<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>The Proton Blog</title><description>News from the front lines of privacy and security</description><link>https://proton.me/</link><language>en</language><feed_url>https://proton.me/feed</feed_url><item><title>Data classification for businesses: how to organize and protect company
information</title><link>https://proton.me/business/blog/data-classification-business</link><guid isPermaLink="true">https://proton.me/business/blog/data-classification-business</guid><description>Learn how to classify business data, define protection levels, control access, and reduce exposure with a data classification framework.</description><pubDate>Tue, 28 Jul 2026 13:44:10 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Data classification helps businesses stop treating every piece of information as if it carries the same risk. A supplier email, an internal process note, a customer payment record, and an admin recovery code should not move through the business under the same rules.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Sensitive data is stored throughout your business network: It moves through CRMs, inboxes, cloud storage, spreadsheets, HR systems, support platforms, finance software, and vendor tools. Without a shared system for classifying it, teams often rely on instinct: if something looks safe to share, or probably needs approval, they’ll take the quicker, easier route.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This may work for a while, but it doesn’t scale. A clear data classification policy gives your business a common language for deciding which information can be public, which should stay internal, which needs tighter controls, and which should only be available to specific roles.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#what-is-data-classification&quot;&gt;What is data classification?&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#why-data-classification&quot;&gt;Why data classification matters &lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#simple-classification-framework&quot;&gt;A simple data classification framework &lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#data-classification-examples&quot;&gt;Data classification examples for business teams&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#classification-access-control&quot;&gt;How classification drives access control&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#sharing-classified-data&quot;&gt;Sharing classified data safely&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#data-audit&quot;&gt;Start with a data audit&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#create-data-classification-policy&quot;&gt;How to create a data classification policy&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#proton-pass-business&quot;&gt;How Proton Pass for Business supports data classification&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#classification-everyday&quot;&gt;Make classification part of everyday data protection&lt;/a&gt;&lt;/p&gt;



&lt;h2 id=&quot;what-is-data-classification&quot; class=&quot;wp-block-heading&quot;&gt;What is data classification?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Data classification is the process of labeling business data by how sensitive it is and how much harm it could cause if it is exposed, changed, lost, or misused. In practice, it means grouping information into clear levels so people know how to store it, share it, protect it, and eventually delete it.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A useful classification system fits into daily work. It gives employees a quick way to understand when information can move freely, when it needs approval, and when access should be limited to a small group. The goal is to make the safer decision obvious before data is copied, shared, exported, or stored somewhere it should not be.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The UK National Cyber Security Centre’s guidance on&lt;a href=&quot;https://www.ncsc.gov.uk/guidance/asset-management&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt; asset management&lt;/a&gt; treats information as an asset that needs visibility, ownership, and protection. This is a useful way to frame classification: before deciding who can access sensitive data, you need to know what that data is and where it lives.&lt;/p&gt;



&lt;h2 id=&quot;why-data-classification&quot; class=&quot;wp-block-heading&quot;&gt;Why data classification matters&amp;nbsp;&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You can’t protect what your business hasn’t identified. This is especially true for SMBs, which usually do not have the resources to protect every system and every type of information with the same level of control. Before a business can decide who should access sensitive data, which systems need stronger protections, or where MFA and secure sharing are most urgent, it needs to know what information it holds and which data matters most.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Data classification is the first step in a practical &lt;a href=&quot;https://proton.me/business/pass/data-breach-protection&quot;&gt;data breach protection&lt;/a&gt; strategy. It separates routine business information from data that could create real harm if exposed, changed, lost, or shared with the wrong person.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This is especially useful as information spreads across CRMs, inboxes, cloud storage, HR systems, support tools, finance software, exports, and vendor platforms. Classification gives employees a clear signal: what can be handled normally, what needs approval, and what should only be available to specific roles.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;It also supports compliance. The UK’s Information Commissioner’s Office (ICO), the authority responsible for data protection enforcement and &lt;a href=&quot;https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;UK GDPR guidance&lt;/a&gt;, expects organizations to apply appropriate technical and organizational measures. Classification helps make that practical by matching protection to the sensitivity of the data.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For breach prevention, the principle is simple: sensitive data should not be accessible to more people than necessary. Proton’s guide to data loss prevention for businesses explains how reducing unnecessary exposure before an incident can limit the damage afterward.&lt;/p&gt;



&lt;h2 id=&quot;simple-classification-framework&quot; class=&quot;wp-block-heading&quot;&gt;A simple data classification framework&amp;nbsp;&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A classification framework doesn’t need to be complicated. Four levels are usually enough for small and midsize businesses:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Public&lt;/li&gt;



&lt;li&gt;Internal&lt;/li&gt;



&lt;li&gt;Confidential&lt;/li&gt;



&lt;li&gt;Restricted&lt;/li&gt;
&lt;/ul&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Public&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Public data is information approved for external use. A published version of this article you are reading, for example, would be Public data: it can be read, safe to share openly, and indexed without creating meaningful security or privacy risk.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Other examples include:&amp;nbsp;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Website copy&lt;/li&gt;



&lt;li&gt;Press releases&lt;/li&gt;



&lt;li&gt;Public job descriptions&lt;/li&gt;



&lt;li&gt;Approved sales materials&lt;/li&gt;



&lt;li&gt;Product pages&lt;/li&gt;



&lt;li&gt;Public company descriptions. &lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Public information still needs accuracy and brand review, but it doesn’t usually need strict access control once it has been approved.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Internal&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Internal data is meant for employees and approved collaborators only, but not for public distribution. Exposure may not cause severe damage, but it can create confusion, reputational risk, or operational issues.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Examples include:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Internal process documents &lt;/li&gt;



&lt;li&gt;Team notes&lt;/li&gt;



&lt;li&gt;Standard operating procedures&lt;/li&gt;



&lt;li&gt;Training materials&lt;/li&gt;



&lt;li&gt;Non-sensitive project plans&lt;/li&gt;



&lt;li&gt;Internal calendars &lt;/li&gt;



&lt;li&gt;General vendor contact lists.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Internal data should stay in approved business systems. For example, a draft campaign brief, an onboarding checklist, or notes from a team planning meeting may not be highly sensitive, but they still belong in the company’s approved workspace, not in a personal folder, private inbox, or unmanaged download.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Confidential&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Confidential data is sensitive business or &lt;a href=&quot;https://proton.me/business/blog/pii&quot;&gt;personally identifiable information&lt;/a&gt; (PII) that could harm the company, customers, employees, or partners if exposed. Access should be restricted to approved roles with a clear business need.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Examples include:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Customer records &lt;/li&gt;



&lt;li&gt;Employee files&lt;/li&gt;



&lt;li&gt;Contracts&lt;/li&gt;



&lt;li&gt;Commercial terms&lt;/li&gt;



&lt;li&gt;Financial reports&lt;/li&gt;



&lt;li&gt;Sales pipeline details&lt;/li&gt;



&lt;li&gt;Support tickets containing personal data&lt;/li&gt;



&lt;li&gt;Unpublished business plans&lt;/li&gt;



&lt;li&gt;Non-public vendor agreements&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Confidential data should only be accessible to approved roles. It shouldn’t live in personal drives, open shared folders, unmanaged spreadsheets, or inboxes where nobody reviews access. If it needs to be shared externally, the business should use end-to-end encrypted (E2EE) &lt;a href=&quot;https://proton.me/business/drive&quot;&gt;business cloud storage&lt;/a&gt; and limit sharing to authorized recipients with a clear business purpose.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Restricted&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Restricted data is the most sensitive category. If it is exposed, misused, or changed, the business could face serious financial, legal, operational, or security consequences.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Examples include:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Admin credentials&lt;/li&gt;



&lt;li&gt;Recovery codes&lt;/li&gt;



&lt;li&gt;Authentication secrets&lt;/li&gt;



&lt;li&gt;Customer payment details&lt;/li&gt;



&lt;li&gt;Highly sensitive HR records&lt;/li&gt;



&lt;li&gt;Legal dispute files&lt;/li&gt;



&lt;li&gt;Security incident reports&lt;/li&gt;



&lt;li&gt;Privileged access logs&lt;/li&gt;



&lt;li&gt;Encryption keys&lt;/li&gt;



&lt;li&gt;Backup access details&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Restricted data needs the strongest controls: limited access, strong authentication and &lt;a href=&quot;https://proton.me/business/pass/credential-management&quot;&gt;credential management&lt;/a&gt;, end-to-end encrypted cloud storage, &lt;a href=&quot;https://proton.me/pass/password-sharing&quot;&gt;secure sharing&lt;/a&gt;, and auditability.&lt;/p&gt;



&lt;figure class=&quot;wp-block-table&quot;&gt;&lt;table class=&quot;has-fixed-layout&quot;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Classification level&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;Sensitivity&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;Examples&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;Access level&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;Sharing rules&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Public&lt;/td&gt;&lt;td&gt;Low&lt;/td&gt;&lt;td&gt;Published articles, website copy, press releases, public job posts, approved sales materials&lt;/td&gt;&lt;td&gt;Approved for external use&lt;/td&gt;&lt;td&gt;Can be shared publicly once reviewed and approved&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Internal&lt;/td&gt;&lt;td&gt;Moderate&lt;/td&gt;&lt;td&gt;Team notes, draft campaign briefs, onboarding checklists, internal process documents&lt;/td&gt;&lt;td&gt;Employees and approved collaborators&lt;/td&gt;&lt;td&gt;Keep inside approved business systems&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Confidential&lt;/td&gt;&lt;td&gt;High&lt;/td&gt;&lt;td&gt;Customer records, employee files, contracts, financial reports, support tickets with personal data&lt;/td&gt;&lt;td&gt;Approved roles only&lt;/td&gt;&lt;td&gt;Share only with authorized recipients and a clear business purpose&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Restricted&lt;/td&gt;&lt;td&gt;Highest&lt;/td&gt;&lt;td&gt;Admin credentials, recovery codes, payment details, security incident reports, privileged access logs&lt;/td&gt;&lt;td&gt;Named users or tightly controlled groups&lt;/td&gt;&lt;td&gt;Do not share through email, chat, screenshots, or unmanaged documents&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/figure&gt;



&lt;h2 id=&quot;data-classification-examples&quot; class=&quot;wp-block-heading&quot;&gt;Data classification examples for business teams&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Classification becomes easier when teams can recognize it in their own work. Finance teams may treat a public pricing page as public, while invoices, payroll files, tax documents, and payment records are usually confidential. Banking credentials and payment platform admin access should be restricted because they can expose information, change settings, or move money.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;In practice, that access should be controlled through role-based permissions, strong authentication, regular access reviews, and a business password manager that helps teams manage and control the credentials behind sensitive systems.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;HR data follows a similar pattern. A job posting can be public, while employment contracts, salary information, sickness records, benefits details, and candidate data are usually confidential. Sensitive investigations, HR admin credentials, and broad access to employee records should be restricted.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This is not a historical anomaly: &lt;a href=&quot;https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2022/10/ico-fines-interserve-44-million-for-failing-to-keep-staff-information-secure/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;the 2022 ICO fine against Interserve&lt;/a&gt;, totaling £4.4 million, is a stark warning that employee data should be classified and protected as sensitive business information, not treated like ordinary internal documentation.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Sales, customer success, marketing, and IT teams also need clear boundaries. Customer records and support tickets that contain personal or account-level information are often confidential. Internal segmentation work, campaign planning, and performance reports may be internal or confidential depending on whether they include customer-level data, commercial sensitivity, or non-public business strategy.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Vendor documentation should be classified based on what it contains, especially if it includes access details, commercial terms, or security information. Exported customer datasets, CRM admin access, admin access to advertising platforms such as Google Ads or Meta Business Manager, backup credentials, recovery codes, privileged access logs, and security tooling credentials should be restricted because one exposed file or account can affect far more than one person.&lt;/p&gt;



&lt;h2 id=&quot;classification-access-control&quot; class=&quot;wp-block-heading&quot;&gt;How classification drives access control&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Once data is classified, access stops being a generic permission setting and becomes a business decision. The question is no longer only whether someone can open a system, but whether their role justifies access to the information inside it.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A support team may need customer conversations, but not every exported customer file. Finance may need payment and accounting records, but not HR investigations. A contractor may need access to one project workspace, not the company’s full archive of client files.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For confidential and restricted data, access must leave an audit trail. The business should know who accessed what, why access exists, and whether permissions are revoked immediately after a role change or &lt;a href=&quot;https://proton.me/business/drive/templates/offboarding-checklist&quot;&gt;offboarding&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A &lt;a href=&quot;https://proton.me/business/pass/for-it-teams&quot;&gt;password manager for IT teams&lt;/a&gt; supports centralized management, secure sharing, policies, admin reporting and logs, SCIM provisioning, and SSO integrations. This helps teams scope access to the credentials that unlock sensitive systems, instead of leaving passwords in browsers, spreadsheets, or chat threads.&lt;/p&gt;



&lt;h2 id=&quot;sharing-classified-data&quot; class=&quot;wp-block-heading&quot;&gt;Sharing classified data safely&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Sharing rules should follow the sensitivity of the information. A published asset can circulate freely once approved, but a contract, customer file, payment record, or recovery code needs more control. The more sensitive the data, the fewer people should receive it, and the more deliberate the sharing method should be.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This is especially important for email. Many businesses still send sensitive information through attachments, screenshots, or copied text, then lose track of where that information goes. Proton’s guide on how to&lt;a href=&quot;https://proton.me/business/blog/securely-send-sensitive-information-via-email&quot;&gt; securely send sensitive information via email&lt;/a&gt; explains safer ways to handle sensitive information when email is necessary.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Credentials and secrets need stricter rules than ordinary documents. Passwords, recovery codes, &lt;a href=&quot;https://proton.me/pass/passkeys&quot;&gt;passkeys&lt;/a&gt;, and admin access details shouldn’t be sent through email, chat, screenshots, or shared documents. They should be stored and shared through a &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt; such as Proton Pass for Business⁠ where access can be controlled, reviewed, and revoked more safely.&lt;/p&gt;



&lt;h2 id=&quot;data-audit&quot; class=&quot;wp-block-heading&quot;&gt;Start with a data audit&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Before writing a data classification policy, map where business data already lives. The first audit doesn’t need to be perfect. It just needs to show which systems hold sensitive information, who can access them, and where uncontrolled copies may exist.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Start with everyday locations such as CRMs, HR platforms, finance software, cloud storage, email inboxes, shared drives, support tools, password managers, vendor portals, downloads, exports, and backups.&amp;nbsp;&lt;/p&gt;



&lt;figure class=&quot;wp-block-table&quot;&gt;&lt;table class=&quot;has-fixed-layout&quot;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Field&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;What to record&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Location&lt;/td&gt;&lt;td&gt;Where the data lives&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Data type&lt;/td&gt;&lt;td&gt;Customer, employee, financial, credential, or operational data&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Classification level&lt;/td&gt;&lt;td&gt;Public, internal, confidential, or restricted&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Owner&lt;/td&gt;&lt;td&gt;Person or team responsible&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Access&lt;/td&gt;&lt;td&gt;Who can view, edit, export, or share it&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;MFA&lt;/td&gt;&lt;td&gt;Whether multi-factor authentication is enabled&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Vendor sharing&lt;/td&gt;&lt;td&gt;Whether third parties can access it&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Retention status&lt;/td&gt;&lt;td&gt;Keep, review, delete, or anonymize&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/figure&gt;



&lt;h2 id=&quot;create-data-classification-policy&quot; class=&quot;wp-block-heading&quot;&gt;How to create a data classification policy&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A data classification policy should be short enough for employees to use and specific enough to guide real decisions. It should define the classification levels, explain who owns sensitive data, and connect each level to access, storage, sharing, retention, and review.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A simple policy can include:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Purpose and scope:&lt;/strong&gt; What the policy covers and who it applies to.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Classification levels:&lt;/strong&gt; Public, internal, confidential, and restricted, with examples.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Ownership:&lt;/strong&gt; Who approves access and handles review for sensitive data categories.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Access rules:&lt;/strong&gt; Who can access each level and how access is approved or removed.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Sharing rules:&lt;/strong&gt; Which channels are approved for each classification level.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Storage and retention:&lt;/strong&gt; Where each type of data should live and how long it should be kept.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Review cadence:&lt;/strong&gt; How often the policy and access rules are reviewed.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Legal hold process:&lt;/strong&gt; When deletion or retention rules must be paused during active investigations, disputes, or litigation.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The policy should also make room for judgment. Not every document will fit neatly into a category. When in doubt, employees should know who to ask and what default to follow. For sensitive data, the safer default is usually to restrict access until the right owner confirms otherwise.&lt;/p&gt;



