Only 64% of small businesses with 1 to 19 employees have a documented internal privacy policy addressing staff obligations, compared with 87% of businesses with 100 or more employees, according to the Office of the Privacy Commissioner of Canada's 2025-26 survey, fielded January 19 to February 25, 2026, among 800 businesses. That 23-point gap sits at the center of a wider pattern: small firms are less prepared on paper and more exposed in practice, since Verizon's 2026 breach data shows small and mid-sized businesses absorb the overwhelming majority of ransomware attacks.
The numbers below combine two threads that rarely appear in the same place: how small businesses handle privacy documentation and training internally, and how exposed those same businesses are to breaches, fines, and the compliance workload that follows. Both threads point the same direction.
What share of small businesses have a written privacy policy?
78% of small businesses report having a customer-facing privacy policy in place, and 88% say they have taken steps to comply with applicable privacy laws, according to the OPC's 2025-26 survey. That sounds close to universal until you separate the customer-facing policy from the internal one: only 64% of small businesses have documented internal policies that tell staff how to actually handle personal information day to day, the gap this post's headline stat measures.
The size gradient is consistent across every measure the OPC tracked. Businesses with 100 or more employees report 87% documentation, mid-sized firms fall between the two, and the smallest businesses trail on every metric from written policy to staff training. A small business selling directly to consumers can close the biggest gap in that gradient by keeping its published privacy policy generated and up to date rather than relying on a template written once and never revisited.
Figure 1: Documentation rates climb steadily with business size. Source: Office of the Privacy Commissioner of Canada, 2025-26 Survey of Canadian Businesses on Privacy-Related Issues (n=800).
How does staff privacy training differ by business size?
55% of small businesses regularly provide staff with privacy training and education, compared with 76% among businesses with 100 or more employees, per the OPC's 2025-26 survey. Training is the practice most directly tied to day-to-day mistakes: a written policy that nobody on staff has been walked through does little to stop a misdirected email or an unencrypted file transfer.
Safeguarding measures follow the same pattern. Only 42% of small businesses report storing customer data off-site with third-party services under a formal arrangement, a lower rate than medium and large organizations report, per the same survey. Fewer safeguards paired with less training compounds the exposure documented in the breach data below.
Figure 2: A 21-point training gap between the smallest and largest businesses surveyed. Source: Office of the Privacy Commissioner of Canada, 2025-26 Survey of Canadian Businesses on Privacy-Related Issues.
Are small businesses actually more likely to be breached?
96% of ransomware victims where organization size was known were small or mid-sized businesses, according to Verizon's 2026 Data Breach Investigations Report, which analyzed incidents between November 2024 and October 2025 and recorded 7,152 confirmed SMB breaches in that window. This is not because larger enterprises have solved ransomware; Verizon attributes the gap to unpatched systems, compromised credentials, and thinner recovery capacity at smaller organizations.
Third parties were involved in 55% of SMB breaches, and the leading initial access vectors were vulnerability exploitation at 26% and credential abuse at 13%, per the same report. Both vectors trace back to basic hygiene gaps, unpatched software and reused or stolen passwords, rather than sophisticated attack techniques.
Figure 3: The two leading attack paths into small and mid-sized businesses. Source: Verizon 2026 Data Breach Investigations Report.
Figure 4: How a typical confirmed SMB breach traces back to its entry point. Source: Verizon 2026 Data Breach Investigations Report.
What does a breach actually cost a small business?
The global average cost of a data breach was 4.44 million dollars in 2025, down 9% from 4.88 million dollars the year before, while the US average rose 9% to 10.22 million dollars, the highest of any country tracked, according to IBM and the Ponemon Institute's Cost of a Data Breach Report 2025. The study is based on 600 organizations breached between March 2024 and February 2025, drawn from 17 industries and 16 countries and regions, with costs measured through interviews with 3,470 security and business leaders using an activity-based costing method.
These averages blend organizations of every size, so a small business will not typically face a multi-million-dollar bill on the scale of a breached bank or hospital network. What the figure demonstrates instead is the scale of the categories involved, detection, notification, post-breach response, and lost business, all of which apply proportionally to a small business even at a fraction of the headline number, and all of which start from the same weak point: an unpatched system or a reused password, the same two vectors Verizon's SMB data names as the leading causes.
| Cost category (per IBM/Ponemon methodology) | What it covers |
|---|---|
| Detection and escalation | Forensics, investigation, audit, crisis management |
| Notification | Contacting affected individuals and regulators |
| Post-breach response | Help desk, credit monitoring, legal fees, identity protection |
| Lost business | Customer churn, revenue loss, reputation damage |
Source: IBM and the Ponemon Institute, Cost of a Data Breach Report 2025.
