Protecting Customer Data: Simple Habits for Small Businesses
Customer phone numbers, addresses, and purchase history are both a trust and a legal duty under Indonesia's PDP Law. Simple practices — no IT team needed.
Picture a scenario that happens more often than anyone admits: a long-time cashier resigns, and her personal phone still holds the contacts of hundreds of your customers — complete with order chats and delivery addresses. Three months later, your customers start receiving broadcasts from the new shop where she works. Nothing was hacked. The data was simply never guarded.
Small business customer data — WhatsApp numbers, addresses, member birthdays, purchase history — tends to be treated as trivial: scattered across admins’ phones, Excel files forwarded between group chats, a notebook in the register drawer. Two things have changed in recent years: customers notice and resent leaks far more than they used to, and the law now has teeth.
No longer just ethics: Indonesia’s PDP Law
Since the Personal Data Protection Law (Law No. 27 of 2022) came into full force in October 2024, anyone collecting and processing personal data — including small businesses — carries a legal duty to protect it. Not just large corporations. A shop recording customer WhatsApp numbers for a membership program is a personal data processor too.
The essence, without needing a law degree: collect only what you need and with the owner’s knowledge, use it for the purpose it was collected, keep it from leaking, and delete it on request. Penalties scale up to serious fines — but long before those, the fastest punishment is the unwritten one: a customer who feels their data was misused does not come back, and the story travels.
Collect less, worry less
The cheapest principle in data protection: data you never store cannot leak. Before adding a field to a member or order form, ask one question — what exactly is it for? A loyalty program needs a name and a WhatsApp number; does it need a birth date? Perhaps, for birthday promos. Does it need a national ID number? Almost certainly not.
An equally important small habit: never request sensitive data through open channels. Asking customers to write phone numbers on a queue sheet other visitors can read, or to send an ID card photo over chat for something that does not require it — these are small leaks made to feel normal.
Get the data off personal phones
The biggest risk in a small business is not hackers; it is scatter. Customer contacts on employees’ personal phones, a file called “Member Data Final (2).xlsx” living on five laptops, and an internal WhatsApp group full of forwarded recaps containing customer addresses.
The fix points one direction: centralize. Customer data lives in one system — a CRM, your POS, or at minimum one access-controlled spreadsheet — and everyone works from it, never from copies. A central system also enables two controls impossible on personal phones: role-based access (a cashier can look up a member during a sale without being able to download the whole list) and access revocation when someone leaves — the account is disabled the same day, and the data does not change employers with them. In a system like Tenavora, per-role permissions and an audit trail of who accessed what are built in rather than bolted on.
Do not neglect the mundane layers either: one shared account with the password “shop123” is a warehouse door that is never locked. One person, one account, real passwords, and two-step verification on the accounts that matter — business email, mobile banking, payment dashboards.
Broadcast yes, spam no
Data collected to fulfill orders is not a license to message people promos three times a day. Ask for simple consent when signing up members (“happy to receive promo info by WA?”), respect a no, and always provide an exit — reply STOP to unsubscribe. Beyond being polite and compliant, this protects your business WhatsApp number from the spam reports that end in blocks. We covered frequency and etiquette in our WhatsApp guide for local businesses.
If the worst happens anyway — a file spreads, an account is breached — do not sit on it. Tell affected customers honestly and quickly; the PDP Law in fact requires it. A business that owns up and apologizes almost always fares better than one caught covering up.
Customers hand over their numbers because they trust you. Treat the data like something held in trust: stored properly, used sparingly, returned on request. Businesses that do earn something increasingly rare in any market — customers who feel safe leaving their data with you.