&lt;h2 id=&quot;proton-pass-business&quot; class=&quot;wp-block-heading&quot;&gt;How Proton Pass for Business supports data classification&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Data classification tells your business which information needs stronger protection. Access control turns that decision into daily practice.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Credentials are part of that access layer. If a password gives access to restricted data, such as admin settings, customer exports, finance systems, recovery codes, or security logs, that credential needs stricter handling than a login for a low-risk internal service.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A secure &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt; like Proton Pass for Business helps teams apply those access decisions in practice. Credentials can be stored in encrypted vaults, organized by team or function, and shared only with the people who need them.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Admins also get better visibility into credential access through reporting and logs, while policies, SSO integrations, and SCIM provisioning help IT teams manage onboarding and offboarding more consistently.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This makes classification easier to enforce in daily work. Finance credentials can stay with finance. HR admin access can stay with authorized HR leads. Backup recovery codes and privileged admin logins can be limited to the people responsible for recovery and security.&lt;/p&gt;



&lt;h2 id=&quot;classification-everyday&quot; class=&quot;wp-block-heading&quot;&gt;Make classification part of everyday data protection&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Data classification is not paperwork for its own sake. It is a way to make &lt;a href=&quot;https://proton.me/business/pass/data-breach-protection&quot;&gt;data breach protection&lt;/a&gt; easier to follow in daily work.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Once your business knows which data is most sensitive, the next step is controlling who can reach it. A password manager can help teams control and monitor the credentials that unlock sensitive systems and restricted data.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Control access to classified data across your organization with a &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt;.&lt;/p&gt;
</content:encoded><category>For business</category><author>Ben Wolford</author></item><item><title>IT disaster recovery plan: how to build one for your SMB</title><link>https://proton.me/business/blog/it-disaster-recovery-plan</link><guid isPermaLink="true">https://proton.me/business/blog/it-disaster-recovery-plan</guid><description>Learn how to build an IT disaster recovery plan for your SMB, including RTO, RPO, backup testing, system priorities, and credential recovery.</description><pubDate>Tue, 28 Jul 2026 13:10:57 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;When a key system within your business goes down, the hardest parts are knowing what to restore first, who has the access to do it, which backup can be trusted, and how long your business can keep working without that system.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;That is where many small and midsize businesses (SMBs) discover the gap between having backups and having an actual recovery plan. A backup may contain the data you need, but it doesn’t decide the recovery order, assign responsibilities, validate whether the restore works, or solve the problem of missing admin credentials during an outage.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;An IT disaster recovery plan gives this process structure before a disruption happens. It defines which systems matter most, how quickly they need to be restored, how much data loss the business can tolerate, what &lt;a href=&quot;https://proton.me/business/pass/data-loss-prevention&quot;&gt;data loss prevention&lt;/a&gt; strategies to implement, who owns each recovery step, and how critical credentials are protected. This clarity can prevent an IT incident from turning into prolonged downtime, lost revenue, or a wider operational crisis.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#what-is&quot;&gt;What is an IT disaster recovery plan?&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#business-continuity&quot;&gt;Business continuity vs. IT disaster recovery&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#what-disaster-plan&quot;&gt;What your IT disaster recovery plan must cover&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#what-plan-defines&quot;&gt;What your IT disaster recovery plan needs to define&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#credential-recovery&quot;&gt;Credential recovery: the overlooked disaster recovery scenario&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#plan-template&quot;&gt;Disaster recovery plan template &lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#test-plan&quot;&gt;How to test your IT disaster recovery plan&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#build-recovery&quot;&gt;Build recovery around systems, data, and access&lt;/a&gt;&lt;/p&gt;



&lt;h2 id=&quot;what-is&quot; class=&quot;wp-block-heading&quot;&gt;What is an IT disaster recovery plan?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;An IT disaster recovery plan is a documented process for restoring technology systems after a disruption. It focuses on the IT layer of the business: data, applications, devices, infrastructure, cloud services, admin access, backups, and the people responsible for recovery.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A practical IT recovery plan should answer questions like:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Which systems must come back first?&lt;/li&gt;



&lt;li&gt;How much downtime can the business tolerate?&lt;/li&gt;



&lt;li&gt;How much data loss is acceptable?&lt;/li&gt;



&lt;li&gt;Where are backups stored?&lt;/li&gt;



&lt;li&gt;Who can restore systems?&lt;/li&gt;



&lt;li&gt;Which admin credentials are needed?&lt;/li&gt;



&lt;li&gt;How will the team confirm that restored systems are safe and usable?&lt;/li&gt;



&lt;li&gt;How will the business communicate with staff and customers if primary channels are down?&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A disaster recovery plan should go beyond dealing with cyberattacks: it needs to cover everyday issues like hardware failure, lost credentials, and accidental deletion. It also needs to cover external service interruptions such as cloud platform or SaaS tool disruptions, misconfigurations, and key employees leaving without transferring critical access.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Recovery is not something to design during an outage. It needs to be planned, owned, communicated, and tested before your business needs to depend on it.&lt;/p&gt;



&lt;h2 id=&quot;business-continuity&quot; class=&quot;wp-block-heading&quot;&gt;Business continuity vs. IT disaster recovery&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Business continuity and IT disaster recovery often get treated as the same thing, but they solve different problems.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/business/business-continuity&quot;&gt;Business continuity&lt;/a&gt; is about keeping the company operating during a disruption. It covers client communication, temporary workflows, staff responsibilities, supplier coordination, and decisions about which services need to continue even if normal systems are unavailable.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;IT disaster recovery focuses on the technology behind that work. It defines how systems, data, applications, backups, and admin access will be restored so the business can return to normal operations safely.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;As an example, consider a CRM outage. A business continuity plan may explain how sales or support teams keep serving customers while the CRM is down. The IT recovery plan explains who contacts the vendor, which data needs to be restored, which backup or export is available, which credentials are required, and how the team confirms the system is safe to use again.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For many SMBs, the gap appears only during an incident. People know who would contact clients, but not who can restore the billing system. They know backups exist, but not whether a restore has ever been tested. They know one employee usually handles IT, but not what happens if that person is unavailable or where the admin passwords are stored if that person is out of contact.&lt;/p&gt;



&lt;h2 id=&quot;what-disaster-plan&quot; class=&quot;wp-block-heading&quot;&gt;What your IT disaster recovery plan must cover&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A strong IT disaster recovery plan doesn’t have to be overly long, but it needs to be specific enough to run during a stressful situation.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Recovery time objective&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Recovery time objective, or RTO, defines how quickly a system needs to be restored. A payment system may need to be back within hours, while an internal reporting dashboard may tolerate a longer outage.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Set RTOs by business impact, not by technical preference, because the cost of downtime is both a business and a technical problem. Ask which systems affect revenue, customer commitments, legal obligations, security, and employee productivity.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Recovery point objective&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Recovery point objective, or RPO, defines how much data loss is acceptable, which then helps set the right &lt;a href=&quot;https://proton.me/business/pass/data-loss-prevention&quot;&gt;data loss prevention&lt;/a&gt; (DLP) strategies. If a system has an RPO of one hour, backups or replication need to support recovery to roughly that point.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If the RPO is one day, the business is accepting a larger gap. RPO also helps determine backup frequency, because the shorter your RPO, the more frequent your backups need to be. Critical systems therefore need more frequent backups than low-priority systems.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;System priority tiers&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Not every system should be restored at the same time. A small business disaster recovery plan should divide systems into priority tiers.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Tier 1:&lt;/strong&gt; Systems required for core operations, security, communication, or revenue.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Tier 2:&lt;/strong&gt; Important systems that can tolerate short downtime.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Tier 3:&lt;/strong&gt; Lower-priority systems that can be restored after the business is stable.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Typical tier 1 systems may include email, identity provider, password manager, finance systems, customer database, cloud storage, and communication platforms.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Backup strategy&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Your backup strategy should define:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;What is backed up and how often&lt;/li&gt;



&lt;li&gt;Where backups are stored&lt;/li&gt;



&lt;li&gt;Who can access them&lt;/li&gt;



&lt;li&gt;How restoration is tested&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The &lt;a href=&quot;https://www.ncsc.gov.uk/collection/ransomware-resistant-backups&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;NCSC has also published&lt;/a&gt; ransomware-resistant backup principles for cloud and on-premises backup solutions, noting that backed-up data is not resistant to ransomware by default and should be assessed against the ransomware threat.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A strong backup strategy usually includes offline or immutable backups for critical data, regular testing, documented restore steps, and separate credentials for backup administration.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Roles and responsibilities&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A disaster recovery plan should name owners, not just tasks. If one person holds all recovery knowledge, the business has a people risk as well as an IT risk. Define who:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Leads recovery&lt;/li&gt;



&lt;li&gt;Restores systems&lt;/li&gt;



&lt;li&gt;Contacts vendors&lt;/li&gt;



&lt;li&gt;Approves emergency access&lt;/li&gt;



&lt;li&gt;Communicates internally&lt;/li&gt;



&lt;li&gt;Documents decisions&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 id=&quot;what-plan-defines&quot; class=&quot;wp-block-heading&quot;&gt;What your IT disaster recovery plan needs to define&lt;/h2&gt;



&lt;figure class=&quot;wp-block-table&quot;&gt;&lt;table class=&quot;has-fixed-layout&quot;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Component&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;What it answers&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;RTO&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;How quickly does each system need to be restored?&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;RPO&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;How much data can the business afford to lose?&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Priority tiers&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Which systems come back first, and which can wait?&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Backup strategy&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;What is backed up, where is it stored, and has restoration been tested?&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Roles and responsibilities&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Who leads recovery, restores systems, contacts vendors, and approves emergency changes?&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/figure&gt;



&lt;h2 id=&quot;credential-recovery&quot; class=&quot;wp-block-heading&quot;&gt;Credential recovery: the overlooked disaster recovery scenario&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Disaster recovery often focuses on data, servers, and backups. But in practice, recovery can fail because the team cannot access the systems needed to restore operations.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Credential recovery asks:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Who has access to admin accounts?&lt;/li&gt;



&lt;li&gt;Where are backup credentials stored?&lt;/li&gt;



&lt;li&gt;Which accounts can restore critical systems?&lt;/li&gt;



&lt;li&gt;What happens if a password is lost, compromised, or held by someone unavailable?&lt;/li&gt;



&lt;li&gt;Are emergency credentials protected and reviewed?&lt;/li&gt;



&lt;li&gt;Can access be revoked and reassigned quickly?&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If backup credentials are stored in one employee’s browser, recovery codes are kept in a private note, or shared admin passwords circulate through chat, the business may not be able to recover cleanly during an incident.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt; helps reduce that risk by centralizing critical credentials in encrypted vaults, assigning access by role, and making it easier to revoke or reassign access when someone leaves or responsibilities change. Proton Pass for Business helps teams &lt;a href=&quot;https://proton.me/pass/password-generator&quot;&gt;generate strong passwords&lt;/a&gt;, store credentials securely, use secure sharing, and keep sensitive access out of chats and spreadsheets.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;As a &lt;a href=&quot;https://proton.me/business/pass/for-it-teams&quot;&gt;password manager for IT teams&lt;/a&gt;, Proton Pass supports centralized &lt;a href=&quot;https://proton.me/business/pass/credential-management&quot;&gt;credential management&lt;/a&gt;, &lt;a href=&quot;https://proton.me/business/pass/password-policy&quot;&gt;password policies&lt;/a&gt;, &lt;a href=&quot;https://proton.me/pass/password-sharing&quot;&gt;secure sharing&lt;/a&gt;, reporting and logs, SCIM provisioning, and SSO integrations. That makes credential recovery more manageable because access to critical systems is not dependent on one person, one browser profile, or one undocumented password.&lt;/p&gt;



&lt;h2 id=&quot;plan-template&quot; class=&quot;wp-block-heading&quot;&gt;Disaster recovery plan template&amp;nbsp;&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A disaster recovery plan works best when it is specific enough to guide action during an outage, but simple enough for the team to use under pressure. For SMBs, the template should focus on the essentials: what needs to be restored, how quickly, from which backup, by whom, and with which credentials.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;1. Scope&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Define which systems, services, locations, devices, and data the plan covers.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Template copy:&lt;/strong&gt; &lt;em&gt;This IT disaster recovery plan covers the systems, data, services, credentials, and vendors required to restore [Company Name]’s critical operations after a technology disruption.&lt;/em&gt;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;2. Critical systems inventory&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;List the systems your business relies on and assign priority tiers.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Template copy:&lt;/strong&gt; &lt;em&gt;Critical systems will be grouped into Tier 1, Tier 2, and Tier 3 based on business impact, recovery time objective, recovery point objective, and dependency on other systems.&lt;/em&gt;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;3. Recovery objectives&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Define RTO and RPO for each priority system.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Template copy:&lt;/strong&gt; &lt;em&gt;Each system must have a documented recovery time objective and recovery point objective. These targets should be reviewed at least annually and after major system changes.&lt;/em&gt;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;4. Backup and restore process&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Document where backups are stored, how often they run, who can access them, and how restore testing works.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Template copy:&lt;/strong&gt; &lt;em&gt;Backups must be protected from unauthorized access, stored separately from primary systems where appropriate, and tested on a regular schedule. Restore procedures must be documented for Tier 1 systems.&lt;/em&gt;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;5. Credential and access recovery&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Define where critical credentials are stored and who can access them during recovery.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Template copy:&lt;/strong&gt; &lt;em&gt;Admin credentials, backup credentials, recovery codes, and vendor access required for disaster recovery must be stored in an approved encrypted vault. Access must be limited to authorized roles and reviewed after role changes, offboarding, and recovery exercises.&lt;/em&gt;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;6. Roles and escalation&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Define recovery owners, alternates, and escalation paths.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Template copy:&lt;/strong&gt; &lt;em&gt;Each recovery role must have a primary owner and a backup owner. The plan must identify who leads recovery, who restores systems, who contacts vendors, who communicates updates, and who approves emergency changes.&lt;/em&gt;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;7. Communication plan&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Define how the business communicates internally and externally during an IT outage.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Template copy:&lt;/strong&gt; &lt;em&gt;During a recovery event, internal updates will be shared through [approved channel]. External communications to customers, vendors, insurers, or regulators must be approved by [role/team].&lt;/em&gt;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;8. Testing and review cadence&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Define how often the plan is tested and updated.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Template copy:&lt;/strong&gt; &lt;em&gt;This disaster recovery plan will be tested at least [annually/twice a year] and reviewed after major incidents, system changes, vendor changes, or failed recovery exercises.&lt;/em&gt;&lt;/p&gt;



&lt;h2 id=&quot;test-plan&quot; class=&quot;wp-block-heading&quot;&gt;How to test your IT disaster recovery plan&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A disaster recovery plan only becomes useful when it has been tested under conditions that resemble real disruption. A backup that exists but has never been restored is still an assumption. A recovery role that only one person understands is still a dependency. An admin credential that no one can find during an outage is still a blocker.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Testing does not need to be complex at first. For most SMBs, the goal is to prove that the business can restore the right systems, with the right people, using the right credentials, within a realistic timeframe.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;1. Tabletop exercise&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Choose a likely scenario, such as ransomware affecting shared files, a cloud storage outage, accidental deletion of customer data, or the sudden loss of access to an admin account. Walk through what the team would do in the first hour, who would lead, which vendors would be contacted, which systems would be prioritized, and what information would be missing.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;2. Test restoration&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Select a critical file, database, mailbox, or system export and confirm that it can be restored to a usable state. Check whether the restored data is recent enough, whether permissions still work, and whether the team knows where the backup lives.&amp;nbsp;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;3. Test regularly&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;As a practical baseline, SMBs should test the plan at least once a year, in line with NIST guidance in&lt;a href=&quot;https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-34r1.pdf&quot;&gt; Special Publication 800-34 Revision 1&lt;/a&gt;⁠￼, and more often after major system or vendor changes.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;4. Test credential recovery&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Confirm that authorized people can access backup admin accounts, cloud admin accounts, vendor portals, recovery codes, and emergency credentials without relying on one employee’s browser, private notes, or memory. The goal is not to expose sensitive passwords unnecessarily. It is to confirm that the access model still works when the business is under pressure.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;After every test, document what failed, what took too long, and assign a specific person and deadline for each fix. A good test is not one where everything goes perfectly. It is one that reveals the gaps while the business still has time to fix them.&lt;/p&gt;



