For the big state privacy laws, almost certainly not: they carry size thresholds, like handling the data of a hundred thousand-plus residents or a large annual revenue, that keep a typical small contractor out of scope. But notification law is different, and it applies to you no matter how small you are. If customer data you hold gets exposed, every state has a law requiring you to notify the people affected. So the honest answer is that the privacy paperwork usually does not bind you, but the breach duty always does. Here is what you actually have to worry about, and the cheap habits that cover most of it.
The state privacy laws: usually not your problem
There is no single federal privacy law, so the country runs on a patchwork of state laws, with around 20 states having comprehensive consumer privacy laws in 2026. The good news for a small trades business is that most of them carry thresholds that exempt you. Typically a law only bites once you process the data of a large number of residents (commonly a hundred thousand or more), or clear a high revenue floor, or make a big share of your revenue from selling data.
Storing customer names, addresses, phone numbers, and emails in a CRM does count as "processing personal data." But being under the threshold means the formal obligations, like publishing a compliant privacy notice or honoring deletion requests on a legal timeline, usually do not apply to you.
Two exceptions worth checking
A couple of states break the usual pattern, so do not assume every state has a threshold that saves you. Some states have no volume threshold at all, meaning the law can reach any business operating there, and others apply broadly unless you qualify as a federally defined small business. If you operate in a state built like that, confirm whether the small-business exemption actually covers you before you assume you are out of scope. Your state's exact rule lives in Working in Your State.
Breach notification: this one always applies
This is the part that catches everyone. All 50 states, plus Washington D.C. and Puerto Rico, have notification laws, and there is no small-business exemption. A sole proprietor with 200 customer records in a spreadsheet who gets hacked is subject to their state's law exactly like a big firm.
- What triggers it: the unauthorized acquisition of personally identifiable information. That usually means a person's name combined with their Social Security number, driver's license number, or a financial account or card number with its access code. Some states also cover medical information, online login credentials, and biometrics.
- The clock varies by state. Some states set a numeric deadline, commonly in the 30 to 60 day range from discovery. Most use language like "without unreasonable delay." Many also require you to notify the state attorney general, and sometimes the credit bureaus. Route your exact deadline and trigger to Working in Your State.
What to do if you get breached
- Contain it. Shut off the access, change credentials, and preserve the logs. Do not wipe anything, because that evidence tells you what was taken.
- Assess what was accessed. Work with your IT help or your CRM vendor to figure out whose data and what fields were exposed.
- Notify the people affected. Tell them what happened, what information was involved, and what they can do, such as placing a fraud alert or watching their accounts.
- Notify your state attorney general if your state requires it. Check Working in Your State for the trigger and the deadline, because this is where the clock is unforgiving.
- Document everything. The timeline of discovery, what you did, and who you notified. If it is ever questioned, your records are your defense.
The cheap habits that cover most of it
- Post a simple privacy policy on your website: what you collect, why, and how someone can ask you to delete it. It costs almost nothing and lowers your risk.
- Use a reputable CRM that runs its own compliance program, and sign its data processing agreement. That covers much of the vendor side for you.
- Turn on multi-factor authentication and stop reusing passwords. Most breaches of a small business start with a compromised login (the digital-safety basics are in Scams that target contractors).
- Do not sell, rent, or share your customer list. Little upside, real legal risk.
- Keep only the data you need for the job, and delete the rest. You cannot lose what you are not holding.
Common questions
Do I need a privacy policy on my website as a small contractor?
Legally you may sit below the threshold of the state privacy laws, so it is often not strictly required, but you should post one anyway. It costs almost nothing, and a simple policy saying what data you collect, why, and how someone can ask you to delete it lowers your risk and looks professional. If you use online forms or advertising pixels, some platforms require one regardless.
Does law apply to a one-person business?
Yes. Unlike the big privacy laws, breach-notification laws have no small-business exemption. All 50 states plus D.C. and Puerto Rico require notification when personal data you hold is compromised, whether you are a large firm or a sole proprietor with a couple hundred customer records in a spreadsheet. If you hold customer data, this duty applies to you.
What counts as a data breach I have to report?
Generally, the unauthorized acquisition of personally identifiable information: most commonly a person's name combined with their Social Security number, driver's license number, or a financial account or card number with its access code. Some states also cover medical information, online login credentials, and biometrics. A lost laptop, a hacked email account, or stolen CRM login can all trigger it.
How long do I have to report a breach?
It depends on your state, so check Working in Your State. Some states set a numeric deadline, commonly 30 to 60 days from discovery, while most require notice "without unreasonable delay." Many also require you to notify the state attorney general, and sometimes the credit bureaus, on top of the affected individuals. Move fast, because the clock is unforgiving.
Can I sell or share my customer list?
You should not, and under some state laws selling personal data is exactly what pushes a business into scope and triggers extra duties. For a small contractor there is little upside and real risk. Keep customer data to what you need for the job, do not rent or sell it, and make sure any vendor who touches it, like your CRM or email platform, has a data processing agreement with you.
The honest bit
- The "around 20 states" count and the threshold shapes are current for 2026 and change fast. Verify the current landscape at a tracker like iapp.org.
- Every state's exact breach deadline, attorney-general notice trigger, and privacy-law threshold varies. Confirm yours in Working in Your State.
- This is general guidance, not legal advice. After a real breach, get a lawyer quickly, because the notification clock starts running the moment you discover it.
Know someone who needs this?
Keep reading
Templates you might need
Was this guide useful?
Didn't find what you were looking for?
Spotted something wrong or out of date? Email us at hello@kilnguides.co.uk.
In crisis? 988 Suicide & Crisis Lifeline 988 ·