Small Business Data Map: A Practical Privacy Readiness Workflow
Learn how to build a small business data map, prepare for DSARs, and clean up privacy operations before there is a problem.
Small Business Data Map: A Practical Privacy Readiness Workflow
Most small businesses do not know where customer data lives until something forces the question. A customer asks you to delete their information. A vendor asks what data you send them. A state privacy law looks relevant. Your email platform, checkout provider, analytics tools, ad pixels, helpdesk, spreadsheets, and contractor folders all hold pieces of the answer.
A small business data map is not a fancy diagram. It is a practical inventory of what personal information you collect, where it came from, why you use it, where it goes, how long you keep it, and how you would find it if someone made a privacy request.
This guide helps you build one without buying software. It is an implementation aid, not legal advice. Privacy laws vary by state, country, industry, data type, and business size, so use this as a readiness workflow and get qualified advice when the stakes are high.
Why a data map comes before a privacy policy
A privacy policy should describe what your business actually does. If you write the policy first, you are guessing. If you map data first, the policy becomes easier and more honest.
The FTC's business guidance emphasizes understanding what personal information you have, who has access to it, and how it moves through your business. Its "Protecting Personal Information" guide says effective security starts by assessing what information you have and identifying who has access to it. See: https://www.ftc.gov/business-guidance/resources/protecting-personal-information-guide-business
That is the heart of data mapping. You cannot protect, delete, export, correct, or explain data you have not located.
Build your first data map in a spreadsheet
Create a spreadsheet with these columns:
| Column | What to write |
|---|---|
| Data category | Name, email, shipping address, order history, payment status, support messages, analytics ID |
| Source | Checkout form, newsletter signup, contact form, platform import, customer email |
| Purpose | Fulfillment, support, marketing, fraud prevention, accounting, analytics |
| System/vendor | Shopify, Stripe, PayPal, Mailchimp, Google Analytics, helpdesk, spreadsheet |
| Shared with | Processor, shipping provider, accountant, contractor, ad platform |
| Retention | How long you keep it and why |
| Deletion/export method | Where to delete, export, or suppress it |
| Owner | Person responsible for knowing this system |
| Notes | Special limits, sensitive data, contract issue, manual process |
Do not try to make it perfect on day one. Start with the systems that touch customers and money:
- Ecommerce platform
- Payment processor
- Email marketing tool
- Analytics and ad pixels
- Customer support inbox or helpdesk
- Shipping/fulfillment tools
- Accounting/bookkeeping software
- Cloud storage folders
- Contractor/vendor access
Then add employee and applicant data if your privacy work includes HR systems.
Include cookies, pixels, and embedded tools
Small businesses often forget website tracking because it is installed once and then ignored.
Make a separate tracker inventory with:
- Tool name
- Page or location
- Purpose
- Data collected
- Whether it is essential, analytics, advertising, personalization, chat, or payment-related
- Vendor privacy page
- Whether it supports opt-out or consent settings
- Owner
Examples:
- Google Analytics on all pages for site measurement
- Meta Pixel on product and checkout pages for ads
- TikTok Pixel on product pages
- Klaviyo or Mailchimp signup forms
- Chat widget on support page
- Stripe, PayPal, or Shop Pay checkout scripts
- Review widgets and referral tools
This matters because many privacy laws focus on collection, disclosure, sale, sharing, targeted advertising, opt-outs, and consumer rights. California's CCPA page says the law gives California consumers more control over personal information businesses collect, including rights around access, deletion, opt-out, and correction. See: https://oag.ca.gov/privacy/ccpa
Colorado's Attorney General explains that the Colorado Privacy Act includes consumer rights to opt out of sale of personal data and targeted advertising, including through a universal opt-out mechanism for covered businesses. See: https://coag.gov/opt-out/
Those pages do not mean every tiny business is automatically covered. They do show why even small businesses should know which trackers and vendors they use.
