloud platforms, shared folders, business applications, and individual devices.
This is common in small and growing businesses. New tools are introduced as the business develops, employees create practical ways to get work done, and information is copied or shared to solve immediate problems. The result is often a large amount of personal data that no one has ever viewed as a complete picture.
Understanding that picture provides a useful starting point for both privacy and cybersecurity. Once you know what information you hold, where it lives, why it is needed, and who can access it, the next decisions become much easier to prioritise.
Personal data is more than customer lists
When people hear the term personal data, they often think of names and email addresses stored in a customer database. Those are personal data, but the definition is much broader.
Personal data generally means information that identifies a real person, either on its own or when combined with other information. It can relate to customers, employees, contractors, job applicants, suppliers, business contacts, and people who made an enquiry but never became customers.
Common examples include:
- Contact details such as names, email addresses, telephone numbers, and home addresses.
- Financial information such as bank account details, payment records, and payroll information.
- Identity information such as passport copies, driver’s licences, dates of birth, and identification numbers.
- Employment information such as contracts, performance notes, leave records, and salary details.
- Health or accessibility information provided by employees or customers.
- Online information such as account activity, device details, IP addresses, and support conversations.
- Opinions or notes about an identifiable person, including interview feedback or customer complaints.
A single item may appear harmless in isolation. When several pieces of information are brought together, they can provide a surprisingly detailed view of someone’s life, employment, finances, or relationship with your business.
Where personal data quietly accumulates
Most businesses do not set out to collect excessive personal data. It usually appears as a by-product of ordinary work and remains in place because there has never been a clear reason or process for removing it.
Email is one of the most common examples. A customer might attach an identity document to help resolve an issue. A job applicant may send a resume containing their address, employment history, and references. A manager may email payroll information to an accountant. These messages can remain in several inboxes and sent folders long after the immediate task has been completed.
Personal data also tends to accumulate in:
- HR folders containing contracts, emergency contacts, identification documents, payroll records, and performance notes.
- Accounting platforms storing bank details, addresses, tax information, invoices, and transaction histories.
- Shared drives containing old proposals, customer forms, signed agreements, scanned documents, and project files.
- Customer relationship management systems holding contact details, notes, correspondence, and sales history.
- Support systems where customers provide screenshots, documents, or personal explanations to describe a problem.
- Messaging platforms where information is shared quickly between colleagues and then forgotten.
- Laptops and mobile devices containing downloaded attachments, exported reports, and locally saved copies.
- Older systems that are no longer used regularly but still contain historical customer or employee records.
None of these locations is unusual. The difficulty comes from information being spread across many places without a clear view of the whole environment.
Growth can make personal data harder to see
Personal data often becomes more difficult to manage as a business grows.
A small team may begin with a few shared folders and a simple accounting system. New software is then added for recruitment, project management, marketing, customer support, document signing, and collaboration. Each platform may hold another copy of the same information.
Staff also create practical workarounds. They download spreadsheets to prepare reports, send documents to personal email accounts while travelling, or share links with contractors to keep a project moving. These decisions may be reasonable at the time, but the information can remain accessible long after the original need has passed.
Responsibility can become unclear as well. The IT provider manages systems, finance looks after payroll, operations manages customer processes, and the business owner carries the overall risk. Each person understands one part of the picture, but no one may be responsible for reviewing personal data across the business.
This is one reason generic privacy and cybersecurity checklists can feel difficult to apply. Recommendations such as encryption, access controls, retention periods, policies, and staff training may all be useful, but their priority depends on the data your business actually holds and how it is used.
Some personal data needs more attention than others
Personal data does not carry the same level of risk in every situation.
A public business email address generally presents a different concern from a passport copy, medical note, bank account number, or payroll record. A list of ten professional contacts is also different from a database containing detailed information about thousands of people.
When deciding where to focus, it helps to consider:
- How sensitive the information is.
- How much information is held about each person.
- How many people are included.
- Whether the information could be used for identity theft, fraud, discrimination, or embarrassment.
- Whether losing access to the information would disrupt the business or affect the person concerned.
- Whether the business still has a clear reason for keeping it.
This does not require a complicated scoring system. The purpose is to identify which information deserves closer attention so that time and effort can be directed towards the most meaningful risks.
Employee data can be particularly sensitive
Customer information often receives the most attention, but employee data can be more detailed and more sensitive.
Even a very small employer may hold:
- Home addresses and personal telephone numbers.
- Bank account and payroll details.
- Copies of identity documents.
- Emergency contact information.
- Leave records and health-related information.
- Performance reviews, complaints, and disciplinary records.
- Background checks or information supplied during recruitment.
This information is often retained for a long time. Copies may remain in email accounts, shared folders, payroll systems, and archived backups after an employee has left.
Because employee information feels internal and familiar, access can also become broader than intended. A shared HR folder may gradually become available to managers or administrators who no longer require it. Former employees or contractors may retain access to systems containing staff records if their accounts are not removed promptly.
A review of employee data is often a useful place to begin because it usually reveals clear opportunities to improve access, storage, and retention.
Why this matters beyond compliance
Privacy laws vary between countries and can depend on the size of the business, the location of the people concerned, the industry, and the type of information being handled.