&lt;h2 id=&quot;build-recovery&quot; class=&quot;wp-block-heading&quot;&gt;Build recovery around systems, data, and access&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A useful IT disaster recovery plan gives the business a recovery order, a set of owners, a realistic view of acceptable downtime, and a way to maintain &lt;a href=&quot;https://proton.me/business/business-continuity&quot;&gt;business continuity&lt;/a&gt; and regain access to the systems that keep work moving.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For SMBs, this might make the difference between a short disruption and a prolonged outage. If email, finance software, cloud storage, customer systems, or admin accounts are unavailable, the team needs to know what comes first, who can act, and which credentials are required to restore access safely.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This is why recovery planning should cover systems, data, and access together. Backups may restore files, but credentials are what let the team regain control of the systems needed to recover. Admin logins, vendor portals, backup accounts, recovery codes, and shared operational credentials all need to be protected, organized, and available to the right people when something goes wrong.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt; helps strengthen that part of the plan. With critical credentials stored in encrypted &lt;a href=&quot;https://proton.me/business/pass/password-vault&quot;&gt;password vaults&lt;/a&gt; and shared only with authorized people, the business is less dependent on one employee’s browser, private notes, or memory during a recovery event.&lt;/p&gt;
</content:encoded><category>For business</category><author>Kate Menzies</author></item><item><title>How to create a data retention policy that keeps your business compliant</title><link>https://proton.me/business/blog/data-retention-policy</link><guid isPermaLink="true">https://proton.me/business/blog/data-retention-policy</guid><description>Learn how to create a data retention policy for your SMB, including GDPR storage limitation, UK recordkeeping rules, and access controls.</description><pubDate>Fri, 24 Jul 2026 16:20:48 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Businesses collect an unbelievable amount of data during their operations, but rarely stop to review and even delete data.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A data retention policy defines how long your business keeps different types of information, why it keeps them, who can access them, and how they should be deleted when they are no longer needed. For small and midsize businesses, it&amp;#8217;s one of the most practical ways to reduce compliance risk without overcomplicating day-to-day operations.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Many companies keep data for longer than necessary because deletion feels risky. Old customer records stay in a CRM. Former employee files remain in shared drives. Contracts sit in inboxes for years. Exported spreadsheets are saved “just in case.” Over time, the business ends up storing more &lt;a href=&quot;https://proton.me/business/blog/pii&quot;&gt;personally identifiable information (PII)&lt;/a&gt;, financial records, and internal information than it can properly govern.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;That creates a problem under GDPR. The storage limitation principle means personal data should not be kept for longer than necessary for the purpose it was collected. A retention policy helps turn that principle into a working system: what you keep, for how long, where it lives, who owns it, how it is removed, and how access to retained data is protected.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;That matters because weak passwords remain one of the most common &lt;a href=&quot;https://proton.me/business/blog/vulnerability&quot;&gt;vulnerabilities&lt;/a&gt; for businesses of all sizes, and retained data is still exposed if access controls are weak.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#what-is&quot;&gt;What is a data retention policy?&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#why-is&quot;&gt;Why is a data retention policy important?&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#what-kind&quot;&gt;What kind of data needs a retention schedule?&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#uk-data&quot;&gt;UK data retention requirements: what SMBs should know&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#data-retention&quot;&gt;Data retention policy template for SMBs&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#access-control&quot;&gt;Access control and retained data&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#common-data&quot;&gt;Common data retention policy mistakes&lt;/a&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;#turn-retention&quot;&gt;Turn retention rules into everyday practice&lt;/a&gt;&lt;/p&gt;



&lt;h2 id=&quot;what-is&quot; class=&quot;wp-block-heading&quot;&gt;What is a data retention policy?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A data retention policy is a set of rules that defines how long different categories of data should be kept within a business, and what happens when the retention period ends. It usually covers personal data, customer records, employee files, financial documents, contracts, communications, operational records, and business-critical documents.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A useful policy should answer these four questions:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;What type of data do we hold?&lt;/li&gt;



&lt;li&gt;Why do we need to keep it?&lt;/li&gt;



&lt;li&gt;How long should we keep it?&lt;/li&gt;



&lt;li&gt;How will we delete, anonymize, or archive it securely?&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The GDPR does not set specific time limits for every type of data, so organizations need to decide what is necessary for their own purposes, document that reasoning, and be prepared to justify it.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A data retention policy is more than a list of dates. It’s a record of the decisions behind those dates. If someone asks why customer data was kept for three years or applicant records were deleted after six months, a business must be able to point to a clear reason.&lt;/p&gt;



&lt;h2 id=&quot;why-is&quot; class=&quot;wp-block-heading&quot;&gt;Why is a data retention policy important?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A retention policy helps with compliance, security, and operational clarity. It protects a business in three ways:&amp;nbsp;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;It reduces the amount of data that could be exposed in a breach&lt;/li&gt;



&lt;li&gt;It lowers legal and compliance risk from keeping information longer than necessary&lt;/li&gt;



&lt;li&gt;It cuts storage costs tied to outdated records.&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;From a compliance perspective, it supports GDPR data retention obligations by showing that your business doesn’t keep personal data indefinitely without a reason. In the UK, the ICO is clear that personal data should not be retained on a “just in case” basis, but only for as long as it is necessary for the relevant purpose.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;From a security perspective, less unnecessary data means less exposure. If your business suffers a breach, every outdated customer record, old payroll file, unused export, or forgotten inbox attachment may increase the amount of information affected.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;That is why retention should be part of your broader approach to &lt;a href=&quot;https://proton.me/blog/data-breach-prevention-for-businesses&quot;&gt;data breach prevention&lt;/a&gt;. How long you keep data directly affects exposure: the longer unnecessary records stay in your systems, the more there is for an attacker to access, steal, or expose.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;From an operational perspective, retention rules reduce guesswork. Employees should know what to keep, where to store it, when to delete it, and who owns the decision. That is especially important for growing teams where data may be spread across email, cloud storage, HR systems, finance software, CRMs, shared drives, and vendor platforms.&lt;/p&gt;



&lt;h2 id=&quot;what-kind&quot; class=&quot;wp-block-heading&quot;&gt;What kind of data needs a retention schedule?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A data retention schedule is the working part of a data retention policy. It maps each data category to a retention period, owner, storage location, deletion method, &lt;a href=&quot;https://proton.me/business/pass/data-breach-protection&quot;&gt;data breach protection&lt;/a&gt; measures, and reason for keeping it.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;SMBs should start with the data categories they use every day.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Employee records&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Employee records don’t all follow the same retention logic. Some need to be kept because of statutory requirements, some because they may be needed to resolve disputes, and others only while there is a clear business reason.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For example, &lt;a href=&quot;https://www.acas.org.uk/checking-holiday-entitlement/keeping-records&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;ACAS&lt;/a&gt; says employers must keep holiday records for at least six years from the date they were made, while &lt;a href=&quot;https://www.gov.uk/data-protection-your-business/recruitment-managing-staff-records&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;GOV.UK&lt;/a&gt; guidance on staff records says employee information should only be kept for as long as the business has a clear need for it, then disposed of securely.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Customer and prospect data&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Customer data may include contact details, purchase history, support tickets, billing information, contracts, account records, and communication history. Prospect data may include marketing leads, event signups, newsletter subscriptions, and sales notes.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Keep customer data for as long as you need it to provide the service, meet contractual obligations, handle disputes, comply with accounting rules, or meet legal requirements. Marketing data needs particular care because consent, legitimate interest, unsubscribe requests, and purpose limitations all affect how long it should be retained.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Financial and tax records&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Financial records include invoices, receipts, payroll records, bank statements, expense claims, VAT records, accounting records, tax documentation, contracts and purchase orders, audit reports, credit card and loan records, and employee benefit or pension records where relevant.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;In many jurisdictions, company and tax law sets a minimum period for keeping accounting and financial records, though the exact length varies by country and by company type.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Contracts and legal documents&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Contracts, statements of work, vendor agreements, client agreements, leases, and legal correspondence may need to be retained for the contract term and for a period afterward in case of disputes.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The exact period depends on the contract, limitation periods, sector requirements, and legal advice. The policy should define an owner for these records, usually legal, finance, operations, or leadership.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Email communications and internal documents&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/business/mail&quot;&gt;Business email&lt;/a&gt; is often where retention policies are tested. Inboxes can hold contracts, personal data, attachments, customer complaints, invoices, candidate information, passwords, and confidential business decisions.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A retention schedule should define what belongs in email, what should be moved to an approved system, and when old messages should be deleted or archived. The same logic applies to internal documents, exported reports, spreadsheets, shared folders, and chat attachments. But the policy also needs an enforcement mechanism.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Retention rules should be tied to approved systems, automated deletion settings where feasible, archive rules, and ownership checks so data doesn’t remain indefinitely just because nobody acted when the retention period ended.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Credentials, access records, and security logs&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Retention also applies to security records. This may include access logs, audit trails, password records, recovery codes, admin activity, incident reports, and authentication records.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Some security records need to be kept for investigation, compliance, or operational review. Others should only be retained for a defined purpose and a documented period, then deleted or archived according to the policy, especially when they reveal how your systems work or expose sensitive access details.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Data retention, &lt;a href=&quot;https://proton.me/business/pass/credential-management&quot;&gt;credential management&lt;/a&gt;, and access control overlap: retained security records need strong access controls because they can reveal how your business systems work.&lt;/p&gt;



&lt;h2 id=&quot;uk-data&quot; class=&quot;wp-block-heading&quot;&gt;UK data retention requirements: what SMBs should know&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;UK data retention requirements vary. They depend on the type of data, the reason for keeping it, and the legal, tax, contractual, or business obligation behind it.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For GDPR data retention, the starting point is storage limitation: personal data should only be kept for as long as necessary for the purpose. UK GDPR doesn’t have one fixed period for every category, so businesses need to set their own retention periods and justify them.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Some records have clearer rules. Limited companies generally need to keep accounting records for six years from the end of the financial year they relate to, and sometimes longer in specific circumstances. Staff records vary by record type, so sensitive employment data should be categorized carefully and reviewed with legal or HR advice where needed.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Ultimately, it isn’t possible to apply one retention period to everything. Data should be separated by category, reason for keeping it defined, and document why each period is appropriate.&lt;/p&gt;



&lt;h2 id=&quot;data-retention&quot; class=&quot;wp-block-heading&quot;&gt;Data retention policy template for SMBs&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Use this structure as a simple data retention policy template. Adapt the wording to your business, sector, and legal requirements.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;1. Purpose and scope&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Template copy:&lt;/strong&gt; &lt;em&gt;This data retention policy explains how [Company Name] stores, retains, archives, deletes, and protects business and personal data. It applies to employees, contractors, vendors, systems, and services that collect, process, store, or access company data.&lt;/em&gt;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;2. Data categories&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Template copy:&lt;/strong&gt; &lt;em&gt;[Company Name] groups data into categories, including customer data, prospect data, employee records, financial records, contracts, operational records, security logs, and internal communications. Each category must have an owner, storage location, retention period, and deletion method.&lt;/em&gt;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;3. Retention schedule&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Template copy:&lt;/strong&gt; &lt;em&gt;Data must only be kept for as long as required for business, legal, regulatory, contractual, or security purposes. Each data category must be listed in the retention schedule with a defined retention period and reason.&lt;/em&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Example schedule:&lt;/p&gt;



&lt;figure class=&quot;wp-block-table&quot;&gt;&lt;table class=&quot;has-fixed-layout&quot;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Data category&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;Example records&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;Suggested retention approach&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;Owner&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;Deletion method&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Customer data&lt;/td&gt;&lt;td&gt;Account records, support tickets, service history&lt;/td&gt;&lt;td&gt;Keep while customer relationship is active, then retain only as needed for legal, contractual, or dispute purposes&lt;/td&gt;&lt;td&gt;Operations or customer success&lt;/td&gt;&lt;td&gt;Delete or anonymize from CRM and support systems&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Financial records&lt;/td&gt;&lt;td&gt;Invoices, receipts, payroll, tax documents&lt;/td&gt;&lt;td&gt;Generally keep for six years after the relevant financial year, unless longer retention is required&lt;/td&gt;&lt;td&gt;Finance&lt;/td&gt;&lt;td&gt;Archive securely, then delete&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Employee records&lt;/td&gt;&lt;td&gt;Contracts, payroll, holiday records, HR files&lt;/td&gt;&lt;td&gt;Retain based on record type, statutory rules, and business need&lt;/td&gt;&lt;td&gt;HR or operations&lt;/td&gt;&lt;td&gt;Delete securely from HR systems and shared storage&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Contracts&lt;/td&gt;&lt;td&gt;Client agreements, vendor contracts, statements of work&lt;/td&gt;&lt;td&gt;Keep for contract term plus a defined dispute period&lt;/td&gt;&lt;td&gt;Legal, finance, or leadership&lt;/td&gt;&lt;td&gt;Archive securely, then delete&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Security logs&lt;/td&gt;&lt;td&gt;Access logs, admin activity, incident records&lt;/td&gt;&lt;td&gt;Keep for investigation, security, and accountability needs, then delete or archive based on risk&lt;/td&gt;&lt;td&gt;IT or security owner&lt;/td&gt;&lt;td&gt;Delete or archive securely&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Marketing data&lt;/td&gt;&lt;td&gt;Leads, newsletter lists, campaign records&lt;/td&gt;&lt;td&gt;Keep while there is a valid purpose and suppression rules are respected&lt;/td&gt;&lt;td&gt;Marketing&lt;/td&gt;&lt;td&gt;Delete, anonymize, or suppress as appropriate&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/figure&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;4. Access controls&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Template copy:&lt;/strong&gt; &lt;em&gt;Access to retained data must be limited to people who need it for their role. Sensitive data must be stored in approved systems, protected by strong authentication, and reviewed regularly. Shared credentials must not be used to access retained data unless they are managed through an approved business password manager.&lt;/em&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This section is where retention connects directly to credential management. Data that must be kept still needs protection. If old contracts, payroll files, customer records, or security logs remain accessible to people who no longer need them, the retention policy is only solving half the problem.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt; supports access control by helping teams create strong credentials, store them securely, and share access only with authorized people. Proton Pass for Business helps teams manage credentials in encrypted vaults and use secure sharing, so retained data is less likely to be exposed through reused passwords or informal access.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;5. Deletion and disposal&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Template copy:&lt;/strong&gt; &lt;em&gt;When the retention period ends, data must be securely deleted, anonymized, or archived according to the retention schedule. Paper records must be shredded or disposed of securely. Digital records must be deleted from approved systems, shared drives, backups where appropriate, and any unmanaged storage locations. Deletion should be documented for sensitive data. Employees should also know where not to store information, such as personal drives, unapproved spreadsheets, or chat threads. If a data category becomes subject to a legal hold, dispute, audit, or investigation, deletion must be paused until legal or leadership authorizes the next step.&lt;/em&gt;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;6. Responsibilities&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Template copy:&lt;/strong&gt; &lt;em&gt;Each data category must have an owner responsible for retention decisions, access reviews, deletion, and policy updates. Employees are responsible for storing data in approved systems and reporting data they believe is outdated, duplicated, or stored in the wrong place.&lt;/em&gt;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;7. Review cadence&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Template copy:&lt;/strong&gt; &lt;em&gt;This policy and retention schedule will be reviewed at least annually, and sooner if [Company Name] introduces new systems, changes legal obligations, experiences a security incident, or changes how it collects or processes personal data.&lt;/em&gt;&lt;/p&gt;



&lt;h2 id=&quot;access-control&quot; class=&quot;wp-block-heading&quot;&gt;Access control and retained data&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A retention policy should never be separated from access control. Keeping data for a valid reason does not mean everyone should be able to reach it.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Retained data often includes sensitive information: employee files, customer records, tax documents, contracts, security logs, and incident reports. If access is unmanaged, older data can become an easy target during an account compromise. It can also create internal risk if employees can open records unrelated to their role.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Access controls should answer:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Who can access each retained data category?&lt;/li&gt;



