December 5, 2025

2026 Privacy Compliance Checklist: What Grand Rapids Businesses Need to Know

This article has been written by Greg Johnson

A practical guide to staying compliant (and avoiding fines) in a changing digital landscape.

Privacy Laws Are Changing Fast. Here’s What That Means for You.


In 2026, privacy compliance is no longer optional, it’s foundational.

Whether you’re a solo practice dental office, a small law firm with a few paralegals, or a service-based business that collects emails from your website, privacy laws apply to you.


According to DLA Piper, GDPR fines alone have topped $6.5 billion globally. And U.S. states like California, Colorado, and Virginia have passed their own strict rules—many of which are actively enforced.


The takeaway? If you collect data online, whether through a contact form, newsletter signup, appointment scheduling tool, or just tracking cookies, you need to take privacy seriously.


And in 2026, that means more than a boilerplate policy buried in your footer.


Why This Matters to Small Businesses


Regulators are watching. Customers are paying attention. And search engines increasingly reward businesses that are upfront about privacy practices.

Privacy isn’t just about staying out of trouble, it’s about building trust.


Your clients want to know:


  • What data you collect
  • Why you collect it
  • Who has access to it
  • And what happens if something goes wrong


Your 2026 Privacy Compliance Checklist ✅


Here’s what your small business needs to have in place this year to stay protected, compliant, and ahead of the curve:


1. Transparent Data Collection

Be clear about what personal data you collect, why you collect it, and how you use it. Avoid vague generalities such as “we might use your information to enhance services.” Be specific and truthful.


✅ Tip: If you're collecting emails, names, or IP addresses—call it out. Let users know how that data will be used (and not used).


2. Consent Management

Consent must be active, recorded, and reversible. Users should be able to opt in or out at will, and you should have records that show when consent was given. You need to refresh user consent whenever you change how their data is used.

  • Active
  • Recorded
  • Reversible


Users should be able to opt in/out easily and you should have a record of when and how they gave consent.


🔄 If your privacy policy changes, get fresh consent.


3. Disclose Third-Party Tools

Be honest about what third parties process user data, from email automation tools to payment systems, and how you evaluate their privacy policies.  Do you use Mailchimp? Stripe? Google Analytics? Those vendors touch your customer data.


List the tools you use and make sure they’re compliant too.


4. Support User Rights

Clearly outline users’ rights, such as access, correction, deletion, data portability, and the ability to object to processing, and make it simple for them to exercise these rights without endless email back-and-forth.


Let users:

  • Request their data
  • Ask for corrections
  • Delete their records
  • Export their data
  • Opt out of certain processing


Make it easy. Don’t bury it in legal jargon or force endless email exchanges.


5. Strong Security Measures

Apply encryption, multi-factor authentication (MFA), endpoint monitoring, and regular security audits.


Implement:

  • Encryption (at rest + in transit)
  • Multi-factor authentication (MFA)
  • Device monitoring + endpoint protection
  • Regular vulnerability scans and audits
Need help? Explore our Managed IT Security Services

6. Cookie Consent (Don’t Wing It!)

Cookie popups are changing and give users more control over non-essential cookies. Don’t rely on default “opt-in” methods or confusing jargon. Clearly disclose tracking tools and refresh them on a regular basis.


Cookie popups need to be:

  • Clear
  • Non-deceptive
  • Easy to manage


Just saying “we use cookies” doesn’t cut it anymore, especially if you’re tracking behavior or using ad pixels.


7. Regional Compliance

f you serve international customers, ensure compliance with GDPR, CCPA/CPRA, and other regional privacy laws. Keep in mind each region has its own updates, such as enhanced data portability rights, shorter breach notification timelines, and expanded definitions of “personal data.”


If you serve customers across state lines (or internationally), you must comply with:

  • GDPR (Europe)
  • CCPA/CPRA (California)
  • VCDPA (Virginia)
  • and others


Each law comes with its own definitions, deadlines, and user rights.


8. Smart Data Retention

Avoid keeping data indefinitely “just in case.” Document how long you retain it and outline how it will be securely deleted or anonymized. Regulators now expect clear evidence of these deletion plans.


Don’t hold onto data forever “just in case.” Create a retention schedule. Delete what you don’t need. Anonymize where appropriate. Regulators now expect to see your deletion policy.


