Give staff access only to the product or customer information needed for their assigned work. Use individual accounts when the current product supports them, and avoid shared passwords where an action needs to be traced to a person.

Keep customer contact and credit details restricted to staff handling that transaction. Review access when someone changes role or leaves, and store exports or paper records in a controlled place. Confirm which controls are available in the current setup before promising different permission levels.

Train staff not to copy customer details into public messages, product photos, or informal notes. Remove unnecessary access and copies while retaining records required for ordinary business purposes. Follow current privacy obligations and keep the process proportionate to the information the shop holds. Store paper notes out of view and securely destroy unneeded copies.