Skip to main content
← Back to blog

How Do Cannabis Businesses Protect Customer Data?

Dispensary customer records combine government ID, date of birth, and purchase history in one place. Here is what protecting that actually requires.

By Alex Castrillo8 min readFact-checked September 6, 2026
CannaShield answer page: how cannabis businesses protect customer data

The single highest-leverage move is collecting and keeping less. A dispensary that scans an ID to verify age and retains only the verification result has a far smaller problem than one storing ID images for years. After that: control who can reach the data, encrypt it, put MFA on every system that holds it, and know exactly which vendors have a copy.

The short version

  • Cannabis retail data is unusually toxic — government ID, date of birth, medical status, and purchase history in a single record.
  • The STIIIZY notice is the reference case: roughly 380,000 people notified, and the compromise ran through a point-of-sale vendor.
  • Retention policy beats security tooling. Data you deleted cannot be stolen.

What customer data does a dispensary actually hold?

More than most operators realize, because it accumulates across systems nobody audits together.

The STIIIZY breach notice is a useful inventory of what a cannabis retail record can contain: name, address, date of birth, age, driver's license number, passport number, photograph, signatures from government ID cards, medical cannabis cards, and transaction histories. Roughly 380,000 people were notified. The company said not all of that information was affected for every individual.

Read that list again and think about your own environment. Then add the loyalty platform, the delivery app, the SMS marketing tool, and the e-commerce menu. Each holds a slice.

Why is this data worse than typical retail data?

Because of what it lets someone conclude, and because you cannot reissue it.

A stolen credit card gets cancelled in an afternoon. A driver's license number, date of birth, and ID photograph are useful to a fraudster for years. Combine those with purchase history at a cannabis retailer and you have a record that supports identity theft and, depending on the customer's employment, immigration status, custody situation, or professional licensing, real personal harm.

That combination is also what makes the litigation exposure disproportionate to the size of the business.

What does data minimization look like in practice?

Four questions, asked about every field you collect:

  • Do we need this to complete the sale or satisfy a regulation?
  • Do we need to keep it after the sale, or only to have checked it?
  • If we must keep it, for how long, and who enforces the deletion?
  • Does a second system get a copy, and does that copy expire too?

The specific decision worth revisiting: ID scan images. Verifying age is required. Warehousing a photograph of every customer's license indefinitely usually is not, and it converts a routine compliance step into the most damaging thing in your environment. Confirm your state's retention requirements with counsel, then delete on schedule and make the deletion automatic rather than someone's quarterly chore.

Who inside the business should be able to see customer records?

Far fewer people than currently can.

Most dispensary POS deployments start with a couple of role templates and drift. Budtenders end up with reporting access. A manager account gets shared during a busy weekend and never rotated. Former employees stay active for weeks because offboarding is a verbal process.

Fix the boring things first: named accounts for every person, no shared logins, roles that match what the job actually requires, MFA on every administrative account, and an offboarding checklist that includes POS, email, the seed-to-sale system, and every SaaS tool. Then review the access list quarterly and write down that you did.

How much of this depends on our vendors?

Most of it, which is the uncomfortable part.

In the STIIIZY case, the compromise involved a vendor that provided point-of-sale processing services for certain retail locations. The operator's own controls were not the failure point, and the operator still owned the notification, the litigation, and the brand damage.

So the vendor register is not paperwork. For every service that touches customer data, record who owns the relationship, what data it holds, what access it has, when the contract renews, what security evidence you have seen and when, and what you would do if it went dark tomorrow. Prioritize anything connected to identity, POS, seed-to-sale, payments, or backups. CISA publishes a vendor risk template built for small and midsize businesses if you want a starting structure.

Is encryption enough?

Encryption is necessary and frequently misunderstood.

Data encrypted at rest on a server does nothing if an attacker is logged in as a valid user — the application decrypts it for them, same as it does for you. Encryption defeats stolen disks and intercepted traffic. It does not defeat stolen credentials, which is how most of these incidents actually start.

Encryption does have one concrete legal effect worth knowing: under Connecticut's breach-notification analysis, whether covered data was encrypted can change the obligation. That is a reason to encrypt, not a reason to stop at encrypting.

What do we owe customers if their data is exposed?

Under Conn. Gen. Stat. § 36a-701b, a breach involving covered personal information triggers notification duties to affected residents and to the Connecticut Attorney General, within statutory timeframes. The Attorney General's office publishes reporting guidance and a submission process.

Layered on top: DCP policies treat certain security incidents as separately reportable, potentially by the next business day. Those two clocks run independently. An operator who only knows about the breach-notification statute can be compliant with one obligation and late on the other.

Where should a small operator start this week?

Two things, both of which take less than a day.

First, list every system that holds customer data — including the ones marketing set up without telling anyone. Second, find out how long your POS retains ID scans and whether you can shorten it.

That is not a security program. It is the first honest inventory most operators have ever had, and it usually surfaces at least one system nobody knew was still collecting.

Where to go next

Scope note: This page is practical cybersecurity and GRC guidance for licensed cannabis operators. It is not legal advice, and it does not claim that every recommended control is expressly required by a cannabis regulator. Confirm how each obligation applies to your business with counsel.

Primary sources

About the author

Alex Castrillo

Founder of CannaShield. Working cyber incident response analyst and vCISO for licensed cannabis operators. Writes on cannabis breach analysis, GRC, cyber insurance readiness, and email-spoofing risk.

CannaShield on LinkedIn →

Make the risk concrete.

Start with the free CannaShield Email Security Scorecard to see whether your domain can be spoofed and whether DMARC, SPF, and DKIM are giving attackers room to impersonate your cannabis business.

Run the free scorecard →

Keep sharpening the cannabis security picture.

GRC & Frameworks

Cannabis Cybersecurity Checklist for 2026

Twelve controls, ordered by what actually prevents loss, with the evidence each one should produce. Built for operators who have limited hours and need to spend them well.

Compliance & Licensing

Cannabis Data Privacy Requirements by State

A method for reading any state’s obligations, plus what applies in Connecticut, New York, Massachusetts, New Jersey, and Illinois. Verify the details with counsel before you rely on them.

Security Leadership

Do Cannabis Companies Need a CISO?

Most licensed operators do not need a full-time CISO. They do need someone accountable for security decisions. Here is how to tell which one you are.