9. Children’s Data

Your privacy policy should have the name of a Data Protection Officer (DPO) or privacy contact point.


If your site is used by minors or collects information from children, you’ll need:

  • Verifiable parental consent
  • Stricter cookie disclosures
  • Age-appropriate privacy notices


10. Disclose Use of AI

Add a “last updated” date to your privacy policy to notify users and regulators that it is actively maintained and up-to-date.


If you use automated decision-making (e.g., AI chatbots, pricing calculators, applicant screeners), you must:

  • Disclose the use of AI
  • Provide users a way to request a human review
  • Explain how the system works—at least in plain terms


11. Public Contact + Governance

If you are collecting data from children, have more stringent consent processes. Some laws now require verifiable parental consent for users under a specified age. Review your forms and cookie use for compliance.


Include a contact person (or Data Protection Officer) for questions or complaints. Add a clear “last updated” date to your privacy policy to show it’s maintained.



What’s New in Privacy Laws in 2026


Privacy regulation is evolving...fast. Here are the major developments shaping compliance this year:


International Data Transfers

Cross-border data flow is under scrutiny again. The EU-U.S. Data Privacy Framework faces new legal challenges, and several watchdog groups are testing its validity in court. Moreover, businesses that depend on international transfers need to review Standard Contractual Clauses (SCCs) and ensure their third-party tools meet adequacy standards.



Consent and Transparency

Consent is evolving from a simple 'tick box' to a dynamic, context-aware process. Regulators now expect users to be able to easily modify or withdraw consent, and your business must maintain clear records of these actions. In short, your consent process should prioritize the user experience, not just regulatory compliance.


Consent must be:

  • Easy to give
  • Easy to revoke
  • Logged properly


No more shady pre-checked boxes or complicated opt-out pages.


Expanded User Rights

Expect broader rights for individuals, such as data portability across platforms and the right to limit certain types of processing. These protections are no longer limited to Europe, several U.S. states and regions in Asia are adopting similar rules.


More regions now offer:

  • Data portability
  • Right to limit profiling
  • Right to restrict processing


Not just in the EU.  These are popping up in California, Virginia, and parts of Asia too.


Breach Notifications

Many regions now require breach reporting within 24–72 hours. No more sweeping it under the rug.

Delays = bigger fines + reputation damage

Children's Privacy + Cookie Crackdowns

Regulators are targeting websites that track minors. You’ll need to ensure cookie banners are region-specific and protect children by default.



What Not to Do


Even smart businesses make mistakes. Avoid these common pitfalls:


❌ Relying on a template you copied from someone else's site

❌ Using confusing, legal-heavy language in your popups

❌ Keeping user data “just in case” for 10+ years

❌ Forgetting to update your privacy policy after launching new tools

❌ Assuming your website developer is handling compliance (they probably aren’t)



FAQ: Common Privacy Questions from Small Business Owners


Do I need a privacy policy if I don’t sell anything online?
Yes. If your site collects info via forms, uses analytics, or embeds third-party tools, you need one.


Does GDPR apply to my Michigan-based business?
If you use tools like Google Analytics or email software that process EU citizen data - yes, indirectly.


What about AI?
If AI is involved in decisions that affect your clients (like pricing, recommendations, or screening), you need to disclose it and allow a human review process.


Can IT Systems help?
Absolutely. We provide compliance audits, setup support, policy guidance, and ongoing tech management for local businesses.



Don’t Let Privacy Laws Catch You Off Guard

In 2026, privacy compliance can no longer be treated as a one-time task or a simple checkbox. It’s an ongoing commitment that touches every client, system, and piece of data you manage. Beyond avoiding fines, these new laws help you build trust, demonstrating that your business values privacy, transparency, and accountability.


This isn’t a one-time box to check.  It’s part of how you do business.  And we can help.


Schedule a Privacy Compliance Assessment

Let’s make your compliance plan a competitive edge.

