On Data Privacy & Security
The Year the Rules Caught Up With You
Data privacy laws that once applied only to large enterprises are now reaching small businesses in states across the country. Here is what 2026 actually requires of you — and what it costs to find out the hard way.
Cale · Dansbee Designs
For most of the past decade, data privacy was something small business owners could reasonably treat as someone else's problem. The regulations being discussed in the news — GDPR, CCPA, data breach notification requirements — felt like enterprise concerns. They were written about in the context of companies with legal teams, compliance departments, and dedicated IT staff. Not the business owner handling client deliverables, payroll, and a leaking faucet in the office bathroom simultaneously.
That window has closed. The legislative pace accelerated sharply in 2024 and 2025, and in 2026 small businesses in a growing number of states are operating under enforceable privacy obligations whether or not they know it. The gap between "this is a large company problem" and "this is your problem" has been quietly legislated away.
What follows is not a legal brief — it is a practical map. Four areas, each with specific actions. The goal is not compliance theater. It is genuine understanding of what changed, what is at risk, and what the smallest possible set of meaningful responses looks like.
"The gap between 'this is a large company problem' and 'this is your problem' has been quietly legislated away."
Area One
The State Privacy Law Explosion
In the absence of federal privacy legislation, states have been writing their own. California moved first with the CCPA in 2020 and expanded it significantly with the CPRA in 2023. What followed was not a slow trickle — it was a surge. Virginia, Colorado, Connecticut, and Utah enacted comprehensive privacy laws in 2023. Texas, Florida, Montana, Oregon, Indiana, Tennessee, and others followed in 2024 and 2025. By 2026, more than twenty states have comprehensive consumer data privacy statutes in effect, with more pending.
These laws are not identical. Each has its own thresholds, definitions, consumer rights, and enforcement mechanisms. But they share a common architecture: they require businesses to be transparent about what data they collect and why, to honor consumer requests to access, correct, or delete that data, and in many cases to allow consumers to opt out of having their data sold or used for targeted advertising.
The threshold question most small business owners ask is: "Does this apply to me?" The honest answer is: it depends on the state and the specific law, but the trend is toward broader applicability with each new statute. California's law applies to businesses that handle the personal information of 100,000 or more consumers, or that derive 50% or more of revenue from selling personal data. Other states have lower thresholds. And crucially — if your business serves customers in a state with a privacy law, that state's law may apply to you regardless of where your business is incorporated or headquartered.
Universal Opt-Out Signals
Several states now recognize the Global Privacy Control (GPC) — a browser-level signal that communicates a consumer's opt-out preference automatically across every website they visit. Colorado, California, and others require that businesses honor this signal as a valid opt-out request. If your website uses any form of tracking, analytics, or advertising technology, this is a technical compliance requirement, not just a policy one.
Mandatory transparency is the other pillar. These laws generally require a privacy notice that accurately describes what data you collect, how you use it, and who you share it with. For a small business whose website was built before any of these laws existed and whose privacy policy is either a generic template or doesn't exist — this is the first place to start.
Enforcement is escalating. Attorneys general in multiple states have made clear that small and mid-size businesses are not invisible to them. The cost of a regulatory inquiry — even one that results in no fine — is measured in time, legal fees, and distraction. The cost of a privacy notice review is not.
Area Two
The AI Risk Factor
Your team is already using AI tools. Not because they are careless — because AI makes them faster, and faster is how people survive a busy week. The problem is not the behavior. It is the absence of any policy governing it, at exactly the moment when the privacy and legal stakes of that behavior have become significant.
Consumer and free-tier AI tools — the ones most employees sign up for on their own without any organizational review — are typically paid for with data. The terms of service of many of these platforms permit the provider to use user inputs to train future model versions, unless the user has found and toggled a specific opt-out setting buried in account preferences. When your employee pastes a client contract, a financial summary, or a customer list into one of these tools to ask for help with a task, that content has been disclosed to a platform your client never consented to and that your contract with your client may expressly prohibit.
The opt-out landscape is not static. Each major AI provider — OpenAI, Google, Anthropic, Microsoft Copilot, and dozens of others — has its own data retention and training policies, and those policies change. Enterprise tiers of these same platforms typically operate under materially different terms: no training data retention, data residency options, and administrative controls over what employees can access. The gap between consumer and enterprise terms is significant, and the cost difference is often modest.
The Minimum Viable AI Policy
A one-page policy does not need to be a legal document. It needs to answer three questions:
What categories of information are never acceptable to share with any AI tool — regardless of the tool or the task?
Which AI tools has the organization reviewed and approved for business use?
What is the process for an employee who wants to use a new AI tool not yet on the approved list?
A policy that exists and is communicated is categorically different from one that doesn't — both for internal accountability and in the event of a regulatory inquiry.
Contractors introduce a separate dimension. A contractor using their own personal free-tier AI account to complete work for your business is not covered by any policy your organization has. If that contractor pastes your client's data into their personal ChatGPT account to summarize a document, you may have a breach on your hands through a channel you never thought to govern. Contractor agreements written before AI tools became ubiquitous almost certainly say nothing about this. In 2026, they should.
Area Three
The Cybersecurity Baseline
"We have antivirus" is the 2026 equivalent of "we have a lock on the front door." It is not nothing — but it is not enough, and it has not been enough for several years. The threat landscape has moved, and the baseline of protection required to keep pace with it has moved with it. What changed is worth understanding specifically, because it explains why the old answer no longer applies.
