Compliant by design: what it means for a 10-person business
Compliant by design, explained for a small business: where the idea comes from, what it means day to day, a one-page checklist, and what it doesn't mean.
By the Ceety Systems teamUpdated 5 min read
Key takeaways
- Compliant by design means the rules are built into how your tools work from the start, not patched on after a problem.
- The idea comes from privacy law: GDPR Article 25 requires data protection by design and by default.
- For a small business it comes down to a few habits: collect less, prove consent, give everyone their own login, protect sensitive data and keep a record.
- Most of it can be done by your tools, if you choose tools that do it.
- It isn’t a certificate. It makes compliance easier to show, and your own policies still matter.
Compliant by design means building the rules your business lives under into how your technology works from the first day, instead of fixing things after a complaint, an audit or a breach. For a 10-person business that mostly means a handful of habits: collect only what you need, record consent, give everyone their own login, protect sensitive information and keep a record of who did what. The good news is that the right tools do most of it for you.
This article explains where the idea comes from, what it looks like day to day, and a one-page checklist you can use this week.
Where does "compliant by design" come from?
The idea is written into privacy law. Article 25 of the EU’s General Data Protection Regulation is titled "Data protection by design and by default" (GDPR, Regulation (EU) 2016/679). It asks organizations to build safeguards into how they process data "both at the time of the determination of the means for processing and at the time of the processing itself". It also says that, by default, "only personal data which are necessary for each specific purpose of the processing are processed".
US guidance says much the same about security. The Federal Trade Commission’s guide Start with Security (August 2023) opens with the point that "sound security is no accident". It also notes that companies that consider security from the start "make reasonable choices based on the nature of their business and the sensitivity of the information involved."
"Compliant by design" applies the same thinking to all the rules a business lives under. For a small business those are privacy, texting consent, security and, increasingly, AI.
What does it mean day to day?
Collect only what you need
Every field on a form is information you now have to protect. If you don’t need a date of birth to book a consultation, don’t ask for it. GDPR calls this data minimisation, and it’s the cheapest control there is: data you never collected can’t leak.
Record consent you can prove
If you text customers, you need their permission, and you need to be able to show it. That means a checkbox that isn’t pre-ticked and wording that says what they’ll get. Keep a record of the exact words they agreed to, where and when. Service texts, such as appointment reminders, and marketing texts need separate consent. Our guide to A2P 10DLC registration explains what the carriers check.
Give everyone their own login
Shared passwords are convenient, and they make it impossible to know who did what. The FTC’s guide lists "Control access to data sensibly" and "Require secure passwords and authentication" among its first lessons. One login per person, with access that matches their job, is the foundation for everything else.
Protect sensitive information
Some information needs more care: Social Security numbers, health details, financial documents. The FTC’s guide says to "Store sensitive personal information securely and protect it during transmission". In practice that means encrypted storage, showing only what’s needed (the last four digits, not the whole number), and never putting personal details in web addresses or email subject lines.
Keep a record
When someone asks what happened to a customer’s data, whether a customer, a partner, an insurer or a regulator, a record of who did what, and when, is your answer. The record needs to be one that can’t be quietly edited.
Put a person in charge of automation
Automated texts, reminders and AI tools save time, and they should never act beyond what a person has approved. A "NO" reply to a reminder should create a task for your team, not cancel an appointment on its own. And AI should draft while a person decides. Our article on safe AI for small business goes into this.
Choose providers who do this for you
A small business can’t build all of this itself, and it doesn’t have to. The FTC’s guide says: "Make sure your service providers implement reasonable security measures". The practical test is to ask each provider how it handles consent, logins, sensitive data and records, and to prefer the ones that answer plainly.
A one-page checklist
- Every form asks only for what we need.
- Texting consent is a separate, unticked box, with the wording saved.
- Service and marketing texts have separate consent.
- STOP and unsubscribe work everywhere, straight away.
- Everyone has their own login, and nobody shares passwords.
- Access matches each person’s job.
- Sensitive numbers and documents are encrypted and only partly shown.
- No personal details in web addresses or email subject lines.
- There is a record of who did what that can’t be edited.
- Automations and AI draft or suggest, and a person approves anything that reaches a customer.
- We know what each provider does with our customers’ data.
- We review this list when we add a new tool.
What compliant by design doesn’t mean
It isn’t a certificate, and it doesn’t make a business compliant on its own. Whether you meet a particular law also depends on your policies, your contracts and how your team works day to day. What compliant by design gives you is controls that are already in place, and the evidence to show them when someone asks.
This article is general information, not legal advice.
How does it differ by business size?
- A 10-person business needs the checklist above, and tools that do most of it by default.
- A growing business adds written policies, access reviews when people join or leave, and a named person responsible for data.
- A larger organization adds formal frameworks such as SOC 2 or ISO 27001, independent audits, and documented risk assessments.
How Ceety builds it in
Compliant by design is how we build and run everything. On the Ceety Platform:
- consent is recorded with the exact words the person agreed to, and service and marketing consent are kept separate;
- opt-outs are honored everywhere at once;
- each person has their own login, and staff users are unlimited on every plan;
- sensitive numbers are encrypted, and every full view is logged with a reason;
- an audit trail records who did what, and it can’t be edited;
- a person approves every action the AI proposes.
Frequently asked questions
Is compliant by design a legal requirement?
For organizations covered by the GDPR, data protection by design and by default is a legal requirement under Article 25. In the US there’s no single rule by that name, but the FTC’s guidance for businesses starts from the same point: consider security from the start.
Does compliant by design mean we’re HIPAA-compliant or GDPR-compliant?
No. It means the controls those rules ask for are built in, which makes compliance easier to reach and to show. Whether you comply also depends on your own policies and practices.
We’re only ten people. Is this overkill?
No. Much of the checklist is habits and tool settings rather than spending. Consent records, separate logins and an audit trail are far easier to start with than to add after a problem.
Where do we start?
Start with forms and logins. Remove fields you don’t need, add a proper consent box if you text customers, and give everyone their own login. Then work down the checklist.