By Greg Johnson September 14, 2026
If your business runs on Microsoft 365, you've got two places to store files: OneDrive and SharePoint. Most people are never told the difference, so files end up wherever is easiest, spread across OneDrive, SharePoint, Teams, and the desktop. That's how you end up with the everyday headaches: a file nobody can find, a document only one person can open, and a scramble to recover someone's work after they leave. The rule for where things should go is simple once you know what each one is for. What each one is for OneDrive is your own space. Think of it as the cloud version of the My Documents folder on your computer: your work files, private to you unless you choose to share them. It's the right place for drafts and anything only you need. SharePoint is the team's space. It's built for files with shared ownership, the documents your team, department, or the whole business works on together. Microsoft's own advice is straightforward: if you're working on something by yourself, save it to OneDrive; if you're working as a team, save it where the team works. Where Teams fits in Microsoft Teams confuses this for a lot of people, because it looks like a third place to keep files. In reality, when you upload a file to a Teams channel, it's stored in that team's SharePoint site. The Files tab in Teams is just a view into SharePoint. So if your team works in Teams, your shared files are already in SharePoint, whether you realized it or not. That's a good thing. It means the files have shared ownership and don't belong to one person's account. So where should your files live? Here's the rule that keeps things simple: If it's your own draft or something only you need, keep it in OneDrive. If the team needs it, more than one person works on it, or it's a client or project file, put it in SharePoint (or the Teams channel for that work, which is the same thing). Don't leave important shared files sitting only on someone's desktop or only in their personal OneDrive. Sharing files the right way Where a file lives also changes how you share it. When you share a file from your OneDrive, you're sending people into your personal space, usually with a link tied to your account. That works, but the link depends on you. If you leave, or the file moves, those links can stop working, and whoever relied on them is stuck. In SharePoint or a Teams channel, the right people already have access, because the files belong to the team rather than to you. You can point a colleague to the folder and they're in, with no one-off links to manage. It's also worth sharing a link instead of emailing a copy. When everyone opens the same file in OneDrive or SharePoint, they're all looking at the current version, and you avoid ending up with five slightly different copies attached to five different emails. Why this matters Putting files in the right place saves you real trouble later. Take what happens when someone leaves. Their personal OneDrive isn't shared by default, so any important work kept only there can be hard to reach. Microsoft holds a deleted user's OneDrive for 30 days by default and gives their manager access, but that turns into a rush against the clock. Files kept in SharePoint stay with the team no matter who comes or goes. It also makes files easier to find. When the team's documents live in one shared SharePoint library, people know where to look, instead of hunting through inboxes and personal drives. And it helps you recover from mistakes. Both OneDrive and SharePoint keep older versions of your files and a recycle bin, so if a document gets overwritten or ransomware scrambles your files, you can roll back to a clean copy instead of starting over: How to get it right Put shared work in SharePoint or Teams. Anything the team works on together belongs in a shared library. Keep it out of one person's OneDrive. Keep OneDrive for your own files. Drafts and personal work are fine there. Just don't let it become the only home for something the team needs. Get files off local desktops. A file saved only on a laptop isn't backed up, isn't shared, and is gone if the laptop is lost. Move important files into OneDrive or SharePoint. You can still work from your computer the way you always have: the OneDrive app keeps a copy on the device for offline use and saves your changes to the cloud automatically. Agree where things go. A simple, shared rule, like "client files live in the client's SharePoint folder," saves endless confusion later. Use version history when you need it. If a file gets changed or deleted by mistake, you or your IT provider can restore an earlier version rather than redoing the work. Frequently Asked Questions What's the key difference between OneDrive and SharePoint? OneDrive is for your own work files. SharePoint is for files your team shares.  