&lt;li&gt;Which systems store it?&lt;/li&gt;



&lt;li&gt;Which credentials protect it?&lt;/li&gt;



&lt;li&gt;Is MFA enabled?&lt;/li&gt;



&lt;li&gt;Are shared credentials controlled?&lt;/li&gt;



&lt;li&gt;When was access last reviewed?&lt;/li&gt;



&lt;li&gt;What happens when someone leaves or changes roles?&lt;/li&gt;



&lt;li&gt;Are third-party vendors and suppliers granted access, and is it controlled?&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Data retention is connected to &lt;a href=&quot;https://proton.me/business/pass/credential-management&quot;&gt;credential management&lt;/a&gt;. For breach prevention, access control also reduces blast radius. If an attacker compromises one account, they should not automatically reach years of archived customer data, old contracts, or employee records. Creating a password policy&lt;a href=&quot;https://proton.me/business/pass/password-policy&quot;&gt;⁠&lt;/a&gt; can help teams define rules for password creation, sharing, access management, and authentication.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For breach prevention, access control also reduces blast radius. If an attacker compromises one account, they should not automatically reach years of archived customer data, old contracts, or employee records. Proton’s guide to &lt;a href=&quot;https://proton.me/business/pass/data-breach-protection&quot;&gt;data breach protection&lt;/a&gt; for businesses⁠ explains why limiting access and reducing unnecessary exposure are important before an incident happens.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt; such as Proton Pass for Business⁠ can also help teams control and review access to the credentials that unlock retained data, with centralized management, secure sharing, and clearer ownership through the admin panel.&lt;/p&gt;



&lt;h2 id=&quot;common-data&quot; class=&quot;wp-block-heading&quot;&gt;Common data retention policy mistakes&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Many SMBs already have informal retention habits, but not a reliable policy. The most common mistakes are easy to make: keeping too much data, applying one rule to every record, forgetting copies in everyday systems, deleting without checking legal holds, or keeping retained data accessible to too many people.&lt;/p&gt;



&lt;figure class=&quot;wp-block-table&quot;&gt;&lt;table class=&quot;has-fixed-layout&quot;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Mistake&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;Why it creates risk&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;What to do instead&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Keeping everything forever&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Storing data “just in case” can increase compliance risk and breach exposure.&lt;/td&gt;&lt;td&gt;Keep data only while there is a clear legal, contractual, security, or business reason.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Using one retention period for everything&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Financial records, employee files, marketing leads, contracts, and logs serve different purposes.&lt;/td&gt;&lt;td&gt;Define retention periods by data category.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Forgetting email, spreadsheets, and exports&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Copies may remain in inboxes, downloads folders, shared drives, or unmanaged files.&lt;/td&gt;&lt;td&gt;Include secondary storage locations in the policy.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Deleting without checking legal holds&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Some data may need to be preserved for disputes, audits, investigations, or regulatory obligations.&lt;/td&gt;&lt;td&gt;Add a review step before deletion.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Ignoring access to retained data&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Kept data can still be exposed if too many people can access it.&lt;/td&gt;&lt;td&gt;Assign owners, restrict permissions, and review access regularly.&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/figure&gt;



&lt;h2 id=&quot;turn-retention&quot; class=&quot;wp-block-heading&quot;&gt;Turn retention rules into everyday practice&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A practical policy starts with the data your business already holds and turns it into a schedule people can follow. Each category should have a reason for being kept, an owner, a review cadence, and a clear deletion process. While that data remains in your systems, access should stay limited to the people who genuinely need it.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For many SMBs, credential management is one of the easiest places to make improvements. Strong passwords, secure sharing, and controlled access help make sure retained data is only available to the people who need it.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Control who can access retained data in your business with a secure &lt;a href=&quot;https://proton.me/business/pass&quot;&gt;business password manager&lt;/a&gt;.&lt;/p&gt;
</content:encoded><category>For business</category><author>Kate Menzies</author></item><item><title>Is Malwarebytes safe? All you need to know</title><link>https://proton.me/blog/is-malwarebytes-safe</link><guid isPermaLink="true">https://proton.me/blog/is-malwarebytes-safe</guid><description>Is Malwarebytes legit? Yes: but it doesn&apos;t offer full antivirus protection. Here&apos;s what it does, what it misses, and what fills the gap.</description><pubDate>Fri, 24 Jul 2026 15:36:21 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Free security software &lt;strong&gt;should&lt;/strong&gt; make you a little suspicious. After all, fake anti-malware apps are one of the most common malware disguises out there. So is Malwarebytes safe to use?&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Rest assured: Malwarebytes is highly rated by trusted outlets like PC Mag and CNET, with a 4.2 rating on Trustpilot, and is safe to download and install, provided you follow official download links.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;But just because Malwarebytes is legitimate doesn’t mean it’s all you need to keep malware at bay. In its free form, Malwarebytes is a scanner, not a shield. And a scan only protects you from what’s already on your device, not whatever comes next.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Keep reading to find out what Malwarebytes is, what the free version doesn’t help with, and the best practices you should follow to keep your device protected in ways Malwarebytes can’t.&amp;nbsp;&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What is Malwarebytes?&amp;nbsp;&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Malwarebytes is cybersecurity software designed to detect, block, and remove malicious threats from Windows, Mac, Android, and iOS devices.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Most people looking for a quick &lt;a href=&quot;https://protonvpn.com/blog/what-is-malware&quot;&gt;malware&lt;/a&gt; removal tool will only ever use the free version of Malwarebytes, which is far more limited than the paid tiers.&lt;/p&gt;



&lt;figure class=&quot;wp-block-table&quot;&gt;&lt;table class=&quot;has-fixed-layout&quot;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Plan&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;Entry-level price&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;Devices covered&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;Key Features&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Free&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;$0&lt;/td&gt;&lt;td&gt;1&lt;/td&gt;&lt;td&gt;On-demand scan and removal, browser/web protection, ad and tracking blocker, data breach notifications&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Standard&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;$44.99/yr&lt;/td&gt;&lt;td&gt;1&amp;nbsp;&lt;/td&gt;&lt;td&gt;Same as Free, plus advanced, real-time antivirus protection, personalized security assessments, Browser Guard (in-browser scam and web protection, ad and tracking blocker, data breach notifications)&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Plus&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;$79.98/yr&amp;nbsp;&lt;/td&gt;&lt;td&gt;3&amp;nbsp;&lt;/td&gt;&lt;td&gt;Same as Standard, plus Privacy VPN&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Total&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;$89.99/yr&lt;/td&gt;&lt;td&gt;3&amp;nbsp;&lt;/td&gt;&lt;td&gt;Same as Plus, plus Identity Protection ($1 million identity insurance, identity recovery specialists, advanced social media monitoring)&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/figure&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Is Malwarebytes safe? Why a scan isn’t the same as malware protection&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;As with any cybersecurity tool, there are limits to what Malwarebytes can and can&amp;#8217;t do. Here&amp;#8217;s a clear explanation of exactly what it can do for your device.&amp;nbsp;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;What a malware scan does (and what it doesn’t catch)&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The free version of Malwarebytes is essentially a scan-on-demand tool with a handful of protective tools bundled in. It’s effective at checking the files already on your device, identifying &lt;a href=&quot;https://protonvpn.com/blog/what-is-malware&quot;&gt;malware&lt;/a&gt; and viruses, and removing them. &lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;However, this is only retrospective protection: any malware that was on your device before the scan could already have done damage: &lt;a href=&quot;https://proton.me/blog/what-is-ransomware&quot;&gt;ransomware&lt;/a&gt; could have encrypted your files to be held hostage, or &lt;a href=&quot;https://proton.me/blog/what-is-spyware&quot;&gt;spyware&lt;/a&gt; could have harvested your data and sold it to &lt;a href=&quot;https://proton.me/blog/data-brokers&quot;&gt;data brokers&lt;/a&gt;. &lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;What antivirus protection does (but can’t account for)&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Instead of waiting for you to run a scan, full antivirus protection continuously monitors and blocks threats in real time. It catches most malware as it tries to install or run — before it has the chance to do damage.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This is a stronger layer of defense, which is why Malwarebytes charges you for it. The good news is you don’t have to pay for real-time protection, since you probably already have a real-time layer running on your device.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Microsoft devices: &lt;/strong&gt;Microsoft Defender and its &lt;a href=&quot;https://proton.me/business/blog/firewall&quot;&gt;firewall&lt;/a&gt; are built into Windows&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Apple devices: &lt;/strong&gt;XProtect is built into macOS&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Android devices &lt;/strong&gt;(with Google Play services): Google Play Protect is baked into every &lt;a href=&quot;https://proton.me/blog/how-to-remove-malware-android&quot;&gt;Android device&lt;/a&gt; and switched on by default&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;But whether free or paid for, real-time protection doesn’t guarantee against malware infection, because no antivirus tool catches everything. There are two reasons for this:&lt;/p&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;New threats are always emerging: &lt;/strong&gt;Before services like Malwarebytes can detect them, they&amp;#8217;re able to slip past the defenses of even the most sophisticated tools &lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Human error: &lt;/strong&gt;If you download a malicious app from a sketchy site, or accidentally grant  permission to an untrustworthy service or app, your antivirus won’t always save you&lt;/li&gt;
&lt;/ol&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;To be fully protected, you need to back up your antivirus protection and malware scans with smarter behavior. Use our guides to check if your &lt;a href=&quot;https://proton.me/blog/phone-virus&quot;&gt;phone has a virus&lt;/a&gt; and find out more about &lt;a href=&quot;https://proton.me/blog/android-vs-ios-security&quot;&gt;Android vs iOS security&lt;/a&gt;.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Five free habits that close the security gaps left by Malwarebytes&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Here are five simple rules to follow that will provide an extra layer of protection no antivirus app can.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;1. Keep your OS and apps up to date&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Updates patch known vulnerabilities in &lt;a href=&quot;https://protonvpn.com/blog/operating-system-updates&quot;&gt;operating systems&lt;/a&gt; and apps. Neglecting to update can present cybercriminals with a backdoor into your device that they already have the key to. &lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Turn on automatic updates for your OS and apps, right now. That way you don’t have to rely on remembering.&amp;nbsp;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;2. Do your due diligence before you install&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;On desktop&lt;/strong&gt;, only download apps from the developer’s own official site, never a third-party download aggregator.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;On mobile&lt;/strong&gt;, only install apps from official stores. But be careful: there’s an abundance of disguised malware on both the Play Store and App Store. If you&amp;#8217;re unsure, check the developer&amp;#8217;s name in the app store to see what else they&amp;#8217;ve published and find their personal website.&amp;nbsp;&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For a guide to protecting yourself against malicious apps on official stores, read our article on &lt;a href=&quot;https://proton.me/blog/android-malware-malicious-apps-google-play&quot;&gt;avoiding malware on Play Store&lt;/a&gt;. (Most of the advice applies to the Apple App Store, too.)&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;3. Use strong passwords (and don’t reuse them across accounts)&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Most of us have a bad habit of using passwords that are easy to remember: short, predictable, and easy for cybercriminals to crack.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;That habit’s even more damaging if you’re using that same, weak password across multiple accounts. One password is exposed, and every account that shares that password is compromised.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;To avoid falling into these traps, you need a password manager to &lt;a href=&quot;https://proton.me/pass/password-generator&quot;&gt;generate unique, strong credentials&lt;/a&gt; for every one of your accounts.&amp;nbsp;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;4. Use email aliases&amp;nbsp;&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Your inbox is a valuable target for cybercriminals, full of the &lt;a href=&quot;https://proton.me/blog/how-do-scammers-get-your-personal-info&quot;&gt;personal information&lt;/a&gt; they need to build a clearer picture of you in order to scam you. &lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;An &lt;a href=&quot;https://proton.me/pass/aliases&quot;&gt;email alias&lt;/a&gt; gives you a unique, disposable email address to use for each service, with all mail feeding into a single, “real” email address. As well as helping to get rid of &lt;a href=&quot;https://proton.me/blog/how-to-stop-spam-emails&quot;&gt;spam email&lt;/a&gt;, aliases help hide your real inbox from cybercriminals when companies get breached. &lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;5. Use a VPN&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;When you use unencrypted public networks, anyone else on that network can see what websites you&amp;#8217;re visiting. They might not be able to see what you&amp;#8217;re doing on a banking website, but they&amp;#8217;ll be able to find out which bank you use.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Using a &lt;a href=&quot;https://protonvpn.com&quot;&gt;virtual private network (VPN)&lt;/a&gt; protects your privacy by encrypting your connection, so anyone else on the network who tries to look at your traffic sees only a scrambled, unexploitable mess.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Prevention starts with a secure VPN and password manager&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;When your device is already infected with malware, a Malwarebytes scan provides a handy cure. Ideally, though, you want to prevent malware getting on there in the first place.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Malwarebytes cleans up what&amp;#8217;s already there. Proton VPN and Proton Pass make sure there’s less to clean up. Here’s how.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Proton VPN&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Malwarebytes has its own VPN: Privacy VPN. It has some downsides:&amp;nbsp;&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;It can only be used with a &lt;strong&gt;$79.98/yr &lt;/strong&gt;subscription to Malwarebytes Plus &lt;/li&gt;



&lt;li&gt;Malwarebytes operates under US jurisdiction, which makes it subject to &lt;a href=&quot;https://proton.me/blog/european-alternative-us-tech-survey&quot;&gt;the CLOUD Act&lt;/a&gt;, meaning your data can be disclosed under compulsion &lt;/li&gt;



&lt;li&gt;It’s only passed one independent audit, in 2026, which &lt;a href=&quot;https://cyberinsider.com/malwarebytes-vpns-audit-uncovers-critical-flaws-fixes-underway/&quot;&gt;flagged a critical vulnerability&lt;/a&gt; &lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;The Independent Swiss&lt;/strong&gt; &lt;strong&gt;&lt;a href=&quot;https://protonvpn.com&quot;&gt;VPN&lt;/a&gt;, Proton VPN&lt;/strong&gt;, by contrast: &lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Is free to use &lt;/li&gt;



&lt;li&gt;Is under &lt;a href=&quot;https://proton.me/blog/switzerland&quot;&gt;Swiss jurisdiction&lt;/a&gt;, not subject to any mandatory data retention laws &lt;/li&gt;



&lt;li&gt;Has passed &lt;a href=&quot;https://protonvpn.com/blog/no-logs-audit&quot;&gt;five consecutive annual independent audits&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://protonvpn.com&quot;&gt;&lt;strong&gt;Discover Proton VPN&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Proton Pass&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If malware or a &lt;a href=&quot;https://proton.me/business/pass/breach-observatory&quot;&gt;data breach&lt;/a&gt; &lt;strong&gt;does&lt;/strong&gt; compromise one of your accounts, our end-to-end encrypted &lt;a href=&quot;https://proton.me/pass&quot;&gt;password manager&lt;/a&gt; Proton Pass can contain the damage. &lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Proton Pass&lt;/strong&gt; makes it easy to create, store, and use strong credentials. It lets you:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;a href=&quot;https://proton.me/pass/password-generator&quot;&gt;Generate strong passwords&lt;/a&gt; for every account&lt;/li&gt;



&lt;li&gt;Autofill credentials across sites and apps, so you only need to remember one password&lt;/li&gt;