Create a DSAR process before the first request
DSAR means data subject access request. Depending on the law, the request might ask you to access, delete, correct, opt out, or provide information about personal data. Even if your business is not covered by a specific law today, having a simple process prevents panic.
Create a DSAR workflow:
- Intake: where requests come in, such as privacy@yourdomain.com or a contact form.
- Log: date received, request type, requester name, contact, status, deadline, owner.
- Verify: confirm the requester is the person they claim to be without collecting more data than needed.
- Scope: identify which systems may contain the data.
- Search: use the data map to check ecommerce, email, support, payment, shipping, analytics, and storage tools.
- Decide: determine what can be provided, corrected, deleted, retained, or denied.
- Respond: use a clear written response.
- Record: save what you did, when, and why.
You do not need to write a legal treatise in every response. You do need consistency. A simple log will help you avoid losing track of requests.
Decide what you keep and why
Privacy readiness is not only about responding to requests. It is also about reducing unnecessary data.
For each data category, ask:
- Do we still need this?
- Is there a legal, accounting, fraud, warranty, chargeback, tax, or contract reason to keep it?
- Is it duplicated in multiple places?
- Who can access it?
- Can we delete or anonymize old records?
- Is the retention period written anywhere?
A practical retention schedule might say:
- Newsletter unsubscribes: keep suppression record so the person is not re-added.
- Customer support tickets: review after a set period unless needed for warranty, dispute, or legal reasons.
- Payment records: keep according to accounting and tax needs, but rely on processor records where possible.
- Analytics data: shorten retention where the tool allows it.
- Contractor folders: remove access when the project ends.
Do not invent retention periods casually for tax, employment, healthcare, financial, children's, or regulated records. Put "confirm with advisor" where needed.
Check vendor access
Your data map should show which outside companies can access customer data. For each vendor, capture:
- What data they receive
- Why they receive it
- Whether they are essential to operations
- Whether they offer a data processing addendum or privacy terms
- How to export or delete data
- How they notify customers of incidents
- Whether staff or contractors have individual logins
This is especially important for stores that use many apps. A theme developer, fulfillment partner, review app, analytics platform, and email marketer may all touch different pieces of customer information.
Turn the map into privacy notice updates
Once the map is useful, compare it to your public privacy notice.
Check whether the notice accurately describes:
- Categories of personal information collected
- Sources of information
- Business purposes
- Categories of vendors or third parties
- Cookies, analytics, ads, and tracking
- Consumer choices or request methods
- Retention or criteria for retention
- Contact information
The FTC warns businesses to live up to privacy promises they make, including promises in privacy policies. See: https://www.ftc.gov/business-guidance/privacy-security
If your privacy policy says "we do not share personal information with third parties" but your store uses payment processors, shipping providers, analytics tools, email platforms, and ad pixels, the wording needs review.
A one-day privacy readiness plan
If you only have one day, do this:
- List every customer-facing system and vendor.
- Fill in data category, purpose, vendor, retention, and owner for the top ten.
- Create a tracker inventory for analytics, ads, cookies, chat, and checkout scripts.
- Set up a DSAR request log.
- Draft response templates for access, deletion, correction, and opt-out requests.
- Compare your privacy notice to the data map and mark mismatches.
- Remove stale vendor access and unused tracking tools.
- Add "confirm with counsel/accountant" notes where you are unsure.
That is not a full privacy program, but it gives you a base.
Where the getdigi kit fits
The Data Privacy Readiness Starter Kit packages this into editable small-business worksheets: customer data map, cookie and tracker inventory, DSAR request log, DSAR response templates, vendor checklist, retention/deletion schedule, incident contact log, notice-at-collection checklist, and law-screening worksheet.
Use it to save setup time, not to skip judgment. It is not a finished privacy policy, legal opinion, breach plan, or compliance guarantee. But if your privacy work is scattered across memory, inbox searches, and vendor dashboards, a structured kit can move you from guessing to managing.