Where do files in a Teams channel get stored? In SharePoint. Every team has a SharePoint site behind it, and the Files tab in a channel is a view into that site. Uploading a file to Teams is the same as putting it in SharePoint. Should I keep work files on my computer's desktop? Try not to, for anything important. A file only on your desktop isn't shared or backed up, and it's gone if the device is lost or breaks. Save it to OneDrive or SharePoint instead, where it's protected and reachable. What happens to files in someone's OneDrive when they leave? By default, Microsoft keeps a deleted user's OneDrive for 30 days and gives their manager access, and that window can be extended if it's set up in advance. It's recoverable, but it's far easier if shared work was in SharePoint to begin with. Can I get back a file that was deleted or changed by mistake? Usually, yes. OneDrive and SharePoint both keep a recycle bin and older versions of files, so you can restore a deleted file or roll back to an earlier version. Your IT provider can help if you can't find it. Article used with permission from The Technology Press.
By Greg Johnson August 28, 2026
 When you search Google for a program to download or a website to log into, the first thing you see is usually an ad. It sits at the top, marked "Sponsored," and most people click it without a second thought, because the top result is normally what you wanted. Scammers count on that. They buy ads on the names of trusted companies and popular software, so their fake site appears right at the top, above the real one, and you click it thinking it's the official page. How the scam works The trick is called malvertising, short for malicious advertising. A scammer buys a search ad for a term people trust, like the name of your bank, a Microsoft login, or a common program such as a PDF reader or a video player. The ad looks normal, with the real brand name and a web address that looks right. When someone clicks it, they land on a page built to look exactly like the real one. Sometimes that page asks you to log in and hands your username and password straight to the scammer. Other times it offers the software you were after, and the download installs malware instead of the real program. Why these ads are so easy to fall for These ads are convincing. They sit above the real result, so they're the first thing you see. They use the real company's name and a web address that looks right. And they show up on a search you started yourself, so they don't feel as suspicious as a random email or text would. Attackers have also gotten good at hiding from the checks meant to stop them. They show a clean, harmless page to the ad reviewers and the real, malicious page to everyone else, so the ad can pass review and still do damage. How common is this? Very. In its 2025 Ads Safety Report , Google said it blocked or removed more than 8.3 billion ads that broke its rules, suspended 24.9 million advertiser accounts, and took down 602 million ads tied to scams. Google also noted that criminals are now using AI to make fake ads faster. Security researchers have found scam search ads pretending to be well-known programs like VLC, 7-Zip, and CCleaner, and even Google's own apps, with downloads that installed password-stealing malware. These show up on the everyday searches your team runs. What this means for your business For a business, the risk comes up in two everyday situations: downloading software, and logging in. When someone downloads software, they search for a tool, click the top ad, and install something that steals the passwords and logins saved in their browser. When someone logs in, they search for "Microsoft 365 login" or their bank, click the ad rather than the official link, and type their username and password straight into a fake page. In both cases, the problem is info-stealing malware. Once it's on a machine, it can steal saved passwords, browser cookies, and session tokens, which can get an attacker into accounts even when multi-factor authentication is switched on. How to protect your team Scroll past the sponsored results. The ads sit at the top, marked "Sponsored" or "Ad." The real website is usually just below, in the normal results. Don't download software from an ad. Type the maker's web address yourself, or search and use the normal result, then download from the official site. Bookmark the sites you log into. For your bank, Microsoft 365, and other important accounts, use a saved bookmark instead of searching each time. Keep devices and browsers updated. Turn on automatic updates so a bad download is less likely to work. Tell your team this is a thing. Most people have no idea the top result can be a trap and, once they know, they stop clicking it. Frequently Asked Questions Aren't ads at the top of Google checked and safe? Google reviews ads and removes billions that break its rules, but scammers still slip through by showing reviewers a clean page and everyone else the malicious one. A "Sponsored" label doesn't mean the site is safe. What is malvertising? Malvertising is short for malicious advertising: scammers buy online ads, often on trusted brand names, to send people to fake sites that steal logins or install malware.

