As a small business becomes more networked and data-intensive, personal information and customer trust are critical assets that must be protected. This paper was written to help small business avoid data breaches that are harmful to both brand reputation and costly. Privacy policies and procedures alone, without a concrete strategy for implementation, will not protect an organization from privacy risks. Applying the basic concepts of Privacy by Design in a small enterprise setting is essential to avoiding the pitfalls of harmful data leaks.