&lt;li&gt;Use up to 10 &lt;a href=&quot;https://proton.me/pass/aliases&quot;&gt;email aliases&lt;/a&gt; (with the free version), and unlimited aliases with &lt;a href=&quot;https://proton.me/pass/pricing&quot;&gt;Pass Plus&lt;/a&gt; &lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Your vault is kept private by &lt;a href=&quot;https://proton.me/blog/zero-knowledge-cloud-storage&quot;&gt;zero-knowledge encryption&lt;/a&gt;: not even Proton can access your credentials. &lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Ultimately, Malwarebytes is a helpful tool that can help you secure a compromised device. But staying safe online requires a more proactive strategy, which Proton&amp;#8217;s easy-to-use tools can help anyone create.&lt;/p&gt;
</content:encoded><category>Guides</category><author>Kate Menzies</author></item><item><title>Is Venmo safe? Here’s how to protect yourself</title><link>https://proton.me/blog/is-venmo-safe</link><guid isPermaLink="true">https://proton.me/blog/is-venmo-safe</guid><description>Is Venmo safe? Yes, provided you use it as intended. Learn how it works, the common scams to watch for, and how to protect your money.</description><pubDate>Fri, 24 Jul 2026 15:09:14 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Need to send your friend some money for a group vacation, or your grandchild a cashless transfer for their birthday? If you’re in the US, you might be thinking of using the Venmo app.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;It’s a popular option for a reason: Venmo makes sending money to family and friends easy and even fun with a social feed that lets you follow transactions between your friends. But is it safe?&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Firstly, Venmo isn’t a scam app: it’s a legitimate business, with a 4.9/5 rating on the Apple App Store from over 15 million ratings and a 4.4 star rating on Google Play Store from over 900,000 reviews (with over 50 million downloads).&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;And it’s safe to use, too, provided you&amp;#8217;re making payments to people you know. But you should be aware that paying strangers is riskier, and that scammers can impersonate both Venmo itself and your friends on the platform.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Here&amp;#8217;s how to use it safely, and spot the scams that put your money at risk.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What is Venmo and how does it work?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Venmo is a US-only peer-to-peer payment app owned by PayPal. Using Venmo, you can instantly and directly send other Venmo users money.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You can also:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Send gift cards &lt;/strong&gt;from brands including Amazon, Starbucks, and Doordash&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Split group payments &lt;/strong&gt;by creating groups with your peers, adding expenses, and&lt;strong&gt; &lt;/strong&gt;settling up&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Pay online and in-person&lt;/strong&gt;&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Move money from and to your bank account&lt;/strong&gt;&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Get your paycheck sent right to your Venmo account (up to 2 days early)&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Venmo tries to make all this fun: you can attach messages (including emojis) to payments, and a social feed, which enables you to see what payments your peers are making (and vice versa).&amp;nbsp;&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Is Venmo safe to use with strangers?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The Venmo app is built for moving money between people who already know each other, not for strangers. In practice, though, many people use it to pay strangers selling items online.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Sellers on&lt;a href=&quot;https://proton.me/blog/is-facebook-marketplace-safe&quot;&gt; Facebook Marketplace&lt;/a&gt; will often ask buyers to pay via Venmo. It isn’t a built-in option like Meta Pay, so you’ll have to agree to it off-platform, usually in a Facebook Messenger thread.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This isn’t necessarily a red-flag request: plenty of legitimate sellers prefer Venmo for its lack of fees. But when a seller refuses to use a protected option (Meta Pay, PayPal Goods &amp;amp; Services) when one’s available, you could have cause for concern.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The problem is that &lt;strong&gt;Venmo personal payments carry no buyer protection by default and can’t be reversed once accepted. &lt;/strong&gt;If you pay a stranger without buyer protection and&amp;nbsp; receive the wrong item, a damaged item, or nothing at all, you won’t be able to get your money back.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;How to protect personal payments on Venmo&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Payments to approved business accounts are automatically protected. To confirm they’re approved, look for “Eligible items covered by Purchase Protection” under the pay button. &lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If you’re paying a personal Venmo account page, however, your payment won’t be covered by&lt;a href=&quot;https://venmo.com/purchaseprotection&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt; Venmo’s Purchase Protection Program&lt;/a&gt; unless you &lt;strong&gt;tag it as a purchase. &lt;/strong&gt;(Note: this makes the coverage possible, not automatic: see Venmo’s&lt;a href=&quot;https://venmo.com/legal/purchase-protection-eligibility&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt; Purchase Protection Eligibility guidelines&lt;/a&gt;.)&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;To tag your transaction:&lt;/strong&gt; tap the toggle shown below the payment method to confirm it’s a purchase.&lt;/p&gt;



&lt;figure class=&quot;wp-block-image size-large&quot;&gt;&lt;img width=&quot;1024&quot; height=&quot;676&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; src=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_676,c_scale/f_auto,q_auto/v1784897923/wp-pme/is-venmo-safe-2/is-venmo-safe-2.jpg?_i=AA&quot; alt=&quot;&quot; class=&quot;wp-post-243193 wp-image-243195&quot; data-crop=&quot;1.51&quot; data-format=&quot;jpg&quot; data-transformations=&quot;f_auto,q_auto&quot; data-filesize=&quot;112 KB&quot; data-optsize=&quot;29 KB&quot; data-optformat=&quot;image/webp&quot; data-percent=&quot;73.9&quot; data-version=&quot;1784897923&quot; data-seo=&quot;1&quot; srcset=&quot;https://res.cloudinary.com/dbulfrlrz/images/w_1024,h_676,c_scale/f_auto,q_auto/v1784897923/wp-pme/is-venmo-safe-2/is-venmo-safe-2.jpg?_i=AA 1024w, https://res.cloudinary.com/dbulfrlrz/images/w_300,h_198,c_scale/f_auto,q_auto/v1784897923/wp-pme/is-venmo-safe-2/is-venmo-safe-2.jpg?_i=AA 300w, https://res.cloudinary.com/dbulfrlrz/images/w_768,h_507,c_scale/f_auto,q_auto/v1784897923/wp-pme/is-venmo-safe-2/is-venmo-safe-2.jpg?_i=AA 768w, https://res.cloudinary.com/dbulfrlrz/images/f_auto,q_auto/v1784897923/wp-pme/is-venmo-safe-2/is-venmo-safe-2.jpg?_i=AA 1170w&quot; sizes=&quot;auto, (max-width: 1024px) 100vw, 1024px&quot; /&gt;&lt;/figure&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This incurs a 2.99% fee for the recipient, which won’t be refunded to them if they have to refund the sender. Some sellers may use this as an excuse to discourage you from adding this fee.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Be wary if they do: Purchase Protection protects sellers from being scammed by buyers too, provided the seller can produce proof of shipment and delivery.&amp;nbsp;&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;How to spot scams on Venmo &lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Once you&amp;#8217;ve signed up to Venmo, you might be targeted by scams,&lt;a href=&quot;https://help.venmo.com/cs/articles/common-scams-on-venmo-vhel167&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt; as Venmo itself acknowledges&lt;/a&gt;. Here are three scams Venmo flags, and how to protect yourself.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;An email or text saying you’ve won money through Venmo&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This message will include a &lt;a href=&quot;http://proton.me/blog/what-is-phishing&quot;&gt;phishing link&lt;/a&gt;, which you shouldn’t click. &lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Never enter Venmo login information&lt;/strong&gt; outside of &lt;a href=&quot;http://venmo.com&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;Venmo.com&lt;/a&gt; and the Venmo app, and never share account information on social media, except through Venmo’s official accounts: &lt;strong&gt;@Venmo&lt;/strong&gt; and &lt;strong&gt;@VenmoSupport &lt;/strong&gt;on X/Twitter, &lt;strong&gt;@Venmo&lt;/strong&gt; on Instagram, and &lt;strong&gt;@Venmo&lt;/strong&gt; on Facebook. &lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;A call from Venmo (which isn’t from Venmo)&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Under some pretext, the caller asks you to make a payment, or share a&lt;a href=&quot;http://proton.me/blog/what-is-two-factor-authentication-2fa&quot;&gt; two-factor authentication code&lt;/a&gt; that’s been sent to your phone.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Never share your Venmo verification code. &lt;/strong&gt;Venmo states that they will never ask for your verification code on a call, ask to access your device remotely, or to send money to another account.&amp;nbsp;&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;A scammer impersonates a friend on Venmo &lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You get an unusual (often time-sensitive) payment or request for money from someone who looks like your friend.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;strong&gt;Double-check that it’s actually them.&lt;/strong&gt; A scammer can copy a&lt;a href=&quot;https://proton.me/blog/safe-username&quot;&gt; username&lt;/a&gt;, profile picture, and social feed details to seem credible. Check their profile’s public transaction history, and, if still in doubt, reach out to your friend outside Venmo to verify.&amp;nbsp;&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;How to use Venmo safely&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Follow these guidelines to make sure Venmo is a safe place to buy, sell, and transfer money.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Tag any purchases made via personal Venmo accounts as purchases&lt;/strong&gt; to ensure you’re covered by Purchase Protection&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Set transaction visibility to private&lt;/strong&gt; so that not even friends, including potential scammers posing as your friends, can see them on their feed. Following privacy issues&lt;a href=&quot;https://www.theverge.com/tech/927503/venmo-app-redesign-privacy-posts&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt; reported by The Verge in May 2026&lt;/a&gt;, new users are set to see only friends’ activities by default, but this doesn’t guard against impersonators.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Verify identities through a second channel before paying, &lt;/strong&gt;including anyone who’s unfamiliar, and anyone who is familiar but acting unusually&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Beyond your behavior, you can close remaining gaps and minimize any potential damage by installing these tools on your devices:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;A&lt;/strong&gt;&lt;a href=&quot;https://proton.me/pass&quot;&gt;&lt;strong&gt; &lt;/strong&gt;&lt;strong&gt;password manager&lt;/strong&gt;&lt;/a&gt; to generate and store a strong, unique password for your account, so a breach on another site doesn’t hand attackers a working password to all of your online accounts&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;An&lt;/strong&gt;&lt;a href=&quot;https://proton.me/pass/aliases&quot;&gt;&lt;strong&gt; &lt;/strong&gt;&lt;strong&gt;email alias&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt; generator&lt;/strong&gt; to create an individual email address to register with Venmo. It forwards Venmo mail to your main inbox, and protects your real address if Venmo gets breached&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;A&lt;/strong&gt;&lt;a href=&quot;https://protonvpn.com/&quot;&gt;&lt;strong&gt; &lt;/strong&gt;&lt;strong&gt;VPN&lt;/strong&gt;&lt;/a&gt; to encrypt your connection when you’re sending money over public WiFi, keeping your session private from prying eyes&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Secure your passwords and privacy with Proton&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton was founded to make the internet safer. Our products make it harder for scammers to steal your credentials and personal information.They also make it easier to use the internet safely and protect your online accounts.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;With our &lt;a href=&quot;https://proton.me/pass&quot;&gt;free password manager&lt;/a&gt;&lt;strong&gt; Proton Pass &lt;/strong&gt;you can:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;a href=&quot;https://proton.me/pass/password-generator&quot;&gt;&lt;strong&gt;Generate a strong, unique password&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt; for every account you use&lt;/strong&gt; &lt;strong&gt;(including Venmo)&lt;/strong&gt;: if one of your passwords leaks, they won’t all leak&amp;nbsp;&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Set up an&lt;/strong&gt;&lt;a href=&quot;https://proton.me/blog/what-is-email-alias&quot;&gt;&lt;strong&gt; &lt;/strong&gt;&lt;strong&gt;email alias&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt; for Venmo&lt;/strong&gt;: if they ever get breached, the attackers won’t have the keys to your primary inbox&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Ensure your login credentials aren’t autofilled on fake Venmo pages: &lt;/strong&gt;Proton Pass autofills logins only on the websites it recognizes, so it won’t hand your password to a domain that isn’t venmo.com&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://protonvpn.com/&quot;&gt;&lt;strong&gt;Proton VPN&lt;/strong&gt;&lt;/a&gt; won’t stop the scams listed by Venmo, but it keeps you safer online, encrypting your connection whenever you’re using Venmo or any other app, blocking ads and malware trackers.&amp;nbsp;&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Both Proton Pass and Proton VPN are protected by&lt;a href=&quot;https://proton.me/blog/zero-knowledge-cloud-storage&quot;&gt; zero-access encryption&lt;/a&gt; that means not even Proton can access your passwords.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Venmo can be as safe as you make it. Pair smart habits with tools that protect your credentials and your connection, and you can send payments without paying an undue price.&lt;/p&gt;
</content:encoded><category>Guides</category><author>Kate Menzies</author></item><item><title>EU fines Google $1 billion over its search and Play Store</title><link>https://proton.me/blog/google-eu-fine-antitrust-play-search</link><guid isPermaLink="true">https://proton.me/blog/google-eu-fine-antitrust-play-search</guid><description>EU regulators fined Google $1 billion for favoring its own services in search and restricting Play Store developers.</description><pubDate>Thu, 23 Jul 2026 17:20:29 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;European Union regulators &lt;a href=&quot;https://apnews.com/article/google-eu-competition-fine-antitrust-play-search-199c77e09d3829ebfc3d9e51281a369a&quot;&gt;fined Google €890 million on Thursday&lt;/a&gt;, saying the company broke the bloc&amp;#8217;s digital competition law by steering users toward its own services in search results and restricting what app developers are allowed to tell their customers.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The penalty, worth about $1 billion, closes two investigations the European Commission opened in March 2024 and makes Google the third company sanctioned under the &lt;a href=&quot;https://proton.me/blog/digital-markets-act-explained&quot;&gt;Digital Markets Act&lt;/a&gt;. Alphabet, Google&amp;#8217;s parent company, takes in roughly that much revenue in a day.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;What regulators found&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The European Commission split the fine in two. It attributed €460 million to self-preferencing in search, finding that Google gave its own shopping, hotel, transport and sports results better placement than it gave competitors. &lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The remaining €430 million covers the Play Store, where regulators said Google barred developers from telling users about cheaper offers available elsewhere and charged steering fees beyond what the law permits.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Teresa Ribera, the Commission&amp;#8217;s executive vice president for competition, &lt;a href=&quot;https://www.nytimes.com/2026/07/23/business/google-eu-fine-search-competition.html&quot;&gt;said the best products should succeed on merit&lt;/a&gt; rather than on who owns the search engine. Google has 60 days to comply or face daily penalties of up to 5% of Alphabet&amp;#8217;s worldwide turnover.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Kent Walker, Google&amp;#8217;s president of global affairs, called the decision &amp;#8220;&lt;a href=&quot;https://www.politico.eu/article/eu-fines-google-e890m-for-breaching-big-tech-rulebook/&quot; type=&quot;link&quot; id=&quot;https://www.politico.eu/article/eu-fines-google-e890m-for-breaching-big-tech-rulebook/&quot;&gt;product degradation driven by a small group of self-serving complainants.&lt;/a&gt;&amp;#8221; The company said it is weighing an appeal. Politico reported that the Commission reached its decision internally in March and announced it a day before temporary US tariffs on trading partners are due to expire.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;A day of revenue&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Alphabet reported $403 billion in revenue in 2025, roughly $1.1 billion a day, meaning Thursday&amp;#8217;s penalty is worth less than 24 hours of business.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton &lt;a href=&quot;https://proton.me/tech-fines-tracker&quot;&gt;tracks what Big Tech pays&lt;/a&gt; in fines each year. In 2025, regulators worldwide levied about $7.8 billion against Alphabet, Apple, Meta and Amazon, the largest annual total we have recorded.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Measured against free cash flow, those four companies could have cleared the entire year of penalties in 28 days. Alphabet drew about $4.24 billion of it, more than any of them, and could have covered its share in about three weeks.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The pattern holds going back further. EU regulators have fined Google more than €10 billion since 2017, and Europe&amp;#8217;s highest court &lt;a href=&quot;https://curia.europa.eu/site/upload/docs/application/pdf/2026-07/cp260093en.pdf&quot;&gt;upheld the largest of those&lt;/a&gt;, a €4.1 billion Android penalty, on July 2.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;None of it changed how the company operates, however, because none of it cost more than operating that way earns.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;What the fine does not reach&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Self-preferencing is a competition finding, but what it protects is an &lt;a href=&quot;https://proton.me/blog/what-does-google-know-about-me&quot;&gt;advertising business&lt;/a&gt;. Results that keep users on Google surfaces keep them measurable. Privacy-first services rarely lose on quality. They lose on placement.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For the first time in a long while, governments are taking their duty to citizens seriously and fighting the monopolies that corrupted the internet&amp;#8217;s early promise. But make no mistake: the fines are still too small to make Big Tech sit up. Unwinding Big Tech&amp;#8217;s structural advantages, rather than the checks it writes, is what holds real promise for restoring freedom and fairness online. A fairer internet would let services that protect personal data instead of exploiting it succeed on merit. &lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Building that better internet will take years. Until then, the burden falls on you, and the choice carries much further than it may seem: Keeping your data out of Big Tech&amp;#8217;s hands protects your information and cuts into the ad revenue that pays for the conduct regulators keep fining.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The simplest defense is &lt;a href=&quot;https://proton.me/blog/what-is-end-to-end-encryption&quot;&gt;end-to-end encryption&lt;/a&gt;. Proton is funded by the people who use it rather than by advertisers, so it has no reason to collect your data. Sign up free and take control of your &lt;a href=&quot;https://proton.me/mail&quot;&gt;email&lt;/a&gt;, &lt;a href=&quot;https://proton.me/calendar&quot;&gt;calendar&lt;/a&gt;, &lt;a href=&quot;https://proton.me/drive&quot;&gt;photos and files&lt;/a&gt;, &lt;a href=&quot;https://protonvpn.com/&quot;&gt;browsing&lt;/a&gt;, and &lt;a href=&quot;https://proton.me/pass&quot;&gt;passwords and online identity&lt;/a&gt;.&lt;/p&gt;
</content:encoded><category>News</category><author>Edward Komenda</author></item><item><title>Why your business needs document version control </title><link>https://proton.me/business/blog/document-version-control</link><guid isPermaLink="true">https://proton.me/business/blog/document-version-control</guid><description>Understand document version control and revision control to keep business files secure, auditable, and recoverable.</description><pubDate>Thu, 23 Jul 2026 14:18:17 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;An email from a client pops up on your laptop: &amp;#8220;This contract is rife with errors.&amp;#8221;&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You pull up the file and realize — you sent them a version from 36 hours ago, before legal had reviewed it, before that key clause was approved. Nobody can tell you with certainty which version left your hands, or why.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;That’s a version control failure. And in a moment of exposure — an audit, a near-miss, a client complaint, an internal dispute — it can mean more than a lost deal. It can mean a compliance violation you can&amp;#8217;t defend, a dispute you can&amp;#8217;t prove, or a client relationship that doesn&amp;#8217;t recover.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Document version control helps you answer who changed what, when, and which version left your hands. If you&amp;#8217;re responsible for how documents move through your organization — contracts, compliance records, internal policies — this is what you need to understand about it. &lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What is document version control?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Document version control is also known as revision control or file version control. It’s the system that tracks every change to an ongoing file or project. It doesn’t overwrite what was there before. It preserves every change as a new entry in the document’s history, so you can see every decision that different collaborators made and return to a previous version if you need to.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Version control can be done manually — saving and renaming files as &amp;#8220;v1,&amp;#8221; &amp;#8220;v2,&amp;#8221; &amp;#8220;FINAL&amp;#8221; — but that depends on everyone following the same convention consistently, which is how records get gaps.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The more reliable approach is using &lt;a href=&quot;https://proton.me/business/drive&quot;&gt;business cloud storage&lt;/a&gt; software that does it automatically, logging every change in the background without anyone having to remember. You won’t have to manually save and name files with version numbers, it does it automatically, giving you a complete record of changes without anyone having to maintain it. &lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You’ll find more tips on finding the right software further down this blog.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Find out more about the &lt;a href=&quot;https://proton.me/business/blog/document-management-best-practices&quot;&gt;best practices of document management&lt;/a&gt;.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Why does version control matter for compliance?&amp;nbsp;&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;In regulated industries like &lt;a href=&quot;https://proton.me/business/drive/hipaa-compliant-cloud-storage-for-healthcare&quot;&gt;healthcare&lt;/a&gt;, &lt;a href=&quot;https://proton.me/business/drive/cloud-storage-for-law-firms&quot;&gt;law&lt;/a&gt;, or &lt;a href=&quot;https://proton.me/business/drive/financial-services-document-management&quot;&gt;finance&lt;/a&gt;, process failures like document problems have a serious consequence: They leave gaps in your record that you may one day have to explain.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;What changed?&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;When something goes wrong with a document — a clause that shouldn&amp;#8217;t have been there, a figure that doesn&amp;#8217;t match what was agreed, terms that contradict an earlier version — the first question anyone asks is: what changed, and when?&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;In a regulated environment, that question isn&amp;#8217;t just internal. A financial regulator may want to know exactly what was amended in a client agreement and when. A court may want to see whether a clause was present in the original draft or added later. A compliance officer may need to demonstrate that a policy document wasn&amp;#8217;t altered after it was approved. &lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Without a complete version history, none of those questions have a reliable answer.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Who had access?&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Knowing what changed is only part of the record. Regulators and auditors will also want to know who had access to a document, and at what stage. &lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A contractor whose access wasn&amp;#8217;t revoked after a project ended. A team member who opened a file outside their authorization. An external party who saw a draft before it was finalized. None of these events alter the document — but all of them are exposure events, and in a compliance context, exposure events need to be logged. &lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A SaaS company handling customer &lt;a href=&quot;https://proton.me/business/blog/pii&quot;&gt;PII data&lt;/a&gt; will face this question directly every time an enterprise client asks: &amp;#8220;who has seen our data, and can you prove it?&amp;#8221; SOC 2 auditors will ask the same thing. If you can&amp;#8217;t produce that access history, you don&amp;#8217;t pass.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Which version is final?&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;In a contract dispute, a regulatory submission, or an internal investigation, there can only be one answer to this question. &lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If multiple versions of a document exist across shared drives, email threads, and downloaded copies, nobody can say with certainty which one is authoritative. Ambiguity is a liability. &lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A proper version control system designates a single, timestamped record as final — and keeps the full history of everything that came before it, so the answer to this question is never in doubt.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;7 ways to maintain version control for your business&lt;/h2&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Always work in &lt;/strong&gt;&lt;a href=&quot;https://proton.me/business/drive/secure-file-sharing-for-business&quot;&gt;&lt;strong&gt;shared files&lt;/strong&gt;&lt;/a&gt; — if anyone is working on a local copy, the compliance record has a gap&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Be logged in when you edit&lt;/strong&gt; — anonymous edits aren&amp;#8217;t attributable, and attribution is what auditors require&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Never edit outside the system&lt;/strong&gt; — changes made in a downloaded copy or an email attachment are invisible to the version history. If it didn&amp;#8217;t happen in the shared document, it didn&amp;#8217;t happen on the record&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Only share access with people who need it&lt;/strong&gt; — every unnecessary collaborator is an unlogged exposure risk&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Revoke access when it is no longer necessary&lt;/strong&gt; — access that outlives its purpose is a liability, not just an oversight&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Designate and protect the final version&lt;/strong&gt; — once a document is approved, it should be clearly identifiable as final and protected from further edits. A version history full of post-approval changes is not a clean compliance record&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Never delete a document to start over&lt;/strong&gt; — deleting a file destroys its compliance record permanently&lt;/li&gt;
&lt;/ol&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What to look for in a document tool&amp;nbsp;&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For business uses, here is what matters:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Automatic versioning: Version history should not need manual work. If team members need to keep track of versions, they will most likely get confused and create friction. They will need a real-time &lt;a href=&quot;https://proton.me/business/drive/docs&quot;&gt;collaborative document&lt;/a&gt; that actually saves the edits automatically. &lt;/li&gt;



