When data privacy is worth the effort
Teams tend to reach for this after something has already gone wrong. Data privacy is not free, and pretending otherwise leads to bad decisions.
The realistic threat for most small businesses is automated and opportunistic, not targeted. Check it against what you would want a competitor's site to get wrong.
When it is worth it
Collect only what you can justify keeping. It is worth being explicit about, because assumptions differ quietly. Assume whoever inherits this will have half your context and none of your patience.
When it is not
If nothing downstream depends on it and nobody is complaining, it can wait. The reasoning matters more than the rule, because the rule has exceptions.
How to decide
Know where personal data actually lives. Getting it slightly wrong is survivable. Ignoring it entirely is not. It is worth deciding this deliberately rather than inheriting whatever the last person set up.
In practice
Security is a maintenance habit rather than a purchase, which is why it drifts. Three things worth confirming about data privacy before you move on:
- Someone can say what the current setup is without going to look
- Know where personal data actually lives — and you know whether that is true here
- There is a way to tell whether the last change to this helped
Pick the one that would hurt most if it failed, and start there.