Data and Confidential Information Security Protections: Is Your Business Doing Enough?

As technology continues to play a larger role in the core functions of businesses, the importance of data security has increased accordingly. Whether securing a company's proprietary information or protecting customer data, best practice for a business is implementing policies and procedures that (i) help prevent security threats, (ii) establish clear protocols for responding to a data breach, and (iii) comply with applicable privacy laws. Below, we have highlighted a few standard policies and guidelines that we believe will assist your company in establishing a strong data security framework.
Employee Data Security Policies
Employee policies are a major component and key starting point for developing your data privacy and security framework. There are several employee policies that a company can implement, including acceptable use, password and authentication, access control policy, and more. These policies allow businesses to establish clear restrictions on who may access certain information as well as detail the manner in such information may be accessed and utilized. They also promote the implementation of strong password and authentication requirements, helping ensure that an organization's security is not compromised by weak credentials. Such considerations are imperative to protect the company's information but may also be required to maintain your cyber insurance policy if a condition of coverage.
Whether establishing new policies or maintaining current ones, it is essential that businesses regularly review and update their policies to ensure they remain aligned with current security threats, regulatory requirements and are sufficient for the company’s operations.
Incident Response Plan
Businesses should also maintain a written incident response plan that outlines the procedures to be taken in the event of a data breach or cybersecurity incident. The response plan should identify the key personnel responsible for responding to the incident, establish procedures for investigating and containing the breach, and outline any notification obligations to customers, vendors, insurers, regulators, or law enforcement regarding the breach. The plan should clearly define the role and responsibilities of the key employees for managing and coordinating the organization's response to a data breach or cybersecurity incident, as well as provide emergency contact information accessible to all personnel. Having a clear response framework in place and identifying these responsibilities in advance can help ensure a timely and coordinated response when a security incident occurs.
Artificial Intelligence Policy
Data security risks are not limited to third-party threats. As AI tools become more common in the workplace, there is an increased risk that a business’s proprietary information may be unintentionally shared through such platforms. We are seeing AI become integrated throughout Microsoft Office applications, web browsers, and other common workplace technologies. As a result, it is becoming less practical for businesses to rely solely on policies that prohibit AI usage to attempt to prevent improper disclosure. Instead, businesses should consider implementing an AI policy that provides employees with clear guidance on the appropriate use of AI when performing their job responsibilities, including providing a list of approved AI tools. This can create safeguards controlling employees’ AI usage. Like with any business policies, an AI policy should be reviewed frequently to ensure regulatory compliance as privacy laws continue to go into effect, and AI is incorporated into more workplace technologies.
Privacy Policy
Since California enacted the CCPA, numerous states across the country have adopted their own comprehensive privacy laws governing the collection, use, and protection of personal information. In particular, Kentucky and Indiana joined the growing number of states with each of their comprehensive consumer privacy laws going into effect on January 1, 2026. Though guided by applicable law, generally a business’s privacy policy should disclose what personal information the company collects and how it is collected, how an individual’s personal information is used, whom it is shared with, and the rights a customer may have regarding their personal information that is collected and stored by the business. The overall theme across privacy laws is ensuring that companies maintain transparency in their collection and processing of individuals’ personal information, as well as honor the rights of such individuals when exercised.
Document Destruction Policy
Document retention and destruction policies are another important component of a business's data protection strategy. These policies establish guidelines for how long records should be maintained in accordance with law and determine when they should be securely destroyed. By routinely disposing of documents and data that are no longer necessary nor required to be retained, organizations can reduce the amount of confidential information vulnerable to unauthorized access or disclosure.
Non-Disclosure Agreements
Non-disclosure agreements, or NDAs, are an important tool for protecting a business's confidential information. For employees, contractors, and vendors who will be exposed to a company’s proprietary information as part of the performance of their duties or services, it is imperative that a company requires such individuals to execute an NDA prior to disclosure. NDAs establish clear expectations for maintaining the confidentiality of the information, which in turn can prevent the unauthorized disclosure of trade secrets, financial data, customer information, business strategies, and other valuable information. NDAs also provide businesses with legal remedies in the event of a breach, helping to protect the company's competitive advantage and business interests.
We recommend that businesses establish confidentiality obligations by incorporating confidentiality language into employment agreements, employee handbooks, and vendor agreements. Companies should also consider executing NDAs before disclosing proprietary information in connection with exploring opportunities with prospective vendors, consultants, or other third-party service providers.
If you would like to further discuss any of the information above or would like to discuss implementing new data security policies and procedures for your company, please reach out to Stephen S. Schmidt at ssschmidt@strausstroy.com or Tara K. Bailey at tkbailey@strausstroy.com.