&lt;li&gt;Long retention: A 30-day edit log will not be enough for audits or disputes. Business document version control should keep the records for months — or even years — and make sure you keep all compliance checks in place. &lt;/li&gt;



&lt;li&gt;Safe restore options: Restoring a previous version should not overwrite or delete what came after it. Look for tools that let you make a copy of a past version or roll back fully while keeping the complete history intact. This is crucial to safeguarding client data and keeping teams aligned. &lt;/li&gt;



&lt;li&gt;Attribution and controls: Timestamps are not enough. You need to tie each change to a person. That is what makes file revision control useful for accountability. Also, permissions or link-expiration features should not be managed through separate tools. Version control and &lt;a href=&quot;https://proton.me/business/drive/secure-file-sharing-for-business&quot;&gt;secure file sharing for teams&lt;/a&gt; should be part of the same workflow.&lt;/li&gt;



&lt;li&gt;End-to-end encryption: Version history can contain sensitive information. If the service provider can access all draft versions, then your information is also accessible to them. Look for tools that provide full &lt;a href=&quot;https://proton.me/learn/encryption/types-of-encryption/what-is-end-to-end&quot;&gt;end-to-end encryption&lt;/a&gt; for increased security. &lt;/li&gt;
&lt;/ul&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Protect your documents from the get-go&amp;nbsp;&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;At Proton, we built Proton Docs and Proton Sheets, online software for collaborative documents and secure spreadsheets, to give remote teams full control over their documents, with automatic versioning and end-to-end encryption across every file and every revision. So your document history stays secure by default.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Version control is only as reliable as the tools behind it. Proton Drive automatically saves your version history, with no need for manual checkpoints. It retains document history for up to 10 years — long enough to meet most data retention requirements — and allows you to safely roll back to any version you need.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Start with &lt;a href=&quot;https://proton.me/drive/pricing&quot;&gt;a free Proton account&lt;/a&gt; or explore our &lt;a href=&quot;https://proton.me/business/drive&quot;&gt;business cloud storage&lt;/a&gt;, Drive for Business.&amp;nbsp;&lt;/p&gt;
</content:encoded><category>For business</category><author>Alanna Alexander</author></item><item><title>What to look for in a secure cloud workspace (before you commit)</title><link>https://proton.me/business/blog/how-to-choose-a-cloud-workspace</link><guid isPermaLink="true">https://proton.me/business/blog/how-to-choose-a-cloud-workspace</guid><description>Here&apos;s how to evaluate security, data sovereignty, and lock-in risk before you commit to a new cloud workspace.</description><pubDate>Thu, 23 Jul 2026 13:23:37 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Choosing a cloud workspace is probably the most consequential infrastructure decision you can make.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Many teams default to &lt;a href=&quot;https://proton.me/business/google-workspace-alternative&quot;&gt;Google Workspace&lt;/a&gt; or &lt;a href=&quot;https://proton.me/business/microsoft-365-alternative&quot;&gt;Microsoft 365&lt;/a&gt; because they seem like the obvious choice: familiar, feature-rich, deeply integrated cloud collaboration platforms that are easy to adopt and already embedded in many modern workflows.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;But that’s precisely why they’re worth scrutinizing before you commit. Here are four key things you need to consider when evaluating a cloud workspace, plus a checklist of questions to help guide you.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;1. Integrations can free you up now — but lock you in later&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Integrations are a major selling point for most cloud workspaces. Many companies (especially fast-moving start-ups) want a platform with lots of integrations that slots seamlessly into existing workflows with minimal disruption.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;However, over the long term using integrations can mean embedding your workflows inside a single ecosystem. And once you’ve tied yourself into a cloud workspace ecosystem, switching providers becomes a data admin’s worst six months at the office — we’re talking siloed data, identity and access disruption, denied permissions, inaccessible files, and a dip in productivity your CEO will &lt;em&gt;definitely&lt;/em&gt; notice.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This certainly applies to go-to platforms like Google Workspace and Microsoft 365, which are &lt;em&gt;strategically designed&lt;/em&gt; to hook businesses on a wider ecosystem of co-dependent tools — Meet, Teams, Drive, and SharePoint — that become progressively harder to detach from.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The question you need to ask before picking a cloud workspace isn’t “how easy is this to adopt?” It’s “how hard will this be to get out of?”&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;2. ‘Security’ means different things to different providers&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Most enterprise workspace providers market their platforms as boasting ‘enterprise-grade security’, with certifications, perimeter protections, and encryption of data in transit and at rest.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;What many providers are &lt;em&gt;less&lt;/em&gt; keen to advertise is that they retain server-side access to your data. This enables their most useful features: indexing, analytics, cloud-side processing and AI assistance provided by tools like Google’s &lt;a href=&quot;https://proton.me/lumo/ai/gemini-alternative&quot;&gt;Gemini&lt;/a&gt; and &lt;a href=&quot;https://proton.me/lumo/ai/copilot-alternative&quot;&gt;Microsoft Copilot&lt;/a&gt;, both of which rely on visibility into your &lt;a href=&quot;https://proton.me/business/mail&quot;&gt;business emails&lt;/a&gt;, documents, calendars, and collaboration data to function.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For many businesses shopping for a cloud workspace, that’s an entirely acceptable tradeoff: Strict &lt;a href=&quot;https://proton.me/business/drive/cloud-data-security&quot;&gt;cloud data security&lt;/a&gt; sacrificed for the sake of convenience and functionality. But if your business handles sensitive information, such as confidential client data, &lt;a href=&quot;https://proton.me/business/business-continuity&quot;&gt;business continuity&lt;/a&gt; documents, or financial records, you might want to think twice about it.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If you’re an SMB, you might want to think &lt;em&gt;more&lt;/em&gt; than twice. According to Proton’s SMB Cybersecurity Report 2026, &lt;a href=&quot;https://proton.me/business/smb-cybersecurity-report&quot;&gt;&lt;u&gt;nearly one in four SMBs fell victim to a data breach&lt;/u&gt;&lt;/a&gt; in 2025. Hackers view SMBs as &lt;a href=&quot;https://proton.me/business/blog/vulnerability&quot;&gt;vulnerable targets&lt;/a&gt;. The wrong cloud workspace could expose you even more.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The right cloud workspace will offer end-to-end &lt;a href=&quot;https://proton.me/learn/encryption&quot;&gt;&lt;u&gt;encryption&lt;/u&gt;&lt;/a&gt; and &lt;a href=&quot;https://proton.me/blog/zero-knowledge-cloud-storage&quot;&gt;&lt;u&gt;zero-knowledge cloud storage&lt;/u&gt;&lt;/a&gt;. This means your provider can’t access your data, even if compelled.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;3. Data sovereignty is important (but not all providers respect it)&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Where data is collected, processed, and stored determines which laws and jurisdictions apply to it, and therefore its potential exposure.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Many cloud providers operate across jurisdictions, including countries where governments may compel access under local legal frameworks, either now or in the future. Your provider’s terms of service may not protect you from that.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;To stop jurisdictional authorities from exposing your data, privacy-first providers like Proton promote &lt;a href=&quot;https://proton.me/business/blog/data-sovereignty&quot;&gt;&lt;u&gt;data sovereignty&lt;/u&gt;&lt;/a&gt;: the concept that the laws that govern data should be the laws of where it was generated and collected — no matter where it&amp;#8217;s stored.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For companies operating in regulated industries and handling sensitive customer information and/or managing intellectual property, data sovereignty should be a significant strategic consideration. &lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Overlooking data sovereignty can be costly. In 2023, Meta was&lt;a href=&quot;https://www.edpb.europa.eu/news/news/2023/12-billion-euro-fine-facebook-result-edpb-binding-decision_en&quot;&gt; &lt;/a&gt;&lt;a href=&quot;https://www.edpb.europa.eu/news/news/2023/12-billion-euro-fine-facebook-result-edpb-binding-decision_en&quot;&gt;&lt;u&gt;fined €1.2 billion&lt;/u&gt;&lt;/a&gt; (the largest GDPR fine ever issued) not for a hack or a breach, but for storing &lt;a href=&quot;https://proton.me/business/blog/data-sovereignty-for-european-businesses&quot;&gt;European user data in the US&lt;/a&gt;. The data was secure. The jurisdiction wasn&amp;#8217;t.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;If you’re concerned about your data security and sovereignty, seek out providers that host data in privacy-first jurisdictions, such as Iceland or &lt;a href=&quot;https://proton.me/blog/switzerland&quot;&gt;&lt;u&gt;Switzerland&lt;/u&gt;&lt;/a&gt;.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;4. Remember: your governance burden grows with your business&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A common &lt;a href=&quot;https://proton.me/business/blog/cybersecurity-for-startups&quot;&gt;cybersecurity mistake made by scaling SMBs&lt;/a&gt; when choosing a cloud workspace is underestimating how quickly data governance and &lt;a href=&quot;https://proton.me/business/blog/network-access-control&quot;&gt;&lt;u&gt;access control&lt;/u&gt;&lt;/a&gt; becomes complicated by growth.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A workspace that enables you to manage permissions for a workforce of 10 might not be suited to doing the same for a workforce of 60, particularly when that expanded workforce includes contractors, external collaborators, and people spanning multiple departments with different access requirements.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;As you scale, your data governance will evolve from a simple setup task to a full-time job, involving a host of challenges, including permission sprawl, higher risk &lt;a href=&quot;https://proton.me/business/drive/templates/offboarding-checklist&quot;&gt;&lt;u&gt;offboarding&lt;/u&gt;&lt;/a&gt;, unreliable manual tracking, and decreasing visibility into who has access to what.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Some cloud ecosystems compound this challenge by distributing permissions and workflows across multiple integrated systems, which makes centralized oversight difficult.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Others, however, provide a single admin layer where admins can monitor, manage, and adjust access as the organization grows and evolves.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Pick the right type now, and you’ll avoid the headaches of the future that come with retrofitting access controls into a &lt;a href=&quot;https://proton.me/business&quot;&gt;workspace&lt;/a&gt; you’ve already scaled into.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;9 questions to ask yourself before you commit to a cloud workspace&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Before committing to a provider, ask:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Who controls the encryption keys?&lt;/li&gt;