Traditional antivirus works by comparing files against a database of known malicious signatures. It catches the threats it has already seen. Modern attacks are frequently designed to evade exactly that mechanism — using legitimate system tools that are already present on the machine, hiding inside encrypted traffic, or operating entirely in memory without writing a file to disk that antivirus can inspect. Ransomware groups in particular have become sophisticated at moving through a network for days or weeks before triggering an encryption event, specifically because that reconnaissance period happens below the threshold that antivirus is looking for.
Multi-factor authentication — no exceptions
Every business email account. Every cloud storage repository. Every accounting portal. Every payroll system. MFA means that a stolen password alone is not sufficient to gain access. Business email compromise — where an attacker gains access to an executive's or employee's email and uses it to redirect payments, impersonate the owner, or pivot to connected systems — is among the most financially damaging attacks targeting small businesses, and it almost always succeeds because MFA was not enabled. This is the single highest-return security action available, and it costs nothing beyond the time to configure it.
Endpoint Detection and Response (EDR)
EDR tools monitor endpoints — laptops, desktops, servers — for behavioral indicators of compromise rather than just file signatures. They watch what processes are running, how they are communicating, and whether that behavior looks like an attack in progress, even if the tool being used is a legitimate system utility. Microsoft Defender for Business, CrowdStrike Falcon Go, and SentinelOne are examples at price points designed for small businesses. The cost difference between basic antivirus and EDR is typically a few dollars per device per month. The difference in protection is not marginal.
Patching — current and consistent
A significant percentage of successful attacks exploit known vulnerabilities in operating systems and applications for which patches have already been released. The attack succeeds not because the vulnerability was unknown, but because the patch was not applied. Keeping every device, operating system, and business application current is not glamorous — but it closes the category of attack that accounts for the largest share of successful breaches against small organizations.
Backups — tested and isolated
A backup that has never been tested is an assumption, not a recovery plan. Ransomware operators have learned to target and encrypt backup files before triggering the main encryption event, which is why backups that are connected to the same network they are protecting are not sufficient. The standard is: at least one backup copy that is offline or air-gapped, tested on a schedule, and stored in a location the ransomware cannot reach from the same credentials that were compromised.
Area Four
Know What You Own
Every privacy law, every cybersecurity framework, every insurance underwriting questionnaire eventually arrives at the same set of foundational questions. They are not technical questions. They are organizational ones — and the businesses that can answer them concretely are in a categorically better position than those that cannot, regardless of what tools they use or what policies they have written.
These are the four questions I use with every client before any conversation about technology, platforms, or security products.
What important data does your business own or hold on behalf of others?
Where does that data actually live — which systems, devices, accounts, and locations?
Who has access to it, and is that access list current?
What would it mean for your business operations if that data were lost, corrupted, or exposed tomorrow?
The first question usually produces a general answer. The second starts to reveal the complexity underneath it — data that was supposed to live in one place is also in email attachments, a former employee's personal Dropbox folder, a spreadsheet someone built three years ago that nobody remembers creating. The third almost always produces a pause. Access lists accumulate over time and are rarely pruned. The person who left eighteen months ago may still have credentials that work.
The fourth question is where the real conversation begins. There is consistently a gap between what a business owner believes is their most important data and what is actually irreplaceable. Client relationship history accumulated over a decade. The pricing model that took three years to calibrate. The process that only works because one person remembers the undocumented steps. These are the things that cannot be recreated from a backup — because they were never formally captured in the first place.
This inventory — incomplete as the first attempt will be — is the foundation for every other decision in this essay. You cannot protect what you have not named. You cannot govern access to what you have not located. You cannot assess the risk of loss without understanding the operational consequence of it.
The Reframe
Privacy and security compliance is a large company problem. We're too small to attract attention and too busy to prioritize it.
The regulations do not care about your headcount. The attackers prefer your size. And the cost of a one-time review is a fraction of the cost of discovering this the other way.
None of what is described here requires a compliance department. It requires decisions — made once, thoughtfully, by the person who understands the business well enough to make them. A privacy notice that accurately reflects what your business does. A one-page AI policy. MFA on every account that touches sensitive data. EDR in place of basic antivirus. A written answer to four questions about your data.
That is not a compliance program. That is a Tuesday afternoon and a commitment to not finding out what you should have done from someone who is billing you by the hour to help you do it retroactively.
The Starting Point
One Question Before You Close This Page
Everything above connects to a single underlying question. Take a moment with it.
The Question
If a regulator, a client, or an insurer asked you today to describe what data your business holds, where it lives, and how it is protected — how long would it take you to answer, and how confident would you be in what you said?
The founders who can answer that question quickly and specifically are not the ones who built a compliance department. They are the ones who sat down at some point — before it was urgent — and worked through what they actually knew. The ones who discovered gaps found them in a context where they had time to close them.
2026 is a reasonable moment to be that person. The legal landscape has shifted enough that the question is no longer hypothetical. The technology to protect what you find is available at a price point that fits a small business. And the conversation that starts with "here is what we own and here is how we protect it" is a very different conversation than the one that starts with "we didn't know."
Dansbee Designs
Start with what you actually know.
Every engagement begins with the four questions — not a tool recommendation, not a product. Understanding what you own is the only place from which good decisions follow.
Begin the Conversation