Compliance is important, but the practical reasons for understanding personal data extend beyond legal requirements.
Customers, employees, and business partners expect reasonable care to be taken with their information. They may also ask questions about how their data is stored, protected, shared, or deleted, particularly when choosing a supplier or completing a security review.
When personal data is scattered and unmanaged, several problems become more difficult:
- Access is harder to control because the business does not have a clear view of where the information is stored.
- Old information remains available even though it no longer supports a business purpose.
- Privacy requests take longer because records must be found across several systems.
- Security incidents are harder to investigate because no one knows exactly what information may have been involved.
- Customer and employee questions are harder to answer with confidence.
- The amount of information affected by an account compromise or data breach may be greater than necessary.
Understanding the information your business holds creates a clearer basis for privacy, security, and customer assurance decisions.
What commonly goes wrong
Businesses rarely struggle with personal data because they do not care. More often, the information has accumulated gradually and no one has had the time, ownership, or context to review it.
Some common issues include:
- Data is kept “just in case” without a clear business reason or review date.
- Multiple copies of the same document exist across email, shared folders, and local devices.
- Former employees and contractors retain access to systems or files.
- Sensitive documents are sent as email attachments when a more controlled method could be used.
- Shared links remain active long after a project or customer request has ended.
- Broad groups of employees can access personal information that only a few people use.
- Old software platforms remain connected or accessible because they contain historical records.
- No one has clear responsibility for deciding how personal data should be stored, shared, or deleted.
These gaps are common in growing businesses. They can usually be addressed through a series of focused improvements rather than a large compliance project.
Create a simple map of your personal data
A useful first action is to create a basic map of one important business process.
Trying to document every system and every piece of information at once can become overwhelming. A more manageable approach is to choose an area such as recruitment, payroll, customer onboarding, project delivery, or customer support and follow the information through that process.
For each process, ask five questions:
- What personal information do we receive or create?
Consider forms, emails, documents, notes, reports, recordings, and information entered directly into software. - Where is it stored or copied?
Include the main business system as well as email accounts, shared folders, downloaded files, backups, and connected applications. - Why are we keeping it?
Identify the operational, contractual, legal, or customer reason for retaining the information. - Who can access it?
Look at employees, managers, administrators, contractors, IT providers, software vendors, and external advisers. - How long should it remain available?
Consider when the information stops being useful and whether there are legal or contractual reasons to retain it.
This can be completed as a short team discussion or a simple spreadsheet. The goal is to develop enough visibility to make sensible decisions, rather than to create a perfect record of the entire business.
What to do once you can see the data
Once personal data becomes visible, the improvements are usually easier to identify.
The first actions often fall into four areas.
Remove information that is no longer required
Old identity documents, abandoned customer forms, duplicate spreadsheets, and outdated contact records can create risk without providing much value.
Deleting information should be considered carefully, particularly where legal or contractual retention periods apply. Where there is no reason to continue holding it, removal reduces the amount of information the business has to protect.
Limit access to the people who use it
Personal data is easier to manage when access reflects someone’s current role.
This may involve reviewing shared folders, removing former employees, limiting administrator accounts, checking external sharing links, and confirming that contractors can only access the information required for their work.
Improve how sensitive information is collected and shared
Email is convenient, but it is not always the best place for sensitive documents.
Depending on the information involved, a controlled upload form, secure portal, restricted shared folder, or time-limited link may provide better visibility and access control. The right approach will depend on the business, the people involved, and the systems already available.
Set a practical review point
Personal data tends to accumulate again when there is no agreed time to review it.
A yearly review, a customer closure process, or a clear deletion period can help prevent old information from being kept indefinitely. A simple and consistently followed process is often more useful than a detailed policy that no one has time to apply.
How BrightShield helps you turn visibility into action
Understanding what personal data your business holds is an important first step, but it can still be difficult to decide which improvements should come first.
BrightShield helps small and growing businesses understand their current position, identify the risks that matter in their environment, and turn those findings into a practical Cyber Action Plan.
With Guided, your business receives a tailored plan, practical resources, and expert support while your team carries out the improvements. This can include clearer data handling practices, stronger access controls, better account management, and support with privacy and security documentation.
With Complete, BrightShield manages the improvement work with your team and IT provider. We help coordinate the actions, address the agreed gaps, and confirm that the work has been completed properly.
For growing businesses that need continuing oversight, customer assurance, or support managing security and privacy responsibilities, Security Leadership provides ongoing access to experienced security guidance without the cost of building a full internal security function.
BrightShield’s role is to help make the situation clearer and more manageable. The focus remains on the information your business holds, the way your team works, and the improvements that will make the most meaningful difference.
Clearer information leads to better decisions
Most businesses do not need to map every piece of personal data in one sitting. Building a clearer picture of one important process is enough to begin making better decisions.
Once you understand what information you hold, where it lives, why it is needed, and who can reach it, priorities become easier to see. You can remove unnecessary information, improve access where it matters, and build sensible handling practices into everyday work.
Personal data has usually accumulated through normal business activity. Improving how it is managed can happen in the same way, through practical steps that fit the business and become part of how work is done.
That clearer understanding provides a stronger foundation for privacy, security, and customer trust, while giving the business greater confidence that the information entrusted to it is being looked after properly.



