Applies to small businesses too
Measurements, photos, and preferences are sensitive personal data.
Volume 09, Chapter 6
The richer your customer records, the greater your data protection responsibility. The two grow together, a strength and an obligation, side by side.
Personal information, customer and employee data alike, must be collected, stored, and used responsibly, regardless of business size.
Measurements, photos, and preferences are sensitive personal data.
Data collected for fitting records shouldn't silently become marketing.
Decide it before the crisis, not during it.
Rich records are a real advantage and a real responsibility, together.
Imagine a striking fitting photo sits in a business's customer records, taken purely to document a garment's fit. A staff member, meaning no harm at all, considers posting it to social media for marketing. Nobody had ever actually decided whether that was allowed. The photo was collected for one reason and was about to quietly serve a completely different one, and no rule existed to catch that shift before it happened.
is the legal obligation to collect, store, and use personal information, customer and employee data alike, responsibly, securely, and only for the purposes people reasonably expect.
A customer's measurements, phone number, and order history (Volume 04, Chapter 7) and an employee's salary and personal details (Volume 04, Chapter 5) are all personal data, and in most countries, the business has legal obligations about how that information is collected, stored, and shared, regardless of how small the business is.
Don't gather personal details with no clear business reason.
Restrict access with the same discipline as password management.
A number collected for order updates shouldn't fund unrelated marketing.
Many laws give individuals the right to review or correct their data.
Many countries legally require notifying affected people.
| Principle | What It Means in Practice |
|---|---|
| Collect only what's needed | Don't gather personal details with no clear business reason |
| Store it securely | Restrict access per Volume 04, Chapter 8's rule and Volume 20's password discipline |
| Use it only as expected | A customer's phone number collected for order updates shouldn't be used for unrelated marketing without consent |
| Allow correction and deletion where required | Many data protection laws give individuals the right to review or correct their own data |
| Report serious breaches | Many countries legally require notifying affected people (and sometimes a government authority) after a serious data breach (personal data being lost, stolen, or exposed) |
Specific data protection laws, thresholds, and breach-notification rules vary significantly by country. This chapter teaches the underlying principles, confirm specific legal requirements with a qualified local professional, especially if the business handles data across borders.
It's tempting to assume data protection only matters for large tech companies. But recall Volume 05, Chapter 3's Measurement Intelligence System, body measurements, photos, and personal preferences are exactly the kind of sensitive personal data these principles protect. A business that builds rich customer records (a genuine advantage, per Volume 04, Chapter 7) takes on a real responsibility to protect that same data properly.
The richer your customer records, the greater your data protection responsibility. The two grow together, a strength and an obligation, side by side.
Here's the full version of the fitting-photo story from the start of this chapter.
MANIAC MINDZ's fitting photos (Volume 05's measurement intelligence) were a genuine quality advantage, until a staff member, meaning no harm, considered posting a striking fitting photo to the shop's social media for marketing. Because no policy existed, it was unclear whether that was acceptable. A simple rule fixed it going forward: any customer photo used publicly requires explicit, recorded consent, otherwise, photos stay strictly internal, access-controlled per Volume 04, Chapter 8.
| Business | A Data Protection Consideration |
|---|---|
| Bright Path Academy | Student records require particularly careful handling in most countries |
| Nimbus Labs | Customer data stored digitally, often across borders, the most legally complex case |
| Rapid Auto Works | Vehicle and customer contact records, often shared with parts suppliers |
Gathering personal information with no clear purpose increases risk without adding value.
As in the photo story, data collected for one reason (fitting records) shouldn't silently be repurposed (marketing) without asking.
Many countries require timely notification after a serious breach, decide the response plan before it's needed, not during the crisis.
List every type of personal data your business collects (customers and employees). For each, confirm: is it actually needed, is it stored securely and access-controlled, and is it ever used for a purpose the person wouldn't reasonably expect?