Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Data Privacy Security topic

No spam. Unsubscribe anytime.

Privacy and security briefing: small businesses at risk, FTC checklist and simple steps to reduce exposure

3094780 · April 23, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

A Smith Anderson data privacy specialist and firm lawyers told Raleigh business owners that small firms are frequent targets of breaches, and recommended a short FTC checklist: inventory data, limit collection, lock controls, destroy unneeded data and plan incident response.

David Center, leader of Smith Anderson’s data privacy practice, told the workshop that small businesses face a growing number of cyber incidents and that many are unprepared for a breach. “More than half of data breaches affect small businesses, yet only about 23% of small firms say they are prepared for a cyber incident,” he said.

Center walked attendees through a plain‑English version of the Federal Trade Commission’s five‑step business guidance: take stock (understand what personal data you hold and where it is), scale down (collect only what you need), lock it (physical, administrative and technical safeguards), pitch it (securely destroy data you no longer need), and plan ahead (incident response and vendor contracts).

He advised firms that handle regulated data—particularly health care records subject to HIPAA—or those that process customers across multiple states to review sector‑specific laws and to expect notification duties if a breach occurs. North Carolina has a state breach‑notification law that requires notice to affected individuals and to the attorney general’s office in many cases.

Center recommended simple steps lower‑cost firms can take immediately: identify the categories of personal information they process, restrict access to data to staff who need it, require MFA and vendor contracts that allocate security responsibilities, securely dispose of older records, and prepare a written incident response plan that identifies internal contacts and steps to notify customers and regulators.

Ending: Small firms were told to begin with a short inventory, to adopt basic technical safeguards, and to line up a trusted IT/provider partner and legal counsel to prepare breach response plans and vendor agreements.