List the personal data your business collects
Start with a simple inventory: website enquiries, customer records, staff files, invoices, bookings, delivery details, support messages, app accounts, and any sensitive information handled by the business. Record where each data set lives, why it is collected, who uses it, and how long it should be kept.
Review forms, websites, and customer touchpoints
Public forms should ask only for information needed to respond or deliver the service. The website should explain how enquiry data is used, avoid collecting unnecessary sensitive data, and route submissions to controlled business channels rather than personal accounts where possible.
Tighten identity and access
NDPA readiness depends on operational controls, not just policy files. Use named user accounts, remove access for former staff, apply strong passwords or multi-factor authentication where available, and avoid shared admin logins for email, cloud tools, websites, payment systems, and customer records.
Prepare for incidents before they happen
Every business should know who investigates a suspected breach, who communicates with affected people, what systems may need to be locked down, and where evidence is kept. A short breach-response checklist is better than trying to decide everything during an incident.
Check vendors and cloud tools
Many SMEs use external providers for hosting, forms, email, analytics, payments, CRM, messaging, and backups. Keep a list of these tools, what data they process, who manages the accounts, and whether the business can export or remove data when required.
Keep evidence of the controls
Customers and partners may ask for proof that privacy and security practices are real. Useful evidence can include data maps, access reviews, backup checks, privacy notices, staff guidance, vendor lists, risk registers, and records of security improvements. Keep this evidence organised and current.
How Echo1 supports privacy and security readiness
Echo1 Cybersecurity and vCISO services include practical security leadership, risk management, NDPA readiness, assessments, policies, awareness, and executive reporting. The work is scoped around the business environment, including identity, email, devices, data, cloud tools, backups, and compliance exposure.
Need a practical security starting point?
Review Echo1 cybersecurity services, then request a focused assessment of identity, email, devices, data, backups, and compliance exposure.