Figure 5: The US carries the highest average breach cost of any country tracked. Source: IBM and the Ponemon Institute, Cost of a Data Breach Report 2025 (n=600 organizations).
How much time do small business owners spend on compliance?
32% of small business owners spend up to 20 hours a month on compliance-related tasks, and 46% say their overall compliance workload is heavier than it was a year earlier, according to LegalZoom's survey of 1,000 US small business owners fielded in December 2025. That figure covers all regulatory compliance, licensing, filings, tax and employment obligations included, rather than privacy specifically, so treat it as context for the broader burden privacy work sits inside rather than a privacy-only number.
33% of small business owners in the same survey say compliance requirements have already prevented them from pursuing a new business opportunity, most often expansion into a new market, a partnership, or a hire. 25% report receiving a compliance-related warning, fine, or citation, with most penalties falling between 2,000 and 10,000 dollars once fines, fees, and lost revenue are combined.
Figure 6: Nearly half of small business owners say compliance has gotten harder, not easier. Source: LegalZoom, State of Small Business Compliance survey, December 2025 (n=1,000).
The Bottom Line
The gap is not that small businesses ignore privacy entirely. 78% have a customer-facing privacy policy and 88% report taking compliance steps, both respectable numbers on their own. The gap is depth: only 64% have documented the internal policy that trains staff on handling data correctly day to day, only 55% run regular privacy training, and only 42% use formal off-site data storage arrangements, all trailing large enterprises by double digits. That shallower documentation lines up directly with the breach data: 96% of ransomware victims by count are small or mid-sized businesses, hit mainly through unpatched systems and stolen credentials, the exact gaps a documented internal policy and regular training are built to close. A small business does not need enterprise-scale compliance spending to close most of that gap; a current, accurate privacy policy paired with basic staff training addresses the two leading SMB breach vectors directly.
Frequently Asked Questions
What percentage of small businesses have a documented privacy policy? 64% of small businesses with 1 to 19 employees have a documented internal privacy policy addressing staff obligations, compared with 87% of businesses with 100 or more employees, according to the Office of the Privacy Commissioner of Canada's 2025-26 survey of 800 businesses.
Are small businesses more likely to be hit by a ransomware attack? Yes. 96% of ransomware victims where organization size was known were small and mid-sized businesses, according to Verizon's 2026 Data Breach Investigations Report, which logged 7,152 confirmed SMB breaches in its dataset.
How much does a data breach cost a small business? The global average cost of a data breach was 4.44 million dollars in 2025, and 10.22 million dollars for US organizations specifically, per IBM and the Ponemon Institute's Cost of a Data Breach Report 2025, based on 600 breached organizations studied.
Do small businesses spend much time on compliance? 32% of small business owners spend up to 20 hours a month on compliance tasks, and 46% say their overall compliance workload is heavier than a year earlier, per LegalZoom's December 2025 survey of 1,000 US small business owners, though that figure covers all regulatory compliance rather than privacy specifically.
Where the Numbers Come From
- Office of the Privacy Commissioner of Canada. (2026). "2025-2026 Survey of Canadian Businesses on Privacy-Related Issues." Telephone survey of 800 businesses, fielded January 19 to February 25, 2026, margin of error plus or minus 3.5 percentage points, 19 times out of 20.
- Verizon. (2026). "2026 Data Breach Investigations Report." 7,152 confirmed SMB breaches; incidents analyzed from November 1, 2024, to October 31, 2025.
- IBM and the Ponemon Institute. (2025). "Cost of a Data Breach Report 2025." 600 organizations studied, breaches occurring between March 2024 and February 2025, across 17 industries and 16 countries and regions.
- LegalZoom. (2026). "The State of Small Business Compliance." Survey of 1,000 US small business owners, fielded December 2025.
Note: All figures verified as of August 2026. The OPC and Verizon figures are drawn from surveys and reports with disclosed sample sizes and methodology; the LegalZoom figures cover general regulatory compliance rather than privacy specifically and are cited as supporting context. Figures are refreshed at least twice a year as new survey and report editions are published.