&lt;li&gt;Can your provider’s employees access your data?&lt;/li&gt;



&lt;li&gt;What metadata remains visible to the provider?&lt;/li&gt;



&lt;li&gt;Is your data processed by the &lt;a href=&quot;https://proton.me/lumo/ai&quot;&gt;platform’s AI systems&lt;/a&gt;?&lt;/li&gt;



&lt;li&gt;Where is data stored and processed, and which jurisdictions apply?&lt;/li&gt;



&lt;li&gt;Can admins enforce multi-factor authentication and permissions centrally?&lt;/li&gt;



&lt;li&gt;How difficult would it be to migrate to a different workspace down the line?&lt;/li&gt;



&lt;li&gt;Can data be exported cleanly and completely?&lt;/li&gt;



&lt;li&gt;Will your governance tooling scale with your headcount?&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;A cloud workspace for the next five years, not the next 12 months&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The right cloud workspace isn’t the easiest to adopt today. It’s the one you’ll still be using, and trusting, in five years. A platform that gives you long term security, control, and flexibility, and without locking you into an ecosystem forever.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Sounds like Proton Workspace to us. A secure cloud &lt;a href=&quot;https://proton.me/business&quot;&gt;workspace&lt;/a&gt;, built on end-to-end &lt;a href=&quot;https://proton.me/learn/encryption&quot;&gt;encryption&lt;/a&gt;, zero-knowledge &lt;a href=&quot;https://proton.me/business/drive&quot;&gt;business cloud storage&lt;/a&gt;, and Swiss privacy law — with centralized admin controls designed to scale with your organization.&lt;/p&gt;



&lt;div class=&quot;flex flex-wrap justify-center gap-2&quot;&gt;

  &lt;a class=&quot;btn inline-block rounded-full font-bold btn-small btn-solid-purple&quot; href=&quot;https://proton.me/business/smb-cybersecurity-report#download-report&quot;&gt;Start free trial of Proton Workspace&lt;/a&gt;

&lt;/div&gt;
</content:encoded><category>For business</category><author>Alanna Alexander</author></item><item><title>How to set up secure document collaboration for your team — without leaking your
IP</title><link>https://proton.me/business/blog/document-collaboration</link><guid isPermaLink="true">https://proton.me/business/blog/document-collaboration</guid><description>Learn from this step-by-step guide how to secure real-time editing, access controls, and encrypted storage.</description><pubDate>Thu, 23 Jul 2026 12:14:51 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;Right now, there’s a file in your shared drive named something like &lt;strong&gt;v3_final_FINAL_FINAL.docx&lt;/strong&gt;&lt;em&gt;.&lt;/em&gt; You don’t know who edited it last. You don’t know if it’s the version your CTO signed off on. You’re not &lt;em&gt;entirely&lt;/em&gt; sure who has access to it.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This is ‘version chaos’: an all too common problem for teams scaling remotely. Feels bad, doesn’t it? Possibly not bad enough. Because it isn’t just a messy irritant: it’s a serious security liability.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Uncontrolled access means ex-employees and contractors retain permissions that were never revoked. Untracked versions mean sensitive information ends up in the wrong places at the wrong times. And the document collaboration tools you’re using are quietly and constantly &lt;a href=&quot;https://proton.me/blog/what-is-your-data-worth-to-google&quot;&gt;&lt;u&gt;processing the contents of your documents&lt;/u&gt;&lt;/a&gt; to power their AI features and search indexing.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;But it doesn’t have to be this way. Here’s a step-by-step guide to using document collaboration tools without opening yourself up to an IP leak.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;How most teams get document collaboration wrong&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/business/drive/docs&quot;&gt;Online document collaboration&lt;/a&gt; is an essential part of doing business. It’s fast, efficient, and it doesn’t matter where your workforce is (as long as they’ve got WiFi).&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The problem is, many early-stage teams tend to reach for whatever’s fastest to implement — &lt;a href=&quot;https://proton.me/drive/google-docs-alternative&quot;&gt;Google Docs&lt;/a&gt;, Notion, &lt;a href=&quot;https://proton.me/drive/dropbox-alternative&quot;&gt;Dropbox&lt;/a&gt; — and immediately start using them without stopping to build a system around them. No folder architecture, access conventions, or version control protocol.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For a startup team moving fast, this can feel fine. But it really &lt;em&gt;isn&amp;#8217;t&lt;/em&gt; fine, especially for a team whose documents contain IP worth protecting. In fact, &lt;a href=&quot;https://proton.me/business/blog/cybersecurity-for-startups&quot;&gt;cybersecurity for startups&lt;/a&gt; should start a lot earlier than you think.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The resulting issues tend to cluster around three things:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Version chaos: &lt;/strong&gt;With no system in place, documents multiply and there’s no single source of truth to hang onto. People work from outdated files. Changes get lost in the mix. There are five slightly different versions of the same roadmap on your drive without any way to confirm which one’s current.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Access sprawl:&lt;/strong&gt; Managing permissions is time-consuming, so files get broadly shared instead of specifically managed. Contractors, ex-employees, and external collaborators accumulate access. You soon lose track of who can see what.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Unnoticed data exposure:&lt;/strong&gt; Consumer-grade collaboration tools commonly scan documents to power their search indexing, AI suggestions, and personalized advertising. Nothing just sits securely in your cloud folder — it’s being read by a robot.&lt;/li&gt;
&lt;/ul&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;What good document collaboration looks like&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Before you’ve even looked at document collaboration tools, be clear about what you’re trying to achieve first.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;A good document collaboration setup gives you five things:&lt;/p&gt;



&lt;ol class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Real-time co-editing: &lt;/strong&gt;Instead of having to play email tennis with documents, multiple people can edit the same document at the same time, with changes visible as they happen&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Version history: &lt;/strong&gt;A reliable, timestamped record of who changed what and when that prevents you having to rely on your sticky notes or less sticky memory&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Granular access controls:&lt;/strong&gt; You can set permissions at folder, document, and user level (the opposite of an “anyone with the link” policy)&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Secure external sharing: &lt;/strong&gt;You can share documents outside your organization without opening the floodgates to everything else in your drive&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;True data privacy: &lt;/strong&gt;You’re confident that your document-based data isn’t being scanned, mined, or processed by a third party (and that includes your &lt;a href=&quot;https://proton.me/business/drive&quot;&gt;business cloud storage&lt;/a&gt; provider)&lt;/li&gt;
&lt;/ol&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;With most popular collaboration tools (those tools teams reach for without a second thought) you might get two of these. The right platform can give you all five.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;But whatever you use, you’ll still need a system to make them work.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;How to set up document collaboration for your team: a step-by-step framework&lt;/h2&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Step 1: Audit what you have&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;You can’t build a clean, secure system for document collaboration on top of a messy, insecure one. So start with an honest audit of what you’ve already got.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;List every tool where your documents currently live (&lt;a href=&quot;https://proton.me/drive/google-drive-alternative&quot;&gt;Google Drive&lt;/a&gt;, Notion, &lt;a href=&quot;https://proton.me/drive/dropbox-alternative&quot;&gt;Dropbox&lt;/a&gt;, email attachments, Slack). Then find out who has access to these tools, who controls access to them, and what happens to a document once it&amp;#8217;s left your system.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Scour your drives for ‘problem files’ that will need special attention: documents that exist in multiple versions with no clear owner, folders shared with people who no longer need access, and commercially sensitive files (e.g. roadmaps, financial models, technical specs) sitting in tools with weak or non-existent access controls.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Step 2: Design a folder architecture that makes sense (and isn’t too complex)&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Whatever you do next, &lt;em&gt;don’t&lt;/em&gt; migrate first and organize later. That’s just compounding chaos: moving the same mess to a new and less familiar location.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Instead, take a breath… then design your folder structure. To guide you, here’s a simple, scalable folder architecture that will suit most start-ups:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Company&lt;/strong&gt;: board meeting minutes, shareholder agreements, fundraising materials, legal contracts&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Product&lt;/strong&gt;: roadmaps, feature specs, design files, research&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Engineering&lt;/strong&gt;: technical documentation, architecture decisions, internal tooling guides, technical specs&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Operations: &lt;/strong&gt;HR policies, finance, supplier contracts&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Clients&lt;/strong&gt;: one subfolder per client, containing everything related to that relationship.&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Remember: keep things simple and &lt;em&gt;shallow&lt;/em&gt;. Complex file structures tend to get ignored — people dump files at the top level and chaos ensues. As a general rule: three levels of nesting, and no more. If you find yourself creating a fourth, the structure needs simplifying.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Step 3: Match your access levels to data sensitivity&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Not everybody needs access to everything. &lt;a href=&quot;https://proton.me/business/drive/data-protection&quot;&gt;Business data protection&lt;/a&gt; starts with setting three tiers of access &lt;em&gt;before&lt;/em&gt; you invite your team in.&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Company-wide: &lt;/strong&gt;non-sensitive operational documents such as team handbooks, general meeting notes, process guides&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Team-level access: &lt;/strong&gt;departmental work that’s accessible to the relevant team only&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Restricted access: &lt;/strong&gt;anything commercially sensitive, legally protected, or covered by client confidentiality. This is the most important tier to secure: if (say) fundraising documents, roadmaps, technical specs, customer data, or client contracts are seen or shared by the wrong person, it spells competitive or legal liability&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Our &lt;a href=&quot;https://proton.me/business&quot;&gt;&lt;u&gt;Workspace&lt;/u&gt;&lt;/a&gt; app handles all of this from a single admin dashboard. You can control members, permissions, and app access in one place, however big the team gets.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Step 4: Establish the four golden rules of version control&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Now your folder architecture is in place, you need to establish four simple conventions to ensure that you never see a file in one of those folders named &lt;strong&gt;v3_final_FINAL_FINAL2_FINAL3.docx&lt;/strong&gt; again. And won’t that be nicer for everyone?&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;These four rules apply to everyone on your team (make sure they know it):&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;All live documents exist in one place&lt;/strong&gt;: No local copies, no email attachments&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;No version numbers in file names: &lt;/strong&gt;Your tool should provide a proper version history and track every change. Share documents via link rather than attachment to avoid confusion. If you need to share a static export, put the date in the covering note, not the file name.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Version history is the single source of truth&lt;/strong&gt;: If you want to know who changed what, when, just look in the version history.&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Don&amp;#8217;t delete — archive: &lt;/strong&gt;Move superseded documents to a clearly labeled archive folder. You don’t want to delete a document that you (or a regulator) needs later.&lt;/li&gt;
&lt;/ul&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Step 5: Define your protocol around external sharing&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;External sharing is where access control most commonly breaks down. A contractor gets linked to an entire project folder rather than just what&amp;#8217;s relevant (with no expiration date on that access). A potential investor retains access to your fundraising data room long after deciding not to invest. It’s a dangerous world outside your perimeter.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;To minimize that danger, set a protocol before you share anything externally. Three rules:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;&lt;strong&gt;Grant minimum access &lt;/strong&gt;for specific documents or folders only (not entire workspaces or drives)&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Set expiration dates&lt;/strong&gt; on all links&lt;/li&gt;



&lt;li&gt;&lt;strong&gt;Revoke access at project end&lt;/strong&gt; as a standard &lt;a href=&quot;https://proton.me/business/drive/templates/offboarding-checklist&quot;&gt;&lt;u&gt;offboarding&lt;/u&gt;&lt;/a&gt; step&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The right productivity and collaboration tools automatically enforce rules like this for you. Proton Drive sets expiration dates on shared links by default — so access expires without anyone having to remember to revoke it.&lt;/p&gt;



&lt;h3 class=&quot;wp-block-heading&quot;&gt;Step 6: Choose a platform that can enforce your security requirements&lt;/h3&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Most teams evaluate collaboration platforms on usability alone. Usability matters, of course. But security cannot be an afterthought.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Intellectual property is now the most expensive data type to lose in a &lt;a href=&quot;https://proton.me/business/pass/breach-observatory&quot;&gt;&lt;/a&gt;&lt;a href=&quot;https://proton.me/business/pass/breach-observatory&quot;&gt;data&lt;/a&gt; breach (at $178 per compromised record, according to &lt;a href=&quot;https://www.ibm.com/reports/data-breach&quot;&gt;&lt;u&gt;IBM&lt;/u&gt;&lt;/a&gt;). If your documents contain IP worth protecting, your collaboration platform needs to be secure by default, not configuration.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;When selecting a collaboration tool, you need to know:&lt;/p&gt;



&lt;ul class=&quot;wp-block-list&quot;&gt;
&lt;li&gt;Can the provider access your document content?&lt;/li&gt;



&lt;li&gt;Where is your data stored and which jurisdictions apply? Is your &lt;a href=&quot;https://proton.me/business/blog/data-sovereignty&quot;&gt;&lt;u&gt;data sovereign&lt;/u&gt;&lt;/a&gt;?&lt;/li&gt;



&lt;li&gt;Is &lt;a href=&quot;https://proton.me/learn/encryption&quot;&gt;encryption&lt;/a&gt; end-to-end or only in transit?&lt;/li&gt;



&lt;li&gt;Are admin controls centralized and granular enough to enforce access policy?&lt;/li&gt;
&lt;/ul&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Here’s how four online document collaboration tools compare:&lt;/p&gt;



&lt;figure class=&quot;wp-block-table&quot;&gt;&lt;table class=&quot;has-fixed-layout&quot;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;Google Docs&lt;/td&gt;&lt;td&gt;Notion&lt;/td&gt;&lt;td&gt;Microsoft 365&lt;/td&gt;&lt;td&gt;Proton Docs&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Real-time co-editing&lt;/td&gt;&lt;td&gt;✓&lt;/td&gt;&lt;td&gt;✓&lt;/td&gt;&lt;td&gt;✓&lt;/td&gt;&lt;td&gt;✓&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Version history&lt;/td&gt;&lt;td&gt;✓&lt;/td&gt;&lt;td&gt;Limited&lt;/td&gt;&lt;td&gt;✓&lt;/td&gt;&lt;td&gt;✓&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;End-to-end encryption&lt;/td&gt;&lt;td&gt;✗&lt;/td&gt;&lt;td&gt;✗&lt;/td&gt;&lt;td&gt;✗&lt;/td&gt;&lt;td&gt;✓&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Zero-knowledge storage&lt;/td&gt;&lt;td&gt;✗&lt;/td&gt;&lt;td&gt;✗&lt;/td&gt;&lt;td&gt;✗&lt;/td&gt;&lt;td&gt;✓&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Centralized admin controls&lt;/td&gt;&lt;td&gt;Partial&lt;/td&gt;&lt;td&gt;Limited&lt;/td&gt;&lt;td&gt;✓&lt;/td&gt;&lt;td&gt;✓&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;No data processing for AI/ads&lt;/td&gt;&lt;td&gt;✗&lt;/td&gt;&lt;td&gt;✗&lt;/td&gt;&lt;td&gt;✗&lt;/td&gt;&lt;td&gt;✓&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Privacy-first jurisdiction*&lt;/td&gt;&lt;td&gt;✗&lt;/td&gt;&lt;td&gt;✗&lt;/td&gt;&lt;td&gt;✗&lt;/td&gt;&lt;td&gt;✓&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/figure&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;em&gt;*Google Docs, Notion, and Confluence are headquartered in the US and subject to US jurisdiction, including &lt;/em&gt;&lt;a href=&quot;https://proton.me/business/blog/tech-investment-not-cost&quot;&gt;&lt;u&gt;&lt;em&gt;the CLOUD Act&lt;/em&gt;&lt;/u&gt;&lt;/a&gt;&lt;em&gt;. Proton is headquartered in Switzerland, outside US and EU jurisdiction.&lt;/em&gt;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For teams handling sensitive IP, Proton Docs lets your team perform &lt;a href=&quot;https://proton.me/business/drive/docs&quot;&gt;&lt;u&gt;real-time collaborative editing&lt;/u&gt;&lt;/a&gt; without risking data exposure.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;It’s part of Proton Workspace, a &lt;a href=&quot;https://proton.me/business&quot;&gt;&lt;u&gt;secure collaboration suite&lt;/u&gt;&lt;/a&gt; which adds encrypted &lt;a href=&quot;https://proton.me/business/drive&quot;&gt;business cloud storage&lt;/a&gt;, secure &lt;a href=&quot;https://proton.me/business/meet&quot;&gt;&lt;u&gt;video conferencing&lt;/u&gt;&lt;/a&gt;, and centralized admin controls to document collaboration. All built on end-to-end encryption and protected by Switzerland’s stringent privacy laws.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Meet your efficient &lt;em&gt;and&lt;/em&gt; secure collaboration stack&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;To have true control over your documents — and peace of mind about their security — you need to have the right system in place &lt;em&gt;and&lt;/em&gt; the right platform.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;We’ve shown you how to build the right system. The platform to enforce it is &lt;a href=&quot;https://proton.me/business&quot;&gt;&lt;u&gt;Proton Workspace&lt;/u&gt;&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Over 100,000 organizations (including government agencies, healthcare providers, and law firms) trust Proton to secure their most sensitive data. Your documents deserve the same standard of protection.&lt;/p&gt;