How do I download software safely?

Go to the maker's official website by typing the address yourself, or search and use the normal (non-ad) result. Don't download from a sponsored ad, and don't trust a download that arrives through one. What should I do if someone clicked a scam ad? If they only visited the page, close it and don't enter anything. If they typed a password, change it and turn on MFA. If they downloaded and ran a file, disconnect the device and have your IT provider check it for info-stealing malware. Does an ad blocker help? It can. A reputable ad blocker hides many sponsored results, which takes the fake links off the page before anyone can click them. It isn't a complete fix, so keep the habits above too. Article used with permission from The Technology Press.
Text: QR Code Scams: What They Are and How to Protect Your Michigan Buisiness.
By Greg Johnson August 11, 2026
A QR code scam, sometimes called quishing, hides a malicious web link inside a QR code. Because the link is buried in an image instead of written as text, it slips past the email filters that normally catch bad links, and scanning the code usually moves the victim onto a personal phone that sits outside the company's s
Show More
By Greg Johnson September 14, 2026
If your business runs on Microsoft 365, you've got two places to store files: OneDrive and SharePoint. Most people are never told the difference, so files end up wherever is easiest, spread across OneDrive, SharePoint, Teams, and the desktop. That's how you end up with the everyday headaches: a file nobody can find, a document only one person can open, and a scramble to recover someone's work after they leave. The rule for where things should go is simple once you know what each one is for. What each one is for OneDrive is your own space. Think of it as the cloud version of the My Documents folder on your computer: your work files, private to you unless you choose to share them. It's the right place for drafts and anything only you need. SharePoint is the team's space. It's built for files with shared ownership, the documents your team, department, or the whole business works on together. Microsoft's own advice is straightforward: if you're working on something by yourself, save it to OneDrive; if you're working as a team, save it where the team works. Where Teams fits in Microsoft Teams confuses this for a lot of people, because it looks like a third place to keep files. In reality, when you upload a file to a Teams channel, it's stored in that team's SharePoint site. The Files tab in Teams is just a view into SharePoint. So if your team works in Teams, your shared files are already in SharePoint, whether you realized it or not. That's a good thing. It means the files have shared ownership and don't belong to one person's account. So where should your files live? Here's the rule that keeps things simple: If it's your own draft or something only you need, keep it in OneDrive. If the team needs it, more than one person works on it, or it's a client or project file, put it in SharePoint (or the Teams channel for that work, which is the same thing). Don't leave important shared files sitting only on someone's desktop or only in their personal OneDrive. Sharing files the right way Where a file lives also changes how you share it. When you share a file from your OneDrive, you're sending people into your personal space, usually with a link tied to your account. That works, but the link depends on you. If you leave, or the file moves, those links can stop working, and whoever relied on them is stuck. In SharePoint or a Teams channel, the right people already have access, because the files belong to the team rather than to you. You can point a colleague to the folder and they're in, with no one-off links to manage. It's also worth sharing a link instead of emailing a copy. When everyone opens the same file in OneDrive or SharePoint, they're all looking at the current version, and you avoid ending up with five slightly different copies attached to five different emails. Why this matters Putting files in the right place saves you real trouble later. Take what happens when someone leaves. Their personal OneDrive isn't shared by default, so any important work kept only there can be hard to reach. Microsoft holds a deleted user's OneDrive for 30 days by default and gives their manager access, but that turns into a rush against the clock. Files kept in SharePoint stay with the team no matter who comes or goes. It also makes files easier to find. When the team's documents live in one shared SharePoint library, people know where to look, instead of hunting through inboxes and personal drives. And it helps you recover from mistakes. Both OneDrive and SharePoint keep older versions of your files and a recycle bin, so if a document gets overwritten or ransomware scrambles your files, you can roll back to a clean copy instead of starting over: How to get it right Put shared work in SharePoint or Teams. Anything the team works on together belongs in a shared library. Keep it out of one person's OneDrive. Keep OneDrive for your own files. Drafts and personal work are fine there. Just don't let it become the only home for something the team needs. Get files off local desktops. A file saved only on a laptop isn't backed up, isn't shared, and is gone if the laptop is lost. Move important files into OneDrive or SharePoint. You can still work from your computer the way you always have: the OneDrive app keeps a copy on the device for offline use and saves your changes to the cloud automatically. Agree where things go. A simple, shared rule, like "client files live in the client's SharePoint folder," saves endless confusion later. Use version history when you need it. If a file gets changed or deleted by mistake, you or your IT provider can restore an earlier version rather than redoing the work. Frequently Asked Questions What's the key difference between OneDrive and SharePoint? OneDrive is for your own work files. SharePoint is for files your team shares.  Where do files in a Teams channel get stored? In SharePoint. Every team has a SharePoint site behind it, and the Files tab in a channel is a view into that site. Uploading a file to Teams is the same as putting it in SharePoint. Should I keep work files on my computer's desktop? Try not to, for anything important. A file only on your desktop isn't shared or backed up, and it's gone if the device is lost or breaks. Save it to OneDrive or SharePoint instead, where it's protected and reachable. What happens to files in someone's OneDrive when they leave? By default, Microsoft keeps a deleted user's OneDrive for 30 days and gives their manager access, and that window can be extended if it's set up in advance. It's recoverable, but it's far easier if shared work was in SharePoint to begin with. Can I get back a file that was deleted or changed by mistake? Usually, yes. OneDrive and SharePoint both keep a recycle bin and older versions of files, so you can restore a deleted file or roll back to an earlier version. Your IT provider can help if you can't find it. Article used with permission from The Technology Press.
By Greg Johnson August 28, 2026
 When you search Google for a program to download or a website to log into, the first thing you see is usually an ad. It sits at the top, marked "Sponsored," and most people click it without a second thought, because the top result is normally what you wanted. Scammers count on that. They buy ads on the names of trusted companies and popular software, so their fake site appears right at the top, above the real one, and you click it thinking it's the official page. How the scam works The trick is called malvertising, short for malicious advertising. A scammer buys a search ad for a term people trust, like the name of your bank, a Microsoft login, or a common program such as a PDF reader or a video player. The ad looks normal, with the real brand name and a web address that looks right. When someone clicks it, they land on a page built to look exactly like the real one. Sometimes that page asks you to log in and hands your username and password straight to the scammer. Other times it offers the software you were after, and the download installs malware instead of the real program. Why these ads are so easy to fall for These ads are convincing. They sit above the real result, so they're the first thing you see. They use the real company's name and a web address that looks right. And they show up on a search you started yourself, so they don't feel as suspicious as a random email or text would. Attackers have also gotten good at hiding from the checks meant to stop them. They show a clean, harmless page to the ad reviewers and the real, malicious page to everyone else, so the ad can pass review and still do damage. How common is this? Very. In its 2025 Ads Safety Report , Google said it blocked or removed more than 8.3 billion ads that broke its rules, suspended 24.9 million advertiser accounts, and took down 602 million ads tied to scams. Google also noted that criminals are now using AI to make fake ads faster. Security researchers have found scam search ads pretending to be well-known programs like VLC, 7-Zip, and CCleaner, and even Google's own apps, with downloads that installed password-stealing malware. These show up on the everyday searches your team runs. What this means for your business For a business, the risk comes up in two everyday situations: downloading software, and logging in. When someone downloads software, they search for a tool, click the top ad, and install something that steals the passwords and logins saved in their browser. When someone logs in, they search for "Microsoft 365 login" or their bank, click the ad rather than the official link, and type their username and password straight into a fake page. In both cases, the problem is info-stealing malware. Once it's on a machine, it can steal saved passwords, browser cookies, and session tokens, which can get an attacker into accounts even when multi-factor authentication is switched on. How to protect your team Scroll past the sponsored results. The ads sit at the top, marked "Sponsored" or "Ad." The real website is usually just below, in the normal results. Don't download software from an ad. Type the maker's web address yourself, or search and use the normal result, then download from the official site. Bookmark the sites you log into. For your bank, Microsoft 365, and other important accounts, use a saved bookmark instead of searching each time. Keep devices and browsers updated. Turn on automatic updates so a bad download is less likely to work. Tell your team this is a thing. Most people have no idea the top result can be a trap and, once they know, they stop clicking it. Frequently Asked Questions Aren't ads at the top of Google checked and safe? Google reviews ads and removes billions that break its rules, but scammers still slip through by showing reviewers a clean page and everyone else the malicious one. A "Sponsored" label doesn't mean the site is safe. What is malvertising? Malvertising is short for malicious advertising: scammers buy online ads, often on trusted brand names, to send people to fake sites that steal logins or install malware.

How do I download software safely?

Go to the maker's official website by typing the address yourself, or search and use the normal (non-ad) result. Don't download from a sponsored ad, and don't trust a download that arrives through one. What should I do if someone clicked a scam ad? If they only visited the page, close it and don't enter anything. If they typed a password, change it and turn on MFA. If they downloaded and ran a file, disconnect the device and have your IT provider check it for info-stealing malware. Does an ad blocker help? It can. A reputable ad blocker hides many sponsored results, which takes the fake links off the page before anyone can click them. It isn't a complete fix, so keep the habits above too. Article used with permission from The Technology Press.
Text: QR Code Scams: What They Are and How to Protect Your Michigan Buisiness.
By Greg Johnson August 11, 2026
A QR code scam, sometimes called quishing, hides a malicious web link inside a QR code. Because the link is buried in an image instead of written as text, it slips past the email filters that normally catch bad links, and scanning the code usually moves the victim onto a personal phone that sits outside the company's s
Show More

Share this article