&lt;div class=&quot;flex flex-wrap justify-center gap-2&quot;&gt;

  &lt;a class=&quot;btn inline-block rounded-full font-bold btn-small btn-solid-purple&quot; href=&quot;https://proton.me/business/smb-cybersecurity-report#download-report&quot;&gt;Start free trial of Proton Workspace&lt;/a&gt;

&lt;/div&gt;
</content:encoded><category>For business</category><author>Alanna Alexander</author></item><item><title>The best office suites in 2026 (free and paid)</title><link>https://proton.me/business/blog/best-office-suites</link><guid isPermaLink="true">https://proton.me/business/blog/best-office-suites</guid><description>Office suite prices are rising and privacy questions are growing. Here&apos;s how Microsoft, Google, Zoho, and Proton compare in 2026.</description><pubDate>Thu, 23 Jul 2026 11:42:48 GMT</pubDate><content:encoded>
&lt;p class=&quot;wp-block-paragraph&quot;&gt;For the better part of 20 years, there have been a big two dominating the office suite space, and only one choice for many businesses: the desktop power of &lt;a href=&quot;https://proton.me/business/microsoft-365-alternative&quot;&gt;Microsoft 365&lt;/a&gt;, or the online collaboration ease of &lt;a href=&quot;https://proton.me/business/google-workspace-alternative&quot;&gt;Google Workspace&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Now prices are rising, and not everyone (least of all SMBs) can afford them. Microsoft is &lt;a href=&quot;https://www.microsoft.com/en-us/licensing/news/2026-m365-packaging-pricing-updates&quot;&gt;&lt;u&gt;hiking its prices again&lt;/u&gt;&lt;/a&gt; in July 2026. There are also questions, increasingly hard to ignore, over what these providers are doing with your data, and what that means from a privacy and security perspective.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Historically, the alternative for those not using one of the big two has been a self-assembled stack sourced from multiple providers. This approach, however, can leave you with something more expensive, fragmented, and vulnerable than a single integrated platform.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The market has changed, and in 2026 your choices are less restricted.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Here’s a comparison of the main office suites in 2026: what each costs, what each includes, and what each does with your data.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;How the main office suites compare&amp;nbsp;&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Four suites cover most of the office suite market in 2026: the two established leaders, a budget option, and a suite built on a fundamentally different architecture to any other.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;That suite is &lt;a href=&quot;https://proton.me/business&quot;&gt;&lt;u&gt;Proton Workspace&lt;/u&gt;&lt;/a&gt;. Built on open source, independently audited &lt;a href=&quot;https://proton.me/blog/zero-knowledge-cloud-storage&quot;&gt;&lt;u&gt;zero-knowledge architecture&lt;/u&gt;&lt;/a&gt; which encrypts your data before it reaches Proton’s servers, Proton Workspace makes it impossible for Proton to access your data.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Whether you need a full online office suite or a desktop replacement, here’s how the four best options stack up.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;em&gt;N.B. Prices shown are for Business Standard tiers (annual billing) unless otherwise noted. Prices are accurate as of time of writing.&lt;/em&gt;&lt;/p&gt;



&lt;figure class=&quot;wp-block-table&quot;&gt;&lt;table class=&quot;has-fixed-layout&quot;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;Microsoft 365&lt;/td&gt;&lt;td&gt;Google Workspace&lt;/td&gt;&lt;td&gt;Zoho Workplace&lt;/td&gt;&lt;td&gt;Proton Workspace&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Core apps&lt;/td&gt;&lt;td&gt;Word, Excel, PowerPoint, Teams, Outlook, OneDrive&lt;/td&gt;&lt;td&gt;Docs, Sheets, Slides, Meet, Gmail, Drive&lt;/td&gt;&lt;td&gt;Writer, Sheet, Show, Cliq, Mail, WorkDrive&lt;/td&gt;&lt;td&gt;Docs, Sheets, Meet, Mail, Drive, Calendar&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Desktop apps&lt;/td&gt;&lt;td&gt;Business Standard+&lt;/td&gt;&lt;td&gt;Web only&lt;/td&gt;&lt;td&gt;Web only&lt;/td&gt;&lt;td&gt;Web only&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;AI assistant&lt;/td&gt;&lt;td&gt;Copilot (basic included; full Copilot adds $30/user/month)&lt;/td&gt;&lt;td&gt;Gemini (included)&lt;/td&gt;&lt;td&gt;Limited&lt;/td&gt;&lt;td&gt;Lumo (Premium only)&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Data is protected from being used by AI for functionality and training&lt;/td&gt;&lt;td&gt;No&lt;/td&gt;&lt;td&gt;No&lt;/td&gt;&lt;td&gt;Yes (limited AI features)&lt;/td&gt;&lt;td&gt;Yes&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Encryption&lt;/td&gt;&lt;td&gt;Server-side, Microsoft holds encryption keys&lt;/td&gt;&lt;td&gt;Server-side, Google holds encryption keys&lt;/td&gt;&lt;td&gt;Server-side, Zoho holds encryption keys&lt;/td&gt;&lt;td&gt;Zero-knowledge architecture, Proton holds no keys&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;VPN included&lt;/td&gt;&lt;td&gt;No&lt;/td&gt;&lt;td&gt;No&lt;/td&gt;&lt;td&gt;No&lt;/td&gt;&lt;td&gt;Yes&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Password manager included&lt;/td&gt;&lt;td&gt;No&lt;/td&gt;&lt;td&gt;No&lt;/td&gt;&lt;td&gt;No&lt;/td&gt;&lt;td&gt;Yes&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;ISO 27001 and SOC 2 Type II certified&amp;nbsp;&lt;/td&gt;&lt;td&gt;Yes&lt;/td&gt;&lt;td&gt;Yes&lt;/td&gt;&lt;td&gt;Yes&lt;/td&gt;&lt;td&gt;Yes&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Jurisdiction&lt;/td&gt;&lt;td&gt;US&amp;nbsp;(CLOUD Act applies)&lt;/td&gt;&lt;td&gt;US&amp;nbsp;(CLOUD Act applies)&lt;/td&gt;&lt;td&gt;India/US (CLOUD Act applies)&lt;/td&gt;&lt;td&gt;Switzerland (not subject to CLOUD Act)&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Base price/user/month&lt;/td&gt;&lt;td&gt;$14 (from July 2026)&lt;/td&gt;&lt;td&gt;$14 (Standard)&lt;/td&gt;&lt;td&gt;$6 (Professional)&lt;/td&gt;&lt;td&gt;~$14.25 (€12.99)&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;True cost/user/month&lt;/td&gt;&lt;td&gt;$44 with full Copilot add-on&lt;/td&gt;&lt;td&gt;$14+ with security add-ons&lt;/td&gt;&lt;td&gt;$6&lt;/td&gt;&lt;td&gt;~$14.25 all-inclusive&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Best for&lt;/td&gt;&lt;td&gt;Microsoft ecosystem, desktop apps&lt;/td&gt;&lt;td&gt;Collaboration, UX&lt;/td&gt;&lt;td&gt;Budget-conscious SMBs&lt;/td&gt;&lt;td&gt;Privacy-first SMBs&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/figure&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;The real cost of each office suite&amp;nbsp;&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;This comparison table includes a ‘real cost’ row because headline prices can be misleading.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Microsoft 365 Business Standard and Google Workspace Standard both list at $14/user/month. Proton Workspace Standard costs €12.99/user/month. The differences only appear when you look at what each platform charges extra for.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Microsoft is promoting Copilot as a reason to stay on its platform. But for the full Copilot experience, you’ll need to pay an additional $30/user/month on top of the Business Standard subscription. For a 25 person team that’s $9,000 more per year.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Google won’t charge you extra for its AI. Google Workspace Business Standard includes Gemini. But if you want additional security features beyond the baseline, you’ll need Google Workspace Business Plus ($22/user), or to purchase add-ons separately.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Zoho Workplace Professional really is only $6/user/month. The trade-off is a less polished ecosystem and no zero-knowledge architecture.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton’s pricing is similarly transparent, but Proton Workspace Standard includes a lot more than Zoho Workplace. You get all the main office apps for €12.99/user/month, plus apps Microsoft and Google don’t include: &lt;a href=&quot;http://proton.me/business/vpn&quot;&gt;&lt;u&gt;business VPN&lt;/u&gt;&lt;/a&gt; and a &lt;a href=&quot;http://proton.me/pass&quot;&gt;&lt;u&gt;password manager&lt;/u&gt;&lt;/a&gt; — all protected by zero-knowledge encryption and &lt;a href=&quot;https://proton.me/blog/switzerland&quot;&gt;&lt;u&gt;Swiss jurisdiction&lt;/u&gt;&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;The privacy question most office suite comparisons skip&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Who holds the encryption keys?&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;In other words, does your office suite provider have technical access to your documents, emails, and files?&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Google, Microsoft, and Zoho all hold the keys.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Here’s why this matters: if your provider has the keys, they can access your data, whatever their stated privacy policy says — policies change. And if your provider gets breached, your data is exposed, too.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Google and Microsoft’s AI compounds the problem: Copilot and Gemini both depend on having access to your document contents to function. (In fact, &lt;a href=&quot;https://workspaceupdates.googleblog.com/2025/01/expanding-google-ai-to-more-of-google-workspace.html&quot;&gt;&lt;u&gt;Google raised its prices&lt;/u&gt;&lt;/a&gt; in 2025 to incorporate Gemini in Business and Enterprise packages.)&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/business/blog/data-sovereignty&quot;&gt;&lt;u&gt;Data sovereignty&lt;/u&gt;&lt;/a&gt; is a third concern. Microsoft, Google and Zoho store data in jurisdictions subject to the &lt;a href=&quot;https://www.congress.gov/bill/115th-congress/senate-bill/2383&quot;&gt;&lt;u&gt;US CLOUD Act&lt;/u&gt;&lt;/a&gt;. That means the US government can demand access to your data at any time.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton doesn’t hold the keys, and can never access your data, even if compelled by a court order. With Proton Workspace, you get the structural guarantee of zero-knowledge architecture, not a changeable privacy policy. Your data is encrypted on your device before it reaches Proton’s servers, and it’s stored in Switzerland, outside US CLOUD Act jurisdiction.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton Workspace Premium users get Lumo AI, a &lt;a href=&quot;http://proton.me/business/lumo&quot;&gt;business AI assistant&lt;/a&gt; that doesn’t require access to your document contents and never trains on your data. (Zoho Workplace offers only limited AI features.)&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Find out more about &lt;a href=&quot;https://proton.me/business/blog/us-tech-risk-report-for-europe&quot;&gt;European businesses&amp;#8217; dependence on US tech&lt;/a&gt; and why the stakes are now higher than ever.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Proton Workspace: the only office suite with privacy by design&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;With &lt;a href=&quot;https://proton.me/business&quot;&gt;&lt;u&gt;Proton Workspace&lt;/u&gt;&lt;/a&gt;, teams get to use all the major office apps you’ll find in Microsoft 365 and Google Workspace: business e&lt;a href=&quot;https://proton.me/business/mail&quot;&gt;&lt;u&gt;mail&lt;/u&gt;&lt;/a&gt;, &lt;a href=&quot;https://proton.me/business/mail/team-calendar&quot;&gt;&lt;u&gt;calendar,&lt;/u&gt;&lt;/a&gt; enterprise cloud s&lt;a href=&quot;https://proton.me/business/drive&quot;&gt;&lt;u&gt;torage&lt;/u&gt;&lt;/a&gt;, &lt;a href=&quot;https://proton.me/business/drive/docs&quot;&gt;&lt;u&gt;documents,&lt;/u&gt;&lt;/a&gt; &lt;a href=&quot;https://proton.me/business/drive/sheets&quot;&gt;&lt;u&gt;spreadsheets&lt;/u&gt;&lt;/a&gt;, &lt;a href=&quot;https://proton.me/business/meet&quot;&gt;&lt;u&gt;video conferencing&lt;/u&gt;&lt;/a&gt; and (for Premium users) an &lt;a href=&quot;http://proton.me/business/lumo&quot;&gt;&lt;u&gt;AI assistant&lt;/u&gt;&lt;/a&gt;.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Proton’s office suite also includes two security features that the big two don’t: &lt;a href=&quot;http://proton.me/business/vpn&quot;&gt;&lt;u&gt;a business VPN&lt;/u&gt;&lt;/a&gt; that keeps your team’s connections private wherever they’re working, and a team p&lt;a href=&quot;http://proton.me/business/pass&quot;&gt;&lt;u&gt;assword manage&lt;/u&gt;&lt;/a&gt;&lt;a href=&quot;http://proton.me/business/pass&quot;&gt;&lt;u&gt;r&lt;/u&gt;&lt;/a&gt; that closes one of the most vulnerable vectors.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;Finally, unlike the big two, zero-knowledge encryption applies across every Proton product by default.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;For now, Proton Workspace doesn’t have a presentation app equivalent or deep legacy ERP integrations (worth knowing upfront if your business depends on complex third-party connections).&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;But for businesses that value &lt;a href=&quot;https://proton.me/business/blog/data-sovereignty-for-european-businesses&quot;&gt;data sovereignty&lt;/a&gt;, Proton is the straightforward choice. That’s why Proton is trusted by 100M+ users and 100,000+ businesses, including UN agencies and Fortune 500 companies.&lt;/p&gt;



&lt;h2 class=&quot;wp-block-heading&quot;&gt;Which office suite is right for you?&lt;/h2&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;The office suite market has changed. You can now have both privacy and productivity in a single, full-stack platform that covers everything a growing SMB needs — without asking you to accept vendor access and uncertain jurisdiction as part of the deal.&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;&lt;a href=&quot;https://proton.me/business/drive/workspace&quot;&gt;Proton Workspace&lt;/a&gt; is the only suite in this comparison built on zero-knowledge architecture, which ensures only you can access your data. It’s about the same price as market leaders, with more essential security capabilities bundled in.&amp;nbsp;&lt;/p&gt;



&lt;p class=&quot;wp-block-paragraph&quot;&gt;And it’s easy to get started. Migration from Microsoft 365 and Google Workspace can be &lt;a href=&quot;http://proton.me/easyswitch&quot;&gt;&lt;u&gt;self-service&lt;/u&gt;&lt;/a&gt;, or fully supported by Proton if it’s more complex, and the UX is familiar enough for your team to get started without training.&lt;/p&gt;



&lt;div class=&quot;flex flex-wrap justify-center gap-2&quot;&gt;&amp;nbsp;
&lt;a class=&quot;btn inline-block rounded-full font-bold btn-small btn-solid-purple&quot; href=&quot;https://proton.me/business/drive/workspace&quot;&gt;Start free trial of Proton Workspace&lt;/a&gt;
&lt;/div&gt;
</content:encoded><category>For business</category><author>Alanna Alexander</author></item></channel></rss>